Version 2 of the National Cybersecurity Strategy and Implementation Plan has been released
In March 2023, the U.S. administration released the first National Cybersecurity Strategy Implementation Plan (NCSIP). This was presented as a government action plan consisting of 27 strategic objectives prioritizing critical initiatives to protect national security from ongoing cyber threats.
Recently, 31 initiatives have been added to this plan, and a number of federal agencies have been identified to lead these efforts moving forward.
Goals of the National Cybersecurity Strategy Implementation Plan
The NCSIP outlines several critical implementation actions to improve the U.S. national cybersecurity posture. This effort involves collaboration with various industries and supporting agencies to regulate and enforce new standards in cybersecurity best practices while supporting the development of safer technologies.
The five core pillars established by the NCSIP focus on the following areas:
- Defending critical infrastructure by establishing standardized frameworks.
- Disrupting threat actors by working with interagency partners and proposing legislation to govern cloud providers.
- Encouraging safer software development practices by exploring software liability frameworks.
- Adopting network security best practices and promoting memory-safe programming languages.
- Expanding international partnerships to establish more flexible foreign assistance mechanisms.
What does the new version of the plan do?
The latest version of the plan, released on May 7, 2024, introduces 31 additional initiatives that have been included and grouped within the five core pillars.
Below are some of the most recent additions:
Initiatives for improving the resilience of critical infrastructure
New initiatives have been added that address actions designed to promote better cybersecurity practices in a range of sectors, including healthcare and water and wastewater services.
In the healthcare sector, the White House will work with the National Institute of Standards and Technology (NIST) to create a Department of Health and Human Services (HHS)-wide strategy to enforce greater accountability in this area.
In the water and wastewater services sector, the U.S. Department of Agriculture will work with the Environmental Protection Agency (EPA) to promote cybersecurity technical assistance, education and training.
Leveraging more collaborations to help avoid large-scale cyberattack campaigns
The second pillar of the NCSIP, focused on “disrupting and dismantling threat actors,” has seen several new additions regarding collaboration to reduce the impact and likelihood of larger cyberattack campaigns.
Implementation timeframes have now been specified for the initial 2023 Department of Defense (DoD) Cyber Strategy that was put in place last year, as well as a renewed focus on collaborating with private-sector entities to improve the speed and utility of cybersecurity efforts.
Ensuring the production of safer digital products
Another part of the NCSIP is designed to put more responsibility on influential digital brands to create more secure products. The plan’s latest version adds a new initiative for the State Department to work with the Joint Ransomware Task Force, the Department of Justice and other U.S. interagency partners to deny ransomware attackers safe havens in foreign countries.
There are also plans to update the National Privacy Research Strategy in collaboration with the Office of Science and Technology Policy (OSTP) to protect the data privacy of individuals when personal data is stored and accessed for large-scale data analytics.
Implementation of the National Cyber Workforce and Education Strategy
A key pillar of the NCSIP is securing next-generation technologies and infrastructure by making smarter investments in cybersecurity training and support.
The new plan introduces the National Cyber Workforce and Education Strategy and calls for reporting on its progress over the next year. This strategy is designed to help develop a playbook to improve cybersecurity workforces and make it easier for workers to enter the field.
Many other initiatives have been added to this latest version of the NCSIP. While deadlines for each initiative vary, most have deadlines stretching through fiscal year 2025, with some initiatives planned for execution by the end of this year.
How will these new initiatives impact the private sector?
The NCSIP is designed to be a dynamic plan with expectations that it should be updated yearly. Version 2 of this plan represents the first annual update and shouldn’t surprise organizations.
Private sector organizations should expect increased collaboration efforts with government agencies as these new initiatives roll out and should keep themselves updated as the deadlines for critical objectives approach.
While many of the new initiatives impact specific industries, there may also be sector-wide impacts that will require all private sector organizations to quickly adapt to the new standards being put in place, with guidance from supporting agencies and industry experts.
More from News
May 31, 2024
How has Executive Order 14028 affected federal cybersecurity so far?
3 min read – Recently, the United States Government Accountability Office issued an update on the progress of Executive Order 14028, Improving the Nation’s Cybersecurity. In 2021, the White House identified 55 leadership and oversight requirements that needed to be met to improve cybersecurity in federal IT systems, with all systems needing to meet or exceed the standard outlined. Executive Order (14028) on Improving the Nation’s Cybersecurity elaborated on the reasons for the requirement, stating that the “prevention, detection, assessment and remediation of cyber…
May 30, 2024
Inside the DHS’s AI security guidelines for critical infrastructure
3 min read – Last year, Executive Order 14110 (Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence) stated that “Artificial intelligence (AI) holds extraordinary potential for both promise and peril.” In response to this reality, the United States Department of Homeland Security (DHS) recently released guidelines to help critical infrastructure owners and operators develop AI security and safety. The DHS guidelines stem from insights gained from CISA’s cross-sector analysis of AI risk assessments completed by Sector Risk Management Agencies (SRMAs) and relevant…
May 29, 2024
ONCD releases 2024 Report on the Cybersecurity Posture of the U.S.
4 min read – On May 7, the Office of the National Cyber Director (ONCD) released the 2024 Report on the Cybersecurity Posture of the United States. This new document is a report card on how well cyber policy followed the guidelines set by the National Cybersecurity Strategy, introduced in March 2023. Here’s what you need to know about the newly released report. Fundamental shifts in cyber roles Over the past year, the U.S. national cybersecurity posture was driven by the 2023 National Cybersecurity…
Topic updates
Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today
This post was originally published on the 3rd party site mentioned in the title of this this site