G-01-011
Assessment of Information Technology Security
Vulnerabilities at a NASA Installation

(August 13, 2002)


EXECUTIVE SUMMARY

The Office of Inspector General performed an assessment of information technology security (ITS) vulnerabilities at a NASA installation to determine the security and functionality of a Center's network infrastructure, to assess the presence of suspicious traffic patterns on the installation's computer network, and to determine the information technology staff's awareness of and response to such network traffic. We also reviewed the procedures used by the installation's staff to find and eliminate vulnerabilities in their own systems. We made 18 recommendations for specific improvements. NASA management concurred with 16 recommendations, partially concurred with 1 recommendation, and conditionally concurred with the remaining recommendation.

This report contains information that may not be releasable to the general public.


Rev. September 11, 2002