The Security Policy and Standards Landscape is Changing – What Developers Need to Know | DevOps Connect 2022
Amit Elazari of Intel Corp, Cherilyn Pascoe of NIST, Jeffrey Rothblum of Senate Homeland Security and Governmental Affairs Committee and Kate Stewart of Linux Foundation take the stage at DevOps Connect 2022 to cover the key takeaways and insights for developers on emerging regulatory topics.
Transcript
So we have an exciting panel for you here today, and we're gonna be talking about security policy and standards development and specifically how do they impact and apply to developers what the technical experts in the community here with us in the room need to know and we have a amazing lineup of experts here from both standards and government and Industry and they're gonna go ahead and and introduce themselves. I'm joined here joined here with cherry over here from nest. And then of course Jeff from Senate Homeland Security and government Affairs committee.
He's Gap phone Congress and Kate from the Linux Foundation. I'm Amita lazari. I do security policy for Intel and with that.
Let me invite our speakers to just himself Sherry over to you. Hello, good afternoon. I'm Sherry Pasco.
I work at nist the National Institute of Standards and Technology. I am a senior Tech policy advisor there which essentially means that I work with congressional committees like his Geck and I work with the White House to advance priorities with respect to this Mission. I always also lead the cybersecurity framework program and on Friday.
We just announced that we're going to be updating the framework. So I'll fill you in on that a little bit later. I hope most of you guys in the audience know what missed is and kind of the role that we play in the cyber security space this year.
We are celebrating our 50th anniversary of work and cyber security you can we have a whole website. We've set up a number of workshops and events to celebrate, you know, this role and cyber security starting with Our work in cryptography 50 years ago. Now, you know our work still includes cryptography, but we've expanded to so many more other important cybersecurity topics and overall, you know, our work is is largely to conduct, you know, fundamental applied and developmental research as well as develop standards guidelines and tools to advance cybersecurity and we believe that you know cybersecurity is really fundamental to building trust in technology.
And in the technology ecosystem and standards is you know, not a lot of folks care about standards. We care a lot about standards. I know the folks in the panel care a lot about standards, but we believe that standards and Technology standards are really kind of fundamental to increasing that trust that we see between consumers and between developers in advancing.
Technology, so thanks so much for for inviting me to be here. Sam I'm Jeff rothblum. I'm a senior professional staff member on the Democratic staff for the Senate Homeland Security and governmental Affairs committee.
I think that might be one of the longer titles here. It's like size four font on my on my badge. So, you know for a lot of folks, you might not fully understand what that means.
So just like the quick rundown So within Congress within each, you know in the senate in the house, there's committees. What that really means is when bills are introduced when a member decides they want to write a bill. To try and make that into a lot gets introduced and it gets sorted and filed off to the different committees based on sort of the purview of that particular committee where there's expertise on that committee to look at that topic and and then the committee started decides whether or not they think this is a bill worth moving or a bill that is not as good and then that you know through that process it would go forward to them potentially get passed by the chamber and you know that you know how it built becomes a law 101 that that we all know.
So with that really means is any bill that gets introduced into Senate that relates to DHS or critical infrastructure. On critical infrastructure protection or federal cybersecurity or federal kind of acquisition policy comes to my committee and if it touches it all on sort of cybersecurity or technology security issues the net falls into my portfolio. And so, you know, my job is to evaluate all of that all of that different legislation and then also to write legislation on behalf of my boss who's the chairman of the committee.
His name is Senator Peters in terms of how can we try and move forward in advance and improve cybersecurity and we can talk about some of the specific bills that we've worked on throughout the discussion. But yeah, that's sort of the role that that we play in the committee process in terms of evaluating and coming up with different policies to try and Advance those goals. Thank you.
My name is Kate Stewart. And I'm the VP of Dependable embedded systems at the Linux foundation. And so my area focuses.
