Risk

7/14/2017
11:27 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

States Pledge to Meet Cyber Threats

Outgoing National Governors Association Chair Gov. McAuliffe Sunsets his Initiative, 38 Governors Sign Compact

PROVIDENCE, RI—Today National Governors Association (NGA) Chair Virginia Gov. Terry McAuliffe kicked off the 2017 NGA Summer Meeting with a discussion on how states continue to develop strategies to thwart cyber threats.

Over the last year, Gov. McAuliffe has spearheaded an effort to strengthen state cybersecurity through Meet the Threat: States Confront the Cyber Challenge, his NGA chair’s initiative.

“The goal of my initiative as NGA chair was to elevate the importance of cybersecurity on every governor’s agenda. To do that, we had to highlight why cybersecurity was more than just an information technology issue. I am proud that, throughout the last year, we have successfully engaged governors and their states on strengthening their cyber protocols and recognizing that cybersecurity is a technology issue, but it’s also a health issue, an education issue, a public safety issue, an economic issue and a democracy issue,” Gov. McAuliffe said.

Among the speakers joining him for the session were Matt Spence, partner at venture capital firm Andreesen Horowitz; Chris Bream, chief technology officer at IT company Tanium; and Wes Kremer, vice president of defense contractor Raytheon and president of Raytheon Integrated Defense Systems.

Gov. McAuliffe highlighted governors’ actions to boost cybersecurity defenses throughout the past year. “In New Mexico, Gov. Martinez signed legislation clarifying when the National Guard can be used during cyber events,” he said. “In Oregon, Gov. Brown signed an executive order to unify all cybersecurity efforts into one agency. Lastly, our incoming [NGA] chair, Gov. Sandoval, recently signed a bill to create a cyber defense center to lead all their cyber projects in Nevada.

“Since the launch of my initiative, more than 30 governors have signed an executive order, legislation or announced a cybersecurity initiative,” he continued, adding, “This has resulted in a dozen executive orders, 14 signed bills and 17 initiatives.”

Gov. McAuliffe also announced at the session that 38 governors across the country had signed on to a compact to improve state cybersecurity in which they pledged to enhance cybersecurity governance, prepare and defend their states from cybersecurity events and help grow the nation’s cyber workforce.

The work of Meet the Threat will live on, both in the Governor’s Guide to Cybersecurity, a comprehensive resource for state officials that outlines concrete steps they can take to bolster cybersecurity practices, and NGA’s Resource Center for State Cybersecurity, which Gov. McAuliffe co-chairs with Michigan Gov. Rick Snyder

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17317
PUBLISHED: 2018-09-21
FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_in_mask, io_in_gw, io_out_iface, io_out_set, io_out_mask, io_out_gw, iface, or domain parameter to /ww...
CVE-2018-17320
PUBLISHED: 2018-09-21
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
CVE-2018-17141
PUBLISHED: 2018-09-21
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
CVE-2018-17173
PUBLISHED: 2018-09-21
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
CVE-2018-17174
PUBLISHED: 2018-09-21
A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data.