A top official at the Cybersecurity and Infrastructure Security Agency (CISA) said that we can expect to see “much more” guidance from agency cyber gurus in the coming months on Cybersecurity Supply Chain Risk Management (C-SCRM).

[…]

CISA

Daniel Bardenstein, the Cybersecurity and Infrastructure Security Agency’s (CISA) Chief of Technology Strategy and Delivery, said on Jan. 18 he will be stepping down from his post at the cyber defense agency.

[…]

As open source tools and software are becoming a more integral part of the government’s technology base, a host of agencies are at work formulating strategies to take best advantage of that trend, according to Allan Friedman, senior advisor and strategist at the Cybersecurity and Infrastructure Security Agency (CISA)

[…]

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) co-chaired the second meeting of their Joint Ransomware Task Force (JRTF) on Dec. 14, with a CISA leader saying that the task force effort is yielding “unifying” effects in the fight against ransomware-driven cyber attacks.

[…]

CISA

Top officials at the Cybersecurity and Infrastructure Security Agency’s (CISA) Joint Cyber Defense Collaborative (JCDC) are “demystifying” how the Federal government maintains critical infrastructure security and resiliency by partnering and sharing information with organizations across the globe, panelists said at Splunk’s Dec. 14 Government Summit in Washington, D.C.

[…]

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new Common Vulnerabilities and Exposures (CVEs) listings to its already extensive website catalog of CVEs, the agency said in a Twitter posting on Nov.28.

[…]

ransomware
supply chain risk management process automation

The Cybersecurity and Infrastructure Security Agency (CISA) along with the National Security Agency (NSA) and the Office of the Director of National Intelligence (ODNI) published the final part of the three-part series on securing supply chains on Nov. 17.

[…]

The Cybersecurity and Infrastructure Security Agency (CISA) announced on Nov. 22 the release of a new update on the agency’s Infrastructure Resilience Planning Framework (IRPF) which helps state, local, tribal, and territorial planners protect technological infrastructure.

[…]

CISA

Iranian nation-state threat actors breached a Federal agency’s network before deploying malware, including a credential harvester and a cryptocurrency miner, according to a joint advisory released on Nov. 16, by the Federal Bureau of Investigations (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA).

[…]

A Cybersecurity and Infrastructure Security Agency (CISA) official told attendees at the Nov. 9 Red Hat Government Symposium that the agency’s efforts to improve security threat hunting within Federal government networks relies on speeding threat data to end users who can best use it.

[…]

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services (HHS) released a new Cybersecurity Advisory (CSA) on Oct. 21 warning about ransomware attacks by the Daixin Team hacking group. The advisory says the Daixin Team has been targeting U.S. healthcare organizations […]

[…]

CISA
CISA

The Cybersecurity and Infrastructure Security Agency (CISA) plans to host a public listening session in Washington, D.C. on Oct. 19 to get input on forthcoming proposed regulations to implement the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).

[…]

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) has selected Mona Harrington to be the assistant director for the agency’s National Risk Management Center (NRMC), a position she has been serving on a temporary basis since March.

[…]

The Cybersecurity and Infrastructure Security Agency (CISA) has opened their annual, voluntary cybersecurity assessment for state, local, tribal, and territorial (SLTT) entities across the nation and aims to provide a broad picture of the current cybersecurity gaps and capabilities.

[…]

CISA

The Senate Homeland Security and Governmental Affairs Committee on Sept. 28 voted to approve legislation that would authorize the Cybersecurity and Infrastructure Security Agency (CISA) to undertake and fund a new initiative to provide industrial control systems (ICS) security training.

[…]

ransomware

The Federal government’s Joint Ransomware Task Force (JRTF) kicked off its inaugural meeting with a discussion of new initiatives to collaborate with state, local, tribal, and territorial entities to protect against ransomware intrusions and disrupt malicious actors, according to a September 14 press release from the Cybersecurity and Infrastructure Security Agency (CISA).

[…]

Iran

The Cybersecurity and Infrastructure Security Agency (CISA), along with its partners, released a Cybersecurity Advisory (CSA) on Sept. 14 to warn agencies about continued malicious cyber activity from actors affiliated with the Iranian Government’s Islamic Revolutionary Guard Corps (IRGC).

[…]

CISA

The Cybersecurity and Infrastructure Security Agency (CISA) has issued its strategic plan for 2023 to 2025, setting forth four main goals of cyber defense, risk reduction and resilience, operational collaboration, and agency unification.

[…]

The Billington CyberSecurity Summit closed out day two with a discussion with the Cybersecurity and Infrastructure Security Agency’s (CISA) Senior Election Security Advisor, Kim Wyman, on the necessity of voting infrastructure protection in the upcoming national elections.

[…]

CISA

Collaborating with private entities is a sure way to improve the security of open source software, said Allan Friedman, the senior advisor and strategist for the Cybersecurity and Infrastructure Strategy Agency (CISA), during day two of the Billington CyberSecurity Summit.

[…]

three-keys-to-cybersecurity

The Executive Assistant Director for Cybersecurity for the Cybersecurity and Infrastructure Security Agency (CISA), Eric Goldstein, preached the importance of offensive and defensive cybersecurity teams working together to mitigate attacks in America from adversaries.

[…]

AI

Chief Technology Officer (CTO) of the Cybersecurity & Infrastructure Security Agency (CISA), Brian Gattoni, discussed the future of applying artificial intelligence (AI) to Federal cybersecurity operations during the Billington Cybersecurity Summit on September 7.

[…]

quantum computer processor chip intel computing hardware

The Cybersecurity and Infrastructure Security Agency (CISA) has released a new guideline aimed at preparing critical infrastructure operators in the United States for the cybersecurity dangers of post-quantum cryptography.

[…]

CISA

Implementing zero trust security architectures remains a team-based exercise in which technology and security leaders need to lean on each other for knowledge and advice – even those who help run IT operations at tech-savvy agencies like the Cybersecurity and Infrastructure Security Agency (CISA).

[…]

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) on August 11 issued a Cybersecurity Advisory (CSA) on the Zeppelin ransomware threat as part of CISA’s #StopRansomware initiative.

[…]

Categories