What do we need to do to get open source to be able to be used in critical infrastructure in places where it's safety critical and have some degree of trust about these types of these initiatives because open source is being used there today and we need to figure out how we can use more effectively part of that is going to be transparency. And so I have been pretty much hanging around on the s-bomb front as well for the last few years trying to help improve the transparency with Alan and others that feel pretty passionate about this area. I've also been involved with improving the transparency with the project called spdx for about 10 years.
and trying to get that so that we can automate a lot of this stuff because there's a lot of manual steps right now and the more we can understand what is there and how it might be impacted by the vulnerabilities and so forth the The story we'll get over time. So that's to served what I'm working on in the nutshell. I work on a couple of embedded projects Zephyr where it's an iot our toss and then Linux kernel and a variety of other technologies that are useful here.
Thanks. Thank you so much and you as you can see, we have a broad set of expertise here with us in the room. And I think you know, maybe just setting the stage.
Definitely what we have absorbed that with the front landscape evolving and continuous growth and Reliance on digital infrastructure for Society for our nation. Right? We really need to continue and maintain a critical Focus to advance the adoption of security Technologies and more importantly security best practices.
And in this space we have seen a lot of developments across all sectors specifically also critical infrastructure and government infrastructure in the last year and it's really been a pivotal year. We have seen how the executive order from the Biden and administration the main 12 EX. Of order we are just celebrating a little bit over a year since that introduction of that executive order to secure the nation and to increase the robustness and preparation of our ability to address threats and attack the deliverables under these Daddio have been released.
So that has been very instrumental. We have seen a lot of developments in the area of open source security and software security and supply chain security. And of course a lot of momentum around incident response and instead of reporting and the prevention of ransomware attack.
So a lot to discuss here as well as new efforts from this and with this brought Focus, I want to quickly invite each of our speakers to pick maybe one or two areas that would like to kind of open up the discussion with and kind of set the stage in terms of the most relevant kind of development. They would like to share here today with the audience. So sharing maybe we can start with you.
Yes, it's certainly as it's like hard to pick one or two topics because as you mentioned, I mean there's there's so much policy and standards discussion in the cybersecurity space right now. I think you know, we've had a number of high profile incidents, you know solar winds Microsoft Exchange clonio pipeline, you know log4j and I think these incidents have raised the profile of cybersecurity particularly within Washington DC and across the administration across the federal agencies, and of course across Congress and I think these incidents all share some commonalities, you know, insufficient supply chain security and sufficient software security. And so, you know, the executive order I talked quite a bit about this yesterday executive or 14028 was kind of critically aimed at Dressing those gaps.
So I you know, I'll point you to the resources that nist has developed pursuant to the executive order that are squarely focused on you know, how do you secure critical software? And then how do you develop software securely securely so, you know focusing on secure software development principles through our secure software development framework. Both of those initiatives at nist have since been mandated by the White House for use by federal agencies.
And so, you know the work that we've done over the past year. I mean the really the hard work is really beginning now and and we're hearing a lot from from technology companies from federal agencies about how do we implement this what steps do we need to take? And so we're kind of committed to working with, you know industry and and other organizations to make sure Not you know the best practices that we've identified can be implemented and can be implemented in a way that's you know, automated and consistent while so increasing, you know while so continuing to address or take a risk-based approach which is kind of difficult to do so when you're when you're mandating things so, you know, I think the EO was really critical and happy to take you know further questions about that.
Yeah, thank you so much and maybe worth highlighting just for our audience just briefly this is really a pivotal executive order for improving donation service security one of their we are going to be talking today a lot about incident reporting information sharing harmonizing instead of reporting a software security best practices supply chain, but some of the other areas addressed by the EO are transitioning the government infrastructure and public agency infrastructure towards cloud services and towards zero trust environments. So if you haven't looked at that document certainly encourage you to you know look online. There is a fact sheet wonderful factor to summarize that there are a lot of resourcefulness and others that describe Theo and the different implementations and deliver girls under the great details including from OMB and Lisa.
There is also focus on enabling best practices right in security like the adoption of multi-factor Authentication. And endpoint detection and I'm sure these are areas of security. You heard a lot about this week.
