<!–Saxotech Paragraph Count: 9
–>
“What gets measured gets done, typically. When these areas aren’t reflected in statistics that show how malware is getting into the government, this is something we have to work on to defeat these threats,” said Kelly Collins, vice president of public sector at Bromium, which recently partnered with defense contractor SAIC to provide vSentry, a software-based security system designed to protect government and partner networks from spear-phishing and other attacks. “Spear-phishing is not an advanced attack per se … but if somebody is tricked into clicking an infected link, that becomes the delivery mechanism for malware to traverse into the system. The end user becomes last mile, in a sense. In key government agencies, that’s a scary paradigm.”
Targeting spear-phishing
One way agencies are combating spear-phishing specifically, as well as broader social-engineering and other cyber-threat tactics, is through employee training.
According to the FISMA report, more than two-thirds of the agencies sponsored emerging threat exercises, including phishing, to increase and measure the effectiveness of cybersecurity awareness and training. All agencies reported providing some form of supplemental security training during the 2013 fiscal year, with some providing daily or weekly supplemental security training.
For agency users with network access privileges, 94 percent were given annual security awareness training, up from 88 percent in fiscal 2012.
Agencies also reported that 98 percent of new users were given security awareness training prior to being granted network access, up from 89 percent in 2012, according to the report.
More broadly, agencies — particularly DHS, charged with coordinating federal security — are taking measures to secure and build resilience into federal networks and systems. That includes new authorities to monitor agency networks, as well as the governmentwide deployment of continuous diagnostics and mitigation (CDM) programs.
The measures come in addition to existing intrusion detection and protection systems and the expansion of partnerships between agencies and with the private sector.
CDM “takes the inside of the network and it turns it into a living, breathing immune system. … It constantly knows what’s secure and has a little dashboard that goes with it so agencies can share and compare notes,” said Phyllis Schneck, deputy undersecretary of cybersecurity in DHS’s National Protection and Programs Directorate.
“Instead of compliance and building a big binder that no one will ever use again, you have a constant understanding of how safe the network is. Putting that together, to understand the perimeter and the inside of the networks between federal agencies, combining that data with what we can see in the private sector, and pushing that out rapidly between humans and between machines — that’s where we’re going, that’s where our projects are pointed.”
