Cybersecurity

CISA director 'very concerned' about election influence from foreign adversaries

Jen Easterly, director of the nation's cyber defense agency, said foreign adversaries could potentially weaponize disinformation and misinformation to incite violence and undermine the public's confidence in the upcoming elections.

Cybersecurity

CISA Director: Big Tech Shouldn’t Charge Extra for Event Logging

The agency has promised to measure the success of efforts to steer major software providers toward the inclusion of logging and other basic security features in their products “by default,” but has said little about how it actually intends to do that.

Emerging Tech

VA Needs Better Data on Employment Outcomes of ‘Promising’ Tech Training Pilot, Watchdog Says

A Government Accountability Office report found that the Department of Veterans Affairs lacks sufficient data on its VET TEC pilot to “assess the effectiveness of the program at getting veterans into jobs.”

Cybersecurity

Agencies Shouldn’t 'Just Trust' Software Vendors' Security Assurances, IG Warns

NIST advisors debating the merits of OMB’s policy on software vendors’ “self-attestation” to secure development practices found common ground on a need for audits and testing.

Cybersecurity

CISA sets voluntary cyber performance targets for critical infrastructure

A new set of documents and resources from the agency is designed to help critical infrastructure operators manage the basics of cybersecurity.

Cybersecurity

OPM's Ahuja Gets an Earful From Agencies Over Enhanced Pay for Cyber Talent

The Director of the Office of Personnel Management is navigating the intense competition among federal agencies for in-demand cybersecurity workers.

Cybersecurity

Public Entities in Nearly Every State Use Federally-Banned Foreign Tech, Report Says

A new report from Georgetown University’s Center for Security and Emerging Technology found that at least 1,681 state and local governments purchased equipment from five Chinese companies that were banned by the federal government between 2015 and 2021.

Cybersecurity

FTC's Data Security Complaint Against Drizly Sets New Leadership Responsibility

The consequences of Drizly’s lax security measures could echo past the beverage delivery company.

Cybersecurity

CISA Seeks Feedback on Baseline Measures to Secure Cloud Configuration

Initial baselines address Microsoft services, and baselines for configuring rival services from Google are up next. 

Cybersecurity

NDAA Amendment Would Establish Veteran-Focused Cyber Training Program

A provision included in House and Senate legislation authorizing Defense Department spending for fiscal year 2023 would allow veterans and military spouses to receive cyber training “at no cost.”

Cybersecurity

TSA Opens Registration for Public Meeting on Cybersecurity Regulations

The agency’s advisory committee typically meets behind closed doors, but they are required to hold at least one public meeting per year. 

Cybersecurity

Global Cyber Workforce Needs 3.4 Million Professionals to Fill Gaps, Study Finds

The survey also found that government cyber workers reported the least confidence in their ability to mitigate security threats over the next couple years “based on their current staff and tools.”

Cybersecurity

CISA to Focus on Water, Education and Health Sectors Over the Next Year 

The agency contributed to the release of security requirements for the transportation sector this week and is expected to issue cross-sector performance goals for critical infrastructure companies’ voluntary adoption next week.

Cybersecurity

White House looks to advance cyber safety labeling effort with 'initial scope' next spring

A senior administration official said the White House is beginning with a label that will focus on some of the most at-risk technologies – and that the National Institute of Standards and Technology will play a major role in getting it done.

Cybersecurity

Can Service Meshes Help Bring Legacy Government Applications into Zero Trust?

The Biden administration’s imperative to move to zero trust could prove challenging for agencies with still-functional legacy systems.

Cybersecurity

NSA Advocates Active Defense, as Industry Lawyer Advises Against Incident Reports

Speakers at a new conference hosted by cybersecurity firm Mandiant highlighted the challenge the government faces in motivating companies to report attacks on critical infrastructure.

Cybersecurity

Cyber Talent Still in High Demand

In the last 12 months, more than 769,000 cyber job postings went up in the United States.

Cybersecurity

How the FBI stumbled in the war on cybercrime

Although cyberattacks were becoming more sophisticated, FBI officials told counterparts at DHS and elsewhere in the federal government that ransomware wasn’t a priority.

Cybersecurity

Labor Group Highlights Conflict of Interest Issues in Cyber Workforce Legislation

The federal workers union wrote to senators opposing an amendment to the NDAA that would establish a civilian reserve at CISA.

Cybersecurity

Malign Influence Operations Increasing Ahead of Midterms, Report Finds

A report from cybersecurity firm Recorded Future found that nation-state adversaries and domestic extremists are engaged in efforts to influence the outcome of the November elections.