So with that I want to Jeff bring a conversation back to you and ask you about your key development to bring to our audience today. I'm sure so I mean Congress has been very busy over the last 18 months or so in terms of trying to pass the legislation to help move the ball forward when it comes to cybersecurity. And so, you know in in Broad Strokes the way the senator, you know, my boss looks at this is that you know, there's a lot of different actors in this space that have different capabilities and different roles and responsibilities.
And so it doesn't make sense to try and pile all of this into necessarily one bill, but to rather try and take different approaches to address different aspects of the problem one of the big pieces of legislation that we recently passed was on incident reporting for critical infrastructure. And so now, you know, there's a multi-year process where we're DHS is going to go through a regulatory process and get input from a bunch of stakeholders, but the bottom line is that critical infrastructure is now going to be required when they experience Some substantial cyber incidents. So this isn't you know, any, you know sort of port scan.
There's you know, some actual impact to the operations the infrastructure one of the other things that my boss talks a lot about is how do we try and improve small business cybersecurity, you know lots of times. This is a resource issue small businesses might not frankly have the revenue stream or The Profit Stream to be able to sort of invest in this while they're focusing on other sort of you know, business operations and important aspects of their businesses. Sometimes it's simply a lack of expertise.
And so we're trying to figure out ways that we can strategically try and help benefit small businesses and think about ways to try and help improve their ability to sort of have the necessary resources they need because they don't have the same, you know, sort of resources or ability to defend themselves as say a large, you know power plant or a large sort of financial institution. And so, you know, we have to think about what the policy problems are for those different actors slightly differently and and that kind of leads into the last area of work that we're doing. As we're starting to look at how can the federal government sort of appropriately work with the open source community in ways to try and improve the open source software, you know, we there's a full understanding of correct in recognition that there's a thriving open source community that is that is doing great work and building these codebases that that like we do not want the federal government to interfere with we do not want the federal government to try and come in and say this is the way to do things.
We recognize that that's just not healthy for the ecosystem but there are probably ways that we can try and help use the federal government to to better improve some security in that environment. So we're thinking about things like, you know, just as a starting point. Is there a particular point of contact within the federal government for the open source Community it was there an office someplace where when events like log4j occur, you know who to call right in there's a belly button in a point in federal government's massive.
There's Andre into agencies. There's people over the place. You have all these different organizations.
How do we organize ourselves to help facilitate that communication better? The other thing we're thinking about is how do we better understand where across critical infrastructure different open source projects are used because we understand that there's ubiquity and that open source projects are used everywhere, but we don't today necessarily have a good understanding of when something like log4j happens or almost more frighteningly when something like log4j happens on a software library that is maybe slightly less used everywhere, but might be used a lot in very critical areas, but doesn't necessarily get the same level of attention. How do we understand the impacts of that?
How do we understand sort of what risk we're facing and once we understand that better and we understand kind of what that risk looks like. What can we do to try and help mitigate that working with the open source community in a productive and beneficial way part of that is through S bombs the EO starts talking about having the federal government require s bombs. So we think there's benefit there, but I think there's also a recognition at esperms are not a silver bullet.
There are peace of the puzzle and an important piece of the puzzle, but we're trying to look at sort of Number of different ways that we can be productive in this space. Yeah s-bombs are starting point for us to do lots of really cool things eventually on terms of the transparency for open source. There's the open source security Foundation that started now at the Olympics Foundation where various large organizations like Intel and others here are getting together to try to collaborate on improving open source in this whole space and there's a mobilization plan that was talked about this morning at the keynote and I would if you have not had a chance to go in and download it and read it I would take and go and look at it and see what areas are interested to you because it's talking about going after three main goals.
It's talking about like, you know, how do we secure our open source software production? How are we going to basically, you know, shorten our time to responses and patching in the ecosystem and then you know, how do we improve our probability Discovery and Remediation and there are very streams of effort where people are trying to collaborate together on these types of topics. So this is one of the areas I know that Alan's been working on in system.
