11.07.2015 Views

syssec_red_book

syssec_red_book

syssec_red_book

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

17.2. Recommendations“Make cyber security and information assurance R&D both an individualagency and an interagency budget priority. Agencies should considercyber security and information assurance R&D policy guidance as theyaddress their mission-related R&D requirements. To achieve the greatestpossible benefit from investments throughout the Federal government,cyber security and information assurance R&D should have high priorityfor individual agencies as well as for coordinated interagency efforts.”“Support sustained interagency coordination and collaboration on cybersecurity and information assurance R&D. Sustained coordination andcollaboration among agencies will be requi<strong>red</strong> to accomplish the goalsidentified in this Plan. Agencies should participate in interagency R&Dcoordination and collaboration on an ongoing basis.”“Build security in from the beginning. The Federal cyber security andinformation assurance R&D portfolio should support fundamental R&Dexploring inherently more secure next-generation technologies that willreplace today’s patching of the current insecure infrastructure.”“Assess security implications of emerging information technologies. TheFederal government should assess the security implications and thepotential impact of R&D results in new information technologies as theyemerge in such fields as optical computing, quantum computing, andpervasively embedded computing.”“Develop a roadmap for Federal cyber security and information assuranceR&D. Agencies should use this Plan’s technical priorities and investmentanalyses to work with the private sector to develop a roadmap ofcyber security and information assurance R&D priorities. This effortshould emphasize coordinated agency activities that address technicaland investment gaps and should accelerate development of strategiccapabilities.”“Develop and apply new metrics to assess cyber security and informationassurance. As part of roadmapping, Federal agencies should develop andimplement a multi-agency plan to support the R&D for a new generationof methods and technologies for cost-effectively measuring IT component,network, and system security. These methods should evolve with time.”“Institute more effective coordination with the private sector. The Federalgovernment should review private-sector cyber security and informationassurance practices and countermeasures to help identify capability gapsin existing technologies, and should engage the private sector in efforts tobetter understand each other’s views on cyber security and information115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!