Skip to Main Content Subscribe

New CDM Security Service Aims to Cut Cyber Response Times

Share

CISA’s SIEM-as-a-Service platform gives federal agencies automated tools to improve threat hunting, logging and incident response.

3m read
Written by:
Acting Federal Chief Information Security Officer Michael Duffy speaks during the Billington Cybersecurity Summit in Washington, D.C. on Tuesday.
Acting Federal CISO Michael Duffy speaks during the Billington Cybersecurity Summit in Washington, D.C. Photo Credit: Oh Yes Communications

Officials are rethinking how the government acquires and deploys cybersecurity capabilities as the Continuous Diagnostics and Mitigation (CDM) program enters its next phase, acting Federal CISO Mike Duffy said Tuesday.

“A few years ago, you may have seen CDM on every agenda in the D.C. area and at every tech conference and every cyber discussion. Maybe a little overexposed at some point, but it’s been a while,” Duffy said at the Elastic-FedScoop Federal Cyber Defense Breakfast. “CDM program has been working on what is next and what the new generation of cyber capabilities should be and the way that we as a federal government should be thinking about the strategic landscape and where CDM fits into all of this.”

The Cybersecurity and Infrastructure Security Agency (CISA) stood up the CDM program more than a decade ago to establish a series to data-sharing dashboards and tools to provide federal civilian agencies with more visibility into user threats on their networks.

The program now supports 94 Federal Civilian Executive Branch (FCEB) agencies. As cyber threats evolve, CDM officials are looking to shorten response times and give agencies additional capabilities to detect, investigate and mitigate attacks.

CDM officials touted their new Security Information and Event Management-as-a-service (SIEMaaS) platform, which they are offering at no cost to FCEB agencies as a way to accelerate detection and response times.

“We very much view SIEM-as-a-service as the Rosetta Stone,” said Richard Grabowski, CDM’s acting branch chief of service delivery and deputy program manager. “The ability to see what is happening with timely, accurate and trustworthy data so we are the tool of first response when the things hit the fan.”

Managed by CDM as a cloud-based security service, SIEMaaS uses automated analytics to integrate security data and give agencies greater visibility into activity across their environments, supporting faster threat hunting and incident response.

It also helps agencies comply with the Office of Management and Budget’s (OMB) M-26-14, which came out in May and calls for agencies to have continuous event monitoring and a logging infrastructure that allows for Threat Hunting, Investigation, Response and Forensics (THIRF) capabilities to investigate potential network compromises.

Grabowski said initiating a response under traditional CDM processes can take as long as 14 days because of administrative, access and investigative requirements. With SIEMaaS, he said, the same process can take about 40 minutes.

“The same intel fires, the same [Information Flow Control]s. Now, rather than asking for paperwork and access, in no greater time than it takes to make a cup of coffee, that analyst can be on mission to start to find things and help our clients,” he said.

Matt House, acting associate director and CDM program manager, said SIEMaaS remains in its early stages, with “just a couple of agencies really now operational.” CDM officials are also working with a large civilian agency to deploy the service and are fielding inquiries from other agencies interested in adopting it.

Related Content