GAO-05-434 Critical Infrastructure Protection: Department of Homeland Security Faces Challenges in Fulfilling Cybersecurity Responsibilities

نویسنده

  • David Powner
چکیده

To view the full product, including the scope and methodology, click on the link above. For more information, contact David Powner at (202) 512-9286 or [email protected]. As the focal point for critical infrastructure protection (CIP), the Department of Homeland Security (DHS) has many cybersecurity-related roles and responsibilities that we identified in law and policy (see table below for 13 key responsibilities). DHS established the National Cyber Security Division to take the lead in addressing the cybersecurity of critical infrastructures. While DHS has initiated multiple efforts to fulfill its responsibilities, it has not fully addressed any of the 13 responsibilities, and much work remains ahead. For example, the department established the United States Computer Emergency Readiness Team as a public/private partnership to make cybersecurity a coordinated national effort, and it established forums to build greater trust and information sharing among federal officials with information security responsibilities and law enforcement entities. However, DHS has not yet developed national cyber threat and vulnerability assessments or government/industry contingency recovery plans for cybersecurity, including a plan for recovering key Internet functions. DHS faces a number of challenges that have impeded its ability to fulfill its cyber CIP responsibilities. These key challenges include achieving organizational stability, gaining organizational authority, overcoming hiring and contracting issues, increasing awareness about cybersecurity roles and capabilities, establishing effective partnerships with stakeholders, achieving two-way information sharing with these stakeholders, and demonstrating the value DHS can provide. In its strategic plan for cybersecurity, DHS identifies steps that can begin to address the challenges. However, until it confronts and resolves these underlying challenges and implements its plans, DHS will have difficulty achieving significant results in strengthening the cybersecurity of our critical infrastructures. • Develop a national plan for critical infrastructure protection, including cybersecurity. • Develop partnerships and coordinate with other federal agencies, state and local governments, and the private sector. • Improve and enhance public/private information sharing involving cyber attacks, threats, and vulnerabilities. • Develop and enhance national cyber analysis and warning capabilities. • Provide and coordinate incident response and recovery planning efforts. • Identify and assess cyber threats and vulnerabilities. • Support efforts to reduce cyber threats and vulnerabilities. • Promote and support research and development efforts to strengthen cyberspace security. • Promote awareness and outreach. • Foster training and certification. • Enhance federal, state, and local government cybersecurity. • Strengthen international cyberspace security. • Integrate cybersecurity with national security. Source: GAO analysis …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Cybersecurity Issues and Challenges: In Brief

The information and communications technology (ICT) industry has evolved greatly over the last half century. The technology is ubiquitous and increasingly integral to almost every facet of modern society. ICT devices and components are generally interdependent, and disruption of one may affect many others. Over the past several years, experts and policy makers have expressed increasing concerns...

متن کامل

Design and Implementation of a Critical Infrastructure Security and Assessment Laboratory

The globally-connected information superhighway, known as cyberspace, ushered our dependence on information technology to support our critical infrastructure. In a recent study [1] conducted by the United States Government Accountability Office (GAO) on critical infrastructure protection, the lessons learned from the first Cyber Storm exercise have yet to be fully addressed. In October, 1997, t...

متن کامل

A Survey of Operations Research Models and Applications in Homeland Security

Operations research has had a long and distinguished history of work in emergency preparedness and response, airline security, transportation of hazardous materials, and threat and vulnerability analysis. Since the attacks of September 11, 2001 and the formation of the US Department of Homeland Security, these topics have been gathered under the broad umbrella of homeland security. In addition,...

متن کامل

Realizing the promise of public-private partnerships in U.S. critical infrastructure protection

To date, much attention has focused on the advantages of public-private partnerships for critical infrastructure protection in the United States. These include reducing the duplication of effort, enhancing cross-sector communication, increasing efficiency, and ultimately achieving the protection objectives better than government or business acting independently. The benefits suggest that public...

متن کامل

Enhancing Resilience through Cyber Incident Data Sharing and Analysis

This document outlines the benefits of a trusted cyber incident data repository that enterprise risk owners and insurers could use to anonymously share sensitive cyber incident data and is the first in a series of white papers. This paper outlines the potential benefits of a trusted cyber incident data repository that enterprise risk owners and insurers could use to anonymously share, store, ag...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005