Critical Infrastructure: Updating The 2013 NIPP And Other Risk Mitigation Actions

CM
Crowell & Moring LLP

Contributor

Our founders aspired to create a different kind of law firm when they launched Crowell & Moring in 1979. From those bold beginnings, our mission has been to provide our clients with the best services of any law firm in the world through a spirit of trust, respect, cooperation, collaboration, and a commitment to giving back to the communities around us.
Protecting critical infrastructure is paramount to today's digital age. Critical infrastructure includes physical and virtual systems essential for the functioning of our society, economy, and national security.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Protecting critical infrastructure is paramount to today's digital age. Critical infrastructure includes physical and virtual systems essential for the functioning of our society, economy, and national security. Such a definition may include power grids, communication networks, and financial institutions, among other networks that heavily rely on interconnected computer systems. These systems are also considered critical infrastructure, as they are used to protect critical cybersecurity infrastructure.

The Cybersecurity and Infrastructure Security Agency (CISA) has identified16 critical infrastructure sectorswhose assets are so "vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof." Cybersecurity is embedded in each of these. The National Infrastructure Protection Plan (NIPP) details how each sector must develop a sector-specific plan through coordinated efforts with public and private partners.

This plan, however, has not been updated since 2013. With the growth of the internet and integration of digital technology, critical infrastructure is more interconnected than ever before. Interconnectivity brings opportunities for efficiency and innovation, but also introduces new vulnerabilities. Since the release of the 2013 NIPP, the threat landscape has evolved significantly, with new and emerging risks posed by cyber threat actors. Thus, updating the 2013 NIPP is an important next step to enhancing the resilience and security of our nation's critical infrastructure.

In November 2023, the Biden Administrationannouncedits plans to review and revisePresidential Policy Directive 21, which established how federal agencies would steer protection of critical infrastructure and called for them to work together to create the 2013 NIPP. In the announcement, the White House acknowledged that an "updated policy would strengthen the public-private partnership and provide clear guidance to executive departments and agencies on designating certain critical infrastructure as systemically important." An updated NIPP would also complement theNational Cybersecurity Strategy, released in March 2023 as part of the Biden Administration's efforts to protect critical infrastructure through comprehensive cybersecurity measures, public-private partnerships, and information-sharing practices.

In February 2023, the Government Accountability Office (GAO) released areporton Critical Infrastructure Protection, calling on CISA to update the 2013 NIPP and provide templates for revising sector-specific guidance documents. On Oct. 25, 2023, the U.S. House of Representatives, Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held ahearingon federal cybersecurity governance, focusing on plans to raise the level of federal cybersecurity resilience across the government as a whole.

Protecting critical infrastructure is a complex and ongoing challenge requiring a collaborative, comprehensive, and proactive approach that enhances overall resilience. As we wait for an update to the NIPP, there are actions thatCISA suggestsgovernment contractors take to help protect the nation's security, such as setting specific goals and objectives, identifying infrastructure, implementing risk management activity, and measuring effectiveness. It is important to identify assets, systems, and networks that contribute to critical functionality and collect information pertinent to risk management, as well as to evaluate risk and consider potential direct and indirect consequences of an incident. Implementing a risk management approach, founded on prevention, protection, mitigation, response, and recovery activities, as well technical solutions, is an important step that companies may take to help protect the nation's critical infrastructure and therefore promote the resilience of our vital systems.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More