critical infrastructure Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/critical-infrastructure/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 12 Apr 2026 17:37:55 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg critical infrastructure Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/critical-infrastructure/ 32 32 59882712 CISA warns of programmable logic controller exploitation https://intelligencecommunitynews.com/cisa-warns-of-programmable-logic-controller-exploitation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-warns-of-programmable-logic-controller-exploitation Sun, 12 Apr 2026 17:37:55 +0000 https://intelligencecommunitynews.com/?p=44304 On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable...

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.”

Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

U.S. organizations should urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the Mitigations section of the advisory to reduce the risk of compromise.

Source: CISA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
44304
Trout Software and Carahsoft partner https://intelligencecommunitynews.com/trout-software-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=trout-software-and-carahsoft-partner Tue, 10 Feb 2026 12:58:47 +0000 https://intelligencecommunitynews.com/?p=43813 On February 3, Trout Software, a provider of proxy-based security for Operational Technologies (OT) and legacy systems, and Carahsoft Technology Corp....

The post Trout Software and Carahsoft partner appeared first on Intelligence Community News.

]]>
On February 3, Trout Software, a provider of proxy-based security for Operational Technologies (OT) and legacy systems, and Carahsoft Technology Corp. announced a partnership. Under the agreement, Carahsoft will serve as Trout Software’s Master Government Aggregator, making the company’s Trout Access Gate solution available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, The Interlocal Purchasing System (TIPS), OMNIA Partners, E&I Cooperative Services Contract and The Quilt contracts.

“We are thrilled to partner with Carahsoft to help agencies protect the critical systems they depend on,” said Florian Doumenc, CEO and co-founder of Trout Software. “Much of the nation’s critical infrastructure still relies on aging OT equipment that cannot be patched or moved to the cloud. Trout Access Gate places a security proxy, deployable in minutes, directly in front of these assets to enable agencies to strengthen resilience with zero downtime and accelerate their path to compliance.”

Trout Access Gate applies Zero Trust security to the essential OT and legacy systems that support public operations, including Programmable Logic Controllers (PLCs), Supervisory Control and Data Acquisition (SCADA) servers, sensors, cameras, building automation systems, controllers and equipment.

With a single appliance per site, Trout Access Gate places a dedicated security proxy in front of each critical asset, providing:

  • Zero Trust access controls
  • Network and asset cloaking
  • Micro-segmentation without network redesign
  • Secure remote operations
  • Protocol filtering and audit visibility
  • CMMC / NIST 800-171 ready safeguards

 

This approach enables organizations to strengthen cyber-physical resilience while maintaining existing infrastructure, which is a priority for municipalities, public utilities, defense logistics sites and manufacturing operations that support the Defense Industrial Base.

“Adding Trout Software to our portfolio enables organizations to modernize on-premise and OT security quickly and with minimal disruption,” said Alex Whitworth, cybersecurity solutions vertical executive at Carahsoft. “As cyber threats increasingly target legacy systems and critical infrastructure, Trout’s on-premise Zero Trust overlay delivers a critical capability for our Government and DIB customers, particularly as they work toward NIST 800-171 and CMMC compliance. Carahsoft and our reseller partners are pleased to collaborate with Trout Software to help protect our nation’s critical infrastructures.”

Source: Carahsoft

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

The post Trout Software and Carahsoft partner appeared first on Intelligence Community News.

]]>
43813
MITRE unveils Embedded Systems Threat Matrix https://intelligencecommunitynews.com/mitre-unveils-embedded-systems-threat-matrix/?utm_source=rss&utm_medium=rss&utm_campaign=mitre-unveils-embedded-systems-threat-matrix Thu, 22 Jan 2026 00:53:10 +0000 https://intelligencecommunitynews.com/?p=43655 On January 20, MITRE announced that it has introduced the Embedded Systems Threat Matrix (ESTM), a cybersecurity framework to protect the embedded systems...

The post MITRE unveils Embedded Systems Threat Matrix appeared first on Intelligence Community News.

