Client Alert: White House Executive Order Seeks to Strengthen Federal Cybersecurity

General News

Summary

• It directs the Director of FedRAMP, in collaboration with CISA and NIST to “develop FedRAMP policies and practices to incentivize or require cloud service providers in the FedRAMP Marketplace to produce baselines with specifications and recommendations for agency configuration of agency cloud-based systems in order to secure Federal data based on agency requirements.” • Finally, it directs the Under Secretary of Commerce for Oceans and Atmosphere, the Administrator of the National Oceanic and Atmospheric Administration, and NASA Administrator to review “civil space contract requirements in the FAR” and recommend to the FAR Council, and for the FAR Council to adopt, updates to civil space cybersecurity requirements and relevant contract language. • Finally, it directs NIST and CISA to develop guidelines for the secure management of access tokens and cryptographic keys used by cloud service providers; the FedRAMP Director, in consultation with NIST and CISA, to develop updated FedRAMP requirements incorporating these access token and cryptographic key guidelines; and the OMB Director, in consultation with NIST, CISA, and the GSA, to require FECB agencies to “follow best practices concerning the protection and management of hardware security modules, trusted execution environments, or other isolation technologies for access tokens and cryptographic keys used by cloud service providers in the provision of services to agencies.” • Section 5 directs agencies with grantmaking authority to make available federal grant funding to assist states with the development and issuance of mobile driver’s licenses, which may be used to access public benefits programs requiring identity verification. It further directs agencies to consider accepting digital identity documents as evidence to access public benefits programs, in a manner that is interoperable with relevant standards and trust frameworks, does not enable surveillance and tracking by authorities and private parties, and supports user privacy and data minimization. Failed attestations or failure to comply with these standards may give rise to liability for false or misleading statements about the company’s cybersecurity practices and lead to potential SEC or private enforcement. Like with the federal secure software development standards, government contractors should prepare to comply with this new contractual language, lest they run afoul of a new round of False Claims Act enforcement based on these requirements.

Classifications

industries
Government, Public sector
applications
AI & Machine learning

AskAI Classifications

Labels
No AI classifications detected

Linked Companies