The April 3 workshop was mobbed, the Department of Commerce auditorium was filled to capicity. I assumed that it would be thinly attended like the meetings of the Federal XML work group; but there must have been something like 500 people there. Clearly people are interested and are planning on following the process very closely. I hope that means that we will build a better standard that gains broad compliance.
This workshop was designed to gain industry's perspective. The first panel had Russell Schrader of VISA, Terry Rice of Merck, Michael Paypay of Northrop Grumman, and Reid Stephan of St. Lukes Health System.
Russell Schrader of VISA described the Executive Order as sensible, and was pleased with the request for private sector feedback. He also expressed the need for international cooperation, and that there is so much more to be done.
Schrader described security as being core to VISA's brand promise. He reminded that audience that VISA as one of the founding members of the Payment Card Industry Council, and suggested that PCI offers a template for cyber security coopoeration. He described the PCI system as scalable from the small merchant to the large.
Schrader described cyber security as a continuing process, that there is no box to be checked. He described VISA's approach as Prevent, Protect, and Respond, saying that, "we try to stop trouble before it begins."
Schrader called on NIST to build on what already exists and aim for global scalability. He was especially concerned that NIST not create contradictory procedures.
He stressed the need for information sharing, and that it was necessary to create a legal framework for law enforcement. (I assume that he meant over and above the work of NEIM.)
Michael Paypay, Chief Information Security Officer for Northrup Grumman, described his work as "where the rubber meets the road". He said that it was extremely important to Northrup protect the information that the government has entrusted to them.
Paypay described the defense industry as having a collaborative approach, going on to describe himself as "representing all my aerospace brothers." He said that cyber security not an area where aerospace competes, but rather they cooperate.
Paypay observed that there is no common lexicon of roles and responsibilities in cyber security. He also said that bench-marking against other people can be a problem. He described government "best practices" as very helpful, in particular NIST 800-53.
He said that it was important to identify what is appropriate for your business, going on to say that you cannot simply protect protect your perimeter; but that it was necessary to build a layered defense, and go through each layer in order to identify risk.
Reid Stephan said that it had been an eye opening experience to join health care industry, we are catching up to other industries. He said that the National Health ISAC looks to existing standards such as the 800-30 guide to risk assessment. He suggested that it was better to integrate existing standards and best practices rather than building something from scratch.
Stephan pointed out that cyber security risk management had to be balanced with business risk management, going on to say a risk based approach rather the control based approach would be more practical.
Stephan lamented the lack of robust intra and inter industry collaboration, and that the framework needs to address this sort of collaboration. He went on to observe that the cyber security framework will will never be finished, but become a dynamic standard.
Terry Rice of Merck thanked Commerce and NIST for hosting the workshop. Rice pointed out that life sciences, including pharmaceuticals, has been identified as critical infrastructure. The pharmaceutical industry is already working with DHS to protect their information.
Rice reiterated the point others had made, that cyber security is not binary - as in one is not either secure or insecure. He lamented lack of metrics for risk assessments and said that NIST is in a good position to help with this.
Rice said that in 2005 the pharmaceutical industry established a not for profit organization to establish digital standard standard for a bio-pharma digital signature. He said that security required authenticity, that is non-repudiable information. He described the NIST-800-63 guidelines as useful.
He reminded the audience that the DEA has established a standard for doctors' digital signature for controlled substances. Rice also spoke about the need for anonymity for persons searching for information about sensitive medical conditions.
Rice pointed out the need for skilled workers, lamenting that computer security is not a required for computer college students.
Rice echoed others call for an international approach, for example, how would the cyber security framework apply to a foreign owner of critical infrastructure?
He said that we have to include privacy as part of the framework. In this he underscored the Executive Order's inclusion of the federal government existing privacy guidelines.
At this point Patrick Gallagher opened it up for a general discussion asking, "How do we support adoption? How should the framework think about supporting adoption?
Michael Paypay said that everyone in the company has to be trained in security. He said that Northrup Grumman's spear phishes their own employees, providing remedial training for people who get it wrong.