]]>
On January 20, MITRE announced that it has introduced the Embedded Systems Threat Matrix (ESTM), a cybersecurity framework to protect the embedded systems that power our nation’s critical infrastructure and defense technologies. Developed in collaboration with the Air Force’s Cyber Resiliency Office for Weapon Systems (CROWS), ESTM helps organizations understand and defend against cyber threats targeting these vital systems.

ESTM reflects MITRE’s mission-first approach as a not-for-profit organization serving the public interest. The framework provides practical tools for researchers, vendors, and security professionals to identify vulnerabilities and build stronger embedded systems. ESTM can be used across many sectors, including transportation, energy, healthcare, industrial controls, and robotics.

“Embedded systems are the foundation of our critical infrastructure and defense capabilities, but they face complex and growing cyber risks,” said Keoki Jackson, senior vice president, MITRE National Security. “ESTM fills a key gap by giving defenders clear, actionable information to identify and stop cyber threats against these essential systems.”

ESTM builds on MITRE’s history of delivering objective, independent solutions to government and industry. Inspired by the MITRE ATT&CK framework and based on MITRE’s proof-of-concept and theoretical research, ESTM organizes tactics and techniques specific to embedded systems, making it easy to add to existing security programs. It also covers emerging threats and weaknesses, helping organizations prepare for future risks. ESTM works with the MITRE EMB3D Threat Model to offer a complete resource for secure system design.

Source: MITRE

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post MITRE unveils Embedded Systems Threat Matrix appeared first on Intelligence Community News.

]]>
43655
Claroty and Mission IT partner https://intelligencecommunitynews.com/claroty-and-mission-it-partner/?utm_source=rss&utm_medium=rss&utm_campaign=claroty-and-mission-it-partner Mon, 22 Dec 2025 14:41:32 +0000 https://intelligencecommunitynews.com/?p=43466 On December 18, Claroty, a cyber-physical systems (CPS) protection company, announced that its partnership with Mission IT has resulted in Claroty...

The post Claroty and Mission IT partner appeared first on Intelligence Community News.

]]>
On December 18, Claroty, a cyber-physical systems (CPS) protection company, announced that its partnership with Mission IT has resulted in Claroty securing an Authority to Operate (ATO) for the Claroty Continuous Threat Detection (CTD) platform at multiple military missile defense sites, and a Facility Related Control System (FRCS) for a classified Intelligence Community, strengthening the cybersecurity posture of some of the nation’s most sensitive operational environments.

As a Claroty Reseller Partner, Mission IT has a proven record of successful deployments across Defense, Intelligence, and Federal Civilian agencies, ensuring all joint projects are executed by technical personnel with high-level security clearances and rigorous training in Claroty’s technology.

These successful deployments underscore the immediate value of the partnership, which combines Claroty’s deep expertise in OT and industrial control systems (ICS) security and comprehensive protection of mission-critical infrastructure with Mission IT’s cleared skilled personnel, technical expertise, and proven track record of deploying secure OT solutions. Building on this foundation, the two companies are expanding their joint efforts to support additional defense and intelligence missions, aligning with federal cybersecurity priorities such as Zero Trust architecture, EO 14028 implementation, and OT/IT convergence. By pairing advanced OT visibility and control with trusted deployment capabilities, the Claroty and Mission IT partnership is driving measurable risk reduction across critical infrastructure.

“Our partnership with Mission IT is already demonstrating its power to protect our nation’s most critical assets,” said Jen Sovada, general manager, public sector at Claroty. “By collaborating with Mission IT, Claroty is providing government customers with the operational and cyber resilience needed to defend our nation at scale, and we consider our valued relationship with Mission IT a clear symbol of our commitment to public service.”

“We’re thrilled to partner with Claroty and bring to government agencies a platform that focuses on their need for true risk reduction as they face a growing number of adversaries,” said Shawn Wells, CEO of Mission IT. “With production deployments across military weapon control systems, classified facility control systems, and other defense OT networks, we are helping federal customers defend against the most sophisticated threats targeting operational environments.”

Source: Claroty

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Claroty and Mission IT partner appeared first on Intelligence Community News.

]]>
43466
MITRE unveils D3FEND for OT https://intelligencecommunitynews.com/mitre-unveils-d3fend-for-ot/?utm_source=rss&utm_medium=rss&utm_campaign=mitre-unveils-d3fend-for-ot Fri, 19 Dec 2025 15:23:16 +0000 https://intelligencecommunitynews.com/?p=43448 On December 16, MITRE announced that it has extended its D3FEND cybersecurity ontology to operational technology (OT), creating a structured knowledge base for...

The post MITRE unveils D3FEND for OT appeared first on Intelligence Community News.

]]>
On December 16, MITRE announced that it has extended its D3FEND cybersecurity ontology to operational technology (OT), creating a structured knowledge base for defending cyber-physical systems. OT includes the controllers, sensors, and actuators that manage physical processes in critical infrastructure, industrial environments, and the defense systems that support service members in their missions. Unlike information technology, which handles data and communications, OT directly affects how machines and systems operate.

As organizations modernize, OT systems are connected to networks and the cloud. This improves efficiency but also introduces new cyber risks, since many OT components were never built for internet exposure. The D3FEND extension provides a common framework to help the cybersecurity community better understand, secure, and sustain these essential systems.

Funded by the Cyber Warfare Directorate in the U.S. Office of the Under Secretary of War for Acquisition and Sustainment and the National Security Agency, D3FEND is expanding into specific domains, including cyber-physical systems that create real-world effects through programmed actions. D3FEND for OT delivers a stable, extensible, and integration-friendly framework to support cybersecurity operations and strategic decision making in OT environments.

“Through D3FEND, we are advancing the cybersecurity frontier alongside the global community,” said Wen Masters, vice president, cyber technologies, MITRE. “As a not-for-profit organization dedicated to national security, we are strategically positioned to tackle complex, high-stakes challenges. The launch of D3FEND for OT demonstrates our unwavering commitment to delivering unbiased, open-sourced tools that are mission-critical.”

Source: MITRE

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post MITRE unveils D3FEND for OT appeared first on Intelligence Community News.

]]>
43448
NSA, FBI warn of pro-Russia Hacktivist threats https://intelligencecommunitynews.com/nsa-fbi-warn-of-pro-russia-hacktivist-threats/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-pro-russia-hacktivist-threats Mon, 15 Dec 2025 13:17:23 +0000 https://intelligencecommunitynews.com/?p=43400 On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and over 20 others to release the Cybersecurity Advisory (CSA), “Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure,” and provide recommended mitigations to reduce the likelihood and impact of related incidents.

The authoring agencies have observed pro-Russia hacktivist groups—attributed to the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—capitalizing on the widespread availability of inadequately secured virtual network computing (VNC) connections to infiltrate operational technology (OT) control devices within critical infrastructure systems and conduct cyber operations against organizations worldwide.

The groups’ ongoing opportunistic targeting methodology can lead to broad targeting and indiscriminate compromise of critical infrastructure entities, including those in Water and Wastewater, Food and Agriculture, and the Energy Sector. Further, their observed lack of strategic focus increases the likelihood of targeting of unintended victims, and tends to result in haphazard attacks with unanticipated damages.

These actors are primarily seeking notoriety with their actions, regularly self-attributing and exaggerating cyberattacks on social media and in group channels to garner attention from peers and the media. Despite this, and their lack of sophisticated ability, actors have been observed willfully causing damage to vulnerable critical infrastructure.

These actors utilize simple, cheap, and easy-to-replicate tactics, techniques, and procedures (TTPs) for the ease of dissemination and replication across various entities, increasing the risk of wide-spread adoption by other cyber actors and escalated frequency of attacks. The authoring agencies warn there is risk that continued attacks may result in further harm or consequences.

Critical infrastructure entities, OT asset owners and operators, and OT device manufactures are encouraged to become familiar with the outlined TTPs and apply the recommended mitigation strategies to reduce the likelihood and impact of incidents related to pro-Russia hacktivists. The report also provides incident response actions organizations should take if compromise is detected.

