Once they find out the foreign location of the attacker, I'm sure it gets handed off to NSA at some level. And recently it seems the FBI isn't scared to seek criminal charges either.
It's not that it's the President's email that's vulnerable. It's that _all_ people's email is vulnerable.
Some of those people are key to national security, many aren't. But they all deserve privacy and protection.
And yes, one of NSA's mandates is to secure U.S. communications:
"The Information Assurance mission confronts the formidable challenge of preventing foreign adversaries from gaining access to sensitive or classified national security information. "
https://www.nsa.gov/about/mission/index.shtml
It's not just the President the NSA are failing.
No, their mandates is to secure military and national security systems. From your own link, their responsibilities with respect to information assurance are (emphasis mine):
- Act as the National Manager for National Security Systems as established in law and policy, and *in this capacity be responsible to the Secretary of Defense and to the Director, National Intelligence*
- Prescribe security regulations covering operating practices, including the transmission, handling, and distribution of signals intelligence and communications security material *within and among the elements under control of the Director of the National Security Agency*
The legal definition of National Security System is[1]: (1) National security system.— In this section, the term “national security system” means a telecommunications or information system operated by the Federal Government, the function, operation, or use of which—
(A) involves intelligence activities;
(B) involves cryptologic activities related to national security;
(C) involves command and control of military forces;
(D) involves equipment that is an integral part of a weapon or weapons system; or
(E) subject to paragraph (2), is critical to the direct fulfillment of military or intelligence missions.
(2) Limitation.— Paragraph (1)(E) does not include a system to be used for routine administrative and business applications (including payroll, finance, logistics, and personnel management applications).
NIST has responsibility for providing guidance on securing unclassified government systems and commercial networks.[2] Like the parent commenter said, securing White House communications in particular falls under the purview of the White House Communications Agency, which is subordinate to DISA.[3]Most of the efforts to bring the NSA and the rest of the intelligence agencies into the fold with regards to securing U.S. communications at large have been heavily protested: [4][5]
[1] https://www.law.cornell.edu/uscode/text/40/11103
[2] http://csrc.nist.gov/publications/nistbul/csl91-02.txt
[3] http://www.disa.mil/Careers/WHCA
[4] https://en.wikipedia.org/wiki/Cyber_Intelligence_Sharing_and...
[5] https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar...
Your point is the more important one. The danger here is not the breach, since it was an unclassified system, but rather the universal surprise that it was possible. That demonstrates a dangerous level of ignorance in our society.
Case in point: when was the last time you heard Russia/China arresting a hacker?
Not that the USA doesn't have plenty of malicious infosec hackers, that's just a silly notion.
[1] http://safe.cnews.ru/news/top/index.shtml?2015/04/13/594827
In other words without knowing how many hackers get away you can't make any assumption about the effectiveness of American hacker catching abilities.
Compare to spending billions of dollars building gigantic data centers, tapping fiber everywhere possible, recording every scrap of communication metadata that exists, actively subverting computers, doing quid pro quo spying on our allies domestic communications in exchange for them doing the same to us. Etc. Etc. Etc.
The grandiose profligacy is unending. That's how bureaucrats get promoted and get job satisfaction.
Actual "National Security" for the President, well, that's obviously beneath them.