Trump Issues First Executive Order on Cybersecurity: While

New Post Public Reply Private Reply Replies (0) Message Board
CyberC
214
Trump Issues First Executive Order on Cybersecurity: While Goals Are Ambitious, Timelines Are Tight
May 16, 2017 Practices: Privacy & Data Security, Cybersecurity

On May 11, 2017, President Donald J. Trump signed an executive order addressing cybersecurity risk management across three key areas: (1) federal government networks, (2) critical infrastructure, and (3) cybersecurity for the nation as a whole (Order). The Order builds upon Presidential Policy Directive 21, issued by the prior administration on February 12, 2013, and orders agency heads and leaders across the executive branch to undertake a period of cybersecurity risk assessment, planning and reporting.

Taken together, the Order and its mandates aim to jump-start cybersecurity risk management activities within the federal government and establish concrete steps toward solving the aging federal information technology infrastructure – an area longcited as needing modernization. But while the Order’s requirements are substantial, the reporting deadlines are relatively short, and many experts in the field query whether impacted agencies – many of which already are facing budget constraints – can undertake meaningful risk assessments and required planning activities on such important topics within these tight timelines.

Embedded within the heap of reporting requirements were several new policy declarations on cybersecurity for the Trump administration:

Risk Allocation: Heads of executive departments and agencies shall be directly accountable for managing cybersecurity risks for their organizations;
NIST Cybersecurity Framework Alignment: Agencies must follow the NIST Cybersecurity Framework for its cybersecurity risk management, and the executive branch plans to align existing cybersecurity and policy regulations with the Framework; and
Shared / Consolidated Services: Agencies must “show preference” for shared IT services (including e-mail, cloud and cybersecurity services), and the executive branch aims to transition all agencies to using shared IT services, where feasible.
In all events, we can expect a flurry of activity across the federal government over the next few months as stakeholders work to meet the requirements of this ambitious Order. Here is a breakdown of those requirements.

Cybersecurity of Federal Networks

The Order establishes that it is “the policy of the United States to manage cybersecurity risk as an executive branch enterprise” and that “the President will hold heads of executive departments and agencies (agency heads) accountable for managing cybersecurity risk to their enterprises.”

In particular, the Order provides that agency heads will be held accountable to:

Implement “risk management measures commensurate with the risk and magnitude of the harm that would result from unauthorized access, use, disclosure, disruption, modification, or destruction of IT and data”; and
Ensure “that cybersecurity risk management processes are aligned with strategic, operational, and budgetary planning processes.”
Toward that end, the Order directs all agencies to use the NIST Framework for Improving Critical Infrastructure Cybersecurity (known as the “Cybersecurity Framework”) to manage each agency’s particularly cybersecurity risk. Notably, NIST released a proposed updated version of the Cybersecurity Framework earlier this year, adding a number of proposed improvements including important supplier controls.

90-Day Agency Reports

In addition, within 90 days of the executive order, all federal agencies must submit a cybersecurity “risk management report” to the Department of Homeland Security (DHS) and the Office of Management and Budget (OMB), documenting:

“(A) the risk mitigation and acceptance choices made by each agency head as of the date of this order, including:

(1) the strategic, operational, and budgetary considerations that informed those choices; and

(2) any accepted risk, including from unmitigated vulnerabilities; and

(B) describe the agency's action plan to implement the Framework.”

The goal of part (A) is to document a baseline of the agency’s current risk profile with relevant considerations, and the goal of part (B) is to outline the agency’s proposed steps for how to map and align that baseline to the Cybersecurity Framework.

Special rules and timing requirements apply to any National Security Systems.

