Creating a National Framework for Cybersecurity: An Analysis of Issues and Options

Abstract

Even before the terrorist attacks of September 2001, concerns had been rising among security experts about the vulnerabilities to attack of computer systems and associated infrastructure. Yet, despite increasing attention from federal and state governments and international organizations, the defense against attacks on these systems has appeared to be generally fragmented and varying widely in effectiveness. Concerns have grown that what is needed is a national cybersecurity framework -- a coordinated, coherent set of public- and private-sector efforts required to ensure an acceptable level of cybersecurity for the nation. As commonly used, "cybersecurity" refers to three things: measures to protect information technology; the information it contains, processes, and transmits, and associated physical and virtual elements; the degree of protection resulting from application of those measures; and the associated field of professional endeavor. Virtually any element of cyberspace can be at risk, and the degree of interconnection of those elements can make it difficult to determine the extent of the cybersecurity framework that is needed. Identifying the major weaknesses in U.S. cybersecurity is an area of some controversy. However, some components appear to be sources of potentially significant risk because either major vulnerabilities have been identified or substantial impacts could result from a successful attack. There are several options for broadly addressing weaknesses in cybersecurity. They include adopting standards and certification, promulgating best practices and guidelines, using benchmarks and checklists, use of auditing, improving training and education, building security into enterprise architecture, using risk management, and using metrics.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Feb 22, 2005
Accession Number
ADA463076

Entities

People

  • Eric A. Fischer

Organizations

  • Library of Congress

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Computer Crime
  • Computer Network Security
  • Computer Networks
  • Computer Program Reliability
  • Computer Programming
  • Computer Programs
  • Computer Security Techniques
  • Computers
  • Congress
  • Cyberattacks
  • Cybersecurity
  • Environmental Protection
  • Information Systems
  • Malware
  • Operating Systems
  • Personnel Management
  • Reliability

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Defense Acquisition Program Management
  • Strategic Security Studies

Technology Areas

  • Cyber