CI Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/ci/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 12 Apr 2026 17:37:55 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg CI Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/ci/ 32 32 59882712 CISA warns of programmable logic controller exploitation https://intelligencecommunitynews.com/cisa-warns-of-programmable-logic-controller-exploitation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-warns-of-programmable-logic-controller-exploitation Sun, 12 Apr 2026 17:37:55 +0000 https://intelligencecommunitynews.com/?p=44304 On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable...

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.”

Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

U.S. organizations should urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the Mitigations section of the advisory to reduce the risk of compromise.

Source: CISA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
44304
MITRE unveils D3FEND for OT https://intelligencecommunitynews.com/mitre-unveils-d3fend-for-ot/?utm_source=rss&utm_medium=rss&utm_campaign=mitre-unveils-d3fend-for-ot Fri, 19 Dec 2025 15:23:16 +0000 https://intelligencecommunitynews.com/?p=43448 On December 16, MITRE announced that it has extended its D3FEND cybersecurity ontology to operational technology (OT), creating a structured knowledge base for...

The post MITRE unveils D3FEND for OT appeared first on Intelligence Community News.

]]>
On December 16, MITRE announced that it has extended its D3FEND cybersecurity ontology to operational technology (OT), creating a structured knowledge base for defending cyber-physical systems. OT includes the controllers, sensors, and actuators that manage physical processes in critical infrastructure, industrial environments, and the defense systems that support service members in their missions. Unlike information technology, which handles data and communications, OT directly affects how machines and systems operate.

As organizations modernize, OT systems are connected to networks and the cloud. This improves efficiency but also introduces new cyber risks, since many OT components were never built for internet exposure. The D3FEND extension provides a common framework to help the cybersecurity community better understand, secure, and sustain these essential systems.

Funded by the Cyber Warfare Directorate in the U.S. Office of the Under Secretary of War for Acquisition and Sustainment and the National Security Agency, D3FEND is expanding into specific domains, including cyber-physical systems that create real-world effects through programmed actions. D3FEND for OT delivers a stable, extensible, and integration-friendly framework to support cybersecurity operations and strategic decision making in OT environments.

“Through D3FEND, we are advancing the cybersecurity frontier alongside the global community,” said Wen Masters, vice president, cyber technologies, MITRE. “As a not-for-profit organization dedicated to national security, we are strategically positioned to tackle complex, high-stakes challenges. The launch of D3FEND for OT demonstrates our unwavering commitment to delivering unbiased, open-sourced tools that are mission-critical.”

Source: MITRE

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post MITRE unveils D3FEND for OT appeared first on Intelligence Community News.

]]>
43448
NSA, FBI warn of pro-Russia Hacktivist threats https://intelligencecommunitynews.com/nsa-fbi-warn-of-pro-russia-hacktivist-threats/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-pro-russia-hacktivist-threats Mon, 15 Dec 2025 13:17:23 +0000 https://intelligencecommunitynews.com/?p=43400 On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and over 20 others to release the Cybersecurity Advisory (CSA), “Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure,” and provide recommended mitigations to reduce the likelihood and impact of related incidents.

The authoring agencies have observed pro-Russia hacktivist groups—attributed to the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—capitalizing on the widespread availability of inadequately secured virtual network computing (VNC) connections to infiltrate operational technology (OT) control devices within critical infrastructure systems and conduct cyber operations against organizations worldwide.

The groups’ ongoing opportunistic targeting methodology can lead to broad targeting and indiscriminate compromise of critical infrastructure entities, including those in Water and Wastewater, Food and Agriculture, and the Energy Sector. Further, their observed lack of strategic focus increases the likelihood of targeting of unintended victims, and tends to result in haphazard attacks with unanticipated damages.

These actors are primarily seeking notoriety with their actions, regularly self-attributing and exaggerating cyberattacks on social media and in group channels to garner attention from peers and the media. Despite this, and their lack of sophisticated ability, actors have been observed willfully causing damage to vulnerable critical infrastructure.

