What is NSA Cybersecurity Guidance? Hardening Advice from the Agency That Watches Adversaries

8 minute read
Beginner

NSA publishes unclassified hardening guidance on identity, cloud, VPNs, and networks, derived from watching nation-state operators. What it covers and why it sets the standard of care.

What NSA Publishes

Cloud Security Mitigation Strategies

In March 2024, NSA and CISA jointly released ten short Cybersecurity Information Sheets on securing cloud environments. The topics: implementing secure cloud identity and access management, using secure cloud key management practices, network segmentation and encryption in cloud environments, securing data in the cloud, defending continuous integration and delivery environments, mitigating risks from managed service providers, upholding the shared responsibility model, managing cloud logs for effective threat hunting, and two others on account management and sensitive data. They are short because they are lists: the specific configurations that decide whether a cloud tenant is defensible.

Identity and Access Management

NSA and CISA's joint IAM guidance, produced with the Enduring Security Framework, is aimed at administrators and covers identity governance, environmental hardening, identity federation and single sign-on, MFA, and auditing and monitoring. Its most quoted contribution is the distinction between phishing-resistant MFA (FIDO2 security keys and PKI-based smart cards) and methods that adversaries relay or fatigue: SMS, voice, and push approvals. The guidance recommends phishing-resistant methods for administrators and remote access first. The adversary-in-the-middle campaigns that defeat push MFA by capturing the session token after approval are why.

Remote Access, Network, and Kubernetes

The joint guidance on selecting and hardening remote access VPNs addresses the appliances that appear in a disproportionate share of ransomware initial-access cases. The network infrastructure security guidance covers segmentation, management-plane isolation, and the configurations that let a single compromised workstation become an enterprise event. The Kubernetes Hardening Guide, co-authored with CISA, is the reference document for organizations running containers.

Why It Reads Differently from a Benchmark

The CIS Benchmarks and CISA SCuBA are product-specific checklists. NSA guidance is threat-derived and often product-agnostic. It explains the technique an adversary uses, then the mitigation, then the reason the mitigation works. The two styles are complementary and a mature program uses both. NSA tells you why external forwarding rules matter and what happens when an attacker creates one; the CIS Microsoft 365 Benchmark tells you which Exchange Online setting disables them.

The other difference is provenance. A Benchmark recommendation carries the authority of industry consensus. An NSA mitigation carries the authority of an agency whose job is watching adversaries succeed against well-defended targets. When a finding in a risk register cites both, it is difficult for any stakeholder to characterize the gap as a matter of opinion.

The Recurring Themes

Across the publications, the same failures recur. Standing privileged access instead of just-in-time activation. MFA that can be relayed. Legacy protocols left enabled for something that stopped needing them years ago. Logs that are collected but not retained long enough to reconstruct an intrusion, or retained but never read. Managed service provider access that is broader and more persistent than the service requires. Flat networks that let a compromised endpoint reach the domain controller. Cloud tenants where the shared responsibility model is assumed to mean the provider is responsible.

None of these are novel. That is the finding. The adversaries NSA watches are not relying on zero-days against mid-market organizations. They are relying on the ten things the guidance lists remaining undone.

NSA Guidance in a Risk Register

Where a finding matches a published NSA mitigation, the register records the document and section as a citation, alongside the NIST SP 800-53 control and the CIS or SCuBA reference. The citation does not change the remediation. It changes the conversation with the board, the underwriter, or the regulator, because the finding now reads as a documented federal recommendation the organization had not yet acted on rather than an advisor's preference.

What NSA Guidance Does Not Ask

NSA guidance is hardening guidance. Applied fully, it reduces the number of ways into an environment and shortens the time an intruder can operate unnoticed. It does not ask whether an intruder is already present. The organizations that appear in the Breach Library after doing the hardening correctly are the ones where the compromise predated the project: the session token captured before phishing-resistant MFA was rolled out, the rogue device registered before device compliance was enforced, the service principal over-permissioned before consent was restricted. Hardening and compromise assessment answer different questions. The first is about the future. The second is about what already happened.

Executive Implications

For a CFO, NSA guidance is a free, authoritative, and short definition of what a reasonably secured environment looks like, which makes it the fastest way to evaluate whether the security budget is buying the right things. For a GC, it is the document opposing counsel or a regulator will cite to establish what the organization should have known; knowing the conformance state first is the entire advantage. For a board, the ten cloud mitigation strategies are a one-page agenda: has management confirmed each one, and how?

For a PE operating partner, the guidance is a common yardstick across portfolio companies of different sizes and stacks, precisely because it is product-agnostic. A portco that cannot answer the ten questions has told you something about its program that no Secure Score would.

Related Reading

Real-World Example: Volt Typhoon and the Guidance That Preceded It

In 2023 and 2024, NSA, CISA, the FBI, and allied agencies published a series of joint advisories on Volt Typhoon, a People's Republic of China state-sponsored actor that pre-positioned inside United States critical infrastructure networks, in some cases for years, using living-off-the-land techniques that generated almost no malware for defenders to find. The actor's initial access came through internet-facing network appliances and VPNs; its persistence relied on valid credentials, flat networks, and logs that were not retained or reviewed.

Every one of those conditions had been the subject of prior NSA guidance: the VPN selection and hardening sheet, the network infrastructure security guidance, the IAM best practices, and the logging recommendations. The Volt Typhoon advisories did not introduce new mitigations. They named which of the existing ones the actor had relied on remaining undone. Cloudskope's analysis of the campaign covers the pre-positioning pattern in detail. The lesson for a mid-market board is simpler: the guidance was published before the intrusion, for free, by the agency that later described the intrusion.

10

Cloud security mitigation strategies published jointly by NSA and CISA in March 2024, covering identity, key management, network segmentation, logging, and managed service provider risk. Each one describes a failure NSA has watched an adversary exploit. None of them is optional for an organization that expects to be believed when it says it was reasonably secured.

How Cloudskope Can Help

Where a Cloudskope finding matches a published NSA mitigation, the register cites the document and section next to the NIST SP 800-53 control and CIS or SCuBA reference, so the finding carries federal authority when it reaches the board or the underwriter. Cloudskope SARTUS™ assesses identity, cloud, endpoint, and credential exposure against that guidance, then runs the compromise assessment hardening guidance cannot, and closes what it finds inside a six-day, fixed-fee window. See how the register maps across frameworks.