GAO: DHS’s National Integration Center Generally Performs Required Functions but Needs to Evaluate Its Activities More Completely

From: GAO

Recommendations for Executive Action
To more fully address the requirements identified in the National Cybersecurity Protection Act of 2014 and the Cybersecurity Act of 2015, we recommend that the Secretary of the Department of Homeland
Security take the following nine actions:
  1. Determine the extent to which the statutorily required implementing principles apply to NCCIC’s cybersecurity functions.
  2. Develop metrics for assessing adherence to applicable principles in carrying out statutorily required functions.
  3. Establish methods for monitoring the implementation of cybersecurity functions against the principles on an ongoing basis.
  4. Integrate information related to security incidents to provide management with more complete information about NCCIC operations.
  5. Determine the necessity of reducing, consolidating, or modifying the points of entry used to communicate with NCCIC to better ensure that all incident tickets are logged appropriately.
  6. Develop and implement procedures to perform regular reviews of customer information to ensure that it is current and reliable.
  7. Take steps to ensure the full representation of the owners and operators of the nation’s most critical cyber-dependent infrastructure assets.
  8. Establish plans and time frames for consolidating or integrating the legacy networks used by NCCIC analysts to reduce the need for manual data entry.
  9. Identify alternative methods to collaborate with international partners, while ensuring the security requirements of high-impact systems.

Read Complete Report

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *