The budget guidance hews closely to the National Cyber Strategy, directing agencies to continue to focus their resources on "zero trust" architectures, as well as requirements for critical infrastructure.
The CISA guidance helps fill a void where agencies have lacked common security standards and configurations for widely used services, like email and productivity capabilities.
The "non-recurring expenses fund" doesn't have a flashy name, but it could become a "significant tool" for DHS to make both IT and facilities improvements.
As law enforcement and national security agencies adopt cloud services, their sensitivity to cyber incidents makes executing cybersecurity basics and transformational approaches in tandem essential. We share advice from two Trend Micro experts.
Instead of waiting for cyber-specific positions to be filled, the White House has prioritized strengthening the current federal workforce through cyber education and skills-based training.
In March, the White House unveiled a new National Cybersecurity Strategy, which deviates from the National Cyber Strategy rolled out by the Trump administration in 2018. Among the changes implemented in the new strategy is a call to “rebalance the responsibility” of defending cyberspace, including a move away from end users and toward the “most capable and best-positioned actors,” including owners and operators of key technologies and infrastructures.
Air Force plans to recruit and retain cyber professionals include a new tech track career path set to debut next year.
Martin Rieger, the chief solutions officer and chief information security officer a stackArmor, said the caring, feeding, maintenance and continuous development of federal cyber regulatory and policy requirements is necessary for success.
U.S. officials say the Department of Energy is among a small number of federal agencies compromised in a Russian cyber-extortion gang’s global hack of a file-transfer program popular with corporations and governments. They say the impact is not expected to be great. Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, told reporters that the hacking campaign was short, opportunistic and caught quickly. A senior CISA official said neither the U.S. military nor intelligence community was affected. Known victims to date include Louisiana’s Office of Motor Vehicles and Oregon's Department of Transportation.
Sources confirmed the Energy Department is treating it as "major incident," with other agencies uncovering intrusions as well.
How do you stop a 21-year-old national guardsman like Jack Teixeira from leaking classified information? Wrong answers to this question have quickly become very popular.
Kurt DelBene, the assistant secretary for information and technology and chief information officer at the Veterans Affairs Department, said the agency is working on several parallel goals including getting to 100% use of multi-factor authentication.
A new instructional letter from the General Services Administration provides guidance for responsible use of generative AI by employees and contractors with access to GSA systems.
Amid the recent spate of high-profile cyberattacks, government agencies and private-sector organizations alike are scrambling to fend off unauthorized intrusions that can compromise digital assets, disrupt operations and derail attainment of critical missions.
The directive comes after suspected China state-backed hackers allegedly used network administration tools to access critical infrastructure systems.