DoDP:国防部首席信息官网络安全风险管理构建(CSRMC)战略方针(2025) 2页

VIP文档

ID:74640

阅读量:4

大小:0.88 MB

页数:2页

时间:2025-09-25

金币:1

上传者:PASHU
STRATEGIC TENETS
Cybersecurity Assessments
Establish comprehensive cybersecurity assessment programs
that integrate threat-informed testing methodologies with
mission-aligned risk management processes.
Enterprise & Inheritance
Share security controls, policies, or risks to increase
adoption proven frameworks, reduce compliance burdens,
and maintain operational consistency.
Critical Controls
Adhere to identified critical controls, and adaptive
recovery strategies strengthen defenses to ensure
operational continuity and protect sensitive assets.
Reciprocity
Accept each other's security assessments to reuse
system resources and/or to accept each other's
assessed security posture to share information.
Continuous Monitoring (CONMON),
Control, and ATO
Provide real-time visibility into threats, vulnerabilities,
and compliance gaps through continuous monitoring.
DevSecOps
Integrate Integrate security and automation through
continuous development, testing, and deployment
to accelerate delivery safely.
Operationalization
Strengthen our defense against evolving threats through
threat detection, incident response, compliance
management, and proactive monitoring.
Cyber Survivability
Safeguard against cyber threats, disruptions, and
data breaches through strong encryption, multi-factor
authentication, continuous monitoring, and incident
response planning.
Training
Enhancer ole-based training program for RMF practitioners to
ensure consistent performance, cybersecurity knowledge, and
standards.
Automation
Automate to enhance risk management by
streamlining processes, reducing human
error, and improving efficiency.
CLEARED
For Open Publication
Department of Defense
OFFICE OF PREPUBLICATION AND SECURITY REVIEW
Sep 23, 2025
资源描述:

【美国国防部】【2025年9月23日】发布《网络安全战略原则》;该文件的目的是指导建立全面网络安全体系,强化威胁防御、保障运营连续性及敏感资产安全;该文件内容包括:一是建立综合网络安全评估项目,整合威胁知情测试方法论与任务对齐的风险管理流程;二是共享安全控制、政策或风险,推广成熟框架应用,减轻合规负担,维持运营一致;三是遵循关键控制及自适应恢复策略,强化防御确保运营连续、保护敏感资产;四是互认安全评估,复用系统资源或认可安全状态以共享信息;五是通过持续监控提供威胁、漏洞及合规差距的实时可见性;六是通过DevSecOps整合安全与自动化,实现持续开发测试部署以安全加速交付;七是通过威胁检测、事件响应、合规管理及主动监控强化演化威胁防御;八是用强加密、多因素认证等防范网络威胁、中断及数据泄露;九是强化RMF从业者角色导向培训,确保一致绩效、网络安全知识及标准;十是通过自动化简化流程、减少人为错误,提升风险管理效率;该文件的结论是上述战略原则覆盖网络安全评估、共享、控制、监控等关键环节,为应对演化威胁提供全面指导;该文件建议落实这些原则,系统化提升网络安全防御能力。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