{"id":{"repo_id":"nps","oai_identifier":"oai:calhoun.nps.edu:10945/73127"},"canonical_url":"https://search.dev.ndltd.org/etd/nps/oai:calhoun.nps.edu:10945/73127","repository":{"repo_id":"nps","name":"Naval Postgraduate School","base_url":"https://calhoun.nps.edu/server/oai/request"},"display":{"title":"COMPARING TLS AND CERTIFICATE CONFIGURATIONS OF GOVERNMENT AND NON-GOVERNMENT WEBSITES","abstract":"This thesis seeks to identify the extent to which government has been successful in implementing security policy pertaining to TLS. Current accountability mechanisms mandate government organizations to formulate their internal cybersecurity policy in consultation with federal guidelines. However, internal leadership retains the authority to weigh and accept risks. This study measures adherence by government domains relative to a baseline of private domains not subject to policy mandate. We utilize a list of registered federal government domains and a sample of private sector domains sourced from the Alexa top one thousand and the Forbes Fortune 500 list. We scan and compare these samples for their adherence to the provisions of four government technical standards. We find that mandates to consult guidance are an effective strategy to drive conformance in some cases. While government entities subject to mandates are significantly more likely to implement relatively simple configuration changes, there remain gaps wherein guidelines are not being implemented. In such cases, government cybersecurity configurations closely resemble those of the private sector domains tested. We conclude by examining the possibility of other forces driving configuration decisions. This study aims to better understand the gaps between policy as written and policy as implemented and to explore the effectiveness of government mandates and other possible factors influencing security outcomes.","abstract_html":"This thesis seeks to identify the extent to which government has been successful in implementing security policy pertaining to TLS. Current accountability mechanisms mandate government organizations to formulate their internal cybersecurity policy in consultation with federal guidelines. However, internal leadership retains the authority to weigh and accept risks. This study measures adherence by government domains relative to a baseline of private domains not subject to policy mandate. We utilize a list of registered federal government domains and a sample of private sector domains sourced from the Alexa top one thousand and the Forbes Fortune 500 list. We scan and compare these samples for their adherence to the provisions of four government technical standards. We find that mandates to consult guidance are an effective strategy to drive conformance in some cases. While government entities subject to mandates are significantly more likely to implement relatively simple configuration changes, there remain gaps wherein guidelines are not being implemented. In such cases, government cybersecurity configurations closely resemble those of the private sector domains tested. We conclude by examining the possibility of other forces driving configuration decisions. This study aims to better understand the gaps between policy as written and policy as implemented and to explore the effectiveness of government mandates and other possible factors influencing security outcomes.","abstract_has_math":false,"creators":["Glade, Thomas L."],"institution":"Monterey, CA; Naval Postgraduate School","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Computer Science (CS)","school":null,"contributors":[],"advisors":["Kroll, Joshua A."],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-06","date_published":"2024-06","updated_at":"2026-07-27T20:24:46Z","subjects":[],"languages":[],"rights":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States."],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10945/73127","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Kroll, Joshua A."]},{"key":"dc:contributor.department","label":"Department","values":["Computer Science (CS)"]},{"key":"dc:creator","label":"Author","values":["Glade, Thomas L."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2024-08-19T16:32:26Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2024-08-19T16:32:26Z"]},{"key":"dc:date.issued","label":"Date","values":["2024-06"]},{"key":"dc:publisher","label":"Institution","values":["Monterey, CA; Naval Postgraduate School"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10945/73127"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["This thesis seeks to identify the extent to which government has been successful in implementing security policy pertaining to TLS. Current accountability mechanisms mandate government organizations to formulate their internal cybersecurity policy in consultation with federal guidelines. However, internal leadership retains the authority to weigh and accept risks. This study measures adherence by government domains relative to a baseline of private domains not subject to policy mandate. We utilize a list of registered federal government domains and a sample of private sector domains sourced from the Alexa top one thousand and the Forbes Fortune 500 list. We scan and compare these samples for their adherence to the provisions of four government technical standards. We find that mandates to consult guidance are an effective strategy to drive conformance in some cases. While government entities subject to mandates are significantly more likely to implement relatively simple configuration changes, there remain gaps wherein guidelines are not being implemented. In such cases, government cybersecurity configurations closely resemble those of the private sector domains tested. We conclude by examining the possibility of other forces driving configuration decisions. This study aims to better understand the gaps between policy as written and policy as implemented and to explore the effectiveness of government mandates and other possible factors influencing security outcomes."]},{"key":"dc:title","label":"Title","values":["COMPARING TLS AND CERTIFICATE CONFIGURATIONS OF GOVERNMENT AND NON-GOVERNMENT WEBSITES"]}]}],"canonical_facts":{"dc:contributor.advisor":["Kroll, Joshua A."],"dc:contributor.department":["Computer Science (CS)"],"dc:creator":["Glade, Thomas L."],"dc:date.accessioned":["2024-08-19T16:32:26Z"],"dc:date.available":["2024-08-19T16:32:26Z"],"dc:date.issued":["2024-06"],"dc:description.abstract":["This thesis seeks to identify the extent to which government has been successful in implementing security policy pertaining to TLS. Current accountability mechanisms mandate government organizations to formulate their internal cybersecurity policy in consultation with federal guidelines. However, internal leadership retains the authority to weigh and accept risks. This study measures adherence by government domains relative to a baseline of private domains not subject to policy mandate. We utilize a list of registered federal government domains and a sample of private sector domains sourced from the Alexa top one thousand and the Forbes Fortune 500 list. We scan and compare these samples for their adherence to the provisions of four government technical standards. We find that mandates to consult guidance are an effective strategy to drive conformance in some cases. While government entities subject to mandates are significantly more likely to implement relatively simple configuration changes, there remain gaps wherein guidelines are not being implemented. In such cases, government cybersecurity configurations closely resemble those of the private sector domains tested. We conclude by examining the possibility of other forces driving configuration decisions. This study aims to better understand the gaps between policy as written and policy as implemented and to explore the effectiveness of government mandates and other possible factors influencing security outcomes."],"dc:identifier.uri":["https://hdl.handle.net/10945/73127"],"dc:publisher":["Monterey, CA; Naval Postgraduate School"],"dc:rights":["This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States."],"dc:title":["COMPARING TLS AND CERTIFICATE CONFIGURATIONS OF GOVERNMENT AND NON-GOVERNMENT WEBSITES"],"dc:type":["Thesis"]},"updated_at":"2026-07-27T20:24:46Z"}