While the Department of Defense (DoD) is still adjudicating comments on its latest Cyber Maturity Model Certification (CMMC) guidelines, Katie Arrington, CISO for the department of Acquisition at DoD, said the department would be ready to release its first Request for Proposal (RFP) by mid-March. […]
Nine Democratic senators are pressing the Department of Justice (DoJ) and the U.S. Courts for a briefing and information about exactly what data was compromised by the SolarWinds hack in a letter to the departments. […]
The U.S Air Force (USAF) has officially designated the Department of Defense (DoD) Cyber Crime Center (DC3) as a Field Operating Agency (FOA) effective Jan. 15. […]
President Biden is asking intelligence agencies for a “full assessment” of Russian involvement in breaches of thousands of government and private-sector networks via SolarWinds Orion products, White House Press Secretary Jen Psaki said Jan. 21. […]
Department of Defense information networks (DoDIN) are working to apply a Comply-to-Connect (C2C) initiative that will boost cybersecurity across DoD with future directives by the DoD CIO addressing components of the initiative. […]
Then-President Trump signed an executive order the day before he left office to target foreign cyber threats and place new reporting obligations on cloud service providers. […]
Four lawmakers are criticizing Secretary of State Mike Pompeo’s approval of a new cybersecurity and emerging technologies bureau and calling for President-elect Joe Biden to hit pause when he is sworn in and takes office. […]
Mark Montgomery, senior advisor to the chairmen of the Cyberspace Solarium Commission that last year produced dozens of recommendations to Congress on legislative steps to improve U.S. cybersecurity, said Jan. 19 that the commission is urging Congress in 2021 to adopt a more comprehensive strategy to protect the nation’s information and communications (ICT) supply chain. […]
Ret. Army Gen. Lloyd Austin, President Joe Biden’s nominee for Defense Secretary, faced a barrage of cybersecurity questions during his Jan. 19 confirmation hearing before the Senate Armed Services Committee. […]
The costs and consequences of the Russia-backed hack of government and private sector networks via a breach of SolarWinds Orion products are continuing to grow more than a month after the exploit was publicly disclosed, a senior official with the Cybersecurity and Infrastructure Security Agency (CISA) said today. […]
Kevin Cox, Continuous Diagnostics and Mitigation (CDM) program manager, said today that he could not directly address the Russian government hack of thousands of government and private sector networks that came to light in December, but emphasized the importance of network resilience to quickly recover from intrusions and breaches. […]
The National Security Agency (NSA) issued its first Cybersecurity Year In Review report, highlighting key achievements from 2020 – including encryption work for the Pentagon – and looking ahead to threats for 2021. […]
Federal government financial regulators are seeking comment on a proposed rule looking to increase accountability for banks that experience cybersecurity incidents by implementing requirements that they report incidents to their primary regulators within 36 hours of discovery. […]
During the nine months of the coronavirus pandemic, we’ve asked a hundred variations of that question to people whose professional lives near the tip of the technology spear put them in good positions to predict the future and get as many good answers back. At the dawn of a more hopeful 2021, here’s a look at how the Federal work-scape may play out in the longer term, courtesy of three veteran technologists. […]
The Cybersecurity and Infrastructure Security Agency (CISA) late Friday issued a new alert – stemming from the Russian hack of SolarWinds Orion products – in which CISA warns it has uncovered evidence of post-hack advanced persistent threat (APT) activity in the cloud environment. […]
The Biden-Harris transition team announced 21 more appointees to the incoming administration’s National Security Council (NSC) Jan. 8, including two that are sure to play significant roles in cybersecurity policy. The transition team has tapped Tarun Chhabra as Senior Director for Technology and National Security, and Caitlin Durkovich as Senior Director of Resilience and Response. […]
In the midst of dealing with the fallout from the Russian cyberattack that used SolarWinds software to breach the networks of thousands of the firm’s customers, SolarWinds has hired former Cybersecurity and Infrastructure Security Agency Director Chris Krebs and his new cybersecurity consulting firm as an independent consultant. […]
Secretary of State Mike Pompeo approved the establishment of the Bureau of Cyberspace Security and Emerging Technologies (CSET) within the Department of State on Thursday to lead diplomatic efforts to deflect cyberattacks from foreign countries. […]
The Department of Commerce Office of the Inspector General (OIG) announced last month that it will be conducting a review of the department’s cyber threat data sharing capabilities, pursuant to the Cybersecurity Information Sharing Act of 2015 which set up structures for sharing threat data with government and private sector entities. […]
President-elect Joe Biden has chosen cybersecurity veteran Lisa Monaco as his nominee for Deputy Attorney General at the Justice Department (DoJ), and according to a Politico report, is getting ready to name Anne Neuberger deputy national security adviser for cybersecurity on the President’s National Security Council (NSC). […]
The National Security Agency (NSA) issued an “emphatic” call for Federal stakeholders to update older Transport Layer Security (TLS) protocols, with the message particularly aimed at system administrators in the Department of Defense (DoD), the intelligence community (IC), and the Defense Industrial Base (DIB). […]
The Cybersecurity and Infrastructure Security Agency (CISA) released a new round of supplemental guidance on Jan. 6 to the emergency directive that the agency issued on Dec. 13, 2020, providing remediation guidance in response to the Russia-backed hack of more than 18,000 government and private sector systems via SolarWinds Orion products. […]
Federal law enforcement and intelligence agencies said today they believe that “fewer than ten” Federal agencies have been targeted by “follow-on” activity after initial breaches in the Russia-directed hacking of government networks via SolarWinds Orion products. […]
The White House issued the National Maritime Cybersecurity Plan – a plan for the Department of Homeland Security (DHS) to develop and deploy a maritime cybersecurity workforce in order to monitor, protect and mitigate cyber threats to the maritime sector. […]
A Treasury Department official told House Ways and Means Committee members in a Dec. 23 letter that the agency has found no evidence that the suspected Russia-backed breach of Federal government systems via SolarWinds Orion products exposed U.S. taxpayer data. […]
With one of the most abnormal years of our lifetimes coming to an end, we look back at the top Fed IT moments of 2020. In a year with both a pandemic and an election, the government had to change the way it worked, ensure trust in election outcomes, and modernize on the fly. […]
A bill introduced on Dec. 11 by Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, would require Federal agencies to report to Congress within seven days about any cyber attacks they have faced that would cause significant harm to national security or agency operations. […]
The National Institute of Standards and Technology (NIST) released a draft version of Special Publication (SP) 800-213 and several supporting documents aimed at manufacturers, with the goal of establishing a baseline for securely integrating Internet of Things (IoT) devices into Federal networks. […]
The Cybersecurity and Infrastructure Security Administration’s (CISA) Continuous Diagnostics and Mitigation (CDM) program is due to receive a much-needed funding increase for Fiscal Year 2021, helping to address a shortfall for the program that aims to improve network security at Federal government civilian agencies. […]
The Cybersecurity and Infrastructure Security Agency (CISA) released a draft version of a Trusted Internet Connections (TIC) Use Case focusing on access for remote users and user-owned mobile devices, setting the stage for more direct network access to agency and cloud-based resources. […]
