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
43400
Empower AI secures CI modernization contract https://intelligencecommunitynews.com/empower-ai-secures-ci-modernization-contract/?utm_source=rss&utm_medium=rss&utm_campaign=empower-ai-secures-ci-modernization-contract Fri, 10 Oct 2025 12:09:39 +0000 https://intelligencecommunitynews.com/?p=42906 On October 9, Empower AI announced that it has been awarded a contract valued at more than $200 million by...

The post Empower AI secures CI modernization contract appeared first on Intelligence Community News.

]]>
On October 9, Empower AI announced that it has been awarded a contract valued at more than $200 million by the U.S. Army Information Systems Engineering Command (ISEC) Mission Engineering Directorate (MED) to support the Army Metering Program (AMP). The program is managed under U.S. Army Materiel Command (AMC) through the TEIS IV contract vehicle. This multi-year effort will modernize critical infrastructure across more than 80 Army installations, enhancing energy resilience, enabling real-time analytics, and strengthening operational readiness objectives across the enterprise.

Empower AI will lead nationwide Engineering, Furnishing, Installation, and Testing (EFI&T) efforts to modernize and secure the Army’s operational technology environments, including energy and water metering, Industrial Control Systems, Facility-Related Control Systems (FRCS), and SCADA systems. The company will deliver secure, standards-compliant solutions with full lifecycle support from procurement and configuration to cybersecurity compliance (including RMF and CMMC), integration, fielding, and sustainment of thousands of meters and monitoring devices.

“Readiness depends on resilient infrastructure that provides the Army with the real-time visibility needed to anticipate and respond to operational demands,” said Jeff Bohling, CEO of Empower AI. “Through this program, we will strengthen the Army’s energy resilience, accelerate modernization, and deliver secure, scalable solutions that drive mission success.”

Empower AI’s proven record of success in complex Army environments, combined with deep experience supporting NETCOM and AMC missions, positions the company to accelerate deployment and deliver mission-critical performance outcomes. Empower AI integrates predictive analytics into infrastructure monitoring to help Army operators anticipate equipment failures, identify risks, and sustain operational readiness.

The company’s AI-driven capabilities support proactive maintenance and resilient, modernized operations across the enterprise, always delivered in alignment with Army approval, oversight, and requirements.

“We are deeply aligned with the Army’s mission and committed to delivering solutions that strengthen capabilities and accelerate mission success. Our team is ready to execute with precision, resilience, and urgency,” said Darryl Jackson, vice president and general manager of the Military Services Business Unit at Empower AI.

Source: Empower AI

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post Empower AI secures CI modernization contract appeared first on Intelligence Community News.

]]>
42906
China state-sponsored actors targeting CI orgs, according to NSA https://intelligencecommunitynews.com/china-state-sponsored-actors-targeting-ci-orgs-according-to-nsa/?utm_source=rss&utm_medium=rss&utm_campaign=china-state-sponsored-actors-targeting-ci-orgs-according-to-nsa Thu, 28 Aug 2025 10:36:28 +0000 https://intelligencecommunitynews.com/?p=42543 On August 27, the National Security Agency (NSA) and other U.S. and foreign organizations released a joint Cybersecurity Advisory to expose...

The post China state-sponsored actors targeting CI orgs, according to NSA appeared first on Intelligence Community News.

]]>
On August 27, the National Security Agency (NSA) and other U.S. and foreign organizations released a joint Cybersecurity Advisory to expose advanced persistent threat (APT) actors sponsored by the Chinese government targeting telecommunications, government, transportation, lodging, and military infrastructure networks globally and outline appropriate mitigation guidance.

The malicious activity outlined in the advisory partially overlaps with cybersecurity industry reporting on Chinese state-sponsored threat actors referred to by names such as Salt Typhoon.

These activities have been linked to multiple China-based entities—including Sichuan Juxinhe Network Technology Co. Ltd., Beijing Huanyu Tianqiong Information Technology Co., Ltd., and Sichuan Zhixin Ruijie Network Technology Co., Ltd.—which provide cyber products and services to China’s Ministry of State Security and People’s Liberation Army.

