Cybersecurity

DHS hammering out cybersecurity planning

power lines at sunset

DHS's mandate includes protecting the nation's critical infrastructure, such as its power grid, highways and financial systems. (Stock image)

With the National Institute of Standards and Technology's cybersecurity framework in the final stages of development, attention is shifting to what the Homeland Security Department is doing to complement NIST's guidelines.

DHS is expected to soon release plans of its own to help the owners and operators of critical infrastructure secure their networks and systems. The plans are part of a directive laid out earlier this year, Presidential Policy Directive-21, which President Barack Obama issued along with an executive order targeting national cybersecurity.

"DHS has a responsibility to develop a program that ... will help make the framework user-friendly," said Suzanne Spaulding, undersecretary at DHS' National Protection and Programs Directorate, speaking Oct. 30 at a Bloomberg Government event in Washington, D.C. The DHS initiative will focus on "how to take all of the work done in pulling together all these best practices, and really make it useful to the wide world of critical infrastructure operators out there."

Assisting companies – particularly small and medium-size organizations – in implementation, helping to make the framework understandable and establishing performance goals are part of DHS's plans. Another focus is incentives.

"We're fleshing out a series of areas in which we might be able to provide incentives," she said. "One of the ways we incentivize appropriate behavior now in the public is through insurance. What can we do to help promote the development of a robust insurance market?"

Spaulding said that workshops and meetings with stakeholders are helping DHS officials examine the current state of cybersecurity and determine the way forward. She also said that, pursuant to PPD-21, DHS officials have been working to develop a list of organizations most vulnerable to a cyber attack that could have national security implications.

"We've engaged in a collaborative effort across [critical infrastructure groups]; hundreds of people were involved to better assess, through a consequence analysis, a list of entities," she said. She noted that the effort was not an individualized risk assessment of security postures in specific organizations, but one that, as ordered in the presidential directive, assumed there had been a cyber incident and examined potential consequences at a range of entities.

Whether that list will be made public remains uncertain, but it is possible that more information about the assessment could come in the forthcoming update to the National Infrastructure Protection Plan, last updated in 2009. PPD-21 called for an update to the plan, and Federal News Radio reported that an update could come to the White House as soon as Nov. 8.

About the Author

Amber Corrin is a former staff writer for FCW and Defense Systems.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Then-presidential candidate Donald Trump at a 2016 campaign event. Image: Shutterstock

    'Buy American' order puts procurement in the spotlight

    Some IT contractors are worried that the "buy American" executive order from President Trump could squeeze key innovators out of the market.

  • OMB chief Mick Mulvaney, shown here in as a member of Congress in 2013. (Photo credit Gage Skidmore/Flickr)

    White House taps old policies for new government makeover

    New guidance from OMB advises agencies to use shared services, GWACs and federal schedules for acquisition, and to leverage IT wherever possible in restructuring plans.

  • Shutterstock image (by Everett Historical): aerial of the Pentagon.

    What DOD's next CIO will have to deal with

    It could be months before the Defense Department has a new CIO, and he or she will face a host of organizational and operational challenges from Day One

  • USAF Gen. John Hyten

    General: Cyber Command needs new platform before NSA split

    U.S. Cyber Command should be elevated to a full combatant command as soon as possible, the head of Strategic Command told Congress, but it cannot be separated from the NSA until it has its own cyber platform.

  • Image from Shutterstock.

    DLA goes virtual

    The Defense Logistics Agency is in the midst of an ambitious campaign to eliminate its IT infrastructure and transition to using exclusively shared, hosted and virtual services.

  • Fed 100 logo

    The 2017 Federal 100

    The women and men who make up this year's Fed 100 are proof positive of what one person can make possibile in federal IT. Read on to learn more about each and every winner's accomplishments.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group