cybersecurity executive order “strengthening the ......cybersecurity risks, 3rd quarter fisma cio...

4
Cybersecurity Executive Order “Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure” 1

Upload: others

Post on 09-Oct-2020

8 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

CybersecurityExecutiveOrder“StrengtheningtheCybersecurityof

FederalNetworksandCriticalInfrastructure”

1

Page 2: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

Background• May11th WhiteHouseissuedtheExecutiveOrder

“StrengtheningtheCybersecurityofFederalNetworksandCriticalInfrastructure”– Renewedemphasisoncyberriskmanagement– Managecybersecurityriskasanexecutivebranchenterprise

• Riskmanagementdecisionsmadebyagencyheadscanaffecttherisktotheexecutivebranchasawhole

• May19th OfficeofManagementandBudget(OMB)issuedMemorandumM-17-25,“ReportingGuidanceforEOonStrengtheningtheCybersecurityofFederalNetworksandCriticalInfrastructure”– ProvidesadditionalguidancetosupplementtheEO

2

Page 3: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

SevenAreasofFocus

3

Focus Area

1.DocumentRiskMitigationandAcceptance Choices

2.DescribeActionPlantoImplementNISTCybersecurityFramework

3.ProvideCurrentITArchitecturetoEvaluateSharedServices

4.IdentifyCapabilitiesSupportingCybersecurityofCriticalInfrastructure

5.AdviseonResilienceAgainstBotnetsandOtherAutomated,DistributedThreats

6.ReportonDeterrenceandProtectionOptions

7.DocumentInternationalCybersecurityPriorities

Page 4: Cybersecurity Executive Order “Strengthening the ......Cybersecurity Risks, 3rd Quarter FISMA CIO Metrics, and NIST Cybersecurity Framework Implementation Action Plan to OMB on July

HighLevelProcessandTimeline

•BureauEnterpriseCybersecurityRiskstoTreasuryonJune16th•BureauFISMACIOMetricstoTreasury(3° Quarter)•DiscussionsonNISTCybersecurityFrameworkImplementation

•WhiteHouseissuesCybersecurityEOonMay11th

•OnepageOMBRiskAssessmentsoneachDepartment(anticipatedonJuly28th)

•ConsolidatedDepartmentalResponseonEnterpriseCybersecurityRisks,3rdQuarterFISMACIOMetrics,andNISTCybersecurityFrameworkImplementationActionPlantoOMBonJuly14th

•OMBissuesM-17-25MemorandumonMay19th

•DepartmentalReviewofRiskAssessmentandwrittenresponse(DueAug9th)

•OMB&DHSprovidereporttotheWhiteHouse(nosoonerthanAug9th)•OMB&DHSwillworkwithagenciestoimprovecybersecurityriskmanagement(Unknown?)