CISA’s Connelly: Agencies Can’t Only Focus on Identity for Zero Trust Dec 2, 2021 | 9:00 am Identity management is one of the main pillars of the Cybersecurity and Infrastructure Security Agency’s (CISA) Zero Trust Maturity Model, but CISA’s program lead for the Trusted Internet Connection (TIC) program office Sean Connelly said that while identity is an important pillar, it should not be the only pillar agencies focus on. […]
CISA Names Members of New Cybersecurity Advisory Committee Dec 1, 2021 | 2:23 pm The Cybersecurity and Infrastructure Security Agency (CISA) announced the members of its new Cybersecurity Advisory Committee, which will be tasked with advising and providing recommendations to the CISA director on policies, programs, planning, and training to enhance the nation’s cyber defense. […]
MITRE Pressing Cyber, FISMA Recommendations Ahead of NDAA Votes Nov 26, 2021 | 2:13 pm MITRE Corp., the operator of Federally-funded R&D centers that aim to help the U.S. government with a host of scientific and tech research issues, is advancing a series of recommendations for congressional action on high-profile cybersecurity issues prior to Senate action beginning Nov. 29 on the FY2022 National Defense Authorization Act (NDAA) which features numerous provisions that would impact Federal cyber defenses. […]
DHS Taps Director of Operations for Cyber Talent Management System Nov 26, 2021 | 12:39 pm The Department of Homeland Security (DHS) has tapped Erin Hayes to serve as the director of operations for its just-launched Cybersecurity Talent Management System (CTMS), according to Hayes’ LinkedIn. […]
Top Cyber/IT Amendments to Watch for in FY2022 NDAA Nov 26, 2021 | 11:55 am As the Senate returns to work on Nov. 29 with the completion of debate on the Fiscal Year (FY) 2022 National Defense Authorization Act (NDAA) at the top of its agenda, lawmakers will be looking to tack on a host of cybersecurity-related amendments to the defense spending bill. […]
CISA Looking to Increase Email Security Capabilities Nov 26, 2021 | 11:18 am The Cybersecurity and Infrastructure Security Agency (CISA) has issued a request for information (RFI) focused on email security capabilities that will protect Federal networks and the Federal Civilian Executive Branch (FCEB) .gov domain enterprise from threats and strengthen cyber defenses. […]
Former DefSec Carter Calls for Stronger Retaliation Against Cyberattacks Nov 26, 2021 | 9:00 am Former U.S. Secretary of Defense Ash Carter said cybersecurity risks are a “very serious matter” and called for stronger retaliation from the U.S. government and Department of Defense (DoD) against malicious cyber actors. […]
CISA’s Easterly: Visibility, Modernization are Keys to Cybersecurity Nov 23, 2021 | 9:00 am As the Federal government continues to focus on boosting the nation’s cybersecurity hygiene, Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly said Nov. 18 that visibility and modernization are the keys to improving the nation’s cybersecurity posture. […]
CISA, FBI Issue Ransomware Warning for Holiday Season Nov 22, 2021 | 3:29 pm The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a cybersecurity advisory today, warning public and private sector organizations to stay vigilant for ransomware attacks and other cyberattacks leading up to and during the holiday season. […]
Sens. Peters, Portman Still Pitching FISMA Reform Inclusion in NDAA Nov 22, 2021 | 1:27 pm After a potential setback late last week, Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, are still looking to attach their legislation to reform the Federal Information Security Modernization Act (FISMA) added to the Senate’s fiscal year (FY) 2022 National Defense Authorization Act (NDAA) making its way through the chamber, a Senate Homeland Security and Governmental Affairs Committee staffer told MeriTalk. […]
CISA Launches Infrastructure Dependency Primer Learning Tool Nov 22, 2021 | 1:20 pm The Cybersecurity and Infrastructure Security Agency (CISA) has launched its Infrastructure Dependency Primer (IDP) learning tool, which aims to help state, local, tribal, and territorial planners and decisionmakers better understand how infrastructure dependencies can impact their communities and how to increase resilience. […]
CISA QSMO Official Explains Security Evaluation for 5G Technologies Nov 22, 2021 | 12:55 pm The complexity and flexibility of emerging fifth-generation (5G) wireless technologies make the process of defining a security assessment boundary complex, thus it’s crucial to maintain a wide aperture concerning 5G cybersecurity, an official from the Cybersecurity and Infrastructure Security Agency (CISA) said during a Palo Alto Network webinar on Nov 18. […]
CISA Rolling out Protected DNS Service in 2022 Nov 19, 2021 | 2:14 pm The Cybersecurity and Infrastructure Security Agency (CISA) will be rolling out a new protected Domain Name System (DNS) technology in 2022, CISA’s Trusted Internet Connections (TIC) program lead Sean Connelly said on Nov. 18. […]
NCD Office Hires Booth as New Senior Policy Advisor Nov 19, 2021 | 1:25 pm The Office of the National Cyber Director has hired Rexford G. “Rex” Booth as its senior policy advisor, according to Booth’s LinkedIn. […]
DoJ Charges Two Iranian Nationals for Cyber-Enabled Election Interference Nov 19, 2021 | 11:53 am The Department of Justice (DoJ) announced it has charged two Iranian nationals for their role in a cyber-enabled disinformation and threat campaign “to intimidate and influence American voters, and otherwise undermine voter confidence and sow discord” in the 2020 U.S. presidential election. […]