The CSA, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,” details specific tactics, techniques, and procedures (TTPs) these actors have been found using for initial exploitation, persistence, collection, and exfiltration. Indicators of compromise (IOCs) and common vulnerabilities and exposures (CVEs) exploited by the APT actors are also detailed.

Further, the report provides threat hunting guidance and specific mitigations that organizations are encouraged to implement to search for malicious activity and reduce the threat of Chinese state-sponsored and other APT actors. These recommendations are especially important for network defenders of telecommunications and critical infrastructure organizations to discover unknown intrusions and prevent undetected malicious activity on their networks. By utilizing the outlined guidance, organizations can also better provide compromise details to appropriate authorities to continue improving all parties’ understanding of initial access methods.

When threat hunting, the authoring agencies advise that organizations gain a full understanding of the APT actors’ accesses before implementing visible incident response and mitigation actions to maximize the chance of achieving full eviction from compromised networks.

This CSA is being released by the following authoring and co-sealing agencies:

  • United States National Security Agency (NSA)
  • United States Cybersecurity and Infrastructure Security Agency (CISA)
  • United States Federal Bureau of Investigation (FBI)
  • United States Department of Defense Cyber Crime Center (DC3)
  • Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
  • Canadian Centre for Cyber Security (Cyber Centre)
  • Canadian Security Intelligence Service (CSIS)
  • New Zealand National Cyber Security Centre (NCSC-NZ)
  • United Kingdom National Cyber Security Centre (NCSC-UK)
  • Czech Republic National Cyber and Information Security Agency (NÚKIB)
  • Finnish Security and Intelligence Service (SUPO)
  • Germany Federal Intelligence Service (BND)
  • Germany Federal Office for the Protection of the Constitution (BfV)
  • Germany Federal Office for Information Security (BSI)
  • Italian External Intelligence and Security Agency (AISE)
  • Italian Internal Intelligence and Security Agency (AISI)
  • Japan National Cyber Office (NCO)
  • Japan National Police Agency (NPA)
  • Netherlands Defence Intelligence and Security Service (MIVD)
  • Netherlands General Intelligence and Security Service (AIVD)
  • Polish Military Counterintelligence Service (SKW)
  • Polish Foreign Intelligence Agency (AW)
  • Spain National Intelligence Centre (CNI)

 

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post China state-sponsored actors targeting CI orgs, according to NSA appeared first on Intelligence Community News.

]]>
42543
Booz Allen invests in Corsha https://intelligencecommunitynews.com/booz-allen-invests-in-corsha/?utm_source=rss&utm_medium=rss&utm_campaign=booz-allen-invests-in-corsha Mon, 14 Jul 2025 14:01:17 +0000 https://intelligencecommunitynews.com/?p=42165 On July 10, Booz Allen Hamilton announced that its corporate venture capital arm, Booz Allen Ventures, has made a strategic investment...

The post Booz Allen invests in Corsha appeared first on Intelligence Community News.

]]>
On July 10, Booz Allen Hamilton announced that its corporate venture capital arm, Booz Allen Ventures, has made a strategic investment in Corsha, the first and only Machine Identity Provider (mIDP) built to secure communication across operational systems and critical infrastructure. This investment will accelerate the use of advanced technology solutions to reinforce U.S. defenses against increasingly sophisticated and frequent cyberattacks.

Operating in demanding environments and working with key partners such as the U.S. Air Force, Corsha uses multi-factor authentication to secure machine-to-machine communication and proactively defend against emerging cyber threats. Corsha leverages advanced behavioral analytics to detect unusual patterns and spot potential threats, blocking adversaries’ access to American operational technology (OT), including within domestic defense manufacturing and other U.S. critical infrastructure.

