Federal panel says agencies need to focus on harmonizing cyber regulations

Federal panel says agencies need to focus on harmonizing cyber regulations

Comment

Welcome to The Cybersecurity 202! Why am I obsessed with eating mass-manufactured cherry pies and orange cupcakes of late? (I won’t name the brand.) It’s unhealthy and I get grossed out right after doing it, then, bam, next day, I’m ready for more of them.

Reading this online? Sign up for The Cybersecurity 202 to get scoops and sharp analysis in your inbox each morning.

Below: The Defense Department says it secured a previously exposed server that leaked sensitive military emails, and gaming giant Activision falls victim to a phishing scheme. First: 

An advisory committee recommended the creation of an office to deconflict cyber rules

The Biden administration needs to take numerous steps to deconflict and organize the proliferation of cybersecurity regulations, according to a report that a presidential advisory committee approved Tuesday.

That includes things like creating an office within the Cybersecurity and Infrastructure Security Agency to harmonize cybersecurity rules across the federal government, or directing a trio of federal agencies to coordinate with foreign governments to develop consensus cybersecurity standards.

The recommendations arrive as the U.S. cyber scene awaits publication of the Biden administration’s national cybersecurity strategy, the White House pushes for mandates on numerous industries, and CISA writes a rule to require critical infrastructure owners and operators to report major cyber incidents to the agency.

The advisory panel, named the National Security Telecommunications Advisory Committee (NSTAC), voted Tuesday to send the report to Biden for his consideration.

The committee draws its membership from the business community, with a heavy emphasis on cybersecurity companies. Many industry groups have indicated opposition to the Biden administration pushing a more muscular federal role for cyber mandates.

But an official with the Office of the National Cyber Director, which led the writing of the national cybersecurity strategy, saw overlap between that strategy and the NSTAC report.

“The recommendations regarding regulatory harmonization align very well with the strategic goals of the strategy,” said Rob Knake, the acting principal deputy at the cyber director’s office.

One such recommendation is for CISA to establish an Office of Cybersecurity Regulatory Harmonization. There are already some federal initiatives with a similar mission, such as the Cyber Incident Reporting Council, and the Cybersecurity Forum for Independent and Executive Branch Regulators. But the new office would have the job of building expertise on cybersecurity regulation and assisting other federal agencies during the cybersecurity rulemaking process.

The report recommended housing the office in CISA for a few reasons, as incoming NSTAC chair Scott Charney, vice president for security policy at Microsoft, explained:

  • “The primary advantage of housing this effort in CISA is that most other departments, such as Treasury or [Health and Human Services], are primarily concerned” with the industries they regulate, Charney said. “By contrast, CISA’s focus on protecting critical infrastructures gives it a broader, cross-vertical perspective.”
  • “The proposed office would act in an advisory capacity to other regulators,” Charney said, “which is consistent with CISA’s existing interactions with regulators.”
  • Furthermore, he said, CISA’s parent agency, the Department of Homeland Security, is home to the aforementioned Cyber Incident Reporting Council. That council was formed as part of legislation Congress passed last year that directed CISA to write a rule requiring critical infrastructure owners and operators to report major cyberattacks within 72 hours.

Agencies writing cyber rules would have to report how their regulations align with the new office’s guidelines. 

Separate from the recommendations about the new office and how agencies would interact with it, the report calls on agencies to review their rules at least every five years and update them as needed. 

And “the Department of State and Department of Commerce, in coordination with the Department of Homeland Security, shall develop and execute a strategy to encourage more foreign government participation in the development and adoption of specific consensus standards,” the report states.

Recommendations that aren’t about harmonization

The report isn’t only about harmonizing regulations.

Among its other recommendations:

  • CISA and the General Services Administration should “draft core, universally applicable procurement language that clearly defines the government’s requirements and preferences” on secure software and services.
  • CISA should expand and enhance a federal program focused on scanning and monitoring services to help federal agencies better protect their networks.
  • CISA and the National Institute of Standards and Technology should form a partnership “focusing on transition to post quantum cryptography” — in other words, making computers safe against quantum computers that could break current encryption.

Private U.S. military emails were exposed online

The Defense Department on Monday afternoon said it secured a server that was left online without a password for two weeks, exposing internal military emails to anyone on the internet, TechCrunch’s Zack Whittaker reports.

The server, which was left without a password due to a misconfiguration, was hosted on Microsoft’s Azure government cloud for Defense Department customers. That platform is typically used to share sensitive but unclassified government data, but in this case it stored about three terabytes of internal military emails, including those related to the U.S. Special Operations Command. 

