edge devices Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/edge-devices/ Breaking news about the market for products, systems and services for the U.S. intelligence community Thu, 12 Feb 2026 12:44:04 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg edge devices Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/edge-devices/ 32 32 59882712 CISA releases directive on edge device risk mitigation https://intelligencecommunitynews.com/cisa-releases-directive-on-edge-device-risk-mitigation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-directive-on-edge-device-risk-mitigation Thu, 12 Feb 2026 12:44:04 +0000 https://intelligencecommunitynews.com/?p=43839 The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy...

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy of the American people. These campaigns are often enabled by unsupported devices that physically reside on the edge of an organization’s network perimeter. Unsupported devices – referred to in this Directive as “end of support (EOS)” – are those that are no longer maintained by their vendors.

The imminent threat of exploitation to agency information systems running EOS edge devices is substantial and constant, resulting in a significant threat to federal property. CISA is aware of widespread exploitation campaigns by advanced threat actors targeting EOS edge devices. Recent public reports of campaigns targeting certain vendors highlight actors’ attempts to use these devices as a means to pivot into FCEB information system networks. Edge devices are attractive targets due to their extensive reach into an organization’s network and integrations with identity management systems. These devices are especially vulnerable to cyber exploits targeting newly discovered, unpatched vulnerabilities. Additionally, they no longer receive supported updates from the original equipment manufacturer, exposing federal systems to disproportionate and unacceptable risks. However, unlike many attack vectors, this can be remediated by agencies following proven lifecycle management practices as outlined in the required actions of this Directive.

This Binding Operational Directive, developed in coordination with OMB, implements OMB policy on phasing out unsupported information systems and information system components. BOD 26-02 specifically addresses EOS devices deployed on the “edge” or public-facing areas of federal networks, exposed to external environments such as the internet. However, EOS devices should not reside anywhere on federal networks. This Directive aligns with OMB’s Circular A-1301Managing Information as a Strategic Resource, which establishes policy for the management of federal information resources, emphasizing security, privacy, and the efficient use of resources throughout their lifecycle. A-130 requires that “unsupported information systems and system components are phased out as rapidly as possible, and planning and budgeting activities for all IT systems and services incorporate migration planning and resourcing to accomplish this requirement.”2 Agencies should mature their lifecycle management practices to identify hardware and software nearing their EOS dates, plan for timely replacements, procure vendor-supported alternatives, and develop a plan for decommissioning EOS devices while minimizing disruptions to agency operations. Agencies that do not maintain appropriate lifecycle management processes for edge devices have a greater risk of compromise and an increased overall risk associated with EOS technology.

To support agencies in the initial identification of EOS devices, CISA developed an EOS Edge Device List. This preliminary repository provides information on devices that are already EOS or soon-to-be EOS. This Directive requires federal agencies to use this information to identify and remediate vulnerabilities within the first three months of Directive issuance. This Directive also specifies long-term requirements for managing EOS edge devices across all federal networks.

Review the directive from CISA.

Source: CISA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
43839
NSA and partners advise on edge device mitigation strategies https://intelligencecommunitynews.com/nsa-and-partners-advise-on-edge-device-mitigation-strategies/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-partners-advise-on-edge-device-mitigation-strategies Wed, 05 Feb 2025 13:41:35 +0000 https://intelligencecommunitynews.com/?p=40895 On February 4, the National Security Agency (NSA) announced that it has joined the Australian Signals Directorate’s Australian Cyber Security...

The post NSA and partners advise on edge device mitigation strategies appeared first on Intelligence Community News.

]]>
On February 4, the National Security Agency (NSA) announced that it has joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (CCCS), and others to release three guides Cybersecurity Information Sheets (CSIs) that highlight critically important mitigation strategies for securing edge device systems, including firewalls, routers, and virtual private network (VPN) gateways.

Collectively, these reports – “Mitigation Strategies for Edge Devices: Executive Guidance,” “Mitigation Strategies for Edge Devices: Practitioners Guidance,” and “Security Considerations for Edge Devices” – provide a high level summary of existing guidance for securing edge devices, with comprehensive recommendations for tactical, operational, and strategic audiences to enhance network security and improve resilience against cyber threats.

“Edge devices act as boundaries between organizations’ internal enterprise networks and the Internet; if left unsecured, even unskilled malicious cyber actors have an easier time finding and exploiting vulnerabilities in their software or configurations,” said Eric Chudow, an NSA cybersecurity vulnerability analysis subject matter expert. “As organizations scale their enterprises, even though securing all devices is important, prioritizing edge device security is vital to defend the many endpoints, critical services, and sensitive data they protect.”

The guide, “Mitigation Strategies for Edge Devices: Executive Guidance” is intended for executives within large organizations and critical infrastructure sectors responsible for the deployment, security, and maintenance of enterprise networks. It outlines seven key mitigation strategies for managing and securing edge devices within traditional network architectures:

  1. Know the edge
  2. Procure secure-by-design devices
  3. Apply hardening guidance, updates, and patches
  4. Implement strong authentication
  5. Disable unneeded features and ports
  6. Secure management interfaces
  7. Centralize monitoring for threat detection

 

The companion guide, “Mitigation Strategies for Edge Devices: Practitioners Guidance,” is written for operational, cybersecurity, and procurement staff and provides an overview of what edge devices are; risks and threats to them; relevant frameworks and controls by some of the authoring nations; and a more in depth discussion on the seven mitigation strategies. Additionally, the report includes a case study of a successful exploitation to show how malicious actors compromise edge devices when they are not secured properly and to highlight further how edge devices are critical to the security of a network.

Expanding on the other reports, the “Security Considerations for Edge Devices” guidance details threats to edge devices from common malicious techniques and ways organizations can reduce the risk of compromise with mitigation recommendations. The publication also outlines factors organizations should consider when evaluating the security of edge devices, along with recommendations for edge device manufacturers to improve the built-in and default security of devices they produce.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post NSA and partners advise on edge device mitigation strategies appeared first on Intelligence Community News.

]]>
40895