These actors utilize simple, cheap, and easy-to-replicate tactics, techniques, and procedures (TTPs) for the ease of dissemination and replication across various entities, increasing the risk of wide-spread adoption by other cyber actors and escalated frequency of attacks. The authoring agencies warn there is risk that continued attacks may result in further harm or consequences.

Critical infrastructure entities, OT asset owners and operators, and OT device manufactures are encouraged to become familiar with the outlined TTPs and apply the recommended mitigation strategies to reduce the likelihood and impact of incidents related to pro-Russia hacktivists. The report also provides incident response actions organizations should take if compromise is detected.

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
43400
China state-sponsored actors targeting CI orgs, according to NSA https://intelligencecommunitynews.com/china-state-sponsored-actors-targeting-ci-orgs-according-to-nsa/?utm_source=rss&utm_medium=rss&utm_campaign=china-state-sponsored-actors-targeting-ci-orgs-according-to-nsa Thu, 28 Aug 2025 10:36:28 +0000 https://intelligencecommunitynews.com/?p=42543 On August 27, the National Security Agency (NSA) and other U.S. and foreign organizations released a joint Cybersecurity Advisory to expose...

The post China state-sponsored actors targeting CI orgs, according to NSA appeared first on Intelligence Community News.

]]>
On August 27, the National Security Agency (NSA) and other U.S. and foreign organizations released a joint Cybersecurity Advisory to expose advanced persistent threat (APT) actors sponsored by the Chinese government targeting telecommunications, government, transportation, lodging, and military infrastructure networks globally and outline appropriate mitigation guidance.

The malicious activity outlined in the advisory partially overlaps with cybersecurity industry reporting on Chinese state-sponsored threat actors referred to by names such as Salt Typhoon.

These activities have been linked to multiple China-based entities—including Sichuan Juxinhe Network Technology Co. Ltd., Beijing Huanyu Tianqiong Information Technology Co., Ltd., and Sichuan Zhixin Ruijie Network Technology Co., Ltd.—which provide cyber products and services to China’s Ministry of State Security and People’s Liberation Army.

The CSA, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” details specific tactics, techniques, and procedures (TTPs) these actors have been found using for initial exploitation, persistence, collection, and exfiltration. Indicators of compromise (IOCs) and common vulnerabilities and exposures (CVEs) exploited by the APT actors are also detailed.

Further, the report provides threat hunting guidance and specific mitigations that organizations are encouraged to implement to search for malicious activity and reduce the threat of Chinese state-sponsored and other APT actors. These recommendations are especially important for network defenders of telecommunications and critical infrastructure organizations to discover unknown intrusions and prevent undetected malicious activity on their networks. By utilizing the outlined guidance, organizations can also better provide compromise details to appropriate authorities to continue improving all parties’ understanding of initial access methods.

When threat hunting, the authoring agencies advise that organizations gain a full understanding of the APT actors’ accesses before implementing visible incident response and mitigation actions to maximize the chance of achieving full eviction from compromised networks.

This CSA is being released by the following authoring and co-sealing agencies:

  • United States National Security Agency (NSA)
  • United States Cybersecurity and Infrastructure Security Agency (CISA)
  • United States Federal Bureau of Investigation (FBI)
  • United States Department of Defense Cyber Crime Center (DC3)
  • Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
  • Canadian Centre for Cyber Security (Cyber Centre)
  • Canadian Security Intelligence Service (CSIS)
  • New Zealand National Cyber Security Centre (NCSC-NZ)
  • United Kingdom National Cyber Security Centre (NCSC-UK)
  • Czech Republic National Cyber and Information Security Agency (NÚKIB)
  • Finnish Security and Intelligence Service (SUPO)
  • Germany Federal Intelligence Service (BND)
  • Germany Federal Office for the Protection of the Constitution (BfV)
  • Germany Federal Office for Information Security (BSI)
  • Italian External Intelligence and Security Agency (AISE)
  • Italian Internal Intelligence and Security Agency (AISI)
  • Japan National Cyber Office (NCO)
  • Japan National Police Agency (NPA)
  • Netherlands Defence Intelligence and Security Service (MIVD)
  • Netherlands General Intelligence and Security Service (AIVD)
  • Polish Military Counterintelligence Service (SKW)
  • Polish Foreign Intelligence Agency (AW)
  • Spain National Intelligence Centre (CNI)

 

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post China state-sponsored actors targeting CI orgs, according to NSA appeared first on Intelligence Community News.

