Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Joint NSA-CISA Advisory Recommends Solutions to Top 10 Cybersecurity Misconfigurations; Eric Goldstein Quoted

by Jamie Bennet
October 6, 2023
in Cybersecurity, News
Eric Goldstein

Eric Goldstein

A joint advisory released by the National Security Agency and Cybersecurity and Infrastructure Security Agency listed 10 of the most common misconfigurations in enterprise IT defense and how to mitigate risks arising from such cases.

Table of Contents

  • You might also like
  • Lt. Gen. Kevin Admiral Nominated to Lead US Army Europe & Africa
  • DIU Launches G-BAM Prize Challenge for Long-Range Strike Systems
  • State Department Publishes Generative AI Playbook Built Around StateChat Rollout

You might also like

Lt. Gen. Kevin Admiral Nominated to Lead US Army Europe & Africa

DIU Launches G-BAM Prize Challenge for Long-Range Strike Systems

State Department Publishes Generative AI Playbook Built Around StateChat Rollout

The list includes default software and application configurations, improper user and administrator privilege separation and insufficient monitoring of internal networks, according to the advisory released Thursday.

NSA and CISA found that some organizations lack network segmentation, effective patch management and access control lists on shared networks and services. In other cases, system access controls are bypassed, multifactor authentication tools and user credentials are weak and code executions lack restrictions.

The agencies urged network defenders to strengthen configurations, implement access controls, prioritize patching of commonly exploited vulnerabilities and monitor and reduce administrative privileges.

For software manufacturers, the NSA and CISA Red and Blue Teams pushed for the adoption of secure-by-design and -default principles to reduce cyber threats and their burden on network defenders.

Eric Goldstein, CISA’s executive assistant director for cybersecurity, echoed the call for practicing secure-by-design tactics. “While enterprises can and must take steps to identify and address these misconfigurations, we know that scalable progress requires urgent action by software manufacturers, particularly by adopting Secure by Design practices where software is designed securely from inception to end-of-life and by taking ownership to improve security outcomes of their customers,” Goldstein wrote in a blog post.

On Nov. 15, the Potomoc Officers Club will gather homeland and national security officials and experts for the 2023 Homeland Security Summit in Virginia. Register now to participate in the event.

POC - 2023 Homeland Security Summit
Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

NASA Posts Draft Solicitation for Goddard Logistics Services Contract

Next Post

Atlantic Council Report Recommends Ways for Effective Implementation of Private-Sector Activities in Warfare

Recommended For You

KBR Joins Multi-Million Dollar NTSP Framework to Support UK Nuclear, Defense Infrastructure; Andrew Barrie, Charles Hoskins Quoted

by Sarah Sybert
December 5, 2022
KBR Joins Multi-Million Dollar NTSP Framework to Support UK Nuclear, Defense Infrastructure; Andrew Barrie, Charles Hoskins Quoted

KBR has announced that the company has reinforced its growing presence in the UK Nuclear and Defence Infrastructure sectors after being selected to join a seven-year, multi-million dollar...

Read moreDetails

GPO Task Force to Offer Recommendations for All-Digital Federal Depository Library Program; Hugh Nathanial Halpern Quoted

by Jane Edwards
January 28, 2022
GPO Task Force to Offer Recommendations for All-Digital Federal Depository Library Program; Hugh Nathanial Halpern Quoted

Hugh Nathanial Halpern, director of the Government Publishing Office, has designated a task force to examine the feasibility of making the Federal Depository Library Program all-digital.The 23-member task...

Read moreDetails

Tactical Software Shows Promise for USAF Fighter Jet Development Cost Reduction

by Jamie Bennet
June 9, 2023
US_Air_Force_Logo

The U.S. Air Force completed a test flight in an attempt to demonstrate the use of a single tactical software on different stealth fighters such as the F35A...

Read moreDetails

Christopher Krebs: Agencies Shifting to Telework Should Boost Investments in Cyber Tools

by Jane Edwards
September 9, 2020
Christopher Krebs

Christopher Krebs, director of the Cybersecurity and Infrastructure Security Agency (CISA) and a 2020 Wash100 awardee, said agencies transitioning to the cloud to support telework should consolidate and...

Read moreDetails

Ellen Lord Sets Plan to Promote Pentagon-Wide Acquisition Transparency

by Darwin McDaniel
January 7, 2019
Ellen Lord Sets Plan to Promote Pentagon-Wide Acquisition Transparency

Ellen Lord, under secretary of defense for acquisition and sustainment, has announced plans to increase transparency of the Pentagon’s acquisition efforts following recent pressure from Congress, Bloomberg reported...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!