The Future-Forward Cybersecurity Fix
[Commentary] Recent breaches to US federal computer networks -- such as the Office of Personnel Management hack -- have catapulted the need for improved identity management and authenticated access to the top of the national agenda. The White House-mandated a 30-day call for action for all federal agencies: tighter control of privileged user access and multifactor authentication. After closing out the “30-day sprint” July 11, the government committed to a July 20 results announcement date only to delay the release until an undetermined date. The delay may serve as an indication the government has a long way to go in its efforts to increase network security, yet meeting the call for improved identity authentication is largely achievable within the existing infrastructure of any government computer network. Today, all federal employees have already been issued Personal Identity Verification credentials, which can be leveraged by a derived credentials system to instantly enhance secure network access from mobile devices.
The US government is playing catch-up on security primarily because it has not been able to keep up with the advances in technology over the last decade. With the imminent availability of derived PIV credentials, the US government can effectively address the critical need to improve the current state of cybersecurity. The growing demand for a more mobile work environment for federal employees and the introduction of new connected devices will create new potential entry points for unauthorized access within a government network.
[Chris Edwards is chief technology officer at Intercede]
The Future-Forward Cybersecurity Fix