Choosing a safe conferencing tool in the era of mass telework – Federal News Network
Best listening experience is on Chrome, Firefox or Safari. Subscribe to Federal Drives daily audio interviews onApple PodcastsorPodcastOne.
Tom Temin: Mr. Ziring, good to have you on.
Neal Ziring:Thanks, Tom, its good to be here.
Tom Temin: Is it correct to say that even the NSA does have people teleworking? I know a lot of people need to be in the SCIFs and so forth in the intelligence community, but you do have some teleworking going on also?
Neal Ziring:Well, I cant go into detail on that, Tom. But you know, were having to react to this crisis like everyone else, and both ourselves and everyone across the national security community that we serve is trying their best to keep their workforce safe while continuing to do their vital national security missions. And collaboration is always a part of that.
Tom Temin: Sure. So lots of federal agencies from the least secure to the most secure are using all kinds of collaboration tools. Give us what are the big security requirements and considerations for these types of tools?
Neal Ziring:Sure, you know, we were watching this, we were supporting all sorts of DoD workforce efforts. And we noticed there was a vacuum in terms of guidance to help people use collaboration services securely. So, you know, we have a great deal of deep expertise here in our workforce on this. So we put together what we thought were core requirements that individuals who maybe were suddenly trying to work from home or from some remote location could pick up and use to choose a collaboration service that would meet their own security needs. For example, does it use good encryption? Does it have ability to use multi factor authentication, can the user see and control who connects? These are all very important requirements for selecting a service that youre going to use for government work.
Tom Temin: Because you have a list of about seven cybersecurity aspects of these encryption, two different levels of encryption and so on, and theres a yes or no according to each one are there any particular characteristics that if they get a no at, that product would be just simply ruled out all together?
Neal Ziring:Well, we didnt want to go there. We didnt want to be prescriptive because the needs of different agencies vary widely. We wanted to inform folks across the national security spectrum of which requirements they should consider. I dont think any of them are sort of showstoppers in that sense. Theyre all reasonably important, and theyre going to vary between different folks. For example, there are some folks in DoD I know where the authentication is a very important concern for them. So for them, criterion number three use a multi-factor authentication will be vital. And we just wanted to inform them and have a representative list of products its not a comprehensive list showing what they should consider and what they should ask of the products that they start to use.
Tom Temin: Basically, it looks like the only thing that doesnt encrypt or use multi factor authentication or do anything is plain old SMS text, which is not really a brand, but thats what everybodys got on their phones.
Neal Ziring:Yeah, we threw that in as a comparison. Were really hoping people will choose to use more secure means than their SMS.
Tom Temin: And then coming up with the list and the different ratings for the different yes or no answers on the different aspects of security on these products, did you just get that from the product literature? Or did you test them?
Neal Ziring:For the most part, we got it from the product literature, because we noticed this vacuum. We had received multiple sort of time sensitive requests from customers across Dod and other national security establishments saying, Hey, we need some help here. So we got together a team of folks. We did some testing and a whole lot of reading of product literature under conditions emulating what a teleworking user would face. And then we put these together and we invite the folks who maintain these systems, if they spot an inaccuracy in what weve published then they can write to us, and we will correct it. Weve already gone through one round of revision.
Tom Temin: Got it. Were speaking with Neal Ziring, the technical director of the Cybersecurity Directorate at the National Security Agency. And have you heard from any agencies that said, Hey, this happened to us with this particular product, you better be aware of that potential?
Neal Ziring:No, we havent received reports of actual incidents. We have had several national security organizations write to us and say the guidance is helpful and asking additional technical questions. Thats pretty standard for us.
Tom Temin: Sure. And I have a question about these products, too. Suppose someone in a national security situation is teleworking and collaborating over these and lets postulate that no data is being exchanged. Say no documents or something would be exchanged back and forth in that manner. Because it may be against the rules, and depending on the sensitivity of the data, but people are talking. If they were to be talking about something that could be classified or make a reference is one of the issues that voice could be somehow obtained by a third party thats not authorized?
Neal Ziring:Yeah, thats certainly a concern for this category of product, right. Now, we do caution folks to think about what theyre saying over these systems. These are unclassified systems. And so they shouldnt be talking classified over them in any case. But yeah, thats why criterion number one is important, for example, right? Is this something that employs encryption, so that if theres somebody who can see that traffic, then theyre not going to see anything but ciphertext. Thats a very important part of selecting a secure collaboration service.
Tom Temin: Let me ask you this. If you could design a ideal product in terms of cybersecurity for collaboration, what would it look like?
