Senators want answers on State Department's glaring cybersecurity gaps
Full article692 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The bipartisan group is particularly focused on the department's lack of multi-factor authentication.
The State Department must do more to shore up its cybersecurity posture, according to a bipartisan group of senators.
The department is woefully behind on hitting various federal cybersecurity benchmarks, and it is weak on basic measures to protect against phishing, hacks and other cyberattacks, wrote Ron Wyden, D-Ore., Cory Gardner, R-Colo., Ed Markey, D-Mass., Rand Paul, R-Ky., and Jeanne Shaheen, D-N.H., in a letter to Secretary Mike Pompeo.
The letter cites two recent reports: The department’s inspector general found last year that 33 percent of diplomatic missions failed to conduct even the most basic cyberthreat management practices, like regular reviews and audits. Also, the General Services Administration found that the department has only instituted enhanced access controls on 11 percent of agency devices. The Federal Cybersecurity Enhancement Act requires agencies to enable multi-factor authentication (MFA) for elevated privileged accounts.
“We urge you to improve compliance by enabling more secure authentication mechanisms across the Department of State’s information systems,” the senators wrote. “While certainly not a silver bullet, MFA is a simple step that makes it significantly harder for foreign governments or criminals to access accounts.”
Cybersecurity has been big point of contention at the State Department under the Trump administration. Outside of internal procedures, the cybersecurity policy office has been caught in an internal tug-of-war over its mission.
Additionally, the House Foreign Affairs Committee advanced a bill in May that would task the secretary of State with setting up a vulnerability disclosure process for researchers to hunt for and disclose flaws in the department’s public-facing websites and applications.
The senators issued various questions to Pompeo around statistics tied to high-value assets, lack of multi-factor authentication and cybersecurity policy for foreign State Department missions.
You can read the letter below.
[documentcloud url=”http://www.documentcloud.org/documents/4872636-State-Dept-Cybersecurity-Letter-From-Wyden.html” responsive=true height=500]
More Scoops
Federal judiciary touts cybersecurity work in wake of latest major breach
The Administrative Office of the United States Courts denied ignoring expert advice in a letter to Sen. Ron Wyden, D-Ore., who blasted Chief Justice Roberts in a…
Unusually patient suspected Russian hackers pose as State Department in ‘sophisticated’ attacks on researchers
A tangled mess: Government rules for social media security lack clarity
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/state-department-cybersecurity-senators-letter/