InvestorsHub Logo
Followers 111
Posts 6224
Boards Moderated 0
Alias Born 04/20/2016

Re: Gold49er post# 170849

Friday, 06/23/2017 1:30:58 PM

Friday, June 23, 2017 1:30:58 PM

Post# of 235099
White House Tells Agencies to Tighten Up Cyber Defenses 'Immediately

Read the 4th Bullet Pt @ http://www.nextgov.com/cybersecurity/2015/06/white-house-tells-agencies-tighten-online-security-immediately/115216/

According to White House officials, the emergency procedures include:

"Immediately" deploying so-called indicators, or tell-tale signs of cybercrime operations, into agency anti-malware tools. Specifically, the indicators contain "priority threat-actor techniques, tactics and procedures" that should be used to scan systems and check logs.

Patching critical-level software holes "without delay." Each week, agencies receive a list of these security vulnerabilities in the form of DHS Vulnerability Scan Reports.

Tightening technological controls and policies for "privileged users," or staff with high-level access to systems. Agencies should cut the number of privileged users; limit the types of computer functions they can perform; restrict the duration of each user's online sessions, presumably to prevent the extraction of large amounts of data; "and ensure that privileged user activities are logged and that such logs are reviewed regularly."

Dramatically accelerating widespread use of of "multifactor authentication" or two-step ID checks. Passwords alone are insufficient access controls, officials said. Requiring personnel to log in with a smartcard or alternative form of ID can significantly reduce the chances adversaries will pierce federal networks, they added, stopping short of mandating multi-step ID checks.