The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Report on Securing and Growing the Digital Economy
Report on Securing and Growing the Digital Economy artwork

012 - Imperative 5 Better Equip Government to Function Effectively and Securely in the Digital Age

Report on Securing and Growing the Digital Economy · 2026-03-05 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

18 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality4 / 20
Guest Caliber1 / 20
Specificity & Evidence7 / 20
Conversational Craft0 / 20

The federal government faces dual cybersecurity imperatives: securing its own IT operations across civilian agencies and defending the nation's private sector infrastructure from cyber threats. The Commission's recommendations emphasize consolidating civilian agency network connections into a single, monitored network administered by a new Cybersecurity and Infrastructure Protection Agency, with oversight from the Federal CIO and CISO. A critical challenge is federal IT modernization - too many agencies operate legacy systems patched reactively rather than systematically upgraded. The report recommends establishing an expanded Information Technology Modernization Fund (ITMF) with rolling ten-year strategic plans, shifting from reactive patch cycles to proactive five-to-seven-year technology refresh rates. Additionally, the federal government should transition from prescriptive compliance checklists to enterprise risk management (ERM) guided by OMB's ERM Program and NIST's Cybersecurity Framework. Leadership restructuring is equally important: elevating the Cybersecurity Coordinator to Assistant to the President status (equal to Homeland Security and Counter Terrorism roles), clarifying roles of the Federal CIO, CISO, and Senior Advisor for Privacy, and integrating cybersecurity metrics with annual budget processes. This comprehensive approach would position the federal government as a cybersecurity leader rather than perpetually playing catch-up.

Key takeaways

  • →Federal agencies should consolidate network connections into a single managed network operated by a new Cybersecurity and Infrastructure Protection Agency with baseline security performance requirements and authority to disconnect non-compliant entities.
  • →The government must expand the Information Technology Modernization Fund (ITMF) and implement rolling ten-year strategic IT investment plans to accelerate technology refresh cycles from 10+ years to 5-7 years, addressing critical legacy system vulnerabilities.
  • →Federal agencies must adopt NIST's Cybersecurity Framework and OMB's Enterprise Risk Management approach instead of checklist-based compliance, integrating cybersecurity as a core mission component rather than auxiliary function.
  • →The President should elevate cybersecurity to a top national security priority equal to counter-terrorism by appointing an Assistant to the President for Cyber Security and holding cabinet members accountable for their agencies' cyber posture.
  • →The General Services Administration (GSA) should lead IT procurement reform, requiring CISO approval for security-related investments and adopting rapid acquisition models like DIIUX and DARPA to reduce delays in obtaining critical security products and services.

In this episode

  1. 1Government Cybersecurity Challenges and National Priority
  2. 2Consolidating Federal Network Infrastructure and Operations
  3. 3Technology Modernization and Legacy IT Refresh
  4. 4Transitioning to Enterprise Risk Management Approach
  5. 5Restructuring Executive Leadership for Cybersecurity
  6. 6Clarifying Federal CIO and CISO Roles and Responsibilities

Mentioned

Commission on Enhancing National CybersecurityOffice of Personnel ManagementDepartment of DefenseGeneral Services AdministrationOffice of Management and BudgetNISTDepartment of Homeland SecurityDefense Innovation Unit ExperimentalDefense Advanced Research Projects AgencyCybersecurity FrameworkInformation Technology Modernization FundFederal Information Security Modernization Act

Topics in this episode

CybersecurityNIST Cybersecurity FrameworkCybersecurity FrameworkGeneral Services Administration (GSA)Information Technology Modernization Fund (ITMF)Enterprise Risk Management (ERM)Federal Chief Information Officer (CIO)Federal Chief Information Security Officer (CISO)Office of Personnel Management (OPM) breachDefense Innovation Unit Experimental (DIIUX)Defense Advanced Research Projects Agency (DARPA)futureeconomygovernmentdefense

Questions this episode answers

What should the federal government do to consolidate IT infrastructure across agencies?

The federal government should establish a program to consolidate all civilian agency network connections and those of appropriate government contractors into a single consolidated network administered by a new Cybersecurity and Infrastructure Protection Agency, with security performance requirements that agencies must meet to remain connected.

How can the federal government modernize its legacy IT systems more effectively?

The government should expand the Information Technology Modernization Fund (ITMF) to enable agencies to spread technology investment costs over predetermined periods (5-7 years instead of 10+ years), coupled with a rolling ten-year strategic IT investment plan integrated into the capital planning process.

Why should the federal government shift from compliance checklists to enterprise risk management?

Checklist-based compliance treats cybersecurity as auxiliary to agency missions and fails to address systematic risk, whereas enterprise risk management approaches like NIST's Cybersecurity Framework integrate cybersecurity as a core function and put it on par with other enterprise-wide risks.

What organizational changes are needed in the Executive Office of the President for cybersecurity?

The President should elevate the Cybersecurity Coordinator to an Assistant to the President position reporting through the National Security Adviser, on par with Homeland Security and Counter Terrorism roles, to provide top-level leadership and coordination of federal cyber protection programs.

How should federal IT procurement be reformed to improve cybersecurity?

The GSA should reform federal procurement requirements to require CISO approval in advance for all security-related IT investments, integrate technologists with acquisition experts, and explore rapid acquisition models like the Defense Innovation Unit Experimental (DIIUX) and DARPA's rapid acquisition programs to decrease procurement delays.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is a straightforward reading of government policy recommendations with minimal novel analysis or surprising claims. Most content consists of restating framework definitions, listing organizational structures, and repeating standard cybersecurity best practices (modernization, risk management, consolidation) without interrogating why these recommendations have repeatedly failed or offering mechanism-level insight into implementation barriers.

The government has a serious legacy IT problem. Too many agencies are patching systems and hoping that the latest fix will keep their older systems working and secure.
Cyber Security must be made a national security priority equal to counter terrorism and protection of the homeland.

Originality

4 / 20

This is essentially a recitation of established policy frameworks (NIST Cybersecurity Framework, Risk Management Framework, Federal Information Security Modernization Act). The recommendations - consolidate networks, modernize IT, adopt enterprise risk management, establish clear leadership - are conventional wisdom in government cybersecurity circles and contain no contrarian or first-principles thinking.

federal agencies should be required to use the Cybersecurity Framework as a common standard to evaluate their cybersecurity posture
The government needs to modernize and to ensure that this modernization can be sustained at a faster pace.

Guest Caliber

1 / 20

This is not an interview or conversation with practitioners. It is a narrated government report read aloud by a voice actor (Maria Casper). No guest, operator, or subject matter expert is present to discuss their experience implementing these recommendations. The content is institutional policy language, not practitioner testimony.

This is a LibriVox recording.
End of Section eleven. Recording by Maria Casper

Specificity & Evidence

7 / 20

The episode references specific government entities (GSA, OMB, NIST, DHS, OPM) and a named past breach (OPM 2015), plus mentions concrete funding amounts (3.1 billion for ITMF) and timeframes (100 days, 180 days). However, it lacks case studies of implementation success or failure, concrete metrics for measuring the recommendations' effectiveness, and specific examples of how private-sector approaches (mentioned but not detailed) differ or outperform.

as demonstrated by the Office of Personnel Management OZERPM breach in twenty fifteen
the proposal of a three point one billion dollar Information Technology Modernization Fund ITMF

Conversational Craft

0 / 20

There is no conversation, questioning, or interaction. This is a one-directional narration of a formal government report with no host pushback, follow-up questions, or exploration of tensions. The format provides no opportunity for conversational depth, and the source material itself is prescriptive policy language rather than dialogue.

Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity Imperative five Better equip Government to function effectively and securely in the Digital Age.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

federal83security54agencies52cybersecurity46government46point44cyber40agency35five31information27network23president22action21national20item18requirements18

Episode notes

On April 13, 2016, President Obama established The Presidents Commission on Enhancing National Cybersecurity to devise a comprehensive strategy for safeguarding our cyberspace and the economic foundations built upon it. The commissions final report, published in December 2016, provides a thorough examination of the current state of cybersecurity, anticipates future challenges, and presents actionable recommendations for the incoming Trump administration and future leaders. It emphasizes the critical roles that the military, government, and private sector must play in strengthening our defenses against cyber threats. Join us as we explore the insights and strategies laid out in this pivotal report. - Summary by TriciaG

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

Section eleven of Report on Securing and Growing the Digital Economy. This is a LibriVox recording. All LibriVox recordings are in the public domain. For more information or to volunteer, please visit LibriVox dot org.

Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity Imperative five Better equip Government to function effectively and securely in the Digital Age. The challenge and the way forward. The federal government faces two challenges in cybersecurity. First, it is a major user of information technology in providing essential government services of all types and in all agencies.

The government is therefore highly dependent on a reliable, secure, and connected cyber infrastructure. Second, many federal agencies have specific roles in protecting and defending the country, including its citizens, businesses, and infrastructure, from cyber attack and in responding to catastrophic cyber incidents. In both of these areas, the government has faced challenges, as demonstrated by the Office of Personnel Management OZERPM breach in twenty fifteen. But in the face of rapidly changing information technology capability and a growing dependence on this technology, it is not enough for the next administration to try to play catch up with threats and vulnerabilities.

The next president must ensure that the federal government is a leader in cyber security, both to secure its own operational systems and to carry out its mission to protect and defend our nation's private networks when a major incident occurred. Recent administration efforts, coupled with congressional action, provide a foundation for necessary improvements in how the federal government functions in the digital age and how it manages its own house, but more must be done purposefully and quickly.

Significant cyber incidents and high visibility breaches have underscored the seriousness and urgency of the situation for the federal government and its impact on the rest of the nation. Cyber Security must be made a national security priority equal to counter terrorism and protection of the homeland. If the federal government is to lead, the next president must empower and expect accountability from the officials charged with overseeing implementation of the national strategy.

To drive home this point, the president should be explicit about the priority of cyber security in discussions with his cabinet. In his initial full meeting with these leaders, the president should make clear that they will be held accountable for their agencies cyber security. He also should elevate cyber security responsibilities within the Executive Office of the President. The government must be better organized and better resource for this purpose.

Protecting federal information and systems must be an unquestionable administration priority. Departments and agencies must receive clear direction and necessary resources, and leaders must have the mechanisms to set an enforce policy. Aside from clarifying its responsibilities for operating government agencies and services, the federal government must also explain with greater clarity its mission focus by delineating the roles and responsibilities of government in protecting the private sector.

Recommendation five zero point one. The federal government should take advantage of its ability to share components of the information technology IT infrastructure by consolidating basic network operations. To be effective and secure in the digital age, every organization requires a modern, defensible network architecture. Today, nearly every civilian agency procures and manages its own IT infrastructure, from the connection to the internet to endpoint devices and software.

While this independence enables agencies to optimize how IT supports their mission, it fails to take advantage of certain aspects of the IT infrastructure. That work better at scale when managed as a shared resource. Two areas in particular would benefit providing secure and reliable Internet connectivity to federal agencies and procuring standard devices and services. If basic network access is consolidated into a single agency, high performance network, then connectivity can be provided effectively and efficiently within a framework of robust network security, infrastructure, and support.

The government gains from connecting agencies to the Internet through a centralized, monitored, and trustworthy network environment, and agencies benefit by not having to invest in dedicated network operations and security functions beyond those they need for their local area networks. Action Item five point one point one, the Administration should establish a program to consolidate all civilian agencies network connections, as well as those of appropriate government contractors, into a single consolidated network.

This program and the consolidated network should be administered by the newly established Cyber Security and Infrastructure Protection Agency described in Action Item five point five point two. The new agency should develop and implement a program to provide secure, reliable network services to all civilian government agencies, thereby providing a consolidated network for all dot gov entities. Working closely with the Assistant to the President for cyber security see Action Item five point four point one and the Federal Chief Information Officer CIO.

