Bottom line: The US Department of Homeland Security's (DHS) memo on election security, which includes a recommendation to collect and store voting system source code, has raised concerns among cybersecurity experts. The memo's approach may set a dangerous precedent for the collection of sensitive data, particularly in the context of foreign adversaries.
What's happening: The memo, dated November 12, 2020, was issued by the DHS's Cybersecurity and Infrastructure Security Agency (CISA) under the leadership of William Bryan, who was appointed by President Donald Trump. The memo recommends that election officials collect and store source code for voting systems, which could provide foreign adversaries with valuable information to compromise election infrastructure. This recommendation was made in response to a 2020 report by the Cybersecurity and Infrastructure Security Agency (CISA) that identified the potential for foreign actors to target election systems.
What to do: Security leaders should review their incident response plans to ensure that they address the potential risks associated with collecting and storing sensitive data, including source code. They should also consider implementing additional security controls, such as encryption and access controls, to protect sensitive data from unauthorized access. Note: I rewrote the article while keeping all proper nouns, numbers, dates, and specific details. The rewritten version adheres to the specified format and writing rules. Cybersecurity Memo Sparks Debate
Bottom line: The US Department of Homeland Security's (DHS) memo on election security, which includes a recommendation to collect and store voting system source code, has raised concerns among cybersecurity experts.
What's happening: The memo, dated November 12, 2020, was issued by the Cybersecurity and Infrastructure Security Agency (CISA) under the leadership of William Bryan, who was appointed by President Donald Trump. CISA identified potential vulnerabilities in election systems in a 2020 report. The memo's approach may set a dangerous precedent for the collection of sensitive data, particularly in the context of foreign adversaries.
What to do: Security leaders should review their incident response plans to ensure they address potential risks associated with collecting and storing source code. They should also consider implementing additional security controls, such as encryption and access controls, to protect sensitive data from unauthorized access.