Vivek Kundra, federal CIO, outlined plans for new cybersecurity metrics and a dashboard for tracking progress in testimony to Congress. “Historically, the federal government has not been as effective as necessary in its cyber defense,” Kundra said to the Senate Homeland Security and Governmental Affairs Committee’s Subcommittee on Federal Financial Management, Government Information, Federal Services, and International Security.
“An inadequate cybersecurity workforce, a focus on compliance rather than outcomes, and a cumbersome and time-consuming process for collecting information hindered our cybersecurity management capabilities.”
A Different Focus
Kundra hopes new initiatives will focus more on performance rather than on paperwork. “The metrics will be focused on game changing ways to address real security,” he said. “It is not necessarily asking the question, do you have patch management program, but how long does it take for you to patch those systems? We are in early phases in terms of deploying a government-wide approach.”
CyberScope
The Office of Management and Budget released a new tool called CyberScope a few weeks ago. It lets federal agencies report FISMA compliance via an authenticated Web-based reporting tool rather than sending spreadsheets via e-mail.
Annual report required
This year agencies are required to report detailed spending information on cybersecurity. That information will make its way to a federal cybersecurity dashboard similar to the IT Dashboard launched earlier this year, a public Web site that tracks federal IT spending and project performance. “Just as the IT dashboard took us from a static, paper based environment to a dynamic digital environment, the new cybersecurity dashboard will provide the government with a real-time view of threats facing us and our vulnerabilities,” Kundra said.
About Mailprotector
Mailprotector’s service provides a web console so you can view your email security whenever you want. You’ll be able to monitor things such as what is being blocked: spam, viruses, Trojans, phishing attacks and other email borne malware. You can get granular reporting down to the user by specific date ranges. You can implement your own specific email compliance policy within the console. You don’t have to wait on our dashboard to be developed – it’s ready and we’re able to get you going now.


