logo

On the Cyber Safety Review Board

ID: bfba8141-8a66-5908-bf13-61164e8dfb63

STIX ID: report--bfba8141-8a66-5908-bf13-61164e8dfb63

Feed Name: Schneier on Security

Date Published: 2024-08-06

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This essay critiques the U.S. Cyber Safety Review Board (CSRB) for lacking subpoena power, transparency, and independence, arguing that its reports—on Log4j, Lapsus$, and China’s breach of Microsoft’s cloud—provide either basic hygiene advice or company-specific criticism rather than generalizable, standards-based guidance. It urges Congress to codify the CSRB with subpoena authority, mitigate conflicts of interest, and drive the creation and mapping of actionable industry standards (e.g., NIST-backed key rotation expectations) so cybersecurity investigations yield consistent, science-based lessons comparable to NTSB practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.