tools to find and fix vulnerabilities in critical software. Second, to mitigate the potential risks
posed by AI to our critical infrastructure, EO 14110 directs DHS to establish an AI Safety and
Security Board and, based on NIST’s AI Risk Management Framework, provide safety and
security guidelines to critical infrastructure owners and operators. Third, to protect the AI
ecosystem against cyber threats, developers of certain AI models will be required to report to the
Department of Commerce their capabilities for defending against sophisticated threat actors.
The Federal Government continues to engage with a wide range of stakeholders to prepare for a
post-quantum future. In August 2023, NIST submitted for public comment three draft Federal
Information Processing Standards (FIPS) designed to resist future attacks by cryptanalyticallyrelevant quantum computers. To support non-Federal cryptographic transitions, OMB, CISA,
NIST, and NSA published resources for organizations to develop and implement their own
Quantum-Readiness Roadmaps. NIST, NSA, and partners are working across multiple standards
developing organizations to integrate the expected NIST post-quantum cryptographic standard in
a wide variety of security standards. NIST also continues to engage with a working group of
industry, academic, and government stakeholders to identify and address the challenges related
to cryptographic transitions at the NIST National Cybersecurity Center of Excellence.
Managing Risks to Data Security and Privacy
In the absence of a national data privacy law, the Administration is pursuing targeted measures to
protect Americans’ data and their privacy, and enable safe, data-rich cross-border commerce.
EO 14117 on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States
Government-Related Data by Countries of Concern authorizes the Attorney General to prevent
the large-scale transfer of Americans’ personal data to countries of concern and provides
safeguards around other activities that can give those countries access to Americans’ sensitive
data. The protections authorized by EO 14117 will extend to genomic data, biometric data,
personal health data, geolocation data, financial data, and certain kinds of personal identifiers
that adversaries may exploit for a variety of nefarious purposes, including to engage in malicious
cyber-enabled activities.
The EU-U.S. Data Privacy Framework, finalized in July 2023, is a leading example of the
international partnership required for safe and trusted cross-border data flows. Alongside the
framework’s finalization, the Department of Commerce released the Data Privacy Framework
program website for companies participating in cross-border data transfers.
EO 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,
reinforces the importance of mitigating privacy risks in emerging technologies. EO 14110
directs departments and agencies to take steps to safeguard Americans’ privacy in the
development and deployment of AI. In December 2023, NIST issued draft guidance for agencies
on evaluating differential-privacy-guarantee protections. In February 2024, DOE and NSF
established a Research Coordination Network to advance research, development, and
implementation of privacy-enhancing technologies (PETs).
PETs are an important part of the Administration’s affirmative vision for a secure, trustworthy,
and rights-respecting digital ecosystem. To coordinate Federal efforts to harness PETs, the
2024 REPORT
24
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE