NASA infosec again falls short of required US government standard
- Reference: 1671631208
- News link: https://www.theregister.co.uk/2022/12/21/nasa_immature_cycbersecurity/
- Source link:
The review was conducted by accounting firm RMA Associates using the Council of the Inspectors General on Integrity and Efficiency's Quality Standards for Inspection and Evaluation and using reporting metrics spelled out in the Federal Information Security Modernization Act of 2014, which define five levels of infosec maturity.
Ad Hoc
Defined
Consistently Implemented
Managed and Measurable
Optimized.
Level 4 – Managed and Measurable – is considered the benchmark for an effective infosec program. As the chart below shows, NASA did not reach that level for any of the nine capabilities measured, across the period from October 1, 2021, through September 30, 2022.
[1]
NASA's FY 2022 Infosec maturity – click to enlarge
The audit attributes NASA's poor rating to the agency just not having the tools or data to understand the disposition and state of its IT infrastructure, and to lacking the processes to frame or respond to risks.
Among the document's findings is that NASA can't identify and record all the network devices it operates. Manual processes were adopted to sort that out. The agency hasn't completed a cybersecurity workforce assessment since 2016 so is not well placed to understand if it has the skills needed to defend itself properly.
The organization has not implemented recommended data protection and privacy standards so that regime has blind spots. Multi-factor authentication is not universal. The supply chain risk management regime is not yet mature.
[2]
While the agency's incident response processes are mature, "additional controls and processes need to be designed and implemented" for it to score a Level 4 rating.
[3]
[4]
We could go on, but you get the idea: NASA infosec isn't great.
[5]NASA's latest AI will navigate the Moon using landmarks
[6]NASA's Mars InSight uploads its (probably) final image, shares it in a tweet
[7]You're getting warmer: NASA's thermal mole reveals active mantle plume on Mars
[8]Orion snaps 'selfie' with the Moon as it prepares for distant retrograde orbit
[9]Look! Up in the sky! Proof of concept for satellites beaming energy to Earth!
The agency's CIO has therefore been given a list of 17 recommended actions. NASA agrees with most and in a letter responding to the audit gave November 17, 2023, as the estimated completion date for each.
NASA acted on all the recommendations from last year's infosec audit, and appears to have sorted out all but one. But as NASA's financial year commences on October 1, that November 17 deadline could see the agency's 2022/23 audit contain more painful reading.
NASA consistently scores low ratings when its infosec is assessed: the agency also scored a Level 2 rating [10]in 2019 , was earlier this year found to be [11]unready to handle insider threats , and has identified that low-budget missions scarcely think of infosec because they try to spend every cent on science.
[12]
Which is noble but scary given that NASA operates extensive shared services and cybercrooks love landing in one ill-defended location and then spreading as far as possible.
Seeing as NASA works on lots of secret projects, the persistent immaturity at the agency clearly has the potential for very nasty consequences. ®
Get our [13]Tech Resources
[1] https://regmedia.co.uk/2022/12/21/screenshot_nasa_infosec_audit_maturity.jpg
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y6M7rrwy84iiv-NYjrWrcwAAABI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6M7rrwy84iiv-NYjrWrcwAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y6M7rrwy84iiv-NYjrWrcwAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/12/20/nasa_ai_moon_navigation/
[6] https://www.theregister.com/2022/12/20/nasa_mars_insight_farwell_tweet/
[7] https://www.theregister.com/2022/12/05/nasas_thermal_mole_reveals_active/
[8] https://www.theregister.com/2022/11/25/orion/
[9] https://www.theregister.com/2022/11/10/esa_space_based_solar_power/
[10] https://www.theregister.com/2019/03/11/nasa_infosec_office_inspector_general_fisma/
[11] https://www.theregister.com/2022/03/15/nasa_insider_threat_audit/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6M7rrwy84iiv-NYjrWrcwAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
On a scoring system of 1 - 5 about -5 if the auditors actually looked at everything that should be happening (and isn't) and all of the things that shouldn't be happening (and are).
I guess there won't be any spontaneous whooping and cheering and slapping each other on the back today then.
About that
"identified that low-budget missions scarcely think of infosec because they try to spend every cent on science"
As someone who's been there and done that, I wonder if most readers, who probably think of NASA Projects as rolling in gigabucks, understand that in "Phase E" (post commissioning activities that follow launch), most if not all NASA space science missions operate on budgets considerably leaner than during Phases A - D (formulation, development, testing, integration, &c.). After one or sometimes two Congressionally mandated Senior Review cycles, the operating budgets are almost without exception, even for scientifically highly successful missions, put on a life-support budget, that is, one that barely provides for paying the Flight Operations Team (the folks who operate the spacecraft), the science operations team(s), either at a center or the various Principal Investigators' (PIs') institutions, and any non-Deep Space Network tracking and telemetry services (DSN services are paid for at a higher level in NASA's Science Mission Directorate budgets), and so on.
At that point there's little or no funding for new science in project budgets, beyond the fairly routine analysis of sample software data to insure instrument health and safety and data integrity.
Thus, NASA's uncrewed, science flight projects don't have to make a tradeoff between science and risk management (including IT security, mandated and otherwise); it's been made for them. For at least a decade, at two year intervals in our division of SMD, as a project scientist I requested modest increases in finding to cover increased IT security requirements. Never got one. That could be explained by the fact that the Senior Review panels were made up of scientists, some of the university research scientists who'd never been in mission ops and had no clue why, in the words of one, "Why are these things so expensive?" We did our best to explain, but the requirements appeared to be so foreign to university scientists with no direct mission experience that it was like talking a foreign language.
I would hope that by now (I've been retired for four years) SMD management would take the IT sec requirements to heart and add people with experience in implementing successful IT security in mission/mission science operations to its Senior Review panels. And seriously consider what decent, thoughtful IT security
costs.
I'll just stop down off my soapbox now....
P.S. As an example of what the costs are like, I had to dedicate at least 1/3 of the time of my most senior system/net admin to security compliance (more like 2/3 in years with then required triennial reviews), while not having any funds to replace her time. And that didn't count my time, or the time of the PI teams and other sys admins — with no offsetting funds. I got the impression that my management chain didn't appreciate, however, my response that stretching the staff so thin was a significant risk for mission success and possibly even mission survival because I had to make it in the "risk assessment" section of annual budget reviews.
I do wonder how other gov agencies really rate?