Sorry, you need to enable JavaScript to visit this website.
Skip to main content
Report File
Date Issued
Submitting OIG
Department of Commerce OIG
Other Participating OIGs
Department of Commerce OIG
Agencies Reviewed/Investigated
Department of Commerce
Components
U.S. Census Bureau
Report Number
OIG-23-004-I
Report Description

For our evaluation of the U.S. Census Bureau's (the Bureau's) cybersecurity posture, our objective was to determine the effectiveness of the Bureau’scybersecurity posture against a simulated real-world attack. To do this, we conducted a covertcyber red team with six goals tailored to relevant risks. We found that the red team was able to gain unauthorized and undetected access to a Bureaudomain administrator account as well as personally identifiable information of Bureauemployees; reduce the Bureau’s defensive options; use insecure programs to send fake emails; and carry out severalmalicious actions that identified 11 security weaknesses.

Report Type
Inspection / Evaluation
Agency Wide
Yes
Number of Recommendations
10
Questioned Costs
$0
Funds for Better Use
$0

Department of Commerce OIG

United States