60-Day Determination and Plan

After receiving the risk management reports from the agency heads, the Order then directs DHS and OMB, along with other stakeholders, to submit a report to the President within 60 days that assesses each agency report and makes a determination as to “whether the risk mitigation and acceptance choices set forth in the reports are appropriate and sufficient to manage the cybersecurity risk to the executive branch enterprise in the aggregate (the determination).” That 60-day report must also establish a plan to:

mitigate any identified risks to the executive branch;
address immediate unmet budgetary needs;
establish a regular process for reassessing these risks and future recurring budgetary needs;
revise all policies, standards, and guidelines issued by any agency necessary to meet the objectives of the Order, consistent with law; and
align such policies, standards, and guidelines with the Cybersecurity Framework.
Preference for Shared Services

The Order establishes a policy “to build and maintain a modern, secure, and more resilient executive branch IT architecture.” Toward that end, the Order directs agency heads to “show preference in their procurement for shared IT services, to the extent permitted by law, including email, cloud, and cybersecurity services.” This mandate brings the federal government more in line with the private sector trend in this same direction.

The Order also directs the American Technology Council to coordinate a report with relevant stakeholders within 90 days of the Order for how to modernize federal information technology systems. This report must outline the considerations relevant to transitioning federal agencies to consolidated network architecture and shared IT services. The Order directs agency heads to supply “information concerning their current IT architectures and plans as is necessary to complete this report on time.”

Cybersecurity of Critical Infrastructure

The second part of the Order focuses on using the executive branch’s “authorities and capabilities to support the cybersecurity risk management efforts of the owners and operators of the Nation’s critical infrastructure ... as appropriate.” The term “critical infrastructure” is defined in 42 USC s. 5195c(e) as “systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

This portion of the Order directs the DHS and relevant stakeholders to identify critical infrastructure at greatest risk of “attacks that could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security (section 9 entities)” and, within 180 days, to provide a report to the President with findings and recommendations for how to support the cybersecurity risk management activities of such critical infrastructure. The Order calls for an updated report to the President annually thereafter.

The Order then directs DHS and other relevant stakeholders to:

Within 90 days of the order, produce a report examining the “sufficiency of existing federal policies and practices to promote appropriate market transparency of cybersecurity risk management practices by critical infrastructure entities, with a focus on publicly traded critical infrastructure entities”
Lead an “open and transparent process” to identify ways “to improve the resilience of the internet and communications ecosystem and to encourage collaboration with the goal of dramatically reducing threats perpetrated by automated and distributed attacks (e.g., botnets)” producing a preliminary report of recommendations within 240 days and a final report due to the President one year from the date of the Order.
As for the energy sector, within 90 days of the Order, the Secretary of Energy, in collaboration with other stakeholders, must assess the “potential scope and duration of a prolonged power outage” that could stem from a significant cyberincident, the nation’s readiness to deal with such an outage, and any “gaps in assets or capabilities” necessary to address such an incident.

And finally, for the defense sector, within 90 days of the Order, the Secretary of Defense working with relevant stakeholders must report to the president on “cybersecurity risks facing the defense industrial base, including its supply chain, and United States military platforms, systems, networks, and capabilities, and recommendations for mitigating these risks.”

Cybersecurity of the Nation

The third and final substantive part of the Order focuses on cybersecurity of the nation as a whole and establishes that in order to “ensure that the internet remains valuable for future generations, it is the policy of the executive branch to promote an open, interoperable, reliable, and secure internet that fosters efficiency, innovation, communication, and economic prosperity, while respecting privacy and guarding against disruption, fraud, and theft.”

This portion of the Order focuses on deterrence and protection and international cooperation. In particular, it directs more reports to be prepared and submitted to the President:

Within 90 days, the Secretary of State, in collaboration with other stakeholders including trade representatives, must submit a report to the President “on the Nation's strategic options for deterring adversaries and better protecting the American people from cyber threats.”
Within 45 days, the Secretaries of State, Treasury, Defense, Commerce, and Homeland Security, in coordination with the Attorney General and the Director of the FBI, “shall submit reports to the President on their international cybersecurity priorities, including those concerning investigation, attribution, cyber threat information sharing, response, capacity building, and cooperation.”
Within 90 days, the Secretary of State must, in collaboration with the other Secretaries, provide a report to the President, “documenting an engagement strategy for international cooperation in cybersecurity.”
The Order closes its substantive directives by requiring a series of additional reports designed to identify and assure the development of a workforce to support the nation’s growing cybersecurity needs, and to ensure the United States “maintains a long-term cybersecurity advantage.”

