NASA must fix cyber vulnerabilities

By

1,120 security incidents over last two years.

A new report from the US Government Accountability Office (GAO) found that NASA has multiple cybersecurity problems.

The report, dubbed “NASA Needs to Remedy Vulnerabilities in Key Networks" and released late last week, said the space agency does not always sufficiently identify and authenticate users, nor does it encrypt network services, audit and monitor computer-related events, or adequately protect its physical information technology resources.

Moreover, NASA networks and systems have been the targets of many successful cyberattacks, the report said. In a two-year period starting in 2007, NASA reported 1,120 security incidents that resulted in the installation of malicious software on its systems and unauthorised access to sensitive information.

“A key reason for these vulnerabilities is that NASA has not yet fully implemented its information security program to ensure that controls are appropriately designed and operating effectively,” the report concluded.

The report made several recommendations to fix the problems, such as implementing an adequate incident detection program, conducting comprehensive security testing of security control, and developing and implementing security policies for malware, physical protection and incident handling roles and responsibilities.

In a letter included in the report to the director of GAO information security issues, a NASA representative said the space agency "generally concurs" with the report's findings.

“Many of the recommendations are currently being implemented as part of an ongoing strategic effort to improve IT management and IT security program deficiencies,” said Lori Garver, NASA deputy administrator. “We will continue to mitigate the information security weaknesses identified in this report."

The GAO also revealed that it would make 179 additional recommendations to address access control weaknesses identified during its investigation.

See original article on scmagazineus.com

NASA must fix cyber vulnerabilities
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Ex-student charged over Western Sydney University cyberattacks

Ex-student charged over Western Sydney University cyberattacks

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

SA Water plans 'once-in-a-generation' core technology uplift

SA Water plans 'once-in-a-generation' core technology uplift

Log In

  |  Forgot your password?