]]>
42543
Sphinx acquires Enigma https://intelligencecommunitynews.com/sphinx-acquires-enigma/?utm_source=rss&utm_medium=rss&utm_campaign=sphinx-acquires-enigma Tue, 15 Jul 2025 14:32:03 +0000 https://intelligencecommunitynews.com/?p=42184 On July 14, Sphinx, a developer of counterintelligence (CI) and cyber tools for the digital battlefield, announced the acquisition of...

The post Sphinx acquires Enigma appeared first on Intelligence Community News.

]]>
On July 14, Sphinx, a developer of counterintelligence (CI) and cyber tools for the digital battlefield, announced the acquisition of Enigma International. The addition of Enigma’s language and systems development capabilities enhances Sphinx’s mission to deliver unparalleled protection against advanced threat actors for defense and commercial security clients.

Enigma’s core values and capabilities aligns with Sphinx’s mission-first excellence and its Solution and Value Delivery (SOLVD) Model, which leverages data-first design, automation, and AI augmentation to counter sophisticated adversaries.

Enigma brings several key contracts, such as the GSA OASIS+ and DIA DLITE II vehicles, that will provide even greater Federal Government access for Sphinx. For example, Sphinx’s Advanced Intelligence & Security (AxIS) software product line has been expanded to serve the cyber and security communities, and OASIS+ is a simple buying mechanism for security clients. AxIS-CI is a purpose-built solution that puts modern technology in the hands of commanders to drive collaborative, automated, and AI-enabled CI mission operations.

Garrett Pagon, CEO of Sphinx, focused on the new customer relationships that emerge from the combination. He noted, “We are thrilled to welcome Enigma into the Sphinx family. They not only add unique qualifications that aid in the protection of U.S. interests, but they are embedded within three new intelligence organizations, where we can now drive transformative solutions.”

Steve Martin, COO of Sphinx, added, “Joining forces with Enigma is a natural evolution for Sphinx. Their dedication to innovation and proactive defense aligns perfectly with Sphinx’s mission to safeguard critical missions from sophisticated adversaries.”

Yolanda Wong, CEO of Enigma, stated, “Sphinx’s capabilities and leadership in developing large scale defense software and services comes at a perfect time in our growth trajectory. We are excited to join such a highly regarded organization that will enhance our support to federal clients and programs.”

Source: Sphinx

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Sphinx acquires Enigma appeared first on Intelligence Community News.

]]>
42184
Air Force posts HUMINT sources sought https://intelligencecommunitynews.com/air-force-posts-humint-sources-sought/?utm_source=rss&utm_medium=rss&utm_campaign=air-force-posts-humint-sources-sought Fri, 16 May 2025 13:24:02 +0000 https://intelligencecommunitynews.com/?p=41736 On May 15, the U.S. Air Force posted a sources sought notice for human intelligence (HUMINT) and counterintelligence (CI). Responses...

The post Air Force posts HUMINT sources sought appeared first on Intelligence Community News.

]]>
On May 15, the U.S. Air Force posted a sources sought notice for human intelligence (HUMINT) and counterintelligence (CI). Responses are due by 12:00 p.m. Central on May 29.

The government is seeking sources to provide expertise in the management of HUMINT and CI collection requirements, HUMINT analysis activities, and integration of HUMINT and CI into current and future cyber operations. Provide HUMINT operations support to include desk officer, sensitive activities, and linguist support.

AF/A2X conducts HUMINT activities as well as HUMINT and CI integration, coordination and deconfliction across the 16 AF/AFCYBER/JFHQ-C(AF) Enterprise (hereafter the 16 AF Enterprise) in support of cyber and Information Warfare operational activities.

Accordingly, the tasks outlined in the Performance Work Statement (PWS) are intended to advance the integration of HUMINT and CI support to 16 AF Enterprise operations, targeting, analysis, collection management, plans, force readiness and tools/systems utilization.

