FB pixel

NSA and CISA publish identity and access management best practices for US

Categories Access Control  |  Biometrics News
NSA and CISA publish identity and access management best practices for US
 

Two powerful security agencies of the U.S. government have published best ID and access management practices recommended for system administrators.

The list of actionable pieces of advice were created by the National Security Agency and CISA, the cybersecurity and Infrastructure Security Agency. It is difficult to know how applicable the practices can be to sysadmins elsewhere in the world.

Executives who feel they have a handle on the situation could still benefit from a discussion about IAM monitoring and auditing.

The guideline announcement dives directly into a summary of the Colonial Pipeline attack in 2021, which proved that vigilance and defensive strategies are required now to avoid catastrophic economic and physical damage due to cyberattacks.

Boilerplate IAM could have prevented the Colonial attack, according to the federal government.

“IAM is a critical part of every organization’s security posture,” Grant Dasher, an ID engineer with CISA, says in a statement.

“We must work collectively with the public and private sector to advance more secure by default and secure by design IAM solutions,” says Dasher.

The best-practices reference itself was created by the NSA and CISA along with input from a public-private security group known as the Enduring Security Framework.

The guide is broken into discussions about ways to mitigate IAM threats – describing each one and emphasizing its importance.

The topics are ID governance, environmental hardening, ID federation and single sign-on, multi-factor authentication and IAM monitoring and auditing.

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Canada regulator backs privacy-preserving age assurance

The Office of the Privacy Commissioner of Canada (OPC) has published a policy note and guidance documents pertaining to age…

 

FCC seeks comment on KYC revision for commercial phone calls

The U.S. Federal Communications Commission (FCC) has proposed stronger KYC requirements for voice service providers to prevent scams and illegal…

 

Deepfake detection upgrade for Sumsub highlights continuous self-improvement

Sumsub has launched an upgrade to its deepfake detection product with instant online self-learning updates to address rapidly evolving fraud…

 

Metalenz debuts under-display camera for payment-grade face authentication

Unlocking a smartphone with your face used to require a camera placed in a notch or a punch hole in…

 

UK regulators pan patchwork policy for law enforcement facial recognition

The UK’s two Biometrics Commissioners shared cautionary observations about the use of facial recognition in law enforcement over the weekend…

 

IDV spending to hit $29B by 2030 as DPI projects scale: Juniper Research

Spending on digital identity verification (IDV) technology is projected to reach a 55 percent growth rate between now and 2030,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events