Cybersecurity
New bill would require all federal contractors to develop vulnerability disclosure policies
The Federal Cybersecurity Vulnerability Reduction Act aims to establish standardized vulnerability disclosure policies across all federal contractors.
People
CISA director touts hiring progress
The agency’s culture has been key to its hiring successes, Jen Easterly says.
Emerging Tech
New post-quantum cryptography guidance offers first steps toward migration
Several agencies partnered to release the first federal recommendations for organizations to begin upgrading their networks and systems to quantum cryptography-resilient security schemes.
Cybersecurity
CISA prioritizing on-site K-12 cybersecurity reviews this school year
The nation’s cyber defense agency is aiming to work with schools “where they’re at instead of where they should be.”
Ideas
4 ways the defense spending bill could have addressed AI, other issues to boost cybersecurity
COMMENTARY | The Senate's version of the fiscal 2024 National Defense Authorization Act does address some important cybersecurity issues, but it may have missed opportunities to expand collaboration and tackle emerging technology challenges.
Cybersecurity
CISA conducts largest annual election security drills amid threats targeting voting systems
The nation’s cyber defense agency hosted a three-day election security exercise with state, local and federal officials ahead of the 2024 race.
Cybersecurity
New CISA guidance looks to guard against supply chain hacks
The Cybersecurity and Infrastructure Security Agency advocates constant communication and education as cyber threat mitigative measures.
Cybersecurity
New bill aims to address private sector cyber risks to FEMA operations
A proposed amendment to the Homeland Security Act would task FEMA and the Cybersecurity and Infrastructure Security Agency to work with private entities to ensure digital risks to agency operations are mitigated.
Cybersecurity
DHS cyber review board to examine China-linked cyberattacks of Microsoft
The Cyber Safety Review Board will assess how a hacking group reportedly linked to China leveraged a vulnerability in Microsoft Exchange Online to access government emails.
Cybersecurity
White House looks to shore up open source software security
The Office of the National Cyber Director wants software providers to "contribute back to the security of the open source software they depend upon."
Ideas
The future of CDM is in data governance, proactive threat detection
COMMENTARY: The Continuous Diagnostics and Mitigation program has helped to greatly fill in cyber gaps for agencies, but there is always more work to be done.
Cybersecurity
CISA unveils plan to measure cybersecurity success
The Cybersecurity and Infrastructure Security Agency's 2024-2026 cybersecurity roadmap focuses on public-private partnerships and using metrics to gauge the effectiveness of cybersecurity measures.
Cybersecurity
CISA, Five Eyes cyber advisory lists common vulnerabilities among 2022’s top exploits
Several federal and international agencies listed bugs detected across private networks, encouraging greater adherence to Secure By Design principles.
Cybersecurity
'Evolving' CISA program helped agencies quickly respond to recent cyber incidents
CISA’s Continuous Diagnostics and Mitigation program uses close collaboration with federal agencies to identify and respond to cyber threats, including last month’s MOVEit breach.
Cybersecurity
CISA is growing up, CIO says
CISA's Bob Costello talks top priorities, challenges and growing pains and progress for a CIO office in a relatively young federal agency.
Acquisition
CISA teases industry day for operational strategy support
The cybersecurity agency is planning to field a multiple award schedule contract for consultant services to help shape its operational strategy.
Digital Government
White House looks to shore up public trust in government websites
Federal agencies need to use 'memorable' and succinct domain names for government websites, per guidance issued on Wednesday.
Cybersecurity
Hackers used legit remote monitoring software to hack agency networks
Guidance from the National Security Agency and the Cybersecurity and Infrastructure Security Agency describe a phishing attack on a federal employee that used fake help desk domains to gain access to at least two federal civilian executive branch networks.
Cybersecurity
CDM team helped define cyber directives
Governmentwide cyber hygiene orders are increasingly taking into account the capabilities of Continuous Diagnostics and Mitigation tools.
Cybersecurity