NIST revises flagship cyber resiliency guidance
The National Institute of Standards and Technology released the first-ever revision to its flagship cyber resiliency guidance with updated controls and a single threat taxonomy Thursday.
NIST updated Special Publication (SP) 800-160 Vol. 2 to align cyber resilience controls with SP 800-53 Rev. 5 security and privacy controls for agencies’ and industry’s IT systems, as well as map it to MITRE’s ATT&CK threat framework.
A product of the NIST Systems Security Engineering initiative, the guidance reflects the latest cyber resiliency implementation approaches for engineers to address known hacker tactics laid out in the ATT&CK framework.
“The goal of the NIST Systems Security Engineering initiative is to address security, safety and resiliency issues from the perspective of stakeholder requirements and protection needs, using established engineering processes to ensure that those requirements and needs are addressed across the entire system life cycle to develop more trustworthy systems,” reads the revised guidance.
Cyber resiliency engineers design and maintain systems that anticipate, withstand, recover from and adapt to stresses, attacks and compromises — thereby reducing risk to agencies.
The guidance provides a cyber resiliency engineering framework complete with a tailorable analysis agencies can use to determine whether a system of theirs, no matter how old, is at risk of being compromised by advanced persistent threats.
Technical appendices supplement that framework with:
- background and contextual information on cyber resiliency;
- detailed descriptions of goals, objectives, techniques, implementation approaches, and design principles;
- mutually beneficial controls in corresponding the SP 800-53; and
- language used to describe the effects of current threat mitigations.
CISA chief: Risk management agencies key to addressing sector-specific cyberthreats
Cybersecurity and Infrastructure Security Agency Director Jen Easterly has said her agency will work closely with federal risk management agencies to enhance cybersecurity practices within their own sectors such as energy and transportation.
Speaking Thursday at the Black Hat conference in Las Vegas, Easterly underscored the importance of using federal departments’ sector knowledge to help improve cybersecurity standards across every area of society in the U.S. To do so, CISA will step up its close work with departments responsible for managing risks in key areas of U.S. infrastructure, including the Department of Energy, the Environmental Protection Agency, and the Department of Transportation, she said.
“Critical infrastructure owners and operations, as well as state and local governments will play a similar role – bringing expertise to the discussion and a unique ability to drive cyber defense activities in their jurisdictions,” said Easterly.
CISA today announced its new Joint Cyber Defense Collaborative strategy for enhanced information sharing between industry, government and academia. It is hoped the scheme will allow federal agencies, lawmakers and the private sector to react faster and more effectively to ransomware attacks and other digital threats.
The agency has obtained buy-in for the new center from technology giants including CrowdStrike, Palo Alto, FireEye, Amazon Web Services, Google, Microsoft, AT&T, Verizon and Lumen, she said. Through JCDC, the member organizations will take part in two cyber sprints: one to combat ransomware, and the second to develop a planning framework for coordinating incidents that affect cloud providers.
In her keynote speech at the conference, Easterly also called on industry to support the federal government’s focus on rapidly growing the U.S.’s cybersecurity workforce, including through new relationships with universities and colleges and at the K-12 level.
The CISA director also issued a wider call for companies and technology experts to join CISA’s community of information sharing and to become evangelists for cybersecurity within their own organizations.
Logistics a prime target for the Marine Corps’ AI, commandant says
The commandant of the Marine Corps wants the service to focus on logistics as a prime use case for artificial intelligence, he said at the Navy League’s Sea-Air-Space conference.
Gen. David Berger, the Marine Corps’ top officer, said that logistics is both an area of extreme importance in a potential future war and one where AI can be helpful. He told the audience at Sea-Air-Space 2021 he wants industry to bring advanced data analytics tools to the USMC to assist in its modernization.
“Look at an area like logistics…if you assume you need to be capable of operating distributed then logistics [comes] to the foreground,” he said.
Military planners assume a potential war with Russia or China would involve logistics being targeted by adversaries to try and stop the resupplying of troops. Marines on the front lines can’t fight with out the ability to refuel vehicles or get more ammunition, Berger added. Using emerging tech to make more resilient resupplies and harden their infrastructure would go a long way in preparing for any potential war, he said.
“If you think we are going to be able to that in a human mind … that is not going to work,” he said of relying just on humans to manage complex supply chains in a battle.
He said that much of the tech to assist marine logisticians is available today in commercial industry, but not to the corps yet. He added that he wants younger officers to be the ones testing and evaluating new tools form industry since they grew up using tech.
“The tools are there now,” he said.
The Marine Corps is already testing fifth generation telecommunication tech in logistics centers to improve warehouse operations. But the commandant want the corps to expand the use of emerging technology in the delivery of supplies in potential battles, not just on bases.
The USMC also recently started building a new wargaming center that will use AI to test its self against potential adversaries.
NASA could take months to respond to $2.5B IT contract protest — Leidos CEO
NASA might not award its $2.5 billion, next-generation enterprise IT contract again for months following a bid protest Science Applications International Corp., said Leidos CEO Roger Krone, on the company’s earnings call Tuesday.
The agency is taking corrective action over the 10-year Advanced Enterprise Global IT Solutions (AEGIS) contract, which could take until the third or fourth quarter of 2021, Krone said.
SAIC held the NASA Integrated Communications Services (NICS) contract, AEGIS’s predecessor, prior to its split with Leidos and protested its now competitor’s win with the Government Accountability Office on July 6. The new contract adds zero-trust security, data center and cloud computing services and is integral to NASA’s Artemis program aiming to send astronauts to Mars, but now it’s in limbo.
“History has told us NASA takes corrective action, they make another award decision and then, of course, usually that is followed by another protest, and those tend to last kind of 100 days,” Krone said. “And so it may take them another three, four weeks to do their corrective action, and then you tack another three months on the back of that.”
NASA did not respond to a request for comment on the corrective action it’s taking by publication time.
The agency plans to use the contract to move to modern identity and access management through network automation. AEGIS also covers wide area networking, center local area networking, telecommunications, online collaboration tools, cable plant, emergency and early warning notification systems, telephony, and radio systems.
White House nominates Biniam Gebre as chief of federal procurement policy
The Biden administration has nominated Biniam Gebre as the administrator of the Office of Federal Procurement Policy within the Office of Management and Budget.
If confirmed by the Senate, he will rejoin government from Accenture, where he is a senior managing director and head of management consulting for Accenture Federal Services.
The OFPP sets overall policy direction for governmentwide procurement procedures and is focused on promoting efficiency and effectiveness. Previously, it was led by Michael Wooten, who was nominated by former President Donald Trump and confirmed to the role in 2019.
Gebre has previously also worked at consulting firms Mckinsey & Co. and Oliver Wyman. He served in the Obama administration at the Department of Housing and Urban Development, where his work focused on access to credit for low-income families, FHA’s financial health, and revamping public housing.
DOE uses firmware machine learning to bolster electric grid cybersecurity
The Department of Energy is integrating machine learning (ML) with a threat information-sharing tool it developed to find cybersecurity adversaries embedded in electric grid control systems.
DOE‘s Grid Modernization Laboratory Consortium (GMLC) consists of the Idaho, Argonne and Sandia national labs and the National Renewable Energy Laboratory — all working together on the Firmware Command and Control (FC2) project.
Firmware is often vulnerable, permanent software present in industrial control systems and operational technology (OT), and INL partnered with software company Forescout to ensure FC2’s cyber data analytics could detect firmware-centric vulnerabilities with ML.
“Embedded systems are black boxes with little insight on what subcomponents make up the code underneath, preventing protection and potentially rendering the system vulnerable,” said Rita Foster, infrastructure advisor at INL, in commentary. “Emerging machine-learning techniques enable the identification of ubiquitous libraries, which may contain known potential vulnerabilities.”
INL further developed the Structured Threat Intelligence Graph (STIG) for sharing of actionable threat information among grid utilities and OT vendors, who are notoriously stingy with such information. Rather than having threat analysts read thousands of lines of code, STIG visualizes relationships between attack patterns, compromise indicators and exploits and presents mitigations.
FC2, and GMLC more broadly, are helping utilities like Southern California Edison and Detroit Energies — which serve as large, expensive testbeds — augment their grid architectures. Meanwhile OT manufacturer partners like Siemens, Rockwell Automation, Eaton, GE, and Hitachi can develop better cyber protections.
“The need for an analysis tool to share security threat information and intelligence has escalated, and existing tools have proven to be inadequate,” Foster said.
A number of big-name OT manufacturers the government employs — Emerson, Honeywell, Mitsubishi Electric, Rockwell Automation, and Schneider Electric — do business with InterNiche, whose stack was revealed to have 14 newly discovered vulnerabilities Wednesday.
Forescout Research Labs and JFrog Security Research disclosed set, dubbed INFRA:HALT, as part of the former’s Project Memoria. The vulnerabilities allow for remote code execution, denial of service, information leaking, transmission control protocol spoofing, and Domain Name System cache poisoning, which could compromise OT and critical infrastructure like the electric grid.
Forescout’s report recommends utilities limit the network exposure of critical vulnerable devices through network segmentation, apply patches once vendors release them, and block or disable support for unused protocols like HTTP.
The 14 vulnerabilities were discovered using cutting-edge automate binary analysis for large-scale vulnerability finding.
“We believe that the cybersecurity community is at a turning point, and soon automated vulnerability discovery techniques will become more common, which should make finding very large-scale vulnerabilities, such as those affecting TCP/IP stacks, faster and more frequent,” reads the report. “All these vulnerabilities, however, will have to be disclosed, mapped to affected devices and mitigated.”
How precise email analysis reduces healthcare ransomware threats
Ryan Witt is an industries solutions and strategy leader at Proofpoint, specializing in healthcare and cybersecurity. He has over 15 years of experience advising healthcare institutions on the value of robust data protection.
The healthcare industry has come under intensified attacks by malicious actors over the last year amid new opportunities to target institutions during the COVID-19 pandemic.

Ryan Witt, Industry Solutions and Strategy Leader, Proofpoint
Among various cyberthreats the healthcare industry faces, ransomware poses particular risks to the patients these institutions are serving. While the goal of ransomware attacks is to extract a payment, the consequences of holding health organizations’ IT systems hostage puts patient safety and critical care at risk.
Earlier this year, for example, one university medical system which offered important oncology services in their region was victim to a ransomware attack that blocked access to its electronic medical record systems (EMRs). That institution was forced to turn away some oncology patients as a result of not being able to reliably access patients’ records; or in other circumstances, they could offer only skeletal services with staff reduced to recreating patient records on pen and paper.
It took the institution roughly a month to essentially reconstitute their medical records and fully eradicate the ransomware from their system at an untold cost in patient safety and lost productivity. This kind of ransomware attack illustrates a large and growing problem occurring throughout the country, where unseen criminals are holding public and private healthcare organizations hostage.
While many organizations have built up an ecosystem of security tools to monitor network activity and firewalls to block malicious traffic, often their greatest security and compliance risk comes from their employees and business associates who inadvertently fall victim to phishing emails or stolen credential dumps.
Cybercriminals have shifted their focus from targeting technical deficiencies to human vulnerabilities: the busy clinician who clicks on an email attachment; the eager patient who fills in credentials to claim a fake offer; an employee who interacts with emails from their suppliers, not realizing it is an imposter account.
Growing threats against the healthcare sector
The Healthcare Information and Management Systems Society (HIMSS) released a 2020 Cybersecurity Survey in which they concluded that 89% of all cyberattacks, including ransomware attacks, start on email. Cybercriminals today are adapting their techniques to strategically target people within the organization, using social engineering techniques that are designed to trick users into making security mistakes.
Threat actors approach these email-based attacks with same effort, time and resources they used to put in to understanding network vulnerabilities. And there is enough actionable research from Proofpoint that clearly states who is being targeted within the healthcare sector.
For example, if an institution has a clinical research component, it is being attacked to gain access to intellectual property. Employees that deal with supply chain — those who are downloading invoices, paying invoices or approving quotes — are being targeted because they are more prone to click on a malicious link. If the organization deals with controlled substances that have monetizable value on the black market, those employees are at high risk as well.