They'll be having listening sessions. They'll be coming up soon. And so if you're interested in that, I'll give you Alan the plug to say, you know, email s bomb at sisa dot if you want to get on to the mailing list for these listening sessions in July because we're trying to build up consensus as to what people want to see and work with between industry government and international.
Yeah. Thank you so much for that. And you just for me just from listening to all these perspectives.
I think we are, you know hearing here a common theme which is all hands on board, right? It takes this ecosystem approach Hardware software collaboration public private Partnerships. Work to introduce the right mechanisms to address these attacks and we are seeing you know, the tremendous leadership from his second Congress on the passage of this federal law the Cyber incident reporting for critical critical infrastructure act which will allow us to have you know, government more situation situational awareness towards attack towards attacks towards how to address them having, you know, a more harmonized approach right towards reporting.
These are really important areas. So just building off on that. We spoke about a few areas.
We talked a little bit about the EO and kind of the supply chain and software security deliverables. We are waiting for there. We talked a little bit about the s bomb and we will kind of follow up on that as well.
But with that I want to what I would like to take it back to Sherry and maybe ask you a little bit more about this kind of next steps that we are waiting on from both on the supply to security side, maybe 800-161 and also with Deo Yeah, so I think you know, we we published a lot of guidance under the executive order nist kind of LED section 4 of the executive order that was squarely focused on improving software supply chain security across federal agencies. So all of our guidance can be found on our website. We have one website for the EO we're all of our work is all essentially located which is very rare for government websites.
I think usually when you're dealing with nist, you're probably wondering which standard do I need and what publication number am I looking for? But for this particular one, we tried to put it in one place. So we we, you know, we developed, you know, one of the I think Center points in a particular interest to this audience was, you know, we updated the secure software development framework.
Which has high level kind of outcomes that developers can use when they are developing software and the secure software development framework outlines, you know specific high level outcomes it all so helps to develop a specific taxonomy or our common language that developers and acquires can use to communicate with each other about software development. It's very similar. It takes a very similar approach as the cyber security framework, but we also recognize that you know, these high level outcomes need to be applied.
And so we are going to be kicking off a project where we will work with industry. We have a center called the national cyber security of center of excellence and it's where industry can join under a crata and R&D agreement with mist. We're going to be working.
In with industry to take the ssdf and apply that to devsecops principles. So we're going to be actually developing use cases going through working with industry to try to automate pieces where we can and actually put out, you know best practices guides for you know, here's here's the type of artifacts you need. Here's how you actually implement the ssdf and and hopefully that will help, you know fill in some of the gaps right now with implementation of of this new framework.
So that's kind of step. That's one really big effort that we're gonna be launching this summer. So stay tuned for that.
I think the other really big effort that we've launched is we've announced we're going to be updating the cyber security framework. So I was security framework is I'm probably one of the most well-known cybersecurity standards across the world and we heard a lot in we did a request for information. We we received about a hundred and thirty comments back from a number of different organizations and over and over we heard nist takes a very kind of open transparent collaborative approach to developing all of our standards all of our guidelines.
So you can expect to have workshops and public drafts and we view all of our work is kind of missed coordinated not nist developed. So we really do need your help to make sure that you know, the guidance that we develop is actually applicable to you and and kind of meets the cyber security challenges that organizations are currently facing. Yeah, thank you so much for that.
And you know, I think again we are seeing this focus on the development of these Frameworks that continue to evolve together with the Innovations and the threats we actually into our very proud We just double down on our commitment with ossf right as part of that effort and over the last five years. We have invested over 250 million dollars into software security and open source security. So, you know with that with the kind of all industry coming together and partnering with our government Partners here and ossf on the developing of friends.
I think one area of importance is how do we engage with the community? Right? So these conversations are happening in the standard bodies.
They're happening with this Coe at ossf and of course with Congress and you know with all of industry and I wanted to take a second and just you know, you already shared here some resource, but get our panelists views on how this He would ask here in the room can engage and kind of Provider input into the conversation. So Kate, maybe we can start with you. So I think the way we can be engaging and start the conversation is there's a lot of listening sessions that are going on.
