Archive for the ‘NSA’ Category

NSA Shines Light on Importance of Transparency and Accountability – HS Today – HSToday

Sunshine Week is in full swing across the federal government, and the National Security Agency (NSA) is taking the time to recognize and reaffirm Agency values of transparency and accountability.

A time to acknowledge and celebrate transparency in the federal government, Sunshine Week was created 18 years ago by the American Society of News Editors, now known as the News Leaders Association. Freedom of Information Day was also celebrated this weekon 16 March. Speaking at the Agencys Privacy Day event last year, GEN Paul M. Nakasone, Commander, U.S. Cyber Command, Director, NSA/Chief, CSS, explained that transparency is always a work in progress: NSA has had a history of strength, civil liberties, and privacy protections in daily operationsand has made great strides in being more transparent about what we do.

NSAs Civil Liberties, Privacy, and Transparency (CLPT) Office is key to the Agencyspromotion and integrationof civil liberties and privacy protections into everything NSA does: policies, plans, procedures, technology, programs, and activities.

At the head of the CLPT Office isActing Director Thomas D. T.D. Stuck, who said hes always asking, How can we be more effective in our transparency? Its more than just providing information, too: Its giving the context of what were doing so that the public can have a sense of how information fits into the broader sense of why there is a National Security Agency, Stuck said.

Transparency and accountability go hand in hand. Ultimately, Stuck underlined, Were accountable to the American people.

Learn more about the CLPT Office bywatching a videoor exploringtheir webpage.

Read more at NSA

Read more:
NSA Shines Light on Importance of Transparency and Accountability - HS Today - HSToday

Even Rep. LaHood Likely Can’t Sue the NSA or FBI to Protect His Rights – EFF

In a stunning revelation, a sitting U.S. Congressman has publicly identified himself as the subject of likely illegal surveillance by the NSA and FBI. During a hearing on the question of renewal the controversial mass NSA spying authorities known as FISA Amendments Act section 702, Rep. Darin LaHood of Illinois revealed: the member of Congress who was wrongly queried multiple times solely by his name was in fact me. It seems Rep. LaHood was one of the Congresspersons identified in a footnote (footnote 92) in a recent government report about the mass spying program which stated that an intelligence analyst improperly repeatedly searched 702 data using only the name of a U.S. congressman.

Whats equally stunning is that despite absolutely knowing that he was spied upon something that is extremely rare given the level of secrecy around 702 neither Rep. LaHood nor anyone else illegally spied upon will likely get a chance to seek a remedy in a court. Thats not just because 702 is poorly drafted and has been even more poorly executed. Its because of how governmental secrecy has now metastasized to completely prevent anyone from stopping illegal NSA spying of them, much less get any other legal remedy.

Quite simply, governmental secrecy now renders moot many of the accountability and oversight mechanisms for national security surveillance that exist on paper in FISA as well as in the U.S. constitution.

One of EFFs highest priorities for nearly two decades is making sure you can have a private conversation online. And specifically, we want to ensure that individuals can seek judicial accountability for violations of their constitutional and statutory rights committed through the governments warrantless foreign intelligence surveillance inside the United States.

EFFs work on this issue predates the passage of Section 702 itself. Our 2006 lawsuit, Hepting v. AT&T, relied on first-hand evidence from whistleblower Mark Klein to show that the telecommunications companies were copying the contents of Internet traffic at the behest of the NSA. Congress essentially mooted this lawsuit in 2008 by granting the companies retroactive immunity as part of the FISA Amendments Act, which also instituted Section 702. Not to be deterred, and at the specific suggestion of key members of Congress, EFF again sued on behalf of AT&T customers, this time seeking to hold the government itself accountable. That lawsuit, Jewel v. NSA, powered on for 14 years, bolstered by the Snowden revelations and the flood of additional public information about the NSAs mass spying programs.

The Jewel lawsuit came to an end last year, not because the judiciary disagreed with our arguments about the unconstitutionality or illegality of the governments surveillance. It ended but because the courts validated the governments claims that a program known and debated across the world is somehow too secret to be challenged in open court by members of the public affected by it. Specifically, the Supreme Court refused to grant certiorari and reconsider a Ninth Circuit decision (and an underlying district court ruling) that held that the common law state secrets privilege blocked our clients efforts to prove that their data was intercepted, such that they had standing to sue. A similar case brought by the ACLU on behalf of Wikimedia was also rejected.

