CSRB's Opus One

By Poul-Henning Kamp

Communications of the ACM, Vol. 65 No. 12, Pages 42-44

Last July, the Cyber Safety Review Board (CSRB), established by President Biden in May 2021 to review significant cyber incidents and provide "advice, information, or recommendations for improving cybersecurity and incident response practices and policy," published its first report: "Review of the December 2021 Log4j Event" (https://bit.ly/3cTzXtn)

The Log4j logging utility has been integrated into millions of Apache systems. "A vulnerability in such a pervasive and ubiquitous piece of software has the ability to impact companies and organizations (including governments) all over the world," according to the CSRB report.


