DHS prepares for possible legal action over Kaspersky directive
Full article607 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Representatives from the Department of Homeland Security are preparing for legal action over their directive to remove the anti-virus software from government systems.
The Department of Homeland Security is continuing to remove Kaspersky Lab software from federal systems after finding that 15 percent of federal agencies detected it on their systems, DHS’s assistant secretary for cybersecurity Jeanette Manfra told Congress Tuesday.
The hearing, held by the House’s Committee on Science, Space and Technology’s Subcommittee on Oversight, focused on the September DHS directive to remove Kaspersky Lab software from federal systems.
Tuesday’s hearing comes after a similar Kaspersky-focused hearing on Capitol Hill held last month.
DHS is preparing for possible legal action from Kaspersky. Late Friday night, Kaspersky Lab delivered a long written response to Homeland Security’s directive banning software from the Moscow-based cybersecurity firm. Lawyers from DHS are reviewing the response.
“The company hopes that DHS will reconsider the repercussions of its Directive in light of the facts presented, and Kaspersky Lab continues to consider all of its possible options,” a Kaspersky Lab spokesperson told CyberScoop.
Rep. Bill Posey, R-Fla., raised his eyebrows over the prospect of legal action from Kaspersky.
“To paraphrase Clint Eastwood: ‘Go ahead and make my day,'” Posey said.
Kaspersky has repeatedly denied any wrongdoing, with company executives saying they are pawns in a U.S.-Russian geopolitical game.
Eugene Kaspersky, the Moscow-based cybersecurity firm’s founder and CEO, previously offered a source code review to the U.S. government. Manfra brushed off the offer and said although it would be welcome, it would not be sufficient to alleviate the government’s concerns.
Cybersecurity experts have repeatedly pointed out that a source code review would reveal little about the ongoing action of Kaspersky’s anti-virus for several reasons, including that anti-virus by design always has enormous access to data on a host machine.
Manfra said that 94 percent of agencies have responded to the DHS directive to remove Kaspersky from federal systems which, she clarified, does apply to federal contractors. The next phases of the plan are to develop an action plan for removal and then to implement the plan.
The Department of Defense, which is not subject to DHS directives, issued its own order to remove Kaspersky on August 3, 2017. A search of the Pentagon’s systems confirmed they do not have Kaspersky products, DOD CIO Essye Miller testified.
You can watch the full hearing here:
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dhs-kaspersky-legal-action-science-committee-hearing/