Business

Kristi Noem’s Approach to Protecting Critical Infrastructure

noem

In the complex landscape of national cybersecurity, the protection of critical infrastructure stands as a paramount concern. With Kristi Noem’s confirmation as the Secretary of the Department of Homeland Security (DHS) in President Donald Trump’s second term, there is a renewed focus on how cybersecurity policies, particularly those concerning critical infrastructure, might evolve. Noem’s approach, informed by her tenure as South Dakota’s Governor and her views expressed during her Senate confirmation hearings, suggests a redirection towards a more streamlined, mission-focused strategy for the Cybersecurity and Infrastructure Security Agency (CISA), which is housed within DHS.

CISA’s Role in Critical Infrastructure Protection

CISA was established to safeguard the nation’s critical infrastructure against cyber threats, a role it has been fulfilling since its inception in 2018. Critical infrastructure includes sectors like energy, finance, transportation, healthcare, and government facilities, all of which are increasingly reliant on digital systems. Noem’s vision for CISA involves refocusing its efforts to ensure that it primarily deals with cybersecurity threats rather than broader issues like misinformation, which she has argued diverts resources from its core mission.

This refocusing could mean several things for the protection of critical infrastructure:

Kevin Gallagher, President of Panurgy IT Solutions, has emphasized the critical nature of such partnerships: “Cloud backup has protections that mitigate risks like that — and more so today than five years ago. It’s important to have a backup in order to do that. If you get breached, you want to do away with whatever was a result of that attack and get back to business.”

CMMC Compliance and Critical Infrastructure

One of the pivotal aspects of cybersecurity in the defense sector, which can be extrapolated to broader critical infrastructure protection, is the Cybersecurity Maturity Model Certification (CMMC). Although initially developed for Department of Defense (DoD) contractors, CMMC’s principles of cybersecurity hygiene and maturity can serve as a model for protecting other types of critical infrastructure:

Challenges and Considerations

While Noem’s approach sounds promising, several challenges and considerations must be addressed:

Looking Forward

Noem’s leadership at DHS could mark a significant shift in how the U.S. approaches the cybersecurity of its critical infrastructure. By potentially adopting or adapting frameworks like CMMC, she aims for a scenario where every component of the nation’s critical services is not just reactive but also proactively secure against cyber threats. This involves not only policy changes but also cultural shifts within organizations to prioritize cybersecurity at every level of operation.

However, the success of these initiatives will hinge on several factors:

In conclusion, Kristi Noem’s approach to protecting critical infrastructure through a more focused CISA and possibly through CMMC-like compliance models represents a strategic pivot towards a more secure national cybersecurity posture. However, the execution of these plans will demand a nuanced understanding of both the technological landscape and the socio-political environment in which these policies will be implemented.