ML19301A365

From kanterella
Jump to navigation Jump to search
OEDO-18-00608 Oedo Ticket - Status of Recommendations: Audit of Nrc'S Safeguards Information Local Area Network and Electronic Safe (OIG-13-A-16) NSIR Enclosure Response
ML19301A365
Person / Time
Issue date: 10/31/2019
From: Robert Norman
NRC/NSIR/DSO/ISB
To: Baker B
NRC/OIG/AIGA
Norman R
Shared Package
ML18320A088 List:
References
OEDO-18-00608
Download: ML19301A365 (1)


Text

AUDIT OF NRCS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE OIG-13-A-16 Status of Recommendations Recommendation 3: Evaluate and update the current folder structure to meet user needs.

The modernization of the Safeguards Information Local Area Network and Electronic Safe (SLES) system is complete. A conceptual plan for reorganizing the SLES folder structure has been discussed. However, due to the complexity of Documentum, which is the underlying database for SLES, actual reorganization of the folder structure requires a Documentum Security Specialist. The Office of the Chief Information Officer (OCIO) has developed a Task Order (T.O.) for a Documentum Security Specialist to analyze the suggested changes under the Global Infrastructure and Development Acquisition contract. When the Documentum T.O. is awarded (estimated completion date (ECD) late calendar year (CY) 2019 or early CY 2020), the Office of Nuclear Security and Incident Response (NSIR) will work with OCIO and the Documentum Security Specialist to implement the new folder structure in a test environment. The Documentum Security Specialist will complete an analysis to validate best security practices for the revised folder structure and least privilege access (ECD June 30, 2020).

Once the revised structure is validated in the test environment by SLES users, OCIO will coordinate deployment of the solution to the SLES production and failover environments. Deployment of the revised structure to these operating environments is estimated to take 3 to 6 months after the revised structure has been validated in a test environment.

Completion of this task is dependent upon the availability of a Documentum Security Specialist contractor.

Revised Target Completion Date: December 31, 2020 Recommendation 7: Develop a structured access process that is consistent with the Safeguards Information (SGI) need-to-know requirement and least privilege principle. This should include:

  • Establishing folder owners within SLES and providing the owners the authority to approve the need-to-know authorization (as opposed to branch chiefs).
  • Conducting periodic reviews of user access to folders.
  • Developing a standard process to grant user access.

Completion of Recommendation 7 is dependent upon implementation of the new folder structure. Both NSIR and OCIO propose the completion of Recommendation 7 be deferred until the new folder structure is analyzed and implemented. This will enable NSIR and OCIO to determine the new folder structure most suitable to the user-community and ensure that the folder structure provides least privilege access to SGI. In the interim, the NSIR SGI program manager has assumed ownership of the existing folders and makes a need-to-know determination on a case-by-case basis for expanded access to folders.

Upon implementation of the new folder structure, and identification of new folder owners, NSIR and OCIO will address the three sub-bullets above, in a more detailed manner that is consistent with the intent of the recommendation.

Revised Target Completion Date: April 30, 2021 Enclosure