ZeroHour
CyberScooppublished ()ingested @timstarks

CISA advisory panel wants agency to act on election disinformation, multifactor authentication

criticalAdvisoryimportance 55
Full article718 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

CISA's director has 90 days to respond to the suggestions.

DHS, Department of Homeland Security, CISA, RSA 2019, coronavirus
(Scoop News Group photo)

A panel advising the Cybersecurity and Infrastructure Security Agency on everything from combatting disinformation to reducing critical infrastructure risks approved its inaugural set of recommendations for the Department of Homeland Security cyber agency on Wednesday.

In total, the panel approved more than 100 recommendations (“Develop incentives and access to information to aid security researchers who will submit vulnerabilities affecting critical systems”) and sub-recommendations (“Encourage continued participation by providing rewards such as public recognition and cash awards”).

Some suggestions require action soon, such as CISA delivering a “What to Expect on Election Day” plan to election officials about how to counter false information ahead of 2022 midterm voting. Others stretch years into the future, such as CISA pressuring federal contractors to set up multifactor authentication by 2025. Multifactor authentication involves users verifying their identity via two or more steps, such as a password and entering a one-time code into a mobile phone.

The CISA Cybersecurity Advisory Committee emerged as a mandate under the fiscal 2021 defense policy bill and held its third meeting Wednesday. It draws membership from industry, academia and government, all of which could be affected by the panel’s recommendations. CISA Director Jen Easterly has 90 days to respond, then develop an action plan if she supports a given recommendation or explain why she rejected any.

Easterly praised the committee at Wednesday’s meeting for coming up with “some really incredible recommendations.”

She said she had added an assignment to one of the panel’s six subcommittees to develop a cyber threat advisory alert system to counter “vigilance fatigue,” the topic of a recent op-ed she penned for CyberScoop with National Cyber Director Chris Inglis. That subcommittee, Building Resilience and Reducing Systemic Risk to Critical Infrastructure, was the only one not to make recommendations Wednesday.

Some of the recommendations have their limits. For instance, CISA can attempt to incentivize federal contractors into meeting a deadline to implement multifactor authentication, but a patchwork of federal regulations govern contractors’ cybersecurity requirements. Others would require additional funding, such as the cash rewards for security researchers who report software flaws to agencies.

More Scoops

(Graphic by Shanima Parker / Scoop News Group)

Across party lines and industry, the verdict is the same: CISA is in trouble

The agency lost a third of its people in a year. Now industry and lawmakers on both sides say it's unprepared for a potential crisis.

Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency, testifies during the DHS oversight hearing in the Cannon House office building on Jan. 21, 2026. (Photo by Heather Diehl/Getty Images)

Acting CISA chief says DHS funding lapse would limit, halt some agency work

(L-R) Rep. Nick LaLota R-N.Y., Rep. Tony Gonzales, R-Texas, Rep. Marjorie Taylor Greene, R-Ga. and Rep. Andrew Garbarino, R-N.Y., listen during a hearing with the House Committee on Homeland Security on Jan. 30, 2024. (Photo by Anna Moneymaker/Getty Images)

Trade groups worry information sharing will worsen without critical infrastructure panel, CISA law renewal

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-cybersecurity-advisory-committee-first-recommendations/