From: FierceGovernmentIT
By Dibya Sarkar
The Nuclear Regulatory Commission needs to perform continuous monitoring of its information systems and update its system security plans, according to a recently released internal audit.
The NRC inspector general’s audit (pdf) also said that configuration management procedures aren’t being consistently implemented and the commission’s action plan to fix deficiencies needs improvement – two findings that were identified from previous evaluations mandated by the Federal Information Security Management Act.