Fed Officials: Cyber EO Producing Long-Lasting Results Nov 8, 2022 | 3:28 pm As President Biden’s cybersecurity executive order (EO) reaches its year-and-a-half milestone, Federal officials today agreed that the cyber EO is different from the rest as it “has legs” and will produce long-lasting results for the government. […]
Cyber EO One Year Later: Implementing Holistic Zero Trust Security May 26, 2022 | 12:30 pm MeriTalk recently sat down with Fortinet’s Jim Richberg, public sector CISO, Peter Newton, senior director, product marketing, and Fortinet Federal’s Felipe Fernandez, senior director, system engineering, to gain their insights into how Federal technology teams can integrate all of the components of a zero trust architecture to achieve holistic cybersecurity in a cloud, hybrid, or closed environment. […]
Federal CISO DeRusha: OMB Zero Trust Strategy ‘Just the Beginning’ May 24, 2022 | 3:27 pm As both Federal chief information security officer and the deputy National Cyber Director, Chris DeRusha has a lot of visibility into Federal efforts to boost cybersecurity. At the AWS Summit in Washington, D.C., today, DeRusha expressed both pride in the Office of Management and Budget’s (OMB) Zero Trust strategy, while also acknowledging that the policy represents only the beginning of zero trust implementation across Federal civilian agencies. […]
Cyber Central: Agencies Need to Approach Zero Trust Strategically May 19, 2022 | 1:34 pm As President Biden’s cybersecurity executive order (EO) stretches past its first year, Federal agencies are at varied points in their progress on the EO’s orders. Federal leaders say it is important for agencies to approach the EO’s zero trust components strategically and understand their networks as they make the move to a zero trust architecture. […]
Big Tech Pledges $30M to Bolster Open Source Software Security May 16, 2022 | 3:59 pm Several major technology organizations have pledged more than $30 million to bolster the security of open-source software. […]
Cyber EO Anniversary: Feds Like Order’s Aims, See Unrealistic Timelines May 5, 2022 | 3:42 pm As President Biden’s landmark cybersecurity executive order (EO) approaches its first anniversary on May 12, new research shows that most Federal cybersecurity decision-makers solidly back the aims of the EO, but also think that its initial timelines to implement zero trust security are unrealistic. […]
MeriTalk Webinar: FEMA CISO Calls OMB Log Order ‘Push in Right Direction’ Apr 12, 2022 | 12:13 pm Senior Federal and industry cybersecurity leaders agreed that the Office of Management and Budget’s (OMB) August 2021 memorandum M-21-31 to implement new event logging and share threat information has proven to be a significant step in bolstering cybersecurity across Federal civilian agencies. […]
FCC Interagency Cybersecurity Forum to Focus on Harmonizing Private-Public Cyber Apr 11, 2022 | 3:16 pm Federal Communications Commission (FCC) Chair Jessica Rosenworcel wants the recently restarted FCC Interagency Cybersecurity Forum to focus on creating harmony between how the private sector and the Federal government implement cybersecurity controls. […]
CISA Releases Zero Trust Mobility Publication for Comment Mar 8, 2022 | 1:58 pm The Cybersecurity and Infrastructure Security Agency (CISA) has released a draft version of its Applying Zero Trust Principles to Enterprise Mobility for public comment. […]
Feds Say Zero Trust Starts With Identity Mar 7, 2022 | 9:00 am Security, in the past, was built on fixed physical networks that allowed access to trusted individuals and kept untrusted individuals out. But, as Federal agencies transform their digital environments and increase remote work security measures had to evolve, making zero trust architectures the new norm and identity the new perimeter. […]
CISA Official: Cyber EO Aims at Priorities, Not a Fix-All Mar 4, 2022 | 9:00 am While President Biden’s 2021 cybersecurity executive order (EO) doesn’t address all of the Federal government’s cybersecurity needs, a security expert from the Cybersecurity and Infrastructure Security Agency (CISA) said the EO’s goal drives toward prioritization of the government’s most pressing needs – rather than a fix-all approach. […]
From EO to Action: Human Factors of Enabling a Cyber Safety Review Board Feb 7, 2022 | 9:00 am President Biden’s executive order (EO) on improving the nation’s cybersecurity was a call to action to prioritize cyber safeguards in both the public and private sectors. […]
DHS Targets Log4j for First-Ever Cyber Safety Review Board Action Feb 4, 2022 | 2:54 pm The Department of Homeland Security (DHS) has officially formed the Cyber Safety Review Board called for in President Biden’s Cybersecurity Executive Order issued last year, and said the board’s first action will be to examine the log4j software library vulnerability that emerged in December 2021 and to generate lessons learned from that for the cybersecurity community. […]
Federal Agencies Require More Work to Be Cyber Ready Jan 13, 2022 | 12:30 pm Improving cybersecurity has become the key to better protecting critical infrastructure and meeting mission needs within the government space, but according to an official from the Government Accountability Office (GAO), Federal agencies still have a long way to go to be cyber-ready. […]
NIST Updates Guidelines for Cybersecurity Engineering Jan 12, 2022 | 2:32 pm The National Institute of Standards and Technology (NIST) has updated its cybersecurity guidance for system engineers, adding more insight for engineers and programmers on mitigating system vulnerabilities. […]
CISA Pushes for Software Bill of Materials While Dealing with Log4j Jan 10, 2022 | 3:05 pm A month after its first public warnings about the Log4j vulnerability, the Cybersecurity and Infrastructure Security Agency (CISA) is continuing to work with Federal agencies and the public to mitigate potential exposure, and also renewing calls for a software bill of materials (SBOM) to aid in system visibility and inventory management. […]
