Tag: compliance
373 articles

AI Reshapes Federal eDiscovery to Meet Surging FOIA Demands
Federal agencies are struggling to keep up with a surge in FOIA requests that are not only increasing in volume but also growing more complex, involving large volumes of electronic records, multiple custodians, and sensitive data. This perfect storm is putting a strain on legacy eDiscovery systems and already limited staff, all while meeting a strict 20-day deadline.

Federal Agencies Rethink Security with Continuous Authorization
Federal agencies are shaking up their security approach with continuous authorization, recognizing that a system's security can't be judged by its paperwork alone. By treating compliance as a stepping stone to mission success, agencies can deliver secure outcomes faster, without sacrificing speed for security.

CMMC Pause Doesn't Halt Compliance Imperative
The pause on CMMC Phase 2.0 doesn't let you off the compliance hook - you still need to prioritize protecting controlled unclassified information (CUI) within your environment. Keep moving forward with necessary security measures to ensure CUI protection, as requirements remain in place despite validation delays.

NIST Identifies Security Gaps in Multi-Cloud Environments
NIST warns that multi-cloud environments, which use two or more cloud service providers, pose unique cybersecurity and compliance risks, despite helping organizations reduce reliance on a single provider and maintain operations during outages or cyber-attacks. A recent NIST report aims to tackle these challenges by providing a structured problem statement and shared vocabulary to inform future research and solution design.

TikTok Settles Child Privacy Suit for $400 Million
TikTok is paying a whopping $400 million to settle a lawsuit alleging it broke US child privacy laws, in a major win for American kids and parents. The deal, secured by the US Department of Justice, marks one of the largest recoveries ever under the Children's Online Privacy Protection Act.

IAM Compliance Requires Verified Enforcement
To truly achieve IAM compliance, it's not enough to just have policies in place - you need to prove that they're being enforced. The real challenge lies in bridging the gap between policy intent and actual runtime execution, where compliance failures and unmanaged access often hide.

Anthropic Embeds Watermarks in AI-Generated Text
Anthropic is taking a proactive approach to transparency with AI-generated text by embedding watermarks globally, ensuring accountability and compliance with regulations like the EU AI Act. This innovative technique, inspired by Google DeepMind's research, helps distinguish AI-created content from human-written text.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations
The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

LexisNexis Disrupts Services Amid Server Breach Probe
LexisNexis swiftly pulled the plug on three key services - Nexis Diligence, Metabase API, and Newsdesk - after detecting suspicious activity on servers managed by a third-party vendor, taking swift action to safeguard customers and contain the breach. The move comes as the company investigates the unusual server activity.

Zero-Knowledge Proofs Offer Secure Path for Cyber Risk Disclosure
ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

Pentagon Moves to Ease Industry Burden on Critical Mineral Restrictions
The Pentagon is giving industries a break, offering a phased approach to ease restrictions on critical minerals sourced from China and other prohibited countries, with a deadline to adapt by early 2027. They're also pledging to collaborate with companies to ensure a smooth transition.

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence
FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Pentagon Scraps Cybersecurity Certification Phase, Launches Reform Review
The Department of Defense is shaking things up in the world of cybersecurity certification, suspending Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day review to explore a more streamlined approach. This move aims to ease compliance burdens, especially for small and medium-sized businesses.

Pentagon Hits Pause on Cybersecurity Certification Requirements
The Pentagon has hit pause on its cybersecurity certification requirements, citing prohibitive compliance costs and bureaucratic burdens that could stifle innovation in the US defense industrial base. This 60-day suspension sparks a review that may reshape enforcement and acquisition rules for defense contractors.

Federal Agencies Modernize Security with Zero Trust Architecture
Federal agencies are revolutionizing their security approach with Zero Trust Architecture, shifting from mere compliance to a robust operational framework that enables seamless mobility, cloud modernization, and AI-driven decision making. By embracing this cutting-edge strategy, leaders are transforming their organizations to stay ahead of emerging threats.

Australia Shifts Cybersecurity Focus to Resilience Over Compliance
Australia is taking a bold step in cybersecurity, shifting its focus from mere compliance to building operational resilience, with a AU$89.3 million investment over four years to drive this change. The Horizon 2 Action Plan is set to boost the nation's cyber posture with 19 key actions and 64 initiatives.

US Datacenter Law Set to Lapse, Leaving Security Gaps Unaddressed
As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

Open Source Community Unprepared for EU's Cyber Resilience Act
The open source community is lagging behind on cybersecurity readiness, with stagnating awareness and a lack of preparedness for the EU's Cyber Resilience Act, which requires minimum security standards for hardware and software products by December 2027. It's time for urgent action to avoid falling short of compliance.

Varonis Integrates Claude Compliance API for Enhanced AI Governance
Varonis has integrated the Claude Compliance API into its Atlas AI Security Platform, empowering enterprises to confidently adopt AI with enhanced governance and oversight. This integration enables security teams to monitor AI usage, detect misuse, and assess risks with unparalleled data context.

AI-Powered Tools Elevate Vulnerability Detection, Pressing Secure-by-Design Mandate
With AI-powered tools, companies can now instantly detect and fix software vulnerabilities, making ignorance a thing of the past when it comes to cybersecurity. As Hans de Vries of ENISA notes, this shift makes a secure-by-design approach not just best practice, but a pressing mandate.

Autonomous AI Exposes Governance Gaps in Enterprise Security
As autonomous AI revolutionizes enterprise security, it's also revealing alarming governance gaps that can leave organizations in highly regulated environments exposed to unprecedented risks. The rapid adoption of autonomous AI is creating a trust gap, where innovation outpaces control, and novel risks to visibility, control, and regulatory compliance are emerging.

FIS and Anthropic Unveil AI to Accelerate Money Laundering Probes
Imagine having an AI-powered ally that supercharges your money laundering investigations, automatically gathering evidence, detecting patterns, and prioritizing case files in minutes - not days. FIS and Anthropic have joined forces to bring you the Financial Crimes AI Agent, revolutionizing banking's most costly compliance challenge.

Digital KYC Push Stalls on Trust and Liability Concerns
KYC is more than just verifying identity - it's a crucial process that requires trust and accuracy to prevent financial crimes. Governments and banks are working together to modernize identity data collection and reuse, with countries like the UAE, Europe, and Singapore launching innovative projects to streamline compliance and strengthen anti-money laundering efforts.

Fintech Firm Exposes Database Credentials in Shared Spreadsheet
A fintech firm's most sensitive secrets were left exposed in a shared spreadsheet, with a password that was embarrassingly simple - literally a combination of the company's name and the year. The shocking discovery was made by Stanislav Kazanov during a routine compliance audit, when he stumbled upon a widely accessible SharePoint folder containing a file ominously titled Prod_DB_Root_Creds_DO_NOT_SHARE.xlsx.