The U.S. Environmental Protection Agency Office of Inspector General identified vulnerabilities related to the EPA's network structure, specifically, the Microsoft Office 365, or O365, environment in which little or no network segmentation exists between the EPA proper and the OIG. The EPA's 0365 administrators can modify OIG account settings as well as access and view sensitive data within the O365 environment without the knowledge or input of the OIG, including email and other data of senior OIG employees and sensitive shared email inboxes. Additionally, poor user access controls and limited event logging degrade the OIG's ability to determine details about user activity within the O365 environment.
Report File
Date Issued
Submitting OIG
Environmental Protection Agency OIG
Other Participating OIGs
Environmental Protection Agency OIG
Agencies Reviewed/Investigated
Environmental Protection Agency
Report Description
Report Type
Other
Agency Wide
Yes
Questioned Costs
$0
Funds for Better Use
$0