Pivoting to security, there’s more.
The Cybersecurity and Infrastructure Security Agency (CISA) is seeking feedback on its “secure by design” white paper, which promotes stricter security principles in the design and development of software products. CISA released an updated joint guidance with domestic and foreign partners in October and is now requesting additional comments on the guidance. The agency aims to encourage technology manufacturers to prioritize security and is interested in the economics of secure development and integrating security into computer science education. The deadline for comment submissions is February 20, 2024.
NASA’s Office of Inspector General conducted an audit of NASA’s privacy program and found it comprehensive but needed improvements. One area of concern is the lack of data loss protection (DLP) implementation in Microsoft 365, which has resulted in self-reported data losses without proper tracking and monitoring. NASA also faces challenges in responding to breaches and ensuring training for security and privacy roles. The report provides recommendations for addressing these issues, which NASA has agreed to implement.
Comment time! For software vendors in particular, this is your time to speak up.
Managed services providers specializing in cybersecurity and data protection can leverage the NASA audit to showcase their expertise in addressing data loss protection and breach response challenges. No reason not to reuse the work.

