Critical Infrastructure Protection: Additional Actions Needed to Identify Framework Adoption and Resulting Improvements

Abstract

Cyber threats to the nations critical infrastructure (e.g., financial services and energy sectors) continue to increase and represent a significant national security challenge. To better address such threats, NIST developed, as called for by federal law, a voluntary framework of cybersecurity standards and procedures. The Cybersecurity Enhancement Act of 2014 included provisions for GAO to review aspects of the framework. The objectives of this review were to determine the extent to which (1) SSAs have developed methods to determine framework adoption and (2) implementation of the framework has led to improvements in the protection of critical infrastructure from cyber threats. GAO analyzed documentation, such as implementation guidance, plans, and survey instruments. GAO also conducted semi-structured interviews with 12 organizations, representing six infrastructure sectors, to understand the level of framework use and related improvements and challenges. GAO also interviewed agency and private sector officials. What GAO Recommends GAO is making ten recommendationsone to NIST on establishing time frames for completing selected programsand nine to the SSAs to collect and report on improvements gained from using the framework. Eight agencies agreed with the recommendations, while one neither agreed nor disagreed and one partially agreed. GAO continues to believe that all ten recommendations are warranted.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Feb 01, 2020
Accession Number
AD1105614

Entities

Organizations

  • United States Government Accountability Office

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Acquisition
  • Agriculture
  • Best Practices
  • Commerce
  • Computer Security Techniques
  • Congress
  • Cyber Threats
  • Cybersecurity
  • Department Of Defense
  • Department Of Homeland Security
  • Environmental Protection
  • Governments
  • Homeland Security
  • Information Exchange
  • Information Security
  • Information Systems
  • Infrastructure
  • Law
  • National Security
  • Public Health
  • Risk Management
  • Security
  • Standards
  • United States
  • United States Government

Readers

  • Defense Technology Research and Development.
  • Government Contracting/Procurement.
  • Organizational Process Management (OPM).

Technology Areas

  • Cyber