CISA's CDM Program Prioritizes Speed and Unification to Combat Evolving Cyber Threats
The Cybersecurity and Infrastructure Security Agency (CISA) is emphasizing the need for its Continuous Diagnostics and Mitigation (CDM) program to become significantly faster and more unified in providing cybersecurity tools and capabilities to federal agencies. Richard Grabowski, acting branch chief of service delivery and deputy program manager for the CDM program, stated that current collaboration methods are insufficient for past threats and will be even less effective for future ones. The program's core goals are velocity, unification, and data-driven risk management. Velocity involves pushing responsible automation to allow experts to focus on novel threats, while unification aims to connect deployments meaningfully to stimulate reusable lessons learned. Data-driven risk management ensures agencies have timely, accurate data for first response during crisis-level events. The CDM program has been evolving since the SolarWinds breach, which compromised at least nine federal agencies, highlighting the n...