Legislation and the future of federal cybersecurity

New laws promise to strengthen agencies' efforts to block network intruders, share information and build a topnotch cybersecurity workforce.

Shutterstock image: U.S. Capitol reflection in black and white.

Cybersecurity continues to be at the forefront of national focus, thanks to Congress’ passing and the president’s signing of three cybersecurity-related bills last December.

Those statutes are now being implemented to continue the progress agencies have made in protecting government networks and working with state and local agencies, critical infrastructure operators, and other private-sector partners to achieve similar progress.

First, the Federal Information Security Modernization Act of 2014 moves government forward in adapting to the ever-changing landscape of the cyber world. Its importance is evidenced by the increasingly complex vulnerabilities, threats and actions against federal networks, often involving malicious third parties.

The act enables federal agencies to be more effective in developing and implementing protective strategies against network intruders. It continues and updates the risk management framework that has been a core tenet of the Federal Information Security Management Act and encourages agencies to use automated security tools to continuously diagnose and mitigate security vulnerabilities. It also codifies the Department of Homeland Security's role in overseeing the implementation of policy and guidelines for federal civilian agencies.

Concurrently, the National Cybersecurity Protection Act codifies the activities of DHS's National Cybersecurity and Communications Integration Center and further strengthens DHS’s ability to coordinate incident response and provide technical assistance to agencies through a variety of information security tools and techniques.

It authorizes DHS’s existing center to act as a critical interface for sharing cybersecurity information among federal civilian agencies and key stakeholders. The law also includes provisions for:

* Promoting situational awareness to enable real-time, integrated and operational actions across the federal government.

* Sharing cybersecurity threat, vulnerability, impact and incident information and analysis by and among federal, state and local government agencies, and private-sector entities.

* Conducting analysis of cybersecurity risks and incidents.

* Providing recommendations on security and resilience measures to federal and non-federal entities.

* Offering timely technical assistance to federal and non-federal entities with respect to cybersecurity threats and attribution, vulnerability mitigation, and incident response and mitigation.

The act also states that the center shall be composed of federal personnel and representatives from state and local governments and other non-federal entities, including information sharing and analysis organizations and owners and operators of critical information systems.

Finally, the DHS Cybersecurity Workforce Recruitment and Retention Act authorizes actions to enhance the government’s pool of talented cybersecurity professionals. It provides additional authorities to the DHS secretary to assist in the recruitment, training, education, development and retention of a highly qualified federal cybersecurity workforce.

The act also requires the secretary to evaluate efforts to improve the department's cybersecurity workforce and submit an annual report to the appropriate committees of Congress detailing DHS’s progress.

DHS’s continuous diagnostics and mitigation program is a prime example of the government’s efforts to operationalize cybersecurity protection in a way that reinforces the provisions of these three important statutes. Implementation of this and similar programs -- as reinforced by the new laws -- will continue to strengthen the way federal agencies protect their networks, systems and data from ever-evolving threats in cyberspace.

The efforts of the government to build a more effective cybersecurity posture is evident in the implementation of these three cybersecurity bills, which taken together will foster a more effective cybersecurity dynamic. By openly collaborating across agencies, coordinating incident response, and increasing the pool of cybersecurity professionals, the government will grow its capacity to operate in cyberspace at a rapid rate. Cohesive implementation of these bills will enable agencies to mitigate cybersecurity risks and proactively plan for vulnerabilities, providing a fountain for increasingly responsive tactics to address cyber threats successfully.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.