Most Popular Stories
- Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts
- Air traffic control training gaps will be exacerbated by NextGen, says OIG
- Federal Aviation Administration
- FAA reauthorization would create NextGen czar UPDATED
- NIC criticizes transfers of youths to the adult justice system
Events
- Learn With Your Peers at the Federal Senior Management Conference
April 15-18 — Cambridge, MD - V2X for Auto Safety and Mobility USA 2012
March 20-21, 2012 — Novi, MI - TECHEXPO Top Secret Career Fair
February 29, 2012 — Colorado Springs, CO 10am - 3pm - AFCEA Bethesda Monthly Breakfast Series
February 24, 2012 — Bethesda, MD
Sponsored Links
Free Newsletter
HOT TOPICS >> Cloud computing | Cybersecurity | Gov 2.0 | Fiscal 2013 | Mobile | Transparency | GAO reports
AGENCY NEWS >> Defense | NASA | Homeland Security | NIST | OMB | Veterans Affairs | NARA | GSA
Latest News
Free Newsletter
About | View Sample | Privacy
Popular Topics
Whitepapers
- Cloud Computing: Threat or opportunity for VARs and MSPs? Special focus on cloud collaboration and messaging
- Innovative Solutions for Database and DBA Management
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Storage Consolidation: Best of Both Worlds
- Efficiency On Demand
- Virtual Game Changer
Critical infrastructure companies drowning in cybersecurity guidance, says GAO
The Homeland Security Department isn't doing enough to distill, promote and disseminate cybersecurity guidance to entities within the critical-infrastructure sectors DHS is required to assist under Homeland Security Presidential Directive 7, according to the Government Accountability Office.
There is no shortage of cybersecurity guidance for entities operating in these sectors, according to a GAO report (.pdf) dated Dec. 9, 2011 but released publicly Jan. 9. In fact, the GAO says the opposite is the problem. Given the "plethora of guidance available, individual entities within the sectors may be challenged in identifying the guidance that is most applicable and effective," the report says.
Regulatory entities require information security compliance in some critical infrastructure sectors that are under the purview of federal law, regulation or mandatory standards. Many critical infrastructure companies also follow National Institute of Standards and Technology guidance or recommendations from their respective standards bodies, such as the International Organization for Standardization, International Electrotechnical Commission or the International Telecommunication Union, says the report.
Rather than create additional guidance, DHS and the other sector-specific agencies should identify the key, existing guidance applicable to or widely used in each sector, recommend report authors.
GAO does not specify how the implementation of cybersecurity guidance should occur, only saying it could be done "through a variety of mechanisms," such as regulatory enforcement or through business incentives. However, responsible federal entities should "take additional steps to promote the most applicable and effective guidance throughout the sectors."
For more:
- download GAO-12-92 (.pdf)
Related Articles:
E.U. body outlines broad security goals for industrial control systems
DHS releases cyber strategy framework
Related Stories
- Federal government has dot-secure Internet domain under consideration
- Commerce: Private sector should adopt codes of conduct to strengthen cybersecurity
- NIST instructs agencies on cyber-incident response
- DOJ seeks to expand Computer Fraud and Abuse Act
- NIST, DHS, solicit information on possible ISP botnet 'code of conduct'
- DHS official: Security vulnerabilities present in technology supply chain
- House subcommittee criticizes White House cybersecurity proposal
- Reitinger: Cybersecurity bill applies 'light touch' to private sector regulation
- White House unveils proposed cybersecurity legislation
- Napolitano: Cybersecurity policy should set goals without being prescriptive
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |


