Gourley provides context for the New New Internet:
For that be effective, Gourley writes that the Department must choose the a capable and intelligence technology leader to head the NCCC. “The nation must choose wisely and put a very smart technology leader in this position,” he writes. “Someone who can enforce the right standards and give direction when required but can back off and let agency IT leaders run things when required and that person must be smart enough to know when and how to decide what to decide about.”
Gourley also praises the movement towards a system of continuous monitoring rather than the current FISMA structure. “Updating FISMA is long overdue,” he writes. “Moving towards real-time monitoring is GREAT!”
Additionally, making NCCC the central coordination point across the federal government is “a solid move.” The proposed effort to create secured supply chains, remove any impediments to sharing information and factoring in the human side of cybersecurity are also important, Gourley writes.
In addition to his praise for the bill, Gourley has one additional piece he would like to see added to the bill.
“I want to suggest that the U.S. Intelligence Community be tasked with providing a detailed yearly cyber intelligence threat assessment for unclassified dissemination,” he writes. “The IC does a good job of providing some counterintelligence assessments and frequently mentions cyber in open fora like Congressional Testimony, but I believe this issue deserves a focused, NIE-like report dedicated to this topic. Of course the IC should also be tasked with support to the NCCC.”
via Gourley: Intelligence Community Should Provide Unclassified Cyber Threat Assessments Annually – The New New Internet.
Related Reading
- A Fierce Domain: Conflict in Cyberspace
- The Bill Codifying The New Cybersecurity and Infrastructure Security Agency Is Short and Sweet
- Working in Cybersecurity: Life on the front lines, in the C-suite, and everywhere in-between
- Leveraging The FFIEC Cybersecurity Assessment Tool (CAT) To Improve Corporate Culture and Raise Security Posture
- CISO-as-a-Service: When your enterprise needs cybersecurity expertise on demand
- Business Decisions Require New Insights Into The Age of Geopolitical Risk
- DHS Opens the National Cybersecurity and Communications Integration Center (NCCIC)