- Develop a national strategy that clearly articulates strategic objectives, goals, and priorities.
- Establish White House responsibility and accountability for leading and overseeing national cybersecurity policy.
- Establish a governance structure for strategy implementation.
- Publicize and raise awareness about the seriousness of the cybersecurity problem.
- Create an accountable, operational cybersecurity organization.
- Focus more actions on prioritizing assets, assessing vulnerabilities, and reducing vulnerabilities than on developing additional plans.
- Bolster public-private partnerships through an improved value proposition and use of incentives.
- Focus greater attention on addressing the global aspects of cyberspace.
- Improve law enforcement efforts to address malicious activities in cyberspace.
- Place greater emphasis on cybersecurity research and development, including consideration of how to better coordinate government and private sector efforts.
- Increase the cadre of cybersecurity professionals.
- Make the federal government a model for cybersecurity, including using its acquisition function to enhance cybersecurity aspects of products and services.
On a timely parallel note this week, NSA Information Assurance Director Richard Schaeffer Jr. testified before the Senate Judiciary Committee's Subcommittee on Terrorism and Homeland Security that if agencies focused security efforts on instituting best practices, standard secure configuration settings, and good network monitoring, those actions alone can guard against the majority of threats and cyberattacks agencies face. This sort of 80/20 rule is not intended to obviate the need for risk assessments or comprehensive implementation of effective security controls in accordance with FISMA and other federal requirements, but the message from NSA seems to be a clear call to agencies to get the basics right.


No comments:
Post a Comment