What Is Executive Order 14028, Who Is Affected and How to Comply

What Is Executive Order 14028?

On May 12, 2021, U.S. president Joe Biden issued an executive order on “Improving the Nation’s Cybersecurity” (Executive Order 14028). It was created in response to the growing number of cyberattacks launched against government agencies, critical infrastructure, and private companies based in the U.S.

Executive Order 14028 aims to help both the U.S. government and the private sector better protect themselves against cyber threats. To achieve this goal, the order establishes a framework that explains how to improve cybersecurity in the U.S. and specifies the technologies and practices required for this purpose. Specifically, EO 14028 requires organizations to implement three cybersecurity measures:

Securing development processes to prevent supply chain attacks.

Scanning application code to ensure it is secure.

Creating a software bill of materials (SBOM) to identify if there are vulnerable components used within a software application.

Who's Affected by Executive Order 14028?

Here are the main parties affected by Executive Order 14028:

Federal agencies The order outlines specific actions federal agencies must take to improve the cybersecurity of their systems and networks. They must implement strong security measures, such as zero trust security, regular risk assessments, and cybersecurity awareness training for their employees.
Critical infrastructure The order emphasizes the importance of protecting critical infrastructure, such as water systems, financial institutions, and power plants, from cyber attacks. It requires U.S. agencies to collaborate with organizations that run and maintain critical infrastructure in order to improve their security posture.
Federal contractors The order requires all federal contractors to implement security measures to secure their IT ecosystem when handling any form of sensitive information on the U.S. government’s behalf. It aims to minimize third-party risks and prevent supply chain attacks from impacting U.S. agencies.
The NIST The order recognizes the importance of the National Institute of Standards and Technology's (NIST) efforts to create and update cybersecurity standards and best practices. To improve cybersecurity across government agencies and critical infrastructure, NIST must collaborate with various stakeholders, including the private sector.

EO 14028: Requirements and Goals

Executive Order 14028 outlines four main requirements to strengthen the security posture of U.S. agencies, federal contractors, and the general public. Here is a brief overview of these requirements:

Sharing threat intelligence

Section 2 of the order requires all federal contracts, including cloud providers and cyber security providers, to share their threat intelligence and report on incidents. They must directly inform the agency affected, report all cyber events to CISA (the Cybersecurity and Infrastructure Security Agency), and cooperate in all investigations.

Implementing stronger security measures

Various sections of the order require federal agencies and critical infrastructure institutions to adopt adequate security standards. For example, section 3 directs the implementation of zero trust security, section 6 directs CISA to build an incident response playbook to be adopted as a standard for all government agencies, and section 7 requires implementing endpoint detection and response (EDR) technology.

Improving software supply chain security

The order mandates improving the security of all software used by federal government agencies. This part is explained in section 4, which directs NIST to review information from various sources, including agencies and private companies, and create standards for building and using software securely.

For example, the order requires using automated tools to secure development environments, generating software bill of materials (SBOM) reports to drive transparency, encrypting data, disclosing vulnerabilities, and more. The Office of Management and Budgeting (OMB) is directed to enforce these practices.

Investigating incidents to prevent future occurrences

The order seeks to ensure that incidents do not repeat themselves and the U.S. improves its overall security rapidly to better defend and prevent security incidents. The order directs the Attorney General and the Secretary of Homeland Security to establish a cyber safety review board to achieve this aim.

This board is required to review and assess significant cyber incidents affecting the information systems of federal civilian executive branch (FCEB) agencies and non-federal systems, as well as vulnerabilities and agency responses. Section 5 directs the Secretary of Homeland Security to prolong the mandate of this board every two years as deemed necessary unless otherwise stated by the president.

Complying with Executive Order 14208

Here are three key steps that can help get you closer to complying with Executive Order 14208:

1. Secure Development Process and Environment

The order requires securing development environments and processes by:

• Achieving visibility into software development infrastructure to determine where security processes and tools should be implemented.

• Implementing control over access to continuous integration (CI) pipelines, code repositories, and artifact registries, and adopting least-privileged access throughout the software delivery lifecycle (SDLC).

• Securing the development environment by scanning for security vulnerabilities and licensing issues on each build, to prevent malicious add-ons.

• Using separately administered build environments and auditing relationships of trust.

• Documenting and reducing dependencies as much as possible in enterprise products that comprise the environment used to develop, edit, and maintain software.

The order includes more directives to ensure secure software development and minimize supply chain risks.

2. Secure Code

The order places importance on verifying that all source code is written securely and can be trusted. Code scanners can help with this aspect by automatically identifying vulnerabilities, malware, secrets, and other threats. Organizations should identify vulnerabilities during the early phases of the SDLC to ensure detection when it is easiest and cost-effective to fix issues.

Organizations can shift security left more easily by using code scanners that automate the process of identifying vulnerabilities, integrate with IDEs and CI/CD tools, and run against binaries. Tools with low false positive rates and policy automation are preferable to prevent alert fatigue and ensure teams have time to focus on pressing security issues.

3. Software Bills of Materials (SBOM)

An SBOM tool generates a list of all components included within a certain piece of software. The order requires using SBOM regularly, directing organizations and agencies to use it to meet compliance.

An SBOM can help determine whether a certain software product is safe to use in the code, holding third-party software suppliers accountable for the security and quality of their products. It provides information about the open-source and proprietary dependency tree, including information about vulnerabilities and the specific license of each component.

