Open Recommendations
Recommendation Number | Significant Recommendation | Recommended Questioned Costs | Recommended Funds for Better Use | Additional Details | |
---|---|---|---|---|---|
1 | No | $0 | $0 | ||
Ensure NARANet user accounts are reviewed and disabled in accordance with NARA’s information technology policies and requirements. | |||||
2 | No | $0 | $0 | ||
Coordinate with other departments as necessary, to implement an authoritative data source which provides the current status of NARA contractors and volunteers at the enterprise level. | |||||
3 | No | $0 | $0 | ||
Enforce mandatory Personal Identity Verification (PIV) card authentication for all NARANet users, in accordance with OMB requirements. | |||||
4 | No | $0 | $0 | ||
Continue and complete efforts to require PIV authentication for all privileged users, servers, and applications, through NARA’s identity and access management project and other efforts. | |||||
5 | No | $0 | $0 | ||
Ensure a comprehensive identity, credential, and access management (ICAM) policy or strategy, which includes the establishment of related standard operating procedures, identification of stakeholders, communicating relevant goals, task assignments, and measure and reporting progress is developed and implemented. | |||||
6 | No | $0 | $0 | ||
Document and implement a process to track and remediate persistent configuration vulnerabilities, or document acceptance of the associated risks. | |||||
7 | No | $0 | $0 | ||
Implement remediation efforts to address security deficiencies on affected systems identified, to include enhancing its patch and vulnerability management program as appropriate, or document acceptance of the associated risks. | |||||
8 | No | $0 | $0 | ||
Fully complete the migration of applications to vendor supported operating systems. | |||||
9 | No | $0 | $0 | ||
Ensure the Information System Security Officers are reviewing system configuration compliance scans monthly as required within NARA’s Configuration Compliance Standard Operating Procedure. | |||||
10 | No | $0 | $0 | ||
Enhance current procedures to ensure that new NARA users who do not complete their initial security awareness training, have their accounts automatically disabled in accordance with timeframes promulgated within the Privacy and Awareness Handbook. |