Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security United States

Biden To Expand National Security Agency Role in Government Cybersecurity (wsj.com) 18

President Biden on Wednesday expanded the National Security Agency's role in protecting the U.S. government's most sensitive computer networks, issuing a directive intended to bolster cybersecurity within the Defense Department and intelligence agencies. From a report: The memorandum signed by Mr. Biden mandates baseline cybersecurity practices and standards, such as two-factor authentication and use of encryption, for so-called national security systems, which include the Defense Department and intelligence agencies and the federal contractors that support them. It effectively aligns the cybersecurity standards imposed on national security agencies with those previously established for civilian agencies under an executive order Mr. Biden signed last May. Affected agencies will soon be expected to implement various cybersecurity protocols, including use of certain cloud technologies and software that can detect security problems on a network. Cybersecurity failures have plagued the U.S. government for decades, including thefts of detailed personnel records and military secrets that have been blamed on Russia, China and other adversaries. While national security agencies are generally seen as more secure than their civilian counterparts, they have endured significant breaches, too.
This discussion has been archived. No new comments can be posted.

Biden To Expand National Security Agency Role in Government Cybersecurity

Comments Filter:
  • Have fun shimming MFA into that 1970s era mainframe code lol
    • The NSA is where most of the government sysadmins and programmers work, they have numerous large buildings full of the "best and brightest" whose current work almost entirely consists of filling databases full of information that would only be used in case of a major war.

      They're definitely not the "1970s mainframe" department.

      It's about time they're being assigned some useful tasks.

  • Such a nebulous term that has no firm definition or meaning. It can't mean classified systems since those are already much more secure than any of the requirements in this EO.

    • by Oarsman ( 87375 ) on Wednesday January 19, 2022 @02:20PM (#62188605)

      You mean this?

      What are National Security Systems?

      National security systems are information systems operated by the U.S. Government, its contractors, or agents that contain classified information or that:
      * involve intelligence activities;
      * involve cryptographic activities related to national security;
      * involve command and control of military forces;
      * involve equipment that is an integral part of a weapon or weapons system(s); or
      * are critical to the direct fulfillment of military or intelligence missions (not including routine administrative and business applications).

      The definition for a National Security System, along with other applicable terms used in the National Security Community, are found in CNSSI 4009, "Information Assurance Glossary"

      https://en.wikipedia.org/wiki/... [wikipedia.org]

      https://www.cnss.gov/CNSS/abou... [cnss.gov]

    • The NSA will collect more data on you. Leaking data is another agency's responsibility.
    • by hey! ( 33014 )

      Just the same. Cybersecurity doesn't do much to stop leaks, because leaks are *intentional* disclosures of information by people who have valid access to it.

      Every administration complains about leaks, but no administration does much about them because often it's the very top of the administration that's doing the leaking. They leak to make things public without being seen publicly acknowledging them. They leak to float policy ideas they can walk back if the public freaks out. Sometimes it's the internal p

  • Obviously won't solve all problems, but it is good to see a president actually take cybersecurity seriously. Use 2FA, continuously update all the software and infrastructure, have active breach monitoring in place.

  • If a system is already on an internet-connected network, then additional cloud-based intrusion, threat, and anomaly detection makes sense. This may be counterintuitive, but it is becoming necessary.

    Intrusion and threat detection both get better as more resources are spent on investigating and classifying anomalies, so it makes sense to collaborate or outsource. As long as the service provider has adequate resources, it's a decent approach.

    Having your own massive department of experts could be better, but it

  • The NSA was originally tasked with securing secret information. It was later that they started spying on everyone. Who knows when they became more concerned with circumventing data security than with promoting it?

Pascal is not a high-level language. -- Steven Feiner

Working...