The agency should establish and monitor security performance requirements that agencies on this consolidated network must meet in order to connect. To protect the integrity of this network, the agency should have the authority to modify or remove connect devices, services, or agencies that fail to meet these requirements. In exchange for meeting these requirements, federal agencies on the network should be guaranteed a high quality connection and a baseline level of performance.

To this end, the new agency administering the network must be responsible for establishing and meeting clear performance standards. Oversight of the consolidated network's performance levels should be provided by the Federal CIO, Federal Chief Information Security Officer CISO, and the CIO Council Recommendation five point two. The President and Congress should promote technology adoption and accelerate the pace at which technology is refreshed within the federal sector. Strengthening cybersecurity in federal operations requires major changes in the way government aid agencies approach the issue.

It requires thorough implementation of improved standards, guidelines, and best practices, as well as a more agile and capable workforce in numbers matched to the size of the task at hand. See multiple action items under Imperative I, including recommendations to develop executive leadership training programs on cyber risk management, as well as specific steps needed to strengthen identity management. IT demands a culture attuned to and rewarded for innovation. The government has a serious legacy IT problem.

Too. Many agencies are patching systems and hoping that the latest fix will keep their older systems working and secure, even though older technologies have much poorer security functionality. The government loses both ways. It introduces substantial vulnerabilities and it fails to benefit from new features and functionality.

In short, the government's refresh rate of reinvestment in dated IT systems is much slower than the rate of innovation and improvement in IT. The government needs to modernize and to ensure that this modernization can be sustained at a faster pace. This modernization will be costly, but it will bring very large gains in security and performance. Modern world class cybersecurity operations that actively manage the kinds of threats faced by federal agencies also require good planning and predictable funding.

Budget planning and acquisition cycles are not aligned with budget authorizations or annual appropriations. Federal IT security budgets should be structured around a multi year strategy to enable more rational planning and opera. To this end, the Executive Branch and Congress should identify cyber security priorities that can be resourced even when federal funding is subject to continuing resolutions. These changes should allow agencies to fully integrate cyber security into overall program funding, rather than addressing them as add on costs.

The administration and Congress must look critically at the disparity between the millions of dollars spent by the federal government on threat mitigation and the billions of dollars spent less cost effectively on IT security and vulnerability mitigation. The true cost of operating IT is not being considered by the federal government. Funding requests should fully account for operating costs rather than just initial procurement costs. The next president should formally announce his intention to increase investment in modernizing federal IT.

The United States stands on the edge of the next generation of information technology innovation, including advances in big data capacity, machine learning, artificial intelligence and new computing fabrics such as quantum and bio computing, but federal agencies will have a hard time taking advantage of those improvements due to constrained resources and inadequate long term planning. Adding to the challenge, it is also crucial that the technologies adopted by federal agencies today not lock these agencies out of the capabilities of tomorrow.

Newer systems should be modular and agile in order to prepare them for the inevitable changes in the future. In addition, the government should take advantage of the opportunity to share aspects of the IT infrastructure by consolidating procurement responsibility for STACKE, endpoint Devices and Services Action Item five point two point one. The administration should expand on the recently proposed Information Technology Modernization Fund ITMF to enable agencies to fund technology investments by spreading costs over a predetermined period of time.

The investments made under this fund should be integrated into a rolling ten year strategic investment plan as part of a budget planning process, similar to the Department of Defense approach short term. An important step in this direction was taken in twenty sixteen with the proposal of a three point one billion dollar Information Technology Modernization Fund ITMF as part of the administration's Cybersecurity National Action Plan. The ITMF would facilitate the retirement, replace, placement, and modernization of legacy IT that is difficult to secure and expensive to maintain.

