How Multifactor Authentication Can Help U.S. Government Contractors Achieve DFARS Compliance

The U.S. government’s Defense Federal Acquisition Regulation Supplement (DFARS) aims to help the DOD protect its own data and that of its business partners through multifactor authentication (MFA).

The post How Multifactor Authentication Can Help U.S. Government Contractors Achieve DFARS Compliance appeared first on Security Intelligence.

Continue reading How Multifactor Authentication Can Help U.S. Government Contractors Achieve DFARS Compliance

Space Rogue: A Security Rebel Turned Pen Tester

Two decades ago, Cris Thomas testified before Congress about various cybersecurity issues he uncovered as a white hat hacker. Today, he works as a penetration testing specialist for IBM X-Force Red.

The post Space Rogue: A Security Rebel Turned Pen Tester appeared first on Security Intelligence.

Continue reading Space Rogue: A Security Rebel Turned Pen Tester

General Services Administration (GSA) Pointing to New IT Security Rules for Contractors

On January 12, 2018, GSA (General Services Administration) posted a request for public comment regarding updates to the General Services Administration Acquisition Regulation that will include new cybersecurity compliance and reporting requirements for… Continue reading General Services Administration (GSA) Pointing to New IT Security Rules for Contractors

SEC Releases Updated Guidance For Cybersecurity Disclosure

The SEC released updated guidance regarding cybersecurity disclosure for public companies, emphasizing the responsibility of executives to report material risks and incidents.

The post SEC Releases Updated Guidance For Cybersecurity Disclosure appeared first on Security Intelligence.

Continue reading SEC Releases Updated Guidance For Cybersecurity Disclosure

SEC Releases Updated Guidance For Cybersecurity Disclosure

The SEC released updated guidance regarding cybersecurity disclosure for public companies, emphasizing the responsibility of executives to report material risks and incidents.

The post SEC Releases Updated Guidance For Cybersecurity Disclosure appeared first on Security Intelligence.

Continue reading SEC Releases Updated Guidance For Cybersecurity Disclosure

DHS threatened with subpoena over information about Kaspersky removal

Another influential congressman has criticized the Homeland Security Department (DHS) for not being transparent enough about the government’s ongoing efforts to remove a Russian anti-virus product from federal systems. Rep. Lamar Smith, chairman of the House Committee on Science, Space and Technology, is threatening to subpoena documents from DHS concerning a ban against Kaspersky Lab’s anti-virus software. The threat comes because the department failed to provide sufficient information requested by the committee, according to Smith. Smith, R-Texas, is not the first lawmaker to call out DHS for a lack of cooperation. In a letter last month, Rep. Bennie Thompson, D-Miss., accused the department of sending “unclear messages” about its progress made on banning Kaspersky products. The committee originally asked for a detailed update about the removal process from DHS on Dec. 5, 2017. After more than a month, DHS produced a limited set of documents, but the report only contained already public information. On […]

The post DHS threatened with subpoena over information about Kaspersky removal appeared first on Cyberscoop.

Continue reading DHS threatened with subpoena over information about Kaspersky removal

10 Steps to Evaluate Cloud Service Providers for FedRAMP Compliance

Companies that wish to do business with federal government agencies in the cloud must complete these 10 steps to achieve FedRAMP compliance.

The post 10 Steps to Evaluate Cloud Service Providers for FedRAMP Compliance appeared first on Security Intelligence.

Continue reading 10 Steps to Evaluate Cloud Service Providers for FedRAMP Compliance

Securing Medical Devices in the Age of the IoT

Both health care IT professionals and device manufacturers are responsible for securing medical devices in light of emerging IoT threats.

The post Securing Medical Devices in the Age of the IoT appeared first on Security Intelligence.

Continue reading Securing Medical Devices in the Age of the IoT

Trump’s decision to elevate Cyber Command will be a boon for defense contractors

With President Donald Trump’s move to elevate U.S. Cyber Command to a unified combatant command, the Fort Meade-based outfit is on track for additional funding dollars and a bump in acquisition authorities, which experts believe will translate into the development of new programs and therefore a cadre of opportunities for private defense contractors. It’s not so much that Cyber Command has been poorly funded in the past, explained Michael Sulmeyer, a former senior U.S. defense official during the Obama administration, but rather that the Combatant Command designation and continued maturation of the organization will position it with an “equal seat at the table” to vie for future funding dollars and pursue innovative technologies. “I think it’s interesting that Trump’s statement mentioned funding, because I am not aware of any budgetary shortfalls faced by the cyber mission. Cyber Command will continue to receive the resources it needs,” said Sulmeyer. “The Defense […]

The post Trump’s decision to elevate Cyber Command will be a boon for defense contractors appeared first on Cyberscoop.

Continue reading Trump’s decision to elevate Cyber Command will be a boon for defense contractors

Government Agencies Must Work With the Private Sector to Bolster Infrastructure Security

To improve infrastructure security per the president’s executive order, government agencies must build trust with the private security industry.

The post Government Agencies Must Work With the Private Sector to Bolster Infrastructure Security appeared first on Security Intelligence.

Continue reading Government Agencies Must Work With the Private Sector to Bolster Infrastructure Security