Wednesday, June 7, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

CISA Director: ‘Strong Security Has to Be a Standard Feature’

Researcher by Researcher
February 28, 2023
in Cybersecurity
0
CISA Director: ‘Strong Security Has to Be a Standard Feature’
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The technology market has evolved in such a way over the last few decades that not only is a certain level of defects in software and hardware accepted, it’s expected, and the responsibility for using those technologies safely and compensating for those flaws has somehow landed on customers. Jen Easterly wants to change that. Now.

“We’ve normalized the fact that technology products are released to market with hundreds or thousands of defects when that would be unacceptable in any other industry. We’ve normalized the fact that security is relegated to IT people or the CISO in enterprises, but few have the ability to incentivize the changes that would help,” Easterly, the director of the Cybersecurity and Infrastructure Security Agency (CISA), said during a speech at Carnegie Mellon University Monday.

“This pattern of ignoring increasingly severe problems is a signal of the normalization of deviant behaviors. Collectively, we’ve become accustomed to a deviance of what we’d all think would be a norm for manufacturers, which is to create a safe product.”

The problem is essentially twofold. The first part is that, despite decades of research and warnings from software security experts, many technology providers do not have the practices and norms in place to develop products securely from the beginning. The premium often is on time-to-market and adding features, which can push security and reliability concerns much farther down the priority list, especially if they’re seen as obstacles to meeting deadlines or ship dates. Part of this also comes from the lack of formal education many developers have in secure coding practices, an issue that has been of concern for many years.

“We need security designed in from the beginning, right out of the box, without added cost. Memory safe language, secure coding practices, the attributes of secure coding by design will evolve over time,” Easterly said.

“Strong security has to be a standard feature of virtually every technology product. The fact that we’ve accepted a monthly patch Tuesday as normal is more evidence of our acceptance of operating at the accident boundary.”

Building security in from the earliest stages of the product development lifecycle is a simple idea, but it’s not easy to execute and requires considerable investment from the company in terms of both time and resources. Many large technology companies have formal secure software development life cycle (SDLC) programs that define processes for making security a core part of the product development process, but that’s not the norm for even mid-tier technology providers, let alone small companies. Finding developers and engineers with secure coding and development training is not a simple matter, nor is preventing the introduction of vulnerabilities into code in the first place.

“We must applaud and encourage progress while recognizing the need to do more. This threat environment is only getting more and more complex.”

That’s where the shift to developing in memory safe languages–those that can prevent common memory safety vulnerabilities–comes in. Moving to languages such as Rust, Go, and others that are considered memory safe can make a big difference in the security of software.

“We need to make memory safe languages ubiquitous in colleges globally. Make a security course a graduation requirement, make it part of every class,” Easterly said.

The second part of the problem, which in many ways derives from the first, is that much of the responsibility for addressing security problems in software and hardware falls on customers and consumers. A security vulnerability that leads to a compromise of a system or a breach of an organization often is seen as the fault of the person or organization using the product, rather than that of the manufacturer.

“We find ourselves blaming the user for failures of technology. Manufacturers are using us, the users, as crash test dummies and the situation isn’t sustainable. We need a new model in which responsibility for technology safety is shared based upon an organization’s ability to bear the burden. A model that emphasizes collaboration as a prerequisite for self preservation and a recognition that a cyber threat to one organization is a safety threat to all organizations,” Easterly said.

“This would begin with tech products that put the safety of the customer first, rebalancing risk onto organizations like major tech manufacturers much more suited to managing cyber risks.”

Addressing these issues requires a long-term approach and not simply a new set of regulations or industry standards. Easterly said it will require the leaders of technology companies to focus explicitly on building safer products, provide transparency into their development and manufacturing processes, and an understanding that the burden of safety should not fall solely (or even mainly) on customers. Part of that transparency commitment should be the use of software bills of materials (SBOM) to provide insight into what components and libraries a given product includes, she said.

“We must applaud and encourage progress while recognizing the need to do more. This threat environment is only getting more and more complex,” Easterly said.



Source link

Related articles

CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
Sentra Raises $30 Million for DSPM Technology

KeePass Update Patches Vulnerability Exposing Master Password

June 6, 2023
Tags: CISADirectorfeaturesecurityStandardStrong
Share76Tweet47

Related Posts

CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
0

North Korean threat group Kimsuky has recently launched a social engineering campaign against a number of experts specializing in North...

Sentra Raises $30 Million for DSPM Technology

KeePass Update Patches Vulnerability Exposing Master Password

June 6, 2023
0

Open source password manager KeePass was updated over the weekend to patch a vulnerability allowing attackers to retrieve the cleartext...

Zero-day MOVEit Transfer vulnerability exploited in the wild

Zero-day MOVEit Transfer vulnerability exploited in the wild

June 6, 2023
0

Shodan search engine results for internet-facing MOVEit instances. Image: Shodan The Cybersecurity & Infrastructure Security Agency has issued an alert...

New DDoS Attack Vector Abuses Content Filtering Systems

UNC4857 Exploits MOVEit Transfer Flaw in Data Extortion Attacks

June 6, 2023
0

A newly discovered threat campaign has been observed exploiting the recently uncovered, critical-severity MOVEit Transfer vulnerability in order to launch...

Sentra Raises $30 Million for DSPM Technology

Dozens of Malicious Extensions Found in Chrome Web Store

June 6, 2023
0

Security researchers recently identified more than 30 malicious extensions that had made their way into the Chrome web store, potentially...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Release date, price and more

Release date, price and more

June 7, 2023
CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
7 tips for spotting a fake mobile app

7 tips for spotting a fake mobile app

June 6, 2023
Sentra Raises $30 Million for DSPM Technology

KeePass Update Patches Vulnerability Exposing Master Password

June 6, 2023

Recent Posts

Release date, price and more

Release date, price and more

June 7, 2023
CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
7 tips for spotting a fake mobile app

7 tips for spotting a fake mobile app

June 6, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved