Multifactor authentication could be long haul for some federal agencies, CISA official says
Full article715 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Eric Goldstein said agencies are focusing hard on adopting MFA, but some are dealing with older IT.
It could be a lengthy path for some federal agencies to adopt the key security step of multifactor authentication required under an executive order last summer, a top federal cybersecurity official told CyberScoop Wednesday.
While Eric Goldstein, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, said agencies were applying “extraordinary attention and focus and effort on this issue,” there are difficulties that will take time to overcome for agencies that still haven’t met a November deadline on multifactor authentication (MFA). MFA requires users to access websites and systems by entering a password, then also using another device to verify their identity.
“The challenge is that no insignificant number of federal systems are running on legacy infrastructure, which means that it’s not just as simple as deploying a modern authentication stack on top of your modernized infrastructure,” Goldstein, whose agency is housed within the Department of Homeland Security, said in an interview at the 2022 RSA Conference.
“I don’t think it’s years away. Obviously, every agency and every system is going to be unique.”
Eric goldstein, cisa
In other words, those old, outdated systems have to be substantially updated or fully replaced to comply with newer security tech.
Asked whether it might years take for some agencies to get up to speed, Goldstein answered, “I don’t think it’s years away. Obviously, every agency and every system is going to be unique.”
Congressional exasperation with the slow pace of agencies deploying MFA emerged at a House hearing last month. The May executive order had “aggressive but achievable” deadlines, a White House official said last year.
MFA, that same official said, could prevent 80 to 90% of all successful cyberattacks.
Goldstein said the solution involves agencies increasingly adjusting their budgets to get to a place where they can get their systems in a place for being able to adopt MFA — something he’s seeing happening. They also are tapping Technology Modernization Fund (TMF) money.
The Biden administration is seeking $300 million for the fund in fiscal 2023, which dedicates dollars to agencies upgrading aging IT systems and expects recipients to reimburse the TMF from cost savings gained via improved efficiency with the better tech.
More Scoops
Federal judiciary touts cybersecurity work in wake of latest major breach
The Administrative Office of the United States Courts denied ignoring expert advice in a letter to Sen. Ron Wyden, D-Ore., who blasted Chief Justice Roberts in a…
CISA pushes guide for high-value targets to secure mobile devices
Agencies face ‘inflection point’ ahead of looming zero-trust deadline, CISA official says
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/multifactor-authentication-cisa-eric-goldstein-federal-legacy-it/