Trump Cybersecurity Order: Impacts & Analysis
- A recent executive order from the Trump administration has altered federal cybersecurity policy, specifically impacting the software supply chain and encryption standards.The order eliminates a requirement for companies...
- Previously, a Biden administration directive mandated that the Cybersecurity and Infrastructure Security Agency (CISA) establish a standard self-attestation form, to be completed by a company officer, verifying adherence...
- The new executive order tasks the National Institute for Standards and Technology (NIST) with creating a reference security implementation for the SSDF, removing the attestation requirement.
The Trump administration is reshaping federal cybersecurity, promptly impacting software supply chains and encryption. Key changes include eliminating mandatory self-attestation for software vendors selling too the government. This significant shift tasks NIST with creating a new SSDF implementation, replacing SP 800-218. The order also rolls back requirements for quantum-resistant encryption adoption. Critics fear these changes could weaken vital cybersecurity attestation processes. News Directory 3 provides you with incisive analysis, revealing how this rollback could affect government contractors and proactive security measures.Discover what’s next for government cybersecurity as these changes unfold.
trump EO Rolls Back Key Cybersecurity Attestation Requirements
A recent executive order from the Trump administration has altered federal cybersecurity policy, specifically impacting the software supply chain and encryption standards.The order eliminates a requirement for companies selling critical software to the government to self-attest to compliance with the Secure Software Growth Framework (SSDF).
Previously, a Biden administration directive mandated that the Cybersecurity and Infrastructure Security Agency (CISA) establish a standard self-attestation form, to be completed by a company officer, verifying adherence to SSDF provisions.This requirement followed breaches at several federal departments, including Commerce, Treasury, Homeland Security, and the National Institutes of Health, as well as private sector compromises affecting Microsoft, Intel, Cisco, Deloitte, FireEye, and CrowdStrike.
The new executive order tasks the National Institute for Standards and Technology (NIST) with creating a reference security implementation for the SSDF, removing the attestation requirement. This new implementation will supersede SP 800-218,the existing government SSDF reference,though the new guidelines are expected to draw from it. This change in cybersecurity attestation is a key shift.
Critics argue that this rollback could allow government contractors to bypass proactive measures designed to address security vulnerabilities, such as those exploited in the SolarWinds compromise. The cybersecurity attestation process is seen as vital for maintaining standards.
“that will allow folks to checkbox their way through ‘we copied the implementation’ without actually following the spirit of the security controls in SP 800-218,” Jake Williams, vice president of research and development for Hunter Strategy, said. “Very few organizations actually comply with the provisions in SP 800-218 as they put some onerous security requirements on development environments, which are usually [like the] Wild West.”
Furthermore, the Trump EO rescinds requirements for federal agencies to prioritize products using encryption schemes resistant to quantum computer attacks. The prior administration had aimed to accelerate the adoption of new quantum-resistant algorithms under development by NIST.
What’s next
The NIST will now begin work on the new SSDF reference implementation, and federal agencies will adjust their procurement processes accordingly. The long-term impact on government cybersecurity posture remains to be seen, as the changes are implemented and assessed.
