
Ep. 131 Identity – One Critical Element of CISA’s Zero Trust Maturity Model When you walk down the grocery store aisle you are bombarded with “New and Improved.” The Cybersecurity and Infrastructure Security Agency sure is not selling soap, but they are in the business of improving their original model as much as Proctor and Gamble. Today, we hear comments on the new CISA Zero ‘trust Maturity Model Version 2.0. The observations will help federal leaders learn lessons from the initial recommendations. The latest version boils down to more prominence on identity, new maturity levels, and increased emphasis on visibility. Each subject matter expert agreed that funding must be applied carefully. For example, Bill Proffer from Leidos notes that added visibility allows people to prioritize data and develop a more effective risk profile. When Frank Briguglio cited the statistic that 84% of recent cybersecurity events were identity-related, each of the participants agreed. CISA recommends more robust identity management as the initial step in the Zero Trust journey. In CISA's first guidelines on Zero Trust, they had three levels of maturity: Traditional, Advanced, and Optimal. Feedback from users showed that most assessments fell between traditional and advanced. To assist in planning, a new category, called “Initial” was included. D This is the stage where automation was brought into Zero Trust, a good reflection of the sophistication of Zero Trust's progress. When you listen, you will learn of all the ways the federal government is providing learning tools for this important transition. Frank Briguglio recommends the NCOEE implementation project which looks at horizons for deploying Zero Trust.
Dec 21, 2023
58 min

Identification, Micro-segmentation, and Continuous Monitoring. Zero Trust is maturing. We have gone from “What is Zero Trust” to “Now that I understand it, how can I afford Zero Trust for my agency? Today’s interview is with Brian Dennis from Akamai, a well-known expert on the deployment of Zero Trust. He will give the listener an overview of the most economical way to deploy Zero Trust. Conceptually, Zero Trust is not a sole product; it is a group of products that work together. This is the main reason careful budgeting must be applied to several specific expenditures in this area. Brian’s advice to get the most “bang for your buck” you need to get Identity Access Management under control, apply micro-segmentation, and include continuous monitoring in your grouping of products. All federal initiatives directed at Zero Trust begin with identity management. This is the linchpin, and the solution must provide correct identification before anything else happens. Divide and conquer is a military concept that can be applied to computer networks. The concept of micro-segmentation was known years ago, but systems have gotten too large to segment manually. Today, we have automated systems that allow permissions to be assigned to each limited area. Ransomware is up; we see new variations of attacks every day. This means that any reasonable budget must include continuous inspection. Focusing on these three areas will enable your systems to use a Zero Trust approach. Of course, there are exceptions, like MRI machines. However, these examples of systems that cannot be upgraded can be isolated with proper security system techniques.
Dec 19, 2023
33 min

The past five years have shown us an incredible increase in the amount of data being generated. We have seen the Internet of Things combine with fast communications and cheap storage. The result is a deluge of data that has to be protected; with new challenges come new solutions. Today we sat down with a veteran in data protection, Aaron Lewis. He shares with listeners lessons learned from decades of his involvement in data protection. He focuses on three ideas that involve data: classification, mapping, and recovery. He starts with you understanding the data itself. The adage, “If you protect everything you protect nothing” applies here. A system administrator must be able to separate sensitive, classified, and top-secret information. Effort should be placed on the most valuable data. Data mapping sounds like a simple task. Well, at one time it was. Today a system may be attacked when data is residing in many locations. Aaron reminds us that in a modern enterprise, you may see data on the wrong network. It could be in a chat tool, like Slack. If you just protect data that sits in your network, you will be vulnerable. Mike Tyson famously said that everyone has a plan until they are hit in the face. However, Aaron points out that many federal leaders may not even have a plan. If they do, it is sitting on a shelf. Some have called this “shelfware.” To be able to effectively defend data, one should have a current plan that is living. Aarons says that a plan is not a plan unless it has been tested. He recommends a disaster recovery plan that responsible parties rehearse.
Dec 7, 2023
56 min

