NATOSource is proudly sponsored by EADS North America

New Atlanticist
National Interests
- Afghanistan
- Albania
- Armenia
- Australia
- Austria
- Azerbaijan
- Belarus
- Belgium
- Bosnia-Herzegovina
- Brazil
- Britain
- Bulgaria
- Canada
- Chad
- China
- Congo (DRC)
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Finland
- France
- Georgia
- Germany
- Greece
- Hungary
- Iceland
- India
- Indonesia
- Iran
- Iraq
- Ireland
- Israel
- Italy
- Japan
- Jordan
- Kazakhstan
- Kosovo
- Kyrgyzstan
- Latvia
- Lebanon
- Lithuania
- Luxembourg
- Libya
- Macedonia
- Malta
- Montenegro
- Morocco
- Netherlands
- North Korea
- Norway
- Pakistan
- Philippines
- Poland
- Portugal
- Qatar
- Romania
- Russia
- Saudi Arabia
- Serbia
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- Spain
- Sudan
- Sweden
- Switzerland
- Syria
- Taiwan (ROC)
- Tajikistan
- Tunisia
- Turkey
- U.A.E.
- U.S.
- Ukraine
- Uzbekistan
- Yemen
Obama's Executive Order on Cybersecurity
Jorge Benitez | February 13, 2013From White House: By the authority vested in me as President by the Constitution and the laws of the United States of America, it is hereby ordered as follows:
Section 1. Policy. Repeated cyber intrusions into critical infrastructure demonstrate the need for improved cybersecurity. The cyber threat to critical infrastructure continues to grow and represents one of the most serious national security challenges we must confront. The national and economic security of the United States depends on the reliable functioning of the Nation's critical infrastructure in the face of such threats. It is the policy of the United States to enhance the security and resilience of the Nation's critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties. We can achieve these goals through a partnership with the owners and operators of critical infrastructure to improve cybersecurity information sharing and collaboratively develop and implement risk-based standards.
Sec. 2. Critical Infrastructure. As used in this order, the term critical infrastructure means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.
Sec. 3. Policy Coordination. Policy coordination, guidance, dispute resolution, and periodic in-progress reviews for the functions and programs described and assigned herein shall be provided through the interagency process established in Presidential Policy Directive-1 of February 13, 2009 (Organization of the National Security Council System), or any successor. . . .
Sec. 4. Cybersecurity Information Sharing. (a) It is the policy of the United States Government to increase the volume, timeliness, and quality of cyber threat information shared with U.S. private sector entities so that these entities may better protect and defend themselves against cyber threats. Within 120 days of the date of this order, the Attorney General, the Secretary of Homeland Security (the "Secretary"), and the Director of National Intelligence shall each issue instructions consistent with their authorities and with the requirements of section 12(c) of this order to ensure the timely production of unclassified reports of cyber threats to the U.S. homeland that identify a specific targeted entity. The instructions shall address the need to protect intelligence and law enforcement sources, methods, operations, and investigations. . . .
Sec. 7. Baseline Framework to Reduce Cyber Risk to Critical Infrastructure. (a) The Secretary of Commerce shall direct the Director of the National Institute of Standards and Technology (the "Director") to lead the development of a framework to reduce cyber risks to critical infrastructure (the "Cybersecurity Framework"). The Cybersecurity Framework shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks. The Cybersecurity Framework shall incorporate voluntary consensus standards and industry best practices to the fullest extent possible. . . .
Sec. 8. Voluntary Critical Infrastructure Cybersecurity Program. (a) The Secretary, in coordination with Sector-Specific Agencies, shall establish a voluntary program to support the adoption of the Cybersecurity Framework by owners and operators of critical infrastructure and any other interested entities (the "Program"). . . .
Sec. 9. Identification of Critical Infrastructure at Greatest Risk. (a) Within 150 days of the date of this order, the Secretary shall use a risk-based approach to identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security. In identifying critical infrastructure for this purpose, the Secretary shall use the consultative process established in section 6 of this order and draw upon the expertise of Sector-Specific Agencies. The Secretary shall apply consistent, objective criteria in identifying such critical infrastructure. The Secretary shall not identify any commercial information technology products or consumer information technology services under this section. The Secretary shall review and update the list of identified critical infrastructure under this section on an annual basis, and provide such list to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs. . . .
Excerpts from President Barack Obama's Executive Order -- Improving Critical Infrastructure Cybersecurity. (photo: Mashable)
NATOSource

