白宫-拜登总统刚刚签署了一份行政命令:改进国家网信安全(英文)-2021.5-21页_347kb
报告摘要
Executive Order on Improving the Nation's Cybersecurity (May 12, 2021) Summary
Core Content
The Executive Order on Improving the Nation's Cybersecurity, issued on May 12, 2021, outlines a comprehensive strategy to enhance the cybersecurity posture of the United States government. It emphasizes the need for improved threat information sharing, modernization of federal cybersecurity practices, and strengthening the security of the software supply chain.
Main Objectives
- Enhance Cybersecurity Capabilities: The Federal Government must improve its ability to identify, deter, protect against, detect, and respond to cyber threats.
- Standardize Cybersecurity Contract Requirements: To streamline compliance and improve security across federal agencies.
- Modernize Federal IT Infrastructure: Promote the use of secure cloud services and implement Zero Trust Architecture.
- Secure Software Supply Chain: Ensure the integrity and security of software used by the government, with a focus on "critical software."
- Improve Public Awareness of IoT and Software Security: Through labeling programs and public education.
Key Measures
1. Removing Barriers to Threat Information Sharing
- Contractor Reporting Obligations: Service providers must report cyber incidents promptly and share relevant data with agencies like CISA and FBI.
- Time Constraints: Severe incidents must be reported within 3 days of detection.
- Standardization of Contract Language: The FAR Council will review and update contract language to ensure consistent cybersecurity requirements across agencies.
- Collaboration Frameworks: Agencies and CSPs must collaborate on incident response and threat detection.
2. Modernizing Federal Cybersecurity
- Cloud Migration: Agencies must prioritize cloud technology adoption and align with Zero Trust Architecture.
- Multi-Factor Authentication and Encryption: Must be adopted by all FCEB agencies within 180 days.
- FCEB Cybersecurity Collaboration: A framework will be established for agencies to share cybersecurity and incident response information.
- FedRAMP Modernization: Includes automation, digitization, and improved communication with CSPs.
3. Enhancing Software Supply Chain Security
- SBOM Requirements: All software products must include a Software Bill of Materials (SBOM) for transparency.
- Critical Software Definition: A clear definition of "critical software" will be established based on its function, access level, and potential impact.
- Security Standards for Critical Software: Guidance will be issued on secure development practices, including least privilege, network segmentation, and proper configuration.
- Compliance with New Standards: Agencies must comply with these standards for software procured after the order date, with possible extensions or waivers.
4. Public Education and Labeling Programs
- IoT Cybersecurity Labeling: NIST will develop criteria for a consumer labeling program to inform the public about IoT device security.
- Secure Software Development Labeling: A similar program will be developed for consumer software, reflecting secure development practices and testing levels.
- Pilot Programs: Inspired by consumer product labeling, these programs aim to educate the public and incentivize manufacturers.
Key Timelines and Responsibilities
| Section | Timeline | Responsible Party |
|---|---|---|
| Sec. 2 | 60 days | OMB, CISA, NSA, DOJ, DHS |
| Sec. 2 | 90 days | OMB, CISA, NSA, DOJ, DNI |
| Sec. 2 | 120 days | OMB, CISA, FBI |
| Sec. 3 | 60 days | Agency heads |
| Sec. 3 | 90 days | CISA, DOJ, FBI, FedRAMP |
| Sec. 3 | 180 days | OMB, CISA, FedRAMP |
| Sec. 4 | 30 days | NIST |
| Sec. 4 | 180 days | NIST |
| Sec. 4 | 360 days | NIST |
| Sec. 4 | 90 days | NIST, CISA, DOJ |
| Sec. 4 | 60 days | NIST, CISA, OMB |
| Sec. 4 | 30 days | OMB |
| Sec. 4 | 1 year | CISA, OMB, DOJ, NIST |
| Sec. 4 | 270 days | NIST, FTC |
Conclusion
This Executive Order represents a significant step toward improving the cybersecurity of the U.S. federal government and its digital infrastructure. It mandates collaboration between the government and private sector, promotes the adoption of modern cybersecurity practices, and enhances transparency and security in the software supply chain. The emphasis on timely reporting, standardized requirements, and public education underscores a holistic approach to national cybersecurity.
试读结束,高清完整版pdf/doc/ppt,请点下载