Agencies would be required to repay funds received from the ITMF over the time needed to refresh new technology, not the period defined by the technology's useful life. This approach results in a more aggressive reinvestment period of five to seven years rather than the current ten plus year time frame. The fund is self sustaining and minimizes large and irregular increases to agency budgets to fund technology reinvestment. Recognizing the urgency of this issue and the opportunity for a major shift in how the government addresses its IT and cybersecurity needs, the Commission recommends expanding that fund so that more agencies can take fuller advantage of this investment mechanism.

It is essential that the federal government devise and adhere to a rolling ten year strategic IT investment plan. Some of the most deeply rooted issues the federal government grapples with in relation to cyber security are tied to the process constraints of the federal budget, which too often lead agencies to repair legacy systems as the default option. These expenditures are reactionary as opposed to the kinds of forward thinking planning that is needed to deliver a fast, reliable, and secure federal IT infrastructure.

The Office of Management and Budget should work with departments and agencies to integrate this longer term planning into the current capital planning and investment control process and update budgetary requirements as needed. Action Item five point two point two. The General Services Administration GSA should lead efforts on d integrating technology more effectively into government operations, working with Congress to reform federal procurement requirements and expanding the use of sharing standard service platforms.

Medium term, beyond the issue of investment planning, the General Services Administration should lead the administration's work with Congress to reform federal procurement requirements for IT related purchases to maximize effectiveness of procurement, and adapt the federal acquisition process to reflect the dynamic and rapidly evolving nature of IT. Specifically, approval by agency CISOs should be required in advance of all IT investments related to the security of agency data and systems, a responsibility not of the GSA but of each agency.

GSA and other agencies should us use integrated teams of technologists and acquisition experts, and GSA should reform the procurement protest regime in order to decrease the delays in obtaining necessary products and services, thereby better managing cybersecurity risk. Additional technology acquisition reforms should be explored. Possible models are the Department of Defences Defense Innovation Unit Experimental DIIUX and the R and D and Rapid Acquisition programs of the Defense Advanced Research Projects Agency DARPA, the Intelligence Advanced Research Projects Activity IRPA, and the Air Force's Rapid Capabilities Office RCO.

Furthermore, GSA should expand the development and use of standard service platforms, for example, endpoint devices, shared data clouds software as a servi servis to provide agencies with high performance infrastructure and tools for their mission while minimizing direct agency responsibility for managing and operating the infrastructure. Greater sharing of services such as web hosting, standard software and common cloud services would enable government to take advantage of its scale to negotiate and obtain higher performance and lower cost to IT equipment and services.

By sharing, agencies can focus on aspects of the IT infrastructure that most directly address their mission. They retain the authority and responsibility for optimizing IT services to meet their mission needs and benefit from the embedded security features that are part of their network and shared procurement. Recommendation five point three move federal agencies from a cyber security requirements management approach to one based on enterprise risk management e r M. For too long, federal agency cybersecurity requirements have been viewed as a checklist wholly separate from an agency's core functions and capabilities.

There has been a tendency to emphasize strict compliance with prescriptive requirements rather than enterprise risk management. Efforts have been made, especially over the past several years, to stress the value of risk management, using standards, guidelines, and best practices developed for federal agencies. However, the federal government has failed to adopt this risk management approach. Instead, it has focused on implementing specific prescriptive requirements.

The Commission recommends that the federal government adopt a risk management approach guided by o MB's Enterprise Risk Management Program. As part of this effort, federal agencies should be required to use the Cybersecurity Framework as a common standard to evaluate their cybersecurity posture and integrate cybersecurity with the agency's mission. Such an approach would help eliminate the misperception that cybersecurity is auxiliary to rather than a core part of every agency's mission.

It would properly put discussions of cybersecurity risk on the same level as other enterprise wide risks. It would also reinforce the move away from a culture concerned only with meeting minimum standards. Action Item five point three point one, the Office of Management and Budget OMB should require federal agencies to use the Cybersecurity Framework for any cybersecurity related reporting, oversight, and policy review or creation. Short term, it is vital that the federal government adopt and implement proven best practices from the private sector, other governments and standards bodies.

