Skip to main content

Nuclear Regulatory Commission

Jump To:

Open Recommendations (23 total)

IT Portfolio Management: OMB and Agencies Are Not Fully Addressing Selected Statutory Requirements

1 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chairman of the Nuclear Regulatory Commission should direct its agency CIO to work with OMB to ensure that annual reviews of their IT portfolio are conducted in conjunction with the Federal CIO and the Chief Operating Officer or Deputy Secretary (or equivalent), as prescribed by FITARA. (Recommendation 39)
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Cloud Computing: Agencies Need to Address Key OMB Procurement Requirements

1 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chairman of NRC should ensure that the CIO of NRC develops guidance to require that contracts affecting the agency's HVAs that are managed and operated in the cloud include language that provides the agency with continuous visibility of the asset. (Recommendation 39)
The Nuclear Regulatory Commission (NRC) concurred with our recommendation and has stated that they will take plans to address it. In November 2024, an official in NRC's Office of the Executive Director for Operations reported that the agency planned to establish a working group to address the OMB requirement. In addition, the agency planned to update its statement of work templates to include this requirement and also to include language in agency guidance that would require the agency to be responsible for monitoring NRC's high value asset systems and the continuous visibility needed to perform these activities. We will continue to monitor NRC's progress in implementing this recommendation.

Cloud Computing: Agencies Need to Address Key OMB Procurement Requirements

3 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chairman of NRC should ensure that the CIO of NRC develops guidance to put a cloud SLA in place with every vendor when a cloud solution is deployed. The guidance should include language that addresses OMB's four required elements for SLAs, including: continuous awareness of the confidentiality, integrity, and availability of its assets; a detailed description of roles and responsibilities; clear performance metrics; and remediation plans for non-compliance. (Recommendation 37)
The Nuclear Regulatory Commission (NRC) concurred with our recommendation and has stated that they will take plans to address it. In November 2024, an official in NRC's Office of the Executive Director for Operations reported that the agency planned to establish a working group to address the OMB requirement. In addition, the agency planned to update its service level agreement guidance (SLA) and make sure it included all four required elements. We will continue to monitor NRC's progress in implementing this recommendation.
Nuclear Regulatory Commission The Chairman of NRC should ensure that the CIO of NRC updates its existing contracts for HVAs that are managed and operated in the cloud to meet OMB's requirement once guidance from the CIO Council is available on language that provides the agency with continuous visibility of the asset. If modifying the existing contract is not practical, the agency should incorporate language into the contract that will meet OMB's requirement upon option exercise or issuance of a new award. (Recommendation 40)
The Nuclear Regulatory Commission (NRC) concurred with our recommendation and has stated that they will take plans to address it. In November 2024, an official in NRC's Office of the Executive Director for Operations reported that the agency planned to establish a working group to address the OMB requirement. In addition, the agency planned to update its existing high value asset contracts to provide the agency with continuous visibility of the asset. We will continue to monitor NRC's progress in implementing this recommendation.
Nuclear Regulatory Commission The Chairman of NRC should ensure that the CIO of NRC develops guidance regarding standardizing cloud SLAs. (Recommendation 38)
: The Nuclear Regulatory Commission (NRC) concurred with our recommendation and has stated that they will take plans to address it. In November 2024, an official in NRC's Office of the Executive Director for Operations reported that the agency planned to establish a working group to address the OMB requirement. In addition, the agency planned to review its current list of recommended clauses and other resources for the procurement to make sure it includes all four required elements for cloud computing services. When procuring cloud computing services through third party resellers, the official noted that the agency will ensure that service level agreements are extended to the NRC, not just the reseller. We will continue to monitor NRC's progress in implementing this recommendation.

Nuclear Power Plants: NRC Should Take Actions to Fully Consider the Potential Effects of Climate Change

1 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chair of the NRC should direct NRC staff to assess whether its licensing and oversight processes adequately address the potential for increased risks to nuclear power plants from climate change. (Recommendation 1)
In September 2024, NRC stated that this recommendation is consistent with actions that are either underway or under development. Specifically, NRC stated that the NRC staff is reviewing the recently released Fifth National Climate Assessment (NCA5) under its Process for the Ongoing Assessment of Natural Hazards Information. This review of NCA5 and its supporting technical literature will be the starting point for the identification of any potential gaps relevant to the NRC's licensing and oversight processes. NRC staff will determine if and how the updated information might inform the licensing and oversight of existing licensed power plants.

Nuclear Power Plants: NRC Should Take Actions to Fully Consider the Potential Effects of Climate Change

2 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chair of the NRC should direct NRC staff to develop, finalize, and implement a plan to address any gaps identified in its assessment of existing processes. (Recommendation 2)
In September 2024, NRC stated that NRC staff will assess the safety significance of any gaps, if identified, through the staff's review of the Fifth National Climate Assessment or through any subsequent activities conducted in response to GAO's Recommendation 1. Pursuant to staff's existing processes, staff will address any risk significant gaps, if identified.
Nuclear Regulatory Commission The Chair of the NRC should direct NRC staff to develop and finalize guidance on incorporating climate projections data into relevant processes, including what sources of climate projections data to use and when and how to use climate projections data. (Recommendation 3)
In September 2024, NRC stated that NRC staff is conducting a comprehensive review of relevant regulatory guides to determine whether any require an update or revision to address considerations related to climate change. NRC further stated that its staff review of the Fifth National Climate Assessment will support a determination of whether specific new guidance related to use of climate projections is warranted.

Cybersecurity: Federal Agencies Made Progress, but Need to Fully Implement Incident Response Requirements

1 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chairman of the Nuclear Regulatory Commission should ensure that the agency fully implements all event logging requirements as directed by OMB guidance. (Recommendation 18)
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

High-Risk Radioactive Material: Opportunities Exist to Improve the Security of Sources No Longer in Use

1 Open Recommendations
Agency Affected Recommendation Status
Nuclear Regulatory Commission The Chairman of the NRC should comprehensively assess leading practices that, if implemented, would minimize the time that disused sources are in a licensee's possession. These practices include financial assurances for all category 1, 2, and 3 sources; tracking of category 3 sources; possession time limits or fees for disused sources; and orphan source funds. (Recommendation 3)
In July 2024, NRC officials stated NRC will evaluate 1) the merits and practicality of time limits and fees for sources not actively being used and 2) authorities required to establish an orphan source fund. NRC staff are also currently developing a regulatory basis for a rulemaking that would consider whether financial assurance requirements should be extended to category 3 sources. However, in 2017, NRC staff recommended the Commission not pursue rulemaking to amend NRC regulations to require inclusion of category 3 sources in NSTS. In December 2021, the Commission documented its agreement with staff's recommendation. In February 2024, NRC staff told us NRC has no further plans to consider including category 3 sources in NSTS.