Pres. Biden calls for strengthening cyber defenses with Zero Trust architecture
President Bidens recent statement on our nations cybersecurity highlighted intelligence indicating that the Russian Government is exploring options for potential cyberattacks on US targets. While this most recent threat is seen as potential retaliation for the economic sanctions the United States and its allies have imposed on Russia for its invasion of Ukraine, the threat of Russian-backed cyberattacks is nothing new. Indeed, as Bidens statement put it, cyberattacks are part of Russias playbook.In early 2020, for example, hackers connected to the Russian foreign intelligence service, the SVR, were identified as perpetrators of the massive SolarWinds cyberattack. The Russians were able to penetrate several US federal agencies, including the Treasury, Justice and Energy departments, the Pentagon, and even the Cybersecurity and Infrastructure Security Agency (CISA). Experts estimated that the hackers had been roaming undetected in these networksas well as those of several large private US companiesfor at least nine months. The SVR was gathering intelligence or laying the groundwork for future attacks, or both.We know that Russias ability to disrupt US networks and steal sensitive data is only getting more powerful. If your organization does work for the Department of Defense (DoD), theres no question that the Controlled Unclassified Information (CUI) youre responsible for is a target too. Thats as true for prime contractors as it is for smaller suppliers far down the supply chain. In fact, DoD officials have noted that supply chain vulnerabilities are most prevalent six or seven levels down from prime contractors. Simply put, cybercriminals know that prime defense contractors are well protected, and save themselves time and effort by going after their subcontractors.Moreover, Russia isnt the only state actor conducting sophisticated cyberattacks against US targets. China, Iran, North Korea and others are in the arena too.
It comes as no surprise that the Biden administration is focused on strengthening US cyber defenses. In a May 2021 Executive Order, Improving our Nations Cybersecurity, President Biden called for the Federal Government to implement security best practices and to quickly lay out specific plans toward adopting Zero Trust architecture.The National Security Agency (NSA) describes Zero Trust as a security model that eliminates trust in any one element, node, or service and assumes that a breach is inevitable or likely has already occurred, so it constantly limits access to only what is needed and looks for anomalous or malicious activity.
Zero Trust is a security model that eliminates trust in any one element, node, or service and assumes that a breach is inevitable or likely has already occurred, so it constantly limits access to only what is needed and looks for anomalous or malicious activity.
This is in contrast to, as the NSA explains: Traditional perimeter-based network defenses with multiple layers of disjointed security technologies [that] have proven themselves to be unable to meet the cybersecurity needs due to the current threat environment.Zero Trusts greatest advantage lies in its integrated, system-wide, security-first approach. When securing your organizations data is paramount, compliance with federal regulations designed to protect CUIincluding DFARS, NIST and CMMCis less complex and far more readily achievable.
The DoD is intent on upgrading cybersecurity throughout the DIB via key regulatory frameworks that your organization needs to abide by. These include NIST SP 800-171, developed by the National Institute of Technology and Standards (NIST) specifically to protect CUI, and the Cybersecurity Maturity Model Certification (CMMC) framework, among others.While neither NIST nor CMMC mandate a Zero Trust security model, the good news is that properly designed Zero Trust systems meet DoD mandates for securing CUI exceptionally well.In fact the State Department has led the way in incorporating Zero Trust principles into compliance frameworks. Its 2020 revisions to International Traffic in Arms Regulations (ITAR) allow contractors to simplify their ITAR compliance by taking advantage of technological advances that implement Zero Trust and enable the secure exchange of defense-related technical data in the cloud. Specifically:
The elegance of the new ITAR regulation lies in the fact that defense contractors have a simple and clear two-point compliance mandate to follow, and the mandates Zero Trust principles deliver some of the highest levels of data security possible. Furthermore, modern cloud based Zero Trust systems are often simpler and less expensive for companies to adopt, and so the ITAR regulation accomplishes key objectives of both security and rapid adoption particularly well.