Review the Air Force HUMINT sources sought.

Source: SAM

The right opportunity can be worth millions. Don’t miss out on the latest IC-focused RFI, BAA, industry day, and RFP information – subscribe to IC News today.

 

The post Air Force posts HUMINT sources sought appeared first on Intelligence Community News.

]]>
41736
Parsons unveils Cyberzcape CI cyber solution https://intelligencecommunitynews.com/parsons-unveils-cyberzcape-ci-cyber-solution/?utm_source=rss&utm_medium=rss&utm_campaign=parsons-unveils-cyberzcape-ci-cyber-solution Fri, 19 Jan 2024 15:48:44 +0000 https://intelligencecommunitynews.com/?p=37618 On January 17, Chantilly, VA-based Parsons Corporation announced the launch of a new holistic cyber solution – Cyberzcape Tracker –...

The post Parsons unveils Cyberzcape CI cyber solution appeared first on Intelligence Community News.

]]>
On January 17, Chantilly, VA-based Parsons Corporation announced the launch of a new holistic cyber solution – Cyberzcape Tracker – that proactively protects and neutralizes cyber threats within critical infrastructure networks. The solution is the first commercial cyber offering of its kind that combines passive monitoring with active threat neutralization within the critical infrastructure protection industry.

Recently, Cyberzcape Tracker was successfully piloted by two leading utility providers in the Midwest, unlocking a comprehensive, holistic, and programmatic contextual analysis of the network’s threat environment and then identifying and neutralizing malicious activity before impacting network integrity.

“In today’s blended global infrastructure and national security landscape, the necessity of safeguarding critical infrastructure’s cybersecurity is more crucial than ever. Protecting critical infrastructure is no longer an option; it’s an imperative,” said Robert Nawy, director of IPK Cyber and Power Division within Parsons. “Society depends on interconnected digital systems and the potential consequences of cyberattacks on vital services and critical infrastructure – like the attacks on Ukraine’s power grid and the United States’ Colonial Pipeline – are serious to the health, safety, and stability of our global communities. The protection of essential sectors like energy, finance, and healthcare is not merely a technical challenge; it’s a cornerstone of national resilience and security in the face of evolving and more sophisticated digital threats.”

Cyberzcape Tracker will enhance the safety and security of customers across the critical infrastructure market, including local communities, utilities, and vital systems, while reducing the risk of effective cyberattacks on infrastructure suppliers. Powered by artificial intelligence and machine learning, Cyberzcape Tracker combines capabilities from the company’s acquisition of IPKeys Cyber Partners with operational Parsons’ cybersecurity solutions that are currently protecting networks across the global infrastructure and national security markets.

Source: Parsons

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Parsons unveils Cyberzcape CI cyber solution appeared first on Intelligence Community News.

]]>
37618
China state-sponsored cyber actor using built-in network tools to target CI sector https://intelligencecommunitynews.com/china-state-sponsored-cyber-actor-using-built-in-network-tools-to-target-ci-sector/?utm_source=rss&utm_medium=rss&utm_campaign=china-state-sponsored-cyber-actor-using-built-in-network-tools-to-target-ci-sector Fri, 26 May 2023 11:32:33 +0000 https://intelligencecommunitynews.com/?p=35662 The National Security Agency (NSA) and partners have identified indicators of compromise (IOCs) associated with a People’s Republic of China...

The post China state-sponsored cyber actor using built-in network tools to target CI sector appeared first on Intelligence Community News.

]]>
The National Security Agency (NSA) and partners have identified indicators of compromise (IOCs) associated with a People’s Republic of China (PRC) state-sponsored cyber actor using living off the land techniques to target networks across U.S. critical infrastructure, NSA announced May 24.

“Cyber actors find it easier and more effective to use capabilities already built into critical infrastructure environments. A PRC state-sponsored actor is living off the land, using built-in network tools to evade our defenses and leaving no trace behind,” said Rob Joyce, NSA Cybersecurity Director. “That makes it imperative for us to work together to find and remove the actor from our critical networks.”

