FB pixel

NSA and CISA publish identity and access management best practices for US

Categories Access Control  |  Biometrics News
NSA and CISA publish identity and access management best practices for US
 

Two powerful security agencies of the U.S. government have published best ID and access management practices recommended for system administrators.

The list of actionable pieces of advice were created by the National Security Agency and CISA, the cybersecurity and Infrastructure Security Agency. It is difficult to know how applicable the practices can be to sysadmins elsewhere in the world.

Executives who feel they have a handle on the situation could still benefit from a discussion about IAM monitoring and auditing.

The guideline announcement dives directly into a summary of the Colonial Pipeline attack in 2021, which proved that vigilance and defensive strategies are required now to avoid catastrophic economic and physical damage due to cyberattacks.

Boilerplate IAM could have prevented the Colonial attack, according to the federal government.

“IAM is a critical part of every organization’s security posture,” Grant Dasher, an ID engineer with CISA, says in a statement.

“We must work collectively with the public and private sector to advance more secure by default and secure by design IAM solutions,” says Dasher.

The best-practices reference itself was created by the NSA and CISA along with input from a public-private security group known as the Enduring Security Framework.

The guide is broken into discussions about ways to mitigate IAM threats – describing each one and emphasizing its importance.

The topics are ID governance, environmental hardening, ID federation and single sign-on, multi-factor authentication and IAM monitoring and auditing.

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Digital sovereignty, infrastructure and credential formats colliding

Digital credential formats are on the verge of being sucked into a global debate over the nature of sovereignty with…

 

Digital ID for alcohol sales is coming to the UK: hear what it means for the identity sector

For about two years now, leaders in the UK have been promising that, soon, people will be able to use…

 

Ant International, Visa, Mastercard work to make agentic protocols interoperable 

Ant International, Mastercard and Visa are collaborating on a Know-Your-Agent (KYA) interoperability framework, which a release says is “designed to…

 

Unico acquires biometrics provider Valida, gaining entry into Argentina market

Unico has announced it signed a definitive agreement to acquire Valida, “an Argentine biometric identity verification platform with an established…

 

KPMG investment in Reality Defender backs hiring spree to fight deepfakes

U.S.-based KPMG LLP has taken a minority stake in deepfake detection developer Reality Defender and plans to integrate its fraud-protecting…

 

Australia expands eSafety powers, doubles penalties in platform accountability push

Australia’s parliament has formally passed the Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Bill 2026, granting…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events