Proofpoint conservatively analyzes 5 billion-plus emails per day with a significant portion of those being sent to health institutions. Our data shows that up to 90% of emails that are sent to healthcare institutions are being blocked by email filters. The rest is composed of targeted emails which appear to come from a known person or entity. Attackers do their homework, targeting people based on data readily available to them. Caught off guard, an employee may click on something without thinking, leaving the network open to risk.
The resulting ransomware attack may not happen immediately after a compromised credential. Once a cybercriminal gets access to the system, they can take their time gathering information about the organization to navigate their way to a part of the architecture where they can launch their exploits.
Though many security leaders today talk about upcoming security threats, such as medical device vulnerability, the data shows ransomware, phishing and imposter emails still work, and these are low investment and high-return attacks for cybercriminals. Certainly, medical devices have very valid weaknesses, but we do not anticipate a significant shift in how criminals invest in attacks until the email-based attacks become less profitable.
The good news is that healthcare organizations don’t have to wait for tools to be developed to address this problem. Modern security platforms, like Proofpoint’s, give security leaders the insights they need to make strategic investments that protect the organization’s people.
Building a security strategy informed by data
At Proofpoint, we believe that if organizations can see the data behind who is being attacked, they can better anticipate and mitigate the risks on their threat landscape. A people-centric security approach provides institutions with the ability to apply risk-based controls based who is being targeted and why they are being targeted.
We understand the value of protecting people. With Proofpoint’s research, tools, capabilities and technology, we give organizations the means to keep the bare minimum of exploits away from their targets.
If an organization has 50,000 email addresses, for example, and only 10% or those are being significantly targeted, it wouldn’t be appropriate or cost effective to set up the gold standard of security tools against all 50,000 email addresses. Instead of treating everyone the same, the institution can apply adaptive controls on those people who are most at risk.
Our Targeted Attack Protection solution provides visibility to an organization’s “Very Attacked People” (VAP), which allows the institution to identify which job functions are under attack and why. Once that is known, the organization can decide which adaptive controls should be used to offer enhanced protection such as fine tuning their sandboxing so that any emails that come to those individuals can be directed into a sandbox for further analysis.
They can also place certain exchanges in an isolated environment, so that whole email interchange exists within a container to prevent seepage onto the enterprise network. All of the activity exists in a containerized environment which can significantly improve the ability to prevent data losses.
Finally, we always recommend that organizations continuously update their security training. Understanding which departments are at greatest risk will help leaders make strategic decisions on who has greater exposure to security awareness training. Ultimately, minimizing risk will come down to making sure that these people are best equipped to understand what a suspicious email would look like.
Learn more about how Proofpoint can help protect your organization, and your people, against malicious attackers.
CMMC Accreditation Body hires CFO from insurance group IFG
The Cybersecurity Maturity Model Certification Accreditation Body, the non-governmental body responsible for operating the Department of Defense’s new contractor cybersecurity compliance regulations has hired Raymond Karrenbauer as CFO.
Karrenbauer will be dual-hatted in the new role and also hold the post of executive vice president overseeing IT and tech portfolios. He is the AB’s first official CFO, taking over from Yong-Gon Chon who served as acting CFO while being on the board of directors. Over the past year, the AB has been transitioning from a volunteer organization run by its board to one with professional staff.
“Raymond is a bona fide IT and business trailblazer who understands both financial management and how to build a world-class online user experience. As such, his joining the Accreditation Body gives us a transformational boost and will change the way our CMMC stakeholders interact with us,” CMMC AB CEO Matt Travis said in a statement.
CMMC is the new compliance program DOD created to verify its contractors have the cybersecurity to handle sensitive information. The model established five tiers of security, with one being the lowest and five requiring expensive cyber systems. Third-party assessors will test all 300,000 defense contractors against the model, with their certification determining a contractor’s ability to continue work with the DOD. The AB oversees the ecosystem of trainers, assessors and certifications of CMMC assessments.
