News: 1715261408

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

68 tech companies sign CISA's secure by design pledge

(2024/05/09)


RSAC Some of the biggest names in tech – including AWS, Microsoft, Google, Cisco and IBM – have signed up to a US Cybersecurity and Infrastructure Agency-led effort and promised to take a series of actions within a year to make their products more secure.

CISA's [1]Secure by Design pledge – signed by [2]68 orgs during RSA Conference on Wednesday – is a voluntary commitment to "make a good-faith effort to work towards" seven goals within a year of signing the pledge, and be able to measurably show their progress.

They are:

Increase the use of multi-factor authentication (MFA) across their products;

Reduce default passwords across their products;

Reduce one or more entire classes of vulnerabilities;

Increase the installation of security patches by customers;

Publish a vulnerability disclosure policy (VDP) that authorizes testing by members of the public on products, commits to not recommending or pursuing legal action against anyone engaging in good faith efforts to follow the VDP, provides a clear channel to report vulnerabilities, and allows for public disclosure in line with coordinated vulnerability disclosure best practices and standards;

Demonstrate transparency in vulnerability reporting by including accurate Common Weakness Enumeration (CWE) and Common Platform Enumeration (CPE) fields in every CVE record for their products – and issue CVE in a "timely manner," at least for critical and high-impact bugs; and

Make it easier for customers to spot evidence of intrusions affecting their products.

"Our goal for the entire community is to shift the security burden from individuals and small businesses – in other words, end users whose business is not a technology development effort or cyber security – to technology manufacturers whose business it is, and who are in the best position to address and manage security risks from the start," CISA director Jen Easterly said during the doc's signing at the annual cyber security conference.

Easterly also noted the [3]threats to US critical infrastructure from Chinese government-backed cyber thugs including Volt Typhoon.

[4]

"They are able to get into our critical infrastructure because of flaws and defects in our technology," she added. "But we have the power to change this. We can, together, achieve long-term security through fundamentally more secure software."

[5]

[6]

In fact, building more secure software is "The only way to catalyze more secure critical infrastructure," Easterly warned.

Still, these commitments remain voluntary. And it is unclear whether the tech titans who have signed on will hold up their end of the agreement – or whether the Feds will do anything to call out those who don't.

[7]CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly'

[8]CISA's early-warning system helped critical orgs close 852 ransomware holes

[9]UnitedHealth's 'egregious negligence' led to Change Healthcare ransomware infection

[10]America's War on Drugs and Crime will be AI powered, says Homeland Security boss

The plan, we hear, is to reconvene at next year's RSA Conference for an update on what the 68 have accomplished over the last year. Plus, the pledge is open to any and all software manufacturers, and CISA hopes to recruit more participants before the 2025 event.

Perhaps unsurprisingly, a big chunk of the names on the list are security providers. As such, building secure software should be a business imperative, according to Christina Cacioppo, CEO of security and compliance firm Vanta.

[11]

"First and foremost, especially as a security company ourselves, to the extent we do something silly that causes us to lose customer data, it is likely – and honestly probably should be – a company-ending event," Cacioppo argued. "As a security company, you live in a glass house. Make sure you're doing what you should do. And so, with that frame, it's very much a company-wide priority." ®

Get our [12]Tech Resources



[1] https://www.cisa.gov/securebydesign/pledge

[2] https://www.cisa.gov/securebydesign/pledge/statements-of-support

[3] https://www.theregister.com/2024/02/07/us_chinas_volt_typhoon_attacks/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjzzIPRDlZcGfHvZCostwwAAABY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjzzIPRDlZcGfHvZCostwwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjzzIPRDlZcGfHvZCostwwAAABY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/05/08/cisa_ransomware_rsac/

[8] https://www.theregister.com/2024/05/07/cisas_ransomware_warnings/

[9] https://www.theregister.com/2024/05/08/unitedhealths_egregious_negligence/

[10] https://www.theregister.com/2024/05/07/dhs_ai_civil_liberties/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjzzIPRDlZcGfHvZCostwwAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Can we start legal proceedings now?

Zibob

This is a plain, bold faced lie. They will say whatever it takes to make sure the juicy government money keeps on flowing.

So knowing that this has zero oversight, enforcement or repercussions when it fails, can we just start building the case right now on the basis that they are lying from second zero.

Security will continue to be a lamentable clown show, where the right thing is visible but skipped over in favour of the money potential.

"Reduce one or more entire classes of vulnerabilities"

Mike 137

"one or more" -- guess which will be done (with luck), and then only "reduce". But it occurs to me that if they were to succeed in significantly reducing a single class of vulnerability (a.k.a. bug) they would have to have put in place the management processes to do the same for most other classes. What will probably happen is that they will set up blacklist check for a specific coding error and disregard any bug with similar effect that doesn't match it exactly. There's long standing evidence of this approach -- patches that trap specific malicious data rather than addressing the weakness that reacts badly to a wider range of malicious data.

In any case, the list of actions hardly touches the extent of the real issues as it's purely technocentric, whereas adequate engineering is grounded in robust management processes. So "secure by design" remains a very long way off. The CISA seems rather prone to developing potentially worthwhile initiatives that can nevertheless be easily sidestepped by those signing up to them -- witness the 2023 [1]secure software attestation form .

[1] https://www.cisa.gov/secure-software-attestation-form

Doctor Syntax

No doubt the words of the pledge will be as meaningful to them as such statements as: "Your privacy/security is important to us.", "We always put security first." and the evergreen "Only a small number of customers were affected.".

Don't worry if you're a kleptomaniac; you can always take something for it.