Board Report: 2024-IT-B-011R April 10, 2024
The Board's web-based embargo application allows authorized members of the media to access documents that are not yet posted to the Board's public website.
Overall, the security controls we tested for the embargo application were effective. For example, the Board ensured that privileged access was provisioned on a need-to-know basis. In addition, required embargo application events were logged and retained in accordance with Board requirements. However, the Board can strengthen access and configuration management controls for the embargo application.
Our report includes one recommendation and one matter for management consideration. Given the sensitivity of the information in our review, our full report is restricted.