Conclusion

As the Trump administration’s first executive action on cybersecurity, the Order calls for a thorough review of the federal government’s cybersecurity practices, but imposes minimal immediate consequences on the private sector or the marketplace.

At several points across the past three months, previously circulated drafts of the executive order did not allocate direct cybersecurity responsibility to agency heads, nor did it include the Federal Bureau of Investigation in its infrastructure review; both features are now included in the signed Order. By including defense and intelligence agencies in the infrastructure review, the executive order also allocates more responsibility to the military for federal cybersecurity, which had been previously resisted by the Obama administration.

Beyond the Order’s reporting and review requirements, the Order does signal the growing importance of the NIST Cybersecurity Framework on both the public and private sectors. The NIST Cybersecurity Framework was originally published in 2014 as a voluntary set of guidelines for federal agencies. Increasingly, regulators have referenced the NIST Cybersecurity Framework in their industry guidance and enforcement actions in an effort to guide companies toward its adoption. Now entities conducting business with federal agencies, directly or indirectly, should anticipate that government agencies will expect that those with whom those agencies do business will have adopted and be operating under the NIST Cybersecurity Framework or a widely recognized alternative. Moreover, the emphasis the Order places on consolidation of services should lead more service providers to consider the benefits of becoming FEDRAMP-certified.

For more information regarding the May 11 executive order or to discuss cybersecurity issues more generally, please contact Heather Egan Sussman, Jim DeGraw, Rohan Massey, Doug Meal, Seth Harrington, David McIntosh, Mark Szpak, Michelle Visser, Paul Rubin, Marc Berger, Laura Hoey, David Cohen, Dan Freshman, or another member of Ropes & Gray’s leading privacy & data security team.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Summit Tackles BRI Infrastructure's Role in Global SDGs

Updated Category News Views 2

A Bold Gathering with Lofty Goals Ever watch a room of world leaders debate the finer nuances of sustainable infrastructure? That's something Singapore pulled off on September 6, 2026, with the Second Global Business Summit on Belt and Road Infrastructure Investment. These aren't just any ordinary suits sitting around in a conference room. We're talking about a dynamic...

Continue Reading
Hims & Hers Faces Class Action: Investors Beware

Updated Category News Views 1

Allegations and Legal Pressure There's trouble brewing in the land of health and wellness apps, with Hims & Hers Health, Inc. (NYSE:HIMS) taking center stage. Slap on your glasses, folks, because this one's a doozy. A class-action lawsuit has exploded against the company and some of its officers—allegations flying as they focus on serious accusations of misleading...

Continue Reading
EyePoint Stumbles: Legal Eagles Circle Post-Trial Flop

Updated Category News Views 2

EyePoint Slips on Clinical Banana Peel Well, if EyePoint was aiming for a splash, they sure got it—just not the kind they were hoping for. News dropped like a lead balloon when EyePoint announced their Phase 3 DURAVYU trial results for wet age-related macular degeneration, revealing they missed their primary endpoint. And what did that mean for their stock? A death...

Continue Reading
Changhong's IFA 2026 Showcase: AI, Culture & Localization

Updated Category News Views 3

Changhong's Game Plan: From Global Reach to Local Touch Well, Changhong's not sitting back at IFA 2026, let me tell you that. This isn't your run-of-the-mill showcase; it's a full-on reveal of what happens when a company takes AI tech and tunes it to the heartbeat of daily life. TVs, fridges, air conditioners—you name it, they've got an AI twist on it. But is this just...

Continue Reading
FDI Launches 'Generation Smile' for Global Oral Health

Updated Category News Views 3

A New Kind of Movement Imagine a campaign not bound by age or geography but united by a shared mission. Generation Smile, freshly launched by the FDI World Dental Federation in Prague, is just that kind of uprising. This initiative redefines existing approaches to oral health, pushing beyond the boundaries of mere dental care to emphasize the integral role oral health...

Continue Reading
Pudu D7 Robot Shines at IFA, Setting New Robotics Bar

Updated Category News Views 2

Breaking New Ground in Robotics at IFA Well, here's a nugget for robotics buffs and investors alike: Pudu Robotics, a heavyweight in commercial service robotics, is carving out a fresh chapter with its PUDU D7. Making waves as an honoree at the IFA Innovation Awards, the D7 presents a mash-up of brains and brawn—exemplifying the future path for robotics. The PUDU D7...

