CISA debuts encrypted DNS implementation guidance for federal agencies aligned with zero trust strategy
Govt & Regulations

Encrypted DNS Implementation Guidance (CISA)

This document is intended to provide implementation guidance for federal agencies to meet federal requirements related to encryption DNS traffic and enhance the cybersecurity posture of their IT networks, as set forth in OMB Memorandum M-22-09.1 The Memorandum sets forth a “zero trust” cybersecurity strategy for FCEB agencies.
Transnational cybersecurity agencies release guidance on secure procurement of digital products, services
Govt & Regulations

Secure-by-Design (cyber.gov.au)

Choosing secure and verifiable technologies. Customers have the responsibility for evaluating the suitability, security and risks associated with acquiring and operating a digital product or service. However, it is important that customers increasingly demand manufacturers embrace and provide products and services that are secure-by-design and secure-by-default.
National Cybersecurity Strategy Implementation Plan (V2)
Govt & Regulations

National Cybersecurity Strategy Implementation Plan (V2)

This is the second iteration of the NCSIP, building upon the first version released in July 2023.  The NCSIP Version 2 describes 100 high-impact initiatives requiring executive visibility and interagency coordination that the Federal Government is pursuing to achieve the Strategy’s objectives. These initiatives carry over from, add to, and build upon the initiatives described in the first NCSIP, and advance the nation closer toward the Strategic Objectives sought in the National Cybersecurity Strategy.
US DHS delivers safety and security guidelines to secure critical infrastructure from AI-related threats
AI

MITIGATING AI RISK- Safety and Security Guidelines for Critical Infrastructure Owners and

The guidelines specifically address risks to safety and security, which are uniquely consequential to critical infrastructure. NIST defines “safety” as a property of a system such that it does not, under defined conditions, lead to a state in which human life, health, property, or the environment is endangered; safety involves reducing both the probability of expected harms and the possibility of unexpected harms. Because AI risks to critical infrastructure are highly contextual, critical infrastructure owners and operators who use AI-systems should account for their specific circumstances as they use these guidelines.
AI for Energy - Opportunities for a Modern Grid and Clean Energy Economy (DoE)
Govt & Regulations

AI for Energy – Opportunities for a Modern Grid and Clean Energy Economy (DoE)

This report was prepared pursuant to the Executive Order (E.O.) on the Safe, Secure, and Trustworthy Development and Use of AI (14110), issued October 30, 2023. Priority use cases have been identified in four broad areas where AI can be immediately deployed to improve the grid while achieving the Administration’s goals for reducing emissions and providing affordable and reliable electricity to all Americans: grid planning, permitting and siting, operations and reliability, and resilience.
New CGCYBER report warns of cybersecurity risks in marine environment due to network-connected OT systems
Govt & Regulations

2023 Cyber Trends and Insights in The Marine Environment (CGCYBER)

This report summarizes U.S. Coast Guard Cyber Command’s (CGCYBER) findings from calendar year 2023 and the associated mitigation recommendations. CGCYBER continues to expand its presence and navigate an increasingly interconnected marine environment. As we witness a surge in technological advancements, the organizations that facilitate the exchange of goods face evolving cyber threats, demanding our unwavering attention and concerted action.
NSA information sheet focuses on enhancing data security and zero trust implementation
Govt & Regulations

Advancing Zero Trust Maturity Throughout the Data Pillar (NSA)

This cybersecurity information sheet (CSI) provides recommendations for maturing data security and enforcing access to data at rest and in transit, ensuring that only those with authorization can access the data. It further discusses how these capabilities integrate into a comprehensive Zero Trust (ZT) framework.
E-ISAC releases report on GridEx VII exercise, highlighting recommendations for grid security and resilience
Govt & Regulations

GridEx VII Lessons Learned Report (NERC & E-ISAC)

This report summarizes the recommendations and observations identified through each exercise. The recommendations are intended to help electric utilities, government partners, the E-ISAC, and other stakeholders prepare for and respond to security incidents that affect the North American electricity system.
US DoD unveils DIB Cybersecurity Strategy 2024 to strengthen national cyber defenses
Govt & Regulations

Defense Industrial Base Cybersecurity Strategy 2024

The DIB Cybersecurity Strategy ensures that we remain on the cutting edge of what it takes to secure our infrastructure. It requires us foremost to coordinate and collaborate across the Department to identify and close gaps in protecting our DIB networks, supply chains, and other critical resources. In it, we have identified opportunities where we can bolster the cybersecurity of the DIB, align the Department's focus on systemic challenges, and provide solutions that deliver the highest return on investment.