SBA relying on shared services to improve cyber posture
From: FederalNewsRadio.com 1500am
By Jason Miller
The Small Business Administration’s technology to-do list is split between internal and external customers.
But none of its priorities matter if it can’t secure those systems. So that’s why the SBA is turning to shared services to meet its cybersecurity demands.
Chase Garwood, the acting chief information officer at SBA, said the agency already is using the Justice Department’s Cybersecurity Assessment and Management (CSAM) tool to complete its reporting under the Federal Information Security Management Act. And now it’s turning to the Homeland Security Department to implement continuous monitoring.
“We’ve had quite a few management challenges from our Inspector General and we continue to look at those and hit those cybersecurity elements. So a big part of that in the next six months or so will be in continuous monitoring,” he said. “That’s just a capability the agency hasn’t been as robust as it could be in the last couple of years. But now that we are out of the continuing resolution, and now that we are moving forward for the rest of the fiscal year, we are looking to get into and deploying and starting to operate our configuration management to improve our cybersecurity posture, to know what’s on our networks, to make sure that the latest baseline and patches are up to date and moving that forward.”
Garwood said SBA made some good progress by deploying over the last year the 802.1x standard to improve its network defense. The standard secures an organizations network ports by applying access control rules so devices need to authenticate before they are allowed to log on.
SBA also is looking to partner with DHS U.S. Computer Emergency Response Team (U.S. CERT) to do penetration testing and implement continuous diagnostics as part of the continuous monitoring initiative.
| Print article |