Clicky

From Cybersecurity Governance to Data Readiness: How Agencies Can Support NSPM-12 

Become an Insider.

Get Modern Integrated Warfare news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

The White House’s National Security Presidential Memorandum, NSPM-12 is explicitly focused on cybersecurity governance for national security systems, but many of its requirements depend on agencies having trusted, governed, and timely access to data about systems, policies, incidents, metrics, risks, and operational responsibilities. To implement the memorandum effectively, agencies need more than isolated security controls; they need a governed data foundation that helps them understand their environment, coordinate across agencies and mission partners, enforce policy consistently, and support mission-critical decisions. 

NSPM-12 establishes a renewed governance model for National Security Systems, with a strong focus on accountability, standardization, coordination, performance metrics, system inventories, secure shared services, policy dissemination, and information sharing across defense, intelligence, and civilian agencies. While the memorandum is explicitly focused on cybersecurity governance for National Security Systems, many of its implementation requirements depend on something broader and more foundational: the ability to connect, govern, understand, and use distributed data across complex agency and mission environments. 

An AI data layer , like the platform Denodo provides, can address this need, offering unified, governed access layer for distributed mission and agency data. Compliance with NSPM-12 will depend on the policies, authorities, controls, and security programs defined by the government. The role of such a layer is more focused: helping agencies create the governed data foundation needed to operationalize those requirements across distributed systems. 

An AI data layer is not a replacement for cybersecurity platforms, cryptographic systems, endpoint protection, network defense, incident response tools, or the authorities and controls defined by NSPM-12. Instead, it sits above an agency’s distributed data sources and creates a single, governed point of access to mission data. By centralizing data access through this layer, agencies can define and enforce consistent security policies, apply governance at runtime, and reduce the need for authorized users, mission applications, analytics tools, and AI systems to connect directly to every underlying source. This can help reduce the exposed surface area of the agency data environment, limit unnecessary data movement, and provide an additional layer of control over how sensitive data is discovered, accessed, and delivered. 

In this way, an AI data layer does not replace cybersecurity controls; it complements them by strengthening the data access foundation agencies need to support secure operations, governed collaboration, and mission-ready decision-making. 

NSPM-12 Raises the Bar for Governed Data Access 

NSPM-12 calls for stronger accountability and oversight across National Security Systems. It emphasizes the need for agencies to coordinate more effectively, maintain inventories, support government-wide metrics, promote shared services, improve access to policy guidance, and ensure owners and operators are accountable for implementing required security measures. 

Each of these objectives depends on data. 

Agencies need to know where relevant data resides, what it means, who is allowed to access it, how it is being used, and whether it can be trusted. But in most government environments, that data is spread across legacy systems, cloud platforms, mission applications, operational repositories, security tools, and agency-specific data stores. Moving all of that data into a single platform is often impractical, costly, risky, or inconsistent with mission and security requirements. 

A more practical approach is to establish a logical data layer that connects data where it resides and makes it available through governed, reusable, semantically consistent data products.  

Creating Active Context 

A well-designed AI Data Layer creates “active context” by connecting, governing, and unifying distributed mission and agency data through live, governed access. Active context gives agencies a trusted, operationally aware view of their data estate, so users, applications, analytics platforms, and AI systems can work with the right data, in the right mission context, at the right time. 

For agencies responding to NSPM-12, active context can help bridge the gap between policy requirements and operational execution. Policies, standards, and directives are essential, but agencies also need the data infrastructure to apply them consistently across distributed systems, cloud environments, mission domains, and organizational boundaries. This kind of infrastructure relies on four core pillars: universal connectivity, zero-copy delivery, governed access, and semantic Trust. 

Universal Connectivity: Connecting Distributed Mission Data 

NSPM-12 highlights the need for coordination across the Department of War, Intelligence Community, and Federal Civilian Executive Branch agencies, as well as access to shared guidance, policies, requirements, and related decisions. Supporting this level of coordination requires access to data across many different systems and environments. 

Universal connectivity enables agencies to connect to distributed data sources across on-premises systems, cloud platforms, SaaS applications, legacy repositories, data lakes, lakehouses, warehouses, and operational systems. Rather than forcing agencies to move data into a single repository before it can be used, solutions like Denodo provide a unified access layer across the existing data estate. 

For NSPM-12-related initiatives, this can help agencies bring together the data needed for system inventories, reporting, compliance analysis, operational oversight, policy implementation, and cross-agency collaboration without creating another layer of unnecessary data duplication. 

