News: 1647324913

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NASA in 'serious jeopardy' due to big black hole in security

(2022/03/15)


An audit of NASA's infosec preparedness against insider threats has warned it faces "serious jeopardy to operations" due to lack of protection for Unclassified information.

A Monday [1]report [PDF] found that NASA has done well, as required, in its efforts to defend and prevent insider threats to Classified information – stuff that NASA [2]defines as "Official information regarding the national security that has been designated Confidential, Secret, or Top Secret."

The report found the agency has deployed defenses including user activity monitoring, adopted mandatory agency-wide insider threat training, and "created an insider threat reference website that assists employees and contractors with identifying threats, their risks, and follow-up information." Procurement controls are being strengthened in ways that address risks of foreign influence.

[3]

But while the report is satisfied NASA has done well to protect its Classified info, it notes that "the vast majority" of NASA tech is not Classified, including plenty of "high-value assets and critical infrastructure." Among those assets are "sensitive and valuable information such as scientific, engineering, or research data; human resources files; or procurement sensitive information." Because that infrastructure is not classified, it's not covered by the insider threat program.

[4]

[5]

And that's a worry, because in 2021 NASA's auditor found "incidents of improper use of NASA IT systems had increased from 249 in 2017 to 1,103 in 2020 – a 343 per cent growth; the most prevalent error was failing to protect Sensitive but Unclassified (SBU) information."

Among the booboos the auditors found were "sending unencrypted email containing SBU data, Personally Identifiable Information, or International Traffic in Arms Regulations data, any of which could expose the Agency to a risk that can affect national security, incur a loss of intellectual property, or compromise sensitive employee and contractor data."

[6]

The report also mentions that in the last three years, NASA users have made over 12,000 requests for elevated privileges – just the sort of thing that could lead to more information reaching the wrong eyes.

[7]NASA to launch 247 petabytes of data into AWS – but forgot about eye-watering cloudy egress costs before lift-off

[8]NASA awaits approval of $24bn 2022 budget

[9]Chinese rocket junk may have just smashed into Moon

[10]Watchdog rejects complaint over NASA IT contract

Further complicating matters is that NASA's infosec responsibilities are spread around different teams. The Office of Protective Services (OPS) is responsible for protecting against insider threats to Classified info, but lacks resources to cover Unclassified systems. The Office of the Chief Information Officer (OCIO) has responsibility for "data loss prevention and behavioral analysis, but has no defined responsibility to monitor unclassified systems for indicators of compromise specifically related to insider threats."

Other US government agencies, the report notes, have already extended their insider threat defenses to cover Unclassified info. The auditors suggest it is time for NASA to do likewise and to undertake two specific reforms:

Establish a cross-discipline team to conduct an insider threat risk assessment to evaluate NASA's unclassified systems and determine if the corresponding risk warrants expansion of the insider threat program to include these systems.

Improve cross-discipline communication by establishing a working group that includes OPS, OCIO, procurement, human resources officials, and any other relevant agency offices to collaborate on wide-ranging insider threat-related issues for both classified and unclassified systems.

NASA management has agreed with the report's findings, agreed to implement the recommendations, and set December 1, 2023, as the deadline for delivery.

Which suggests the changes outlined above might not be rocket science. ®

Get our [11]Tech Resources



[1] https://oig.nasa.gov/docs/IG-22-009.pdf

[2] https://www.hq.nasa.gov/security/infoclass/idclassif.htm

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjBx2d0I@uXGsi0S0RbAYwAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjBx2d0I@uXGsi0S0RbAYwAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjBx2d0I@uXGsi0S0RbAYwAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjBx2d0I@uXGsi0S0RbAYwAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2020/03/19/nasa_cloud_data_migration_mess/

[8] https://www.theregister.com/2022/03/10/nasa_2022_buget/

[9] https://www.theregister.com/2022/03/04/china_moon_impact/

[10] https://www.theregister.com/2022/02/24/gao_nasa_leidos/

[11] https://whitepapers.theregister.com/



Nothing new there...

corestore

About 15 years ago I bought an SGI Onyx system (big high-end workstation) from a guy, who had bought it at public auction but never got it going.

I had to incant some very obscure runes to nuke the PROM password, get it to boot single-user, and hack root, but I did it. And what did I find?

The machine had come out of GSFC - Goddard Space Flight Centre. NASA. And they hadn't wiped it! It has previously been a web server - sprecher.gsfc.nasa.gov - came with a bunch of NASA stuff installed: webservers, internal NASA tools - Earth Observing System Data Gateway etc - user credentials, personnel stuff, Oracle databases - fascinating stuff!

Pic of the thing: https://pbs.twimg.com/media/DuvjScpU8AAhxvk.jpg

Interesting

Terry 6

The psychologist in me is wondering whether there's a culture, at that level, of thinking of themselves as Scientists, not Spooks. So no one is interested in/worried about the security stuff.

Re: Interesting

hoola

Scientists and researchers generally are not that concerned with security unless it relates to regulatory compliance with funding or data that they are using.

It is seen as an unnecessary overhead that stops then doing what they need to do. The same thought process also applies to such things as ensuring the PCs they are using are up to date (not just Windows, Linux has had it's share or holes) and protected.

The one time I had to deal with an encryption ransomware incident, it came in through a research PC in a lab. We disabled the switch port to try and contain things so then they went ape because they could not access the data and demanded that it be fixed NOW. That both PC and server data the had access to were compromised due to user stupidity passed them by.

Never under estimate had incompetent and stupid how really clever people in a different field can be when using IT.

Re: Interesting

Paul Crawford

The "PC up to date" issue is often a case in science due to other factors, such as not wanting to (or being able to) interrupt running software, or some old but essential program that can't run properly with some update or newer OS.

That is OK provided said machines are sufficiently isolated, but usually there is no discussion between IT department and scientists on that sort of dirty detail, or you get a conflict problem when some IT manager simply won't accommodate it so it gets hidden so they can actually get on with important work.

The side effects are just as you describe...

F u cn rd ths u cnt spl wrth a dm!