NSA is just the US Foreign Intelligence and Government protection agency [1][2]. They do nothing, and are expected to do nothing, to protect domestic civilian assets.
NIST [3] is possibly the closest agency I'm aware of that exists to disseminate knowledge and standards to civilian organizations, but they're more interested (per their website, anyway) in simply advancing US business to be competitive in the global marketplace. That, and we've seen that they will bend to the NSA over such critical things as which elliptic curve ought to be recommended for use.
If I go to the NSA website it says "How We Protect the Nation" - So I infer that they do some work to protect something, but the US government was hacked "5.6 million fingerprints stolen in U.S. personnel data hack" https://www.theguardian.com/technology/2015/sep/23/us-govern...
The Democrat and Republican computers recently hacked, you will say they are not specifically government since they are political parties.
Many more US government hacks and leaks on a large scale I don't need to list.
So I assume from your answer that they are tasked at protecting USA government assets, but it seems they don't do a good job.
Well, the NSA does military signals intelligence. They protect US interests by compromising foreign assets, and by intercepting communications. In recent years, there have been efforts to expand its defensive role. But it's rather like the career transformation from "black-hat hacker" to security professional ;)
Nothing is 100% effective, and there will always be a long tail and diminishing returns on any economic organization, such as the NSA.
Additionally, there are simply too many unknowns to say that they're not doing a good job, and I think that's the nature of intelligence work. Lots of secrecy makes oversight and external efficacy judgments difficult to make; there's just not enough data.
It's like trying to say that a chess player is doing poorly when you don't know the size of the board, the number or types of pieces on either side, the positions, or really anything but an incomplete glimpse at the captured pieces of both sides. And they don't want you to see those pieces either, so even that is probably incomplete.
If they were doing their job, would you expect to hear about it? See the comments in this thread about Enigma. It's an interesting thought exercise; how do you tell the difference between peace which is organic and peace created through really effective intelligence?
I'm not arguing that the NSA is ineffective. I'm just saying that I haven't heard of much on the purely defensive side. Or at least, that's what I get from Bamford and the Snowden stuff. Maybe their defense is just unreported.
You assume incorrectly and should read the Information Assurance section on their page:
"NSA to secure National Security Systems, which includes systems that handle classified information or are otherwise critical to military or intelligence activities."
That does not include civilian networks or non-DoD government networks or any system that isn't designated a National Security System. It definitely isn't "protecting USA government assets" in general.
also... Snowden and Manning and Assange. and what those leaks entail about the "smartness" and eliteness of the NSA. People complain about Hillary having a private (well, non-government managed) email server. Yet look at all the leaks/hacks from government-owned/controlled/managed systems, and corporate.
My (yes, admittedly anecdotal and personal) perception is that Google/Gmail is more secure/smart/elite than the NSA. Based on public evidence to date.
So basically your perception is that an insider with access (Snowden, Manning) can leak more info than hackers? That's the most obvious and difficult security threat anywhere, something even Google/Gmail is susceptible to.
and yet... the supposed computer geniuses of the NSA allowed it to happen. whereas Google/Gmail has not, to date (that we're aware of, of course.) this was part of my point.
Keep in mind they have to defend against multiple state actors (Russia, China, even some much smaller countries with a lot of investment in SIGINT) who are also very competent and have a ton of attack vectors to work with.
Defense will never be perfect, however that is no excuse for not having dedicated organization training, audits and enacting and enforcing regulations strictly. While all of this may happen in bit and pieces, there is no single organization doing this and measuring their success by the number of attacks they prevent or failed to prevent.
NSA on the other hand wants backdoors and weakened cryptography tools...