There's a lot of meetings if you care about these topics. Show up. You've got to be in the room to speak and so we're all looking for use cases.
We're all looking to chest out our knowledge and you know, the formats are all evolving poor conveying this information. These cases are all emerging. And the disinformation we want to convey now's time to say okay.
Hey, I want to have a policy decision. That's going to look at this this this Factor. So start showing up at the meetings and start saying hey, how can I determine if this risk is going to happen and if we can start to do that, we can start to codify it and then automate it and you know getting tools out there getting it into the devops flow.
Getting it so that it's just happening behind the scenes. That'll get us there. But we've got to do it as an entire ecosystem and it's not just a one point here one point there.
It's much wider discussion. So all hands on deck. Yeah, I mean I think from my perspective.
You know, it's the there seems to be a sense that the only lobbyists will talk to Congress or congress is sort of inaccessible and you know, I think you one of the reasons that that there's a number of us who are congressional staff were conferences like this and who try and go and talk to the various communities and talk with you know, very businesses and other folks is that you know, we really do need that input. You know, I I have, you know, clear understanding and humility that you know sitting in Washington DC and trying to craft these sorts of policies. You know, we really need to get the input from folks who it's going to impact because you know, when when we pass a lot it's law right, you know, it impacts everyone in the country and oftentimes people outside the country and so, you know, I think you know, for example when we did the incident reporting legislation, you know, I think I'd probably had 200 different meetings with every sector and you know large and small telecoms and large and small water companies and large and small power companies and you know any sort of critical infrastructure sector you can imagine and frankly a lot of companies that weren't sure if they were critical infrastructure and kind of reached out directly and said, you know, hey, we heard you working on this, but we'd love to talk to you about it and and talk to you about from our perspective.
Yeah, what are the implications of reporting an incident? What are the concerns that your companies have with respect to make whether or not an incident might become public. What are the concerns you have about how quickly you might have to sort of respond and and fill out kind of the form to notify about a particular incident and you know, that's just part and parcel of the way that Congress Works in terms of really trying to make sure that we get sort of that breadth of understanding of what these policy issues are and so, you know You know to the extent that folks are interested in these issues or kind of have thoughts on some of the legislation that's moving their way through Congress, you know, it sounds trite but I would say you reach out to your member of Congress is one way to do it.
But you know particularly if it's on if it's on a particular issue you can reach out to the Committees and yeah, we have intake forms. We have you know on all of our websites, you know, contact us Pages where you can provide that sort of input and you know often you'll get a return phone call or return email, you know, where you know, we can have a discussion and try and get that input because you know, it's really important to us to hear from a variety of different folks when we try and craft this this type of policy. Yeah, I think for nist.
I mean we have very limited resources a small handful of staff that work on cybersecurity. And the reason that we're able to put out, you know, so much guidance develop so many tools is because we really do rely on industry to help us and and so stakeholders. They stakeholders Drive our priorities they drive what we focus on then and then they actually, you know inform on and and improve the guidance that we develop and so, you know for the work that we did under the executive order focused on software supply chain security, you know nist had seven workshops over the span of a year each of those workshops attracted, you know, a thousand 1500 attendees.
We had public common periods on on all the guidance that we developed and that was just for the work that we did on on supply chain security. Right. I mean we have we have workshops all the time.
And so, you know, we have a whole website dedicated towards um, you know, if you want to engage in this cyber security and privacy programs, here's how to do it, you know Common come to a workshop. You know, our workshops are are very unique in the fact that we actually expect attendees to work at them. So we'll do breakout rooms and and have facilitators that will improve the discussion.
You know, we have all of our guidance is out for is always available for comment even if it's not under formal comment. All of our authors are known and their email addresses are very publicly known and they would certainly welcome input on Publications at any time. We also have forums that we run we have visiting researchers that will actually come from around the world and join this for a few months.
Here so that we can increase our expertise that way and really I mean collaboration is so key for the work that NIS does because our standards, you know, they have to be trusted. They have to be we want them to be effective. And we also expect that as stakeholders are building these resources that that means they're more widely to be used around the world.
