Common Vulnerabilities

The following are the most common vulnerabilities found during DSS assessments.

  • Not auditing and reviewing audit results for classified systems
  • Persons without proper eligibility accessing classified
  • Processing on an unaccredited system
  • Unreported FCL change conditions (foreign buyout, etc)
  • Uncleared Key Management Personnel
  • Personnel clearance re-investigations out-of-scope
  • Lack of process to detect and deter viruses / malicious code
  • Not reporting classified compromises
  • Classified IS configuration and connectivity management
  • Poor safe combination security