Biden orders federal cyber upgrade after barrage of hacks

· Politico ·

3 min read Original article ↗

And it sets the stage for requiring federal contractors to report data breaches and meet new software security standards.

The directive, which sets deadlines for more than 50 different actions and reports, represents a wide-ranging attempt by the new Biden administration to close glaring cybersecurity gaps that it discovered upon taking office and prevent a repeat of Moscow’s SolarWinds espionage operation, which breached nine federal agencies and roughly 100 companies.

“Today’s executive order makes a down-payment towards modernizing our cyber defenses and safeguarding many of the services on which we rely,” a senior administration official told reporters. “It reflects a fundamental shift in our mindset from incident response to prevention, from talking about security to doing security.”

New requirements for agencies

Many of the executive order’s provisions focus on hardening federal computer networks against the most common types of cyberattacks. In addition to requiring agencies to deploy multi-factor authentication, the order requires them to install endpoint detection and response software, which generates warnings when it detects possible hacks. It also calls for agencies to redesign their networks using a philosophy known as zero-trust architecture, which assumes that hackers are inside a network and focuses on preventing them from jumping from one computer to another.

The order also launches a modernization of FedRAMP, the government’s marketplace for cloud computing services such as Amazon Web Services, to better incorporate security requirements. And it calls for the creation of a new federal cloud security strategy, along with guidance for how agencies can safely move data to the cloud.

Seeing the whole picture

Biden’s order attempts to rectify serious shortcomings in the government’s ability to spot cyberattacks before they become full-blown crises.

It orders the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency to review the agreements that it signs with other agencies when it deploys monitoring software on their networks to ensure that it can access their security data when necessary.

The order also requires CISA to report on its use of authority that it received in the fiscal 2021 defense policy bill to hunt for threats on other agencies’ networks without their prior approval.

Officials say current federal monitoring programs are outdated — they can only spot previously identified malware, and they can’t protect increasingly pervasive cloud platforms.

This poor visibility is a major hindrance. “If you can’t see a network, you can’t defend a network,” Anne Neuberger, the deputy national security adviser for cyber and emerging technology, said during a Feb. 17 White House press briefing.