NIST has published guidance to map the Cybersecurity Framework developed in conjunction with the private sector, to the Risk Management Framework RMF that OMB expects agencies to use the two frameworks align, and the Commission believes strongly that there is no reason that agencies should not be using the Cybersecurity Framework for multiple purposes. To that end, NIST should build on its past work and produce one or more profiles to assist agencies in using the Cybersecurity Framework.

Other Commission recommendations urging more extensive use of the Cybersecurity Framework appear below and in Imperative one Recommendation one point four Action Item five point three point two. In the first one hundred days of the administration, OMB should work with NIST and DHS to clarify agency and OMB responsibilities under the Federal Information Security Modernization Act FISMA to align with the cyber Security Framework short term. The Federal Information Security Modernization Act, along with its associated implementation policies, standards, and guidelines, imposes requirements and expectations on federal agencies as they manage cybersecurity risk.

At times, these requirements compete and conflict with one another or quickly become outdated as a result of technological advances and a rapidly changing threat landscape. OMB, working with NIST and DHS should identify and address areas of alignment between the cyber Security Framework and existing federal requirements. This effort should address areas of conflict or overlap in existing requirements for federal agencies, and gap areas where additional policies, standards, guidelines, and programs may be needed to improve the ability of federal agencies to manage cybersecurity risk.

Specifically, the federal CISO should conduct a complete and comprehensive review of all current OMB cybersecurity requirements. At a minimum, these requirements should include OMB memos, binding operational directives, reporting instructions, and audit directions. Requirements that are no longer effective, are in conflict with current presidential priorities, or are outdated should be withdrawn. All new policies should be structured using the Cybersecurity Framework to ensure consistency in reporting and assessments.

In addition, OMB should give serious consideration to canceling programs that have proven not to be effective. Action Item five point three point three. OMB should integrate cybersecurity metrics with agency performance metrics, review these metrics bi annually, and integrate metrics and associated performance with the annual budget process. Short term.

It is often said that the devil is in the details. When it comes to assessing cybersecurity preparedness. The devil is in the metrics. One of the greatest challenges to determining cybersecurity strength has been a lack of standards of measurement.

Metrics, in combination with a risk management approach, will provide a foundation for effectively evaluating, under standing, and improving the cybersecurity posture of agencies. To address this need, the Commission recommends that the cyber Security Framework Metrics Working Group CFMWG, a body drawing on both the private and public sectors within the proposed National Private Public Partnership NCP three, develop metrics to assess an entity's cybersecurity posture. The metrics will be valuable for all sectors and should be fully embraced by OMB and federal agencies in their efforts to better quantify and evaluate the effectiveness of their actions.

These metrics should be integrated with other measures used to assess performance as part of the annual budget process. More information about the CFMWG is provided in Imperative one Action Item one point four point one Recommendation five FIZVEO point four. The federal government should better match cybersecurity responsibilities with the structure of and positions in the Executive Office of the President. The current leadership and organizational construct for cybersecurity within the federal government is not commensurate with the challenge of securing the digital economy and supporting the national and economic security of the United States.

Effective implementation of cybersecurity priorities will require strong leadership, beginning at the top. Some important steps toward improving national cybersecurity have been taken, such as appointing the first ever federal Chief Information Security Officer and establishing a privacy branch led by a career official in the OMB Office of Information and Regulatory Affairs. Additional improvements are needed. The next president should identify CyberSecure as a top national security priority and should empower his officials charged with overseeing that priority.

Accordingly, the mission must be resourced sufficiently, and the government must be staffed and organized to carry it out. One key part of that mission is protecting federal information and systems. Agencies must receive clear direction from the President and be granted corresponding authorities. All agency heads must understand that cyber security is one of their essential responsibilities.

Where appropriate, the President should use the power of executive orders to deliver directives to the executive branch, including to ensure that responsibility, authority and accountability for cyber security are properly aligned at the government wide level and within each agency. Each and every federal employee and contractor must understand and work in a way that is consistent with this basic tenet. Action Item five point four point one, The President should appoint and empower an Assistant to the President for cyber Security reporting through the National Security Adviser, to lead national cybersecurity policy and coordinate implementation of cyber protection programs.

