NSA shares cyber hygiene best practices

On September 3, the National Security Agency (NSA) released the Cybersecurity Information Sheet (CSI), “Best Practices for Cyber Hygiene.”

Adversaries increasingly use artificial intelligence (AI) to accelerate and scale various cyber network exploitation techniques. Specifically, malicious actors are using AI to automate the intrusion lifecycle, taking advantage of poor cyber hygiene such as unpatched systems, weak authentication, and misconfigurations. Persistent issues include default configurations, insufficient segmentation, and inadequate monitoring.

Developing and prioritizing essential cyber hygiene is encouraged to defend networks against these advanced persistent threats. This guide prioritizes mitigations ranked by effectiveness, building on the NSA’s Top Ten Cybersecurity Mitigation Strategies, National Institute of Standards and Technology frameworks, and the Department of War (DoW) Chief Information Officer’s Brilliant at the Basics initiative information.

Cyber hygiene involves foundational steps to minimize attack surfaces, detect anomalies, and quickly respond to incidents.  This guide will assist organizations looking to develop plans for long-term actions to harden networks against this changing threat landscape, emphasizing immediate actions to reduce risk such as network inventory, multi-factor authentication, and patching while building toward implementation of Zero Trust practices like segmentation and continuous monitoring. While applicable broadly, the guidance prioritizes defenses against AI-enhanced threats like automated reconnaissance and living off the land techniques.

The framework uses progressive maturity tiers that advance from immediate risk reduction to sustained resilience. Network defenders, cybersecurity teams, and enterprise leaders supporting industry organizations – and particularly those throughout the DoW and Defense Industrial Base managing National Security Systems – should prioritize Tier 0 activities (e.g., identifying security gaps and implementing common defensive improvements) to achieve quick wins, followed by Tier 1-3 enhancements.

While the mitigations in the guide will help counter a broad range of exploitation techniques to help minimize mission impacts of network compromises, they do not cover every possible attack vector and should not be used as the sole means of hardening networks.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.