CISA Releases New Sector Specific Goals for IT and Product Design

Originally published CISA Releases New Sector Specific Goals for IT and Product Design on by https://www.hstoday.us/subject-matter-areas/cybersecurity/cisa-releases-new-sector-specific-goals-for-it-and-product-design/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-new-sector-specific-goals-for-it-and-product-design at Homeland Security

Cybersecurity business information protection technology, privacy to protect personal data, lock icon and internet network security connection technology.

The Cybersecurity and Infrastructure Security Agency (CISA) released new voluntary cybersecurity performance goals for the information technology (IT) and product design sector on January 7. The IT Sector Specific Goals (SSGs) are aligned to Secure by Design principles and will help to protect the sector from cyber incidents, identify and address vulnerabilities prior to product release, improve incident response, and significantly improve software security. CISA worked extensively with the IT Sector Coordinating Council (IT SCC) to develop these goals. Through the IT SCC, subject matter experts, associations, and other key partners provided critical, beneficial input and supported the development process.

While specific to the IT sector, the goals provide software and product developers in all critical infrastructure sectors with minimum foundational practices upon which they should focus their efforts. Recommended actions include:

  • Logically separate all software development environments from each other using controls such as network segmentation and access controls.
  • Regularly log, monitor, and review trust relationships used for authorization and access across software development environments.
  • Require multi-factor authentication (MFA)—ideally phishing resistant MFA—to access all software development environments.
  • Establish and enforce security requirements for software products used across software development environments.
  • Do not store sensitive data or credentials in source code. Instead, store sensitive data and credentials in an encrypted manner, such as using a secret manager.
  • Establish a software supply chain risk management program

“The IT SSGs help critical infrastructure sectors significantly strengthen cybersecurity in the design and development of software and hardware. We encourage organizations to review and implement the goals which will benefit and protect the supply chain including consumers,” said CISA Director Jen Easterly, “The industry collaboration was critical to shaping goals with highest-impact and guiding organizations to prioritize their efforts. We applaud organizations that are choosing to take ownership of the security outcomes of their customers.”

CISA encourages product developers to adopt these SSGs to significantly improve the cybersecurity posture of software products, to include those designed for critical infrastructure services, relied upon by our nation. For more information, visit Cybersecurity Performance Goals on CISA.gov.

The original announcement can be found here.

The post CISA Releases New Sector Specific Goals for IT and Product Design appeared first on HSToday.

Originally published CISA Releases New Sector Specific Goals for IT and Product Design on by https://www.hstoday.us/subject-matter-areas/cybersecurity/cisa-releases-new-sector-specific-goals-for-it-and-product-design/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-new-sector-specific-goals-for-it-and-product-design at Homeland Security

Originally published Homeland Security

Related Posts

CISA Releases New Sector Specific Goals for IT and Product Design

The Cybersecurity and Infrastructure Security Agency (CISA) released new voluntary cybersecurity performance goals for the information technology (IT) and product design sector
The post CISA Releases New Sector Specific Goals for IT and Product Design appeared first on HSToday.

Raiza Basilio Joins US AI as Vice President, Federal

Raiza Basilio has joined US AI as Vice President, Federal, bringing over 16 years of experience in government contracting, data science, and cutting-edge IT programs.
The post Raiza Basilio Joins US AI as Vice President, Federal appeared first on HSToday.

About Us
woman wearing glasses

To assist commercially facing small and startup technology companies, and help determine if there is value in engaging with defense, intelligence community.

Let’s Socialize

Popular Post