cisagov / cyber.dhs.gov

A site for CISA directives
https://cyber.dhs.gov
Other
156 stars 61 forks source link

Comments from the U.S. Department of Transportation (CISO + All) #123

Closed aro-usdot closed 3 years ago

aro-usdot commented 4 years ago
aro-usdot commented 4 years ago

(DOT CISO) Additional comment - Large portions of the VDP requirements set forth in the BOD could and should be provided as a (cyber) shared service to Departments/Agencies both for efficiency of implementation and cost, and the consistency of execution and operation.

The envisioned flowing down of requirements, and unfunded mandates with requirements for Departments/Agencies to develop and implement their own solutions, and architect/engineer the appropriate data exchanges/uploads to DHS for visibility and reporting is an approach guaranteed to ensure slow progress, inefficiency and data quality issues.

If the matter of vulnerability management is important, as has been stated, then the fastest way forward is for the Department/Agency with the primary mission - and budget - to do the necessary acquisitions and provide it as a service to other agencies.