GAO Finds NASA Networks Vulnerable to Attack

執筆者
Roy Mark
Roy Mark
Published: Oct 19, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

According to a report from the Government Accountability Office released Oct. 15, “NASA [does] not consistently implement effective controls to prevent, limit and detect unauthorized access to its networks and systems.” While the report found that “NASA has made important progress in implementing security controls and aspects of its information security program,” it said NASA’s networks remain vulnerable.
“A key reason for these weaknesses is that NASA has not yet fully implemented key activities of its information security program to ensure that controls are appropriately designed and operating effectively,” the GAO wrote, (PDF) and pointed out, “Many of these systems and networks are interconnected through the Internet, and may be targeted by evolving and growing cyber-threats from a variety of sources.”
The GAO also said, “During fiscal years 2007 and 2008, NASA reported 1,120 security incidents that have resulted in the installation of malicious software on its systems and unauthorized access to sensitive information. To address these incidents, NASA established a Security Operations Center in 2008 to enhance prevention and provide early detection of security incidents and coordinate agency-level information related to its security posture. Nevertheless, the control vulnerabilities and program shortfalls, which GAO identified, collectively increase the risk of unauthorized access to NASA’s sensitive information, as well as inadvertent or deliberate disruption of its system operations and services.”
“GAO’s findings reminds us that much remains to be done to ensure the security of all of our federal agencies’ IT networks,” Rep. Bart Gordon, chairman of the House Science and Technology Committee, said in a statement. “However, regulation and legislation alone will not suffice. Agencies and departments must follow through with corrective actions to mitigate identified vulnerabilities. GAO has performed an invaluable service to NASA by identifying weaknesses and recommending needed improvements.”
NASA generally concurred with GAO’s recommendations that “the NASA administrator take steps to mitigate control vulnerabilities and fully implement a comprehensive information security program.”

“This GAO audit provides the NASA administrator and his team with important information [with which] to strengthen its cyber-security controls and processes. Correcting the vulnerabilities identified by GAO will take determination, time and focused leadership. We will continue to monitor NASA’s performance in this important area,” said Rep. Gabrielle Giffords, chair of the Space and Aeronautics Subcommittee.

Roy Mark

Roy Mark

Content Writer

Roy Mark is a Datamation contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。