❌

Reading view

There are new articles available, click to refresh the page.

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.

The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.

The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses. 

The IG took a look at the Secure Cloud Business Applications (SCuBA) project, created in response to the 2022 SolarWinds attack. It provides secure configuration baselines, settings and assessment tools to help agencies reduce the risk of breaches.

A December 2024 directive gave agencies a list of requirements to align with SCuBA, with a deadline of June 2025.

The IG found that 88 of 102 agencies, or 86%, didn’t implement all the mandatory SCuBA policies from BOD 25-01. As of February of this year, “compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76%) [Federal Civilian Executive Branch] agencies were still not in compliance with implementing all mandatory SCuBA policies.”

“Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information,” the IG report states. “Implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications.”

That’s the result of CISA’s lack of power to enforce its BODs, which translates into greater risk, the IG concluded.

“Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened,” the report states. “When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”

CISA didn’t respond to the report, according to the IG. 

The agency didn’t immediately respond to a request for comment from CyberScoop.

The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop.

Dems seek top-to-bottom assessment of CISA workforce

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said Tuesday.

“We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation program at CISA. “The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow.”

That means pushing responsible automation of tasks that also can do so at scale, he said, so that experts “can focus more [on] dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day.”

Velocity is one of the three core goals for the CDM program, along with unification and data-driven risk management, Grabowski said at the Elastic Federal Cyber Defense Breakfast, produced by FedScoop.

Unification means keeping data out of silos so “we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned,” Grabowski said. And data-driven risk management means that in the event of a crisis-level event, agencies are able to “see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan.”

One of CDM’s offerings is Security Information and Event Management (SIEM) as a Service, a cloud-based platform for threat analytics, incident response and more. Grabowski said there’s a three-year roadmap for expanding and enhancing it, including by ramping up staff and conducting training.

Mike Duffy, the acting federal chief information security officer, said at the same event that three principles should guide what comes next for CDM. One is aggregating demand across agencies that share common problems: “When agencies need the same capabilities, we should use federal scale to improve security, interoperability and value.”

Second, he said, “is buying outcomes, not product” by making it clear what outcomes the federal government is seeking and then allowing commercial markets room to innovate. 

Duffy said the third was to “design acquisition for continuous improvement,” meaning making sure that acquisition models promote competition and opportunities for new capabilities to enter.

“Now is not the time to set capabilities and move on for the next 10 years,” he said. “Mow that agile mindset of how we can continue to deliver and deploy capabilities based on the threats we’re seeing to reduce risk at scale across the federal government — that is absolutely key.”

CDM has been evolving since the SolarWinds breach that compromised at least nine federal agencies, said Matt House, CISA’s acting associate director and program manager for CDM.

“Post-SolarWinds, one of the things that that the government took away was, we lack what I would say is a common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide,” House said at the event.

The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets — one in the government sector and the other in the water sector — red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither.

CISA published the breakdown Tuesday in a rare public report on its red-team activities, at a time when attacks on the water sector have a higher profile after revelations of targeting of water facilities across the United States over the past month and numerous government warnings.

The agency didn’t name the organizations it tested through a process that is voluntary and by-request.

“In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,” CISA’s analysis reads. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.”

For “Organization A,” the government organization, CISA used an internal email address to send phishing emails to gain access to the workstations, probed further to gain elevated privileges, then moved around and compromised targeted sensitive business systems. The red teamers observed that the organization “did not respond effectively to red team activity” by accessing personnel emails at its security operations center, where they saw them receive low- and medium-severity endpoint detection and response alerts, but didn’t respond to them.

False positives by the thousands, including some with higher severity, “obscured the alerts triggered by red team activity,” CISA said. The agency also faulted “organizational silos.”

Meanwhile, at “Organization B,” the water organization, CISA got access via a spearphishing campaign, convincing three users to click on a malicious link to gain access to workstations. This time, the security operations center triaged the alerts and quarantined the work stations in 2, 10 and 20 minutes, respectively.

The red teamers tried another approach with the help of the organization’s IT contacts who were aware of the activity, but were foiled in their follow-ups.

“Because Organization B detected the initial compromise, the red team moved to an ‘assume breach’ model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity,” CISA wrote. “From there, the red team escalated privileges and moved laterally to [sensitive business systems], cloud resources, and a bastion host in the OT [operational technology] demilitarized zone (DMZ), where defenders again detected activity and isolated the system.”

Still, CISA said both organizations had flaws in their defenses: They underestimated cloud risks; they lacked Conditional Access — a Microsoft security tool — for workload identities; and they didn’t have processes in place to revoke compromised access/refresh tokens.

CISA first published an advisory on its red team activity in 2023, but such advisories have been few and far between since. The agency said last year that it had not “laid off” its red team, after stories revealed the exit of contractors that included red-team members.

The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

CISA issues recommendations to federal agencies on open-source software security

The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.

An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).

“As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.” 

The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.

“All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”

The guidance says that agencies need to take steps to evaluate the trustworthiness of an OSS project before approving an OSS component for use, and track OSS in their asset management repositories. It details how agencies should deal with patching, including when there’s a new OSS vulnerability that doesn’t have one. It offers advice on how agencies might contribute to OSS projects, produce them and secure rights for government reuse of code when contracting for custom software development. And it explains how it should approach open-weight AI models.

“Agencies should approach ‘open source’ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software,” the guidance states.

Æva Black, an open-source security expert and former OSS lead at CISA, said she applauded her former agency for the guidance, telling CyberScoop that it “demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment.” 

She singled out its recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks.

“Due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis,” she said. “Many proprietary software vendors are using this as an opportunity to spread ‘fear, uncertainty, and doubt’ about open source in order to capture public attention, and, I presume, public money — but when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure.” 

CISA has produced a bevy of security guidance and updated advisory materials this week: on the creation of software bills of materials written in conjunction with other agencies and allied governments that won praise from experts; on the isolation of vital operational technology during a crisis, also written with other agencies and allied governments; and the release of updated secure cloud configuration baselines for Google Workspace.

The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.

❌