Biden cybersecurity order mandates new rules for govt software

The executive order's initiatives include the creation of a organization that would investigate major hacks along the lines of National Transportation Safety Board inquiries that are launched after plane crashes.

May 13, 2021 11:48 am | Updated November 18, 2021 04:02 pm IST

Biden cybersecurity order mandates new rules for govt software.

Biden cybersecurity order mandates new rules for govt software.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

President Joe Biden on Wednesday ordered the creation of an air accident-style cyber review board and the imposition of new software standards for government agencies following a spate of digital intrusions that have rattled the United States.

The executive order's initiatives include the creation of a organization that would investigate major hacks along the lines of National Transportation Safety Board inquiries that are launched after plane crashes.

They also include the imposition of new security standards for software bought by government agencies - a requirement first reported by Reuters in March.

The order follows a digital extortion attempt against major fuel transport company Colonial Pipeline that triggering panic buying and fuel shortages in the south eastern United States.

Some recommendations were clearly aimed at avoiding a repeat of the hack of Texas software company SolarWinds , whose software was hijacked to break into government agencies and steal thousands of officials' emails.

The software rules - which are due to be drawn up by the U.S. National Institute of Standards and Technology - were among the most important parts of the order, said Kiersten Todt, the managing director of the Cyber Readiness Institute, which is geared toward helping protect small- and medium-sized businesses.

"It's using the government's buying power to improve the security of software," Todt said, saying that if drafted correctly, the rules "will be a game changer in security."

Other rules imposed by the order mandate the use of multi-factor authentication - effectively a second failsafe password - and the use of encryption both for stored data and communications.

The order follows an series of dramatic or damaging hacks against American interests. Beyond the digital ransom demand imposed on Colonial - which sources told Reuters the company did not intend to pay - and the SolarWinds-linked compromises, foreign hackers have also used vulnerabilities in software made by Microsoft and Ivanti to extract data from U.S. government targets.

Senator Mark Warner, a Democrat who chairs the Senate Intelligence Committee, said the executive order is a good first step but the United States "is simply not prepared to fend off state-sponsored or criminal hackers intent on compromising our systems for profit or espionage."

"Congress is going to have to step up and do more to address our cyber vulnerabilities," he said.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.