Anurag Sen, a security researcher who discovered the breach, said the exposed server contained military emails dating back years, with at least one file in particular including a completed SF-86 questionnaire full of highly sensitive personal and health information. 

The server is now inaccessible. U.S. Special Operations Command spokesperson Ken McGraw said in an email to TechCrunch on Tuesday that an investigation into the leak began Monday and is still underway.

“We can confirm at this point is no one hacked U.S. Special Operations Command’s information systems,” McGraw said. It’s not clear if anyone besides Sen found the server during the two weeks that it was exposed.

Supreme Court knocks down Wikipedia operator’s bid to challenge NSA oversight

The Supreme Court on Tuesday denied a request from the operator of Wikipedia to reopen a lawsuit against the National Security Agency challenging broad internet surveillance, Reuters’s Andrew Chung reports.

In 2015, the Wikimedia Foundation, represented by the American Civil Liberties Union, sought to confront the legality of NSA’s “upstream” program used to surveil foreign targets through the collection and searching of internet traffic on data transmission lines flowing into and out of the United States. The lawsuit alleges that the practice violates Americans’ right to privacy and freedom of speech.

The NSA has defended the surveillance by pointing to the Foreign Intelligence Surveillance Act of 2008. Its existence was leaked in 2013 by former NSA contractor Edward Snowden, who later fled to Russia. 

Tuesday’s decision upholds a lower court’s previous dismissal of the lawsuit because of the state secrets privilege, or a legal doctrine that can shut down litigation if disclosure of certain information, like details about the surveillance, would damage national security. 

Hacker gains access to Activision Slack, steals Call of Duty info

A hacker was able to breach a Slack channel of the game publishing giant Activision after convincing an employee to give them a two-factor authentication token, Motherboard’s Joseph Cox reports.

After the breach, the bad actor posted offensive messages from the targeted staff account and apparently stole information related to upcoming Call of Duty release dates, according to screenshots posted online by the cybersecurity collective vx-underground. 

Activision told Motherboard in a statement: “The security of our data is paramount, and we have comprehensive information security protocols in place to ensure its confidentiality. On Dec. 4, 2022, our information security team swiftly addressed an SMS phishing attempt and quickly resolved it.”

“Following a thorough investigation, we determined that no sensitive employee data, game code, or player data was accessed,” the statement added. Activision did not respond when asked specifically by Motherboard about the data that the hacker seemingly did access, such as the Call of Duty scheduling. 

The attack comes as the gaming sector is increasingly facing cyberthreats, with the industry seeing a 167 percent increase in web application attacks in 2021, and last year becoming the most targeted industry for distributed denial of service (DDoS) attacks. Last month, hackers broke into Riot Games, another gaming giant. In 2021, hackers breached Electronic Arts and CD Projekt.

White House mulls scaling up Login-dot-gov to reach every American (Federal Computer Week)

House Dems call for info on racially-motivated cyberattacks (NextGov)

Tor Project moves away from infrastructure ran by internet monitoring firm (Motherboard)

Hackers extort less money, are laid off as new tactics thwart more ransomware attacks (Wall Street Journal)

Ukraine’s volunteer cyber army could be model for other nations, experts say (Newsweek)

Hackers scored corporate giants’ logins for Asian data centers (Bloomberg News)

Civil liberties groups call for EU-wide ban on spyware (The Record)

Ukraine’s largest charity wants to raise $1.3 million for ‘cyber offensive’ (The Record)

  • The Atlantic Council holds a discussion with the authors of two new reports on Russian narratives to justify the war in Ukraine today at 9 a.m. 
  • The R Street Institute holds a webinar on the state of cybersecurity careers for Black professionals on Thursday at noon.
  • Former U.S. national security adviser John Bolton will join The Washington Post for a conversation about the war in Ukraine and rising tensions with China on Friday at 11 a.m. 

Thanks for reading. See you tomorrow.

A Century of Technological Evolution at the Federal Trade Commission

A Century of Technological Evolution at the Federal Trade Commission

I am honored to announce the generation of the Office of Technology (OT) at the Federal Trade Fee, a team that will provide technological know-how throughout agency matters and improve the agency’s ability to implement the nation’s level of competition and buyer defense rules. We are hiring technologists to be a part of the group.

