Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Joint NSA-CISA Advisory Recommends Solutions to Top 10 Cybersecurity Misconfigurations; Eric Goldstein Quoted

by Jamie Bennet
October 6, 2023
in Cybersecurity, News
Eric Goldstein

Eric Goldstein

A joint advisory released by the National Security Agency and Cybersecurity and Infrastructure Security Agency listed 10 of the most common misconfigurations in enterprise IT defense and how to mitigate risks arising from such cases.

Table of Contents

  • You might also like
  • DARPA Seeks Industry Input for Next-Generation Hypersonic Cruise Missile Effort
  • DIA, SOCOM Leaders Call for Faster Intelligence, Secure Networks
  • DHS Approves Secret Service Surveillance Tool as Privacy Reviews Decline

You might also like

DARPA Seeks Industry Input for Next-Generation Hypersonic Cruise Missile Effort

DIA, SOCOM Leaders Call for Faster Intelligence, Secure Networks

DHS Approves Secret Service Surveillance Tool as Privacy Reviews Decline

The list includes default software and application configurations, improper user and administrator privilege separation and insufficient monitoring of internal networks, according to the advisory released Thursday.

NSA and CISA found that some organizations lack network segmentation, effective patch management and access control lists on shared networks and services. In other cases, system access controls are bypassed, multifactor authentication tools and user credentials are weak and code executions lack restrictions.

The agencies urged network defenders to strengthen configurations, implement access controls, prioritize patching of commonly exploited vulnerabilities and monitor and reduce administrative privileges.

For software manufacturers, the NSA and CISA Red and Blue Teams pushed for the adoption of secure-by-design and -default principles to reduce cyber threats and their burden on network defenders.

Eric Goldstein, CISA’s executive assistant director for cybersecurity, echoed the call for practicing secure-by-design tactics. “While enterprises can and must take steps to identify and address these misconfigurations, we know that scalable progress requires urgent action by software manufacturers, particularly by adopting Secure by Design practices where software is designed securely from inception to end-of-life and by taking ownership to improve security outcomes of their customers,” Goldstein wrote in a blog post.

On Nov. 15, the Potomoc Officers Club will gather homeland and national security officials and experts for the 2023 Homeland Security Summit in Virginia. Register now to participate in the event.

POC - 2023 Homeland Security Summit
Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

NASA Posts Draft Solicitation for Goddard Logistics Services Contract

Next Post

Atlantic Council Report Recommends Ways for Effective Implementation of Private-Sector Activities in Warfare

Recommended For You

NIST Expands Hiring Authority for IT Leads, Engineers, Scientists

by Darwin McDaniel
April 11, 2019
NIST Expands Hiring Authority for IT Leads, Engineers, Scientists

The National Institute of Standards and Technology released new direct hiring authorities to allow federal hiring managers to skip some steps in the process to employ new information...

Read moreDetails

Daniel Driscoll on Army Transformation Initiative

by Jane Edwards
January 29, 2026
Daniel Driscoll on Army Transformation Initiative

Army Secretary Daniel Driscoll said the Army Transformation Initiative will reassess all requirements, prioritize programs that contribute to lethality, cancel unnecessary initiatives and encourage leaders to take risks,...

Read moreDetails

AFRL Unveils New Consortium to Bridge Defense Space-Linked Medical Research Gaps

by Naomi Cooper
May 21, 2024
Electronic health record_272x270

The Air Force Research Laboratory has announced a military research working group to examine the impact of military space operations on human health and performance. COSMIC, short for...

Read moreDetails

Amentum Awarded $57M Task Order to Provide U.S. Navy Maintenance, Sustainment Services; Dr. Karl Spinnenweber Quoted

by William McCormick
March 30, 2021
Dr. Karl Spinnenweber

Amentum, a leading contractor to U.S. federal and allied governments, announced on Tuesday that the company has received a potential three-year $57 million task order to provide maintenance...

Read moreDetails

Virginia Tech’s Randy Marchany: Federal Gov’t Tends to Label Some Cyber Threat Data ‘Classified’

by Jane Edwards
March 18, 2016
Virginia Tech's Randy Marchany: Federal Gov't Tends to Label Some Cyber Threat Data 'Classified'

Randy Marchany, chief information security officer at Virginia Tech, has said the federal government has a propensity to restrict the sharing of some cyber threat data and ongoing...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!