The Department of Homeland Security (DHS) published Binding Operational Directive 18-01, Enhance Email and Web Security. BOD-18-01 focuses on several elements including:
a. Enhance Email Security
b. Enhance Web Security
The above is a summary of the memo and resources available at https://cyber.dhs.gov.
My question for the community is: Does your organization leverage federal government requirements, beyond NIST guidance, to establish your policies and implementation guidance for cybersecurity and risk management? For example, minus the reporting requirements, the bullet list of email and web security parameters could be replicated for a company.
Correct recently all company are changing AES2 encryption for SSL/TLS offloading.
Narrow down such e-mail security we may have industry best practices.
Thanks for highlighting this issue.