UPDATED 21:35 EDT / FEBRUARY 03 2022

Homeland Security SECURITY

DHS establishes Cyber Safety Review Board to elevate cybersecurity

The U.S. Department of Homeland Security today announced the establishment of the Cyber Safety Review Board that will bring together government and industry leaders to elevate cybersecurity.

The establishment of the CSRB is the result of a Biden Administration executive order in May that ordered that the board be created. Robert Silvers, DHS Under Secretary for Policy, will serve as chair of the board, with Heather Adkins, Google LLCs senior director for security engineering, serving as deputy chair.

DHS’s Cybersecurity and Infrastructure Security Agency will manage, support and fund the board and CISA Director Jen Easterly is responsible for appointing CSRB members.

The CSRB will review and assess significant cybersecurity events so government, industry and the broader security community can better protect networks and infrastructure. The board will deliver strategic recommendations to the President and the Secretary of Homeland Security based on cybersecurity incidents that the board studies.

First out of the gate for the CSRB will be a review of the Apache Log4j vulnerabilities discovered in December. Hackers subsequently targeted the vulnerabilities, presenting what DHS describes as an urgent challenge to network defenders. The board examination will generate lessons learned from the cybersecurity community. The White House and DHS determined that focusing on this vulnerability and its associated remediation process was the most important first use of CSRB’s expertise.

The report into Log4j will include a review and assessment of vulnerabilities associated with the Log4j software library, recommendations for addressing any ongoing vulnerabilities and threat activity, and recommendations for improving cybersecurity and incident response practices and policy based on lessons learned from the Log4j vulnerabilities.

“The focus of the newly formed Cyber Safety Review Board on analyzing past incidents to help prevent future ones is a welcome change from focusing on who to blame when something goes wrong,” Mike Parkin, engineer at cyber risk remediation company Vulcan Cyber Ltd., told SiliconANGLE. “Its work will, hopefully, augment the work being done by other public/private partnerships, such as InfraGard.

Ray Kelly, fellow at application security firm NTT AppSec Solutions Inc., said the board could prove to be quite valuable.

“In-depth review of major security incidents with recommendations for remediation and incident response practices can certainly be useful for organizations,” Kelly said. “We will have to wait and see how the first report looks when they address the critical and ever-expanding Log4j vulnerability to determine if the level of detail and guidance is going to be helpful.”

Image: DHS

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.