Tag: nist framework
5 articles

CISA Overhauls CVE Program with Quality-Focused Framework
The CVE Program is getting a major overhaul with a quality-focused framework, marking a new era of prioritizing reliability, responsiveness, and top-notch vulnerability data. CISA is leading the charge by defining quality across four key dimensions: program governance, ecosystem participation, data infrastructure, and CVE record content.

Microsoft Unveils Record 974 CVE Fixes in September Patch Tuesday Release
This September Patch Tuesday release is a doozy, with a record 974 CVEs fixed - a staggering number that more than doubles the previous record and demands immediate attention from IT and security teams. The challenge is clear: prioritize and patch with lightning speed to stay ahead of potential threats.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations
The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

US Agencies Shift Focus to Cyber Resilience
The US Department of Defense is overhauling its cyber defense strategy, shifting towards a holistic approach that emphasizes cyber resilience, enterprise modernization, and operational effectiveness. Chief Information Officer Kirsten Davies is leading the charge, driving practical reforms to boost automation, streamline processes, and strengthen cybersecurity across the department.

CISA Overhauls Vulnerability Patching with Smarter Prioritization Directive
The Cybersecurity and Infrastructure Security Agency (CISA) has rolled out a game-changing directive that revolutionizes vulnerability patching with a smarter approach to prioritization, empowering federal agencies to tackle fixes more efficiently. By introducing clear guidelines and timelines, CISA is helping agencies focus on the most critical patches first, based on criteria like exposure, exploitability, and real-world threat activity.