SIEM, Government security, Risk Assessments/Management, SOC

CISA program needs to speed up to counter evolving cyber threats

The Cybersecurity and Infrastructure Security Agency's Continuous Diagnostics and Mitigation program must accelerate its efforts to provide timely tools and capabilities to other federal agencies, according to an agency official. Richard Grabowski, acting branch chief of service delivery and deputy program manager for CDM, stated that the current pace of collaboration is insufficient to address current and future cyber threats, as first reported by Cyberscoop.

Grabowski emphasized the need for responsible automation to allow cybersecurity experts to focus on novel threats and advanced technology rather than routine alerts. Velocity, unification, and data-driven risk management are the three core goals for the CDM program. Unification aims to break down data silos and foster reusable lessons learned, while data-driven risk management ensures timely and accurate information for crisis response.

The program's offerings include Security Information and Event Management (SIEM) as a Service, with a three-year roadmap for expansion. Acting federal chief information security officer Mike Duffy suggested guiding principles for CDM's future, including aggregating demand across agencies, purchasing outcomes instead of products, and designing acquisition for continuous improvement. The CDM program has been evolving since the SolarWinds breach, which highlighted a lack of government-wide operational visibility for assessing and coordinating responses.

Source: cyberscoop

You can skip this ad in 5 seconds