The Department of Energy Office of Inspector General has identified multiple deficiencies in the agency’s unclassified cybersecurity program.
In a report released Oct. 14, the Energy Department OIG documented an evaluation of whether the department adequately protected its data and information systems, as required by the Federal Information Security Modernization Act of 2014. Recognizing that the Energy Department has addressed 10 of 12 deficiencies identified in fiscal 2015 evaluations, the OIG still found that issues related to vulnerability management, system integrity of web applications, access controls and segregation of duties, as well as configuration management, continue to exist.
The Energy Department has reported more than 640 cybersecurity incidents in fiscal 2016, and contributing to the problem has been outdated software, web application holes, a lack of user access review and password strength management, and weak systems management programs.
A lack of developed and implemented policies and procedures has impacted the Energy Department’s ability to implement corrective actions. Configuration and security patch management, as well as an effective continuous monitoring program, have yet to be properly incorporated.
In addition, primary cybersecurity directives have not been updated with several years of federal requirements, causing programs and sites to fall behind guidance.
The OIG recommended, and the Energy Department management agreed, that administrators must identify, prioritize and track the progress of timely remediation actions to make policies and producers consistent with federal requirements.
The entire report can be viewed on the department’s website.




