FDA Cybersecurity Modernization Action Plan

Share

FDA is launching a cybersecurity modernization action plan (CMAP) to enhance its current cybersecurity defenses to address the ever-evolving threat landscape and protect the vital data supporting the agency’s regulatory decision-making. Writing in an FDA Voices post, chief information officer Vid Desai and chief information security officer Craig Taylor say the action plan takes an agency-wide approach to couple advances in information technology, data, and business process levels with improved cybersecurity capabilities.

“The CMAP outlines the measures we will take to modernize our security and cyber defenses and implement ‘Zero Trust,’” Desai and Taylor write. “Zero Trust is a strategy or approach that ensures that the right people have the right access to the right resources at the right time.”

The key CMAP objectives are listed as:

  • establish a comprehensive Zero Trust approach to facilitate new digital services and modernization efforts;
  • promote software assurance best practices to include security measures at every development lifecycle stage;
  • enhance interoperable and secure data exchange and collaboration across FDA and its public health partners;
  • leverage artificial intelligence and machine learning technologies to enhance cyber detection and response capabilities;
  • integrate counterintelligence and insider risk principles with the Zero Trust model to enable an intelligence-driven approach; and
  • prioritize and invest in FDA’s cybersecurity workforce.

Demonstrating the need for modernization, the post says that during the pandemic FDA experienced a 457% increase in reconnaissance activities, denial of service, attempted exploitation, and other cyber incidents against IT infrastructure, including nearly 9.5 billion firewall and intrusion detection blocks monthly.

Read more