Policy & Regulation: Page 13


  • Kemba Walden, acting national cyber director, rolls out the National Cybersecurity Strategy at a forum by the Center for Strategic and International Studies.
    Image attribution tooltip
    Permission granted by Office of the National Cyber Director
    Image attribution tooltip

    White House to share roadmap for national cyber strategy implementation this summer

    Acting National Cyber Director Kemba Walden said the strategy is built to have a 10-year shelf life, allowing for flexibility as new technologies and threats emerge. 

    By April 26, 2023
  • legal processes
    Image attribution tooltip
    Nico ElNino via Getty Images
    Image attribution tooltip

    Software industry leaders debate real costs and benefits of CISA security push

    The global effort to promote secure by design is seen as a potential game changer for software security, but may require substantial investments and considerable cultural changes.

    By April 14, 2023
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    Explore the core tactics of secure by design and default

    The international joint guide encapsulates security recommendations long-touted by CISA, including technical tactics for software and infrastructure design and best practices for default security measures at large.

    By April 13, 2023
  • CISA Director Jen Easterly
    Image attribution tooltip

    Center for Strategic and International Studies

    Image attribution tooltip

    CISA, partner agencies unveil secure by design principles in historic shift of software security

    Authorities are engaging key stakeholders, but there is a broad understanding that these proposed changes will require massive changes in industry culture.

    By Updated April 13, 2023
  • CISA Director Jen Easterly talks with CEO George Kurtz during the CrowdStrike Government Summit.
    Image attribution tooltip
    Permission granted by CrowdStrike
    Image attribution tooltip

    CISA to unveil secure-by-design principles this week amid push for software security

    The Biden administration plans to shift responsibility for product safety to the tech industry. Stakeholder discussions are already underway.  

    By April 12, 2023
  • The White House in Washington DC at summer day.
    Image attribution tooltip
    lucky-photographer via Getty Images
    Image attribution tooltip

    Biden cyber officials see auto, food safety as models for security overhaul

    The push to hold technology stakeholders liable for secure-by-design products will be a multiyear effort likely to involve Congress, the acting national cyber director said.

    By April 10, 2023
  • Lights in Europe are seen from space.
    Image attribution tooltip
    DKosig/iStock via Getty Images
    Image attribution tooltip

    White House eyes the next frontier of cybersecurity — space

    The focus comes more than a year into the Ukraine war, which led to nation state attacks on commercial satellites.

    By March 30, 2023
  • Image of SEC seal on the side of a building.
    Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip
    Opinion

    The proposed SEC cyber incident disclosure rule is a positive change. But it won’t make organizations safer.

    If organizations want to actually get serious about protecting themselves, they need to have a robust system for handling incidents when they happen.

    By Frank Shultz • March 27, 2023
  • Kemba Walden, acting national cyber director, rolls out the National Cybersecurity Strategy at a forum by the Center for Strategic and International Studies.
    Image attribution tooltip
    Permission granted by Office of the National Cyber Director
    Image attribution tooltip

    US looks to reimagine cybersecurity paradigm with burden shift, rebuilt infrastructure

    Security needs to be baked into the technology Americans use every day and not bolted onto aging systems, said Kemba Walden, acting national cyber director.

    By March 24, 2023
  • Man using facial recognition technology on city street
    Image attribution tooltip
    LeoPatrizi via Getty Images
    Image attribution tooltip

    5 steps organizations can take to counter IAM threats

    Many organizations lean on identity and access management tools to perform credential management and authentication. But these systems aren’t foolproof.

    By March 24, 2023
  • CISA Director Jen Easterly, RSA Conference 2022
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    CISA director urges top business leaders, board members to take cyber risk ownership

    Jen Easterly said the government cannot solve challenges posed by rising threat activity without active participation and corporate oversight from the private sector.

    By March 24, 2023
  • Federal Trade Commission Chair Lina Khan listens as U.S. President Joe Biden delivers remarks on the economy in the Eisenhower Executive Office Building on October 26, 2022 in Washington, DC.
    Image attribution tooltip
    Anna Moneymaker via Getty Images
    Image attribution tooltip

    FTC opens inquiry into cloud market competition, security

    As consolidation among hyperscalers grows, federal authorities are raising concerns over cloud dependence in critical sectors.

