Cybersecurity takes a big hit in new Trump executive order

Date:

Share:

[ad_1]

Cybersecurity takes a big hit in new Trump executive order

The departments of Commerce, Treasury, Homeland Security and the National Institutes of Health were all compromised. A large roster of private companies—among them Microsoft, Intel, Cisco, Deloitte, FireEye, and CrowdStrike—were also breached.

In response, a Biden EO required the Cybersecurity and Infrastructure Security Agency to establish a “common form” for self-attestation that organizations selling critical software to the federal government were complying with the provisions in the SSDF. The attestation had come from a company officer.

Trump’s EO removes that requirement and instead directs National Institute for Standards and Technology (NIST) to create a reference security implementation for the SSDF with no further attestation requirement. The new implementation will supplant SP 800-218, the government’s existing SSDF reference implementation, although the Trump EO calls for the new guidelines to be informed by it.

Critics said the change will allow government contractors to skirt directives that would require them to proactively fix the types of security vulnerabilities that enabled the SolarWinds compromise.

“That will allow folks to checkbox their way through ‘we copied the implementation’ without actually following the spirit of the security controls in SP 800-218,” Jake Williams, a former hacker for the National Security Agency who is now VP of research and development for cybersecurity firm Hunter Strategy, said in an interview. “Very few organizations actually comply with the provisions in SP 800-218 because they put some onerous security requirements on development environments, which are usually [like the] Wild West.”

The Trump EO also rolls back requirements that federal agencies adopt products that use encryption schemes that aren’t vulnerable to quantum computer attacks. Biden put these requirements in place in an attempt to jump-start the implementation of new quantum-resistant algorithms under development by NIST.

[ad_2]

Source link

━ more like this

Sends shares Q1 2026 business update and product progress

Sends reported Q1 2026 updates sharing news on digital cards, app redesign, ClearBank integration, and fintech industry recognition. Sends, a fintech platform operated by Smartflow...

We swipe our phones all day, and scientists just ranked which ones are the most tiring

We all know staring at your phone for hours isn’t great for mental health. But what about your fingers? Previously, researchers couldn’t measure...

Two suspects have been arrested for allegedly shooting at Sam Altman’s house

OpenAI CEO Sam Altman's house may have been the target of a second attack after San Francisco Police Department arrested two suspects for...

You Can Soon Buy a $4,370 Humanoid Robot on AliExpress

Listing consumer electronics on the internet's large ecommerce marketplaces is a key step in “democratizing” the products, allowing them to be purchased by...
spot_img