As Jewel illustrates, the judiciary has used secrecy to create a broad national-security exception to the Constitution, FISA, and 702 itself that allows all Americans to be spied upon by their government and denying them any viable means of challenging that spying. And now that impacts a sitting member of Congress directly.

This exception rests on a pair of misinterpretations of common law and statutory procedures for dealing with supposedly secret evidence. First, courts have allowed the government to invoke the state secrets privilege in Section 702 cases, despite Congress express creation of a statutory method for a federal court to secretly review evidence of claimed illegal surveillance, 50 U.S.C. 1806(f). Second, the courts have expanded the scope of that privilege to effectively allow the government to claim secrecy over widely known facts, and end litigation involving these facts, based on little more than its own say-so.

With the upcoming sunset of Section 702, Congress has the opportunity to correct these mistakes. Congress can and should reaffirm its intention to create actual, useable accountability measures for the inevitable circumstances when individuals are wrongly surveilled or impacted by surveillance, and reopen the courthouse doors to individuals trying to protect their rights.

First, Congress can expressly override the Supreme Courts mistaken statutory interpretation of FISA Section 1806 in FBI v. Fazaga, 142 S. Ct. 1051 (2022). Contrary to the Courts holding in Fazaga, Congress clearly intended for individuals to be able to seek redress when they were wrongfully surveilled and, to do that, intended Section 1806(f) to displace the state secrets privilege in lawsuits in which evidence relating to electronic surveillance is relevant. The Supreme Courts ruling essentially makes FISAs promise of individual redress for violations of surveillance law a dead letter. Congress should reaffirm the rightful interpretation of the statute and correct the Supreme Courts mistake.

Second, even when the state secrets privilege can apply, Congress can make clear that the case should not be dismissed. As far back as 2009, Congress debated the State Secrets Protection Act, H.R. 984, 110th Cong. (2009), which would have created procedures for courts to securely review evidence that the government claims is secret, and prevent cases from being dismissed based on state secrecy until plaintiffs have had an opportunity to discover all non-privileged evidence. Congress should revive these reforms and consider including them as part of any renewal or reform to Section 702.

In short, the courts have effectively blocked individuals from seeking the judicial accountability that Congress intended. Representative LaHood is just the latest in a long line of people who know they were surveilled but cannot do anything about it. Its good that he has a position of authority over the NSAits unlikely they will do that specific surveillance again. But the rest of us deserve to access the courts to protect our constitutional rights too.

These are just a small subsection of the needed reforms to ensure accountability and oversight of Section 702. Spying on the whole world is a bad idea because everyone deserves privacy of their communications. But as the now two decades of NSA mass spying demonstrates, spying on the whole world while protecting the constitutional rights of Americans just cannot be done. Its time to stop the charade and let this authority expire.

View original post here:
Even Rep. LaHood Likely Can't Sue the NSA or FBI to Protect His Rights - EFF

NSA offers new tips on zero trust and identity – FCW.com

The National Security Agency has new recommendations on identity, credential and access management security controls and their role in zero trust architecture.

The cybersecurity information sheet, released Tuesday, builds on previous NSA guidance on zero trust with more specifics for what it calls the user pillar focused on managing access.

Although the information is intended for owners and operators of national security systems including defense and intelligence agencies, but also contractors in the space zero trust has been a cybersecurity focus for federal agencies since at least the beginning of the Biden administration.

Government agencies were called to make plans for zero trust architecture in an executive order released by President Biden in May 2021. National security systems also got zero trust orders via a 2022 memo.

The White House defined zero trust as an architecture that requires continuous verification of the operational picture via real-time information in the order, meaning establishing IT systems that both monitor user behavior on networks and segment access in an effort to mitigate potential cyber attacks.

NSAs model delineates zero trust into seven pillars: user, devices, applications & workloads, data, network & environment, automation & orchestration and visibility & analytics.

Within the user pillar, the information sheet details the capabilities needed for zero trust, including identity management, credential management, access management, federation to ensure system interoperability and governance around continuous improvement.

The report goes through capabilities and maturity levels for identity, credential and access management, as well as identity federation, in what it says is a maturation of existing ICAM architecture for federal agencies in line with the zero trust model.

The new information sheet points to recent breaches and cyber attacks done by exploiting weaknesses in identity and access controls. In 2021, the Colonial Pipeline ransomware attack was perpetrated via a compromised password for a virtual private network that didnt have multi-factor authentication in place. The 2015 data breach of personnel records at the Office of Personnel Management occurred via compromised credentials.

Malicious cyber actors increasingly exploit gaps and immature capabilities in the identity, credential, and access management of our nations most critical systems, said Kevin Bingham, NSAs zero trust lead said in a statement. Our report provides recommendations that will help system operators strengthen identity protections to limit the damage of future compromises.

NSA is also planning to release more information sheets meant to help organize, guide and simplify incorporating zero trust principles and designs into enterprise networks, according to the new cybersecurity information sheet.

View post:
NSA offers new tips on zero trust and identity - FCW.com

NSA Report Suggests Ways to Help National Security System … – Executive Gov

The National Security Agency has issued a cybersecurity information sheet offering recommendations to help system operators and owners mature identity, credential and access management capabilities to prevent cyberattacks.

Malicious cyber actors increasingly exploit gaps and immature capabilities in the identity, credential, and access management of our nations most critical systems, Kevin Bingham, critical government systems, zero trust lead at NSA, said in a statement published Tuesday.

Our report provides recommendations that will help system operators strengthen identity protections to limit the damage of future compromises, added Bingham.

The CSI titled Advancing Zero Trust Maturity throughout the User Pillar discusses how ICAM capabilities integrate into a comprehensive zero trust framework and outlines steps national security system operators should take to further develop access and identity security controls and operational practices when it comes to authorizing users to access key resources and establishing digital identities.

NSA said it will release additional guidance to help system operators streamline the integration of zero trust principles into enterprise networks.

Read the original here:
NSA Report Suggests Ways to Help National Security System ... - Executive Gov

NSA Hiring Efforts Go West to the 2023 Women in Cybersecurity … – National Security Agency

FORT MEADE, Md. - The National Security Agency (NSA) has recently ramped up its hiring efforts to bring more skilled personnel into its cybersecurity mission. This week, leaders from the Cybersecurity Collaboration Center (CCC) will participate in the Women in Cybersecurity Conference in Denver, CO. Their focus is to inform conference participants of the NSA cybersecurity mission and recruit diverse talent to join us in defending the nation's most critical systems.

The 10th annual Women in Cybersecurity (WiCyS) Conference will take place at the Gaylord Rockies Resort and Convention Center in Denver from March 16-18.

WiCyS is the premier conference for women and allies in cybersecurity across industry, academia, and the government.

NSA's presence will be highlighted at booth #300 in the conference career fair. Private mentoring sessions will be available, and speakers Molly Moore, Deputy Director of NSA's Workforce Support Activity, and Morgan Adamski, Director of the Cybersecurity Collaboration Center, will highlight NSA's mission and opportunities.

NSA Speakers at WiCyS 2023:

Be Both, Have Both - Molly Moore will share lessons she has learned throughout her career at NSA, including how to thrive without compromise.

Intel-Driven Cyber Defense: How the IC Helps Drive Collective Defense - Bailey Bickley will moderate a fireside chat with Morgan Adamski, CCC Director, and Lauren Goldman, Director of Analytic Integration at the Cyber Threat Intelligence Integration Center (CTIIC) for the Office of the Director of National Intelligence (ODNI)

Conference participants can learn more about NSA's mission and how it addresses cyber threats facing the nation, as well as meet some of the people who drive the mission and make it happen.

Bring your resume! If you're looking for a rewarding career in the fast-paced world of cyber, and you're passionate about federal service, stop by booth #300 for more information; we'll have folks ready to talk about our compelling and rewarding employment opportunities. Mentoring sessions with Molly Moore and Morgan Adamski will be available on a first-come first-served basis on Friday, March 17, from 10am-11am MDT in Maple 3A. Sign up by emailing CCC_Hiring@uwe.nsa.gov.

NSA Media RelationsMediaRelations@nsa.gov443-634-0721

View post:
NSA Hiring Efforts Go West to the 2023 Women in Cybersecurity ... - National Security Agency