Secure by Design is just the start, CISA official says

<p>Incorporating a Secure by Design framework is just the start to engineering a threat-resilient digital environment, per officials helming the initiative at the Cybersecurity and Infrastructure Security Agency.&nbsp;</p>

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

<p>Speaking during the Critical Effect cybersecurity conference in Washington, D.C., Kirk Lawrence, CISA&rsquo;s program manager for its Secure by Design initiative, said that implementing its principles is akin to &ldquo;locking the front door&rdquo; when securing a house: a first step.&nbsp;&nbsp;</p>

<p>&ldquo;It doesn&#39;t mean that your place can&rsquo;t get broken into, that someone can&#39;t come steal your stuff, but they [have] to work a little harder now to have a different set of skills,&rdquo; Lawrence said. &ldquo;Secure by Design is not the end of risk. It&#39;s the start of resilience.&rdquo;</p>

<p>He specified that threat detection and national coordination efforts are weak spots in the Secure by Design architecture, but it remains &ldquo;a good first step&rdquo; in creating a cybersafe ecosystem.&nbsp;</p>

<p>Lawrence also previewed CISA&rsquo;s ongoing effort to articulate the business benefits for Secure by Design. The core mission in this effort is to create talking points on Secure by Design for a technology project owner to communicate its value to C-level executives in a given organization to garner their support.</p>

<p>&ldquo;One of the key principles that we&#39;ve advocated since the beginning is that it&#39;s not going to happen unless you have executive buy-in, which is one of the very first steps to having effective Secure by Design,&rdquo; Lawrence said.&nbsp;</p>

<p>Regarding a deliverable timeline, he estimated that a business case for Secure by Design will be ready within the coming six months.&nbsp;</p>

<p>Lawrence&rsquo;s comments follow <a href=“CISA officials who led Secure by Design initiative resign - Nextgov/FCW”>the departure</a> of two former leaders of the Secure by Design initiative, Bob Lord and Lauren Zabierek, in mid-April. President Donald Trump has also <a href=“Trump cyber executive order aims to amend ‘problematic’ parts of Biden, Obama cyber orders - Nextgov/FCW”>issued a new executive order</a> that changes cybersecurity policies outlined in two previous executive orders issued under the Biden administration.&nbsp;</p>

<p>Updated cyber provisions notably include an August 1 2025 deadline for the director of the National Institute of Standards and Technology to implement a consortium within the National Cybersecurity Center of Excellence to develop secure software development guidance based on the <a href=“https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-218.pdf”>Secure Software Development Framework</a>.&nbsp;</p>

<p>That framework, published by NIST in 2022, notably calls for organizations to adopt Secure by Design principles.&nbsp;</p>

<p>&ldquo;Addressing security requirements and risks during software design (secure by design) is key for improving software security and also helps improve development efficiency,&rdquo; the document reads.&nbsp;</p>

Article Link: Secure by Design is just the start, CISA official says - Nextgov/FCW