Technology
Sustaining Select Efforts To Strengthen The Nation’s Cybersecurity And Amending Executive Order 13694
Listen to the summary
0:00
Authority: The President uses powers under the Constitution and various laws to amend Executive Order 14144 regarding cybersecurity.
Amendments to Executive Order 14144:
- Section adjustments: Multiple subsections are struck and redesignated, simplifying the structure of the order.
- Policy focus: The new policy emphasizes the persistent cyber threats from nations like China, Russia, Iran, and North Korea, stressing the need for enhanced cybersecurity measures.
Actions by Agencies:
- The Secretary of Commerce and NIST are directed to develop guidance on secure software practices and ensure timely updates to published standards.
- Agencies are tasked with addressing vulnerabilities related to Border Gateway Protocol and preparing for quantum computing risks by transitioning to post-quantum cryptography.
- A focus on artificial intelligence (AI) is established, promoting research accessibility and vulnerability management in AI systems.
Policy Alignment and Implementation:
- Agencies are instructed to align cybersecurity policies with best practices and reduce risks in Federal information systems.
- A pilot program for machine-readable policy guidance is to be established, alongside requirements for IoT products to carry Cyber Trust Mark labeling by 2027.
Further Amendments to Previous Orders:
- Changes to Executive Order 13694 specify that references to "any person" are replaced with "any foreign person," tightening the scope of action against malicious cyber activities.
General Provisions:
- The order clarifies the limits of its authority, and it specifies that it does not create enforceable rights against the U.S. or its entities.
- Implementation of the order is subject to legal compliance and available appropriations.