Report No. DODIG-2019-044 for OFFICIAL USE ONLY
Report No. DODIG-2019-044 FOR OFFICIAL USE ONLY U.S. Department of Defense InspectorJANUARY 9, 2019 General Summary of Reports Issued Regarding Department of Defense Cybersecurity From July 1, 2017, Through June 30, 2018 INTEGRITY INDEPENDENCE EXCELLENCE The document contains information that may be exempt from mandatory disclosure under the Freedom of Information Act. FOR OFFICIAL USE ONLY FOR OFFICIAL USE ONLY FOR OFFICIAL USE ONLY FOR OFFICIAL USE ONLY Summary of Reports Issued Regarding Department of Defense ResultsCybersecurity in From Brief July 1, 2017, Through June 30, 2018 January 9, 2019 Background Objective On February 12, 2013, the President issued Executive Order 13636, “Improving Critical Infrastructure Our objective was to (1) summarize Cybersecurity.” Executive Order 13636 calls for the unclassified and classified reports development of a voluntary cybersecurity framework issued and testimonies made from for Federal and non-Federal entities that provides a the DoD oversight community and the prioritized, flexible, repeatable, performance-based, and Government Accountability Office (GAO) cost effective approach to help owners and operators between July 1, 2017, and June 30, 2018, of critical infrastructure identify, assess, and manage that included DoD cybersecurity issues; cyber risk. The resulting NIST Cybersecurity Framework (2) identify cybersecurity risk areas for was established through collaboration between the DoD management to address based on the Government and private sector entities. The framework five functions of the National Institute has five functions, representing high-level cybersecurity of Standards and Technology (NIST), activities that provide a strategic view of the risk management “Framework for Improving Critical lifecycle—Identify, Protect, Detect, Respond, and Recover.
[Show full text]