Scott Orton, CEO, Owl Cyber Defense
In June, the White House issued National Security Presidential Memorandum 12 (NSPM-12) which restructures cybersecurity governance of the national security systems (NSS) that federal agencies use to store, process, and share classified national security material. The Memo directs some significant changes that will affect agencies’ operating reality, although the implications may be challenging to discern. Principally, NSPM-12 elevates CNSS and the National Manager role with the objective of greater uniformity and compliance to robust cyber protections across the Federal government.
NSPM-12 rescinds two policies. One is the 1990 presidential National Security Directive 42 which established the organization now titled the Committee on National Security Systems (CNSS). NSPM-12 retains the National Security Administration’s (NSA) original designation as the CNSS technical advisor and group member, while transferring the agency’s leadership role to a member of the National Security Council, which is chaired by the President. This is a significant elevation of the Committee’s span of control and ultimate authority.
The other rescinded policy is the 2022 National Security Memorandum 8 (NSM-8). Many provisions of NSPM-12 are similar to NSM-8, which itself is similar to NSD-42, but a notable difference is that NSPM-12 does not contain NSM-8’s waiver process that allowed impacted agency heads to unilaterally disregard CNSS direction if they felt it necessary. Reviewing these policies chronographically, NSPM-12 is an meaningful escalation of the NSA’s authority to impose cyber technical capabilities instead of just advising or observing other agencies’ technical defenses.
These two key changes, arguably the most consequential in the memo, strongly suggest that Federal Civilian Executive Branch (FCEB) departments are expected to comply with cyber security provisions that are standard practice in the Department of War (DoW).
NSPM-12 directs that the National Manager can order DoW and Intelligence Community (IC) agency compliance with NSS cyber security policies, along with the Office of Management and Budget (OMB) directing FCEB compliance using NSA guidance. The National Manager can collect agency metrics and data about threats against NSS systems, provide technical assistance and assign personnel to enhance oversight of FCEB agencies. Agencies can still present mission-specific objections with NSA requirements to the CNSS for adjudication, but cannot simply declare themselves exempt.
The memo puts DoW, IC, and FCEB agencies choosing non-compliance with CNSS directives on notice that the NSA is the new sheriff in town and that compliance to uniform, robust standards is the expectation. In particular, the NSA’s National Cross Domain Solutions Management Office (NCDSMO) is a deputy with a lot more leeway to enforce their Raise The Bar directive broadly across all NSS.
Raising the Bar on Network Protection
Among NSPM-12’s directives is a requirement for all agencies running NSS systems to use technology solutions for separating classification levels―specifically charging the National Manager to establish requirements for cross-domain solutions (CDS). The government’s use of this technology is overseen by the NCDSMO. With the National Manager now able to order compliance with NSA technical guidance, NCDSMO policies will likely enjoy greater adoption across all DoW and intelligence agencies, and likely FCEB agencies also. CDS are a foundational enforcement mechanism for the highest-level federal security policy on NSS. Uniform CDS standards hold promise for improving the federal government’s security posture while also enabling government efficiency through greater information sharing.
NSPM‑12 empowers the National Manager to issue an emergency directive to any agency where it determines there is a “reasonably suspected information security threat” to that agency’s NSS. An emergency directive could include “any lawful action” around operating the NSS deemed necessary to protect it. That is a notably broad rationale for action and equally broad authority for response. The Memo directs CNSS to establish baseline cybersecurity requirements for all NSS, which will support uniformity and compliance across agencies―while informing government-wide incident response measures to help get ahead of any emergency directives. Architectures that allow safe data movement through CDS systems will facilitate effective response and reduce risk, allowing teams to extract logs, telemetry and forensics from compromised networks.
For agencies whose environments are not now architecturally aligned for implementing controlled separation, the NCDSMO provides Raise the Bar guidance detailing CDS security and capabilities across design, development, assessment, implementation and use. Its scope addresses improving the security of CDS solutions that protect classified information, offering standards, best practice guidance and suggested technologies that agencies can integrate into their architectures. Accessing and consuming these authoritative materials is the necessary first step to effective CDS implementation.
The Reset on NSS Governance
NSPM-12 marks a significant change of expectations for agency Chief Information Officers and Chief Information Security Officers. It shifts from decentralized, policy‑heavy efforts like zero trust guidance to a more centralized model that imposes uniform compliance and real accountability. With self-decided exceptions no longer an option, agencies will need to work with the National Manager towards greater compliance with a wholistic approach to cyber security. The Memo points us toward a future that views an agencies’ individual compliance weakness as a threat to the security posture of the whole federal government. NSPM-12 is a 36 year evolution of policy that has meaningfully shifted us from a federated cyber model for NSS to a centralized model structured to defend against an organized threat.
This article originally appeared on Federal News Network.
Media contact
Carolyn Ford
SVP, Marketing
Owl Cyber Defense
cford@owlcyberdefense.com