How CISA is Leading the Way on the Cybersecurity EO Because cybersecurity is a team sport, the Cybersecurity and Infrastructure Security Agency (CISA) may be America’s coach. CISA is a federal agency responsible for elevating government cybersecurity nationwide. Whether the threat is a
cybercriminal or a hostile nation, CISA helps protect its federal, state and local
partners by improving cybersecurity coordination and defenses.
Naturally, Biden’s recent cybersecurity EO closely fits CISA’s mission. From sharing threat
intelligence to practicing zero trust cybersecurity, the EO outlines several key strategies CISA urges agencies to follow going forward.
GovLoop discussed CISA’s role in implementing the new cybersecurity EO with Deputy Executive Assistant Director for Cybersecurity Matt Hartman.
This interview has been lightly edited for brevity and clarity.
GOVLOOP: How is U.S. cybersecurity doing?
need to be in terms of cybersecurity, our
country needs sustained investments in both
HARTMAN: In terms of where we’re doing
well, the first thing that comes to mind is that
many, many, many years.
we are making our adversaries work harder
Recent events have again highlighted the
doing debasement, particularly in the
or solution can prevent an attack from a
MFA, encrypting data and rapidly patching
multiple layers of defense and security
by more consistently and more thoroughly
truth that no one security control, vendor
federal space. It is things like implementing
nation-state adversary. It is going to take
vulnerable systems.
measures to protect an organization. And
The challenge is that while we continue to
continue to represent a great challenge to
improve our defenses, shore up our cyber
hygiene and take advantage of some lowhanging fruit as a federal enterprise, our adversaries are becoming increasingly
even with all that in place, it is going to
keep sophisticated adversaries from gaining access to networks that represent strategic
interest to them, which is why one of the first
sophisticated and brazen. To get where we
32
cybersecurity and IT modernization over
principles of zero trust cybersecurity is to assume breach.
A GovLoop Guide