Print 2 comment(s) - last by wwwcd.. on Jul 31 at 4:34 AM

A NASA audit found that stock vendor contracts and lack of oversight are exposing it to potential security threats

An audit of NASA's public cloud computing contracts recently found that the space agency isn't meeting federal IT security requirements. 

The NASA Office of Inspector General (OIG) recently audited the space agency's public cloud computing system and found that a combination of stock vendor contracts and lack of oversight are exposing it to potential security threats.

The OIG reviewed five NASA contracts in the audit, where four relied on the cloud providers' standard contracts and one was made by NASA. All five failed to meet "federal privacy, discovery, and data retention and destruction requirements" according to ZDNet

In addition, the OIG found that a third-party cloud service that sends over 100 NASA internal and public websites had been operating without security plans or written authorization for more than two years. 

To top it off, NASA's Office of the CIO wasn't clued in on all of the cloud services that different NASA organizations had used, and in many instances, the movement to public clouds was not planned through "a central office."

The OIG concluded that NASA's public cloud contracts are at increased risk of vulnerabilities and need to be addressed through a better-coordinated cloud strategy. 

On the upside, moving to the cloud does save NASA about $1 million each year. 

In 2012, NASA stopped using the Nebula private cloud and moved its data to Azure and Amazon Web Services. The audit, which only looked at a small portion of NASA's computer infrastructure, said up to 75 percent of new IT programs are expected to start in the cloud within five years, and almost all of NASA's public data could be moved to the cloud as well. As much as 40 percent of its legacy systems could go to the cloud, too. 

Source: ZDNet

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

Cloud computing
By djdjohnson on 7/30/2013 3:30:07 PM , Rating: 3
When you say "NASA" and "cloud" in the same sentence, it can take on an entirely different meaning than "cloud" does with other companies... they are the National Aeronautics and Space Administration, after all.

RE: Cloud computing
By wwwcd on 7/31/2013 4:34:49 AM , Rating: 2
they are the National Aeronautics and Space Administration , after all.

"It seems as though my state-funded math degree has failed me. Let the lashings commence." -- DailyTech Editor-in-Chief Kristopher Kubicki

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki