Cybersecurity: Improvements Needed in Addressing Risks to Operational Technology

Much of the nation's critical infrastructure relies on operational technology (OT)—systems that interact with the physical environment—to provide essential services. However, malicious cyber actors pose a significant threat to these systems. Federal law designates Cybersecurity and Infrastructure Security Agency’s (CISA) as the lead agency in helping critical infrastructure owners and operators address cyber risks to OT. The National Defense Authorization Act of Fiscal Year 2022 includes a provision for the U.S. Government Accountability Office (GAO) to report on CISA’s support for industrial control systems. Federal guidance now addresses these systems under the broader category of OT. Accordingly, this report examines, among other things: (1) challenges in delivering CISA’s OT products and services, and (2) challenges to collaborating between CISA and the seven selected agencies. GAO reviewed documentation describing CISA’s 13 OT cybersecurity products and services. GAO also asked officials from CISA and 13 selected nonfederal entities to identify any challenges with the OT products and services. The selected entities included (1) councils representing one sector and three subsectors where OT was prevalent and the intelligence community highlighted their infrastructures as being at risk from cyber threat actors, (2) OT vendors who joined a CISA OT collaboration group, and (3) cybersecurity researchers that contributed to the development of CISA’s OT advisories. GAO then compared CISA’s efforts to address those challenges against leading practices regarding measuring customer service and workforce planning.

Language

  • English

Media Info

  • Media Type: Digital/other
  • Features: Appendices; Figures; References; Tables;
  • Pagination: 70p

Subject/Index Terms

Filing Info

  • Accession Number: 01911030
  • Record Type: Publication
  • Report/Paper Numbers: GAO-24-106576
  • Files: TRIS
  • Created Date: Mar 8 2024 9:14AM