ML20220A318

From kanterella
Jump to navigation Jump to search
OEDO-20-00176 Status of Recommendation: Audit of Nrc'S Safeguards Information Local Area Network and Electronic Safe (OIG-13-A-16) Enclosure
ML20220A318
Person / Time
Issue date: 09/25/2020
From: Brian Holian
Office of Nuclear Security and Incident Response
To: Baker B
NRC/OIG
Stapleton B
Shared Package
ML20220A162 List:
References
NSIR-20-0180, OEDO-20-00176, OIG-13-A-16
Download: ML20220A318 (2)


Text

STATUS OF RECOMMENDATIONS: AUDIT OF THE U.S. NUCLEAR REGULATORY COMMISSIONS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE (OIG-13-A-16)

Recommendation 3: Evaluate and update the current folder structure to meet user needs.

The modernization of the Safeguards Information Local Area Network and Electronic Safe (SLES) system is complete; a draft folder structure has been prepared and submitted to the Office of the Chief Information Officer (OCIO) for review and feasibility of application. However, due to the complexity of Documentum, which is the database underpinning SLES, a Documentum Security Specialist (DSS) is required to physically reorganize the folder structure. The OCIO has developed a task order (T.O.) to enable funds for a DSS to analyze the suggested changes under the Global Infrastructure and Development Acquisition contract. When the Documentum T.O. is awarded (estimated completion date (ECD)

September 30, 2020), the Office of Nuclear Security and Incident Response (NSIR) will work with OCIO and the DSS to implement the new folder structure in a test environment. The DSS will complete an analysis to validate best security practices for the revised folder structure and least-privilege access (ECD March 2021). Once the revised structure is validated in the test environment by SLES users, OCIO will coordinate deployment of the solution to the SLES production and failover environments. Deployment of the revised structure to these operating environments is estimated to be complete 3 to 6 months after the revised structure has been validated in a test environment.

Completion of this task is dependent upon the availability of a contractor-provided DSS.

OCIO management has approved the T.O. and forwarded it to the U.S.

Nuclear Regulatory Commission, Office of Administration to continue the contracting process. Once released, a contract award could occur by November 1, 2020. The DSS could be available as soon as January 2021.

Target Completion Date: June 30, 2021 Point of

Contact:

Bernard Stapleton Recommendation 7: Develop a structured access process that is consistent with the Safeguards Information (SGI) need-to-know requirement and least privilege principle. This should include:

  • Establishing folder owners within SLES and providing the owners the authority to approve the need-to-know authorization (as opposed to branch chiefs).
  • Conducting periodic reviews of user access to folders.
  • Developing a standard process to grant user access.

Enclosure

Completion of Recommendation 7 is dependent upon implementation of the new folder structure.

Proposed file folder structure has been forwarded to OCIO for review and feasibility of application.

Upon implementation of the new folder structure, and identification of new folder owners, NSIR and OCIO will address the three sub-bullets, in a more detailed manner that is consistent with the intent of the recommendation.

Target Completion Date: September 30, 2021 Point of

Contact:

Bernard Stapleton 2