To assist network defenders to hunt and detect this type of PRC actor malicious activity on their systems, NSA is leading U.S. and Five Eyes partner agencies in publicly releasing the “People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection” Cybersecurity Advisory (CSA) today. The partner agencies include:

  • U.S. Cybersecurity and Infrastructure Security Agency (CISA)
    • U.S. Federal Bureau of Investigation (FBI)
    • Australian Cyber Security Centre (ACSC)
    • Canadian Centre for Cyber Security (CCCS)
    • New Zealand National Cyber Security Centre (NCSC-NZ)
    • United Kingdom National Cyber Security Centre (NCSC-UK)

“For years, China has conducted operations worldwide to steal intellectual property and sensitive data from critical infrastructure organizations around the globe,” said Jen Easterly, CISA Director. “Today’s advisory, put out in conjunction with our US and international partners, reflects how China is using highly sophisticated means to target our nation’s critical infrastructure. This joint advisory will give network defenders more insights into how to detect and mitigate this malicious activity. At the same time, we must recognize the agility and capability of PRC cyber actors, and continue to focus on strong cybersecurity practices like network segmentation and ongoing investments in promoting the resilience of critical functions under all conditions. As our nation’s cyber defense agency, CISA stands ready to aid any organization affected and we encourage all organizations to visit our webpage for guidance and resources to make their networks more resilient.”

“The FBI continues to warn against China engaging in malicious activity with the intent to target critical infrastructure organizations and use identified techniques to mask their detection,” said Bryan Vorndran, the FBI’s Cyber Division Assistant Director. “We, along with our federal and international partners, will not allow the PRC to continue to use these unacceptable tactics. The FBI strives to share information with our private sector partners and the public to ensure they can better protect themselves from this targeted malicious activity.”

“It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems, as described in this joint advisory with our international partners,” said Paul Chichester, NCSC Director of Operations. “We strongly encourage UK essential service providers to follow our guidance to help detect this malicious activity and prevent persistent compromise.”

“The Canadian Centre for Cyber Security joins its international partners in sharing this newly identified threat and accompanying mitigation measures with critical infrastructure sectors,” said Sami Khoury, Head of the Canadian Centre for Cyber Security. “The interconnected nature of our infrastructures and economies highlights the importance of working together with our allies to identify and share real-time threat information.”

The CSA provides an overview of hunting guidance and associated best practices. It includes examples of the actor’s commands and detection signatures. The authoring agencies also includes a summary of indicators of compromise (IOC) values, such as unique command-line strings, hashes, file paths, exploitation of CVE-2021-40539 and CVE-2021-27860 vulnerabilities, and file names commonly used by this actor.

As one of their primary tactics, techniques, and procedures (TTP) of living off the land, the PRC actor uses tools already installed or built into a target’s system. This allows the actor to evade detection by blending in with normal Windows systems and network activities, avoiding endpoint detection and response (EDR) products, and limiting the amount of activity that is captured in default logging configurations.

NSA recommends network defenders apply the detection and hunting guidance in the CSA, such as logging and monitoring of command line execution and WMI events, as well as ensuring log integrity by using a hardened centralized logging server, preferably on a segmented network.

Defenders should also monitor logs for Event ID 1102, which is generated when the audit log is cleared.
The behavioral indicators noted in the CSA can also be legitimate system administration commands that appear in benign activity. Defenders must evaluate matches to determine the significance, applying their knowledge of the system and baseline behavior.

Read the full report here.

Source: NSA

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

 

The post China state-sponsored cyber actor using built-in network tools to target CI sector appeared first on Intelligence Community News.

]]>
35662
Compliance Pointers for the New National Cybersecurity Strategy: Defending Critical Infrastructure and Investing in Tomorrow https://intelligencecommunitynews.com/ic-insiders-compliance-pointers-for-the-new-national-cybersecurity-strategy-defending-critical-infrastructure-and-investing-in-tomorrow/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-compliance-pointers-for-the-new-national-cybersecurity-strategy-defending-critical-infrastructure-and-investing-in-tomorrow Mon, 08 May 2023 13:08:48 +0000 https://intelligencecommunitynews.com/?p=35497 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies In early March, the Biden-Harris...

