Skip to main content
Report File
Date Issued
Submitting OIG
Department of Commerce OIG
Other Participating OIGs
Department of Commerce OIG
Agencies Reviewed/Investigated
Department of Commerce
Components
U.S. Census Bureau
Report Number
OIG-23-004-I
Report Description

For our evaluation of the U.S. Census Bureau's (the Bureau's) cybersecurity posture, our objective was to determine the effectiveness of the Bureau’scybersecurity posture against a simulated real-world attack. To do this, we conducted a covertcyber red team with six goals tailored to relevant risks. We found that the red team was able to gain unauthorized and undetected access to a Bureaudomain administrator account as well as personally identifiable information of Bureauemployees; reduce the Bureau’s defensive options; use insecure programs to send fake emails; and carry out severalmalicious actions that identified 11 security weaknesses.

Report Type
Inspection / Evaluation
Agency Wide
Yes
Number of Recommendations
10
Questioned Costs
$0
Funds for Better Use
$0

Department of Commerce OIG

United States