Trump sends cyberwar strategy to Congress

President Donald Trump has sent a cyberwarfare policy to Congress that should outline how the administration will tackle some of the field’s most vexing issues – including launching hacking operations and deterring adversaries. Trump enclosed the document, which was not made public, in a letter Thursday to the House and Senate committees that oversee the departments of Defense, Homeland Security, Justice, and State. The fiscal 2018 National Defense Authorization Act tasked the White House with developing a “multi-prong” cybersecurity policy covering defensive and offensive operations. The policy should include measures to defend against “cyber activities that are carried out against infrastructure critical to the political integrity, economic security, and national security of the United States,” the NDAA states. The White House policy is one of several new cybersecurity measures mandated by the NDAA, including a requirement that the Pentagon more closely communicate with Congress on sensitive, military-led cyber-operations. The new […]

The post Trump sends cyberwar strategy to Congress appeared first on Cyberscoop.

Continue reading Trump sends cyberwar strategy to Congress

Manfra: Private sector on board with more robust DHS cyber strategy

Private firms won’t have any reservations about supporting the more robust cybersecurity strategy that the Department of Homeland Security will soon release, according to the department’s top cyber official. The upcoming DHS document — intended for use in and outside of government — is part of an effort to be “much more forward-leaning on using the tools that we’ve got available to us,” but it is “all still totally voluntary” for private firms, Jeanette Manfra said in an interview with CyberScoop. “A lot of the ideas and the concepts [in the strategy] have come from the private sector.” DHS’s work to make companies more resilient to cyberattacks has always been predicated on trust, without which executives would balk at trading threat data with the government. Manfra hopes that collaboration will intensify. The goal is to be “much more open and transparent in passing information about who is doing what” in cyberspace, she told CyberScoop. […]

The post Manfra: Private sector on board with more robust DHS cyber strategy appeared first on Cyberscoop.

Continue reading Manfra: Private sector on board with more robust DHS cyber strategy

DHS prepares cross-sector strategy to limit domino effects from big cyberattacks

The Department of Homeland Security will soon release a “how-to manual” for the cybersecurity support it offers to federal, state and local government agencies, as well as operators of critical infrastructure, Secretary Kirstjen Nielsen told reporters Tuesday. The nation’s interconnectivity means a cyberattack on the financial sector, for example, could quickly affect the electric grid, Nielsen said at the RSA Conference in San Francisco. “We must be more aware of single points of failure [and] concentrated dependencies,” she said. A DHS official said the strategy could be released next week. The goal of the new cyber strategy is to curb “systemic risk” by helping to secure digital tools used across sectors, Nielsen said. The document will also focus on mitigating the consequences of cyberattacks. “Whether it is common tools such as GPS or payment and settlement systems, our cyber risk assessments need to factor in shocks to the system that could have untold, cascading […]

The post DHS prepares cross-sector strategy to limit domino effects from big cyberattacks appeared first on Cyberscoop.

Continue reading DHS prepares cross-sector strategy to limit domino effects from big cyberattacks

DOD official: Automation can save Pentagon from drowning in data

The Defense Department must do more to take advantage of automation tools to avoid drowning in a sea of network data and risk missing cyber threats, according to a top department official. “Right now, we buy a system for every use case, so we’re probably generating a lot more information than we need to,” Patricia Janssen, director of cybersecurity planning and implementation in the DOD CIO’s office, said Monday at the RSA Public Sector Conference in San Francisco. “How do we bring all that data together to help us manage and identify our vulnerabilities and our weaknesses?” Janssen asked. Automation tools can help DOD cut through the “noise” of unneeded data, she said at a panel discussion of continuous monitoring for cyber threats. The department’s thousands of computer systems make automation imperative to keep those systems patched and identify insider threats, Janssen added. Training staff to carry that out manually simply […]

The post DOD official: Automation can save Pentagon from drowning in data appeared first on Cyberscoop.

Continue reading DOD official: Automation can save Pentagon from drowning in data

Supply-chain vulnerabilities are a ‘digital public health crisis,’ says DHS’s Manfra

Persistent supply chain vulnerabilities such as hardware and software bugs “amount to a digital public health crisis” that the government and private sector must work together to resolve, according to Jeanette Manfra, the Department of Homeland Security’s top cybersecurity official. “We must begin to think in terms of global digital public health, where the decisions of each of us have the potential to affect us all,” Manfra said Monday at SF CyberTalks presented by CyberScoop ahead of the RSA Conference in San Francisco. Manfra, DHS’s assistant secretary for the Office of Cybersecurity and Communications, said that security tools need to be pushed further down the supply chain “to prevent unseen and unknown risk transmitting from vendors to infrastructure.” DHS earlier this year established a supply chain program that provides cyber risk assessments to critical infrastructure firms and federal agencies on products they may acquire or deploy. The supply chain is a logical […]

The post Supply-chain vulnerabilities are a ‘digital public health crisis,’ says DHS’s Manfra appeared first on Cyberscoop.

