惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
Webroot Blog
Webroot Blog
T
Troy Hunt's Blog
S
Secure Thoughts
S
Security @ Cisco Blogs
S
Security Affairs
Forbes - Security
Forbes - Security
W
WeLiveSecurity
H
Hacker News: Front Page
T
Threatpost
Google Online Security Blog
Google Online Security Blog
S
Schneier on Security
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - Franky
腾讯CDC
IT之家
IT之家
博客园 - 聂微东
L
LINUX DO - 最新话题
罗磊的独立博客
Hacker News - Newest:
Hacker News - Newest: "LLM"
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 三生石上(FineUI控件)
Hacker News: Ask HN
Hacker News: Ask HN
C
CXSECURITY Database RSS Feed - CXSecurity.com
C
Cybersecurity and Infrastructure Security Agency CISA
C
CERT Recently Published Vulnerability Notes
Know Your Adversary
Know Your Adversary
V
Vulnerabilities – Threatpost
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cisco Talos Blog
Cisco Talos Blog
S
SegmentFault 最新的问题
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
L
LINUX DO - 热门话题
美团技术团队
G
GRAHAM CLULEY
T
The Exploit Database - CXSecurity.com
AI
AI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Jina AI
Jina AI
Help Net Security
Help Net Security
N
News | PayPal Newsroom
月光博客
月光博客
Spread Privacy
Spread Privacy
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
N
News and Events Feed by Topic

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline The Next AI Wave: Quantum AI CDM’s Evolution to Non-Traditional Technology: Why Now and How Will it Succeed? Customer Expectations Require Agencies to Raise the Bar on Customer Experience, Report Shows Applying for Government Benefits Shouldn’t Be Difficult When It Comes to Identity Verification Four Federal Software Supply Chain Security Trends to Watch FedRAMP Baseline Transition Points to OSCAL-Native Tools What Zero Trust Means for Modern Government: Best Practices for Key Tenets Four Ways to Handle the IT Funding Crunch Agencies Need to Get Creative to Fill the Cyber Workforce Gap Customer Identity trends report shows control trumps convenience Federal Agencies Making Strides Toward Sustainability and Climate Action Executive Order 14028 | Improving the Nation’s Cybersecurity Depends on Data | All Data is Security Data Applying Geospatial Intelligence, AI/ML to Climate Change Challenge My Cup of IT: Angry at Arthritis, Hunting for Cures How the Federal Government Can Help Combat a Fragmented Internet Accelerating Cybersecurity for US Critical Infrastructure Getting in on the Ground Floor of the ‘New Observability’ Comply-to-Connect is Key to Zero Trust for DoD How Will Upcoming Cryptocurrency Regulations Affect Industry? My Cup of IT: Cup Cake for Kushner? Launching a New Era of Government Cloud Security Managing IT Complexity in Federal Agencies Agencies Must Modernize Zero Trust Approaches to Achieve Optimal Protection Five Essential Metrics for Measuring Federal Government CX Unlocking the Benefits of 5G and Beyond The Federal Factory of the Future: How AI is Transforming Manufacturing The Quantum Impact on Cyber How Next-Gen Computers Will Transform What’s Possible for Federal Government Agencies Must Take an Authentic Approach to Synthetic Data Biometrics and Privacy: Finding the Perfect Middle Ground Two-Way Street: Why Officials and Constituents Are Equally Responsible for Securing the Midterms The “Programmable World” Will Bring the Best of the Virtual World Into the Physical One Cyberattacks are a Common Occurrence and the Costs are Higher Than Ever Increasing Equity Through Data and Customer Experience The AI Edge: Why Edge Computing and AI Strategies Must Be Complementary How Metaverses and Web3 can Reshape Government Four Emerging Technology Trends set to Impact Government Most 5G Enables AI at the Edge Plugging Cyber Holes in Federal Acquisition Resilient Critical Infrastructure Starts with Zero Trust The Evolution of Government Tech Procurement Under CMMC 2.0 Zero Trust Requires Continuous, Tested Security for Federal Agencies How Multi-INT Fusion Accelerates Mission Intelligence for Real-Time Decision Advantage Three Things to Consider for Responsible AI in Government Legislation, White House Orders Show Agencies Opportunity for Hybrid Cloud Creating an Effective Framework for DoD’s Software Factories Realizing Upsides for Digital Security in the Hybrid Workplace A Future With AI and ML: The Power of Workforce Education Five Tips to Begin MFA Integration and Embrace Zero Trust The Vital Intersection Between Equity and Digital Transformation Equity as a Platform: Applying a New Mindset to Scale Innovation Harnessing the Right Data for Evidence-Based Equity From EO to Action: Human Factors of Enabling a Cyber Safety Review Board For Equity in Government Services, It’s Time to Change the Paradigm Critical Questions to Ask When Considering Explainable AI (XAI) for Your Federal Agency The Telework Model for Government: COVID Lessons for Building an Effective Workforce DevSecOps: 4 Steps for Mitigating the Next Cyber Attack in Your Federal IT Environment Better Cyber Hygiene Helps, but Federal Security Needs SASE Lift Cloud-Native Government: How to Transform With Intention DoD and VA Health Networks Face Growing Threat From Medical-Device Vulnerabilities New Federal Cybersecurity Requirements: How Agencies Should Implement a Zero Trust Architecture Protecting Our Nation Through Big Data Analytics Three Ways COVID-19 Altered Federal, State IT Budget Allocations Ransomware is More Than a Cybersecurity Issue From Me to We: Take the Mission Further With Multiparty Systems Anywhere, Everywhere: Integrating Your Virtual Workplace ‘I, Technologist’: Empowering Innovators in the Federal Workforce Mirrored World: Digital Twins Report for Duty Across Government Stack Strategically: Rearchitecting Government for What’s Next
DoD, Feds Plot Top Cyber, Cloud Priorities for 2022
Colby Proffi · 2021-11-19 · via MeriTalk

Top cybersecurity officials from the Defense Department (DoD), Federal civilian agencies, and the private sector laid out their developing strategies for zero trust security migration, cloud adoption, and meeting requirements of the Biden administration’s Cybersecurity Executive Order at an October meeting of the Foundation for American Science and Technology (FAST).