The ITAR regulation offers a compelling model for significantly greater adoption of Zero Trust. Nearly 80,000 defense contractors that handle CUI vital to national security are currently embarking on significant security upgrades to comply with the DoDs CMMC 2.0 and NIST SP 800-171 requirements. CMMC 2.0 and NIST SP 800-171 are closely alignedboth require contractors to meet the same 110 security controls specified in NIST SP 800-171.Contractors that handle CUI have been required to comply with NIST SP 800-171 as part of their DFARS contract obligations since 2017, and to report those scores to the DoDs Supplier Performance Risk System (SPRS) since 2020. Under CMMC 2.0, they will have to demonstrate compliance via third party audits. Similar to ITAR, the NIST SP 800-171 and CMMC regulations can be particularly well addressed by the use of Zero Trust systems based on end-to-end encryption. That means we have a timely opportunity now to significantly expand adoption of Zero Trust security.PreVeil is an example of a communications platform grounded in Zero Trust architecture. Its end-to-end encryption is FIPS 140-2 validated. And it meets all applicable standards for cloud systems used to handle ITAR or CUI: PreVeil is FedRAMP Baseline Moderate Equivalent, and stores all ITAR and CUI encrypted data on the Amazon Web Services (AWS) Gov Cloud, which is assessed at FedRAMP High. Neither PreVeil nor Amazon have access to keys, network access codes, or passwords to decrypt your data, ever.PreVeils Zero Trust platform supports 84 of NIST SP 800-171s 110 security controls. Its easily deployed as an overlay to environments such as Microsoft O365 Commercial Email and One Drive or Google Workspace. Thats done without business disruption or the need to rip and replace existing servers, which makes it affordable. A defense contractor using PreVeil to protect CUI recently achieved a 110/110 NIST SP 800-171 score in a rigorous DoD audit, convincingly demonstrating that Zero Trust security seamlessly leads to achieving compliance. And that, in turn, will help your organization meet Pres. Bidens call to action to defend our nations CUI against the very real threats of nation-state backed cyberattacks.
To learn more:
Read PreVeils briefs:
The post Nation-state Cyber Attackers aiming at the US Defense Industrial Base appeared first on PreVeil.
*** This is a Security Bloggers Network syndicated blog from Blog Archive - PreVeil authored by Orlee Berlove. Read the original post at: https://www.preveil.com/blog/nation-state-cyber-attackers-aiming-at-the-us-defense-industrial-base/
Read more:
Nation-state Cyber Attackers aiming at the US Defense Industrial Base - Security Boulevard
- WikiLeaks' Julian Assange: NSA critics got lucky because agency had no PR strategy [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- National Speakers Association New Jersey Chapter NSA [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- National Security Agency - Wikipedia, the free encyclopedia [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- NSA - Satu Hari Di Bulan Juni (TULUS) (COVER) - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Hong Kong: Protesters blow whistles for NSA whistle blower - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- An Inside Look at the NSA With Whistleblower William Binney (Part 2 of 2) - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- UK: China will offer fig leaves to US exposed by NSA leaker - Assange - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- NSA ~ (Autodidactism) Whistleblowing - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Dropping #NSA Knowledge Like a Clumsy Librarian - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Full Show: Disband The NSA or; Corruption in the Capitol FO SHIZZLE {aTV002} - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- NSA DOCUMENTARY SIX YEARS BEFORE SNOWDEN - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- ShmooCon 2014: The NSA: Capabilities and Countermeasures - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- NSA Knew Of Heartbleed Bug, Refused To Protect Americans - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Former NSA Head To Become Columnist For Conservative Paper To Discuss Intelligence - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- An Inside Look at the NSA With Whistleblower William Binney (Part 1 of 2) - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Keynote Address by Shri Shivshankar Menon, NSA at International Seminar on Kautilya - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- NSA Wiretapping: A 4th Amendment Violation?: Blake Norvell at TEDxSMU - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Hang with Rand: Email Privacy, NSA Spying, and Defending Our Civil Liberties - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- NSA Surveillance and What To Do About It - Bruce Schneier - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- READER SUBMITTED: NSA CT April 2014 Meeting [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- MVI 1847 Obama's NSA Denies FOIA About MH 370! - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- George Galloway's Sputnik: Ewen MacAskill on Guardian / Edward Snowden NSA leaks (26Apr14) - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- CIA & NSA DIRECTED ENERGY WEAPON ATTACK ON WHISTLE BLOWER - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Book TV - 2014 San Antonio Book Festival: Panel on the NSA, Big Brother, and Democracy - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- NSA Throwdown: John Oliver v. 60 Minutes [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- NSA will sit on security vulnerabilities because of terrorism [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- New water records show NSA Utah Data Center likely behind