Both Stephan and Rice pointed out that good compliance does not equal security. It is necessary to make sure that people understand, and you have to tread carefully when dealing with doctors.
Schrader said that you have to make sure people understand the need for security procedures.
Gallagher asked Schrader how VISA persuades its service centers and merchants be compliant. Schrader replied that VISA merchants are looking for something to implement that makes sense for their situation.
Panelists agreed that we need safe guards around data, whether in storage and transit.
Paypay observed that not all threats are the same. DDoS not affect business like Northrup Grumman as "we don't do business through the website."
Panelists agreed on the need to establish common vulnerabilities and not create new standards where there is an existing one.
Terry Rice talked about the need for metrics to measure and manage risk.
Gallagher asked the panelists how they talked about risk, and their bosses role in risk management, "how do you make cyber secuirty relavent to the C Suite? Schrader replied, "look at the daily paper, you can't run a company without knowing about these incidents, education not necessary at VISA."
Reid Stephan said that one "can't take a fear approach." It is necessary to have a consistent process to measure risk, and establish a relationship and seen as a partner, that gets you a "seat at the table."
Michael Paypay said that at Northrup-Grumman "we are lucky because our executives understand this. Also, our customers are highly educated about cyber security- they don't have a cut and dry practice for security."
Gallagher pointed out that in the US the government does not establish cyber security standards - "how can we exploit the fact that we work together?"
Schrader said that "you don't want to codify standards" because of the continuing changes in IT.
The next Cyber Security Framework Workshop will take place in Pittsburgh from May 29 through 31
Cyber Security Framework website
Grant Gross: US NIST: Industry should lead creation of cybersecurity framework
Brian Browdie: Cybersecurity Framework Demands Input from Industry, Official Says
J. Nicholas Hoover: No Bold Moves On U.S. Cybersecurity Framework
Jason Miller: NIST, industry begin journey to develop cyber framework
Molly Bernhart Walker: NIST sorting comments on cybersecurity framework
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Wednesday, April 10, 2013
Tuesday, March 26, 2013
The power of the free sample
Brite Technologies offers free instructions for virus removal to highly skilled computer users. What a brilliant idea.
New to me local blogs
Security Debrief, Security Debrief is a blog dedicated to homeland security, terrorism and counter-terrorism, intelligence and law enforcement that provides context to the debates, policies and politics that are playing out in Washington, D.C. ...
... Security Debrief is produced by Adfero Group and The George Washington University Homeland Security Policy Institute.
ECC IT Solutions
ThinkTech Blog, the blog of FedSolutions
Cloud Market Views, the blog of Virtustream
Straight Tech, the TMI blog, from Technology Management, Inc.
Turtle Wings blog, a blog about recycling electronic waste.
Managing Technology, the blog of Visular
The Interactive Files: Squash Errors, not Bugs!, From Wellfire Interactive
Whitehorse Technology Solutions
Accelera Solutions
Salient Federal Solutions
AETEA Information Technology
... Security Debrief is produced by Adfero Group and The George Washington University Homeland Security Policy Institute.
ECC IT Solutions
ThinkTech Blog, the blog of FedSolutions
Cloud Market Views, the blog of Virtustream
Straight Tech, the TMI blog, from Technology Management, Inc.
Turtle Wings blog, a blog about recycling electronic waste.
Managing Technology, the blog of Visular
The Interactive Files: Squash Errors, not Bugs!, From Wellfire Interactive
Whitehorse Technology Solutions
Accelera Solutions
Salient Federal Solutions
AETEA Information Technology
Friday, March 01, 2013
NIST asks for help in building cybersecurity framework
NIST to build cybersecurity framework, with your help
The Cybersecurity Framework will be a set of voluntary standards and best practices to guide industry in reducing cyber risks to the networks and computers that support critical infrastructure vital to the nation's economy, security and daily life, according to the NIST announcement published in the Federal Register. ...
...The first meeting will be held April 3 at NIST headquarters in Gaithersburg, Md. Registration information is available here.If you have concerns about cybersecuirty or privacy, I urge you to participate in these discussions."
Thursday, February 14, 2013
NIST issues RIF for Cybersecurity Framework
NIST has issued a RIF for Cybersecurity Framework (PDF), which will soon be published in the Federal Register. The Information Technology Laboratory of NIST has created a web site for Cybersecurity Framework.
Interested parties need to study the Request for Information, and make whatever response they deem appropriate. Those with questions and concerns should contact cyberframework@nist.gov.
Most of us can content ourselves with watching the Cybersecurity Framework website. I am hoping to attend the local events.
Interested parties need to study the Request for Information, and make whatever response they deem appropriate. Those with questions and concerns should contact cyberframework@nist.gov.
Most of us can content ourselves with watching the Cybersecurity Framework website. I am hoping to attend the local events.
The Cybersecurity Framework
I suggest that everyone who is interested read the Executive Order -- Improving Critical Infrastructure Cybersecurity before you read the news coverage. It is not long and is reasonably clear.
Clearly, much depends upon how this is implemented. I would encourage all those who are interested to participate in the process. Now is the time to speak out, before the Executive Order is implemented.
I would draw particular attention to Section 7:
What goes into the frame work and what is left out will determine what sort of cyber culture we will live with. And by "we" I don't merely mean Americans, this framework is sure to affect the entire industry.
The Executive Order clearly requires a consultative process that will include a public comment process. Section 5 sets for the privacy and civil liberties protections that are to be based on the Fair Information Practice Principles. Privacy and civil liberties advocates would be well advised to familiarize themselves with these principles.
I would also note the deadlines the Executive Order establishes (listed in order of the deadlines):
Clearly, much depends upon how this is implemented. I would encourage all those who are interested to participate in the process. Now is the time to speak out, before the Executive Order is implemented.
I would draw particular attention to Section 7:
Sec. 7. Baseline Framework to Reduce Cyber Risk to Critical Infrastructure. (a) The Secretary of Commerce shall direct the Director of the National Institute of Standards and Technology (the "Director") to lead the development of a framework to reduce cyber risks to critical infrastructure (the "Cybersecurity Framework"). The Cybersecurity Framework shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks. The Cybersecurity Framework shall incorporate voluntary consensus standards and industry best practices to the fullest extent possible. The Cybersecurity Framework shall be consistent with voluntary international standards when such international standards will advance the objectives of this order, and shall meet the requirements of the National Institute of Standards and Technology Act, as amended (15 U.S.C. 271 et seq.), the National Technology Transfer and Advancement Act of 1995 (Public Law 104-113), and OMB Circular A-119, as revised.
What goes into the frame work and what is left out will determine what sort of cyber culture we will live with. And by "we" I don't merely mean Americans, this framework is sure to affect the entire industry.
The Executive Order clearly requires a consultative process that will include a public comment process. Section 5 sets for the privacy and civil liberties protections that are to be based on the Fair Information Practice Principles. Privacy and civil liberties advocates would be well advised to familiarize themselves with these principles.
I would also note the deadlines the Executive Order establishes (listed in order of the deadlines):
Within 90 days of the publication of the preliminary Framework, these agencies shall submit a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, the Director of OMB, and the Assistant to the President for Economic Affairs, that states whether or not the agency has clear authority to establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure, the existing authorities identified, and any additional authority required.
(b) If current regulatory requirements are deemed to be insufficient, within 90 days of publication of the final Framework, agencies identified in subsection (a) of this section shall propose prioritized, risk-based, efficient, and coordinated actions, consistent with Executive Order 12866 of September 30, 1993 (Regulatory Planning and Review), Executive Order 13563 of January 18, 2011 (Improving Regulation and Regulatory Review), and Executive Order 13609 of May 1, 2012 (Promoting International Regulatory Cooperation), to mitigate cyber risk. The Secretary shall coordinate establishment of a set of incentives designed to promote participation in the Program.
