Full Report
President Biden signed a 34-page Executive Order aimed at strengthening the nation’s cybersecurity standards. Here are the top seven takeaways.
Analysis Summary
# Regulation/Compliance: Executive Order 14028 (Improving the Nation’s Cybersecurity)
## Overview
Executive Order 14028 is a federal directive aimed at significantly enhancing the cybersecurity posture of the United States. It focuses on modernizing federal digital infrastructure, improving information sharing between the government and the private sector, and establishing rigorous security standards for software sold to the federal government. The EO was issued in response to high-profile supply chain attacks (e.g., SolarWinds) and ransomware incidents (e.g., Colonial Pipeline).
## Key Details
- **Issuing Authority:** The White House (Executive Office of the President)
- **Effective Date:** May 12, 2021
- **Jurisdiction:** Federal Government Agencies and their private-sector Information Technology (IT) and Operational Technology (OT) service providers.
- **Status:** In Effect (with rolling implementation deadlines)
## Requirements
### Mandatory Requirements
1. **Removal of Contractual Barriers:** IT providers must be able to share threat information with the government.
2. **Incident Reporting:** Service providers are *required* to report cyber breaches that could impact government networks.
3. **Modernization of Security:** Federal agencies must adopt Cloud Security, Zero Trust Architecture (ZTA), and Multi-Factor Authentication (MFA).
4. **Data Encryption:** Mandatory encryption for data at rest and in transit.
5. **Software Supply Chain Security:** Developers must provide a Software Bill of Materials (SBOM) for products sold to the government.
6. **Standardized Response:** Federal agencies must adopt a standardized "playbook" for incident response to ensure consistent action across the government.
### Recommended Practices
1. **Private Sector Alignment:** Non-government entities are strongly encouraged to adopt Zero Trust and MFA.
2. **Information Transparency:** Voluntary sharing of threat intelligence within the cybersecurity community.
3. **Enhanced Logging:** Implementation of robust logging practices for internal investigations.
## Affected Organizations
- **Industries:** IT service providers, software developers, cloud service providers, and any contractor providing digital services to the federal government.
- **Organization Size:** All sizes (if contracting with the federal government).
- **Geographic Scope:** United States (domestic agencies and international vendors serving the U.S. government).
## Compliance Timeline
*Note: The EO mandates various timelines ranging from 30 to 360 days post-issuance.*
- **May 12, 2021:** Executive Order signed/Effective.
- **60-180 Days:** Agencies to prioritize MFA and encryption; NIST to define software security standards.
- **360 Days:** Full implementation of many modernization and reporting requirements.
## Implementation Guidance
### Assessment Phase
- Identify all contracts involving federal agencies.
- Review existing Service Level Agreements (SLAs) for clauses prohibiting info-sharing.
- Audit current authentication methods (check for MFA gaps).
### Implementation Phase
- **Deploy MFA:** Ensure all users, especially privileged accounts, require MFA.
- **Zero Trust:** Move away from perimeter-based security toward identity-based validation.
- **SBOM Generation:** Start cataloging software components to prepare for supply chain disclosure requirements.
### Validation Phase
- Conduct incident response simulations using the new federal "playbook" standards.
- Verify that logging and detection capabilities meet federal "endpoint detection and response" (EDR) requirements.
## Technical Requirements
- **Encryption:** FIPS-validated modules for data at rest and in transit.
- **Authentication:** Phishing-resistant Multi-Factor Authentication.
- **Architecture:** Zero Trust (continuous verification of users and devices).
- **Logging:** Centralized log management and retention for forensic analysis.
## Penalties & Enforcement
- **Fines:** Not explicitly defined as flat fees in the EO, but breach of contract can lead to financial loss.
- **Other Consequences:** Loss of federal contracts, debarment from future bidding, and reputational damage.
- **Enforcement:** Managed via federal procurement processes (FAR/DFARS updates) and oversight by CISA and OMB.
## Related Standards
- **NIST 800-171/800-53:** Alignment with federal security controls.
- **CMMC:** The EO reinforces the need for documented cybersecurity maturity in the defense industrial base.
## Resources
- **Official Documentation:** [hXXps://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/]
- **CISA Guidance:** [hXXps://www.cisa.gov/executive-order-improving-nations-cybersecurity]
## Practical Recommendations
- **Update IR Plans:** Revise incident response policies to include mandatory notification triggers for government clients.
- **Supply Chain Review:** Vet third-party libraries and open-source components used in your software products.
- **Shift to Zero Trust:** If not already implemented, begin the transition to a Zero Trust architecture to remain competitive in the federal marketplace.