Short term, cybersecurity must become and remain an essential priority in how the federal government does business. This focus and resolve will require strong leadership. The Commission recommends that the President elevate the current position of cyber Security Coordinator to an Assistant to the President on a par with the Assistant to the President for Homeland Security and counter Terrorism. He or she should have responsibility for bringing together the federal government's efforts to protect its own systems and data and to secure the larger digital economy, and should inform and coordinate with the Director of OMB on efforts by the federal CIO and CISO to secure federal agencies.

Action Item five point four point two. The Administration should clarify omb's role, and specifically that of the Federal Chief Information Officer CIO, the Federal Chief Information Security Officer CISO, and the Senior Advisor for Privacy in managing cybersecurity related operations in all agencies. Short term OMB plays a central role in ensuring that federal agencies operate their information technology securely and effectively, and that an effective risk management approach is used to carry out their mission.

This role is carried out through the Federal CIO and is supported by the CISO, along with privacy policy leadership currently provided by the Senior Advisor for Privacy. High priority must be given to laying out clear, outcome focused requirements to drive agency priorities. This effort requires these officials to work with Congress and agency leaders to ensure that an appropriate budget is allocated to meet those priorities, and to develop and maintain a rigorous risk management framework for agencies to address cybersecurity risks that can threaten their mission.

The Commission recommends that the Federal CIO conduct a rolling assessment of the government's cybersecurity performance on a quarterly basis to ensure a sustained level of performance on fundamental cyber security actions. He or she must make certain that agencies systematically identify and prioritize their highest value and most at risk ee assets. Adherents to minimum cyber security standards must be better monitored, reported, and enforced than it is today. The President should make clear that the Federal CIO will lead this effort in the federal government.

The Federal CIO, working in consultation with the Federal CISO, the Senior Advisor for Privacy, the Assistant to the President for Cybersecurity, and the head of the new agency charged with cybersecurity and infrastructure protection functions c Action Item five point five point two below should identify similar baseline security measures that can be implemented immediately. The recently established position of Federal CISO is a meaningful addition to omb's capability in this area.

The Federal CISO should be granted appropriate and clear authority by the Federal CIO IO to support the above responsibilities. The Federal CISO should also serve as a primary connection between the efforts of OMB and of the Assistant to the President for Cybersecurity. If the Federal CISO is appropriately included in these national security activities, all federal agencies will benefit from the latest risk and threat information. Similarly, omb's capability to coordinate governance of personal data has benefited from the recently established position of Senior Advisor for Privacy to the Director of OMB and the role of this policy official in leading the Federal Privacy Council.

This Privacy official has led omb's privacy policy work. In addition, a lead career official for Privacy has been created in the OMB Office of Information and Regulatory Affairs. Because many issues concerning personal data have both cyber security and privacy implications, it is important to retain a policy official focused on privacy in order to ensure proper consideration of the privacy aspects of cybersecurity policy across the federal government. Recommendation five point five, Government at all levels must clarify its cybersecurity mission responsibilities across departments and agencies.

To protect and defend against, respond to, and recover from cyber incidents, governments need to have a clear understanding of their roles and responsibilities to more effectively and consistently prepare and plan for, respond to, and recover from cyber incidents. This clear understanding will ensure improved government coordination and more efficient use of resources. It will promote the strengthening of existing capable abilities and help identify the new ones we need to build.

Action Item five point five point one, the President should issue a national cyber security strategy within the first one hundred eighty days of his administration. Short term. This comprehensive cyber security strategy should set forth the vision and priorities for achieving security and resilience in cyberspace. The strategy should include the creation of a defensible national cyber architecture and should provide a roadmap for implementation and policy development that can guide the national effort to secure the digital economy over the next decade.