Neal Ziring:Oh, I think it would, it would look a lot Like some of the commercial products that are out there, now, theres some really good ones. It should implement strong encryption, and that encryption should meet published encryption standards. It should support multi-factor authentication. A really important aspect is transparency, the service should let you see who is connected, see where its connecting through. Allow you to see what data you have stored in the service and delete it. And also whether the service provider is going to be sharing data about you or your usage with any third parties. Thats a concern as well.
Tom Temin: And one of the criteria is whether the source code is shared, the public source code is shared. What is the consideration there? Why is that important?
Neal Ziring:Yeah, that is that is criterion number seven. And thats an aspect of transparency, right that lets reviewers or potentially someone like NSA, examine how the product is implementing its security and see that that is being done correctly.
Tom Temin: Theres probably some good guidance for the vendors. Theres one here called Signal which Im not familiar with, but it gets yess on all of the criteria, except FedRAMP. It seems like that company ought to go for its FedRAMP certification.
Neal Ziring:Well, I would encourage any companies that want to provide service of this kind to the federal government to consider FedRAMP. I was there when they started FedRAMP. I think its a great program. FedRAMP is important because in gaining a FedRAMP certification, a company needs to thoroughly document how their security works and how its provided. And then the federal government can have more faith or more assurance when theyre utilizing that service.
Tom Temin: With respect to video, does video add cybersecurity risk in general to the use of these products?
Neal Ziring:I dont think it adds risks in and of itself. For some of the products, using video may affect whether you get to use encryption or not. So thats an important consideration but no, otherwise, go ahead and do the video. Its fine.
Tom Temin: All right. Neal Ziring is technical director of the Cybersecurity Directorate at the National Security Agency. Thanks so much for joining me.
Neal Ziring:Thank you, Tom.
Continue reading here:
Choosing a safe conferencing tool in the era of mass telework - Federal News Network
- US NSA lauds Ajit Doval for pivoting ties to advanced future tech - The Times of India - January 9th, 2025 [January 9th, 2025]
- Auto insurtech Clearcover expands into Texas NSA market with CGA launch - Re-Insurance.com - January 9th, 2025 [January 9th, 2025]
- "Cannot Think Of A Better Way To End My Tenure": US NSA On His India Visit - NDTV - January 9th, 2025 [January 9th, 2025]
- Heightened Security At U.S. Naval Academy And NSA Annapolis: Public Access Suspended Amid Increased Force Protection Measures - Bay Net - January 9th, 2025 [January 9th, 2025]
- From The Seabed To The Stars: 10 Takeaways From U.S. NSA Sullivans Visit - Strategic News Global - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan to visit India to finalise important ongoing initiatives: White House - The Hindu - January 9th, 2025 [January 9th, 2025]
- What NSA Jake Sullivans India Visit Signals For Nuclear And Tech Ties As US Lifts Curbs On Indian Entities - Swarajya - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan arrives today, seeks to strengthen AI, space, tech ties - The Tribune India - January 9th, 2025 [January 9th, 2025]
- CISA, NSA, and Partners Issue Annual Report on Top Exploited Vulnerabilities - HSToday - December 5th, 2024 [December 5th, 2024]
- Where Will The Top Amateurs at NSA Yamaha Land After the Team Closes? - Vurbmoto - December 5th, 2024 [December 5th, 2024]
- CISA, NSA, FBI and International Partners Publish Guide for Protecting Communications Infrastructure - HSToday - December 5th, 2024 [December 5th, 2024]
- Main players backing Syrian government have been weakened by other conflicts, NSA Sullivan says - NBC News - December 5th, 2024 [December 5th, 2024]
- Trump's incoming NSA Mike Waltz wants US to dance cheek-to-check with India - The Times of India - November 14th, 2024 [November 14th, 2024]
- What Trump's NSA Nominee Said On India's Pivotal Role In The 21st Century - NDTV - November 14th, 2024 [November 14th, 2024]
- Exclusive: Nakasone on exploding pagers, life after the NSA and another possible government job - The Record from Recorded Future News - November 14th, 2024 [November 14th, 2024]
- FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023 - BleepingComputer - November 14th, 2024 [November 14th, 2024]
- CISA, NSA, and Partners Issue Annual Report on Top Exploited Vulnerabilities - National Security Agency - November 14th, 2024 [November 14th, 2024]
- 6 Principles of Operational Technology Cybersecurity released by joint NSA initiative - Security Intelligence - November 14th, 2024 [November 14th, 2024]
- It's official FBI, CISA, and NSA reveal the most exploited vulnerabilities of 2023 - TechRadar - November 14th, 2024 [November 14th, 2024]
- Donald Trump picks Mike Waltz as US NSA: What it means for China and India - The Times of India - November 14th, 2024 [November 14th, 2024]
- Who is Mike Waltz, Donald Trump's new NSA pick? What are his ties to India Caucus? - Firstpost - November 14th, 2024 [November 14th, 2024]
- NSA should not oversee the management of national facilities RexDanquah - Citi Sports Online - November 14th, 2024 [November 14th, 2024]
- Trudeaus NSA admits to leaking secret intel alleging Indias interference to Washington Post - Firstpost - October 31st, 2024 [October 31st, 2024]
- White House dials NSA Ajit Doval: Here's what happened in the call - The Economic Times - October 31st, 2024 [October 31st, 2024]
- NSA Doval Stresses Need For Stable Indo-Pacific In Phone Call With US Counterpart Sullivan - News18 - October 31st, 2024 [October 31st, 2024]
- Director-General of NSA calls for continued support from government - GhanaWeb - October 21st, 2024 [October 21st, 2024]
- 5G Non Standalone Nsa Architecture Market to Reach USD 240.0 - openPR - October 21st, 2024 [October 21st, 2024]
- NSA meets with Minister Muir and DAERA to discuss industry concerns - Meat Management - October 21st, 2024 [October 21st, 2024]
- NSA cyber chief: Espionage is now Russias focus for cyberattacks on Ukraine - The Record from Recorded Future News - October 11th, 2024 [October 11th, 2024]
- NSA Investigating If Chinese Hackers Breached US Telecoms - Yahoo Finance - October 11th, 2024 [October 11th, 2024]
- NSA Issues Updated Guidance on Russian SVR Cyber Operations - National Security Agency - October 11th, 2024 [October 11th, 2024]
- News - Honoring the Stars and Stripes: NSA Philadelphia Hosts Dignified Flag Disposal Ceremony - DVIDS - October 11th, 2024 [October 11th, 2024]
- NSA's Program for Nursing Mothers in the Workplace Considered a Model for USG - National Security Agency - October 11th, 2024 [October 11th, 2024]
- NSA investigating hack of three major telecommunications companies - Baltimore Sun - October 11th, 2024 [October 11th, 2024]
- Honoring the Stars and Stripes: NSA Philadelphia Hosts Dignified Flag Disposal Ceremony [Image 8 of 8] - DVIDS - October 11th, 2024 [October 11th, 2024]
- NSA Hiring Over a Thousand in the Next Year - ClearanceJobs - October 4th, 2024 [October 4th, 2024]
- What Its Really Like to Work at NSA - National Security Agency - October 4th, 2024 [October 4th, 2024]
- US Elections: Former NSA John Bolton Claims Both Harris And Trump Do Not Qualify To Be President | NewsX Exclusive - NewsX - October 4th, 2024 [October 4th, 2024]
- Honoring the fallen: Bells toll for Americas heroes at NSA Mechanicsburg - American Military News - October 4th, 2024 [October 4th, 2024]
- How often should you turn off your phone? Heres what the NSA says - PCWorld - October 4th, 2024 [October 4th, 2024]
- NSA and Allies Issue Advisory about PRC-Linked Actors and Botnet Operations - HSToday - September 28th, 2024 [September 28th, 2024]
- NSA warns that Active Directory is an "exceptionally large and difficult to defend" attack surface - The Stack - September 28th, 2024 [September 28th, 2024]
- News - Honoring the Fallen: Bells Toll for Americas Heroes at NSA Mechanicsburg - DVIDS - September 28th, 2024 [September 28th, 2024]
- National Storage Affiliates Trust (NYSE:NSA) Given Average Recommendation of "Reduce" by Brokerages - MarketBeat - September 28th, 2024 [September 28th, 2024]
- Lack of Standard Stadiums: NSA boss sacked, facilities closed - What has been said and done so far - GhanaWeb - September 21st, 2024 [September 21st, 2024]
- NSA and Allies Issue Advisory about PRC-Linked Actors and Botnet Operations - National Security Agency - September 21st, 2024 [September 21st, 2024]
- UTEP Establishes Collaboration with DoD, NSA to Help Enhance U.S. Semiconductor Workforce - The University of Texas at El Paso - September 21st, 2024 [September 21st, 2024]
