본문 바로가기 주메뉴 바로가기
국회도서관 홈으로 정보검색 소장정보 검색

목차보기

Title page 1

Contents 3

Highlights 2

Letter 5

Background 7

Role of NASA's Chief Information Officer 9

Cybersecurity Risk Management 10

Overview of Selected Spacecraft Projects 14

GAO and Others Have Reported on Challenges in NASA's Cybersecurity Risk Management 16

NASA Did Not Fully Implement Cybersecurity Risk Management Program for Selected Projects 18

NASA Partially Implemented Key Activities for Preparing the Agency to Manage Cybersecurity Risks 19

NASA Partially Implemented Activities to Categorize Security Levels 21

NASA Implemented Key Activities of Control Selection but Did Not Fully Apply Proper Control Baselines for Selected Systems 24

NASA Fully Documented Implementation Information for Critical Controls in Security Plans 26

NASA Partially Implemented Assessment Activities for Selected Systems 27

NASA Partially Implemented Authorization Activities for the Selected Systems 29

NASA Partially Implemented Monitor Activities for Selected Systems 31

Conclusions 33

Recommendations for Executive Action 33

Agency Comments and Our Evaluation 34

Appendix I: Objective, Scope, and Methodology 40

Appendix II: GAO Contacts and Staff Acknowledgments 44

Tables 3

Table 1. Description of Risk Management Framework (RMF) Steps and Summary of Key Activities for Each Step 12

Table 2. Extent to Which National Aeronautics and Space Administration (NASA) and Selected Systems Implemented Risk Management Framework (RMF) Steps 18

Table 3. Extent to Which National Aeronautics and Space Administration (NASA) Implemented Key Activities in the Prepare Step of the Risk Management Framework... 20

Figures 3

Figure 1. Gateway Power and Propulsion Element 15

Figure 2. Orion Multi-Purpose Crew Vehicle 16