And so it really is it's no understatement to say that the collaboration at nist is is really is so so critical and would certainly if you're not currently working with us certainly invite you to do so Here we have. Learned. Yeah, well, thank you.
I just want to take a moment to summarize some of the things we discussed here today. So we mentioned briefly to our audience here domay 12 executive order what it means and kind of some of the recent developments and I think this is where you can you know go online to nist and website and check out all the releases of these deliverables. We talked about ssdf we talked about head 800 161 and we talked about the deliverables that are being kind of released under the Yo, including security practices for critical software and how do you identify critical software among others?
Maybe we're mentioning for a second that there are also some iot deliverables that have been released on the EO and one of the most interesting deliverable is a pilot program right for software consumer software labeling of security practices. So we haven't talked about that but that is interesting as well. We touched about we touched on the ossf work, right and the mobilization plan.
The 10 work streams. So I'm gonna create invite you maybe to talk a little bit more about that. And that's in particular.
If you have one resource to the to our audience, and of course Jeff you talked about our cyber incident reporting law for critical infrastructure and here worth noting that we're going to have a rulemaking coming out of cisa defining some of the key issues and definitions when we are expecting that a little bit less than two years right about that with the passage. So more to expect to so Kate. I I see you have more additional remarks, please.
So just for everyone's just to make sure we're all levels set on what an s bomb is it's effectively a set of components and relationships. There's a minimum defined by ntia that got published last year. And that is sort of the heart of the interoperability.
We'd like to see between the various formats, but there's a lot more information we can add to these s bombs that make of a much more powerful for different purposes. So it's your basic ingredient list, but we can be augmenting and handling a lot more use cases. So certainly interested in cases people want to talk about and grab me up if you want to talk about s bombs spdx other things like that.
You see here the common theme with you know, not just raising the bar on our security practices, right and based on measures that are being deployed. But also collaboration and transparency right to the softer bill of materials this concept of understanding. What is the inventory of software components that you have in order to deploy this risk management and supply chain you kind of assessment measures that allow you to address issues to find vulnerabilities.
These are all of these issues are coming together. And with that I see we have a line of questions. So let's open it up to the floor.
Sure. This is a question in the form of a comet last year. You couldn't get cream cheese on the East Coast.
Because one company Schreiber Foods who provide some milk for basically second largest provider because they're ransomware attack. I don't think JBS or Colonial or Spring Hill Medical if you're familiar with them, right the first baby dying from here into my first litigated. The problem is like these forums are great.
for us but they're not great for the Colonials to jbs's you know, there's 5,600 hospitals that don't have any security personal. so the in critical infrastructure It's not even defined. Like sis is going to supposedly Define it in the future and I don't from an ex-employee of Sissa.
I don't trust them to do anything. So again, the sort of the question is are we talking to the Right audience? Because people are dying.
We're messing with Maslow's hierarchy needs now. Health food and water and we're just spewing and again, you're all brilliant people, but we're just talking to an echo chamber. And we're not solving the infrastructure that allows us our parents to have healthy births that that like they don't get poisoned three days before the Super Bowl in Tampa.
Right like anyway, that's like are we doing are we setting the right mindset? Are we in a tunnel with the people already know what we're talking about? Yeah, I mean, I think the points you the points you raise are fair, and and I think there's a recognition.
And increasingly over the last 18 months. There's a growing recognition from a lot of policymakers in DC that that you know cyber security is something that we need to be paying more attention to right it was sort of thing that was a niche topic. It was sort of paid attention to by a small number of folks for a long time and and I think in in some ways it was because for a lot of people it was sort of seen as you always either an Espionage problem, right?
And so okay. That's that's bad. There's IP theft but you know, it's it might not raise to quite that that same level and all of a sudden we started to see attacks that that actually did have physical real world consequences, right like the ones that you talked about and one of the challenges of sort of being in a space from from our perspective in DC.
