Computer Security: A Summary of Selected Federal Laws, Executive Orders, and Presidential Directives

J. Moteff · 2004

This report provides a short summary of selected federal laws, executive orders, and presidential directives, currently in force, that govern computer security. The report focuses on the major roles and responsibilities assigned various federal agencies in the area of computer security. This report will not be updated. One major area of federal activity in computer security deals with se curing federal computer systems The roles and responsibilities for securing federal computer systems are split between national security systems and all other federal systems The Federal Information Security Management Act of 2002 authorizes the Director of the Office and Management and Budget to oversee the development of, and compliance with, security standards and guidelines, developed by the National Institute of Standards and Technology and promulgated by the Secretary of Commerce. These authorities, however, do not apply to computer systems considered to be national security systems. The roles and responsibilities for securing national security systems are established by National Security Directive 42 (NSD-42). NSD-42 establishes what is now called the Committee on National Security Systems, which it authorizes to develop, and require compliance with, standards and guidelines for national security systems.

Read the paper · More papers on PaperTik