Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Joint NSA-CISA Advisory Recommends Solutions to Top 10 Cybersecurity Misconfigurations; Eric Goldstein Quoted

by Jamie Bennet
October 6, 2023
in Cybersecurity, News
Eric Goldstein

Eric Goldstein

A joint advisory released by the National Security Agency and Cybersecurity and Infrastructure Security Agency listed 10 of the most common misconfigurations in enterprise IT defense and how to mitigate risks arising from such cases.

Table of Contents

  • You might also like
  • Kyle Schutt to Serve as Acting DHS Chief Information Officer
  • CMS Launches QualTech Event
  • US Army Moves to Commercial-First Model for Software Acquisition

You might also like

Kyle Schutt to Serve as Acting DHS Chief Information Officer

CMS Launches QualTech Event

US Army Moves to Commercial-First Model for Software Acquisition

The list includes default software and application configurations, improper user and administrator privilege separation and insufficient monitoring of internal networks, according to the advisory released Thursday.

NSA and CISA found that some organizations lack network segmentation, effective patch management and access control lists on shared networks and services. In other cases, system access controls are bypassed, multifactor authentication tools and user credentials are weak and code executions lack restrictions.

The agencies urged network defenders to strengthen configurations, implement access controls, prioritize patching of commonly exploited vulnerabilities and monitor and reduce administrative privileges.

For software manufacturers, the NSA and CISA Red and Blue Teams pushed for the adoption of secure-by-design and -default principles to reduce cyber threats and their burden on network defenders.

Eric Goldstein, CISA’s executive assistant director for cybersecurity, echoed the call for practicing secure-by-design tactics. “While enterprises can and must take steps to identify and address these misconfigurations, we know that scalable progress requires urgent action by software manufacturers, particularly by adopting Secure by Design practices where software is designed securely from inception to end-of-life and by taking ownership to improve security outcomes of their customers,” Goldstein wrote in a blog post.

On Nov. 15, the Potomoc Officers Club will gather homeland and national security officials and experts for the 2023 Homeland Security Summit in Virginia. Register now to participate in the event.

POC - 2023 Homeland Security Summit
Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

NASA Posts Draft Solicitation for Goddard Logistics Services Contract

Next Post

Atlantic Council Report Recommends Ways for Effective Implementation of Private-Sector Activities in Warfare

Recommended For You

Army, FDA Look to Apply Additive Manufacturing for Medical Logistics

by Brenda Marie Rivers
December 6, 2022
Army, FDA Look to Apply Additive Manufacturing for Medical Logistics

The Army Medical Logistics Command and the Food and Drug Administration conducted a workshop at Fort Detrick in Maryland aimed at identifying the potential benefits of additive manufacturing...

Read moreDetails

Bipartisan Senate Group Presents New Cybersecurity Education Bill

by Nichols Martin
November 7, 2019
Bipartisan Senate Group Presents New Cybersecurity Education Bill

Sens. Roger Wicker, R-Miss., Maria Cantwell, D-Wash., Jacky Rosen, D-Nev., and John Thune, R-S.D., have introduced a bill that aims to fortify the country's cybersecurity education and workforce. The Harvesting American Cybersecurity...

Read moreDetails

US Government Continues to Target Russia’s Defense Sector, Oil Refining Capacity With New Sanctions

by Jane Edwards
March 3, 2022
US Government Continues to Target Russia’s Defense Sector, Oil Refining Capacity With New Sanctions

The Biden administration has imposed full blocking sanctions on 22 Russian defense entities, including those that produce combat aircraft, missiles, infantry fighting vehicles, unmanned aerial vehicles and electronic...

Read moreDetails

NIST Posts RFI on Positioning, Navigation and Timing Technologies

by Matthew Nelson
May 28, 2020
NIST Posts RFI on Positioning, Navigation and Timing Technologies

The National Institute of Standards and Technology (NIST) has published a request for information to seek inputs on the usage of positioning, navigation and timing services.

Read moreDetails

Defense Logistics Agency Kicks Off Fort Bragg Mapping Operations

by Jay Clemens
September 7, 2016
Defense Logistics Agency Kicks Off Fort Bragg Mapping Operations

The Defense Logistics Agency has kicked off its mapping operations at Fort Bragg with the delivery of the first four topographic maps for mission planning on Aug. 16....

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!