Is that we're trying to kind of turn this Battleship and and it's slow and it's hard and we have to take these baby steps, but I do have hope and I am optimistic that that we are starting to see that type of recognition within the policy space and not like for Just For example, you know, the people talked about the last sort of major piece of cybersecurity legislation that passed out of Congress big big piece of legislation was in 2015, and it was the cyber security information sharing act and in 2015, the big piece of legislation right was we will give companies liability if they voluntarily share cyber threat indicators. It didn't really do a lot right? This was the big thing and it didn't do a lot.
And you know, we're now seven years later. And we got unanimous consent means literally a 100 Senators voted in favor of a requirement on companies to share critical infrastructure companies to share when they experienced an incident that impacts the critical infrastructure which like for contacts means we had Rand Paul and Elizabeth Warren voting on the same bill to require companies to report to the government. and so, you know, I do I fully recognize the challenge and and I and your points are very well taken and I agree that we might not be moving as fast as everyone would like us to be moving but I do think that that there is been there has been a turn in terms of sort of DC's recognition of the problem and and I think that you know that things are starting to move quickly.
I think the eeo is another very good example of that where we're starting to drive, you know software, you know development to be more critical or starting to move towards s bombs. We're starting to move towards incident reporting, you know, and so yeah, I think all of us are degree, there's a long way to go but but at least for sort of like it's clicked right when you talk to members now and you talk to folks and government like It's clicked that this is a thing that needs to be prioritized and it needs to be resources but against it. So our side of it.
is international there's interest happening worldwide in these problems things in Europe things in Asia. It's a worldwide problem software is developed worldwide. So the solution is going to be coming from all these places as well.
So as we remove that security debt, we've got on here and the improve the transparency open source is going to be a factor here that it will help and multiple countries. You know. That's why we need the transparency and that's why I'm pretty much passionate about this topic.
I agree with. My colleagues and the remarks that they've made I would just add one more thing is is that like this is whiteness has been focused on cybersecurity risk management for a decade and we've been kind of like yelling about this for a while. And and I think now folks are actually starting to realize that you know, the c-suite and Senior managers of Corporations care a lot about Enterprise risk management.
They care a lot about Financial Risk Management. So how do you get cybersecurity to be part of that larger, you know governance and and risk management conversations that they're having across the senior levels of Corporations, and I think you're starting I mean, you know, the cyber security free work is is started to to enhance that conversation, you know as we look to update that, you know, some of the things that we're going to be considering are, you know, do we Need an explicit governance function and the framework like do we make this explicit that there are certain responsibilities for you know, folks across an organization. Obviously, this is a non-regulatory agency.
So we have to rely on other federal agencies to perhaps mandate the work that we're doing but you know just because we're non-regulatory does not mean we are anti-regulatory, but we want to make sure that as we increase cybersecurity mandates on on specific organizations, you know, you're not just focusing on compliance considerations, but you're actually considering. All right, how do I integrate my compliance considerations within my broader risk management strategy across the board. And so that's that's going to be the really difficult conversation that we need to continue having and with certainly need all of your help to do so.
Important comments were made and I think you know we recognized that this is an evolving problem statement, right that continues right with the attacks to change that it's a scheme Sport and I think one other area of tremendous government leadership and this is where we also see, of course, the cisa focus is educating, you know, everyone about basic cyber hygiene, right? So this is where Shields up right these resource and resource for small and medium business entities. Those are best practices.
There are available online for everybody right that they can take a look and see what can I do in my small business entity right now to reduce my risk right for example to be susceptible to ransomware attack and how should I address it so that we have seen tremendous leadership in making more and more of these resource available. This is also where we have seen International collaboration, and I just wanted to quickly give a plug to that over to you. Yes.
Yes, I have been going through this Niche documentation. They're pretty pretty solid but very long and elaborate is there I mean us how can I find a summarized version of the documents? So, you know I can have a quick read and is there more interactive version or how can I contribute to it as well as applicable?
Yeah. particular publication you're interested in All of them incident response would be one of them incident response. Yeah, this executive order one would be another one.
