Logo

dev-resources.site

for different kinds of informations.

Secure-by-Design: How AWS, Microsoft, and Others Are Embracing CISA's Cyber Goals

Published at
12/14/2024
Categories
cybersecurity
testing
aws
cloud
Author
Adedeji Michael
Categories
4 categories in total
cybersecurity
open
testing
open
aws
open
cloud
open
Secure-by-Design: How AWS, Microsoft, and Others Are Embracing CISA's Cyber Goals

Since its introduction six months ago, the Cybersecurity and Infrastructure Security Agencyโ€™s (CISA) secure-by-design pledge has catalyzed substantial cybersecurity enhancements across the software industry. The pledge, which encourages companies to prioritize security in their design and development processes, sets goals such as removing default passwords, enforcing multi-factor authentication (MFA), improving logging transparency, and adopting a proactive stance on vulnerability management.

Industry Response and Key Security Initiatives

Several major companies have embraced the pledge and made measurable advancements:

  • Amazon Web Services (AWS): AWS now mandates MFA for administrator accounts and has introduced FIDO2 passkeys, offering phishing-resistant authentication.
  • Fortinet: The company has rolled out automatic updates for entry-level devices and supports customers transitioning to cloud-based security products.
  • Microsoft: Enhancing security across Azure and Intune, Microsoft has increased MFA enforcement, committed to reducing cloud vulnerability patching times by 50%, and expanded customer access to logging dataโ€”partially in response to feedback from Capitol Hill.
  • Okta: As a leader in identity and access management, Okta has nearly eliminated default passwords and improved logging for security-critical events.
  • Sophos: Sophos has fulfilled all seven pledge requirements, enhancing customer options with FIDO2 token support and automatic firmware updates.

Many of these companies commend CISAโ€™s pledge to set a practical yet ambitious framework that supports organizations of all sizes in strengthening their cybersecurity.

Expanding Impact and Future Outlook

While CISA is exploring ways to expand the pledgeโ€™s objectives next year, industry leaders agree that the pledge has already helped elevate security standards across the software sector. Experts like Jon Clay from Trend Micro suggest that the pledgeโ€™s influence could grow further if it attracts a wider range of developers, including small and medium-sized companies. By embracing secure-by-design principles, these additional participants could contribute to an even more resilient cybersecurity ecosystem.

Featured ones: