Inspector General audit finds problems with NASA's cloud computing efforts

July 30, 2013 by Bob Yirka weblog

( —The Office of the Inspector General, led by Paul Martin, has published the results of an audit of NASA's cloud computing efforts and has found many such efforts lack proper security. The report also notes that many cloud efforts run by the agency were operating without the knowledge of its own Office of the Chief Information Officer.

Over the past several years, the Office of Management and Budget, which controls the purse strings of federal entities, has demanded that governmental agencies, such as NASA, begin transferring some or all of its and storage activities to the cloud. The idea is that doing so will save the government a lot of money. In following the directive, however, it appears that managers at NASA have failed to ensure that cloud operations are undertaken with the knowledge and approval of the agencies top information officer. Worse, it appears that many of the cloud initiatives were undertaken without due consideration given to necessary security precautions that must be put in place when applications and data become accessible across the Internet.

More specifically, the auditors found over a 100 NASA websites—both internal and external—had never been tested for security integrity. Incredibly, many of those same websites were found to have no security controls in place at all.

Government agencies have two main options when moving applications to the cloud—set up facilities on their own or contract out. NASA, like most other federal agencies has chosen the latter. Unfortunately, the auditors found that officials at the agency in many cases failed to include security issues when writing contracts, which of course resulted in them not being put in place.

Overall, the IG's report has found that weaknesses in cloud applications have impeded the agency from reaping the benefits of —namely reducing costs. And worse, the approach taken thus far has put NASA data at risk. Out of five contracts reviewed, the auditors found "none came close" to operating with industry standard security precautions.

The auditors recommend that NASA set up an office dedicated to cloud computing and the that must be put in place when such initiatives are undertaken.

Explore further: NASA's Nebula Cloud Computing Technology To Play Key Role In New Open Source Initiative

Related Stories

Head for the clouds, feet firmly on the ground

March 5, 2012

Computer engineers in the US writing in the International Journal of Communication Networks and Distributed Systems have reviewed the research literature to get a clear picture of cloud computing, its adoption, use and the ...

Deutsche Boerse to launch cloud computing exchange

July 2, 2013

Deutsche Boerse, operator of the Frankfurt stock exchange, unveiled Tuesday plans to launch a new market place where companies, public sector bodies and research institutes can buy and sell excess cloud computing capacity.

US tech firms losing business over PRISM: poll

July 24, 2013

Revelations about the US government's vast data collection programs have already started hurting American technology firms, according to an industry survey released this week.

Recommended for you

Toyota promises better mileage and ride with Prius hybrid

October 13, 2015

Toyota Motor Corp. released details for its fourth-generation Prius on Tuesday, promising that improvements in the battery, engine, wind resistance and weight mean better mileage for the world's top-selling hybrid car.

Facebook to test mobile app shopping tab

October 12, 2015

Facebook said Monday that it will begin testing a shopping tab for its mobile app as it works to ramp up advertising and online commerce offerings.

1 comment

Adjust slider to filter visible comments by rank

Display comments: newest first

not rated yet Jul 30, 2013
Cloud Computing is going to reduce costs?

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.