Federal CISO forecasts one of toughest tasks in sweeping Biden cyber executive order
Full article551 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Chris DeRusha said cybersecurity event logging is important, but will take years to get right.
At 34 pages, President Joe Biden’s May executive order on cybersecurity is lengthier than many such White House directives. It’s going to keep federal agencies busy for a long time implementing a host of protective measures, but one might prove a heavier burden, according to Federal Chief Information Security Officer Chris DeRusha.
The executive order establishes cybersecurity event log requirements for agencies, meant to improve the government’s ability to investigate and clean-up attacks.
“To do monitoring and understand what activity is occurring or has occurred on your network, that’s a huge multi-year exercise that each agency’s going to have to undertake,” DeRusha said during an interview that aired Tuesday as part of CyberTalks, a summit presented by CyberScoop.
But it’s a very important part of the order, he said.
“When you think about it it’s really a key pillar of … cyber hygiene,” said DeRusha.
Under the order, the Homeland Security Department, attorney general and Office of Management and Budget are charged with writing recommendations for logging event requirements, such as what types of logs need to be kept, how long they should be retained and how they should be protected. DHS and the Commerce Department are then charged with forming policies for agencies to establish logging, log retention and log management requirements.
OMB will work with agencies to make sure they have what they need to carry out the requirements. And agencies must produce logs to DHS and the FBI upon request.
“You start to categorize out all the logs that you need to retain for significant periods of time to do successful digital forensics exercising,” DeRusha said.
Biden penned the executive order primarily in response to the SolarWinds supply chain hack that compromised nine federal agencies. Although it’s ambitious, it’s just one element of the Biden administration response: The president’s budget blueprint for fiscal 2022 also proposes $750 million for agencies affected by the SolarWinds campaign.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/federal-ciso-chris-derusha-logging-executive-order/