The post Compliance Pointers for the New National Cybersecurity Strategy: Defending Critical Infrastructure and Investing in Tomorrow appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

In early March, the Biden-Harris Administration released its new National Cybersecurity Strategy. The strategy builds upon momentum established by the administration’s previously released cybersecurity initiatives including the National Security Strategy, Executive Order 14028 (Improving the Nation’s Cybersecurity), National Security Memorandum 5 (Improving Cybersecurity for Critical Infrastructure Control Systems), M-22-09 (Moving the U.S. Government Toward Zero-Trust Cybersecurity Principles), and National Security Memorandum 10 (Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems).

The strategy recognizes that “robust collaboration, particularly between public and private sectors, is essential to security cyberspace.” To that end, the document seeks to build and enhance collaboration around five pillars:

  1. Defend Critical Infrastructure,
  2. Disrupt and Dismantle Threat Actors,
  3. Shape Market Forces to Drive Security and Resilience,
  4. Invest in a Resilient Future, and
  5. Forge International Partnerships to Pursue Shared Goals

 

The strategy also contains many initiatives that apply to public and private organizations, state and local governments, utilities, healthcare, and educational industries. The good news is federal agencies can get a head start on implementing several initiatives today.

It’s outside the scope of this commentary to address the details of all the five pillars in the cybersecurity strategy. Instead, we’ll focus on Defending the Critical Infrastructure, and Investing in a Resilient Future.

Let’s look more closely at each of these two pillars in particular.

Defend Critical Infrastructure: The Need for Zero Trust Architecture

In describing the “Defend Critical Infrastructure” pillar, the strategy document underscores the need to “give the American people confidence in the availability and resilience of our critical infrastructure and the essential services it provides.” Among other ways to develop confidence in the critical infrastructure, the strategy notes in particular “defending and modernizing Federal networks and updating Federal incident response policy.”

Building on the momentum of EO 14028 and NSM 8, the administration is committed to driving “long-term efforts to defend the Federal enterprise and modernize Federal systems in accordance with zero trust principles that acknowledge threats must be countered both inside and outside traditional network boundaries.”

This is as it should be, because the best way for agencies to protect their data from attacks is by implementing a zero trust architecture. That, of course, requires implementation of a variety of initiatives:

Planning. Zero trust starts by understanding that networked devices should not be trusted blindly, even if they have been verified and connected to a managed agency network. The safest place to start is to assume that networks either have been or will be compromised. From there, it’s essential to put a zero trust plan into effect.

Zero trust planning demands a data-centric approach to security. Files containing sensitive information, and anything else requiring protection, must be adequately addressed regardless of where the data resides – on premises, in the cloud, or in a hybrid environment. This should be an automatic operation, with sensitive data identified as soon as it enters an agency’s IT ecosystem. This data should be secured with policy-based protection across the data lifecycle.

Multifactor Authentication. In essence, multifactor authentication ensures that a user is who they claim to be. The more factors used to determine a person’s identity, the greater the trust of authenticity. Because multifactor authentication requires multiple means of identification at login, it is generally considered to be the most secure method for authenticating access to data and applications.

The best solutions for multifactor authentication address numerous use cases, assurance levels, and threat vectors with unified, centrally managed policies, all managed from a central platform delivered in the cloud or on-premises. Methods of authentication should include context-based authentication combined with step-up capabilities, out-of-band authentication, one-time password and X.509 certificate-based solutions. Authentication methods should be available in numerous form factors, including smart card, USB token, software, mobile app, and hardware tokens.

Data Encryption. Data-at-rest encryption with privileged user access controls can considerably improve security. It not only protects data-at-rest, but also encrypted workloads in the cloud. Role-based access policies enable a zero trust architecture by controlling who, what, where, when and how data can be accessed. Granular access controls enable administrative users to perform their duties while restricting access to encrypted data.

Optimal data-at-rest encryption solutions should be able to deliver granular encryption and role-based access control for structured and unstructured data, whether that data resides in file servers, databases, applications, or storage containers.