Maybe if there's anything on forensics also, that would be useful. Yeah. Yeah, so next is known for very dense Publications.
I think we did a pretty good job with the work under the executive order in keeping the publication short and sweet. But you know, that is something that we're gonna be working on with the nccoe project is you know developing, you know, more practical guides for hot implements more guidance. We're all so um starting to do what we're calling like quick start guides for to do exactly that in, you know, having a shorter executive summary that folks can can get the high points of the publication really quickly.
And so I will I will definitely take your comment back to this because this is something that I've been harboring my colleagues about too is like you have to you know, I'm not I'm not a Cypress Security expert. I I only pretend to be Sometimes and so you do have to make sure that you know, these resources are usable by many different audiences. And so I appreciate that that you've said that most certainly Echo that we need to we need to keep doing them.
So just a couple comments really appreciate the work on the EO the EOS have been that's been very helpful and breaking out of that Echo chamber for some of our large organizations. Also in regard to the nist CSF some of our large security organizations are actually restructuring around the CSF and the subcategory level. So the it's it's critically important that we integrate software security into that CSF.
So the ssdf is a great document and appreciate the revisions on it would really like to see more integration there and you know be reaching out to you to maybe help that. So appreciate your help them appreciate your work great. No, really appreciate it.
I we've heard very similar things from a number of organizations that this is important. I think now we just need to focus on how do we do that and so but certainly like like your help to to accomplish that I consider myself as a security software vendor because we do practice a lot of things that are advertised by nist and others and the question is more about the incident reporting. It's it's like inclusion detection and inclusion prevention.
It's a really security it's just okay, so I know sometimes some organizations some infrastructure were hacks or what. What are you actually doing to prevent it? You know, the enforcing secure software development is one thing but it is about enforcing it.
What are you doing for my name for structure by on a large scale to prevent some hacker for me run going into a water company in Ohio. Why would they even try to do that? Now, why would you even allow them to access this infrastructure?
Yeah, it's a it's a really good question. And and I think the incident reporting is sort of part of the solution. It's not the entire solution So within the bill one of the things that we did is, you know, we've heard a lot that okay.
So you're reporting to the government. So what right it's his black box. It's this black hole the information never comes out, you know to what end and so if you look actually like the very first portion of the bill, you know above the you have to report part of it we say when sister gets information about incidents either through this new mandatory reporting or otherwise They now are mandated to in an anonymous way, you know from whoever the victim is quickly take that and flip it into an alert and to get it out to the public and and so while it might be that, you know, Iran is going and hacking one water plant in Ohio.
The hope is that by quickly being able to report that in an anonymous way, you know, the government will know who it is, but the government's not going to tell anyone else we can prevent all of the other water plants from getting hit or to at least worn them of what the tttps are to warn them of what the attack factor is. So so that's part of the solution. I agree.
It's not the entire solution. Yeah, so beyond that there are there's definitely work happening where we're trying to find out. You know, how can we try and get those resources into the right hands so sis is doing a lot of work today to try and help, you know, interact more with vendors interact more with the cybersecurity community so we can get that information sharing going to the collaboration going.
There are still questions though about how do we ensure that organizations have the right resources to address this and the challenge there frankly from a policy perspective is you know, The question I'm not saying that I have the answer. The question is, you know, if we have a small Municipal Water company that has the resources for a part-time it person where do they get the money to hire a cybersecurity person or the other way to think about it is, you know, maybe they don't but how can we try and increase the security the ecosystem by improving open source software by working with the vendors of ICS software to try and do that and you know, we don't have easy answers to these problems, but And I said, but PCI, for example were able to enforce their data security. It's all we got to wrap it up.
I'm under strict orders here. Yeah, we will we will. Try to stay stay around.
Well, let's wrap it up. I really want to thank our panelists. I think we you know, we had a really diverse set of of experts here and I'm really really appreciative over their time.
I hope you enjoy this as much as I did and we will stay around for some questions and thanks for sticking with us today.