Within 120 days of the date of this order, the Attorney General, the Secretary of Homeland Security (the "Secretary"), and the Director of National Intelligence shall each issue instructions consistent with their authorities and with the requirements of section 12(c) of this order to ensure the timely production of unclassified reports of cyber threats to the U.S. homeland that identify a specific targeted entity.
(c) To assist the owners and operators of critical infrastructure in protecting their systems from unauthorized access, exploitation, or harm, the Secretary, consistent with 6 U.S.C. 143 and in collaboration with the Secretary of Defense, shall, within 120 days of the date of this order, establish procedures to expand the Enhanced Cybersecurity Services program to all critical infrastructure sectors.
Within 120 days of the date of this order, the Secretary and the Secretaries of the Treasury and Commerce each shall make recommendations separately to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, that shall include analysis of the benefits and relative effectiveness of such incentives, and whether the incentives would require legislation or can be provided under existing law and authorities to participants in the Program.
(e) Within 120 days of the date of this order, the Secretary of Defense and the Administrator of General Services, in consultation with the Secretary and the Federal Acquisition Regulatory Council, shall make recommendations to the President, through the Assistant to the President for Homeland Security and Counterterrorism and the Assistant to the President for Economic Affairs, on the feasibility, security benefits, and relative merits of incorporating security standards into acquisition planning and contract administration. The report shall address what steps can be taken to harmonize and make consistent existing procurement requirements related to cybersecurity.
Sec. 9. Identification of Critical Infrastructure at Greatest Risk. (a) Within 150 days of the date of this order, the Secretary shall use a risk-based approach to identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security. In identifying critical infrastructure for this purpose, the Secretary shall use the consultative process established in section 6 of this order and draw upon the expertise of Sector-Specific Agencies.
(e) Within 240 days of the date of this order, the Director shall publish a preliminary version of the Cybersecurity Framework (the "preliminary Framework"). Within 1 year of the date of this order, and after coordination with the Secretary to ensure suitability under section 8 of this order, the Director shall publish a final version of the Cybersecurity Framework (the "final Framework").
(c) Within 2 years after publication of the final Framework, consistent with Executive Order 13563 and Executive Order 13610 of May 10, 2012 (Identifying and Reducing Regulatory Burdens), agencies identified in subsection (a) of this section shall, in consultation with owners and operators of critical infrastructure, report to OMB on any critical infrastructure subject to ineffective, conflicting, or excessively burdensome cybersecurity requirements.I trust that those tasked with creating the Framework will follow the excellent example of the Federal XML Work Group by setting up a website where the rest of us can follow their work. It is particularly important that the minutes of their meetings be posted in a timely manner and that their email discussion groups be publicly posted. This will build trust and increase the chances of a smooth adoption and implementation of whatever Framework is established.
Thursday, August 25, 2011
New to me local tech blog
Emergent, a blog about security.
Labels:
Potomac Tech Culture,
security,
technology
Monday, March 07, 2011
Today in Federal IT
Mark Amtower has some thoughts on defending your marketing budget in hard times.
Tom Temin finds out how his broadband service measures up courtesy of the FCC.
John Zyskowski gives us a wrap up of the recent RSA conference.
William Matthews: CIA blames 'technical difficulties' for website crash
NASA Now: Solar Storms.
Via Fedsphere created by Netspective.
Tom Temin finds out how his broadband service measures up courtesy of the FCC.
John Zyskowski gives us a wrap up of the recent RSA conference.
William Matthews: CIA blames 'technical difficulties' for website crash
NASA Now: Solar Storms.
Via Fedsphere created by Netspective.
Labels:
CIA,
FCC,
federal goverenment,
government contracting,
marketing,
NASA,
security
Thursday, February 10, 2011
New to me local tech blog
Arxan CTO Musings, Discussion on the latest application security developments and issues, including piracy, code protection, application hardening and cybersecurity.