Remaining on the slicing edge of emerging know-how has lengthy been a main part of the FTC’s mandate. The emergence of the radio in the 1920s is an in particular vivid illustration. The radio was starting to be ubiquitous in American living rooms, developing drastically new possibilities for enjoyment and details. At the similar time, this new product provided a potent new vector for bogus promoting. Amidst an influenza pandemic, Vit-O-Net claimed its heating pad induced magnetic discipline that could supply a treatment for rheumatism and a wide variety of other bodily ills. Fairyfoot Enterprise promised an adhesive plaster pad that could instantaneously dissolve bunion ache to accomplish bunion-cost-free toes.

A Century of Technological Evolution at the Federal Trade Commission

Image Resource

Advertisements like these turned so problematic and prevalent in the 1930s that the reasonably new Federal Trade Fee, a short while ago empowered by Congress to law enforcement “unfair or misleading acts or tactics,” introduced the Specific Board of Investigation to analyze a enormous quantity of radio transcript data. When the agency acquired grievances about phony or misleading ads, staff would ask for samples of all advertisement copies revealed, together with samples and formulation of the products in concern. Personnel consulted pro federal agencies like the Meals and Drug Administration and the Public Overall health Assistance for scientific and healthcare opinions to detect illegal fraud and abuse. By leveraging these assets and sharpening investigative methods, the company managed to adapt to the rapid improve brought about by radio know-how.

Today’s technological issues are even far more overwhelming than those of the radio era. Continue to, they elevate systemic fears that would have been acquainted to enforcers in the 1930s. The frequent thread is that some technologies can aid sizeable personal injury to customers, are misleading, or may perhaps negatively have an effect on competitive situations. From the rise of the surveillance financial system, to companies’ prevalent application of artificial intelligence, to business enterprise products that use tech to disrupt marketplaces, the shift in the tempo and quantity of technological improvements usually means that a lot more FTC matters will need workforce members with tech skills. To remain on major of developments, we cannot depend entirely on a situation-by-situation strategy to partaking authorities. We need to bolster our in-household capacity to acquire new abilities and strategies to look into and mitigate prevalent customer and industry harms.

In 2023, the OT will better equip the company to tactic present and upcoming tech threats by building a workforce of technologists with deep knowledge throughout a vary of specialized fields, which include information stability, program engineering, details science, electronic markets, synthetic intelligence, equipment understanding, and human-computer system interaction design. This centralized crew will be led by the agency’s Main Know-how Officer and deployed to meet up with interdisciplinary desires throughout the FTC.

The Business of Technology’s top rated priority is to function with employees and management across the company to reinforce and assist the company on enforcement investigations and litigated conditions. This could necessarily mean dissecting statements created about an AI-run merchandise to evaluate no matter if the featuring is oozing with snake oil, or no matter whether automated choice systems for trainer evaluations adversely impression employment choices and make inferences that affect payment and tenure. We will also continue to keep a finger on the pulse of small business product transform, like shifts in electronic promoting ecosystems, to aid the FTC understand the implications on privacy, competitors, and consumer safety. We’re doing the job with attorneys and knowledge scientists to decipher the assortment and sale of locale info and how that information may well harm individuals, and to comprehend the opaque algorithms producing decisions affecting thousands and thousands of consumers. We are tracking emerging technologies like augmented and digital actuality, where immersive environments supply new styles of info and methods to gather, use, and make inferences from it. And we are assisting the agency these kinds of as by demanding providers to put into action multi-element authentication steps that are resistant to phishing or requiring companies to build a facts retention routine, publish it, and then adhere to it.

Further than enforcement matters, we provide as subject subject experts to advise and interact with FTC workers and the Fee on policy and investigate initiatives. Our Place of work of Congressional Relations might have to have to obtain intel for incoming costs or plan investigate, whether or not it’s deciphering the latest applications of blockchain or unpacking unfair style tactics that can induce sizeable actual physical and other accidents to minors by way of characteristics that aim to maximize engagement and info collection. We liaise with our Office environment of Worldwide Affairs to cultivate meaningful relationships with global regulatory units – researching, figuring out, and integrating best practices from other businesses to greatest fit the wants and culture of the Commission.

We will also engage and tell outside authorities and the general public to advance the Commission’s work. Our crew recently offered at an Open up Commission Meeting on the agency’s strategy to systemically deal with information protection dangers, we have engaged in study and tutorial conferences, and we printed blog posts on the Log4j safety vulnerability and powerful breach notification.

As we shift forward, we will carry on to work with Bureau technologists and lawyers who have deep institutional expertise and enforcement knowledge. Today’s milestone is feasible due to the fact of the contributions of qualified technologists and practitioners in the Division of Privacy and Identification Defense, the Office of Technology, Research and Investigation, and the Know-how Enforcement Division who have now demonstrated the worth of technical experience to bolster the FTC’s casework. We glimpse forward to uniting technologist efforts to much better aid and cultivate the get the job done of our group to make and scale most effective procedures and advertise much better interdisciplinary collaboration.

