ML20300A326

From kanterella
Jump to navigation Jump to search
OIG-13-A-16-Status of Recommendations: Audit of Nrc'S Safeguards Information Local Area Network and Electronic Safe Dated October 26, 2020
ML20300A326
Person / Time
Issue date: 10/26/2020
From: Baker B
NRC/OIG
To: Margaret Doane
NRC/EDO
References
OIG-13-A-16
Download: ML20300A326 (4)


Text

UNITED STATES NUCLEAR REGULATORY COMMISSION WASHINGTON, D.C. 20555-0001 OFFICE OF THE INSPECTOR GENERAL October 26, 2020 MEMORANDUM TO: Margaret M. Doane Executive Director for Operations FROM: Dr. Brett M. Baker /RA/

Assistant Inspector General for Audits

SUBJECT:

STATUS OF RECOMMENDATIONS: AUDIT OF NRCS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE (OIG-13-A-16)

REFERENCE:

DIRECTOR, OFFICE OF NUCLEAR SECURITY AND INCIDENT RESPONSE, MEMORANDUM DATED SEPTEMBER 25, 2020 Attached is the Office of the Inspector Generals (OIG) analysis and status of recommendations as discussed in the agencys response dated September 25, 2020.

Based on this response, recommendations 3 and 7 remain in open and resolved status.

Recommendations 1, 2, 4, 5 and 6 have been previously closed. Please provide an updated status of recommendations 3 and 7 by March 1, 2021.

The OIG issued this report in final on April 1, 2013, and by memorandum dated June 19, 2013, the agency acknowledged agreement with the OIG on these recommendations.

Office of Management and Budget Circular No. A-123 (M-16-17), Section C, dated July 15, 2016, states Management has a responsibility to complete action, in a timely manner, on audit recommendations on which agreement with the OIG has been reached. Audit recommendations 3 and 7 have been in resolved status for more than 6 years.

If you have questions or concerns, please call me at (301) 415-5915, or Terri Cooper, Team Leader, at (301) 415-5965.

Attachment:

As stated cc: J. Jolicoeur, OEDO C. Haney, OEDO S. Miotla, OEDO C. Cook, OEDO RidsEdoMailCenter Resource EDO_ACS Distribution OIG Liaison Resource

Audit Report AUDIT OF NRCS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE OIG-13-A-16 Status of Recommendations Recommendation 3: Evaluate and update the current folder structure to meet user needs.

Agency Response Dated September 25, 2020: The modernization of the Safeguards Information Local Area Network and Electronic Safe (SLES) system is complete; a draft folder structure has been prepared and submitted to the Office of the Chief Information Officer (OCIO) for review and feasibility of application. However, due to the complexity of Documentum, which is the database underpinning SLES, a Documentum Security Specialist (DSS) is required to physically reorganize the folder structure. The OCIO has developed a task order (T.O.) to enable funds for a DSS to analyze the suggested changes under the Global Infrastructure and Development Acquisition contract. When the Documentum T.O. is awarded (estimated completion date (ECD) September 30, 2020), the Office of Nuclear Security and Incident Response (NSIR) will work with OCIO and the DSS to implement the new folder structure in a test environment. The DSS will complete an analysis to validate best security practices for the revised folder structure and least-privilege access (ECD March 2021). Once the revised structure is validated in the test environment by SLES users, OCIO will coordinate deployment of the solution to the SLES production and failover environments. Deployment of the revised structure to these operating environments is estimated to be complete 3 to 6 months after the revised structure has been validated in a test environment.

Completion of this task is dependent upon the availability of a contractor-provided DSS.

1

Audit Report AUDIT OF NRCS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE OIG-13-A-16 Status of Recommendations Recommendation 3 (cont.):

OCIO management has approved the T.O. and forwarded it to the U.S. Nuclear Regulatory Commission, Office of Administration to continue the contracting process. Once released, a contract award could occur by November 1, 2020.

The DSS could be available as soon as January 2021.

Target Completion Date: June 30, 2021 OIG Analysis: The proposed action meets the intent of the recommendation.

This recommendation will be closed when the OIG is provided with documentation verifying that the current folder structure has been evaluated and updated to meet user needs.

Status: Open: Resolved.

2

Audit Report AUDIT OF NRCS SAFEGUARDS INFORMATION LOCAL AREA NETWORK AND ELECTRONIC SAFE OIG-13-A-16 Status of Recommendations Recommendation 7: Develop a structured access process that is consistent with the Safeguards Information (SGI) need-to-know requirement and least privilege principle. This should include:

  • Establishing folder owners within SLES and providing the owners the authority to approve the need-to-know authorization (as opposed to branch chiefs).
  • Conducting periodic reviews of user access to folders.
  • Developing a standard process to grant user access.

Agency Response Dated September 25, 2020: Completion of Recommendation 7 is dependent upon implementation of the new folder structure.

Proposed file folder structure has been forwarded to OCIO for review and feasibility of application.

Upon implementation of the new folder structure, and identification of new folder owners, NSIR and OCIO will address the three sub-bullets, in a more detailed manner that is consistent with the intent of the recommendation.

Target Completion Date: September 30, 2021 OIG Analysis: The proposed action meets the intent of the recommendation.

This recommendation will be closed when the OIG evaluates the structured access process and determines (1) it is consistent with the SGI need-to-know requirement and least privilege principle, and (2) it addresses the three sub-bullets noted in the recommendation.

Status: Open: Resolved.

3