Module 4 - Government and Industry Regulations and Guidance Flashcards
National Security Council offices to assist Federal government
Continuity of Operations
Cyber Security and Information Sharing
Executive Orders to improve infrastructure
- Presidential Policy Directive 1
- National Security Directive 42
- Executive Order – Improving Critical Infrastructure Cybersecurity
- Executive Order 23549
- Executive Order 13563
- Executive Order 13609
Organizations assisting in securing IS (name 9)
- Information Security Oversight Office, which is part of the National Archives and Records Administration
- Department of Commerce and the National Institute of Standards and Technology
- Department of Homeland Security
- US Federal Cyber Center
- FEMA
- Department of Defense
- Department of Justice
- Secret Service
- Government Accountability Office
Trade Organizations with security concerns
American Bar Association (ethical related to sharing)
Presidential Policy Directive 1
2009
- Established National Security Council (NSC)
- References National Security Act of 1947
- Scope includes domestic, foreign, military, intelligence and economic.
- day to day crisis management
- Adds Associate Director of the office of Science and Technology Policy
National Security Directive 42
National Policy for the Security of National Security Telecommunications and Information Systems July 5, 1990
Establishes the NSTISSC (Security Committee) chaired by Assistant Secretary of DoD
NSC org chart
- under National Economic Advisor until 2008
- then under Homeland Security Advisor (DHS) who oversaw Continuity of Operations and Cyber Security and Info Sharing offices.
Executive Order – Improving Critical Infrastructure Cybersecurity
- National & Economic Security
- Reliability of critical infrastructure
- Safety, Security, Confidentiality, Privacy, and civil liberties.
- “Critical Infrastructure”
- Economic security
- Public Health
- Safety
- Section 4 deals with Cyber Security Information Sharing
- Section 5 - Privacy and Civil Liberties Protections
- Section 6 - Consultative Process
- Section 7 - Baseline Framework to Reduce Cyber Risk to Critical Infrastructure
- Section 8 - Voluntary Critical Infrastructure Cyber Security Program
- Section 9 - Identification of Critical Infrastructure at Greatest Risk
- Section 10 - Adoption of Framework
Critical Infrastructure under Executive Order
systems and assets whether physical or virtual, so vital … that the incapacity or destruction of such systems and assets would have a debilitating impact on security
Executive Order 23549
Established program to safeguard and govern sharing of classified National Security Information with state, local, tribal, and private sector (stltps)
National Security Advisor
Director of the Information Security Oversight Office (ISOO)
ISOO within NARA (National Archives and Records Administration) - receives guidance from NSC
ISOO (3 components)
Classification Management Staff
Operations Staff
Controlled Unclassified Information (CUI) office
Executive Order 13563
Improving Regulation and Regulatory Review
- adopt reasoned regulation
Executive Order 13609
Promoting International Regulatory Coorperation
US Federal Cyber Center
- overlapping of roles (Intelligence Law Enforcement / Counterintelligence Defense Civil)
FEMA
- information regarding protecting under cyberattack (general info)