Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Joint NSA-CISA Advisory Recommends Solutions to Top 10 Cybersecurity Misconfigurations; Eric Goldstein Quoted

by Jamie Bennet
October 6, 2023
in Cybersecurity, News
Eric Goldstein

Eric Goldstein

A joint advisory released by the National Security Agency and Cybersecurity and Infrastructure Security Agency listed 10 of the most common misconfigurations in enterprise IT defense and how to mitigate risks arising from such cases.

Table of Contents

  • You might also like
  • Trump Releases National Security Systems Cybersecurity Policy
  • Space Systems Command’s Angela Lindenmuth on International Agreements
  • From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities

You might also like

Trump Releases National Security Systems Cybersecurity Policy

Space Systems Command’s Angela Lindenmuth on International Agreements

From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities

The list includes default software and application configurations, improper user and administrator privilege separation and insufficient monitoring of internal networks, according to the advisory released Thursday.

NSA and CISA found that some organizations lack network segmentation, effective patch management and access control lists on shared networks and services. In other cases, system access controls are bypassed, multifactor authentication tools and user credentials are weak and code executions lack restrictions.

The agencies urged network defenders to strengthen configurations, implement access controls, prioritize patching of commonly exploited vulnerabilities and monitor and reduce administrative privileges.

For software manufacturers, the NSA and CISA Red and Blue Teams pushed for the adoption of secure-by-design and -default principles to reduce cyber threats and their burden on network defenders.

Eric Goldstein, CISA’s executive assistant director for cybersecurity, echoed the call for practicing secure-by-design tactics. “While enterprises can and must take steps to identify and address these misconfigurations, we know that scalable progress requires urgent action by software manufacturers, particularly by adopting Secure by Design practices where software is designed securely from inception to end-of-life and by taking ownership to improve security outcomes of their customers,” Goldstein wrote in a blog post.

On Nov. 15, the Potomoc Officers Club will gather homeland and national security officials and experts for the 2023 Homeland Security Summit in Virginia. Register now to participate in the event.

POC - 2023 Homeland Security Summit
Share5Tweet19

Recommended For You

Trump Releases National Security Systems Cybersecurity Policy

by Jane Edwards
June 15, 2026
Cybersecurity. Trump has issued a policy to strengthen the cybersecurity of U.S. national security systems.

Trump has issued a policy to bolster the cybersecurity of national security systemsThe memo calls for the reestablishment of the Committee on National Security SystemsThe 2026 Intel Summit...

Read moreDetails

Space Systems Command’s Angela Lindenmuth on International Agreements

by Jane Edwards
June 15, 2026
Angela Lindenmuth. The SSC International Affairs Office deputy chief said SSC executes nearly 40 international agreements.

A Space Systems Command division has executed nearly 40 international cooperative agreementsSSC expects to record nearly $700 million in additional partner investments by the end of 2026The 2026...

Read moreDetails

From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities

by Elodie Collins
June 15, 2026
Army seal. The Army is seeking commercial technologies across AI, autonomy, cloud infrastructure, training and air defense

The Army has issued contract opportunities for advanced technologies, such as AI, command-and-control systems, air defense, autonomous and robotic systems, synthetic training, and dronesThe Army is also seeking...

Read moreDetails

Navy Launches Recruitment Drive for Commercial Technology Experts

by Miles Jamison
June 15, 2026
U.S. Navy logo. The Navy is launching a recruitment drive for top commercial technology experts.

The Department of the Navy has announced a national talent search to recruit top commercial technology professionals into the Navy Reserve's Navy Innovation Unit.The Navy's push to recruit commercial...

Read moreDetails

DOW Issues Guidance to Mitigate Vendor Threats in Overseas Operations

by Kristen Smith
June 15, 2026
DOW logo. DOW has released guidance for identifying foreign vendors that pose security risks to U.S. operations abroad.

The Department of War has set department-wide procedures for identifying foreign vendors that pose security risks to U.S. operations abroad and removing them from federal contracts, grants and...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!