Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

DOE OIG report flags systemic shortcomings across NIST cybersecurity framework functions

(Department of Energy)

By Anna Ribeiro

A new report from the Department of Energy’s Office of Inspector General (OIG) reveals that while the Department, including the National Nuclear Security Administration, has acted on some previously identified cybersecurity weaknesses, significant gaps remain. Of 63 recommendations from prior audits and evaluations, the OIG report identified that only 19 were closed, leaving 44 still open. In addition, the OIG issued 79 new recommendations during the fiscal year covering various aspects of DOE’s unclassified cybersecurity program.

“The weaknesses identified occurred for a variety of reasons. For instance, findings at some Department sites had occurred due to vulnerability management processes that were not fully effective in identifying, addressing, and/or remediating vulnerabilities,” according to a report titled ‘The Department of Energy’s Unclassified Cybersecurity Program – 2024,’ which the OIG made public this week. “We also found that several sites had not fully developed and/or maintained policies and procedures to help facilitate the design and implementation of security controls.” 

It added that without improvements to address the weaknesses identified in our report, the Department may be unable to adequately protect its information systems and data from compromise, loss, or modification.

Read more at Industrial Cyber

Click to listen highlighted text!