Here's The NSA's Guide For Choosing A Safe Text Chat And Video Conferencing Service
The US National Security Agency (NSA) published last week a security assessment of today's most popular video conferencing, text chatting, and collaboration tools.
The guidance contains a list of security criteria that the NSA hopes companies take into consideration when selecting which telework tool/service they want to deploy in their environments.
The NSA document is not only meant for US government and military entities but the private sector as well.
The idea behind the NSA's initiative is to give military, public, and private organizations an overview of all of a tools' features, so IT staff don't make wrong decisions, expecting that a tool provides certain features that are not actually living up to the reality.
Per the NSA's document, the assessed criteria answers to basic questions like:
- Does the service implement end-to-end (E2E) encryption?
- Does the E2E encryption use strong, well-known, testable encryption standards?
- Is multi-factor authentication (MFA) available?
- Can users see and control who connects to collaboration sessions?
- Does the tool's vendor share data with third parties or affiliates?
- Do users have the ability to securely delete data from the service and its repositories as needed (both on client and server side)?
- Is the tool's source code public (e.g. open source)?
- Is the service FedRAMP approved for official US government use?
A snapshot of these assessments is available in the image below. [In case any of these change and the screenshot becomes outdated through the years, please refer to the original PDF document.]
The NSA published the above assessment due to the ongoing coronavirus (COVID-19) pandemic, which has resulted in many private-sector employees, government workers, and military members working from home and increasingly relying on teleworking tools.
Knowing which tool fits which security posture and threat matrix is the first step in preventing intrusions, the NSA said.
This assessment also marks the second cyber-security advisory that the NSA issued last week. Days before, the agency had also published guidance and a list of the most common vulnerabilities threat actors had been using to plant web shells on servers.
Yesterday, the US government has also issued another security alert, this one by the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). CISA said it was concerned about hasty deployments of Office 365 and Microsoft Teams that may have exposed companies to attacks due to missing key security configurations.
Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals
The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more
AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments
Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more
Technology Sector Fuels U.S. Economic Growth In Q2
The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more
Tech Start-Ups Advised To Guard Against Foreign Investment Risks
The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more
Global IT Outage Threatens To Cost Insurers Billions
Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more
Global IT Outage Disrupts Airlines, Financial Services, And Media Groups
On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more