Here's The NSA's Guide For Choosing A Safe Text Chat And Video Conferencing Service

NSA logo
Image: Pankaj Patel, NSA, ZDNet

The US National Security Agency (NSA) published last week a security assessment of today's most popular video conferencing, text chatting, and collaboration tools.

The guidance contains a list of security criteria that the NSA hopes companies take into consideration when selecting which telework tool/service they want to deploy in their environments.

The NSA document is not only meant for US government and military entities but the private sector as well.

The idea behind the NSA's initiative is to give military, public, and private organizations an overview of all of a tools' features, so IT staff don't make wrong decisions, expecting that a tool provides certain features that are not actually living up to the reality.

Per the NSA's document, the assessed criteria answers to basic questions like:

  1. Does the service implement end-to-end (E2E) encryption?
  2. Does the E2E encryption use strong, well-known, testable encryption standards?
  3. Is multi-factor authentication (MFA) available?
  4. Can users see and control who connects to collaboration sessions?

  5. Does the tool's vendor share data with third parties or affiliates?

  6. Do users have the ability to securely delete data from the service and its repositories as needed (both on client and server side)?

  7. Is the tool's source code public (e.g. open source)?

  8. Is the service FedRAMP approved for official US government use?

A snapshot of these assessments is available in the image below. [In case any of these change and the screenshot becomes outdated through the years, please refer to the original PDF document.]

NSA teleconferencing
Image: NSA

The NSA published the above assessment due to the ongoing coronavirus (COVID-19) pandemic, which has resulted in many private-sector employees, government workers, and military members working from home and increasingly relying on teleworking tools.

Knowing which tool fits which security posture and threat matrix is the first step in preventing intrusions, the NSA said.

This assessment also marks the second cyber-security advisory that the NSA issued last week. Days before, the agency had also published guidance and a list of the most common vulnerabilities threat actors had been using to plant web shells on servers.

Yesterday, the US government has also issued another security alert, this one by the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). CISA said it was concerned about hasty deployments of Office 365 and Microsoft Teams that may have exposed companies to attacks due to missing key security configurations.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more