Beyond the FTC, the institution of the Workplace of Engineering is in line with practices of other federal agencies, such as the Shopper Financial Security Bureau, the Securities and Exchange Fee, and the Section of Justice. Legislation enforcement businesses in other countries have also increased tech capability, together with the United Kingdom, Australia, Canada, France, Japan, Korea, Germany, and the Netherlands. This goes further than growing tech ability to construct goods and services. We‘re bringing in sharp technologists to translate elaborate systems, and to do the job with lawyers to enforce the legislation and condition policy issues.

Today’s action marks a considerable commitment to sustaining a framework for technologists in and throughout the FTC. A large amount has changed considering the fact that the radio age, but some points have not. No matter if the underlying technological know-how is a radio or a mobile app or a monitoring pixel, the Commission will keep on to keep technological know-how providers accountable for complying with the customer protection and competition regulations we implement. The Business of Technologies will play a vital position in that work.

We are employing technologists and hope you will aid us distribute the phrase: https://www.ftc.gov/technologists

—–

Thank you to the recent and alumni FTC technologists for their perform in creating these foundations at the agency and my colleagues for examining this piece.

 


1 William Kovacic & Marc Winerman, Outpost Years for a Commence-up Agency: The FTC from 1921-1925, 77 Antitrust L.J. 145 (2010).

Accenture Federal Services Awarded a Position on National Cancer Institute’s IT Services Blanket Purchase Agreement

Accenture Federal Services Awarded a Position on National Cancer Institute’s IT Services Blanket Purchase Agreement

Accenture Federal Services Awarded a Posture on National Cancer Institute’s IT Solutions Blanket Purchase Agreement

 
ARLINGTON, Va Dec. 15, 2022 – Accenture Federal Services (AFS), a subsidiary of Accenture (NYSE: ACN), has been awarded a posture on a software package engineering and IT assistance solutions Blanket Acquire Agreement (BPA) with the Countrywide Cancer Institute (NCI) Information Engineering (IT) Engineering place of work.
 
Specifically, the enterprise will supply a wide range of software package engineering and guidance products and services to NCI buyers and the Institute’s scientific, grants management, and company programs.

Accenture Federal Expert services Handling Director
&#13
and Federal Health and fitness Chief, Jill Olmstead
 

“Accenture Federal Services appears to be forward to improving the National Most cancers Institute’s capacity to continue to keep pace with technology trends, adopt emerging systems, and help transfer innovative suggestions to answer supply and generation,” mentioned Accenture Federal Services Handling Director and Federal Health Chief, Jill Olmstead. “We’re thrilled to help the Countrywide Most cancers Institute with its mission-essential work conducting most cancers research and advancing scientific information to help persons reside more time, more healthy lives.”
 
The BPA is valued at $137 million around a time period of five decades.
 
NCI is 1 of 27 institutes and centers that comprise the Countrywide Institutes of Wellbeing (NIH).
 
About Accenture
Accenture is a world expert services enterprise with leading capabilities in digital, cloud and stability. Combining unmatched encounter and specialized competencies throughout a lot more than 40 industries, we provide Technique and Consulting, Engineering and Operations companies and Accenture Music — all run by the world’s largest community of Highly developed Technologies and Smart Functions centers. Our 721,000 people today provide on the promise of technological innovation and human ingenuity just about every working day, serving clients in additional than 120 countries. We embrace the electricity of alter to make worth and shared achievement for our purchasers, people today, shareholders, companions, and communities. Stop by us at accenture.com.
 
About Accenture Federal Services
Accenture Federal Services, a wholly owned subsidiary of Accenture LLP, is a U.S. company headquartered in Arlington, Virginia. We serve every Cabinet-level section and 30 of the major federal corporations. Accenture Federal Services transforms bold concepts into breakthrough outcomes for customers at protection, nationwide safety, general public protection, civilian and navy wellbeing companies. Take a look at us at accenturefederal.com.
 

# # #

 
 
Get in touch with:

Donna Savarese 
&#13
Accenture 
&#13
+1 301 250 0660
&#13
donna.savarese@accenturefederal.com
&#13
 
&#13
 
&#13
 
&#13
 
&#13
 

 

Federal payroll website for over 170 agencies gets a cybersecurity update

Federal payroll website for over 170 agencies gets a cybersecurity update

Above 170 companies are now looking at a new login system to access federal employees’ payroll info, and other kinds of facts for human assets administration.