“The physical world is increasingly hyperconnected and software defined, leaving military installations, civilian critical infrastructure, and other hubs of economic and national security at risk of cyber disruption,” said David Forbes, director of cyber-physical defense at Booz Allen. “Addressing identity verification challenges is a critical step towards creating more resilient systems.  We invested in Corsha because we believe their technology can solve the identity problem and because we expect securing the physical world to be a significant growth vector in the cyber market.”

This investment reinforces Booz Allen’s commitment to innovation as the leading provider of AI and cybersecurity to the federal government.

“Our patented identity technology is instrumental in bringing zero trust to our nation’s critical infrastructure, preventing malicious activity at its onset and safeguarding national security,” said Anusha Iyer, CEO at Corsha. “Cyberattacks targeting our nation and critical operational systems are ever more frequent and advanced. With the support of Booz Allen, we are addressing the toughest cybersecurity challenges to enable faster, safer U.S. operations and advancement.”

Booz Allen will work with Corsha to expand the portfolio company’s research and development lab, scale its AI and machine learning capabilities, and support the advancement of Corsha’s operations in critical manufacturing environments to deliver mission outcomes.

“Corsha stands out for its technical depth, mission focus, and elegant solution to a growing problem in operational cybersecurity,” said Chris Woods, investor at Booz Allen Ventures. “We are excited to tap into Corsha’s broad application in the non-human identity space and it’s clear that Booz Allen believes the company is well-positioned to become foundational security infrastructure for next-generation mission systems.”

Source: Booz Allen

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

The post Booz Allen invests in Corsha appeared first on Intelligence Community News.

]]>
42165
NSA publishes recommendations for making national security-related software understandable https://intelligencecommunitynews.com/nsa-publishes-recommendations-for-making-national-security-related-software-understandable/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-publishes-recommendations-for-making-national-security-related-software-understandable Fri, 17 Jan 2025 15:32:28 +0000 https://intelligencecommunitynews.com/?p=40749 On January 16, the National Security Agency (NSA), the Cybersecurity and Infrastructure Agency (CISA), the Defense Advanced Research Projects Agency...

The post NSA publishes recommendations for making national security-related software understandable appeared first on Intelligence Community News.

]]>
On January 16, the National Security Agency (NSA), the Cybersecurity and Infrastructure Agency (CISA), the Defense Advanced Research Projects Agency (DARPA), and the Office of the Under Secretary of Defense for Research and Engineering (OUSD R&E) published a report that urges a national effort to better understand the behavior of software underpinning national security and critical infrastructure systems.

The Cybersecurity Information Sheet (CSI), “Closing the Software Understanding Gap,” points to the need for policy action, technical innovation, and resources to help systems owners and operators better construct and assess their software-controlled systems across all conditions – normal, abnormal, and hostile.

“A lack of understanding of software imposes risks on many critical systems that are dependent on software to run properly and as intended,” said Neal Ziring, NSA Research Technical Director. “This report is a national call for the government and private sectors to work together to prioritize understanding software as a national effort critical to the nation’s success in the future.”

Currently, the nation’s ability to build software outstrips its ability to understand it, leaving systems vulnerable to exploitation, the CSI states. Undiscovered behavior in software has exposed critical vulnerabilities in aircraft, military systems, and supply chains and impacted national security objectives, with the CSI citing numerous examples.

The CSI outlines a call to action to address gaps in software understanding through:

  • Policy action – As technical capabilities mature, policy needs to evolve to require and formalize processes for characterizing software behavior before it is introduced into critical systems.
  • Technical innovation – Technical capabilities for measuring software and reasoning about its behavior need to be developed to reduce risk. All suitable techniques, including formal methods and artificial intelligence, should be leveraged to develop rigorous, reliable, rapid, and inexpensive capabilities.
  • ​Resources – Significant sustained investments in research, development, and engineering are needed to support a unified set of software understanding capabilities. Public and private partnerships with industry should also be explored to ensure practical and efficient solutions that can be leveraged across missions and diverse systems.

 

Read the full report here.

Source: NSA

Start 2025 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 13,000+ articles, plus new articles each weekday.

The post NSA publishes recommendations for making national security-related software understandable appeared first on Intelligence Community News.

]]>
40749