GAO:优先开放建议:国家网络总监办公室(ONCD)(2025) 10页

VIP文档

ID:74538

阅读量:0

大小:0.58 MB

页数:10页

时间:2025-09-10

金币:10

上传者:PASHU
Page 1 GAO-25-107943
441 G St. N.W.
Washington, DC 20548
Comptroller General
of the United States
September 2, 2025
The Honorable Sean Cairncross
Director
Office of the National Cyber Director
1600 Pennsylvania Ave NW
Washington, DC 20500
Priority Open Recommendations: Office of the National Cyber Director (ONCD)
Dear Director Cairncross:
Congratulations on your appointment. The purpose of this letter is to call your personal attention
to three open priority recommendations from GAO’s past work, which are enclosed.
1
Additionally, there is one other open GAO recommendation that we will continue to work with
your staff to address.
2
We are highlighting the following area that warrants your timely and focused attention:
Improving national cybersecurity strategies. ONCD needs to take additional steps to
improve various national strategies pertaining to cybersecurity. In March 2023, the White House
publicly issued a new National Cybersecurity Strategy, and subsequently published the
accompanying implementation plan in July 2023.
3
Additionally, ONCD, along with several other
federal entities, issued various documents contributing to an emerging national quantum
cybersecurity strategy. However, we previously reported that the National Cybersecurity
Strategy, including the National Cybersecurity Strategy Implementation Plan,
4
and the quantum
1
GAO considers a recommendation to be a priority if when implemented, it may significantly improve government
operations, for example, by realizing large dollar savings; eliminating mismanagement, fraud, and abuse; or making
progress toward addressing a high-risk or duplication issue.
2
GAO, Critical Infrastructure Protection: National Cybersecurity Strategy Needs to Address Information Sharing
Performance Measures and Methods. GAO-23-105468. (Washington, D.C.: September 26, 2023). We recommended
that ONCD should identify outcome-oriented performance measures for the eight cyber threat information sharing
initiatives that are included in the National Cybersecurity Strategy Implementation Plan.
3
The White House, National Cybersecurity Strategy, (Washington, D.C.: Mar. 2023) and National Cybersecurity
Strategy Implementation Plan (Washington, D.C.: July 2023).
4
GAO, Cybersecurity: National Cyber Director Needs to Take Additional Actions to Implement an Effective Strategy.
GAO-24-106916. (Washington, D.C.: Feb. 1, 2024).
资源描述:

这是美国政府问责局(GAO)于2025年9月2日致美国国家网络主任办公室(ONCD)主任肖恩·凯恩克罗斯的信,指出了过去工作中三项未完成的优先建议,强调改善国家网络安全战略的紧迫性。 1. **背景与挑战**:网络安全挑战长期存在,自1997年起就被列入GAO的高风险清单。2024年6月,GAO确定了应对国家网络安全挑战的紧急行动,自2010年以来已提出4310项建议,截至2025年8月仍有515项未完成。 2. **建议内容** - **制定绩效衡量标准**:ONCD应与相关联邦实体合作,为《国家网络安全战略》中的倡议制定以结果为导向的绩效衡量标准,以评估战略目标的实现效果。目前ONCD正在为《国家网络安全战略实施计划》的未来版本制定此类标准,并将于2026年更新计划时纳入。 - **进行成本估算**:ONCD应评估战略中的倡议,确定需要成本估算的项目,并与相关联邦机构协调进行估算,以确保有足够资源支持战略实施。但ONCD因预算限制未同意该建议,截至2025年8月也未提供相关行动更新。 - **领导量子计算网络安全战略协调**:国家网络主任应领导国家量子计算网络安全战略的协调工作,确保战略文件具备国家战略的理想特征,以应对量子计算机对非机密系统加密带来的威胁。ONCD对此建议未明确表态。 3. **国会作用**:国会在监督和确保GAO建议实施方面发挥关键作用,可通过立法、预算、拨款和监督等手段激励行政部门采取行动,并解决实施过程中的潜在问题。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