Presidential Policy Directive 41

Last updated

Presidential Policy Directive 41 (PPD-41) titled "United States Cyber Incident Coordination" is a Presidential Policy Directive signed by President of the United States Barack Obama on 26 July 2016. [1] [2] Its annex has subject "Federal Government Coordination Architecture for Significant Cyber Incidents". [3]

Invocation

Directive 41 was invoked several times by the Obama administration, to address threats to national cybersecurity. [4]

The succeeding Trump administration, which took office in January 2017, did not invoke the directive at all until 15 December 2020. [4] On that occasion, PPD-41 was invoked in a statement by the National Security Council announcing the creation of a Cyber Unified Coordination Group "to ensure continued unity of effort across the United States Government" in response to the 2020 United States federal government data breach. [1] [4] [5]

Related Research Articles

Continuity of Operations (COOP) is a United States federal government initiative, required by U.S. Presidential Policy Directive 40 (PPD-40), to ensure that agencies are able to continue performance of essential functions under a broad range of circumstances. PPD-40 specifies certain requirements for continuity plan development, including the requirement that all federal executive branch departments and agencies develop an integrated, overlapping continuity capability, that supports the eight National Essential Functions (NEFs) described in the document.

United States Department of Homeland Security United States federal department

The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior or home ministries of other countries. Its stated missions involve anti-terrorism, border security, immigration and customs, cyber security, and disaster prevention and management.

National Cyber Security Division

The National Cyber Security Division (NCSD) is a division of the Office of Cyber Security & Communications, within the United States Department of Homeland Security's Cybersecurity and Infrastructure Security Agency. Formed from the Critical Infrastructure Assurance Office, the National Infrastructure Protection Center, the Federal Computer Incident Response Center, and the National Communications System, NCSD opened on June 6, 2003. The NCSD mission is to collaborate with the private sector, government, military, and intelligence stakeholders to conduct risk assessments and mitigate vulnerabilities and threats to information technology assets and activities affecting the operation of the civilian government and private sector critical cyber infrastructures. NCSD also provides cyber threat and vulnerability analysis, early warning, and incident response assistance for public and private sector constituents. NCSD carries out the majority of DHS’ responsibilities under the Comprehensive National Cybersecurity Initiative. The FY 2011 budget request for NCSD is $378.744 million and includes 342 federal positions. The current director of the NCSD is John Streufert, former chief information security officer (CISO) for the United States Department of State, who assumed the position in January 2012.

Homeland Security Act of 2002 Post-9/11 United States law establishing the Department of Homeland Security

The Homeland Security Act (HSA) of 2002, was introduced in the aftermath of the September 11 attacks and subsequent mailings of anthrax spores. The HSA was cosponsored by 118 members of Congress. The act passed the U.S. Senate by a vote of 90-9, with one Senator not voting. It was signed into law by President George W. Bush in November 2002.

The National Incident Management System (NIMS) is a standardized approach to incident management developed by the United States Department of Homeland Security. The program was established in March 2004, in response to Homeland Security Presidential Directive-5, issued by President George W. Bush. It is intended to facilitate coordination between all responders. The system has been revised once, in December 2008. The core training currently includes two courses: (1) IS-700 NIMS, which provides a basic introduction to NIMS, and (2) ICS-100, which includes history, details, and features, along with an introduction to the Incident Command System. Approximately 24 additional courses are available on selected topics.

A computer emergency response team is a historic term for an expert group that handles computer security incidents. '"CERT"' should not be generically used as an acronym for this term as it is registered as a trademark in the United States Patent and Trademark Office, as well as other jurisdictions around the world. Alternative names for such groups include computer emergency readiness team and computer security incident response team (CSIRT).

A cybersecurity regulation comprises directives that safeguard information technology and computer systems with the purpose of forcing companies and organizations to protect their systems and information from cyberattacks like viruses, worms, Trojan horses, phishing, denial of service (DOS) attacks, unauthorized access and control system attacks. There are numerous measures available to prevent cyberattacks.

Whistleblower Protection Act

The Whistleblower Protection Act of 1989, 5 U.S.C. 2302(b)(8)-(9), Pub.L. 101-12 as amended, is a United States federal law that protects federal whistleblowers who work for the government and report the possible existence of an activity constituting a violation of law, rules, or regulations, or mismanagement, gross waste of funds, abuse of authority or a substantial and specific danger to public health and safety. A federal agency violates the Whistleblower Protection Act if agency authorities take retaliatory personnel action against any employee or applicant because of disclosure of information by that employee or applicant.

The National Security and Homeland Security Presidential Directive, signed by President of the United States George W. Bush on May 4, 2007, is a Presidential Directive establishing a comprehensive policy on the federal government structures and operations in the event of a "catastrophic emergency" like a pandemic. Such an emergency is defined as "any incident, regardless of location, that results in extraordinary levels of mass casualties, damage, or disruption severely affecting the U.S. population, infrastructure, environment, economy, or government functions."

The United States National Response Framework (NRF) is part of the National Strategy for Homeland Security that presents the guiding principles enabling all levels of domestic response partners to prepare for and provide a unified national response to disasters and emergencies. Building on the existing National Incident Management System (NIMS) as well as Incident Command System (ICS) standardization, the NRF's coordinating structures are always in effect for implementation at any level and at any time for local, state, and national emergency or disaster response.

Presidential Decision Directive 62 (PDD-62), titled Combating Terrorism, was a Presidential Decision Directive (PDD), signed on May 22, 1998 by President Bill Clinton. It identified the fight against terrorism a top national security priority.

Homeland Security Presidential Directive (HSPD)-8, National Preparedness, describes the way United States Federal agencies will prepare for an incident. It requires Department of Homeland Security to coordinate with other Federal agencies and with State, local, and Tribal governments to develop a National Preparedness Goal with Emergency management. Congressional laws enacted, following the wake of 9/11, which resulted in new developments in the way security was assessed and addressed in the United States, to prevent and respond to threatened or actual domestic terrorist attacks, disasters, and other emergencies by requiring a national domestic all-hazards preparedness goal. HSPD 5, HSPD-7, HSPD-8, and HSPD-8 Annex 1 are directives that deal with the preparedness goals.

As a major developed economy, the United States is highly dependent on the Internet and therefore greatly exposed to cyber attacks. At the same time, the United States has substantial capabilities in both defense and power projection thanks to comparatively advanced technology and a large military budget. Cyber warfare presents a growing threat to physical systems and infrastructures that are linked to the internet. Malicious hacking from domestic or foreign enemies remains a constant threat to the United States. In response to these growing threats, the United States has developed significant cyber capabilities.

The Comprehensive National Cybersecurity Initiative (CNCI) outlines U.S. cybersecurity goals across multiple agencies including the Department of Homeland Security, the Office of Management and Budget, and the National Security Agency. The initiative was established by President George W. Bush in January 2008 in National Security Presidential Directive 54/Homeland Security Presidential Directive 23 (NSPD-54/HSPD-23).

Paul N. Stockton

Dr. Paul N. Stockton is the Managing Director of Sonecon, LLC, a District of Columbia-based advisory firm. From 2009-2013, Dr. Stockton served as Assistant Secretary of Defense for Homeland Defense and Americas' Security Affairs, where he helped lead the Department's response to Hurricane Sandy. He was responsible for Defense Critical Infrastructure Protection, Western Hemisphere security policy, domestic crisis management, continuity of operations planning, and a range of other responsibilities. While Assistant Secretary, Dr. Stockton also served as Executive Director of the Council of Governors.

Lisa Monaco American lawyer

Lisa Oudens Monaco is an American federal prosecutor who was the Homeland Security Adviser to President Barack Obama, the chief counterterrorism advisor to the president. In this capacity, she was a statutory member of the United States Homeland Security Council.

The United States Presidential Policy Directive 19, signed by President Barack Obama, is designed to ensure that employees who serve in the Intelligence Community or have access to classified information can effectively report waste, fraud, and abuse, while protecting classified information. It is the executive order establishing standards for all Federal agencies with employees covered by the Directive, including those under Defense Intelligence Community Whistleblower Protection and the U.S. Department of Defense Whistleblower Program. It also prohibits retaliation against these employees for their reports. PPD-19 accordingly establishes a system of Intelligence community whistleblowing and source protection under the Office, Director of National Intelligence and supervised by the Inspector General of the Intelligence Community.

Presidential Policy Directive 20 (PPD-20), provides a framework for U.S. cybersecurity by establishing principles and processes. Signed by President Barack Obama in October 2012, this directive supersedes National Security Presidential Directive NSPD-38. Integrating cyber tools with those of national security, the directive complements NSPD-54/Homeland Security Presidential Directive HSPD-23.

The National Cybersecurity and Communications Integration Center (NCCIC) is part of the Cybersecurity Division of the Cybersecurity and Infrastructure Security Agency, which is an agency of the U.S. Department of Homeland Security. It acts to coordinate various aspects of the U.S. federal government's cybersecurity and cyberattack mitigation efforts, through cooperation with civilian agencies, infrastructure operators, state and local governments, and international partners.

Space policy of the Donald Trump administration

The space policy of the Donald Trump administration, as of December 2020, comprises five Space Policy Directives and an announced "National Space Strategy", representing a directional shift from the policy priorities and goals of his predecessor, Barack Obama. A National Space Policy was issued on December 9, 2020.

References

  1. 1 2 "Obama Establishes Cyberattack Response Chain of Command". Nextgov. 26 July 2016. Retrieved 16 December 2020.
  2. "Presidential Policy Directive -- United States Cyber Incident Coordination". whitehouse.gov. 26 July 2016. Retrieved 16 December 2020.
  3. "Annex for Presidential Policy Directive -- United States Cyber Incident Coordination". archives.gov. 26 July 2016. Retrieved 16 December 2020.
  4. 1 2 3 "The Wrong Hack". Slate. 15 December 2020. Retrieved 16 December 2020.
  5. "Pentagon, State Department among agencies hacked: report". The Hill. 15 December 2020. Retrieved 16 December 2020.