I highly recommend reading the actual audit[1]. There's a lot of good details in there, similar to the Senate report on the Equifax breach a few days ago. There were several problems: the inventory tracking issue was particularly enlightening: >system administrators did not consistently update the inventory system when they added devices to the network. Specifically, we found that 8 of 11 system administrators respon…
Nobody ever manually maintains inventory correctly. That's why automated systems are supposed to scan networks and inform the inventory of what is actually there , versus what is "supposed to be there". Lack of training doesn't matter at all. This is just a mechanism to blame people, it doesn't ensure security at all. And of course JPL doesn't have a mechanism to allow DHS to scan its entire network . Nobody has a bi…
This works very well to identify stuff that actually answers and will yield devices that are not supposed to be there in the first place but someone planning mischief is not going to place a device that is easily identified like that.