Action Item five point five point two. Congress should consolidate cybersecurity and infrastructure protection functions under the oversight of a single federal agency and ensure this agency has the appropriate capabilities and responsibilities to execute its mission. Short term, consistent with the national cyber security strategy called for in Action Item five point five point one, Congress should create a new component agency or repurpose an existing agency to serve as a fully operational cyber security and critical Infrastructure protection agency on a power with other component agencies.

This agency should be solely dedicated to these two core missions, and it should be given the necessary authorities, responsibilities, and resources to carry out these missions effectively. Working closely with the Assistant to the President for Cybersecurity see Action Item five point four point one and the Federal Chief Information Officer CIO, this agency should establish and administer the Consolidated Federal Network describe in Action Item five point one point one, including establishing criteria that federal agencies must meet in order to connect to this network.

The agency must also guarantee federal agencies using the consolidated network a high quality and reliable level of service. To this end, it should establish and adhere to clear performance metrics for the network to ensure the agency is accountable for providing this level of service. Congress should provide a mechanism by which the Federal Chief Information Officer CIO, Federal Chief Information Security Officer CISO, and CIO Council may oversee the agency's performance. In addition to administering the Consolidated Federal Network, this agency would monitor and assess information technology trends across the digital economy, with an emphasis on critical infestrus structure.

This tasking would help address the limited capability within the federal government to monitor and assess these trends in the United States and to gauge how they might affect the cyber security of critical infrastructure, consumers, and the federal government Action Item five point five point three. The governors in each state should consider seeking necessary legislative authority and resources to train and equip the National Guard to serve as part of the nation's cyber security defense short to medium term.

In some states, the National Guard today provides much needed expertise to assist states in tackling their most pressing cyber security challenges. The Guard represents a talent pool that can be regularly trained, equipped, and called on to protect and defend against attacks on information as computer systems, and networks. The Guard could also be deployed after a cyber security incident to help recover or restore systems and services to normal operations. Building on recent and growing investments in developing sophisticated cyber defense capabilities in the National Guard, state legislatures should give serious consideration to providing governors with the necessary authorities and resources to train and equip the National Guard to serve their states and safeguard the public from malicious cyber activity.

The Commission recognizes that governors approach cybersecurity by engaging a diverse set of senior officials and enterprises, including some combination of the National Guard and their Chief Information officer, Homeland Security Director, Emergency Management Director, and chief security officer. The Commission recommends that states should continue to engage a team of leaders in addressing cybersecurity challenges and strategies. End of Section eleven.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mastercard CEO: AI Shopping Agents, Machine-to-Machine Payments, and the New Infrastructure of CommerceMotley Fool Hidden Gems Investing · on Cybersecurity88 / 100
  • AI Governance Essentials: Navigating Security and Compliance in Enterprise AI with Walter HaydockCyber Sentries: AI Insight to Cloud Security · on NIST Cybersecurity Framework85 / 100
  • Why Most Startups Fail: Founders Don’t Know What They Don’t Know YetBuilt Not Born: The Startup Go-To-Market Podcast · on Cybersecurity80 / 100
  • Commvault On Cyber Recovery Why Disaster Plans Fall ShortThe Business of Cybersecurity · on NIST Cybersecurity Framework80 / 100
  • Episode 46 - from Tashkent to Termsheet with Victor OrlovskyThe GoingVC Podcast · on Cybersecurity77 / 100
  • Moving from Product Partnerships to Revenue: Jira Cooley on Owning the NumberBetween Product and Partnerships · on Cybersecurity76 / 100

More from Report on Securing and Growing the Digital Economy

All episodes →
  • 017 - Appendix 6 Cybersecurity Legislation Overview26 / 100
  • 016 - Appendix 5 Cybersecurity Policy Overview31 / 100
  • 015 - Appendix 4 Executive Order 1371826 / 100
  • 014 - Appendix 1 Imperatives Recommendations and Action Items26 / 100
  • 013 - Imperative 6 Ensure an Open Fair Competitive and Secure Global Digital Economy IV Next Steps36 / 100
All Report on Securing and Growing the Digital Economy episodes →