Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

White House Issues Memo to Bolster NSS Cybersecurity

NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS.

White House cybersecurity

President Trump on Friday signed National Security Presidential Memorandum-12 (NSPM-12) to bolster the cybersecurity of National Security Systems (NSS).

NSS includes the most sensitive computer systems in the US, used for the processing of classified information and for military and intelligence mission support.

The new memorandum establishes a clear structure for NSS governance and NSS cybersecurity requirements accountability, to ensure that NSS owned or operated by civilian agencies receive the same level of protection as those of the government.

“It shall be the policy of the United States Government to foster a proactive, adaptive, and resilient cybersecurity ecosystem for all NSS to better safeguard the Nation against persistent cyber threats from sophisticated adversaries,” NSPM-12 reads.

The memo also reestablishes the Committee on National Security Systems (CNSS), modernizing it to set baseline cybersecurity requirements across all NSS.

Per NSPM-12, CNSS will oversee NSS cybersecurity across the government, will issue emergency directives, provide authoritative minimum requirements, and promote coordination and information sharing to provide collaboration, standardization, and resource management.

Advertisement. Scroll to continue reading.

“The CNSS will leverage the combined authorities and resources of the Federal Chief Information Officer, the Chief Information Officers of the DOW and IC, and the Director of the National Security Agency (NSA) to ensure that there are no gaps or weak links in NSS defenses,” the White House’s NSPM-12 fact sheet reads.

Per the memorandum, the director of the NSA will serve as the National Manager for NSS to bolster NSS security, and a Policy Coordination Committee (PCC) will work with the CNSS on an NSS cybersecurity posture assessment.

The National Manager will provide technical advice to the CNSS, recommendations on incident response, and may issue emergency directives to protect the NSS in response to “intelligence of adversary capability and intent to target NSS,” the memo reads.

Per NSPM-12, within the next three months, CNSS shall revise specific directives, issue a roadmap and policy priority areas, decide which existing policies must be maintained and incorporated into directives, and “review all existing CNSS policies, directives, and instructions to determine which should be rescinded or harmonized”.

Agencies are required to maintain an inventory of NSS they own or operate, update it annually, and make it available to the National Manager.

Related: CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

Related: US Military Reaches Deals With 7 Tech Companies to Use Their AI on Classified Systems

Related: White House Scraps ‘Burdensome’ Software Security Rules

Related: CISA Closes 10 Emergency Directives as Vulnerability Catalog Takes Over

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.