Follow us! >

USPS OIG – Security Assessment of a U.S. Postal Service Product Solutions Application

Background

The U.S. Postal Service continuously strives to improve its [redacted] to become more efficient and responsive to the dynamic market needs of its customers. To [redacted] application is used by over [redacted] is a business-critical application that generated over [redacted] total revenue in fiscal year 2022.

What We Did

Our objective was to evaluate whether the Postal Service had security controls in place to protect the application from cyberattacks, prevent unauthorized access to restricted data, and determine compliance with secure coding practices. We conducted a security assessment of the application including penetration tests to evaluate the application and internal security posture. We also performed a source code review to verify if appropriate security controls were present.

What We Found

Based on our testing, we found the Postal Service implemented network perimeter security controls that limit direct access to the application and help deter known web-based attacks. However, during our security assessment, we identified issues with [redacted]. These issues could lead to attackers gaining unauthorized access to the system to steal, modify, or delete sensitive data if perimeter controls are bypassed. These issues occurred because management did not [redacted]. Also, the Postal Service prioritizes the identification and remediation of vulnerabilities ranked critical and high over medium, low, and informational. However, [redacted], increases the risk of unauthorized access to the application. In addition, [redacted].

Recommendations

We recommended management develop guidance for performing [redacted] application; and [redacted].

Sign up to receive our Daily Postal News blast

Related Articles

Tell us what you think below!

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Hot this week

Regional Transportation Optimization ends evening collections at nearly 12,000 post offices

Over the past two years, the Postal Service has been quietly eliminating the evening collection of mail at thousands of post offices.

Rep. Angie Craig Blasts USPS after Q4 Report Ranks MN Postal Performance One of the Worst in the Country

Today, U.S. Representative Angie Craig blasted U.S. Postal Service (USPS) leadership in Minnesota following the release of the USPS Office of Inspector General’s (OIG) Fiscal Year 2025 (FY25) 4th quarter (Q4) service performance report

When it comes to shipping this item, these precautions make scents

With the holiday season comes an increase in shipments of perfume, which is flammable and considered a hazardous material in the mailstream.

PMG David Steiner and several USPS employees participated in a Halloween celebration at the White House last month

The participating children and their parents could also visit booths, including a USPS station where the kids could write and mail letters and postcards and receive toy LLVs.

USPS hits 3 billion holiday packages in ‘Christmas City’ Noel

NOEL, Mo. — A package with a special number arrived at the post office in Noel — or rather during this time of year — Noël.
spot_img

Related Articles

Popular Categories

spot_imgspot_img
Secret Link
0
Would love your thoughts, please comment.x
()
x