Skip to main content

Critical Infrastructure Protection: Sector-Specific Plans' Coverage of Key Cyber Security Elements Varies

GAO-08-64T Published: Oct 31, 2007. Publicly Released: Oct 31, 2007.
Jump To:
Skip to Highlights

Highlights

The nation's critical infrastructure sectors--such as banking and finance, information technology, and public health--rely on computerized information and systems to provide services to the public. To fulfill the requirement for a comprehensive plan, including cyber aspects, the Department of Homeland Security (DHS) issued a national plan in June 2006 for the sectors to use as a road map to enhance the protection of critical infrastructure. Lead federal agencies, referred to as sector-specific agencies, are responsible for coordinating critical infrastructure protection efforts such as the development of plans that are specific to each sector. GAO was asked to summarize a report being released today that identifies the extent to which the sector plans addressed key aspects of cyber security, including cyber assets, key vulnerabilities, vulnerability reduction efforts, and recovery plans. In the report, GAO analyzed each sector-specific plan against criteria that were developed on the basis of DHS guidance.

Full Report

Office of Public Affairs

Topics

Command and control systemsComputer systemsCritical infrastructureCyber securityEnergyEvaluation criteriaHomeland securityInformation infrastructureInformation securityInformation technologyPublic healthRisk assessmentRisk managementStrategic planningSystem security plansTransportationSecurity standards