Inspector General audit finds problems with NASA's cloud computing efforts

Jul 30, 2013 by Bob Yirka weblog

(Phys.org) —The Office of the Inspector General, led by Paul Martin, has published the results of an audit of NASA's cloud computing efforts and has found many such efforts lack proper security. The report also notes that many cloud efforts run by the agency were operating without the knowledge of its own Office of the Chief Information Officer.

Over the past several years, the Office of Management and Budget, which controls the purse strings of federal entities, has demanded that governmental agencies, such as NASA, begin transferring some or all of its and storage activities to the cloud. The idea is that doing so will save the government a lot of money. In following the directive, however, it appears that managers at NASA have failed to ensure that cloud operations are undertaken with the knowledge and approval of the agencies top information officer. Worse, it appears that many of the cloud initiatives were undertaken without due consideration given to necessary security precautions that must be put in place when applications and data become accessible across the Internet.

More specifically, the auditors found over a 100 NASA websites—both internal and external—had never been tested for security integrity. Incredibly, many of those same websites were found to have no security controls in place at all.

Government agencies have two main options when moving applications to the cloud—set up facilities on their own or contract out. NASA, like most other federal agencies has chosen the latter. Unfortunately, the auditors found that officials at the agency in many cases failed to include security issues when writing contracts, which of course resulted in them not being put in place.

Overall, the IG's report has found that weaknesses in cloud applications have impeded the agency from reaping the benefits of —namely reducing costs. And worse, the approach taken thus far has put NASA data at risk. Out of five contracts reviewed, the auditors found "none came close" to operating with industry standard security precautions.

The auditors recommend that NASA set up an office dedicated to cloud computing and the that must be put in place when such initiatives are undertaken.

Explore further: Coping with floods—of water and data

Related Stories

Deutsche Boerse to launch cloud computing exchange

Jul 02, 2013

Deutsche Boerse, operator of the Frankfurt stock exchange, unveiled Tuesday plans to launch a new market place where companies, public sector bodies and research institutes can buy and sell excess cloud computing ...

US tech firms losing business over PRISM: poll

Jul 24, 2013

Revelations about the US government's vast data collection programs have already started hurting American technology firms, according to an industry survey released this week.

Head for the clouds, feet firmly on the ground

Mar 05, 2012

Computer engineers in the US writing in the International Journal of Communication Networks and Distributed Systems have reviewed the research literature to get a clear picture of cloud computing, its adoption, use and th ...

Recommended for you

Coping with floods—of water and data

Dec 19, 2014

Halloween 2013 brought real terror to an Austin, Texas, neighborhood, when a flash flood killed four residents and damaged roughly 1,200 homes. Following torrential rains, Onion Creek swept over its banks and inundated the ...

Cloud computing helps make sense of cloud forests

Dec 17, 2014

The forests that surround Campos do Jordao are among the foggiest places on Earth. With a canopy shrouded in mist much of time, these are the renowned cloud forests of the Brazilian state of São Paulo. It is here that researchers ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

MCPtz
not rated yet Jul 30, 2013
Cloud Computing is going to reduce costs?

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.