It is essential to protect network transmitted data against cyber-attacks and data breaches. This calls for high-assurance network encryption, with secure, dedicated encryption devices to protect data-in-transit. To truly be called “high assurance,” devices must use embedded, zero-touch encryption key management; provide end-to-end, authenticated encryption and use standards-based algorithms.

Agencies should look for network encryption solutions that provide a single platform to encrypt everywhere— from network traffic between data centers and the headquarters, to backup and disaster recovery sites, whether on premises or in the cloud. High-assurance network data encryption enables an organization to have the confidence that its data will be useless in unauthorized hands.

Manage Authorization and Access. Agencies need awareness into who and what is accessing sensitive data, including privileged users who may be assuming the identity of other users. An ideal way of monitoring that type of activity is by maintaining a log of the time, place, and individuals accessing the data, as well as what action took place.

Logs offer deep visibility into data access, which can alert administrators to unauthorized access attempts to protected data. Such logs can also be used to understand typical access patterns when combined with other infrastructure and access information. For example, consider a user that typically accesses information in small quantities inside a local network. If that user suddenly starts accessing large amounts of data remotely, that could constitute a threat, which should generate an alert and prompt an investigation.

Adopt Cloud Security Tools. Agencies must apply solutions to simplify the data security landscape. This applies to multiple cloud and legacy environments as well as cloud-oriented digital transformation applications.

Data security solutions should be able to protect data moving between clouds and out of the cloud to on-premises environments, using centralized data security solutions across multiple cloud platforms. Keep in mind that most cloud service providers (CSPs) have a “shared responsibility” view of security. These providers are responsible for securing the infrastructure that runs their cloud services. Data owners are responsible for protecting the confidentiality, integrity, and availability of their data in the cloud.

CSPs generally offer native data security solutions to their users. However, data owners need to determine the sensitivity level of their cloud-stored data and apply the most appropriate security measures to protect said data. For example, in cloud deployments where security is less critical, agencies may choose to rely on a CSP’s native encryption and deploy additional cryptographic key management services (Bring Your Own Key). Or, for deployments where the highest level of security is required, agencies may choose to deploy Bring Your Own Encryption tools to their cloud environments.

Invest in a Resilient Future: Preparing for a Post-Quantum Future

The National Cybersecurity Strategy By taking the initiative on these two key pillars of the national cybersecurity strategy – zero trust architecture and post-quantum planning – as quickly as possible, agencies will have made major steps forward in complying with the strategy across the board.

puts a great deal of emphasis on life after quantum, particularly in “Objective 4.3: Prepare for our Post-Quantum Future.” According to this objective, the nation needs to “prioritize and accelerate investments in widespread replacement of hardware, software, and services that can be easily compromised by quantum computers.”

The language in this objective goes on to say that “Strong encryption is key to cybersecurity and global commerce. It is the primary way we protect our data online, validate end users, authenticate signatures and certify the accuracy of information. But quantum computing has the potential to break some of the most ubiquitous encryption standards deployed today.”

When preparing an infrastructure strategy for quantum-safe encryption, there are a few things to keep in mind:

Know your risks. long-term data is at risk to harvesting and early attacks. IT managers and other network professionals must assess their organizations’ use of vulnerable cryptography, the expiration date of their encrypted data, and the crypto-agility maturity of their IT infrastructure.

Several sources are available to understand risks and to plan ahead. NIST offers a publication titled “Getting Ready for Post-Quantum Cryptography” to help monitor standards development, and perform risk assessment of where public-key crypto may be used in the infrastructure. It’s important reading to understand whether a network’s equipment is crypto-agile.

The National Cybersecurity Center of Excellence (NCCoE) has recently launched its “Migration to Post Quantum Cryptography” Project. Understanding that replacement of cryptographic algorithms is both technically and logistically challenging, the NCCoE is undertaking a practical demonstration of technology and tools that can provide a head start on executing a migration roadmap in collaboration with a public and private sector community. Thales Trusted Cyber Technologies is among the technology collaborators participating in this project

Another excellent source of information is the NSA Post-Quantum Cryptography FAQ, which provides an excellent summary on the subject.

Focus on crypto-agility. Crypto-agility requires flexible upgradeable technology and a hybrid approach of classic and quantum-resistant crypto solutions.

