Perspectives on Federal Cybersecurity Spending
Summary
The federal government invests significant resources in cybersecurity across every agency through a variety of activities. Although a methodologically rigorous total for these investments has not been calculated and may not be possible, an understanding of how the federal government applies resources to protect U.S. public and private sector data and networks from cyberattacks is necessary for Congress to provide constructive oversight of those efforts.
This report considers federal cybersecurity investments in three broad categories:
Agency spending to protect its own systems, networks, and data;
Agency spending to protect other governmental systems, networks, and data; and
Agency spending to protect non-federal IT systems, networks, and data.
Each department and agency has some level of participation in cybersecurity activities. However, the Office of Management and Budget, the Department of Homeland Security, the Department of Commerce, the Department of Justice, and the Department of Defense have unique responsibilities established by statute—either for their role in assisting other departments and agencies, or, as in the case with the Department of Defense, for their unique responsibility for their own information technology.
Each February the administration releases three sets of documents which describe some facets of the government’s investments in cybersecurity:
The President’s Budget;
Congressional Budget Justifications from each department or agency; and
The Federal Information Security Management Act (FISMA) report to Congress.
These reports provide some valuable insights into how or why the government makes certain investments associated with promoting cybersecurity. However, on their own, none of these documents provides a complete and precise representation of how much the federal government is spending on cybersecurity. This is in part because of how they are developed; they are developed from agency submissions based on administration guidance that does not require methodologically consistent reporting on cybersecurity spending—or even provide a common definition for what cybersecurity is.
Even if such an authoritative top-line figure for federal cybersecurity investments were available, without detail and context it would not effectively inform the Congressional decision-making process. Understanding the risks an individual agency faces, and what strategies they have for confronting those risks given their size, complexity, and mission is vital to determining the appropriate level of future cybersecurity investments for that agency. Armed with an understanding of those factors, Congress may choose to assess cybersecurity investments of a federal agency independently. Congress may alternatively choose to assess internal cybersecurity investments by an agency relative to similar federal agencies, and external investments relative to, and supporting, the non-“.gov” sector.
Note: CRS reports are prepared for Members of Congress and their staffs. This summary is provided for informational purposes and does not constitute legal advice.
This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.