The Nationwide Finance Middle, an company housed underneath the Agriculture Office, has introduced a multi-variable authentication technique for its federal consumers to obtain the payroll and staff internet site.

“Our final decision to apply multi-aspect authentication is a best apply that makes it possible for NFC to safe programs by providing a multi-layered method to…

Browse Extra

Above 170 agencies are now looking at a new login procedure to entry federal employees’ payroll information, and other kinds of information for human sources administration.

The National Finance Heart, an company housed under the Agriculture Section, has released a multi-aspect authentication procedure for its federal buyers to obtain the payroll and personnel web site.

“Our conclusion to employ multi-aspect authentication is a greatest practice that allows NFC to protected techniques by providing a multi-layered method to securing user accounts, thus producing the account significantly less likely to make it possible for unauthorized obtain,” a USDA spokesperson mentioned in an electronic mail to Federal Information Network.

The NFC is 1 of the four big federal payroll companies for companies. NFC partners with additional than 170 businesses, and gives payroll products and services to much more than 600,000 federal staff — making it especially significant to protect feds’ economic information and facts with enhanced cybersecurity tactics. Multi-issue authentication demands customers to verify their identification through various techniques, intending block any users who shouldn’t have accessibility to private information.

With the web-site update, the NFC has also come to be a single of many businesses hoping to get techniques to comply with the White House’s federal cybersecurity and zero have confidence in requirements.

“USDA will go on to adhere to and carry out all federal mandates, govt orders and Nationwide Institute of Specifications and Engineering (NIST) steering to ensure the security of all worker and customers’ accounts, facts and details,” the spokesperson mentioned.

Implementing multi-element authentication is just a person part of governmentwide cybersecurity specifications for federal businesses. It’s provided, for occasion, in the Federal Details Security Modernization Act (FISMA), which demands agencies to build a possibility administration framework and be certain specified stability controls. It is also element of cybersecurity direction from NIST, as effectively as the Biden administration’s executive order on enhancing the nation’s stability. Multi-aspect authentication is furthermore a need underneath the White House’s zero have confidence in strategy, which the Biden administration introduced in January of this calendar year.

But there is even now a long way to go to attain governmentwide compliance with the White House’s security specifications. Although the White Property produced its zero trust strategy back again in January, several agencies have considering that then created only minimal development on employing multi-variable authentication. As of now, most businesses have not adopted multi-variable authentication throughout all of their units, even if they are employing it in some locations. Just 13 agencies have fully adopted the practice throughout all of their enterprises.

Some fears over cybersecurity have also arisen together with the increase of remote get the job done and telework for federal workforce, which may possibly open up the doorway to larger possible for cybersecurity hazards.

“The rising reliance on distant function has companies grappling with the challenge of unmanaged individual equipment of staff members staying utilized for function. They normally really don’t have the similar degree of defense that corporation-owned devices do, nor can these equipment be monitored for abnormal or anomalous behavior,” the spokesperson stated.

But multi-element authentication on NFC’s internet site can enable mitigate that sort of danger, according to the spokesperson. It is portion of the motive that the company carried out the adjust in Oct.

And the update to NFC’s internet site is not the only forthcoming adjust for the agency when it arrives to cybersecurity. Alongside with implementing a multi-element authentication system, the company also programs to before long increase endpoint detection and response, application source chain inventory, and asset visibility and vulnerability detection. USDA will also continue on to maintain trainings for workers on the value of guarding personalized information. All of those ideas are also necessities less than the White House’s zero have faith in guidance, as well as the cybersecurity executive get.

Some of these demands from the zero believe in guidance are beginning to get tough deadlines, far too. According to a the latest Workplace of Administration and Spending budget memo, agencies have a 90-working day deadline, setting up from Sept. 14, to inventory all of their 3rd-bash computer software.

In basic, not all kinds of multi-component authentication are similarly safe. Eric Mill, senior advisor to the federal chief information officer, has stated that SMS textual content messages and drive notifications, for occasion, are even now susceptible to phishing attacks. Mill has also said that the changes beneath the White House zero have faith in approach have a a lot more significant intention — and broader implications — than just utilizing a multi-issue authentication method for federal businesses.

“We’re looking at a key architectural change for the federal government. And we know that is a multi-year procedure,” Mill mentioned in January, when the White Home in the beginning produced the zero believe in method. “We’re making an attempt to both equally layout an oversight and timing process that reflects the urgency with which we need to move and the fact of the dimensions of the do the job that is happening.”