HomeSecurityNASA identified 1,785 cybersecurity incidents in 2020!

NASA identified 1,785 cybersecurity incidents in 2020!

NASA has identified more than 6,000 cybersecurity incidents over the past four years, according to a report released by NASA’s Office of Inspector General. The space agency has a large attack surface due to the presence of nearly 3,000 websites and more than 42,000 publicly accessible data sets. The audit , conducted by NASA’s inspector general, revealed that the agency has more than 4,400 applications, over 15,000 mobile devices, about 13,000 software licenses, nearly 50,000 computers and 39,000 terabytes of data.

Specifically, the report published by the NASA Inspector General’s Office states the following: “Cybersecurity incidents at NASA can impact national security, intellectual property, and individuals whose data could be lost or compromised. In cybersecurity, an attack vector is a path or means by which an attacker gains unauthorized access to a computer or network – for example, through email, websites, or external/removable media. Once a malicious actor gains access, they can exploit system vulnerabilities, gain access to sensitive data, install various types of malware, and conduct cyberattacks.”

Read also: NASA detects mysterious radio signals from deep space

NASA - cybersecurity incidents
NASA identified 1,785 cybersecurity incidents in 2020!

Cyberattacks against an organization's systems are not uncommon. Malicious actors could attempt to steal critical information with sophisticated operations, and for this reason, it is important for the organization to detect and mitigate them.

NASA identified 1,785 cybersecurity incidents in 2020, including brute-force attacks, email-related attacks, impersonation attacks, improper use of systems, equipment loss/theft, and cyberattacks.

See also: NASA: How much has “Clyde's Spot” on Jupiter changed in a year?

In 2020, most of the incidents discovered were misuse issues, followed by equipment loss/theft and cyberattacks.

"The cyber threat to NASA's computer networks from Internet-based intrusions is expanding in scope and frequency, and the success of these intrusions demonstrates the increasingly complex nature of the cybersecurity challenges facing the Agency. Simply put, to date, the Agency's security processes are too often ineffective in staying ahead of the dynamic threat landscape," the report notes.

NASA - cybersecurity incidents
NASA identified 1,785 cybersecurity incidents in 2020!

Proposal: 2021: 2.9 million DDoS attacks in the first three months

Key findings in the report include:
• NASA did not have an agency-wide risk management framework for information security or an information security architecture.
• There are weaknesses in NASA’s internal controls and risk management practices.
• The Security Operations Center lacks visibility into information security management, incident detection, and recovery across NASA’s entire IT infrastructure.
• NASA’s cybersecurity program remained ineffective at level 2 out of 5, meaning the agency has not consistently implemented policies and procedures that define its security program.
• NASA does not adequately control the business rules necessary to grant access to manage mobile devices on its network.

Information source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS