On the Cyber Safety Review Board
ID: bfba8141-8a66-5908-bf13-61164e8dfb63
STIX ID: report--bfba8141-8a66-5908-bf13-61164e8dfb63
Feed Name: Schneier on Security
This essay critiques the U.S. Cyber Safety Review Board (CSRB) for lacking subpoena power, transparency, and independence, arguing that its reports—on Log4j, Lapsus$, and China’s breach of Microsoft’s cloud—provide either basic hygiene advice or company-specific criticism rather than generalizable, standards-based guidance. It urges Congress to codify the CSRB with subpoena authority, mitigate conflicts of interest, and drive the creation and mapping of actionable industry standards (e.g., NIST-backed key rotation expectations) so cybersecurity investigations yield consistent, science-based lessons comparable to NTSB practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