Remember that crypto-agility is not about quantum; it’s about being able to face the reality that all algorithms fail with time. Many systems today make it difficult to rotate keys, to choose different sizes/parameters, and to change mechanisms or key algorithms. These are all required for protocols to be versioned, negotiated and not to fail when presented with unknown options. They are essential for crypto-agility, and it’s important to work with providers with solutions that embrace those needs.

Start today. This cannot be understated, which is why National Security Memo 10 made a point of it. Organizations must begin now to design a quantum-resistant architecture today to protect against the emerging quantum threat.

IT infrastructure equipment often is deployed for years or decades without hardware replacement. Consequently, it is important to make sure currently deployed hardware was developed with crypto-agility principles in mind, to receive software or firmware updates once post-quantum crypto algorithms and protocols are standardized.

It is also important to check with equipment providers to see what beta or technology preview firmware they have available for testing in non-production systems, that implements pre-standardized quantum-resistant cryptographic algorithms. Testing will help identify performance or interoperability issues early and provide time to address the issues and mitigate the identified risks.

By taking the initiative on these two key pillars of the national cybersecurity strategy – zero trust architecture and post-quantum planning – as quickly as possible, agencies will have made major steps forward in complying with the strategy across the board.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Compliance Pointers for the New National Cybersecurity Strategy: Defending Critical Infrastructure and Investing in Tomorrow appeared first on Intelligence Community News.

]]>
35497
USMC posts CIHEP RFI https://intelligencecommunitynews.com/usmc-posts-cihep-rfi/?utm_source=rss&utm_medium=rss&utm_campaign=usmc-posts-cihep-rfi Fri, 19 Feb 2021 14:16:50 +0000 https://intelligencecommunitynews.com/?p=28700 On February 18, the U.S. Marine Corps posted a request for information for Counterintelligence (CI) and Human Intelligence (HUMINT) Equipment...

The post USMC posts CIHEP RFI appeared first on Intelligence Community News.

]]>
On February 18, the U.S. Marine Corps posted a request for information for Counterintelligence (CI) and Human Intelligence (HUMINT) Equipment Program (CIHEP) engineering services. Responses are due by 1:00 p.m. Eastern on March 10.

Marine Corps Systems Command (MCSC) requires engineering, integration, and logistics support to aid in the support of the Terrestrial Humint Team (THT) program (Counterintelligence (CI) and Human Intelligence (HUMINT) Equipment Program (CIHEP), Marine Air-Ground Task Force (MAGTF) Secondary Imagery Dissemination System (MSIDS), etc.) systems and subsystems to enable various Marine Corps missions and resolve capability gaps.

The CIHEP team is conducting market research to determine the availability of responsible and qualified sources in accordance with Federal Acquisition Regulation (FAR) Part 10. This requirement is associated with North American Industry Classification System (NAICS) Code 541330, Engineering Services.  The purpose of this RFI is for the Marine Corps to gain awareness of potential qualified sources and to develop additional knowledge of the existing market for the required services.

 GENERAL TECHNICAL REQUIREMENTS

  1. Design, development and prototyping support for the Marine Corps current and future THT program systems and components
  2. Development of testing procedures for the THT program systems and components.
  3. Support integration of THT components and systems
  4. Provide engineering support in the manufacturing and fielding of THT program systems and solutions
  5. Procure and deliver developed THT program systems and components
  6. Program management
  7. Generate and maintain Technical Data Packages (TDP) for any product or component of the system
  8. Provide configuration management for the Marine Corps version of any THT program systems, components, or prototyped solutions
  9. Support all cyber requirements for the THT program systems and components
  10. Refresh to improve reliability, maintainability, reduce cost and/or add minor performance enhancement
  11. Maintain software and licenses used in the THT program systems and components.
  12. Lifecycle sustainment of the THT program systems and components
  13. Help Desk troubleshooting and support for the THT program systems and components
  14. Provide training for man-portable systems and components for operators or users

Full information is available here.

Source: SAM

The post USMC posts CIHEP RFI appeared first on Intelligence Community News.

]]>
28700