U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Independent Evaluation of the Security of NRC's Publicly Accessible Web Applications

Report Information

Date Issued
Report Number
OIG-16-A-15
Report Type
Inspection / Evaluation
Joint Report
Yes
Participating OIG
Nuclear Regulatory Commission OIG
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

Develop and document procedures for ensuring publiclyaccessible Web applications are assigned a system ownerwith responsibility for ensuring adequate security measuresare in place for those applications.

Develop and document procedures for ensuring publiclyaccessible Web applications are incorporated into anapproved system authorization boundary and for clearlyidentifying those applications in system authorizationdocumentation.

Develop and document procedures for ensuring OHS isnotified of any changes to the population of publiclyaccessible Web applications to be included in the CyberHygiene scans.

Develop a plan and schedule to identify, review, and updateall NRC cyber security standards that have not beenupdated in the past 12 months.

Develop a plan and schedule for evaluating thevulnerabilities identified, determining the appropriate actionto address the vulnerability (e.g., mitigation, deviation, riskacceptance), and implementing the remedial actions.