    By Matt Ashare • March 23, 2023
  • CISA, cybersecurity, agency
    Image attribution tooltip
    Photo illustration by Danielle Ternes/Cybersecurity Dive; photograph by yucelyilmaz via Getty Images
    Image attribution tooltip

    CISA revises cybersecurity performance goals

    After months of feedback from stakeholders, the agency made changes to better align with the NIST framework and update language on MFA.

    By March 22, 2023
  • Senate Holds Hearing On Reform Of US Financial Market Regulations
    Image attribution tooltip
    Brendan Smialowski / Stringer via Getty Images
    Image attribution tooltip

    SEC proposes cybersecurity disclosure rules for financial industry specialists

    The changes would require broker-dealers and other entities to adopt written plans to minimize risk and promptly disclose major incidents.

    By March 17, 2023
  • Futuristic electronic semiconductor and telecommunication network concept
    Image attribution tooltip
    Danai Jetawattana via Getty Images
    Image attribution tooltip

    CISA launches ransomware warning pilot for critical infrastructure providers

    The agency already warned dozens of organizations about ProxyNotShell.

    By March 14, 2023
  • CISA Director Jen Easterly speaks at Carnegie Mellon University urging the tech industry to embrace secure-by-design product development.
    Image attribution tooltip
    Permission granted by Carnegie Mellon University
    Image attribution tooltip

    Shift to secure-by-design must start at university level, CISA director says

    Jen Easterly says secure coding and memory safety should be incorporated into computer science curriculum. 

    By March 13, 2023
  • Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    Blackbaud to pay $3M to settle SEC charges of a misleading ransomware investigation

    The regulator said the cloud-based software provider made misleading disclosures about the scope of a 2020 ransomware attack. 

    By March 10, 2023
  • American Airlines jet taking off from an airport runway.
    Image attribution tooltip
    Joe Raedle / Staff via Getty Images
    Image attribution tooltip

    TSA unveils emergency cybersecurity requirements for airlines, airports

    The requirements follow the release of the Biden administration’s national cybersecurity strategy, which includes enhanced measures for critical infrastructure.

    By March 8, 2023
  • Person pushing large stone uphill
    Image attribution tooltip
    Nastco via Getty Images
    Image attribution tooltip

    How will the government enforce the national cyber strategy?

    Efforts to enact laws and regulations that impose greater responsibility on the technology sector aren’t likely to come quick or easy.

    By March 8, 2023
  • General Motors connected vehicle animation
    Image attribution tooltip
    Permission granted by General Motors
    Image attribution tooltip

    Who is liable for flawed software? New guidance upends the security standard

    Development practices and safe harbor provisions are the subject of major debate as work to implement the White Houses’ cyber strategy begins.

    By March 6, 2023
  • A water purification facility in San Jose.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    EPA unveils cybersecurity oversight for public drinking water systems

    An agency memorandum marks the first new initiative on critical infrastructure since the White House released its national cyber strategy.

    By March 3, 2023
  • Kemba Walden, acting national cyber director, rolls out the National Cybersecurity Strategy at a forum by the Center for Strategic and International Studies.
    Image attribution tooltip
    Permission granted by Office of the National Cyber Director
    Image attribution tooltip

    The US cyber strategy is out. Now, officials just have to implement it

    Industry stakeholders signal a willingness to discuss further steps, while congressional leaders hint additional action may be on the table. 

    By March 3, 2023
  • The sun rises near the White House in Washington, DC.
    Image attribution tooltip
    Zach Gibson via Getty Images
    Image attribution tooltip

    White House releases national cyber strategy, shifting security burden

    The long-anticipated policy will push the technology industry to shoulder more of the load for cyber risk, while promoting long-term investments and global cooperation against common threats. 

    By March 2, 2023
  • Computer engineer working with a computer interface in a factory.
    Image attribution tooltip
    Thinkhubstudio via Getty Images
    Image attribution tooltip

    CISA red team cracks a critical infrastructure provider’s defenses, a lesson in lateral access

    The voluntary assessment raises concerns as the unnamed organization with a mature security program was unable to detect simulated actors moving laterally across its systems for months.

    By March 1, 2023
  • Jen Easterly, CISA director, Black Hat keynote
    Image attribution tooltip
    Samantha Schwartz/Cybersecurity Dive
    Image attribution tooltip

    3 CISA principles for secure by design

    The Biden administration is expected to emphasize safer development practices when it rolls out the national security strategy for cyber. 

    By Feb. 28, 2023