The National Oceanic and Atmospheric Administration is scrambling to get its newest satellites into space before the existing hardware fails, creating a significant gap in the availability of critical data. However, the Government Accountability Office is warning the agency to be wary of critical information security flaws that could leave the system vulnerable.
According to a GAO audit released May 17, NOAA has made significant progress with the Joint Polar Satellite System since the potential data gap was first identified in 2012 and is on track to launch JPSS-1 by March 2017.
As the program speeds toward completion, new security weaknesses are being identified regularly, which, if not resolved, could end up delaying the final launch.
As of August 2015, the program had more than 1,400 critical and high-risk vulnerabilities, according to GAO, all of which were more than four months old but had yet to be addressed.
And the threat is real. NOAA officials reported 10 medium-to-high security incidents between August 2014 and August 2015 involving “hostile probes, improper usage, unauthorized access, password sharing and other IT-related security concerns.” To date, six of those investigations have been closed while the other four remain outstanding.
A successful attack on NOAA satellites could lead to information leakage, an inability to access important data or, worse, the manipulation of data before it gets to researchers.
GAO researchers note NOAA has created a set of security guidelines based on controls recommended by the National Institute of Standards and Technology, though the JPSS program office has yet to implement them. This is particularly true when it comes to the program’s ground systems, which manage the satellites and handle data processing.
“The program categorized the JPSS ground system as a high-impact system and selected and implemented multiple relevant security controls,” according to the report. “However, the program has not yet fully implemented almost half of the recommended security controls, did not have all the information it needed when assessing security controls and has not addressed key vulnerabilities in a timely manner.”
GAO found that the program office had only implemented 53 percent of the required baseline security controls and of the 17 control areas, only one — incident response — had been fully implemented.
Officials explained that the controls for the current ground system were created under the previous satellite program, which used an older version that was based on moderate controls established by the Defense Department. Program managers told GAO they are aware of the gap between moderate and high baseline controls and have “implemented compensating controls to mitigate the risks inherent” in the older system.
All totaled, the older system — known as Block 1.2 — has at least 146 critical and 951 high-risk vulnerabilities. The system now in development — Block 2.0 — has 102 critical and 295 high-risk weaknesses.

Auditors added that the assessment itself was also flawed, meaning there could be many more yet unidentified vulnerabilities.
The JPSS program office plans to address all open vulnerabilities on both ground systems as part of an authority to operate (ATO) certification process, expected in July 2016.
“Given the increasing information security risks across the federal government, building information security into ground systems is a critical component of the JPSS system development,” GAO auditors wrote. “Until these deficiencies are addressed, the polar satellite infrastructure will continue to be at increased risk of compromise.”
NOAA officials generally concurred with GAO’s recommendations on information security.




