Computer hackers continue to target the Department of Energy complex, and DOE’s Inspector General has concluded that the Department isn’t doing everything it can to protect its various networks and computer systems. In a report released yesterday, the IG noted that it found some improvements during its annual review of the computer security practices across the Department and the National Nuclear Security Administration. However, the IG also continued to turn up an increase in weaknesses across the complex, noting that four successful cyber attacks occurred during Fiscal Year 2011 at DOE sites. The IG said it conducted testing at 25 locations across the Department, including its headquarters facilities, and turned up 32 new weaknesses and found that 24 weaknesses remained from a FY2010 review. The IG did not disclose details about the weaknesses or reveal where they occurred, but suggested that the recurring issues present a serious challenge for a Department that faces cyber threats on a daily basis. “Without improvements to its unclassified cyber security program, such as consistent risk management practices and adopting processes to ensure security controls are appropriately developed, implemented and monitored, there is an increased risk of compromise and/or loss, modification, and non-availability of the Department’s systems and information,” the IG said.
In a response to the report, Ken Powers, the NNSA’s Associate Administrator for Management and Budget, said the IG’s findings don’t accurately characterize the security posture at its sites. “All NNSA systems are protected by distinctive, layered, and defense-in-depth approaches,” Powers wrote in a letter included with the IG’s report. “The finding of a particular technical misconfiguration, alone, does not necessarily translate to substantive risk to NNSA’s systems.”
Jobs