Internet Security Alliance: NIST framework metrics should focus on threats

Posted on June 1, 2017 at 11:41 am

The National Institute of Standards and Technology should focus on developing an “analytical tool” enabling entities to assess cyber threats on a monetized basis, according to the president of the Internet Security Alliance, as NIST continues probing the use of NIST cybersecurity framework metrics. “The next step in the evolution of the NIST CSF shouldn’t […]

Metrics? What Metrics? Finding the Missing Link to the NIST Cybersecurity Framework

Posted on May 31, 2017 at 11:00 am

The NIST Cybersecurity Framework (NIST CSF) is one of the cornerstones – and most popular features – of US government policy to strengthen our nation’s cybersecurity. The hottest topic at the recent NIST workshop aimed at updating and refining the CSF was the development of metrics. Many experts believe that for the CSF to properly […]


Posted on May 26, 2017 at 4:18 pm

(WASHINGTON, D.C.) – The second annual cybersecurity summit specifically targeted to individuals who sit on corporate boards will be hosted by The National Association of Corporate Directors, and the Internet Security Alliance, June 20 & 21 at the JW Marriott in Chicago. The conference will build on the Cyber Risk Handbook for Corporate Boards NACD […]

Top 25 ISA Accomplishments in 2016

Posted on at 3:03 pm

Top 25 ISA Accomplishments in 2016   PricewaterhouseCooper’s 2016 Global Information Security Survey independently documents positive impact of the “Cyber Risk Oversight Handbook” prepared by ISA board and for the National Association of Corporate Directors. PWC credits the Handbook, by name, with fundamentally changing the way boards are now treating cybersecurity including significant increases ion […]

How the Trump Budget Would Fund Cybersecurity

Posted on May 24, 2017 at 11:45 am

The Donald Trump administration, in its proposed fiscal year 2018 budget, outlines steps it contends would strengthen the U.S. federal government’s information systems, even as it would cut some cybersecurity spending at specific agencies. At the heart of the budget for the fiscal year that begins Oct. 1 is a proposal to spend $1.5 billion […]

Modernizing Government Technology Act Passes House

Posted on May 18, 2017 at 11:09 am

The House of Representatives has passed the Modernizing Government Technology Act, which supporters contend should help improve the security of the federal government’s information networks. The legislation passed May 17 on a voice vote and now goes to the Senate, where its prospects are uncertain. Should the bill become law, major agencies would create IT […]

Eye on Chicago: Going on the Offensive to Win the Cyber War

Posted on May 15, 2017 at 11:16 am

HMG Strategy Reports: Taking a defensive approach to cybersecurity isn’t working for keeping the bad guys out. The volume and level of sophistication with cyber attacks has continued to rise dramatically. In 2016, one-third of all businesses globally were breached, according to PwC. And while millions of attacks are being launched on a daily basis, […]


Posted on May 11, 2017 at 4:06 pm

(WASHINGTON, D.C.) – The Internet Security Alliance (ISA) supports President Trump’s new executive order on cybersecurity. The President’s order places responsibility for cybersecurity on agency heads, who are now directed to use a risk management model for cybersecurity programs. ISA supports this critical paradigm shift and is a long-standing proponent of using risk assessments to […]

Congressional memo on President Trump Cybersecurity Executive Order 13800

Posted on at 11:40 am

The Internet Security Alliance (ISA) supports President Trump’s new executive order on cybersecurity, and looks forward to assisting in its implementation. The Senate Committee on Commerce, Science, and Transportation, with its jurisdiction covering interstate commerce, has broad authority over key elements of the Order. ISA suggests the Committee consider some of the following recommendations as […]

Assessing the Latest Draft Cybersecurity Executive Order

Posted on May 6, 2017 at 11:13 am

The latest draft version of the Trump administration’s cybersecurity executive order is similar to the previous version and lays out a plan to secure U.S. federal government and critical infrastructure IT that could have come out of the Barack Obama White House, including modernizing federal IT. “That fact that they are focusing on IT modernization […]