Supply Chain, Modernization, and Cyber Loom Large in House Passed $1.75T+ Build Back Better Act Nov 19, 2021 | 11:48 am The House of Representatives passed the Build Back Better (BBB) Act this morning, sending the more than $1.75 trillion reconciliation package to the Senate. The bill includes billions for supply chain resiliency, as well as additional cybersecurity and IT modernization funding. […]
Senate Commerce Clears NIST Director Nomination Nov 18, 2021 | 3:57 pm The Senate Commerce, Science, and Transportation Committee voted Nov. 17 to approve President Biden’s nomination of Laurie Locascio to become Undersecretary of Commerce for Standards and Technology, and director of the National Institute for Standards and Technology (NIST). […]
Cyber Agencies Warn Against Vulnerabilities in Fortinet, Microsoft Products Nov 18, 2021 | 2:48 pm U.S., U.K., and Australian cybersecurity agencies are warning that hackers associated with Iran have exploited vulnerabilities in Fortinet and Microsoft products to carry out attacks. Officials urged in a recent advisory that critical infrastructure organizations patch these vulnerabilities to mitigate against possible attacks. […]
FBI Official Defends Decision to Delay Release of Kaseya Decryption Key Nov 17, 2021 | 2:01 pm An FBI official did not deny prior reports that the agency held the decryption key from the Kaseya ransomware attacks for multiple weeks without giving it to parties victimized by the attacks but told the House Oversight and Reform Committee at a Nov. 16 hearing that it chose to do so in the interest of figuring out how to achieve the widest-ranging impact from the key. […]
CISA Releases New Cyber Incident and Vulnerability Response Playbooks Nov 16, 2021 | 2:52 pm The Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA) released new Cybersecurity Incident and Vulnerability Response Playbooks today, completing a vital assignment from President Biden’s Cybersecurity executive order (EO). […]
How Fed CISOs are Complying With the Cyber EO Nov 16, 2021 | 1:56 pm The Biden administration issued its cybersecurity executive order (EO) in May 2021, giving marching orders to Federal agencies to move to zero trust security architectures, among other directives. During a SCGov panel discussion today, Federal chief information security officers (CISOs) shared how they’re leveraging their agency’s previous programs around zero trust to fulfill the obligations of the EO. […]
FBI Email System Hacked, Sent Fake Cyberattack Emails Nov 15, 2021 | 3:56 pm The FBI’s email system was hacked, sending emails to thousands of recipients about a fake cyberattack, the agency confirmed over the weekend. The law enforcement agency said the cause of the hack has since been remediated. […]
White House Creates Task Force to Drive Infrastructure Bill Implementation Nov 15, 2021 | 3:51 pm The White House said today it has created a task force made up mostly of top Federal agency officials to “coordinate effective implementation” of the many new programs and mandates created by the $1.2 trillion Infrastructure Investment and Jobs Act signed into law by President Biden on November 15. The task force is being created through a new executive order. […]
DHS Launches New Personnel System to Recruit, Retain Cybersecurity Talent Nov 15, 2021 | 3:41 pm The Department of Homeland Security (DHS) finally launched the Cyber Talent Management System (CTMS) to enable more effective recruitment, development, and retention of cybersecurity talent. […]
Senators Back GAO Findings, Urge Better Cyber Protections for K-12 Schools Nov 15, 2021 | 12:29 pm In the wake of a Government Accountability Office (GAO) report encouraging the Departments of Education and Homeland Security (DHS) to update K-12 cybersecurity guidance, several Democrat senators have written to both agencies urging them to heed GAO’s recommendations, and establish critical infrastructure council structures to advance the issue. […]
Biden Signs Secure Equipment Act Nov 12, 2021 | 4:01 pm President Biden on Nov. 11 signed the Secure Equipment Act, which will prevent equipment manufactured by Chinese state-backed firms such as Huawei, ZTE, Hytera, Hikvision, and Dahua from being further utilized and marketed in the United States. […]
Waiting on the NDAA: Big Cybersecurity Bills Looking to Hitch a Ride Nov 12, 2021 | 3:08 pm Sponsors of two major pieces of legislation that would make formative changes to the way that private sector companies report cyberattacks to the government – and how Federal government agencies conduct their own cyber defenses – are hitching their hopes for passage to annual defense spending legislation that traditionally gets strong bipartisan support from lawmakers. […]
GAO Prods Education Department to Update K-12 Cyber Guidance Nov 12, 2021 | 1:48 pm With K-12 educational institutions increasingly targeted by ransomware and other cyber attacks during the coronavirus pandemic, the Government Accountability Office (GAO) is pushing the Department of Education to update its plans – which currently date from 2010 – for addressing cyber risks faced by schools. […]
DoD DCIO: Zero Trust Offers ‘Fighting Chance’ Against Hackers Nov 11, 2021 | 3:06 pm With cybercriminals becoming more sophisticated at disguising themselves as legitimate network users, a top Defense Department (DoD) IT official said this week that the Pentagon’s move to zero trust security architectures gives the agency a “fighting chance” to detect and eject hackers before they can do much damage. […]
White House Signs onto French Cyber, Supply Chain Framework Nov 11, 2021 | 3:02 pm Following a November 10 meeting with French President Emmanuel Macron, Vice President Kamala Harris announced that the U.S. will sign onto a three-year old framework offered by the French government as an international framework for cooperation on cyber and supply chain security. […]