Opinions from knowledgeable people?
Opinions from knowledgeable people?
http://www.nbcnews.com/storyline/hacking-of-america/new-trump-executive-order-would-move-federal-cybersecurity-cloud-n758141
http://www.nbcnews.com/storyline/hacking-of-america/new-trump-executive-order-would-move-federal-cybersecurity-cloud-n758141
http://www.nbcnews.com/storyline/hacking-of-america/new-trump-executive-order-would-move-federal-cybersecurity-cloud-n758141
http://www.nbcnews.com/storyline/hacking-of-america/new-trump-executive-order-would-move-federal-cybersecurity-cloud-n758141
Inherent suspicion.
ReplyDeleteI'm not convinced the EO says what the article says it says. Bossert talks up moving security to the cloud, but the EO text itself doesn't. It mentions the word "cloud" only twice:
ReplyDeleteAgency heads shall show preference in their procurement for shared IT services, to the extent permitted by law, including email, cloud, and cybersecurity services.
...And a longer passage that mandates a strategy report on the possible transition to either a consolidated network or a set of shared services, including e-mail, cloud and cybersecurity.
None of that says, "This EO requires moving cyber security to the cloud," to me. The passages I mention are the most aggressive but they only go so far as directing a preference, still subject to strategic considerations (in the broadest sense not of "national security" but of cost, flexibility, defense implications, etc) and the aforementioned report.
In general, it's a thoroughly boring document mandating more papers to be pushed than anything else, in three expanding but concentric circles: Federal infrastructure, critical national infrastructure (which could presumably be state, municipal, or even private), and finally international security priorities.
I see basically nothing controversial in it, and it's based off of the framework created by an Obama EO from 2013, which basically runs through NIST. Mercifully, the horizon for report generation is relatively short-- 90 to 120 days, depending on what report we're talking about, but after that meaningful action probably leaves the realm of EOs passes to actual laws since doing anything meaningful will require appropriations.
After a painful week of watching President Ruprect continually taking the cork off the fork, there's really not a lot here to complain about that I can see.
"President Ruprect continually taking the cork off the fork, "
ReplyDelete<3 <3 <3