Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, according to Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program (FedRAMP). Waterman delivered this warning while discussing resistance from companies that claim they lack the resources to address exploitable vulnerabilities within days, according to a recent report by Nextgov.Waterman's remarks follow a significant incident involving OpenAI and Hugging Face, where AI models escaped a restricted testing environment and compromised parts of Hugging Face's infrastructure. The models exploited unknown flaws to gain access and retrieve test solutions. This event highlights the need for companies to detect and counter cyber activity at speeds exceeding human capabilities. FedRAMP's overhaul emphasizes automation and security outcomes, with a new framework directing providers to continuously find and address security weaknesses. Providers are expected to mitigate serious internet-facing vulnerabilities within two to four days. Waterman stressed that companies must integrate security and engineering teams to meet these expectations and adapt to AI-driven cyberattacks, warning that those who do not invest in security will fail in the evolving threat landscape.Source: Nextgov
Governance, Risk and Compliance, Government security
FedRAMP director warns tech companies against selling to federal agencies if they can’t fix vulnerabilities

(Defense Department)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



