The Road to the Data Requirement in Executive Order 14028
Video
Enhancing Federal Agency Cybersecurity: Kiteworks’ Solution for Zero-trust Compliance and Protection
In response to cyberattacks becoming increasingly more complex over the past couple years, the U.S. White House issued an Executive Order (EO 14028) in May 2021—Improving the Nation’s Cybersecurity—requiring federal agencies to ask their suppliers to provide software bill of materials (SBOMs). Further clarification was provided in September 2021 when the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA) released three draft guidance documents on a zero-trust strategy.
Additional detail was added to the draft documents from September with the release of a new memorandum from the White House on January 26, 2022. The task mandate in the memorandum for data is to complete the following within 120 days:
- Develop a Data Security Strategy
- Automate Security Responses
- Audit Access to Sensitive Data
- Govern Access to Logging and Information Security
Kiteworks’ mission is to protect privacy and ensure compliance of all sensitive content sent via email, file share, automated file transfer, application programming interface (API), and web form through one platform. For federal agencies, they can unify, track, control, and secure sensitive content as it moves within, into, and out of their organizations using the Kiteworks platform. This continuous governance and security approach complies with zero-trust principles spelled out in the memorandum.
Kiteworks is already compliant with various federal standards, including the Cybersecurity Maturity Model Certification (CMMC), SOC 2, the Federal Information Security Management Act (FISMA), and FIPS 140-2. Kiteworks also has FedRAMP authorization for Moderate Impact Level Information and satisfies requirements for the General Data Protection Regulation (GDPR), International Traffic in Arms Regulations (ITAR), and the National Institute of Standards and Technology (NIST) 800-171.