Biden administration launches cybersecurity executive order

Key Points

  • The Biden administration announced an executive order on cybersecurity, imposing new standards for companies selling to the U.S. government.
  • The order calls for greater disclosure from software providers and aims to strengthen America’s digital infrastructure.
  • Companies must demonstrate secure development practices, with evidence posted on a government website for public benefit.
  • The U.S. Cyber Trust Mark label will be mandatory for government purchases of internet-connected devices starting in 2027.

Summary

The Biden administration has introduced a new executive order focused on enhancing cybersecurity, particularly for companies that provide services or products to the U.S. government. This order comes in response to the increasing frequency and severity of cyberattacks, which have notably disrupted federal agencies and private companies. Key measures include mandatory secure development practices for software vendors, with transparency through public disclosure of compliance evidence. Additionally, the order mandates the use of the U.S. Cyber Trust Mark for internet-connected devices in government procurement starting in 2027. This initiative aims to bolster the security of digital infrastructure by ensuring that only secure products are used by government entities. The order also addresses the need for better handling of software updates, referencing past breaches like the SolarWinds incident. However, there remains uncertainty about whether these policies will be upheld by the incoming Trump administration, as discussions between current and future cybersecurity teams have not yet taken place.

cnbc
January 16, 2025
Stocks
Read article

Related news