- The NSA advises you to turn off your phone once a week - here's why - ZDNet - September 21st, 2024 [September 21st, 2024]
- NSA Publishes Cyber Advisory on China-Linked Threat Actors - Executive Gov - September 21st, 2024 [September 21st, 2024]
- Former NSA Director Nakasone opens new institute at Vanderbilt to train right type of leader - Washington Times - September 21st, 2024 [September 21st, 2024]
- ACR lauds legislation that would fine insurers for delayed NSA payments - AuntMinnie - September 16th, 2024 [September 16th, 2024]
- NSA threatens lawsuit over election rigging allegation, demands apology - Pulse Nigeria - September 16th, 2024 [September 16th, 2024]
- NSA explains its work with private sector on election security and fighting foreign cyber threats - Washington Times - September 16th, 2024 [September 16th, 2024]
- NSA to debut podcast to boost public awareness of classified missions - Nextgov/FCW - August 31st, 2024 [August 31st, 2024]
- In Beijing, Bidens NSA Calls Out Chinas Destablising Actions, Openly Supports Philippines - Hindustan Times - August 31st, 2024 [August 31st, 2024]
- Why the NSA advises you to turn off your phone once a week - ZDNet - August 31st, 2024 [August 31st, 2024]
- Getting into rhythm: NSA places high expectations on themselves for 2024 - Suffolk News-Herald - August 31st, 2024 [August 31st, 2024]
- NSA readying podcast to share untold stories of codebreakers missions - Washington Times - August 31st, 2024 [August 31st, 2024]
- Trump govt stopped aid to Pakistan over ISI's 'undeniable complicity' with terrorists: Ex-US NSA - Hindustan Times - August 31st, 2024 [August 31st, 2024]
- Top NSA researcher tapped to lead Pentagons UAP investigation hub - DefenseScoop - August 27th, 2024 [August 27th, 2024]
- NSA Releases Guide to Combat Living Off the Land Attacks - Infosecurity Magazine - August 27th, 2024 [August 27th, 2024]
- With a little help from the National Archives, NSA finally releases Grace Hopper lecture. Watch it here. - MuckRock - August 27th, 2024 [August 27th, 2024]
- Trump administration NSA H.R. McMaster says there was "inconsistency" in foreign policy - CBS News - August 25th, 2024 [August 25th, 2024]
- 'Putin exploited Trump's ego and insecurities': Former NSA in new book - The Times of India - August 25th, 2024 [August 25th, 2024]
- NSA calls for urgent Government action on illegal sheep imports - Meat Management - August 14th, 2024 [August 14th, 2024]
- Sheikh Hasina Resignation LIVE Updates: Ex Bangladesh PM Sheikh Hasina Meets NSA Ajit Doval At Hindon Airbase - NDTV - August 5th, 2024 [August 5th, 2024]
- NSA Claims It Cant Watch an Important Tape It Recorded in the 1980s - Gizmodo - July 17th, 2024 [July 17th, 2024]
- Letter to NSA Sullivan Requesting Assessment of Information Russia Has Shared with the PRC on U.S. Weapons Capabilities in Ukraine - Select Committee... - July 17th, 2024 [July 17th, 2024]
- The NSA Is Defeated By A 1950s Tape Recorder. Can You Help Them? - Hackaday - July 17th, 2024 [July 17th, 2024]
- Letter to NSA on Microsoft's Billion Dollar Partnership with UAE Firm G42 - Select Committee on the CCP | - July 17th, 2024 [July 17th, 2024]
- NSA Fast Pitch World Series kicks off with Skills Competition & Heavy Hitters Camp, featuring College World Series Champions from the University... - July 17th, 2024 [July 17th, 2024]
- NSA contractor bilked government for hundreds of hours she never worked - Washington Times - July 6th, 2024 [July 6th, 2024]
- Signals intelligence has become a cyber-activity - The Economist - July 6th, 2024 [July 6th, 2024]
- OpenAI adds former NSA chief to its board - CNBC - June 15th, 2024 [June 15th, 2024]
- Former head of NSA joins OpenAI board - The Verge - June 15th, 2024 [June 15th, 2024]
- Former NSA Head Joins OpenAI Board and Safety Committee - RetailWire - June 15th, 2024 [June 15th, 2024]
- Former NSA head joins OpenAI board and safety committee - TechCrunch - June 15th, 2024 [June 15th, 2024]
- OpenAI Appoints Cybersecurity Expert And Retired US Army Genera With NSA Pedigree To Board, Enhancing AI ... - Benzinga - June 15th, 2024 [June 15th, 2024]
- Former NSA head Paul Nakasone to helm national security institute at Vanderbilt - The Record from Recorded Future News - May 15th, 2024 [May 15th, 2024]
- US is still chasing down pieces of Chinese hacking operation, NSA official says - The Record from Recorded Future News - March 18th, 2024 [March 18th, 2024]