news.mlab.sh
Back to the feed
threat-intel

CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says

Medium
Summary

CISA is undergoing a significant transformation in its approach to cybersecurity vulnerability assessment, shifting from a blanket patching strategy to a risk-based prioritization model. This change, driven by increasing cyber risks and resource constraints, will involve directing federal agencies to focus on critical assets and engage in more detailed conversations with affected organizations. The agency aims to move from broad intelligence to a ‘fine grade’ approach, emphasizing measurable resilience and specific vulnerabilities.

CISA is fundamentally altering its strategy for assessing and responding to cyber vulnerabilities. The agency’s Acting Director, Nick Andersen, announced plans to implement a binding operational directive that will require federal agencies to prioritize vulnerabilities based on risk, rather than simply applying patches as quickly as possible. This shift acknowledges the current environment of escalating cyber threats and the agency’s limited resources. The directive will also focus on targeted engagement with critical infrastructure entities, demanding a deeper understanding of their specific vulnerabilities and resilience needs.

The core of this transformation lies in moving away from a reactive, ‘patch-everything’ approach. CISA recognizes the limitations of this strategy, particularly given the potential for overstretched resources. The agency intends to utilize a ‘fine grade’ system, focusing on vulnerabilities associated with internet-exposed assets, known exploited vulnerabilities, and those amenable to automation. This approach necessitates a more targeted and strategic allocation of resources, prioritizing the most impactful threats.

Addressing staffing shortages is also a key component of CISA’s strategy. The agency plans to hire over 300 new personnel, including 180 by the end of the month, primarily to bolster infrastructure security, emergency communications, and state cybersecurity coordination. This expansion aims to support the agency’s new risk-based approach and improve its ability to engage in detailed conversations with critical infrastructure entities.

Read the full article at The Record