Cybersecurity

FISMA Bill Drops in House Amid Confusion Over Federal CISO Role

Rep. John Katko is continuing a campaign to make the Cybersecurity and Infrastructure Security Agency a central Chief Information Security Office—or CISO— for federal civilian agencies.

Digital Government

DISA’s First Diversity Chief Wants Tech and Data to Make a Difference

Damien Terry briefed Nextgov on his vision and goals for the new role—including a potential request for information in the pipeline.

Policy

DHS Expands Fields of Study In STEM Training Program 

The 22 new fields of study have been added to the STEM Optional Practical Training program in a bid to keep U.S. science and math education competitive.

Digital Government

Former Homeland Security Acting Inspector General Pleads Guilty To Data Theft

Charles Edwards pleaded guilty to two federal charges of stealing government software and personnel data.

Cybersecurity

FBI Officials Clarify What the Bureau Wants in Cyber Incident Reporting Bill

However the legislation is eventually passed, CISA plans to share reports with the FBI and other agencies, a Homeland Security official said.

Modernization

Coast Guard Completes Financial System Modernization

The Coast Guard is the latest agency to update its financial software systems as more federal agencies continue modernization efforts.

Cybersecurity

How the Log4j Vulnerability is Forcing Change in Federal Cybersecurity Policy

Officials say agencies have demonstrated more dedication than ever in addressing a bug with astronomical reach, but organizations are at the mercy of product vendors to issue the patches they need to implement.

Cybersecurity

GSA Seeks Comments on Transfer of .Gov Domain to Cybersecurity Agency

The government’s site for managing government websites—dotgov.gov— may temporarily go down for maintenance as officials make the switch.

Policy

Women Report from the Frontlines of Federal Cryptocurrency Governance

Over the course of 2021, Congress and the administration have recognized significant benefits from diving into the technology, a trend that looks poised to continue.

Ideas

The Implications of Publicly Disclosing Cyberattacks

Officials must weigh the benefits and risks on a case-by-case basis.

Cybersecurity

Agencies Under New Deadlines to Address ‘log4j’ Flaws with Emergency Directive

The Cybersecurity and Infrastructure Security Agency order comes as a prominent firm says nation states are exploiting the vulnerabilities.

Cybersecurity

NSA, CISA, Add Original Equipment Manufacturers to Audience for 5G Security Guidance

The agencies got specific about who is responsible for what in a four-part series on securing the inherently cloud-based environments.

Cybersecurity

Federal Cybersecurity Advisor Floats Executive Order on Cloud Service Providers

The idea sprung from a sense of moral outrage Cybersecurity and Infrastructure Security Agency Director Jen Easterly identified with.

Cybersecurity

Agencies Must Fix Newly Cataloged Vulnerabilities by Christmas Eve

Officials stressed the importance of maintaining a bill of materials for software in flagging the “Log4j” vulnerability.

Cybersecurity

Increased Interconnectivity Demands Stronger Federal Data Protection Protocols, Officials Say

Officials in the public and private sectors warned of the need to enact a robust cybersecurity posture at the federal level ahead of growing ransomware and hacking threats.

Cybersecurity

House Passes NDAA Without Cyber Incident Reporting Legislation

The bill still includes what the House Armed Services Committee referred to as the widest empowerment of CISA since SolarWinds.

Emerging Tech

ACLU Calls for Halt of Homeland Security’s Use Of Facial Recognition Technology

The civil rights organization said that the biometrics technology can lead to discriminatory arrests based on race.

Cybersecurity

OMB Guidance Heralds Automation of FISMA Reporting

The new Federal Information Security Modernization Act guidance also prioritizes security testing and doubles down on CISA’s Continuous Diagnostics and Mitigation program.