The U.S. Environmental Protection Agency Office of Inspector General identified vulnerabilities related to the EPA's network structure, specifically, the Microsoft Office 365, or O365, environment in which little or no network segmentation exists between the EPA proper and the OIG. The EPA's 0365 administrators can modify OIG account settings as well as access and view sensitive data within the O365 environment without the knowledge or input of the OIG, including email and other data of senior OIG employees and sensitive shared email inboxes. Additionally, poor user access controls and limited event logging degrade the OIG's ability to determine details about user activity within the O365 environment.
Wednesday, March 15, 2023
Agency Reviewed / Investigated:
Type of Report:
Funds for Better Use:
Report updated under NDAA 5274: