GAO:网络安全的未来:需要领导层全面定义量子威胁缓解战略(2024) 12页

VIP文档

ID:71821

大小:2.38 MB

页数:12页

时间:2024-11-22

金币:10

上传者:PASHU
Page 1 GAO-25-107703 Quantum Cybersecurity Strategy
Federal agencies and our nation's critical infrastructuresuch as energy,
transportation systems, communications, and financial servicesare dependent
on technology systems and electronic data to provide essential services and to
process, maintain, and report vital information. Agencies and critical
infrastructure owners and operators rely on cryptography (e.g., encryption) to
protect sensitive systems and data.
However, the emergence of quantum computers could undermine the security of
widely used cryptographic methods. Some experts predict that a quantum
computer capable of breaking certain cryptography—referred to as a
cryptographically relevant quantum computer (CRQC)may be developed in the
next 10 to 20 years, putting agency and critical infrastructure systems that rely on
cryptography for security at risk. Furthermore, adversaries could copy data
protected by cryptography today and store it with the intention of accessing it
later once a CRQC is developed.
We were asked to examine the federal government’s strategy to address the
threat that quantum computers pose to cryptography on unclassified systems.
This report provides information on how cryptographic methods protect systems
and data, the threat quantum computers pose, strategies that international
organizations have established to address this threat, and the U.S. national
quantum computing cybersecurity strategy and the extent to which it addresses
the desirable characteristics of a national strategy.
Various documents developed over the past eight years have contributed to
an emerging U.S. national quantum computing cybersecurity strategy. Based
on our review of these documents, we identified three central goals: (1)
standardize post-quantum cryptography, (2) migrate federal systems to that
cryptography, and (3) encourage all sectors of the economy to prepare for the
threat.
The U.S. strategy documents partially address the desirable characteristics of
a national strategy, as identified in prior GAO work. For example, with respect
to the objectives, activities, milestones, and performance measures
characteristic, the strategy documents identified objectives and activities for
the first two goals but not for the third. In addition, the strategy documents did
not fully identify milestones for the second and third goals and did not identify
performance measures for any of the three goals.
U.S. Government Accountability Office
Future of Cybersecurity: Leadership Needed to
Fully Define Quantum Threat Mitigation
Strategy
GAO
-25-107703
Q&A
Report to the Subcommittee on Emerging Threats and Spending Oversight, Committee on Homeland
Security and Governmental Affairs, U.S.
Senate
November
21, 2024
Why This Matters
Key Takeaways
资源描述:

密码学是一组可以“锁定”、“解锁”或验证信息的数学过程。机构、银行、公用事业公司和其他公司依赖。。。

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