schedule [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- MVI 1871 NSA Might Be OnTo Me! - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- ZyXEL NSA 325 v2 Hands On - Deutsch / German notebooksbilliger.de - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- German opposition says US should destroy Merkel's NSA file - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Germany: NSA spying "unacceptable" says SPD - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- NSA Surveillance 2 - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- NSA Surveillance Panel 1 - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Chalk Talk How Snowden Breached NSA Security - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- NSA reveals some cyber security flaws are left secret [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- NSA data center uses less water than expected [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- April 2014 Breaking News Do you use Google or Yahoo? NSA Intercepts Google And Yahoo Traffic - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Supreme Court could weigh in on NSA case, justice says [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- New NSA chief: Agency has lost trust [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- NSA on Heartbleed: 'We're not legally allowed to lie to you' [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- What's The NSA Doing Now? Training More Cyberwarriors [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Anonymous NSA - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Cutting off H2O to the NSA - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Brazil: Greenwald slams US media, shares tips to avoid NSA - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- NSA IS TRYINGG 2 KILL ME FAMS - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- What was more popular on Twitter, NSA, NRA or NBA..today? - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- CIS111: NSA Uncovered - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Views from the Street on NSA Activities and Liberty (6/6) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Views from the Street on NSA Activities and Liberty (4/6) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Views from the Street on NSA Activities and Liberty (3/6) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Views from the Street on NSA Activities and Liberty (2/6) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Views from the Street on NSA Activities and Liberty (1/6) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Germany: NSA may have accidentally outed secret base - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- ZyXEL NSA 325 v2 Installations-Wizard - Deutsch / German notebooksbilliger.de - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Tech firms to increase alerts about police requests for data -- report [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- German Chancellor Angela Merkel visits US, after the NSA eavesdropping scandal - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- NSA spies on more US citizens than Russians Snowden [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- THE NEXT NSA?Police under scrutiny for using spying technology [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Ukraine and NSA will test Merkel - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- The Latest Attacks On NSA Whistleblower Edward Snowden - Kevin Gosztola Discusses - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Still Report #246 - NSA Classifies MH370 Material - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Code Talker Induction into NSA Hall of Honor - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- NSA ( National Security Agency ) refusal to release documents on UFO's - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Obama & NSA Refuse FOIA Request on Malaysia Flight deemed classified - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Kafkawinstons World`s Channel Terminated NSA is replacing Channel`s with Sockpuppet Channel`s - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- NSA Volunteer Justin Hall at the NSA Comedy Tour February 2014 - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Barack Obama on NSA Surveillance I'd Be Concerned Too If I Wasn't in Government - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- GBPPR Vision #26: Overview of the NSA's TAWDRYYARD Radar Retro-Reflector - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- NSA proof phone Case - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- 2014 NSA 2014 Million Dollar Publisher's Lab - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Gen. Michael Hayden - the Former Director of NSA and the CIA - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- REVEALED: Here's The Solution To That Encoded NSA Puzzle Tweet [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Michael Hayden's Unwitting Case Against Secret Surveillance [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- NSA's Encrypted Tweet: We're Hiring Code Breakers [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Russ Tice: Life as a NSA Whistleblower - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- What Is Going on at NSA These Days - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- What is the Role of the NSA? AFF Dallas Debates - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Edward Snowden said CIA , and NSA had 52. 6 Billion for black budget - Video [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- NSA looks to appeal to young cryptographers through coded ads [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- Code Cracked: Mysterious NSA Tweet Is Decrypted in Seconds [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]