• DMCA
  • Terms and Conditions
  • Privacy Policy
  • Contact Us
  • Whitelist
Friday, May 27, 2022
Survival Society
  • Home
  • Naval Survival
  • Land Survival
  • Survival Strategy
  • Defense
No Result
View All Result
  • Home
  • Naval Survival
  • Land Survival
  • Survival Strategy
  • Defense
No Result
View All Result
Survival Society
No Result
View All Result

Falcon Spotlight ExPRT.AI Helps Federal Agencies Meet CISA Mandate

wbstadm by wbstadm
November 15, 2021
in Uncategorized
0
Falcon Spotlight ExPRT.AI Helps Federal Agencies Meet CISA Mandate

The Cybersecurity and Infrastructure Security Agency (CISA) issued a mandate on November 2, 2021, for all U.S. federal agencies to fix hundreds of known vulnerabilities. Binding Operational Directive 22-01 (BOD 22-01) compels all federal departments and agencies to specifically address the vulnerabilities in the published catalog to protect and safeguard valuable federal data and information systems. The order will require all agencies to have patches in place for all vulnerabilities published prior to 2021 within six months, and all vulnerabilities from 2021 and beyond within two weeks of the issuance date. 

The U.S. Department of Homeland Security and CISA will oversee the implementation of this mandate. As stated in the directive, “It is essential to aggressively remediate known exploited vulnerabilities to protect federal information systems and reduce cyber incidents.” The catalog of vulnerabilities contains many of the most highly exploited and most significant severity vulnerabilities that are known, making this list an important and essential tool for review and remediation within any organization covered in the directive. 

While this directive is required only for federal agencies, CISA strongly recommends that all state and local government as well as private organizations review and monitor the provided vulnerability catalog and implement remediation procedures in the time frame specified in the directive to strengthen their overall security posture. 

As a result of this mandate, CrowdStrike has added this catalog of vulnerabilities to Falcon Spotlight™ ExPRT.AI as a new source of exploited vulnerability data. With Falcon Spotlight, government agencies and enterprises alike are able to quickly identify and prioritize vulnerabilities that pose the most risk for their organization. 

Why Issue BOD 22-01?

This is the first time CISA has issued a government-wide mandate for federal agencies to remediate vulnerabilities. CISA Director Jen Easterly stated that CISA is using its authority to help enforce and encourage federal cybersecurity efforts to protect from potential malicious actors. She goes on to say, “The Directive lays out clear requirements for federal civilian agencies to take immediate action to improve their vulnerability management practices and dramatically reduce their exposure to cyber-attacks.” Because this catalog contains already known exploited vulnerabilities and due to the sensitive or valuable nature of government systems and data, this mandate is timely to help ensure the protection and defense of the U.S. infrastructure. 

Falcon Spotlight’s ExPRT.AI Helps Enable IT Staff to Meet CISA Requirements

SecOps staff for both government agencies and organizations are often pressed for time. With the plethora of critical and highly scored vulnerabilities, a common issue arises where not all highly scored vulnerabilities are addressed in a timely manner. This leaves organizations with gaps or flaws within their systems — and threat actors use those holes to exploit organizations for nefarious gain. Historically, SecOps has relied on vendors to provide some prioritization information around this large body of vulnerabilities — but that is not enough. With the limited amount of time typically allocated for patching and updating systems, critical vulnerabilities are not being remediated, and that could be potentially very damaging.

Falcon Spotlight goes beyond identification of these vulnerabilities and prioritizes them  in a new and extremely useful way. This method utilizes the recently announced ExPRT.AI — a dynamic model that capitalizes on a wide variety of vulnerability and threat-based telemetry, including CrowdStrike’s threat intelligence — as well as CISA’s Known Exploited Vulnerabilities Catalog to provide a more intuitive, relevant score or rating that enables staff to target those vulnerabilities that would have the most detrimental impact within an organization. 

How Does Falcon Spotlight’s ExPRT.AI Work? 

