战略与国际研究中心-Cybersecurity-Policy-Review-Recommendations-Comparison-Chart_4页_132kb
报告摘要
CSIS 60-Day Review on Cybersecurity: Summary
Core Content Overview
The CSIS 60-Day Review outlines a comprehensive set of recommendations aimed at enhancing the United States' cybersecurity posture. It emphasizes the need for a unified, strategic approach to cybersecurity, involving both government and private sector collaboration, modernization of legal and regulatory frameworks, and the development of a skilled cybersecurity workforce. The review also touches on the importance of identity management, secure communications, and research and development in securing the nation's digital infrastructure.
Main Recommendations and Key Points
1. National Security Strategy for Cyberspace
- Core Content: A comprehensive national security strategy for cyberspace is needed to secure the country's information and communications infrastructure.
- Main Viewpoints:
- The President should declare cyberspace infrastructure as a strategic national asset.
- Cybersecurity should be a national security priority, focusing on protection, deterrence, prevention, detection, defense, and rapid recovery from cyber incidents.
2. Public Doctrine for Cybersecurity
- Core Content: The President should establish a public doctrine for cybersecurity that defines the nation's stance on protection and deterrence.
- Main Viewpoints:
- The President's May 29 speech emphasized the need to treat digital infrastructure as a national security asset.
- The doctrine should guide the nation's approach to cybersecurity in terms of policy and action.
3. Broad National Consultation
- Core Content: Cybersecurity strategy and deterrence should be discussed with a wide range of experts and stakeholders.
- Main Viewpoints:
- The review process was transparent and included consultations with private sector groups.
- Involving a broad community ensures that diverse perspectives are considered in shaping cybersecurity policy.
4. Cyber Advisor and NSC Directorate
- Core Content: The President should appoint a cyber advisor and establish a cyber directorate within the National Security Council (NSC).
- Main Viewpoints:
- The advisor should have direct access to the President.
- The NSC directorate should absorb the functions of the Homeland Security Council (HSC).
- No new EOP office is created for cybersecurity.
5. Coordination of Operational Activities
- Core Content: Existing agencies should retain responsibility for their operational activities, but under the oversight of the NSC and a new EOP office.
- Main Viewpoints:
- The White House will coordinate policy and agency implementation.
- The Office of Management and Budget (OMB) will maintain budget oversight in coordination with the NSC and other relevant entities.
6. Regulation of Cyber Infrastructure
- Core Content: The National Office for Cyberspace (NOC) should work with agencies and NIST to develop standards and guidance for securing critical cyber infrastructure.
- Main Viewpoints:
- Consideration of liability adjustments, indemnification, tax incentives, and regulatory requirements is recommended.
- No specific mention of SCADA or Industrial Control Systems in the review.
7. Identity Management
- Core Content: Strong authentication and verification of identity should be a mandatory requirement for critical cyber infrastructures.
- Main Viewpoints:
- The Federal government should collaborate with industry and privacy groups to develop a cybersecurity-based identity management strategy.
- There is no specific mention of consumer use of strong credentials, but the review supports the use of federal credentials by emergency responders and critical infrastructure operators.
8. Modernize Legal Authorities
- Core Content: The President should direct the Department of Justice to update laws related to criminal investigations of online crime.
- Main Viewpoints:
- The review supports identifying gaps in law enforcement and investigative authorities.
- Any new legal authorities must align with the protection of civil liberties and privacy rights.
Additional Key Recommendations
9. FISMA Modernization
- Core Content: The President should work with Congress to update the Federal Information Security Management Act (FISMA) to use performance-based security measurements.
- Main Viewpoints:
- The Administration should update and strengthen FISMA to improve cybersecurity governance.
10. Unified Cybersecurity Authority
- Core Content: Legislation should replace the current split between civilian and national security systems with a risk-based approach.
- Main Viewpoints:
- The review highlights the need for a unified structure to handle cybersecurity incidents.
- Consolidation of authorities may require new legislation.
11. Cyber Education and Workforce Development
- Core Content: The President should establish training programs and career paths for the federal cyber workforce.
- Main Viewpoints:
- The NOC should work with the Office of Personnel Management and the National Science Foundation (NSF) to develop education and training initiatives.
- The goal is to attract and retain cybersecurity expertise in the federal government.
12. Cybersecurity R&D Coordination
- Core Content: The NOC should coordinate cybersecurity research and development (R&D) with the Office of Science and Technology Policy (OSTP).
- Main Viewpoints:
- A framework for R&D strategies should be developed, focusing on game-changing technologies.
- The aim is to increase cybersecurity R&D resources and innovation.
Summary of Implementation Status
| Recommendation | Status | Notes |
|---|---|---|
| 1-3 | ✅ | Implemented or partially addressed |
| 4-7 | ✅ | Implemented or partially addressed |
| 8-10 | ✔️ | Recommended but not fully implemented |
| 11-12 | ✔️ | Recommended but not fully implemented |
Conclusion
The CSIS 60-Day Review provides a roadmap for strengthening the U.S. cybersecurity framework through strategic planning, legal modernization, interagency coordination, and workforce development. While some recommendations have been implemented or are under consideration, others remain as policy goals requiring further legislative or executive action. The review underscores the importance of a unified, proactive, and collaborative approach to securing the nation's digital infrastructure.
试读结束,高清完整版pdf/doc/ppt,请点下载