OMB orders federal agencies to let CISA access defenses of devices, servers
Full article656 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It's an area of weakness that the SolarWinds hackers exploited, officials have said.
The White House is directing agencies to let the Cybersecurity and Infrastructure Security Agency work with them on their efforts to protect endpoints, such as computer workstations and servers — an area where officials have said the federal government fell short in the SolarWinds hack.
The Office of Management and Budget issued a memo on Friday that sets a 90-day deadline for CISA, the main cyber wing of the Department of Homeland Security, to access agencies’ current endpoint detection and response deployments. It then spells out timelines for other steps to improve their endpoint defenses.
OMB says the goal is to establish “improved agency capabilities for early detection, response, and remediation of cybersecurity incidents on their networks, using advanced technologies and leading practices.”
The memo is an outgrowth of President Joe Biden’s cybersecurity executive order from May. And the focus on endpoints reflects one of the main takeaways from a March Senate hearing where then-CISA Director Brandon Wales said the agency wasn’t equipped to catch today’s hackers, like the SolarWinds perpetrators who compromised nine federal agencies, hopping from server to server to avoid notice.
OMB’s memo directs agencies to take other actions within 90 days. CISA must develop a method for continuously evaluating the effectiveness of agencies’ endpoint detection capabilities. CISA will work with the Chief Information Officer Council to recommend endpoint detection improvements and agencies.
Within 120 days, agencies must conduct an analysis with CISA of endpoint detection and response gaps, coordinate with CISA on future plans, make sure they have the right spending and staffing levels and ensure their endpoint plans are compatible with privacy. Within 180 days, CISA and the CIO Council have to publish a playbook of best approaches.
Biden officials have spoken frequently about the value of endpoint defenses. Last week, Deputy National Security Adviser for Cyber and Emerging Technology Anne Neuberger identified endpoint detection as one of the most important technologies for feds to adopt, along with multifactor authentication, encryption of data, a fully manned security operation center and logging.
“We call them ‘five,’ in terms of five specific areas that we know dramatically reduce the risk of a cybersecurity attack, and if one happens, reduce the risk of it being broadly impactful,” Neuberger said at an event hosted by cybersecurity firm Mandiant.
The OMB memo is part of a busy period for both that office, and CISA, on publishing cybersecurity guidance.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/omb-cisa-endpoint-detection-memo/