Tag: government regulations
25 articles

Federal Agencies Rethink Security with Continuous Authorization
Federal agencies are shaking up their security approach with continuous authorization, recognizing that a system's security can't be judged by its paperwork alone. By treating compliance as a stepping stone to mission success, agencies can deliver secure outcomes faster, without sacrificing speed for security.

Pentagon Memo Reshapes Contractor Data Disclosure Rules
A new Pentagon memo is shaking up data disclosure rules for contractors, forcing them to rethink their approach at a time when AI innovation is taking center stage. This game-changing update intersects with emerging tech developments, sparking key questions for contractors, reporters, and military technologists.

Sharpening Cybersecurity Standards
Don't let your guard down now - Katie Arrington stresses that now is not the time to relax cybersecurity standards, especially after self-attestation failed to protect the war industrial base. The Cybersecurity Maturity Model Certification was created to ensure verification and accountability.

NIST Seeks Input on NVD Overhaul Amid AI-Driven Cybersecurity Shift
The US government's quest to modernize the National Vulnerability Database is underway, and it's seeking your input - with an October 13 deadline to share innovative ideas on how to bring this critical cybersecurity resource into the automation age. NIST wants to hear your forward-looking perspectives on how to scale the NVD and supercharge its support for automated security workflows.

White House Charts Course to Secure AI with Flexible Framework
The White House is taking a bold step towards securing AI, with National Cyber Director Sean Cairncross emphasizing the importance of speed, adaptability, and partnership with private-sector defenders to protect the country's systems. By striking a balance between responsible use, security, and mutual benefit, the administration aims to foster a flexible framework that prioritizes collaboration over regulation.

CMMC Pause Spurs Urgent Gap Assessments
The Department of Defense's sudden pause on CMMC Phase 2 has created an urgent need for gap assessments, especially for small and non-traditional businesses struggling to meet compliance requirements. This 60-day review aims to ease the burden, but existing obligations, including Phase 1 self-assessment requirements, remain in force.

US Government Accelerates Post-Quantum Cryptography Transition
The US government is taking a proactive approach to stay ahead of emerging threats by accelerating its transition to post-quantum cryptography, a critical step in safeguarding federal systems against advanced cryptographic attacks. A new Executive Order is driving this effort, requiring federal agencies to rapidly adopt this next-generation security measure.

Trump Administration Seeks to Revive Mail-In Voting Restrictions
The Trump administration is pushing to revive restrictions on mail-in voting, with the Solicitor General asking the Supreme Court to allow an executive order to take effect, potentially reshaping how Americans cast their ballots in the November midterms. The order, signed in March, aims to tighten mail-in voting rules and verify voter eligibility.

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence
FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Pentagon Hits Pause on Cybersecurity Certification Requirements
The Pentagon has hit pause on its cybersecurity certification requirements, citing prohibitive compliance costs and bureaucratic burdens that could stifle innovation in the US defense industrial base. This 60-day suspension sparks a review that may reshape enforcement and acquisition rules for defense contractors.

CISA Mandates Patching of Exploited Adobe ColdFusion Flaw
Adobe has issued a warning to patch a critical flaw, CVE-2026-48282, in ColdFusion versions 2025.9, 2023.20, and earlier, as attackers have already begun exploiting it just two hours after disclosure. Admins are urged to deploy the updates within 72 hours to prevent code execution on unpatched systems.

Credentials Face Quantum Threat Decades Ahead
The NSA has set a critical deadline: by January 1, 2027, new national security systems must support quantum-resistant algorithms to stay ahead of emerging threats. With deadlines stretching into the 2030s, organizations must plan now to protect their systems from the looming quantum threat.

Federal Agencies Pursue Secure AI With Data Clarity, Infrastructure Overhaul
The harsh reality is that most organizations are flying blind when it comes to their data, with little insight into what they have, where it's stored, or if it's properly secured. This knowledge gap is a major hurdle for federal agencies looking to harness the power of AI while keeping sensitive data safe.

US Datacenter Law Set to Lapse, Leaving Security Gaps Unaddressed
As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

CISA Overhauls Vulnerability Patching with Smarter Prioritization Directive
The Cybersecurity and Infrastructure Security Agency (CISA) has rolled out a game-changing directive that revolutionizes vulnerability patching with a smarter approach to prioritization, empowering federal agencies to tackle fixes more efficiently. By introducing clear guidelines and timelines, CISA is helping agencies focus on the most critical patches first, based on criteria like exposure, exploitability, and real-world threat activity.

CISA Directive Overhauls Cyber Risk Prioritization Across Agencies
The Cybersecurity and Infrastructure Security Agency is shaking up its approach to cyber risk with a new directive that prioritizes impact over raw vulnerability counts, helping agencies focus on protecting what matters most. Acting director Nick Andersen urges a pragmatic approach, acknowledging that some systems are more critical than others.

Lawmakers Press Army for Detailed Transformation Plans
Congress is pushing the Army for a clearer roadmap to achieve its transformation goals, with Rep. Mike Rogers bluntly stating that the Army hasn't done its homework. The House Armed Services Committee has now mandated an annual report and briefing from the Army to keep lawmakers in the loop.

NIST's Vulnerability Database Plagued by Duplication, Inefficiency
The National Vulnerability Database is facing a massive backlog crisis, with unprocessed security flaws doubling from 13,000 in June 2024 to over 27,000 by the end of 2025, and officials admit they lack a long-term plan to tackle the problem. Despite promising to clear the backlog by September 2024, the database continues to struggle with inefficiencies and a lapsed contract.

OPM Proposes Sweeping NDA Rule for Federal Employees
The Office of Personnel Management wants to shake up the way federal employees handle confidential information, proposing a new nondisclosure agreement rule that would require all employees to sign a pledge protecting internal agency details. If implemented, the rule could have far-reaching implications for whistleblowing and employee accountability.

House Panel Targets Defense Industrial Base in $1.15T Policy Bill
The House Armed Services Committee's draft defense policy bill aims to bolster the Defense Industrial Base, driven by a stark reality: the US no longer has the capacity to rapidly produce war-fighting capabilities at scale. A $1.15 trillion spending plan is on the table, but a separate $350 billion request remains a crucial wildcard.

UK Cybersecurity Market Booms as Government Targets Enhanced Resilience
The UK's cybersecurity market is thriving, generating £14.7bn in revenue and supporting nearly 70,000 jobs, with the government investing in its own defenses and setting national standards to boost resilience. This booming sector has seen a 20% surge in cybersecurity firms, now totaling 2,603, and a 17% annual increase in gross value added.

Vought Targets Shipbuilders with OMB Rebuke at Sea Air Space
In a stunning move, Office of Management and Budget chief Russel Vought took aim at the shipbuilding industry during the Navy League's Sea Air Space conference, delivering a sharp rebuke that made headlines. His bold intervention marked a dramatic close to the annual gathering.

European Firms Launch Sovereign Disaster Recovery Offering
Four European tech firms have teamed up to offer a game-changing solution: a fully sovereign disaster recovery pack that lets businesses safeguard their critical technology from external threats, giving them peace of mind in an uncertain world. This innovative stack is designed to sit on corporate premises, shielding users from potential disruptions and ensuring business continuity.

CISA Pushes AI Firms to Join Vulnerability Disclosure Efforts
The Cybersecurity and Infrastructure Security Agency (CISA) is calling on AI companies to take a more active role in disclosing vulnerabilities, sparking a crucial conversation about who's responsible for revealing flaws in AI systems. By joining forces, CISA and AI firms can work together to strengthen vulnerability disclosure efforts and protect against potential threats.