S1-DES-CIOCRM-2017, Designate the Senior Accountable Official for Cybersecurity Risk Management
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
Department of Energy
Washington, DC 20585
July 6, 2017
EXEC-2017-003964
MEMORANDUM FOR THE SECRETARY
THROUGH:
FROM:
SUBJECT:
MATTHEW B. MOURY
ACTING UNDER SECR
AND PERFORMANCE
STEPHEN (MAX) EVERETT t:8ML
CHIEF INFORMATION OFFICER ,1:/7''
ENT
ACTION: Designate the Senior Accountable Official for Cybersecurity
Risk Management
ISSUE: Pursuant to the Office of Management and Budget (0MB) Memorandum M-17-25,
the Department must notify 0MB of the senior accountable official that will be responsible
for implementing Section l(c) of the Executive Order on Strengthening the Cybersecurity of
Federal Networks and Critical Infrastructure (Executive Order).
BACKGROUND: Section l(c) of the Executive Order states that agency heads will be held
accountable by the President for implementing cybersecurity risk management measures,
and prescribes a series of actions that agencies must take to manage cybersecurity risk
attendant to Federal networks. OM B's implementation guidance grants the agency head
latitude to designate a senior accountable official responsible for implementation of this
section of the Executive Order so long as the individual is a direct report to the agency head
and possesses the requisite visibility and authority across the organization.
OPTIONS: Maintain the Secretary as the senior accountable official or delegate this
responsibility to a direct report.
RECOMMENDATION: That the Department submit the following statement to 0MB:
The Chief Information Officer, Stephen (Max) Everett, is the Department of Energy's
senior accountable official for implementing Section 1(c) of the Executive Order.
APPR0�:
2
?olSAPPROVE: ___ NEEDS DISCUSSION: ___ DATE: JUL l 0017
Designation No.
S1-DES-CIOCRM-2017