Labels:
Potomac Tech Culture,
security,
software
Monday, January 03, 2011
Monday, December 06, 2010
Vigilante virtual riot
Hackers Target WikiLeaks Foes
You are attacking sites in the name of an open Internet? Isn't that a little like destroying the village to save it?
Edit -
It seems the anonymous group has decided on much smarter tactics.
"The reason is amazingly simple," said Anonymous member Gregg Housh. "We all believe information should be free, and the Internet should be free," said Housh, in an interview with The New York Times published Monday.
You are attacking sites in the name of an open Internet? Isn't that a little like destroying the village to save it?
Edit -
It seems the anonymous group has decided on much smarter tactics.
Wednesday, July 15, 2009
What would you do if you witnessed a crime?
Confidential Twitter documents
If someone shows you stolen material the proper thing to do is return the stolen items, and report the incident to the police. There seems to be a lot of confusion about this amongst journalists, but it is really very simple. A citizen should report criminal activity to the police.
If the stolen items are themselves evidence of criminal conduct, then the case is different. But if the material is just the information connected to a normal business, then its theft is a criminal matter.
I will be writing more about this when I have a chance, but once again the news business seems to be losing their moral compass and taking the rest of us with them.
If someone gets hold of private documents and sends them to you, and you’re an online publisher, what do you do?
Say you’re not interested and tell them to phk off? Publish and be damned, if not possibly sued, whatever the content? Publish bits and pieces according to your lights and sensitivities?
TechCrunch seems to have chosen the latter course.
If someone shows you stolen material the proper thing to do is return the stolen items, and report the incident to the police. There seems to be a lot of confusion about this amongst journalists, but it is really very simple. A citizen should report criminal activity to the police.
If the stolen items are themselves evidence of criminal conduct, then the case is different. But if the material is just the information connected to a normal business, then its theft is a criminal matter.
I will be writing more about this when I have a chance, but once again the news business seems to be losing their moral compass and taking the rest of us with them.
Labels:
anonymice,
Google,
news media,
privacy,
security,
TechCrunch,
Twitter
Wednesday, April 01, 2009
The case for alternative intelligence sources and outside contractors
My client Michael Bagley of the OSINT Group is profiled in this month's Homeland Security Today, check out page 52:
Note -
Wanted: Computer hackers ... to help government
One of Bagley’s constant themes is the utility of having an outsider challenging existing assumptions, particularly when it comes to hacking and network intrusions.
“Black operations require people to think this way” he argued. “Otherwise, there are no black teams. If we were all thinking the white way, the right way, we’d have no ability to counter these kinds of events or operations. It takes both kinds of people to work this way.”
Note -
Wanted: Computer hackers ... to help government
General Dynamics Information Technology put out an ad last month on behalf of the Homeland Security Department seeking someone who could "think like the bad guy." Applicants, it said, must understand hackers' tools and tactics and be able to analyze Internet traffic and identify vulnerabilities in the federal systems.
Labels:
intelligence,
national security,
OSINT,
security
Friday, February 06, 2009
Brilliant marketing
ComputerWorld has a story about KnujOn's report on the top ten spam-friendly domain registrars. This is normal public relations, do research, issue a report and alert the press. Just solid, basic PR, good but not brilliant.
I discovered the brilliant part when I went to the KnujOn's website. They are asking visitors to send them their spam. This gives them a list of prospects for their premium services along with the raw data for future research on spam. Well done KnujOn. File this under the Department of I wish I had thought of this myself.
I discovered the brilliant part when I went to the KnujOn's website. They are asking visitors to send them their spam. This gives them a list of prospects for their premium services along with the raw data for future research on spam. Well done KnujOn. File this under the Department of I wish I had thought of this myself.
Thursday, January 29, 2009
Call for papers: NSF Cyberinfrastructure Software Sustainability Workshop
Announcement
Venue: University Place Conference Center on the Indiana University Purdue University Indianapolis campus in Indianapolis, Indiana.
Workshop dates: 26-27 March 2009 (informal reception on evening of 25 March)
Paper submission deadline: 20 February 2009 (for invitation); 25 March (to contribute content)
Cyber war; but who is attacking?
