GAO Urges NASA to Strengthen Cybersecurity Risk Management

NASA must strengthen its cybersecurity risk management to mitigate growing cyber threats to its spacecraft and space systems.

Bottom line: NASA must strengthen its cybersecurity risk management to mitigate growing cyber threats to its spacecraft and space systems.

What's happening: The U.S. Government Accountability Office (GAO) has released a report urging NASA to improve its cybersecurity risk management. NASA's contractors have experienced a 13% increase in security breaches over the past two years, with 71% of those breaches caused by phishing attacks. The breaches have resulted in an estimated $10 million in losses. The GAO report notes that NASA's current cybersecurity risk management process is inadequate, with only 24% of its contractors using a risk management framework.

What to do: NASA should implement a risk management framework for all contractors, and provide regular training on cybersecurity best practices. The agency should also conduct a thorough review of its current cybersecurity risk management process to identify areas for improvement. Additionally, NASA should work with its contractors to implement more robust security measures, such as multi-factor authentication and encryption.

Source: Industrial Cyber