@Grace_Segers, @byrdinator, and I deliver on our show's name with a truly hoth take: Attack of the Clones gets too much hate and actually has a bunch of fun stuff in it. 😱🔥
The House Appropriations homeland security subcommittee is about to start a hearing on "Modernizing the Federal Civilian Approach to Cybersecurity" with acting CISA chief Brandon Wales and new CISA Cyber Division head Eric Goldstein.
Wales and Goldstein will tell Congress that CISA needs better "visibility into agency cloud
environments and end-points," esp. in light of remote work. And they'll announce work with NIST on a "common baseline" of security rules, esp. for logging. docs.house.gov/meetings/AP/AP…
Wales and Goldstein, whose agency is dealing with SolarWinds and Exchange on top of its regular work, will also deliver this warning to appropriators: CISA's "incident response resources must be fortified now to ensure that we will not be overwhelmed in the future."
One of the three men charged was previously charged in connection with this activity in 2018: justice.gov/opa/pr/north-k…
"The DPRK cyber threat has followed the money and turned its revenue-generation sights on the most cutting-edge aspects of international finance, including through the theft of cryptocurrency from exchanges and other financial institutions," AAG John Demers says on press call.
Scoop: The public-private ICT supply chain security task force plans to craft a legislative proposal to improve information sharing, including liability protections. Task force has found companies are afraid of vendors suing them for sharing info on risks. subscriber.politicopro.com/article/2021/0…
The supply chain task force approved the plan to develop an info sharing proposal at its 2/12 meeting, along w/ other projects (stay tuned for more on those).
The task force won't send its proposal directly to WH or Congress but will find other parties best positioned to do so.
"We wouldn't do the advocacy per se," a person involved in the task force's work said of the info sharing proposal. "We would provide the analysis and the motivation for [that advocacy]."
Naturally, this storm is worsening our already dysfunctional vaccine rollout process.
"Dallas hit 5 degrees on Monday morning, its coldest reading since 1989. ... In Dallas the average high on Feb. 14 is about 58 degrees, the average low 42 degrees."
Half of the witnesses (@C_C_Krebs and former Principal Deputy DNI Sue Gordon) were pushed out by Trump.
One theme from hearing so far: interest in making CISA the civilian fed govt's network defender. Not just helping, but actually supervising improvements to agencies' networks.
One suggestion made: let agencies offload accountability to CISA in exchange for giving up authority.
Another notable moment: @C_C_Krebs noted how little $ CISA had for IR and for CI operator engagement and said his "biggest regret" as director was inability to "plow additional resources" Into CI community engagement.
$800m of CISA's $1.2b cyber budget went to CDM and EINSTEIN.