OTSecurity

GAO urges NASA to strengthen cybersecurity risk management as spacecraft, space systems face growing cyber threats


A new report from the U.S. Government Accountability Office (GAO) has urged the National Aeronautics and Space Administration (NASA) to strengthen its cybersecurity risk management after finding that the agency has yet to implement a priority recommendation to conduct an organization-wide cybersecurity risk assessment. GAO said spacecraft and space systems face increased risks of cyberattacks and mission disruption, making a comprehensive cybersecurity risk management program critical to protecting systems and information, detecting suspicious activity and responding to incidents. 

The recommendation calls on NASA to prepare a documented, organization-wide assessment to identify and mitigate its highest-priority cyber threats. GAO warned that without such an assessment, NASA is less likely to identify relevant threats and internal and external vulnerabilities, assess the potential impact of exploitation, or determine the likelihood of harm. The recommendation remains among four priority recommendations GAO is highlighting for NASA, which had 46 open recommendations as of July 2026 and had not implemented any of its priority recommendations since GAO’s August 2025 review. 

“Spacecraft and space systems are operating in a cyber threat environment with increased risks of attack and mission disruption,” Orice Williams Brown, acting U.S. Comptroller General, wrote in a letter to Jared Isaacman, NASA’s administrator. “Developing, implementing, and maintaining a comprehensive cybersecurity risk management program is critical to protecting NASA’s systems and information, detecting suspicious activity, and responding to incidents. One of the key activities related to implementing a cybersecurity risk management program is preparing an organization-wide cybersecurity risk assessment, which we recommended.” 

He added that a “documented organization-wide risk assessment is essential to identifying and mitigating the highest priority cyber threats across the enterprise. Without such an assessment, NASA is less likely to be able to identify relevant threats and internal and external vulnerabilities, determine the impact if these threats and vulnerabilities are exploited, and ascertain the likelihood that harm will occur.”

In July this year, GAO identified an additional priority recommendation, bringing the total to four. GAO is highlighting three areas that warrant timely and focused attention, including monitoring program costs, managing cybersecurity risks, and using federal contracting metrics.

Addressing GAO’s recommendations in these areas would enhance NASA’s efforts to improve transparency into Artemis program and mission costs; help NASA understand its cybersecurity risks by performing an organization-wide cybersecurity risk assessment to identify and mitigate the highest priority cyber threats across the enterprise; and position NASA to make more informed management decisions and potentially save millions of dollars in its procurements. Taking action to implement all of GAO’s open priority recommendations would help enhance the efficiency and effectiveness of operations across NASA.

The GAO report noted that two of these areas—monitoring program costs and cybersecurity—are also included on GAO’s High Risk List. “Several other government-wide high-risk areas have direct implications for NASA and its operations, including strategic human capital management and managing federal real property. We have also identified actions NASA should take to reduce the cost of government operations. For example, we reported that NASA and other federal agencies were affected by restrictive software licensing practices, including vendor processes that limit, impede, or prevent agencies’ efforts to use software in cloud computing.”

The U.S. watchdog has previously raised concerns over gaps in NASA’s approach to cybersecurity across both major space projects and spacecraft acquisition. In a 2025 review, GAO found that NASA had not fully implemented key cybersecurity risk management activities across selected systems, including the absence of an approved organization-wide cybersecurity risk assessment and documented continuous monitoring strategies. Earlier, in a 2024 review of three spacecraft projects, GAO also found that NASA had not established a plan and timeline for incorporating additional cybersecurity controls into required spacecraft acquisition policies and standards, creating a risk of inconsistent implementation across programs.



Source link