Continue reading Supply-chain vulnerabilities are a ‘digital public health crisis,’ says DHS’s Manfra

Congress wants answers on FBI’s ‘going dark’ problem in wake of DOJ IG report

A bipartisan group of House lawmakers wrote to FBI Director Christopher Wray Friday slamming the FBI’s handling of the San Bernardino shooter’s locked iPhone, adding that the bureau’s claim that it couldn’t bypass encryption on some 7,800 devices last year “seems highly questionable.” The lawmakers said a recent Justice Department inspector general report on the subject “undermines statements that the FBI made during the San Bernardino litigation and consistently since then, that only the device manufacturer could provide a solution.” The report found that some bureau officials didn’t want to find a solution because it could undercut FBI efforts to legally compel Apple to break the device’s encryption. The letter could further inflame the debate over the “going dark” issue, which posits that criminal investigations are often thwarted due to law enforcement’s inability to bypass encryption. CyberScoop recently reported that a Senate panel could be drawing up a new bill on the subject. Signatories of the letter include […]

The post Congress wants answers on FBI’s ‘going dark’ problem in wake of DOJ IG report appeared first on Cyberscoop.

Continue reading Congress wants answers on FBI’s ‘going dark’ problem in wake of DOJ IG report

Mulvaney: CFPB hit by over 200 data ‘lapses’

The head of the Consumer Financial Protection Bureau revealed Thursday that the agency had suffered some 240 “lapses” in data security over an unspecified time period, in addition to a suspected 800 other such incidents. “We have been able to document about 200-odd – I think 240 – lapses in our data security,” Acting CFPB Director Mick Mulvaney told the Senate Committee on Banking, Housing, and Urban Affairs during a hearing on the bureau’s semi-annual report to Congress. “Lapses – is that a breach?” Sen. David Perdue, R-Ga., asked Mulvaney during a tense exchange. “I think data got out that should not have gotten out,” Mulvaney replied, adding, “there’s another 800 [incidents] that we suspect that we haven’t been able to confirm.” As part of its mandate to protect consumers, the CFPB has the right to collect data on credit card transactions, mortgages, and car loans, Mulvaney said. “Everything that […]

The post Mulvaney: CFPB hit by over 200 data ‘lapses’ appeared first on Cyberscoop.

Continue reading Mulvaney: CFPB hit by over 200 data ‘lapses’

Cisco: Malware and encrypted traffic will challenge federal agencies

Hackers will continue to give U.S. government agencies headaches in the coming months thanks to an evolving malware market and their use of encryption to evade detection, Cisco declared in a new report. “The expanding volume of encrypted web traffic, both legitimate and malicious, creates even more challenges and confusion for the public sector as it tries to identify and monitor potential threats,” the networking giant said in a report on government cybersecurity. “The growing number and variety of malware types and families perpetuates chaos in the attack landscape by undermining government efforts to gain and hold ground on threats,” the report said. Malware is evolving to the point that ransomware campaigns can be launched automatically, without human assistance, according to Cisco. Internet of Things botnets are also on the rise and carrying out advanced distributed-denial-of-service (DDoS) attacks, researchers found. Verizon’s annual cybersecurity report also found a rise in ransomware; […]

The post Cisco: Malware and encrypted traffic will challenge federal agencies appeared first on Cyberscoop.

Continue reading Cisco: Malware and encrypted traffic will challenge federal agencies

White House seeks to tighten identity management in federal agencies

A new White House memo tasks agencies with clamping down on identity security by designating a team of officials from the offices of the chief information officer and chief security officer, among others, to tackle the issue. The Office of Management and Budget draft policy released Friday asks these officials to coordinate regularly to make sure federal Identity, Credential, and Access Management (ICAM) policies are consistently implemented. The proliferation of personal information through social media and data breaches makes verifying identities all the more important for agencies, OMB said. ICAM – a set of measures to prevent unauthorized access to sensitive information – is a staple of cybersecurity, and federal agencies have had to adapt to evolving identity scams from hackers. ICAM took on added importance in the U.S. government after the devastating 2015 Office of Personnel Management breach, in which hackers used compromised credentials to steal information on 22 million […]

The post White House seeks to tighten identity management in federal agencies appeared first on Cyberscoop.

Continue reading White House seeks to tighten identity management in federal agencies