惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
G
Google Developers Blog
D
Docker
The GitHub Blog
The GitHub Blog
H
Help Net Security
WordPress大学
WordPress大学
博客园_首页
Recent Announcements
Recent Announcements
P
Proofpoint News Feed
罗磊的独立博客
I
InfoQ
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
Visual Studio Blog
Jina AI
Jina AI
J
Java Code Geeks
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report
Five Tips to Begin MFA Integration and Embrace Zero Trust
Robert Blumo · 2022-03-08 · via MeriTalk

The Federal government has recently taken new steps towards creating a zero trust security environment, building on last May’s Executive Order on Improving the Nation’s Cybersecurity (EO) aimed at advancing the standards by which we protect our federal information system.

On January 19, the President issued a National Security Memorandum extending the EO to National Security Systems (NSS), stating that NSS has 180 days to adopt Multi-Factor Authentication (MFA). On January 26, the Office of Management and Budget released a memorandum creating a Federal zero trust architecture, requiring that all agencies achieve zero trust security goals by FY2024 and referencing MFA as a critical part of the government’s security baseline.

The key foundation of all of this work is the integration of MFA agency by agency. As new measures are undertaken to protect our government’s cybersecurity systems, the government must ensure that MFA solutions are widely adopted across agencies and that lessons learned are shared. While we currently don’t have specific data (for understandable security reasons) describing where agencies are in the adoption of MFA, at Akamai, we know from our own MFA journey how much time, effort, and resources it takes for organizations to implement MFA solutions, and the struggles faced when doing so.

With this experience in mind, here are five tips for federal agencies, and others, looking to adopt MFA technology and begin a zero trust security journey:

Start With a Quick Win

It is daunting and, frankly, impractical, to migrate all systems and applications to MFA immediately.  So begin your journey with a quick and impactful win – for example, implement MFA for your Single Sign-On (SSO). Likely, you already have many applications behind the SSO, so this point of integration gets you MFA for all of those applications in one step. In addition, this step will get your teams familiar with implementing your chosen MFA solution and start getting your end-users into the habit of using MFA.

Prioritize MFA Integrations by Impact

Once you have a quick win under your belt, evaluate your environment to prioritize the remaining necessary MFA integrations. At the top of your list should be integrations that will have the greatest impact – either by volume of applications and systems protected or by criticality to your agency. After SSO, implement MFA for your virtual private network (VPN) (and better yet, replace your VPN with a Zero Trust Access solution), since numerous attacks have started by exploiting weak authentication on the VPN. This prioritization exercise will help you break your migration into manageable increments and ensure your most valuable assets are protected first. 

Leverage FIDO2 With Mobile Devices Versus Physical Tokens 

If you can use mobile devices for MFA instead of physical tokens, the MFA implementation and enrollment is greatly simplified both for your end users and your helpdesk. Everybody already has a mobile device, so by using these devices, you avoid the headache of rolling out and maintaining physical tokens. Moreover, push-based MFA for mobile devices is incredibly easy to use – your users will be delighted – and modern solutions make it very easy for users to enroll their devices, so almost no effort is needed from your helpdesk.

As long as your MFA solutions leverage the newer FIDO2 MFA security technology, you will both improve your security defenses and provide greater convenience to users with frictionless mobile push notifications. Of course, in some cases, physical tokens may be a necessity. In those cases, it’s important to have an MFA solution that is flexible enough to adapt to your agency’s requirements.

Piggyback on Other Cyber Initiatives

As with any IT or security initiative, there is no success without end-user awareness and adoption. To help speed up adoption, we recommend combining an MFA rollout with other cybersecurity training or awareness campaigns whenever possible. By introducing (and then reminding) your employees about how to use MFA and explaining its role in a broader zero trust architecture as part of your regular cadence of training, you help prevent training fatigue and integrate MFA into the day-to-day technology landscape.

Invest in a Strong Identity Solution

While it’s a separate initiative from the MFA implementation, I’d be remiss if I didn’t mention the importance of your other Identity and Access Management (IAM) systems like Identity Management (IdM). These systems provide the framework to link authenticated users with the policies that control what they are able to access. Consider when and how you can focus on your IdM solution, either in parallel with your MFA implementation, or shortly thereafter.?? Strong identity and access management with FIDO2-based MFA is the foundational technology upon which additional security technologies can be most effective.

With these key steps in mind, Federal agencies can ease the transition to an MFA solution and work to improve their cybersecurity defenses. These steps also satisfy the requirements of the Administration’s Executive Order for improving the government’s cybersecurity posture, and help agencies move towards a true zero trust approach to security.