Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

How operating reality shifts under NSPM-12

Дата публикации: 10-08-2026 21:13:57

It shifts from decentralized, policy‑heavy efforts like zero trust guidance to a more centralized model that imposes uniform compliance and real accountability.

Основное содержимое страницы с новостью.

It shifts from decentralized, policy‑heavy efforts like zero trust guidance to a more centralized model that imposes uniform compliance and real accountability.

Scott Orton

August 10, 2026 5:13 pm

4 min read

In June, the White House issued National Security Presidential Memorandum 12 (NSPM-12) which restructures cybersecurity governance of the national security systems (NSS) that federal agencies use to store, process and share classified national security material. The memo directs some significant changes that will affect agencies’ operating reality, although the implications may be challenging to discern. Principally, NSPM-12 elevates the Committee on National Security Systems (CNSS) and the national manager role with the objective of greater uniformity and compliance with robust cyber protections across the federal government.

NSPM-12 rescinds two policies. One is the 1990 presidential National Security Directive 42, which established the organization now known as the CNSS. NSPM-12 retains the National Security Agency’s (NSA) original designation as the CNSS technical advisor and group member, while transferring the agency’s leadership role to a member of the National Security Council, which is chaired by the president. This is a significant elevation of the committee’s span of control and ultimate authority.

The other rescinded policy is the 2022 National Security Memorandum 8 (NSM-8). Many provisions of NSPM-12 are similar to NSM-8, which itself is similar to NSD-42, but a notable difference is that NSPM-12 does not contain NSM-8’s waiver process that allowed impacted agency heads to unilaterally disregard CNSS direction if they felt it necessary. Reviewing these policies chronographically, NSPM-12 is a meaningful escalation of the NSA’s authority to impose cyber technical capabilities instead of just advising or observing other agencies’ technical defenses.

These two key changes, arguably the most consequential in the memo, strongly suggest that Federal Civilian Executive Branch (FCEB) agencies are expected to comply with cybersecurity provisions that are standard practice in the Defense Department.

NSPM-12 directs that the national manager can order DoD and intelligence community (IC) agency compliance with NSS cyber security policies, along with the Office of Management and Budget directing FCEB compliance using NSA guidance. The national manager can collect agency metrics and data about threats against NSS systems, provide technical assistance and assign personnel to enhance oversight of FCEB agencies. Agencies can still present mission-specific objections with NSA requirements to the CNSS for adjudication, but cannot simply declare themselves exempt.

The memo puts DoD, IC, and FCEB agencies choosing non-compliance with CNSS directives on notice that the NSA is the new sheriff in town and that compliance to uniform, robust standards is the expectation. In particular, the NSA’s National Cross Domain Strategy and Management Office (NCDSMO) is a deputy with a lot more leeway to enforce their Raise the Bar directive broadly across all NSS.

Raising the bar on network protection

Among NSPM-12’s directives is a requirement for all agencies running NSS systems to use technology solutions for separating classification levels ― specifically charging the national manager with establishing requirements for cross-domain solutions (CDS). The government’s use of this technology is overseen by the NCDSMO. With the national manager now able to order compliance with NSA technical guidance, NCDSMO policies will likely enjoy greater adoption across all DoD and intelligence agencies, and likely FCEB agencies also. CDS are a foundational enforcement mechanism for the highest-level federal security policy on NSS. Uniform CDS standards hold promise for improving the federal government’s security posture while also enabling government efficiency through greater information sharing.

NSPM‑12 empowers the national manager to issue an emergency directive to any agency where it determines there is a “reasonably suspected information security threat” to that agency’s NSS. An emergency directive could include “any lawful action” around operating the NSS deemed necessary to protect it. That is a notably broad rationale for action and equally broad authority for response. The memo directs CNSS to establish baseline cybersecurity requirements for all NSS, which will support uniformity and compliance across agencies ― while informing government-wide incident response measures to help get ahead of any emergency directives. Architectures that allow safe data movement through CDS systems will facilitate effective response and reduce risk, allowing teams to extract logs, telemetry and forensics from compromised networks.

For agencies whose environments are not now architecturally aligned for implementing controlled separation, the NCDSMO provides Raise the Bar guidance detailing CDS security and capabilities across design, development, assessment, implementation and use. Its scope addresses improving the security of CDS solutions that protect classified information, offering standards, best practice guidance and suggested technologies that agencies can integrate into their architectures. Accessing and consuming these authoritative materials is the necessary first step to effective CDS implementation.

The reset on NSS governance

NSPM-12 marks a significant change of expectations for agency chief information officers and chief information security officers. It shifts from decentralized, policy‑heavy efforts like zero trust guidance to a more centralized model that imposes uniform compliance and real accountability. With self-decided exceptions no longer an option, agencies will need to work with the national manager toward greater compliance with a holistic approach to cybersecurity. The memo points us toward a future that views an agencies’ individual compliance weakness as a threat to the security posture of the whole federal government. NSPM-12 is a 36-year evolution of policy that has meaningfully shifted us from a federated cyber model for NSS to a centralized model structured to defend against an organized threat.

Scott Orton is chief executive officer of Owl Cyber Defense.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Army moves cloud management under its Cyber Command07.925-08-2026
2Observability as the backbone of compliance in a new federal cyber era08.417-04-2026
3FedRAMP and Identity Security: Why federal organizations are consolidating identity security platforms06.2130-07-2026
4AI incidents bolster push for federal cyber improvements08.6224-07-2026
5CMS moving beyond compliance-based cybersecurity020.2503-08-2026
6OPM to tighten reins on federal employees’ performance reviews06.8524-02-2026
7Three proposed changes to the process to remove federal employees09.7701-07-2026
8The Zero Trust Imperative for the Frontier AI Era05.531-07-2026
9The Journey towards Logically Air-Gapped Deployment018.8624-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.3. Источник: federalnewsnetwork.com.