NSA releases best practices guide on cyber hygiene for defending against advanced threats
The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those leveraging artificial intelligence for exploitation. The guide includes actions to immediately reduce risk, such as network inventory, multifactor authentication and patching, while progressing toward implementing zero trust practices such as segmentation and continuous monitoring. Zero trust is a strategy guided by the principle that no users or devices are safe and they must always be verified. The guide prioritizes defenses against AI-enhanced threats such as automated reconnaissance and “living off the land” techniques, which are fileless malware attacks involving native tools within a victim’s system.
For more information on this or other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org, or Scott Gee, AHA deputy national advisor for cybersecurity and risk, at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.