Performance Audit of the U.S. Nuclear Regulatory Commission’s Implementation of the Federal Information Security Modernization Act of 2014 for Fiscal Year 2024 Technical Training Center: Chattanooga, Tennessee
Report Information
Recommendations
We recommend that the NRC OCIO management, in coordination with OCHCO and ADM, evaluate the NRC’s separation policies and procedures and re-engineer the related business processes and the automation used to disable separated employees’ accounts to ensure that the NRC terminates these accounts in a timely manner.
OIG Analysis: The OIG will close this recommendation after confirming that the OCIO, in coordination with OCHCO and the ADM, has evaluated the NRC’s separation policies and procedures and re-engineered the related business processes and the automation used to disable separated employees’ accounts to ensure that the NRC terminates these accounts in a timely manner.<br />
<br />
Agency Response Dated February 10, 2025: The management of the NRC OCIO, in coordination with the OCHCO and the ADM, will evaluate the NRC’s separation policies and procedures, and re-engineer the related business processes and the automation used to disable separated employees’ accounts to ensure that the NRC terminates these accounts in a timely manner. Target Completion Date: Fiscal year (FY) 2026, second quarter (Q2)<br />
OIG Analysis: The OIG will close this recommendation after confirming that the management of NRC OCIO, in coordination with OCHCO and ADM evaluate the NRC’s separation policies and procedures and re-engineer the related business processes and the automation used to disable separated employees’ accounts to ensure that the NRC terminates these accounts in a timely manner. This recommendation remains open and resolved.
We recommend that the TTC and NRC management evaluate the TTC system ATO memorandum for revision and update it to reflect the current operating environment.
OIG Analysis: The OIG reviewed the evidence and confirmed that the TTC and NRC management revised the ATO memorandum to reflect the current operating environment. Hence, this recommendation is now closed.<br />
<br />
Agency Response Dated February 10, 2025: The NRC and TTC management will evaluate the TTC system authority to operate (ATO) memorandum for revision and update it to reflect the current operating environment. Target Completion Date: FY 2026, Q1 <br />
OIG Analysis: The OIG will close this recommendation after confirming the NRC and TTC management evaluated the TTC system ATO memorandum for revision and updated it to reflect the current operating environment. This recommendation remains open and resolved.
We recommend that the NRC’s TTC management install a server cage on the second floor of the facility for the NRC Information Technology Infrastructure Patch Panel.
OIG Analysis: The OIG will close this recommendation after confirming that TTC management has installed a server cage for the NRC IT Infrastructure Patch Panel on the facility’s second floor.<br />
<br />
Agency Response Dated February 10, 2025: The NRC’s TTC management will install a server cage on the second floor of the facility for the NRC Information Technology Infrastructure Patch Panel. In addition, OCHCO will coordinate with the OCIO network team to have OCIO purchase a sever cage that is delivered and installed at the TTC facility.<br />
Target Completion Date: FY 2026, Q2 <br />
OIG Analysis: The OIG will close this recommendation after confirming the NRC’s TTC management installed a server cage on the second floor of the facility for the NRC Information Technology Infrastructure Patch Panel while the OCHCO coordinates with the OCIO network team to have OCIO purchase a sever cage that is delivered and installed at the TTC facility. This recommendation remains open and resolved.
We recommend that the NRC’s TTC management install protective covers over the emergency power shut-off switches throughout the facility.
Target Completion Date: The NRC suggests closure of this item.<br />
OIG Analysis: The OIG reviewed the evidence and confirmed that the NRC’s TTC management installed protective covers over the emergency power shut-off switches throughout the facility. Hence, this recommendation is now closed.<br />
<br />
Agency Response Dated February 10, 2025: The NRC’s TTC management will purchase and install either protective covers or extended collars over the emergency power shut-off switches throughout the facility, which will stop accidental pushing of the power shut-off switch. Target Completion Date: FY 2025, Q4 <br />
OIG Analysis: The OIG will close this recommendation after confirming that the NRC’s TTC management purchased and installed either protective covers or extended collars over the emergency power shut-off switches throughout the facility, which will prevent accidental pushing of the power shut-off switch. This recommendation remains open and resolved.
We recommend that NRC management define and implement a risk-based process for regularly reviewing users who have badged access to the NRC general access group and restricting badged access to the Regions based on business needs.
Identification Standard for Federal Employees and Contractors,” dated August 27, 2004. The use of PIV cards aids access control for NRC facilities to ensure that only authorized persons gain entry. PIV cards also indicate any access limitations to classified information and limited access, security control, or other areas. Target Completion Date: The NRC suggests closure of this recommendation.<br />
<br />
OIG Analysis: The OIG reviewed the evidence and confirmed that NRC management defined a risk-based process for regularly reviewing users who have badged access to the NRC general access group and restricting badged access to the Regions based on the business needs. However, implementation evidence of the risk-based process was not provided to address the recommendation. The OIG will close this recommendation after confirming that NRC management has implemented a risk-based process for regularly reviewing users with badged access to the NRC general<br />
access group and restricting badged access to the Regions based on business needs.<br />
<br />
Agency Response Dated February 10, 2025: The NRC’s ADM management will define the risk-based determination and mitigations for including the regions in the NRC general access group. Target Completion Date: FY 2025, Q2<br />
OIG Analysis: The OIG will close this recommendation after confirming that the NRC’s ADM management defined and implemented a risk-based process for regularly reviewing users who have badged access to the NRC general access group and define the risk-based determination and mitigations for including regions in the NRC general access group. This recommendation remains open and resolved.