The Brookhaven National Laboratory is in need of a fully effective unclassified cybersecurity program, according to an audit by the Department of Energy’s Office of Inspector General.
A review of the multipurpose research institution — located in Upton, New York, and employing nearly 3,000 — identified weaknesses as Brookhaven officials had not adhered to all federal and site-specific policies and procedures related to the Federal Information Security Modernization Act of 2014 and National Institute of Standards and Technology mandatory guidance.
A report on the Energy Department’s cybersecurity risk management framework previously found multiple sites that had not implemented a continuous monitoring process, prompting a further examination. A look at Brookhaven’s network, specifically, identified over 200 unique vulnerabilities on workstations, servers and web applications because of lax configuration management.
In addition, Brookhaven has not always maintained adequate physical or logical access controls over its information and systems, needs to conduct security planning and assessment activities in accordance with federal requirements, and needs to develop adequate contingency planning and data retention procedures in the event of a disruption of essential functions.
The OIG made several recommendations to enhance controls, policies and processes and assure Brookhaven’s information and systems are not subject to a higher-than-necessary risk of compromise, loss or modification.
The facility’s management concurred with the corrective actions to establish an effective plan of action and milestones and has taken steps to implement a defense-in-depth cybersecurity posture and oversee mitigating risk.
All of the Energy Department OIG’s findings can be viewed on its website.




