NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds

NASA's cybersecurity framework for spacecraft development is inconsistent and must be improved, according to a 34-page review by the U.S. Government Accountability Office.
The GAO report highlighted the need for mandatory cybersecurity updates throughout the space agency's $83 billion space development project portfolio.
The U.S. government agency urged NASA to develop a plan with timeframes for policy updates.
The review focused on three projects managed out of three different research centers: the Gateway Power and Propulsion Element, the Orion Multipurpose Crew Vehicle, and the Spectro-Photometer for the History of the Universe, Epoch of Reionization and Ices Explorer.
While contracts for reviewed projects include cybersecurity requirements, the space system protection standard, NASA-STD-1006, approved in October 2019, provides limited guidance for cybersecurity.
Warner warned that this could lead to severe consequences, such as unauthorized access to sensitive data or even the compromise of mission-critical systems, making it easier for attackers to breach systems before they reach space.
The GAO cautioned that the implementation timing remains uncertain without a clear plan, posing risks of inconsistent cybersecurity controls and inadequate defense against cyber threats.
NASA's space projects involve significant investments and operate in a high-threat cyber environment.
Addressing these vulnerabilities is crucial for mission protection and success.
Narayana Pappu, CEO at Zendata, pointed out that in recent years, nation-states-and insider threats- have targeted NASA and its affiliated organizations to steal employee information, mission data, and other sensitive information.
In his response to the report, NASA CIO Jeffrey Seaton outlined the challenges in developing one set of essential controls applicable to all types of mission spacecraft due to their diversity.
Pappu suggested following a microservices or modular architecture of controls, which would allow customizability for each mission without introducing duplication in measures, controls, and approaches.
It's not only advisable but necessary to treat cybersecurity as an essential and non-negotiable aspect of operational strategy, said Warner.
This requires implementing well-thought-out governance policies and standards that incorporate the unique risk of these systems across platforms and interoperable systems to protect controls, sensitive information, supply chain security, economic loss prevention, customer trust, and resiliency against evolving threats.
Autonomous threat and anomaly and drift detection are among the ways artificial intelligence and machine learning could help reduce NASA's cyber risks.
AI could significantly enhance cybersecurity by rapidly processing vast data sets to detect anomalies and threats more efficiently than human operators.
These technologies are force multipliers in security strategies to evolving threats, ensuring defenses are updated based on fresh data.


This Cyber News was published on securityboulevard.com. Publication date: Thu, 09 May 2024 23:13:05 +0000


