DHS and GSA Undermining NIST Cybersecurity Framework?

Editor’s Note: The complete GAO report, “CRITICAL INFRASTRUCTURE PROTECTION: Measures Needed to Assess Agencies’ Promotion of the Cybersecurity Framework,” (GAO-16-152) is available here. Below is a brief excerpt.

From: GAO

Conclusions

NIST has generally fulfilled its requirements, established in Executive Order 13636 and the Cybersecurity Enhancement Act, to develop a cybersecurity framework for adoption by critical infrastructure sectors. By using a collaborative process for developing the framework, NIST has helped ensure that the resulting guidance, standards, and methodologies, if effectively implemented, can help cost-effectively reduce cyber risks to critical infrastructure.

To facilitate the voluntary adoption of the framework by critical infrastructure owners and operators, DHS, sector-specific agencies, and NIST are taking a variety of actions. However, while DHS has established a program dedicated to encouraging the framework’s adoption, without establishing metrics to assess the effectiveness of these efforts, it has less assurance that it is meeting its objectives. In addition, while most SSAs have determined the need for sector-specific guidance to implement the framework, DHS and GSA have yet to meet this requirement for the government facilities sector, which may hinder adoption of the framework in this sector. [Emphasis added]

 

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *