{"id":3525,"date":"2024-05-10T13:21:29","date_gmt":"2024-05-10T18:21:29","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/rsa-2024-cisa-secure-design-pledge-necessary-toothless"},"modified":"2024-05-10T13:21:29","modified_gmt":"2024-05-10T18:21:29","slug":"is-cisas-secure-by-design-pledge-toothless","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/10\/is-cisas-secure-by-design-pledge-toothless\/","title":{"rendered":"Is CISA&#8217;s Secure by Design Pledge Toothless?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb766a2d711b177d5\/663d51b660bdf40b52573bc8\/RSA_2024-RSA.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At 2024&#8217;s RSA Conference this week, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/securebydesign\/pledge\/statements-of-support\" rel=\"noopener\">brand names<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> like Microsoft, Amazon Web Service (AWS), International Business Machines (IBM), Fortinet, and more <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/tech-companies-promise-secure-by-design-products\" rel=\"noopener\">agreed to take steps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> toward meeting a set of seven objectives defined by the US&#8217;s premier cyber authority.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2024-05\/CISA%20Secure%20by%20Design%20Pledge_508c.pdf\" rel=\"noopener\">The agreement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is voluntary, not legally binding, anodyne, and can be flexibly applied to all or just one of a company&#8217;s products or services. Still, signees say, it may help move the needle to incentivize good security practices and investments across industries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I think that this represents the zeitgeist,&#8221; says Grant Geyer, CPO of Claroty, one of the signatories. &#8220;It&#8217;s a recognition that as more of us agree that we&#8217;re going to operate at a certain standard, that makes it more comfortable and open for others to do the same.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"No Teeth, No Problem\">No Teeth, No Problem<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISA&#8217;s Secure by Design pledge consists of areas of improvement split into seven primary categories: multi-factor authentication (MFA), default passwords, reducing entire classes of vulnerability, security patches, vulnerability disclosure policy, CVEs, and evidence of intrusions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The pledge contains nothing revolutionary and has no teeth whatsoever. But for those involved, that&#8217;s all beside the point.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While they may not have direct authority, I think that there is indirect authority by starting to define what the expectation is,&#8221; says Chris Henderson, senior director of threat operations at Huntress, another signee.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, he says, &#8220;In the private space there are companies effectively war profiteering off of the security tooling within their products. You see a lot of companies adding security features behind paywalls because it&#8217;s viewed as an easy way to increase revenue. In reality, a lot of these features don&#8217;t actually cost any extra money to deliver,&#8221; Henderson adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He thinks the pledge could be a new approach toward pushing public-private partnerships without new regulations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I think the Secure By Design pledge is a really interesting approach through private and government partnership to try to drive not regulation, but change what the expectation is for &#8216;reasonable.'&#8221; Henderson says. &#8220;If you&#8217;re a product that offers multi-factor authentication (MFA) or single sign-on (SSO), but it&#8217;s behind a paywall, and one of your clients gets breached because they weren&#8217;t paying for that, well, now are you negligent?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like Henderson, Jonathan Trull, CISO of Qualys (also a signatory), envisions the pledge&#8217;s effects as primarily economic in nature. &#8220;In the commercial sector you&#8217;ve got two (incentive) mechanisms. You&#8217;ve got compliance, where it&#8217;s binding and SEC-enforceable for publicly traded companies,&#8221; Trull explains. &#8220;And then you&#8217;ve got the more powerful (one), which is: Where will the dollars flow?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">His hope is that these basic security principles start to influence tech buyers, Trull adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;m hoping buyers stop and say: &#8216;Hey, why didn&#8217;t you sign up for this? Even if it&#8217;s voluntary,'&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Zooming Out Beyond Just Vulnerabilities\">Zooming Out Beyond Just Vulnerabilities<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Regardless of how companies address it, for Claroty&#8217;s Geyer, the pledge alone is important in how it reframes the conversation around some fundamental security issues.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, there&#8217;s vulnerability management. Organizations know to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-to-measure-patching-and-remediation-performance\" rel=\"noopener\">patch individual bugs when they pop up<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> but, as CISA notes in its report, &#8220;The vast majority of exploited vulnerabilities today are due to classes of vulnerabilities that can often be prevented at scale.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/web-assets.claroty.com\/team82_the-cps-blind-spot.pdf\" rel=\"noopener\">recent analysis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of more than 20 million assets, Claroty&#8217;s Team82 found that 22% and 23% of all industrial OT and connected medical devices (IoMT), respectively, possessed vulnerabilities with critically-ranked CVSS scores of 9.0 or higher. However, only 1.3% and 1.9% of industrial OT and IoMT devices were found to contain at least one known exploitable vulnerability and communicated directly with the Web instead of through a secure access solution.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;So if you take the traditional approach, you have to patch 23% of your assets,&#8221; Geyer says. &#8220;Not only is that an enormous number, but what we found is that when you broaden out what a risk is \u2014from just a vulnerability to things like default passwords, clear text, communications, the things that are covered in this pledge \u2014 you would only need to focus on 1.3% of your assets.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you did take the approach of catching all 23%, it turns out that you would miss 43% of the highest risks, like default credentials,&#8221; Geyer adds. &#8220;So it&#8217;s super important that CISA is taking a more expansive view of risk, rather than only focusing on vulnerabilities. That has been the traditional wisdom, and traditional wisdom is misguided, both in terms of effort and impact.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/rsa-2024-cisa-secure-design-pledge-necessary-toothless\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>At 2024&#8217;s RSA Conference this week, brand names like Microsoft,<\/p>\n","protected":false},"author":12,"featured_media":3526,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=2560%2C1706&ssl=1",2560,1706,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=640%2C426&ssl=1",640,426,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=1536%2C1023&ssl=1",1536,1023,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=1024%2C682&ssl=1",1024,682,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/is-cisas-secure-by-design-pledge-toothless-scaled.jpg?fit=2560%2C1706&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3525"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3525\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3526"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}