Falcon Spotlight’s ExPRT.AI is based on two important factors: the data that the algorithm model relies on and the structure and dynamism of the model itself. Let’s explore how this works.

The ExPRT.AI model is constantly adapting. It takes data from an impressive database of threat and exploit intelligence from a large variety of sources, and then uses both historical and new data (such as the CISA catalog) to create an output, the ExPRT Rating, which provides a more accurate and transparent rating than what SecOps staff have traditionally been forced to rely on. Since the model is always adapting, it provides a dynamic ExPRT rating — one that changes as new data comes in. When new threats or exploits are discovered, the rating for the vulnerability changes to reflect whether it should be ranked more or less severely based on the inputs. 

While other vendors may claim to have a dynamic rating system, only CrowdStrike’s vast library of telemetry can provide such an operationally useful solution as ExPRT.AI, giving SecOps staff greater efficiency and a higher degree of visibility to immediately remediate or patch the vulnerabilities that adversaries are most likely to target, specific to their organization. To see how Falcon Spotlight ExPRT.AI works in action, check out this demo.

Additional Resources

Source
Falcon Spotlight ExPRT.AI Helps Federal Agencies Meet CISA Mandate is written by Alyssa Ideboen for www.crowdstrike.com

Previous Post

November 2021 Patch Tuesday: Updates and Analysis

Next Post

AAA Rating and Best EDR Award

Next Post
AAA Rating and Best EDR Award

AAA Rating and Best EDR Award

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter

Categories

  • Defense
  • Land Survival
  • Naval Survival
  • Survival Strategy
  • Trending
  • Comments
  • Latest
Army modernization programs need to put ‘points on the board’: Acquisition chief – Breaking Defense Breaking Defense

Army modernization programs need to put ‘points on the board’: Acquisition chief – Breaking Defense Breaking Defense

February 17, 2022
Lockheed Martin walks away from $4.4B Aerojet Rocketdyne acquisition – Breaking Defense Breaking Defense

Lockheed Martin walks away from $4.4B Aerojet Rocketdyne acquisition – Breaking Defense Breaking Defense

February 14, 2022
Starting Seeds, The Easy And Smart Way Off The Grid News

Starting Seeds, The Easy And Smart Way Off The Grid News

March 11, 2022
China’s Third Aircraft Carrier Takes Shape: CSIS – Breaking Defense Breaking Defense

China’s Third Aircraft Carrier Takes Shape: CSIS – Breaking Defense Breaking Defense

June 16, 2021
After DoD’s $1.5B move, Army and Marines rush to buy new Javelins, Stingers

After DoD’s $1.5B move, Army and Marines rush to buy new Javelins, Stingers

0
Workplace Hate Crimes | Carol Cambridge

Workplace Hate Crimes | Carol Cambridge

0
Situational Awareness | Carol Cambridge

Situational Awareness | Carol Cambridge

0
Survival Mindset vs. Victim Mentality

Survival Mindset vs. Victim Mentality

0
After DoD’s $1.5B move, Army and Marines rush to buy new Javelins, Stingers

After DoD’s $1.5B move, Army and Marines rush to buy new Javelins, Stingers

May 6, 2022
A Littoral Combat Ship deploys to 6th Fleet for the first time

A Littoral Combat Ship deploys to 6th Fleet for the first time

May 6, 2022
For first time, France talks openly about sending weapons to Ukraine

For first time, France talks openly about sending weapons to Ukraine

May 5, 2022
Marines’ new aviation plan in the works: General – Breaking Defense Breaking Defense

New Marine Corps aviation plan makes ‘digital interoperability’ a top priority

May 3, 2022

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • August 2019
  • July 2019
  • May 2018
  • April 2018
  • DMCA
  • Terms and Conditions
  • Privacy Policy
  • Contact Us
  • Whitelist

© 2021 All Rights Reserved survivalsociety.com

No Result
View All Result
  • Home
  • Naval Survival
  • Land Survival
  • Survival Strategy
  • Defense

© 2021 All Rights Reserved survivalsociety.com