Smarter Gov Tech, Stronger MerITocracy

President Trump today signed into law the FY 2019 National Defense Authorization Act (NDAA), which clocks in at $717 billion in spending for the Pentagon. After months of negotiations, hearings, and compromises, the must-pass defense spending bill was signed during a visit by President Trump to Fort Drum in upstate New York this afternoon. […]

voting, election security

As Federal agencies adopt DevOps practices to shorten development cycles and increase deployment frequency, security must be interwoven into every aspect of the process from design, through coding, testing, release, and operation. […]

A former top White House cybersecurity policymaker and IT systems manager at the Department of Education said today at the FCW Cybersecurity Summit that Federal agencies should expect to become targets of sophisticated cyber attacks and should count on assistance from other entities including their cloud service providers to meet those assaults.  […]

The Small Business Administration’s (SBA) Deputy CIO Guy Cavallo and CTO Sanjay Gupta said today at the FCW Cybersecurity Summit that their agency’s unorthodox approach to the Continuous Diagnostics and Mitigation (CDM) Program is yielding a ton of practical benefits, even though it required a bit of a departure from CDM’s initial guidelines. Now, SBA is providing a new potential model for other agencies – many struggling with the first of CDM’s four phases – to use when considering how to achieve the outcomes the program intends. […]

A new survey from Tripwire, a security and compliance automation software provider, found that organizations need to go back to basics and make sure they are properly implementing and maintaining cybersecurity fundamentals. The survey, released today, found that organizations are not focusing on basic security controls that the Center for Internet Security (CIS) refers to as “cyber hygiene.” […]

The U.S. Cyber Command (Cybercom) and the National Security Agency have joined the effort to protect the integrity of this year’s midterm elections, which are occurring under the shadow of Russia’s meddling in the 2016 election and warnings from U.S. intelligence agencies that 2018 is seeing more of the same. […]

Federal CIO Suzette Kent said today at the FCW Cybersecurity Summit that continuous dialogue and attention on cybersecurity priorities are working to move the Federal government collectively in the right direction at a time when the need for unified effort is paramount. […]

threat

Officials in government, the private sector, and academia discussed their efforts to establish a defensive posture and use technology-augmented programs to deter and detect insider threats, at an event hosted by Nextgov and Equifax Tuesday. […]

The Pentagon is looking to get into the weeds with cyber defense, using artificial intelligence to hunt down attacks that may use the size and complexity of its systems to hide out while waiting to strike. […]

Wayne Belk, director of the National Insider Threat Task Force (NITTF), said today at an event hosted by Nextgov and Equifax that his unit in the Office of the Director of National Intelligence is now working with the Defense Department to clarify and strengthen the roles of the Federal government’s insider threat staff, beginning with its security analysts. […]

The Department of Homeland Security (DHS) on Monday convened a conference call with the National Association of Secretaries of State (NASS) and the National Association of State Election Directors (NASED) regarding cybersecurity and ongoing threats to the 2018 midterm elections. […]

Bill Evanina, director of the National Counterintelligence and Security Center (NCSC) in the Office of the Director of National Intelligence, said today that the billions of dollars the U.S. government and private sector spend each year on cybersecurity are not being properly and efficiently utilized unless government and industry wrap human resources departments tightly into security discussions. […]

Federal agencies must build “identity-aware” infrastructures to effectively monitor and manage user access to information and information systems across their enterprise for more secure and efficient operations, according to cybersecurity experts. […]

U.S. Census Bureau CIO Kevin Smith said that the Department of Homeland Security performed penetration tests this year that were unable to break through Census’ data safeguards, confirming the strength of Census’ cybersecurity programs for both its self-response website and in-field mobile devices. […]

The Department of Defense is getting on board with some critical website and email protections that have been mandated across civilian Federal government agencies, even if it is lagging somewhat behind other departments in applying encryption and anti-phishing measures. […]

Department of Homeland Security Under Secretary Chris Krebs, head of the agency’s National Protection and Programs Directorate (NPPD), has named Bob Kolasky to serve as director of the newly-established National Risk Management Center (NRMC), a DHS official confirmed to MeriTalk today. […]

Brad Nix, senior advisor at the Department of Homeland Security’s National Cybersecurity and Communications Integration Center (NCCIC), said Thursday at MeriTalk’s Cyber Security Brainstorm that DHS’s establishment earlier this week of its new National Risk Management Center represents “an acknowledgement on our end that there is more to be done” to assess risk faced by critical infrastructure sectors–some of whom have less-well developed abilities to detect and respond to threats. […]

Federal IT leaders discussed the ways their organizations are tackling the proliferation of more and more endpoints on Federal networks at MeriTalk’s Cyber Security Brainstorm Thursday. In particular, ever-increasing mobile connectivity is creating the potential for further headaches, but the officials advised that next-gen technologies and proper network and data governance provide avenues to expand the ways employees work without compromising security at the network edge. […]

Sen. Ron Wyden, D-Ore., wants to understand what the Department of Homeland Security (DHS) has learned from Domain-based Message Authentication, Reporting, and Confirmation (DMARC) reports about cyber criminals using email to impersonate Federal agencies. […]

Paul Beckman, chief information security officer at the Department of Homeland Security, said Thursday at MeriTalk’s Cyber Security Brainstorm that software-defined networking, adopting a zero-trust model, and optimizing DHS’ security operations centers (SOC) are his biggest emerging priorities to promote better security across the department. […]

Categories