Continue Reading
DUVA ONE Sleep Earbuds: Real-Time Innovation Debuts

Updated Category News Views 3

While You Dream, DUVA ONE Works Here's the scoop: DUVA just took sleep tech to another level with their DUVA ONE earbuds launched at Berlin's IFA 2026. These aren't just any earbuds; they're engineered to actually do something while you're sleeping. DUVA ONE senses what’s happening during your snooze session and adjusts right on the fly. The Night Patrol: In-Ear and...

Continue Reading
ATTACK SHARK Partners with Cloud9 League Team

Updated Category News Views 2

Shaking Hands with Cloud9 ATTACK SHARK is jumping headfirst into the esports game, teaming up with Cloud9's League of Legends team. Now, before you roll your eyes at another corporate matchmaking play, consider the magic at play here. League of Legends isn't just any game; it's a titan in the esports universe, and partnering with Cloud9 offers a serious boost. It's not...

Continue Reading
China's Manufacturing: Squeeze or Opportunity?

Updated Category News Views 3

Analyzing China's Impact on Global Markets Think of China's manufacturing clout and you're likely to picture booming factories, relentless steel, and smoke-churning industries reshaping the global chessboard. But here's the kicker: are they swallowing up room for others, or paving the way for their growth? It’s this debate that took the spotlight at the Asia-Pacific...

Continue Reading
TCL’s AI Vision: Immersive Living at IFA 2026

Updated Category News Views 0

AI and Displays: A Match Made in Tech Heaven Every so often, a company stands up at a tech fair and gives a glimpse into the next chapter of living, as TCL did at IFA 2026. This time, they're not just talking about screens; they're weaving them into the fabric of everyday life alongside AI capabilities. From sporting arenas to your living room, it's a vision of what could...

Continue Reading

Top 5 Most Recently Viewed Articles

Anika Therapeutics Shows Recovery in Q3 2024 Performance

Updated Category News Views 46

Anika Therapeutics Reports Q3 2024 Financials In a significant move, Anika Therapeutics, Inc. (NASDAQ: ANIK), a global leader in joint preservation, has reported its financial results for the third quarter ending September 30, 2024. This release follows the company’s strategic decisions to pivot its focus towards high-growth segments within the orthopedic industry. Key...

Continue Reading
Red Cat Secures $20 Million Funding for Drone Innovation

Updated Category News Views 328

Red Cat's Strategic Shift in Drone Technology Funding Red Cat Holdings, Inc. (Nasdaq: RCAT), a leader in drone technology designed for military, government, and commercial applications, has recently announced a significant financial move. The company secured an agreement for up to $20 million in debt financing, with the initial tranche of $16.5 million already completed....

Continue Reading
Investing in Alamos Gold: A 5-Year Performance Review

Updated Category News Views 84

Understanding Alamos Gold's Investment Potential Alamos Gold (NYSE: AGI) has shown impressive performance in the market over the past five years, boasting an annualized return of 27.3%. This strong growth has allowed the company to outperform the market by a significant margin of 12.72% annually. With a current market capitalization of approximately $8.42 billion, Alamos...

Continue Reading
Explore Phemex's Revolutionary 24/7 Futures Trading Hub

Updated Category News Views 135

Phemex Launches 24/7 TradFi Futures Trading Phemex, a user-focused cryptocurrency exchange, has recently announced an exciting development in trading: the introduction of their traditional finance (TradFi) futures trading. This innovative offering allows users to access a variety of traditional financial assets, including stocks and precious metals, at any time of the day...

Continue Reading
Kraig Biocraft Laboratories Announces New Production Milestone

Updated Category News Views 64

Kraig Biocraft Laboratories Reaches Remarkable Production Goal Kraig Biocraft Laboratories, Inc. (OTCQB: KBLB) has recently made headlines by completing a noteworthy production cycle that resulted in the delivery of over one million BAM-1 Alpha hybrid eggs. This significant achievement marks a pivotal moment for the company as they look to amplify their production...

Continue Reading