CISA advisory panel wants agency to act on election disinformation, multifactor authentication
Full article718 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
CISA's director has 90 days to respond to the suggestions.
A panel advising the Cybersecurity and Infrastructure Security Agency on everything from combatting disinformation to reducing critical infrastructure risks approved its inaugural set of recommendations for the Department of Homeland Security cyber agency on Wednesday.
In total, the panel approved more than 100 recommendations (“Develop incentives and access to information to aid security researchers who will submit vulnerabilities affecting critical systems”) and sub-recommendations (“Encourage continued participation by providing rewards such as public recognition and cash awards”).
Some suggestions require action soon, such as CISA delivering a “What to Expect on Election Day” plan to election officials about how to counter false information ahead of 2022 midterm voting. Others stretch years into the future, such as CISA pressuring federal contractors to set up multifactor authentication by 2025. Multifactor authentication involves users verifying their identity via two or more steps, such as a password and entering a one-time code into a mobile phone.
The CISA Cybersecurity Advisory Committee emerged as a mandate under the fiscal 2021 defense policy bill and held its third meeting Wednesday. It draws membership from industry, academia and government, all of which could be affected by the panel’s recommendations. CISA Director Jen Easterly has 90 days to respond, then develop an action plan if she supports a given recommendation or explain why she rejected any.
Easterly praised the committee at Wednesday’s meeting for coming up with “some really incredible recommendations.”
She said she had added an assignment to one of the panel’s six subcommittees to develop a cyber threat advisory alert system to counter “vigilance fatigue,” the topic of a recent op-ed she penned for CyberScoop with National Cyber Director Chris Inglis. That subcommittee, Building Resilience and Reducing Systemic Risk to Critical Infrastructure, was the only one not to make recommendations Wednesday.
Some of the recommendations have their limits. For instance, CISA can attempt to incentivize federal contractors into meeting a deadline to implement multifactor authentication, but a patchwork of federal regulations govern contractors’ cybersecurity requirements. Others would require additional funding, such as the cash rewards for security researchers who report software flaws to agencies.
More Scoops
Across party lines and industry, the verdict is the same: CISA is in trouble
The agency lost a third of its people in a year. Now industry and lawmakers on both sides say it's unprepared for a potential crisis.
Acting CISA chief says DHS funding lapse would limit, halt some agency work
Trade groups worry information sharing will worsen without critical infrastructure panel, CISA law renewal
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-cybersecurity-advisory-committee-first-recommendations/