On the heels of the US cyber strategy, CISA set to release secure by design principles
Full article689 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
CISA Director Jen Easterly said the agency plans to release the principles this week to encourage more safe coding practices.
The Cybersecurity and Infrastructure Security Agency plans to release its secure by design principles this week to encourage the adoption of safe coding practices, which are a core part of the Biden administration’s recently released national cybersecurity strategy.
The document isn’t meant to be the “Holy Grail” on secure by design, said CISA Director Jen Easterly during the CrowdStrike Government Summit in Washington on Tuesday, but it’s an important step when it comes to “shifting the burden to software companies from individual users and small businesses” when it comes to cybersecurity.
The secure by design approach to building software products isn’t a new idea but it is gaining more traction. Before the release of the national cybersecurity strategy, Easterly and Eric Goldstein, CISA’s assistant director for cybersecurity, wrote an op-ed calling on software vendors to “stop passing the buck on cybersecurity.” Easterly also made the case for secure by design during a speech at a recent Carnegie Mellon University event, where she called for three “core principles” for technology manufacturers.
At the CrowdStrike summit, Easterly repeated those principals for software vendors, which are: take ownership of security outcomes for their customers, provide “radical transparency” to their customers, and improving design quality in product by focusing on building safe products. “It’s incredibly important that we now focus on ensuring that the software that powers our lives is secure by design and secure by default,” she said.
One early implementation of secure by design comes from the Department of Energy’s cyber informed engineering strategy, a framework aimed at including cybersecurity in engineering practices.
Easterly noted CISA will focus more in the coming months on issues related to open source software used within industrial control systems. Additionally, she said, CISA will work on the High-Risk Community Protection initiative announced late March.
Easterly also talked about the need to increasingly become more resilient in the face of growing cyber threats, and noted that one major lesson out of the Ukraine war is “the power of societal resilience.”
“I don’t think our country really showed that during Colonial Pipeline and I don’t think we showed it recently under the high-altitude balloon,” she said, referencing the Chinese spy balloons that floated through the U.S. and received widespread media attention.
During the early days of the Colonial Pipeline ransomware incident after the company shut down the pipeline during recovery, fears of a loss of gas lead to long lines at the pump. Easterly continued: “I think at the end of the day, our ability to keep calm and carry the hell on is really going to be the key to deal with very significant nation state threats.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-secure-by-design/