Fed IT Leaders Size Up Security Challenges Beyond the Cyber EO in New Report Dec 14, 2021 | 1:45 pm The Biden administration’s Cybersecurity Cybersecurity Executive Order issued in May 2021 has put a greater emphasis on cybersecurity at the Federal level – which is especially important after numerous high-profile ransomware and software supply chain attacks came to light earlier in the year – but many Federal cyber leaders say the Cyber EO only addresses a fraction of today’s cybersecurity challenges. […]
CISA Releases New Cyber Incident and Vulnerability Response Playbooks Nov 16, 2021 | 2:52 pm The Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA) released new Cybersecurity Incident and Vulnerability Response Playbooks today, completing a vital assignment from President Biden’s Cybersecurity executive order (EO). […]
CDM Chief Hails Fast Progress on New Agency MOAs for Object-Level Data Nov 1, 2021 | 12:38 pm The acting manager of the Cybersecurity and Infrastructure Security Agency’s (CISA) Continuous Diagnostics and Mitigation (CDM) program is hailing quick progress that the program and Federal agencies have made in signing new agreements mandated by the Biden administration’s Cybersecurity Executive Order to share object-level network data with the CDM program, rather than the summary-level data that was previously required. […]
Cyber Defenders: Feds Point to Zero Trust, Supply Chain, Data as Top Priorities Oct 28, 2021 | 4:10 pm As Federal agencies approach the six-month mark since President Biden issued his Cybersecurity Executive Order (EO) in May, Federal officials are pointing to the zero trust, supply chain risk management, and data aspects of the EO as the greatest opportunities to make a difference in shoring up security. […]
Cyber Defenders: OMB Sees Agencies ‘Highly Engaged’ in Zero Trust Mandate Oct 28, 2021 | 3:42 pm Five months after the debut of the Biden administration’s sweeping Cybersecurity Executive Order, Federal agencies are “highly engaged” in grappling with the order’s mandate for migration to zero trust security architectures, both on the planning and funding fronts. […]
Microsoft Warns of New Activity From SolarWinds Attacker Nobelium Oct 26, 2021 | 3:52 pm Microsoft is warning that it has seen Nobelium – the Russian nation-state threat group responsible for the SolarWinds software supply chain hack – trying to recreate the same approach that allowed it to gain access to Federal government systems, according to an Oct. 24 blog post from the company. […]
OMB Gives Agencies Three-Month Marching Orders on EDR Progress Oct 11, 2021 | 1:08 pm The Office of Management and Budget (OMB) is giving Federal agencies a three-month deadline to make initial strides at identifying the current state of endpoint detection and response (EDR) capabilities on their networks and to start undertaking additional work with the Cybersecurity and Infrastructure Security Agency (CISA) to quicken the pace of deploying those capabilities. […]
Tech Funding Abounds as House Panels Finish Reconciliation Markups Sep 15, 2021 | 4:11 pm Proposed funding for a host of new tech-related spending projects are springing forth from new House committee legislative prints contributing to the $3.5 trillion reconciliation bill, and now it’s wait-and-see on which – if any – of them survive what is likely to be a free-wheeling House-Senate negotiation on the giant spending bill. […]
CISA Gets $865 Million in Homeland Security Committee Amendment Sep 13, 2021 | 3:06 pm The House Homeland Security Committee will mark up its portion of the legislative language for the $3.5 trillion reconciliation bill tomorrow, but the released text of the chairman’s amendment to the bill shows that Rep. Bennie Thompson, D-Miss., proposes to give the Cybersecurity and Infrastructure Security Agency (CISA) $856 million to fund various programs and operations expenses. […]
What’s in Your Broadband? White House EO Aims to Revive Service Disclosure Push Jul 9, 2021 | 1:47 pm A wide-ranging executive order released by the Biden administration on June 9 is seeking to revive an Obama-era push for more public disclosure of broadband service performance and contract terms – an effort that fell by the wayside during the Trump administration. […]
U.S. Army Corps of Engineers has Created a ‘Zero Trust Playbook’ Jul 7, 2021 | 3:54 pm With President Biden’s cyber executive order (EO) guiding Federal agencies towards implementing zero trust architectures, the U.S. Army Corps of Engineers has already created a Zero Trust Playbook to help outline the change and create guidelines, the Corps’ CIO said today. […]
TMF Board Reviewing Zero Trust Proposals, CISA Official Says Jun 22, 2021 | 3:29 pm The board of the Technology Modernization Fund (TMF) has been reviewing in recent days proposals from Federal agencies to help fund their efforts to move toward zero trust security architectures, according to Matt Hartman, who is Deputy Executive Assistant Director for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA), and also a member of the TMF board. […]
White House Cyber Advisor Cites ‘Disappointment’ With Fed Network Hygiene May 27, 2021 | 4:20 pm Anne Neuberger, the White House deputy national security advisor for cyber and emerging technologies who is a driving force behind the Biden administration’s cybersecurity executive order issued earlier this month, today noted an initial “disappointment” with Federal network hygiene in a follow-up discussion about the broader aims of the order. […]
Tech Sector Likes Cyber Order’s Enterprise-Wide View, Cloud Push May 13, 2021 | 3:42 pm Tech-sector reaction to the White House’s sweeping cybersecurity executive order issued May 12 came in largely positive today, with security technology makers particularly applauding the urgency of the administration’s plans, the enterprise-wide view that the order takes for improving security, and its actions to hasten the movement of Federal agencies to cloud services. […]