Government Technology Insider
  • About
  • State & Local
  • Civilian
  • Defense & IC
SUBSCRIBE
No Result
View All Result
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
Government Technology Insider
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
No Result
View All Result
Government Technology Insider
No Result
View All Result
Home Cybersecurity

NIST Director, Patrick Gallagher, Discusses Headway on Cybersecurity Framework (Part 2)

by GTI Editors
August 14, 2013
in Cybersecurity
Reading Time: 4 mins read
A A
Share on FacebookShare on Twitter

In part one of our exclusive interview with Patrick Gallagher, Director of the Department of Commerce’s NIST, he provides us with an overview of the cybersecurity framework that he is heading.  The framework is based off of public and private best practices as directed by President Obama’s executive order.  In the second half of this interview, we discuss mandated standards versus a voluntary framework, educating organizations of cyber gaps in security and securing buy-in from senior decision makers.

Q: Currently, the framework is voluntary.  Wouldn’t mandated standards or best practices be more effective?

A: Not necessarily. The U.S. system of voluntary standards works because businesses have a stake in developing them, and they work together to ensure the standards are aligned with business needs and processes. As an example, most product safety standards in the United States are fully managed by industry. We’ve seen that industry is quite capable of adopting muscular conformity assessment tools to assure themselves that they are complying with their own standards and protocols – addressing performance issues themselves.

Fundamental to the approach of the framework is maintaining the ability for our U.S. companies to be competitive worldwide and to ensure that this framework can be accepted globally. While all governments have an interest in protecting their citizens, they also have an interest in avoiding fragmented and unpredictable rules that frustrate innovation, the free flow of information, and the broad commercial success of the online environment. Businesses know their needs, know their technologies and challenges, and are in the best position to solve these challenges. Our role is to bring everyone together to facilitate the conversation.

Eventually, we want industry to take ownership of the framework and update it themselves, ensuring it will be dynamic and evolving with the threats. If they identify areas where new or improved standards are needed, NIST is here to support the technical quality of those standards.

Q: If the status quo is based on voluntary adoption of standards and best practices and there are many current gaps in protection from cyber attacks, how will NIST issuing this new framework spur increased voluntary compliance and implementation of these techniques?

A: The initial framework will have two characteristics; it will show us where we have a good base of existing standards and best practices, and where we have gaps. This process is revealing those gaps and bringing industry together to agree on how to prioritize them, so the framework will provide an action list for the future. If we can call attention to the gaps and get industry working on them together, that’s a powerful outcome.

The framework needs to be an ongoing, industry-intensive effort to ensure it keeps up with changing technology and changing threats, and aligns with business needs and practices. If good cyber security performance becomes equivalent to good business, industry will use it. It is becoming much more clear that this is an issue that affects their bottom lines, their global competitiveness, and in some cases, their very ability to operate.

Q: How will the framework help companies ensure their senior leaders are fully aware of their organization’s cyber risks and how they are managed in relation to their overall risk environments?

A: At our July workshop, we gained consensus for including in the framework a section for senior executives and others on using this framework to evaluate an organization’s preparation for potential cybersecurity-related impacts on their assets and on the organization’s ability to deliver products and services. By using this framework, senior executives can manage cybersecurity risks within their enterprise’s business plans and operations. I don’t underestimate the importance or the magnitude of the task in raising awareness among the most senior executives across many sectors, and this will require a sustained communications effort that many stakeholders will need to carry out in conjunction with release of the framework.

Q: Anything else to add?

A: Developing this Cybersecurity Framework is a difficult, complex task. We need the full support and participation of all sectors of business and industry providing critical infrastructure to do this right.

Even if a company or other organizations has not been involved in this process so far, I invite them to look hard at their own cybersecurity best practices and protections and see what they may have to bring to the table.  Then let us hear about them, and consider joining us in Dallas in September.  Our economy – and our overall security — depends on reliable, secure cyber systems. Help us to make this framework as useful as possible and we’ll all benefit.

Tags: critical infrastructure protectioncyber riskscyber threatscybersecurity frameworkcybersecurity risksDepartment of CommerceDr. Patrick GallagherNational Institute of StandardsNISTPatrick Gallagher

RELATED POSTS

Four Smart Strategies to Combat the Log4j Security Vulnerability
Cybersecurity

Four Smart Strategies to Combat the Log4j Security Vulnerability

June 6, 2022
Alerts
Civilian

Identify, Protect, Detect, Respond, and Recover: How Alerts Empower Agencies in a Tough Cybersecurity Environment

February 17, 2022
FedRAMP solutions
Civilian

In 2022, Agencies Will Return Their Focus to FedRAMP Solutions

January 11, 2022
Please login to join discussion

TRENDING NOW

  • Advana

    Meet Advana: How the Department of Defense Solved its Data Interoperability Challenges

    5353 shares
    Share 2141 Tweet 1338
  • Customer and Industry Partnerships Are Helping Deliver 5G Solutions to Federal Agencies

    102 shares
    Share 41 Tweet 26
  • For the Army to Reach Modernization Goals, a Tactical Data Fabric is Crucial

    40 shares
    Share 16 Tweet 10
  • Design Secure Application Software That Transforms Government Agencies

    11 shares
    Share 4 Tweet 3
  • 2022 Government Investigations Technology Guide Discusses Nine Factors Investigators Should Consider in Technology Solutions

    12 shares
    Share 5 Tweet 3

CONNECT WITH US

MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Advertisement Banner Advertisement Banner

BECOME AN INSIDER

Get Government Technology Insider news and updates in your inbox.

Strategic Communications Group is a digital media company that helps business-to-business marketers drive customer demand through content marketing, content syndication, and lead identification.

Related Communities

Financial Technology Today
Future Healthcare Today
Modern Marketing Today
Retail Technology Insider
Today’s Modern Educator

Quick Links

  • Home
  • About
  • Contact Us

Become a Sponsor

Strategic Communications Group offers analytics, content marketing, and lead identification services. Interested?
Contact us!

© 2021 Strategic Communications Group, Inc.
Privacy Policy      |      Terms of Service

No Result
View All Result
  • Home
  • About Government Technology Insider
  • State & Local
  • Civilian
  • Defense & IC
  • Categories
    • Acquisition
    • AI & Data
    • Digital Transformation
    • Cybersecurity
    • Hybrid Work
  • Contact Us