Emerging from the meeting was a much-needed dialogue between the public and private sectors for better collaboration, and a realization that while each Federal agency has its own mission and unique challenges, many share a similar focus.

Zero Trust and the Cyber EO

Executive Order 14028 on Improving the Nation’s Cybersecurity was released in May with nine sections outlining specific focus areas for security improvements. The EO places significant emphasis on zero trust security adoption – mentioning it eleven times. But six months after the order’s release, and despite several guidance documents from the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA), Federal agencies are in many ways still grappling with how to best incorporate zero trust concepts into their overall security strategy.

While zero trust guidance provides a common roadmap, each agency faces the challenge of charting an effective course for adoption and layering zero trust onto its existing security strategy without disruption to mission sustainment. Despite the EO – and apart from a strong, proven use case as precedent – it can be difficult to make the first move, especially without dedicated funding.

Agencies are hoping that the criticality of zero trust, however, may provide an opportunity to break the traditional mold for procurement and implementation. They are pushing for changes to the requirements process with things like a lightweight or continuous Authority to Operate (ATO) – reducing the number of controls from hundreds to a few dozen core controls, and reducing the duration of the overall process. Sometimes referred to as a rapid ATO, this continuous authorization can allow software to be authorized once and used many times, providing the opportunity for security solutions to not just be used and shared across a single agency, but across multiple agencies as well.

Better security doesn’t just require modern solutions, it requires a modern approach for procurement, authorization, and adoption. Just as legacy tech can introduce security risks, legacy processes can allow pervasive security risks and threats to persist.

Cloud Adoption and Cyber in the Cloud

While many agencies were already leveraging the cloud in some capacity, the pandemic served as a forcing function that has propelled further adoption to satisfy requirements of accessing data and applications remotely. What’s top of mind now is consolidating and converging cloud instances for better security and visibility. Barring specific requirements for cloud adoption, and spurred by the need to maintain the mission, cloud management and security both now frequently fall to organizations to sustain independently. This has created a massive gap in visibility and increased risks for these organizations.

In addition to visibility, Federal organizations require a hybrid cloud model and cloud portability – the ability to move applications and data from one cloud provider to another, and to keep some critical data and applications on premise. Limited budgets are a key driver for the government’s requirement for portability and flexibility. Much like consumers shop around for the best value for goods or services, agencies have to use the service that represents the best value within their budget – and sometimes that means changing services.

Federal agencies at the October FAST meeting agreed with the idea that moving to the cloud will save money was a misnomer. While there may be some long-term cost savings and opportunities for improved efficiencies, the top drivers behind cloud adoption are mission requirements and the need for modernization and better security.

Modernization, Integration, and Continuous Authorization

IT modernization has been an ongoing effort across government for years, but in many cases, modernization really just means catching up as opposed to getting ahead. Government systems and networks weren’t architected for the cloud. Those that haven’t yet been modernized were built to support an on-premise environment, both in terms of IT operations and security.

While cloud adoption is but one facet of an overall modernization strategy, it’s a big one. From data transfer and data center consolidation to application and tools rationalization and retraining and retooling personnel, it’s a time-consuming and resource intensive process. And, because of the time required, the best-laid strategy for modernization and adoption might be realized as outdated by the time it’s fully funded and executed.

Federal and industry participants agreed that just as government needs to streamline procurement and ATO processes, industry can help reduce stove-piped solutions by providing integrated solution offerings. While Federal agency participants acknowledged the need to retire legacy tech, they also said they are looking for integrated solutions that augment what they already have, while complementing other new investments.

Solution providers selling to the government, of course, face the challenge of trying to provide Federal-specific solutions for a federated government that’s comprised of hundreds of individual organizations and sub-organizations.

What’s next?

While there are certainly some significant obstacles to implementing the necessary changes to meet the requirements of the Cyber EO, there are two clear actions that must remain in focus for both government and the private sector.

First, the mutual acknowledgement that legacy structures aren’t just limiting, but actually increase risk – not only in terms of technology, requirements, strategy and processes – but also in terms of technology and security expectations. Decisions in each of these areas that were made in years past may have been the best decisions at the time, but that doesn’t mean they are the right decisions for today’s environment. It’s never been more critical that the public and private sectors determine ways to overcome long-standing limitations brought about by precedent and political inertia, and demand improvements that exceed the current security status quo.

Second, there must be a willingness to assemble and speak candidly across the public and private sectors. Apart from transparent communication and a sincere desire to collaborate for the betterment of our nation’s security, progress will be difficult to realize for either sector. To that end, FAST will reconvene on Jan. 13, 2022 to continue the conversation and chart a course for tackling the hardest problems facing government.