Top Banner
Cybersecurity Executive Order “Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure” 1
4

Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

Oct 09, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

CybersecurityExecutiveOrder“StrengtheningtheCybersecurityof

FederalNetworksandCriticalInfrastructure”

1

Page 2: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

Background• May11th WhiteHouseissuedtheExecutiveOrder

“StrengtheningtheCybersecurityofFederalNetworksandCriticalInfrastructure”– Renewedemphasisoncyberriskmanagement– Managecybersecurityriskasanexecutivebranchenterprise

• Riskmanagementdecisionsmadebyagencyheadscanaffecttherisktotheexecutivebranchasawhole

• May19th OfficeofManagementandBudget(OMB)issuedMemorandumM-17-25,“ReportingGuidanceforEOonStrengtheningtheCybersecurityofFederalNetworksandCriticalInfrastructure”– ProvidesadditionalguidancetosupplementtheEO

2

Page 3: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

SevenAreasofFocus

3

Focus Area

1.DocumentRiskMitigationandAcceptance Choices

2.DescribeActionPlantoImplementNISTCybersecurityFramework

3.ProvideCurrentITArchitecturetoEvaluateSharedServices

4.IdentifyCapabilitiesSupportingCybersecurityofCriticalInfrastructure

5.AdviseonResilienceAgainstBotnetsandOtherAutomated,DistributedThreats

6.ReportonDeterrenceandProtectionOptions

7.DocumentInternationalCybersecurityPriorities

Page 4: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

HighLevelProcessandTimeline

•BureauEnterpriseCybersecurityRiskstoTreasuryonJune16th•BureauFISMACIOMetricstoTreasury(3° Quarter)•DiscussionsonNISTCybersecurityFrameworkImplementation

•WhiteHouseissuesCybersecurityEOonMay11th

•OnepageOMBRiskAssessmentsoneachDepartment(anticipatedonJuly28th)

•ConsolidatedDepartmentalResponseonEnterpriseCybersecurityRisks,3rdQuarterFISMACIOMetrics,andNISTCybersecurityFrameworkImplementationActionPlantoOMBonJuly14th

•OMBissuesM-17-25MemorandumonMay19th

•DepartmentalReviewofRiskAssessmentandwrittenresponse(DueAug9th)

•OMB&DHSprovidereporttotheWhiteHouse(nosoonerthanAug9th)•OMB&DHSwillworkwithagenciestoimprovecybersecurityriskmanagement(Unknown?)