U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Breadcrumb

Information Security Risk Evaluation of Region IV- Arlington, TX

Report Information

Date Issued
Report Number
OIG-13-A-07
Report Type
Other
Joint Report
Yes
Participating OIG
Nuclear Regulatory Commission OIG
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

Update the backup procedures for seat-managed servers to(i) reflect the current Region IV seat-managed server infrastructure; (ii) document current backup procedures for seat-managed servers; (iii) document procedures for creating Ghost images, including where those images are stored; (iv) define the schedule for creating Ghost images; (v) correct references to current seat-management contractor; and (vi) correct any other sections impacted by the changes to the server infrastructure or the transition to the new seat-management contractor.

Develop documented backup procedures for NRC-managed servers. The procedures should include the same level of detail as the backup procedures for seat-managed servers.

Develop and implement procedures for sending backups of NRC-managed servers to an offsite storage location in accordance with NRC requirements.

Establish a general laptop system and complete the process described in the NRC Laptop Security Policy for authorization of the general laptop system.

Update PG 0754.2, Physical Security Plan, to reflect the new office location, describe the current access control procedures for visitors, and describe functions now performed by the security guards.