Cyber News related to NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds

NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds - NASA's cybersecurity framework for spacecraft development is inconsistent and must be improved, according to a 34-page review by the U.S. Government Accountability Office. The GAO report highlighted the need for mandatory cybersecurity updates ...
1 month ago Securityboulevard.com
US Agencies Failing to Oversee Ransomware Protections - The White House's goal of bolstering the cyber resilience of critical infrastructure is being threatened by US federal agencies' lack of oversight of ransomware protections, according to a new Government Accountability Office report. The GAO noted ...
5 months ago Infosecurity-magazine.com
Fortinet Contributes to World Economic Forum's Strategic Cybersecurity Talent Framework - Shining a light on the cybersecurity workforce challenge, the World Economic Forum recently published its Strategic Cybersecurity Talent Framework, which is intended to serve as a reference for public and private decision-makers concerned by the ...
1 month ago Feeds.fortinet.com
GAO Urges Action to Address Critical Cybersecurity Challenges Facing U.S. - A report from the Government Accountability Office highlighted an urgent need to address critical cybersecurity challenges facing the nation. The report also highlighted the escalating frequency and sophistication of cybersecurity incidents, which ...
1 week ago Securityboulevard.com
SpaceX Launched Military Satellites Designed to Track Hypersonic Missiles - Two prototype satellites for the Missile Defense Agency and four missile-tracking satellites for the US Space Force rode a SpaceX Falcon 9 rocket into orbit Wednesday from Florida's Space Coast. These satellites are part of a new generation of ...
4 months ago Wired.com
GAO: Federal Agencies Yet to Fully Implement Incident Response Capabilities - US federal agencies have made progress in implementing mature incident response plans, but many are still steps away from fully achieving this goal, a new report from the Government Accountability Office shows. According to GAO's report, out of 23 ...
6 months ago Securityweek.com
Majority of Gao's Cybersecurity Recommendations Not Implemented by Federal Agencies - The Government Accountability Office has recently reported that federal agencies have been slow to implement a majority of the recommendations it made for improving the cybersecurity of federal agencies. Despite the implementation progress at some ...
1 year ago Securityweek.com
NASA hasn't implemented Microsoft 365 Data Loss Prevention The Register - NASA's Office of Inspector General has run its eye over the aerospace agency's privacy regime and found plenty to like - but improvements are needed. That's a welcome assessment, given NASA employs around 16,000 people and - as with all government ...
6 months ago Go.theregister.com
CISA's OT Attack Response Team Understaffed: GAO - The US Government Accountability Office has conducted a study focusing on the operational technology cybersecurity products and services offered by CISA and found that some of the security agency's teams are understaffed. OT environments continue to ...
3 months ago Securityweek.com
Understanding the New SEC Rules for Disclosing Cybersecurity Incidents - The U.S. Securities and Exchange Commission recently announced its new rules for public companies regarding cybersecurity risk management, strategy, governance, and incident exposure. "Currently, many public companies provide cybersecurity disclosure ...
7 months ago Feeds.dzone.com
Student Cybersecurity Clubs: Fostering Online Safety - Student cybersecurity clubs are playing a crucial role in promoting online safety among students. Student cybersecurity clubs play a vital role in this regard, as they provide a platform for students to learn about the latest threats, share best ...
6 months ago Securityzap.com
Key cybersecurity skills gap statistics you should be aware of - As the sophistication and frequency of cyber threats continue to escalate, the demand for skilled cybersecurity professionals has never been bigger. The skills gap is not merely a statistical discrepancy; it represents a substantial vulnerability in ...
6 months ago Helpnetsecurity.com
The U.S. Needs a Better AI Plan - To supercharge its technological capabilities, the US government is setting sail on a transformative AI journey. A recent Government Accountability Office report reveals a critical lack of policies and standards, leaving the nation's security ...
6 months ago Securityboulevard.com
Growing threats outpace cybersecurity workforce - The cybersecurity skills shortage threatens the well-being and even survival of numerous businesses as cybersecurity threats grow more numerous, sophisticated, and dangerous to the point that cybersecurity groups have vowed not to pay ransom demands. ...
5 months ago Legal.thomsonreuters.com
Cybersecurity Curriculum Development Tips for Schools - With the constant threat of cyber attacks, schools must prioritize the development of a robust cybersecurity curriculum to equip students with the necessary skills and knowledge. This article provides valuable insights and tips for schools aiming to ...
6 months ago Securityzap.com
The Importance of Cybersecurity Education in Schools - Cybersecurity education equips students with the knowledge and skills needed to protect themselves and others from cyber threats. Cybersecurity education can teach students about the impact of cyberbullying, how to prevent it, and how to respond ...
6 months ago Securityzap.com
Cybersecurity Training for Business Leaders - This article explores the significance of cybersecurity training for business leaders and its crucial role in establishing a secure and resilient business environment. By examining the key components of effective training programs and the ...
5 months ago Securityzap.com
US Federal Agencies Miss Deadline for Incident Response Requirements - Although US federal agencies have made progress in preparing for and responding to cyber threats, too many have failed to meet the deadline to implement incident response capabilities required by law, according to the US Government Accountability ...
6 months ago Infosecurity-magazine.com
How to become a cybersecurity architect - Cybersecurity architects implement and maintain a comprehensive cybersecurity framework to protect their company's digital assets. The cybersecurity architect position is a fundamental role that all organizations need, said Lester Nichols, director ...
1 week ago Techtarget.com
What the cybersecurity workforce can expect in 2024 - For cybersecurity professionals, 2023 was a mixed bag of opportunities and concerns. The good news is that the number of people in cybersecurity jobs has reached its highest number ever: 5.5 million, according to the 2023 ISC2 Global Workforce Study. ...
6 months ago Securityintelligence.com
Report Surfaces Extent of SaaS Application Insecurity - An analysis of how 493 organizations are employing software-as-a-service applications published today by Wing Security finds nearly all experienced a security incident involving at least one application. A full 81% reported security incidents ...
4 months ago Securityboulevard.com
Beyond Mere Compliance - Too often we continue to see executives whose approach to cybersecurity - compliance rather than protection - is strikingly similar to that of the ill-advised business owner whose minimal fire protection is designed only to meet the building code. ...
6 months ago Cyberdefensemagazine.com
Digital Learning Tools for Cybersecurity Education - In the field of cybersecurity education, digital learning tools have become indispensable. This article explores various digital learning tools tailored specifically to cybersecurity education. These digital learning tools play a crucial role in ...
6 months ago Securityzap.com
Cyber Employment 2024: Sky-High Expectations Fail Businesses & Job Seekers - Well-publicized estimates of a massive shortfall in cybersecurity workers have resulted in high expectations among job seekers in the field, but the reality often falls flat, because of a mismatch between companies' requirements and job seekers' ...
6 months ago Darkreading.com
Gamification in Cybersecurity Education - Gamification has become increasingly prevalent in numerous domains, including cybersecurity education. Gamification presents a promising approach to meet this challenge, making cybersecurity education both effective and enjoyable. One way to ...
6 months ago Securityzap.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)