The federal government employs millions of people doing, it seems, millions of activities. With such a wide range of activities taking place, it is difficult to take a technology like AI and see how it can live up to its billing by making the federal workforce more efficient. Each federal agency will, undoubtedly, apply AI in a differing manner. One way to see how AI may fit your organization is to listen to this interview. We have a wide range of individuals representing a wide range of agencies and commercial agencies who know about federal operations. During the interview, they share ways they are using AI, including: · Department of State: Using AI to classify diplomatic cables. · Government Accounting Office: acquisition · Defense Innovation Unit: Aerospace maintenance Taka Ariga takes a view of “applied” AI from a large-scale. What he sees is AI applied to specific segments, with limited knowledge. For example, in aerospace maintenance, a system can be devised to know when aircraft wires may need to be replaced. Similar silos are represented in identity proofing, and data analytics. Taka’s observation is that AI is a team sport. Each federal project must include compliance issues, ethical issues, and transparency. He feels that projects must include team members who can understand subtle concepts like biased databases. With all the ink that has been given to AI, Jamie Fitzgibbon from the Defense Innovation Unit makes a startling statement when she says the “only 1% of DoD appropriation is dedicated to AI.” She articulated many of the use cases when AI makes the DoD more efficient but notes that military leaders have more caution than others. All participants note that one weakness in AI is in the selection of data sets. The selection process of that data can bias results. What about data sets that are sitting in storage? Can they bring valuable findings for a valid conclusion?
Nov 22, 2023
1 hr 23 min

Prioritization Patching Pre-Authentication Logging has always been a thankless and tedious task for systems administrators. Over twenty years ago, this problem was solved with a free logging program called Log4j. It was effective, free, and easy to use. The logging framework became so popular that it was truly pervasive, being part of nearly all systems. As William Shakespeare would say, “Aye, that’s the rub.” Because it was everywhere, it made a tantalizing target for malicious actors. They knew that if they could compromise its code, it would open doors to areas that were extremely hard to find. Two years ago, Log4j was compromised by a malicious actor enabling them to get control of systems. During the interview, you will hear how leaders structured a response through prioritizing, patching, and preauthorization efforts. Prioritizing: Every federal agency has sensitive data assets. With system visibility, one could discover which assets were vulnerable as well as the location of outward-facing applications. This way, assets could be prioritized. This tiering system was important because some libraries were not being used and shouldn’t be worried about. Patching: Large systems take time to patch. The risk, of course, is that the malicious code would propagate during this time. Solomon Adote discussed his targeted response. He recommends leaders limit access to systems to buy time for the rest of the patching activities. Pre-Authentication efforts: Members of the leadership group agreed that one of the best preventative practices occurs before anyone enters the system. West Colie recommends a way to make sure software libraries are examined before they are loaded onto sensitive federal applications. He mentions a Software Bill of Materials that can assure developers that threats like Log4j are not included. In the area of prevention, it was recommended that the person asking for access to a system be authenticated “upstream.” Before even submitting a username and password, a potential visitor should be vetted at a completely different site. The world of cybersecurity is a never-ending battle. Learn lessons from the remediation efforts for Log4j so you can apply them to the next cyber threat to your federal agency.
Nov 15, 2023
1 hr 27 min

“Word clouds” were popular a few years ago. If we attempted to re-popularize the visual representation of an image with terms associated with federal technology, you would see phrases like “hybrid cloud,” “Zero Trust,” and “unfunded mandate.” We may have to adjust the “word cloud” because of the Infrastructure Act of 2022, we are looking at $1.9 billion in funds appropriated for cybersecurity. Today’s discussion provides guidance on optimizing the use of these funds, so state and local governments can solve today’s threat and prepare their staff for years down the road. Tim Roemer from Thrive DX suggests that some local organizations may not have a mature position when it comes to cybersecurity posture. Because of this, a typical local area may consider spending money on advanced technology, what he calls the “Ferrari.” He suggests they should optimize funds for basics like cybersecurity awareness training. One way to optimize the funding is to take advantage of the free services that CISA provides. They offer free assessments as well as penetration tests. These activities can bring local areas up to a more mature model of cybersecurity where they can make informed decisions about funding measures. During the interview, it became obvious that, even with the increased funding nobody has 100% certainty, and nobody has 100% of all the answers. Continuous training must be part of any plan to optimize these funds.
Nov 8, 2023
31 min

More end points staffing challenges automation Today, we sat down with three state experts and three subject matter experts and heard them give ideas on the most effective way to combat cyber threats. The discussion can be boiled down into three main areas: risk in increased workload, staff challenges, and automation. Covid increased the number of people logging in remotely and, at the same time, there was an increase in data collected by sensors. That increased workload presented opportunities for malicious actors. Tony Lauro mentions that this data collection can involve Application Program Interfaces (APIs). They must be protected because they act as a gateway and an attack point for outsiders. This increase in data collection also includes the obligation to act in a way that protects personal information. If not done correctly, sensitive data can be collected and stored in an unsafe manner, leaving it exposed to attack. Everyone knows about the lack of staff for cybersecurity professionals. Jeremy Wilson from Texas details how Texas has an “Infosec Academy” that trains staff in principles of combatting cyber-attacks. His experience shows that a person doesn’t necessarily need a degree in computer science to be effective at preventing and remediating attacks. Automation is a double edges sword. On one hand, it can assist in updating systems and validating identity; on the other hand, attackers can use automation to accelerate attacks as well. David Morgan from Texas suggests that in a post pandemic world Identity, Credential, and Access Management must be a priority. Automation can allow platforms to talk to each other, but a systems administrator must know where the gaps are and provide end point protection.
Nov 2, 2023
30 min

Complexity Identity Credentials and Access Management (ICAM) Toxic Combinations Napoleon Hill once said that a goal is a dream with a deadline. When it comes to the federal transition to Zero Trust Architecture, the Office of Management and Budget outlines a path for implementing zero-trust architecture by 2024. Today’s discussion gives federal practitioners terrific guidelines on how to accomplish that noble goal. The group is a wonderful mix of federal experience, innovative leaders, and experts who were part of many initial network specifications. During the discussion three topics were obvious: how to manage complexity, identity, and unexpected combinations. Complexity During an exchange about “shiny new things” that seem to trap system managers, Josh Brodbent made a fantastic observation when he stated that complexity doesn’t always mean effectiveness. Drilling deeper into the concept of new technology, Frank Bruglio suggests some people will purchase a “shiny new toy” for the sole reason to check a box on a compliance requirement. ICAM Bryan Rosensteel has spent his career in the world of federal identity management. His experience leads him to believe that to fulfill the desired transition to zero-trust architecture, application developers must be taken into consideration. His point is simple, if ICAM isn’t a part of application development, how can they assure that it will be compliant? Bolting on compliance brings about delays and unneeded code revisions. Bryan expands on this concept with his thoughts on abstract authentication and centralized structures. Toxic Combinations Frank Briguglio reminds us that managing Identity Credentials and Access Management must be understood at a much deeper level. In the discussion, he revives the phrase “toxic combinations.” This is a reference to granting privileges to users that can create risks in unexpected ways. Automation has its limits, and humans must be part of the package when a federal agency commits to zero-trust-architecture.
Oct 25, 2023
59 min

Sprawl > Visibility > Segmentation & micro segmentation When technology people hear the term “segmentation” they normally apply that term to network topology. After all, networks have been segmented since the early days when subnets were devised (RFC 791 in 1984). During today’s discussion, we will learn that although network segmentation is important, we must also consider the value of applying segmentation to applications as well. Rob Thorn from ICE explains that we need both approaches to have a secure federal system. Instead of a server down the hall, a typical federal agency is encountering “sprawl.” Public clouds, private clouds, multiple data centers, and the day of saying an application is sitting on a server in the building is long forgotten. Gary Barlet from Illumnio points out that many systems administrators really don’t know what calls are being made by applications. When it comes to network visibility, applications must be included. Hence the importance of application segmentation. An argument can be made that this approach can be termed micro segmentation. The next logical step is gaining visibility into the network to have a deeper understanding of who is accessing what. Gary Barlet makes some shocking observations about visibility. Some organizations do a thorough analysis of their system and see servers they thought were taken offline; these “ghost” servers may not be patched properly and result as being a significant vulnerability.
Oct 20, 2023
58 min

Everyone who has driven through Missouri knows that the state motto is “Show Me.” That is the theme for today’s interview. We all have seen the hype about artificial intelligence. Well, time to give some specific examples so federal and state leaders can see how to apply AI to reduce costs and improve service for citizens. Today’s podcast is a fantastic panel of experts who reflect views from academia, states and localities, as well as corporate expertise. They manage topics ranging from AI bias to floodplain insurance. Amanda Randles opens with practical advice. She says we should not fear AI, we should focus on ways to train users on how to use these tools in the best way. Moving from academia, David Edinger gives specific examples from Denver on how he has deployed AI to improve citizen experience. For example, if AI can detect anomalies on an X-ray better than a human, why not use AI to free up time for a radiologist to face-to-face with patients? A more mundane example is Denver’s non-critical support line, what he calls “311.” David details how AI has been deployed in chatbots to help people with typical tasks like getting a license. It can also anticipate questions and provide appropriate answers. Finally, AI-enhanced response systems can work 24 hours a day 7 days a week, which improves citizen service as well as reduces the burden on staff to work weekends. Moving to the West Coast, Hong Sae describes how AI can be used to predict major events on a flood plain. This predictive ability has helped citizens with reducing the cost of flood plain insurance. This far-ranging discussion includes each person contributing to the concern of AI being used in an ethical manner as well as how to trust the data that is provided.
Oct 16, 2023
1 hr 26 min
Load more
