In response to the Trump administration announcement of the appointment of a White House cybersecurity coordinator. Contrast Security Co-founder and CTO, Jeff Williams, was ask to provide his thoughts in a recently published CSO article, "US Needs a Federal CISO." Below is an excerpt from that article as well as Jeff's quotes.
"A federal CISO is what’s needed to get healthy and get those grades up," he said. "Someone has to coordinate efforts, set priorities, manage the budget, raise awareness and create a culture of cybersecurity in government. Definitely a tall order."
IN THE NEWS...
A White House cybersecurity coordinator is a good first step, but the government also needs a federal CISO
by Maria Korolov, Contributing Writer, CSO
Last week, the Trump administration announced the appointment of a White House cybersecurity coordinator. That's a good first step, security experts say, but the government also needs to have a federal CISO.
"It's a big leadership vacancy," said Sanjay Beri, CEO and co-founder at cloud security vendor Netskope.
The job of a federal CISO is very new — it was only created last year and filled in September with the appointment of retired brigadier general Gregory Touhill...
Last week, President Donald Trump's homeland security adviser, Tom Bossert, said that the administration has selected Rob Joyce, who previously headed up the National Security Agency's office of Tailored Access Operations, to be the White House cybersecurity coordinator. There's been no official announcement yet, however...
The new administration should address all aspects of security, said Danielle Jackson, CISO at authentication vendor SecureAuth.
"Appointing a CISO will ensure that the increase in risk of cyber threats to our nation is appropriately addressed, monitored and combated," she said. "It certainly doesn't hurt to have an extra set of experienced eyes focused on our nation whose president has frequent cyber communications -- social media included -- and engagement with other nations."
There are other federal agencies that work on cybersecurity issues....
"For example, both the Government Accountability Office and National Institute of Standards and Technology play key roles," said Jeff Williams, CTO and cofounder at application security vendor Contrast Security.
"The GAO has been auditing agencies using the NIST Cybersecurity Framework for several years, and the results have not been stellar," he said. "The GAO review isn’t a deep review, just a high-level overview."
Someone has to step up and start doing the hard work.
"A federal CISO is what’s needed to get healthy and get those grades up," he said. "Someone has to coordinate efforts, set priorities, manage the budget, raise awareness and create a culture of cybersecurity in government. Definitely a tall order."
READ ENTIRE ARTICLE ONLINE AT CSO >>