Zero-Copy Delivery: Reducing Unnecessary Data Movement 

Government agencies often operate under strict requirements for data protection, classification, sovereignty, and operational resilience. In these environments, copying sensitive data into multiple downstream systems can increase complexity, cost, and risk. 

Zero-copy delivery allows agencies to access and deliver data without unnecessary movement or replication. Data can remain in its source systems while a governed access layer provides live access through logical views and reusable data products. 

This aligns well with the operational realities behind NSPM-12. Agencies need better visibility and coordination, but they also need to avoid creating new data sprawl or expanding risk through uncontrolled duplication. A zero-copy approach helps agencies make data more usable while keeping governance and access controls centralized at the point of delivery. 

Governed Access: Applying Policy at Runtime 

NSPM-12 places significant emphasis on accountability, compliance, and the implementation of required security measures by NSS owners and operators. It also calls for mechanisms that help agencies access authoritative guidance, requirements, and related policies. For data programs, this reinforces an important point: governance cannot remain only in documentation, policy repositories, or catalog entries. It must be applied when data is accessed and used. 

Governed access means defining and enforcing centralized data access policies across distributed data sources. Instead of managing access inconsistently across many individual systems, agencies can use a single data access layer where policies are applied consistently to users, applications, analytics tools, and AI systems. 

This can help agencies strengthen control in several ways. First, it reduces the need to expose underlying data sources directly to every consumer. Second, it enables agencies to apply access policies at runtime, based on the user, role, data sensitivity, purpose, or operational context. Third, it creates a more consistent control point for monitoring, auditing, and managing how data is delivered across the agency data environment. 

For agencies working to support NSPM-12, this kind of runtime governance can help turn policy intent into operational control. The result is not just better documentation of policy, but more consistent enforcement of policy at the point where data is actually consumed. 

Semantic Trust: Making Data Understandable and Reliable 

NSPM-12 calls for stronger coordination, performance metrics, system inventories, and shared access to authoritative guidance. These requirements are not only technical; they also depend on shared understanding. Agencies need to know what data means, how it relates to policies and systems, and whether it can be trusted for decision-making. 

Semantic trust provides a consistent business and mission-oriented understanding of distributed data. By creating reusable semantic models and governed data products, Denodo helps agencies ensure that users and systems are working from consistent definitions, trusted relationships, and shared context. 

This is increasingly important as agencies explore AI and agentic systems. AI systems do not simply need access to more data; they need access to trusted, governed, and semantically meaningful context. An AI data layer helps provide that context by connecting AI systems to live mission and operational data with the governance, meaning, and operational awareness required for responsible use. 

From Cybersecurity Governance to Operational Data Readiness 

NSPM-12 is a cybersecurity governance directive, but its success will depend in part on how effectively agencies can operationalize data across complex environments. Agencies will need to support inventories, metrics, reporting, incident response, policy harmonization, cloud oversight, shared services, and cross-agency coordination. Each of these efforts requires trusted access to distributed data. 

An AI data layer helps agencies support these initiatives by creating active context across the agency data environment. This does not replace cybersecurity controls, cryptographic standards, incident response systems, or classified domain protections. Instead, it complements them by making relevant data easier to connect, govern, understand, secure, and use. 

For agency leaders, this creates a practical path forward. Rather than waiting for large-scale data consolidation programs, agencies can establish a logical data layer that works across existing systems and environments. This enables faster access to trusted data, stronger governance at the point of use, reduced data duplication, and more consistent context for analytics, applications, reporting, and AI. 

Supporting the Mission with Trusted Data 

NSPM-12 reinforces the importance of resilience, accountability, coordination, and secure operations across National Security Systems. To support those objectives, agencies need more than isolated systems and fragmented data pipelines. They need a modern data foundation that can provide trusted, governed, real-time context across the enterprise. 

Platforms such as Denodo are heading in this direction: architectures built around governed access, zero-copy delivery, universal connectivity, and semantic trust. The goal is to create active context from distributed data, enabling agencies to support mission-critical decisions with greater confidence, consistency, and control.  

As agencies work to interpret and implement NSPM-12, the opportunity is not only to strengthen cybersecurity governance. It is also to modernize the data foundation that makes governance actionable, measurable, and operational across the mission. 

The author, Kevin Bohan, is Director of Product Marketing at Denodo.