Karrenbauer comes from the insurance industry, most recently working as senior vice president and chief information officer for IFG Companies, a privately held insurance group. There he was responsible for the company’s IT portfolio. He also has experience in other IT roles and at online startups.
“I look forward to creating a world-class cyber accreditation organization and an online marketplace that accelerates the adoption of the CMMC framework,” Karrenbauer said in a statement.
Coast Guard launches new cyber strategy
The Coast Guard will build more cyber teams to focus on the cybersecurity of maritime critical infrastructure from attacks after a rash of hacks and ransomware incidents that shut down key services, the service’s top cyber officer announced Tuesday.
Its new Cyber Strategic Outlook was developed over the past 18 months and is the first update to the Coast Guard’s cyber strategy since it was signed in 2015. The changes come amid concerns over the increased vulnerability of critical infrastructure and an increase in attacks like the Colonial Pipeline ransomware incident, Rear Adm. Michael Ryan, commander of the Coast Guard’s Cyber Command said at the Sea-Air-Space conference.
“It really is about revitalizing the focus of our organization,” he said.
The new outlook focuses on protecting the tech that enables maritime commerce, like software that tracks shipments and operational technology in ports. There has been an increase in automation and tech used to enable the global shipping network, a growth in attack surface for hackers Ryan said needed to be recognized in the strategy.
“As your strategy gets older and latent it becomes less relevant,” Ryan added.
One of the deliverables in the new strategy is creating new cyber teams focused on defending networks and conducting cyber operations to thwart malicious attack on critical infrastructure. The first two cyber mission teams have already been stood up, with funding for a third team requested in the fiscal 2022 budget request. Other units, like a cyber support team will also be established, according to the new strategy.
Another part of the strategy focuses on protecting the guard’s own IT platform, the Enterprise Mission Platform (EMP), which is part of the Department of Defense’ Information Network (DODIN). The goal is to ensure the Guard has secure connectivity to carry out its broader homeland defense mission, according to the strategy.
The Coast Guard, a military service, is uniquely housed under the Department of Homeland Security, giving it law enforcement authority and relationships with other DHS agencies like the Cybersecurity and Infrastructure Security Agency (CISA).
The service has sought to modernize its legacy IT since 2020. The latest outlook is separate the Coast Guard’s previously-established IT modernization strategy, but speaking at the Sea-Air-Space conference, Rear Adm. Ryan said the two would work in tandem to improve its network. security.
FedRAMP just automated checking security authorization packages for completeness
The General Services Administration plans to release XML-automated validations next week allowing vendors to check their security authorization packages for completeness before submitting them to the Federal Risk and Authorization Management Program.
FedRAMP used Schematron’s rule-based validation for making assertions against XML to automate the process and wants vendors to self-test their packages to ensure all the required data is there, before the program reviews them and decides whether to issue a cloud product an authority to operate (ATO).
More easily hackable legacy systems stay in operation longer when agencies can’t quickly purchase cloud products they need for lack of an ATO, and vendors have long wanted FedRAMP to automate parts of its authorization process.
“I think it’s a great step in automated validation,” said Zach Baldwin, automation lead within the FedRAMP program management office (PMO), during an ACT-IAC event Tuesday. “I want cleaner documentation before I have my review team lay eyes on it.”
The PMO wants vendors to implement the validations that allows them to reinsert new files with more complex checks as FedRAMP improves them, Baldwin said.
FedRAMP is also considering an agile ATO, a critical set of controls vendors can implement quickly while saving lesser ones for later.
The PMO recently partnered with the Department of Homeland Security’s .govCAR to score vendors’ security architectures against cyberthreat heat maps. Updated scores will be released in the near future, but they can be used to create a risk profile as agencies make cloud service purchasing decisions, Baldwin said.
Automation wouldn’t be possible without FedRAMP’s work with the National Institute of Standards and Technology to create the standardized Open Security Controls Assessment Language (OSCAL) for authorization packages. NIST released OSCAL 1.0.0 in early June.
“I’m going after the time it takes to get an authorization and the number of passbacks between my review teams and the [cloud service providers] and [third-party assessors],” Baldwin said.