FAS

CRS Views the Cybersecurity Initiative

03.12.09 | 2 min read | Text by Steven Aftergood

The Comprehensive National Cybersecurity Initiative (CNCI) that was established by classified presidential directive (NSPD 54 and HSPD 23) in January 2008 is deliberately opaque, and there is little specific information in the public domain about its conduct or performance to date.

“Much remains unknown about the CNCI due to the classified nature of the presidential directives and supporting implementation documents,” says a new report (pdf) from the Congressional Research Service.

But the CRS report summarizes what has been disclosed, and illuminates many of the ensuing questions raised by the Initiative.  These include the extent of its underlying legal authority; the respective roles of the executive and legislative branches on cybersecurity; the involvement of the private sector; the impact of privacy considerations; and even the possibility that offensive or defensive cybersecurity activities would fall into the category of “covert action.”

See “Comprehensive National Cybersecurity Initiative: Legal Authorities and Policy Considerations,” March 10, 2009.

“A chief concern” about the Initiative, the Senate Armed Services Committee declared last year, “is that virtually everything about [it] is highly classified, and most of the information that is not classified is categorized as `For Official Use Only’.”

“These restrictions preclude public education, awareness, and debate about the policy and legal issues, real or imagined, that the initiative poses in the areas of privacy and civil liberties. Without such debate and awareness in such important and sensitive areas, it is likely that the initiative will make slow or modest progress. The committee strongly urges the administration to reconsider the necessity and wisdom of the blanket, indiscriminate classification levels established for the initiative.” (“Cyber Security Initiative is Too Secret, SASC Says,” Secrecy News, May 15, 2008.)

On February 9, 2009 President Obama ordered a 60-day review of cybersecurity policy.

publications
See all publications
Emerging Technology
day one project
Policy Memo
Strategies to Accelerate and Expand Access to the U.S. Innovation Economy

With targeted policy interventions, we can efficiently and effectively support the U.S. innovation economy through the translation of breakthrough scientific research from the lab to the market.

11.27.24 | 16 min read
read more
Government Capacity
day one project
Policy Memo
Collaborative Intelligence: Harnessing Crowd Forecasting for National Security

Crowd forecasting methods offer a systematic approach to quantifying the U.S. intelligence community’s uncertainty about the future and predicting the impact of interventions, allowing decision-makers to strategize effectively and allocate resources by outlining risks and tradeoffs in a legible format.

11.27.24 | 5 min read
read more
Clean Energy
day one project
Policy Memo
The Energy Transition Workforce Initiative

The energy transition underway in the United States continues to present a unique set of opportunities to put Americans back to work through the deployment of new technologies, infrastructure, energy efficiency, and expansion of the electricity system to meet our carbon goals.

11.27.24 | 5 min read
read more
Clean Energy
day one project
Policy Memo
Promoting Fusion Energy Leadership with U.S. Tritium Production Capacity

The United States has the only proven and scalable tritium production supply chain, but it is largely reserved for nuclear weapons. Excess tritium production capacity should be leveraged to ensure the success of and U.S. leadership in fusion energy.

11.26.24 | 12 min read
read more