CISA Cloud Security Order Compliance Gaps Expose Agencies to Attack Risk

A recent audit by the DHS inspector general found that most federal agencies failed to implement recommended cloud security controls, leaving them vulnerable to attacks.

Bottom line: The failure of federal agencies to comply with cloud security orders increases the risk of successful attacks on sensitive data.

What's happening: A recent audit by the DHS inspector general found that the Cybersecurity and Infrastructure Security Agency (CISA) lacked the power to compel agencies to implement its Binding Operational Directives (BODs) for cloud security. The audit also revealed that 97% of surveyed agencies reported being "unaware" of the risks associated with cloud computing. Furthermore, the audit found that the top three cloud providers – Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) – had not provided adequate information to agencies about the security controls in place.

What to do: Security leaders must prioritize the implementation of recommended cloud security controls, such as encryption at rest and in transit, and multi-factor authentication, to mitigate the risk of successful attacks. --- [REWRITE] TITLE: CISA Cloud Security Order Compliance Gaps Expose Agencies to Attack Risk SUMMARY: A recent audit by the DHS inspector general found that most federal agencies failed to implement recommended cloud security controls, leaving them vulnerable to attacks.

Bottom line: The lack of agency compliance with CISA's cloud security orders increases the risk of successful attacks on sensitive data.

What's happening: The Cybersecurity and Infrastructure Security Agency (CISA) lacked the power to compel agencies to implement its Binding Operational Directives (BODs) for cloud security. A recent audit by the DHS inspector general found that 97% of surveyed agencies reported being "unaware" of the risks associated with cloud computing. The top cloud providers, including AWS, Microsoft Azure, and GCP, failed to provide adequate information about security controls.

What to do: Security leaders must prioritize the implementation of recommended cloud security controls, such as encryption at rest and in transit, and multi-factor authentication. --- [FINAL] TITLE: CISA Cloud Security Order Compliance Gaps Expose Agencies to Attack Risk SUMMARY: A recent audit by the DHS inspector general found that most federal agencies failed to implement recommended cloud security controls, leaving them vulnerable to attacks.

Bottom line: The lack of agency compliance with CISA's cloud security orders increases the risk of successful attacks on sensitive data.

What's happening: The Cybersecurity and Infrastructure Security Agency (CISA) lacked the power to compel agencies to implement its Binding Operational Directives (BODs) for cloud security. A recent audit by the

Source: CyberScoop