Improving Federal Cybersecurity Governance Through Data-Driven Decision Making and Execution

Abstract

Although efforts are underway through Information Security Continuous Monitoring initiatives to improve situational awareness and risk mitigation at the operational level, the federal government must make better enterprise-level cybersecurity decisions in the shortest time possible. This report outlines an approach called Data Driven Cybersecurity Governance Decision Making. This approach leverages the Observe, Orient, Decide, Act (OODA) loop used by the U.S. Department of Defense to enable decision makers at the strategic levels of government to best set the conditions for success at the point of execution. To best target the unique considerations of enterprise decision makers, this report discusses the difference between cybersecurity governance and cybersecurity operations. Within this context, it describes best practices in collecting and analyzing authoritative data present in the federal space to develop a level of situational awareness tailored to decision makers needs in a cybersecurity governance scorecard. Cybersecurity governance decision makers can leverage this enhanced situational awareness to support a data-driven decision-making process that targets root causes of the problems facing the Federal government enterprise. Finally, the report discusses key considerations to ensure success at the point of execution based on work performed in the Observe, Orient, and Decide phases of the OODA Loop.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Sep 01, 2015
Accession Number
AD1044987

Entities

People

  • Anne Connell
  • Brian D. Wisniewski
  • Constantine Cois
  • Douglas Gray
  • Erik Ebel
  • Julia H. Allen
  • Marie Vaughan
  • Michael Riley
  • Robert W. Stoddard
  • William Gulley

Organizations

  • Carnegie Mellon University

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Engineered Resilient Systems
  • Human Systems

DTIC Thesaurus Topics

  • Business Administration
  • Computational Science
  • Cybersecurity
  • Data Mining
  • Data Science
  • Data Visualization
  • Databases
  • Department Of Defense
  • Information Science
  • Information Systems
  • Knowledge Management
  • Management Personnel
  • National Governments
  • National Security
  • Organizational Structure
  • Situational Awareness
  • United States Government

Fields of Study

  • Computer science

Readers

  • Defense Acquisition Program Management
  • Team-Based Human-Centered Cognitive Task Decision Making and Information Performance.

Technology Areas

  • Cyber
  • Space