The Committee on National Security Systems (CNSS) is a United States intergovernmental organization that sets policies for the security of the US security systems. The CIA triad (
data confidentiality,
data integrity
Data integrity is the maintenance of, and the assurance of, data accuracy and consistency over its entire Information Lifecycle Management, life-cycle. It is a critical aspect to the design, implementation, and usage of any system that stores, proc ...
, and
data availability) are the three main security goals of CNSS.
History
The Committee dates its establishment back to 1953, under the name of U.S. Communications Security Board (USCSB).
Under the name National Security Telecommunications and Information Systems Security Committee (NSTISSC) the committee was established by the
National Security Directive
National security directives are presidential directives issued for the National Security Council (NSC). Starting with Harry Truman, every president since the founding of the National Security Council in 1947 has issued national security directi ...
42, "National Policy for the Security of National Security Telecommunications and Information Systems", dated 5 July 1990. On October 16, 2001,
President
President most commonly refers to:
*President (corporate title)
* President (education), a leader of a college or university
*President (government title)
President may also refer to:
Arts and entertainment Film and television
*'' Præsident ...
George W. Bush
George Walker Bush (born July 6, 1946) is an American politician and businessman who was the 43rd president of the United States from 2001 to 2009. A member of the Bush family and the Republican Party (United States), Republican Party, he i ...
signed
Executive Order
In the United States, an executive order is a directive by the president of the United States that manages operations of the federal government. The legal or constitutional basis for executive orders has multiple sources. Article Two of the ...
13231, the Critical Infrastructure Protection in the Information Age, re-designating NSTISSC as the Committee on National Security Systems.
Activities
The CNSS holds discussions of policy issues, sets national policy, directions, operational procedures, and guidance for the information systems operated by the U.S. Government, its contractors or agents that either contain classified information, involve intelligence activities, involve cryptographic activities related to national security, involve command and control of military forces, involve equipment that is an integral part of a weapon or weapons system(s) or are critical to the direct fulfillment of military or intelligence missions.
The
Department of Defense
The United States Department of Defense (DoD, USDOD, or DOD) is an executive department of the U.S. federal government charged with coordinating and supervising the six U.S. armed services: the Army, Navy, Marines, Air Force, Space Force, ...
chairs the committee. Membership consists of representatives from 21 U.S. Government Departments and Agencies with voting privileges, including the
CIA,
DIA,
DOD,
DOJ,
FBI
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
,
NSA, and the
National Security Council
A national security council (NSC) is usually an executive branch governmental body responsible for coordinating policy on national security issues and advising chief executives on matters related to national security. An NSC is often headed by a n ...
, and all
United States Military
The United States Armed Forces are the Military, military forces of the United States. U.S. United States Code, federal law names six armed forces: the United States Army, Army, United States Marine Corps, Marine Corps, United States Navy, Na ...
Services. Members not on the voting committee include the
DISA,
NGA,
NIST
The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into physical s ...
, and the
NRO. The operating Agency for CNSS appears to be the
National Security Agency
The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
, which serves as the primary contact for public inquiries.
Certification
The CNSS defines several standards, which include standards on training in
IT security
Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
. Current
certification
Certification is part of testing, inspection and certification and the provision by an independent body of written assurance (a certificate) that the product, service or system in question meets specific requirements. It is the formal attestatio ...
s include:
* NSTISSI-4015 National Training Standard for Systems Certifiers
* CNSSI-4016 National Information Assurance Training Standard For Risk Analysts
* NSTISSI-4011 National Training Standard for Information Systems Security (INFOSEC) Professionals
* CNSSI-4012 National Information Assurance Training Standard for Senior Systems Managers
* CNSSI-4013 National Information Assurance Training Standard For System Administrators
* CNSSI-4014 Information Assurance Training Standard for Information Systems Security Officers
CNSS launched the
National Information Assurance Certification and Accreditation Process (NIACAP) in 2000 (was cancelled in 2012).
References
Sources
*
* {{cite conference , last1=Schou , first1=C. , conference=4th Australian Information Warfare and IT Security Conference – Enhancing Trust , date=2003 , publisher=
University of South Australia , location=
Adelaide, Australia , title=Standards, Standards, Standards, Who has the Standards? , url = https://www.academia.edu/download/4733002/10.1.1.96.7578.pdf#page=311
External links
Official WebsiteCrypto Security NewsVulnerability Assessment
Computer security organizations
United States government secrecy
Independent agencies of the United States government
Government agencies established in 2001
2001 establishments in the United States