惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
腾讯CDC
D
Docker
The Cloudflare Blog
量子位
爱范儿
爱范儿
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Vercel News
Vercel News
MyScale Blog
MyScale Blog

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report
Better Cyber Hygiene Helps, but Federal Security Needs SA...
Craig Muelle · 2021-11-24 · via MeriTalk

The recent Binding Operational Directive issued through the Cybersecurity and Infrastructure Security Agency (CISA) requiring Federal agencies to immediately patch hundreds of cybersecurity vulnerabilities affirms the Biden administration’s prioritization on securing Federal government networks and reinforces that improved cyber hygiene is critical to protect against malicious adversaries seeking to infiltrate government systems and compromise data.

Earlier this year, the Senate Committee on Homeland Security and Government Affairs issued a bipartisan report entitled, “Federal Cybersecurity: America’s Data Still at Risk” that outlines the challenge the government has with a mountain of technical debt. The report highlights that seven of the eight agencies audited used unsupported applications and technologies, and in doing so neglected to implement basic cybersecurity standards necessary to protect America’s sensitive data.

Although Federal cybersecurity spending has increased significantly over the past 10 years, the problem of securing our critical information and protecting our employees against adversaries hasn’t gotten any easier. And many would agree that the new, hybrid government workforce presents an additional set of challenges.

Bottom line: the proliferation of telework and the complexities associated with legacy government networks – in conjunction with the enduring shortage of cybersecurity professionals to perform these critical services – illuminates the need for the Federal government to modernize existing network security architectures and leverage cloud-native services for today’s network security functions.

Getting Going

The challenge for many agencies is knowing where to start. To securely connect today’s hybrid Federal employee and alleviate the burden on an already taxed cyber workforce, government agencies should adapt their network and security plans and focus their digital transformation efforts on moving to a Secure Access Service Edged (SASE) platform that provides the fundamental zero trust principles for secure connectivity outlined in NIST S.P. 800-207.

Moving to a SASE platform enables agencies to begin to implement a zero trust model, as required by the Biden administration’s Cybersecurity Executive Order issued in May.

When looking for a SASE platform, agencies should prioritize what networking and security capabilities they require to strengthen their cybersecurity posture and understand the impact their near-term decisions will have on their longer-term goals. Implementing the correct SASE service – one that provides native IPv6 support throughout the entire platform, for example – is critical for the Federal government to achieve its zero trust goals.

Some agencies will also start deploying Zero Trust Network Access (ZTNA), replacing their VPNs as a first step. Having ZTNA as an integrated security microservice within a SASE platform – and not as a standalone product – will help simplify and streamline the end-state architecture.

Insight into the expected end state – not only from a technology perspective, but also including doctrine, people, and process – will allow Federal agencies to achieve the outcomes they’re looking to accomplish through modernization:  increased security, reduced cost and complexity, improved performance, ability to deliver on mission, and assured compliance.