ZeroHour
CyberScooppublished ()ingested @gregotto

Senators want answers on State Department's glaring cybersecurity gaps

criticalExploit / PoC exploited in the wildimportance 60
Full article692 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The bipartisan group is particularly focused on the department's lack of multi-factor authentication.

state department cybersecurity
Mike Pompeo. (Mark Taylor / Flickr)

The State Department must do more to shore up its cybersecurity posture, according to a bipartisan group of senators.

The department is woefully behind on hitting various federal cybersecurity benchmarks, and it is weak on basic measures to protect against phishing, hacks and other cyberattacks, wrote Ron Wyden, D-Ore., Cory Gardner, R-Colo., Ed Markey, D-Mass., Rand Paul, R-Ky., and Jeanne Shaheen, D-N.H., in a letter to Secretary Mike Pompeo.

The letter cites two recent reports: The department’s inspector general found last year that 33 percent of diplomatic missions failed to conduct even the most basic cyberthreat management practices, like regular reviews and audits. Also, the General Services Administration found that the department has only instituted enhanced access controls on 11 percent of agency devices. The Federal Cybersecurity Enhancement Act requires agencies to enable multi-factor authentication (MFA) for elevated privileged accounts.

“We urge you to improve compliance by enabling more secure authentication mechanisms across the Department of State’s information systems,” the senators wrote. “While certainly not a silver bullet, MFA is a simple step that makes it significantly harder for foreign governments or criminals to access accounts.”

Cybersecurity has been big point of contention at the State Department under the Trump administration. Outside of internal procedures, the cybersecurity policy office has been caught in an internal tug-of-war over its mission.

Additionally, the House Foreign Affairs Committee advanced a bill in May that would task the secretary of State with setting up a vulnerability disclosure process for researchers to hunt for and disclose flaws in the department’s public-facing websites and applications.

The senators issued various questions to Pompeo around statistics tied to high-value assets, lack of multi-factor authentication and cybersecurity policy for foreign State Department missions.

You can read the letter below.

[documentcloud url=”http://www.documentcloud.org/documents/4872636-State-Dept-Cybersecurity-Letter-From-Wyden.html” responsive=true height=500]

More Scoops

The ‘Authority of Law’ statue outside the entrance to the U.S. Supreme Court building in Washington, D.C., US. Photographer: Al Drago/Bloomberg, Getty Images

Federal judiciary touts cybersecurity work in wake of latest major breach

The Administrative Office of the United States Courts denied ignoring expert advice in a letter to Sen. Ron Wyden, D-Ore., who blasted Chief Justice Roberts in a…

Russian President Vladimir Putin delivers a speech standing in front of the monument “Fatherland, Valor, Honor” outside of the Foreign Intelligence Service of the Russian Federation (SVR) in Moscow on June 30, 2022. (Photo by Mikhail Metzel / Sputnik / AFP) (Photo by MIKHAIL METZEL/Sputnik/AFP via Getty Images)

Unusually patient suspected Russian hackers pose as State Department in ‘sophisticated’ attacks on researchers

An aerial view shows a newly constructed X sign on the roof of the headquarters of the social media platform previously known as Twitter, in San Francisco, on July 29, 2023. (Photo by JOSH EDELSON/AFP via Getty Images)

A tangled mess: Government rules for social media security lack clarity

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/state-department-cybersecurity-senators-letter/