The daily news of the world's most powerful alliance.
The views expressed in NATOSource are solely those of the authors and do not necessarily reflect the views of the Atlantic Council, its staff, or its supporters.
Follow on Twitter: @NATOSource
"I am an enormous fan of NATOSource. I use it virtually every day, because it provides a wide variety of views, a solid base of factual knowledge, and keeps me in touch with the world of NATO."
Admiral James Stavridis, (Ret,), former SACEUR

(Graphics: Deutsche Welle and Reuters)
Most Popular NATOSource Posts
Key Issues
- Alliance Unity
- Allied Command Operations
- Allied Command Transformation
- Article 5
- Burden Sharing
- Capabilities Gap
- Chicago Summit
- Congress
- CSTO
- Cyber Threats
- Defense Spending
- Energy Security
- EU
- High North
- Intelligence
- ISAF
- Missile Defense
- NATO Defense Ministerials
- NATO Exercises
- NATO Ministerials
- NATO Operations
- NATO Partnerships
- NATO Response Force
- Nuclear Weapons
- OSCE
- Piracy
- R2P
- SACEUR
- SACT
- Secretary General
- Smart Defense
- Special Forces
- Strategic Concept
- Terrorism
- Transatlantic Relations
- United Nations
- Weapon Systems
TransAtlantic Links
Media Links
- Associated Press
- Baltic Times
- Brussels blog
- Deutsche Welle
- Economist
- EU Observer
- European Voice
- Financial Times
- Guardian
- Hurriyet Daily News
- International Herald Tribune
- Kathimerini
- Kyiv Post
- Le Monde Diplomatique
- Moscow Times
- New York Times
- Newsweek
- Prague Daily Monitor
- Radio Free Europe
- Reuters
- Ria Novosti
- Russia Today
- Slovak Spectator
- Spiegel
- St. Petersburg Times
- Sur
- Telegraph
- Times (London)
- Today's Zaman
- Wall Street Journal
- Washington Post
- Xinhua
- American Enterprise Institute (AEI), United States
- Aspen Institute, United States
- Atlantic Council, United States
- Brookings Institution, United States
- Carnegie Endowment for International Peace, United States
- Cato Institute, United States
- Center for a New American Security (CNAS), United States
- Center for International Relations (CIR), Poland
- Center for Security Studies (CSS), Switzerland
- Center for Strategic and International Studies (CSIS), United States
- Center for Transatlantic Relations, United States
- Cicero Foundation, Netherlands
- Council on Foreign Relations, United States
- Danish Institute of International Studies (DIIS), Denmark
- EU Institute for Security Studies, France
- European Council on Foreign Relations, Bulgaria, France, Germany, Spain, UK
- European Institute, United States
- Fondation pour la Recherche Stratégique (FRS), France
- French Institute of International Relations (IFRI), France
- Fundacion para el Análisis y los Estudios Sociale (FAES), Spain
- German Council on Foreign Relations (DGAP), Germany
- German Marshall Fund of the United States, United States
- Grupo de Estudios Estratégicos (GEES), Spain
- Heritage Foundation, United States
- Hoover Institution, United States
- Institut de Relations Internationales et Stratégiques (IRIS), France
- Institute for Foreign Policy Analysis (IFPA), United States
- Institute for International and Security Affairs (SWP), Germany
- Instituto Affari Internazionali (IAI), Italy
- International Institute for Strategic Studies (IISS), United Kingdom
- Konrad Adenauer Stiftung, Germany
- Lemnitzer Center, United States
- Marshall Center, Germany
- NATO Defense College
- Netherlands Institute of International Relations (Clingendael), Netherlands
- Norwegian Institute of International Affairs (NUPI), Norway
- RAND, United States
- Real Instituto Elcano, Spain
- Ridgway Center, United States
- Royal Institute of International Affairs (Chatham House), United Kingdom
- Royal United Services Institute (RUSI), United Kingdom
- Schuman Center (RSCAS), Italy
- Security & Defence Agenda (SDA), Belgium
- Strategy International (SI), Greece
- U.S. Institute of Peace, United States
- Woodrow Wilson International Center for Scholars, United States

