|
38 | 38 | <remarks>
|
39 | 39 | <p>The assessor's security automation platform analyzed all roles specific to the
|
40 | 40 | GoodRead Product Team, not those managed by the Office of Information Technology.
|
41 |
| - The <code>IFA-GoodRead-SystemEnginer</code> role in their respective AwesomeCloud |
| 41 | + The <code>IFA-GoodRead-SystemEngineer</code> role in their respective AwesomeCloud |
42 | 42 | account permitted use of the following high-risk actions.</p>
|
43 | 43 | <ul>
|
44 | 44 | <li>awesomecloud:auditlog:DeleteAccountAuditLog</li>
|
|
75 | 75 | <mitigating-factor uuid="401c15c9-ad6b-4d4a-a591-7d53a3abb3b6">
|
76 | 76 | <description>
|
77 | 77 | <p>The GoodRead application is designed and implemented to only allow access to the
|
78 |
| - administrative functions for those with PAO staff fole via the VPN via network |
| 78 | + administrative functions for those with PAO staff role via the VPN via network |
79 | 79 | configuration between the IFA Enterprise Support Systems and the GoodRead
|
80 | 80 | AwesomeCloud account. Additionally, the load balanacer configuration only allows
|
81 | 81 | access to view shortlinks from the public internet.</p>
|
82 | 82 | </description>
|
83 | 83 | </mitigating-factor>
|
84 | 84 | <deadline>2024-01-01T05:00:00-04:00</deadline>
|
85 | 85 | <response uuid="d28873f7-0a45-476d-9cd3-1d2ec0b8bca1" lifecycle="planned">
|
86 |
| - <title>IFA-GOODREAD-RISK1-RESPONSE: IFA GoodRead Prouct Team Response</title> |
| 86 | + <title>IFA-GOODREAD-RISK1-RESPONSE: IFA GoodRead Product Team Response</title> |
87 | 87 | <description>
|
88 | 88 | <p>The GoodRead Product Team does not have sufficient personnel and budget to
|
89 | 89 | implement the required changes in their use of the Django Framework and its
|
|
100 | 100 | <description>
|
101 | 101 | <p>The owner, ISSO, and product team of the GoodRead Project intend to complete
|
102 | 102 | the necessary development between September 2023 and December 2023. Whether
|
103 |
| - or not the necessary development for remedation is complete, the product |
| 103 | + or not the necessary development for remediation is complete, the product |
104 | 104 | team's project manager will submit the final annual report. They will
|
105 | 105 | identify this work item and whether it has been completed.</p>
|
106 | 106 | </description>
|
|
129 | 129 | duration of a potential incident, such a configuration greatly increases the risk of
|
130 | 130 | an insider threat if there were likely to a potential insider threat in the GoodRead
|
131 | 131 | Product Team.</p>
|
132 |
| - <p>If such an insider threat existed and acted with this misconfigruatio, the resulting |
| 132 | + <p>If such an insider threat existed and acted with this n, the resulting |
133 | 133 | event could cause significant financial and reputational risk to IFA's
|
134 | 134 | Administrator, executive staff, and the agency overall.</p>
|
135 | 135 | </statement>
|
|
143 | 143 | </characterization>
|
144 | 144 | <deadline>2023-06-23T17:00:00-04:00</deadline>
|
145 | 145 | <response uuid="4676b126-ba6d-40cc-9dc8-f2aa677b03ee" lifecycle="planned">
|
146 |
| - <title>IFA-GOODREAD-RISK1-RESPONSE: IFA GoodRead Prouct Team Response</title> |
| 146 | + <title>IFA-GOODREAD-RISK1-RESPONSE: IFA GoodRead Product Team Response</title> |
147 | 147 | <description>
|
148 |
| - <p>The GoodRead Product Team does not have siginficant mitigations or compensating |
| 148 | + <p>The GoodRead Product Team does not have significant mitigations or compensating |
149 | 149 | controls to counter this risk, even if likelihood is low. The IFA CISO has cited
|
150 | 150 | ongoing guidance that potential insider threat risks be prioritized above
|
151 | 151 | alternative categories of risk for this quarter. Additionally, there is
|
|
177 | 177 | <title>Update Django Framework Configuration to Disable Default Admin Panel</title>
|
178 | 178 | <description>
|
179 | 179 | <p>Budget and technical staff are needed to re-design and re-implement a part of the
|
180 |
| - GoodRead application's use of a web appplication programming framework to mitigate |
| 180 | + GoodRead application's use of a web application programming framework to mitigate |
181 | 181 | the risk of low privilege users directly modifying the database of this application.
|
182 | 182 | This application is a high-visibility service and integral to future operations of
|
183 | 183 | the IFA Office of Public Affairs and its staff.</p>
|
|
0 commit comments