Skip to main content
Report File
Title Full
BIS Needs to Improve Its Incident Response Capabilities to Handle Sophisticated Cyberattacks
Date Issued
Submitting OIG
Department of Commerce OIG
Agencies Reviewed/Investigated
Department of Commerce
Components
Bureau of Industry and Security
Report Number
OIG-25-022-I
Report Description

For our evaluation of the Bureau of Industry and Security’s (BIS's) detection of and response to cyber incidents, our objective was to assess the adequacy of actions taken by BIS when detecting and responding to cyber incidents in accordance with federal and departmental requirements. We found that (1) BIS lacked effective detection and response capabilities to handle our simulated malicious activities; (2) BIS misconfigured critical security controls for its export control networks; and (3) BIS mishandled classified and other privileged credentials.
 

Report Type
Inspection / Evaluation
Agency Wide
Yes
Number of Recommendations
13
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Department of Commerce OIG

United States