Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
US Cyber Safety Review Board faults Microsoft failure 'cascade' in Chinese hack (washingtonpost.com)
5 points by wolverine876 on April 3, 2024 | hide | past | favorite | 2 comments


Two very interesting parts (IMHO):

First, there is a US Cyber Safety Review Board (CSRB), established 2022:

It's part of the Cybersecurity & Infrastructure Security Agency (CISA), which you may recognize, at the Department of Homeland Security. The board "serves a deliberative function to review and assess significant cyber incidents and make concrete recommendations that would drive improvements within the private and public sectors." Membership is government and private industry, including a Google VP, former Crowdstrike CTO, NSA leaders, etc.

https://www.cisa.gov/cyber-safety-review-board-csrb-members

Second, how much I am stuck with Microsoft's explanation. Did anyone know much of what is in the OP or in this summary:

https://www.dhs.gov/news/2024/04/02/cyber-safety-review-boar...


The TLDR tangible outcome appears to be:

1. Stop charging for audit logs for Exchange Online's MailItemsAccessed activity[1].

On this point, Microsoft announced in July 2023[2] and added it to their roadmap in October 2023[3] that they'll make this feature part of the "standard" feature level some time after June 2024.

The rest of the items give the impression of just being a bit angry, but nothing materially planned to be done about it. What other option realistically exists once 99% of businesses and government agencies are locked into using M365?

[1] https://learn.microsoft.com/en-us/purview/audit-solutions-ov...

[2] https://www.bleepingcomputer.com/news/microsoft/microsoft-ex...

[3] https://www.microsoft.com/en-us/microsoft-365/roadmap?filter...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: