Wednesday, the White House released an 18-page Executive order on cybersecurity. Although the timing was excellent - the attack against the Colonial Pipeline left many in the Eastern US panicking for gasoline - the document was months in the making and sorely needed. Here ScaleSec breaks down the most important parts of the order and provides steps that you can take immediately to work towards compliance.
This order aims to establish and codify a cybersecurity stance for all software and cloud technology used by the federal government, including third parties. Currently, individual, private-sector frameworks (like SOC 2 and the ISO 27000 series) and multiple, comprehensive federal guidelines (FedRAMP, NIST) cover various organizations, but with different purposes, laws, and requirements. This order clarifies acceptable cybersecurity for many in both the public and private sectors.
It can! The order covers third parties, as well as providers to many agencies. If a business isn’t impacted directly, the industry pressure and competition will eventually force compliance in other ways. Proactivity now will be beneficial later; not to mention, security should be a concern for everyone.
The order sets timelines to develop various standards around incident reporting timelines, appropriate encryption practices, environment segregation, auditing, and more. Specifics will become available in the next few months, but several items can be expected:
The order mentions the need to standardize the usage of cloud service providers (CSPs) and their role within cybersecurity. Because AWS, Google Cloud, and Azure are authorized for government use under FedRAMP, it wouldn’t be surprising to see mandates that reflect CSPs’ existing security best practices.
At rest or in transit, data will need to be encrypted. Access to data needs to be restricted to a minimum, and there need to be logs - lots of quality logs.
The Director of NIST is responsible for many components of the Executive order, including using the “migration steps,…standards and guidance” provided within their Zero Trust Architecture. Further, the Playbook (essentially an SOP of cybersecurity) to be released later this year will “incorporate all NIST standards.”
Automation is critical to achieve compliance at scale. Endpoint detection, incident response, threat hunting, and deployment pipelines are all within the scope of the order, with deadlines for notification of breaches to be established. If this work is being done manually, it will be exceedingly difficult to comply.
The order specifically mentions the right to conduct audits without warning using third-party providers or external agencies.
There’s a lot of content in the Executive order, but the majority of critical information is yet to come. Various deadlines for procedures, requirements, and implementation will occur over the next year, changing the understanding of cybersecurity in the public sector each time. The above action points can be a great first step, though, allowing for a headstart in critical security planning. Remember, security is beneficial to everyone, regardless of business sector!