NSA also fell short of safeguarding server racks and other sensitive systems as well as subjecting its high-level administrators to two-phase authentication in response to leaks of domestic surveillance files by former contractor Edward Snowden, according to the declassified version of the report.
The inspector general identified vulnerabilities in internal controls at NSAâs laboratories in Texas, North Carolina, Utah and Washington, D.C.
The report also found that NSAâs data security group had carried out four of the seven measures and those include the implementation of two-person access controls at machine rooms and data centers and evaluation of the number of system administrators at the agency.
The New York Times also reported that NSA failed to shrink the number of âprivilegedâ users, contractors and officials with authority to download top-secret data.
âNSA has never stopped seeking and implementing ways to strengthen both security policies and internal controls,â Vanee Vines, a spokeswoman for the agency, said in a statement.