Nathan Hodge has an interesting post on the recent shut down of internet traffic in Kyrgyzstan and make the interesting point that it is not clear how it happened. Was it an external attack? Or internal repression?
Tuesday, January 27, 2009
Privacy is a security issue
Security experts ask Obama for help
Edit -
Shareholder Activists Take On Web Privacy
Edit ii
It seems that today is privacy day.
A band of security and privacy experts is calling on President Obama to create a federal clearinghouse of information about data breaches -- and make that intelligence accessible to companies, consumers and law enforcement to help stem identity theft.
The proposal comes in a report titled, The Perfect Storm: Why the New Administration Cannot Ignore Identity Theft(PDF), compiled by Adam Levin, Chairman and Co-Founder of Identity Theft 911; Jay Foley, co-founder of the Identity Theft Resource Center; Pam Dixon founder of World Privacy Forum; and Chris Hoofnagle, senior staff attorney at the Berkeley Center for Law and Technology.
Edit -
Shareholder Activists Take On Web Privacy
Edit ii
It seems that today is privacy day.
Labels:
federal goverenment,
privacy,
security
Monday, January 26, 2009
Obama's cyber security iniative
Gautham Nagesh has a good summary. Much of it has to do with working with industry to develop secure standards. The federal government, and by extension, the Potomac area, has always played a leadership role in the development of IT standards. It is one of the most poorly understood aspects of Potomac technology culture, in spite of the fact that I have been blogging about it for five years.
What particularly caught my eye was the emphasis on corporate espionage:
It never ceases to amaze me that giant corporations think that they can trash the law and yet appeal to the law's protection when it suits them. If left unchecked, such a mentality swiftly degenerates into Russian style gangsterism. It is just pure hubris.
Note - White House Homeland Security Agenda
What particularly caught my eye was the emphasis on corporate espionage:
Prevent Corporate Cyber-Espionage: Work with industry to develop the systems necessary to protect our nation's trade secrets and our research and development. Innovations in software, engineering, pharmaceuticals and other fields are being stolen online from U.S. businesses at an alarming rate.
It never ceases to amaze me that giant corporations think that they can trash the law and yet appeal to the law's protection when it suits them. If left unchecked, such a mentality swiftly degenerates into Russian style gangsterism. It is just pure hubris.
Note - White House Homeland Security Agenda
Cyber sercurity and regime change
From last summer's International Relations & Security Network:
It we are to do better we need to do more than change Presidents, we have to ask for accountability. Our national security cannot be reduced to the newest watering whole for those who served us so poorly in the past.
In February 2007, Erik Prince, founder of the infamous private military company, Blackwater Worldwide, started what seems to be the next most lucrative market for such companies: intelligence gathering and analysis.
The new venture exists as a nexus of three companies that were quietly assembled by Prince the year before: the Black Group, LLC, the Terrorism Research Center, Inc (TRC), and Technical Defense, Inc. These companies form Total Intelligence Solutions, LLC, a company run out of an office in Arlington, Virginia, offering "evolved intelligence gathering and analysis" for "Fortune 1000 companies."
It we are to do better we need to do more than change Presidents, we have to ask for accountability. Our national security cannot be reduced to the newest watering whole for those who served us so poorly in the past.
Labels:
Blackwater,
Internet,
national security,
security
Thursday, January 22, 2009
A common misunderstanding about cloud computing
Matt Seidel, TechFlash
Using could computing does not necessitate giving up control of your data. I keep trying to tell reporters this, but clearly I am not getting through.
Amazon’s core business is to sell goods. Google‘s core business is search and advertising. Microsoft’s is traditional software. Are these really the companies we should be relying on to offer a highly reliable cloud infrastructure? Not to mention questions of security and data control, and the risks of storing valuable intellectual property outside your company’s firewalls.
Using could computing does not necessitate giving up control of your data. I keep trying to tell reporters this, but clearly I am not getting through.
Subscribe to:
Posts (Atom)