The Board of Audit and Inspection revealed the outcomes of the laptop community inspection of six organizations beneath the Ministry of Science and ICT and the National Aeronautics and Space Administration
12 HDD used by retirees are lacking…Unauthorized NAS uncovered abroad hacking
27 circumstances of warning and notification measures, together with the institution of management procedures with the Ministry of Science and ICT and the National Aeronautics and Space Administration
The audit by the Board of Audit and Inspection revealed that government-funded research institutes in the subject of science and expertise that perform core nationwide research and improvement had failed to put in vaccines and different safety issues.
On the twenty eighth, the Board of Audit and Inspection launched the outcomes of the “Public Computer Network Security Management Status” audit carried out on six research institutes, together with the Korea Institute of Science and Technology, the Korea Institute of Biotechnology, the Korea Electronics and Telecommunications, the Korea Atomic Energy Research Institute, the Korea Aerospace Research Institute, and the Korea Aerospace Research Institute beneath the Ministry of Science and ICT.
According to the audit outcomes, 690 HDD hooked up for a 12 months from October 2024 to September final 12 months have been eliminated after analyzing inside PCs from 5 organizations besides the Korea Electronics and Telecommunications Research Institute, which has no exhausting disk attachment document. Of the 39 HDD used by retirees, 12 weren’t positioned or weren’t in the establishment. One retiree, who transferred from the Korea Aerospace Research Institute to a college adjunct professor, didn’t delete 69,956 recordsdata of research knowledge, together with 4 safety duties, and took out HDD with out permission. Under the present pointers, laptops and exterior storage media have procedures for entry and exit, however HDD inside the laptop was left to self-management and there was no management machine.
Server safety administration was additionally poor. Except for the Korea Aerospace Research Institute, which has a forty five.1% vaccine set up charge, 5 establishments put in and operated solely 374 (2.2%) out of 17,073 servers. As a consequence of checking 251 servers with out vaccines, 38 varieties of malicious applications have been detected on 21 servers in 4 organizations. After the announcement of the newest safety replace suggestions, most of the main servers weren’t up to date as a result of they didn’t handle precise measures.
The use of unauthorized exterior entry gadgets and applications was additionally caught. 144 out of 191 community knowledge sharing storage gadgets (NAS) servers with exterior Internet entry have been searched by hacking search engines like google and uncovered to hazard. Of these, 46 have been weak variations that may steal knowledge. An worker’s NAS server saved and operated 20,000 work knowledge, and greater than 60,000 login makes an attempt have been confirmed in about two months overseas. The Ministry of Science and ICT and every research institute didn’t even perceive the use of digital non-public community (VPN) software program that permits bypass entry to the inside community.
Based on the audit outcomes, the Board of Audit and Inspection issued a complete of 27 inclinations, together with 25 notifications and 2 cautions, associated to safety administration of exhausting disks and safety vulnerabilities. The Ministry of Science and ICT and the National Aeronautics and Space Administration referred to as for measures comparable to prohibiting the use of unauthorized exhausting disks, enacting procedures for entry and exit, putting in server vaccines and strengthening vulnerability administration, and checking the standing of VPN and NAS use. Additional investigations and follow-up measures have been notified for 12 exhausting disks that are believed to be exported outdoors.