Showing posts with label Cyber Czar. Show all posts
Showing posts with label Cyber Czar. Show all posts

Friday, July 3, 2009

Coordinator in chief (C4ISR Journal)

Coordinator in chief
What experts say Obama's cybercoordinator must do to succeed
By Ben Iannotta
July 01, 2009
When America's first national cybersecurity coordinator arrives at the White House, he or she will have to settle long-standing questions about the precise roles of the military, private companies and federal regulators in protecting the country's electrical systems, water supplies and other services from a hacker's computer keystrokes.
President Barack Obama said he would personally choose and meet regularly with the coordinator, a position he announced in a May 29 speech at the White House. He said this person will have an office and staff in the White House, and will draft a "comprehensive" national cyberstrategy in "partnership" with the U.S. computer industry and government agencies. The coordinator — White House officials are not using the term "czar" — would work closely with White House budget officials on spending decisions and coordinate U.S. responses in the event of a cyberattack, he said.
Obama spoke in the East Room before a cast of 120 mostly civilian VIPs, an exception being Marine Corps Gen. James E. Cartwright, the vice chairman of the Joint Chiefs of Staff, whose job is to set the military's buying priorities. Also in the East Room were corporate CEOs and independent analysts who participated in the administration's "Cyberspace Policy Review," a fact-finding mission led by Melissa Hathaway, a former Bush administration intelligence official and now the top cyberofficial at the National Security Council. Hathaway and her staff met with networking companies, independent analysts and defense officials over the course of 60 days.
By placing responsibility for cybersecurity within the White House, and announcing a partnership with the industry, Obama set the U.S. on a different path than that of the Bush administration, which had relied on a combination of free market forces, presidential directives and the leadership of the Department of Homeland Security (DHS) to protect the private infrastructure. Instead of DHS leading the way, a White House official would be in charge, and this official would have a direct line to the White House Office of Management and Budget (OMB), which assembles spending requests from U.S. agencies into the annual budget requests to Congress. "It's going to be very important for the coordinator to work with OMB to ensure cybersecurity is adequately funded," said an OMB official in the East Room.
Neither Obama nor the 38-page Hathaway report spelled out precisely what actions the new spending authority and partnership with the industry would produce.
Would the government work with computer and software companies to draft regulations defining the security standards for the software underlying the U.S. infrastructure? Electrical hubs, for example, now have Internet Protocol addresses, which helps managers run electrical grids more efficiently, but also makes them vulnerable. Would better cybersecurity at such sites remain voluntary, as was the case under the Bush administration? Would the government cover the costs of beefed up cybersecurity in the private sector? For its part, the Hathaway report called for refining "government procurement strategies" and improving "market incentives" as the answer, but it did not define those steps any further. Would the coordinator's decisions affect the 2010 budget, which is currently before Congress, or wait until 2011 for impact?
Obama also did not discuss the controversial issue of America's offensive cyberattack planning, nor the precise role of the intelligence community and military in securing the U.S. private-sector infrastructure.
Military efforts
In recent months, military officials have been engaged in their own effort to reorganize themselves for cybersecurity. In May, for example, the U.S. Air Force announced it would establish a 400-person cyberheadquarters and operations center at Lackland Air Force Base, Texas, to coordinate cyberdefense with other services and, when necessary, launch offensive cyberactions. Originally, the Air Force planned on establishing its own cybercommand but backed away when critics said the service should focus on working with the other services instead of trying to lead in the cyberdefense domain.
Air Force Maj. Gen. William Lord, the service's top cybercommander, said "six verbs" would govern the work of the new 24th Air Force, the group focused on cyberspace: "establish, operate and maintain, defend, and exploit and attack." He spoke in late March at the National Space Symposium, before the service announced the location of the cyberheadquarters and operations center.
Lord said U.S. offensive cyberactions could turn out to be critical in future wars: "If you think about not warfare today, but warfare maybe 20 or 50 years from now, maybe it's not about the kinetic destruction of people or facilities. Maybe it's about so confusing a technologically advanced force by scrambling their technology that they don't have the ability to conduct warfare."
Part of the Obama strategy is likely to focus on technologies for identifying cyberattackers without violating the privacy of Internet users, something defense officials said would not be technically easy. "Two years ago in April, a million computers from 75 different nations attacked Estonia. Who do you go to war with?" he said. "Most of that attack came from [unknown people in] the United States. We're friends with Estonia," he said. "So figuring out: One, who the enemy is, and second, what's the intent of an enemy, in this domain, is very, very challenging."
Lord said the Air Force advised the Hathaway panel indirectly about the Air Force's plans and views on major cyberissues through the Pentagon's Joint Staff and the Office of the Secretary of Defense. Lord said reacting quickly to a cyberattack would be one of the great challenges confronting the country.
"What happens when you track back an IP address to you-name-the-country? How do you get law enforcement to that address, that physical address and using the laws of that country say, 'Stop that stuff?' That process takes weeks today. And we've got figure out how to make it occur more quickly," he said.
As far as military management of cyberdefense, Lord said defense officials were discussing the possibility of establishing a "sub-unified command" under U.S. Strategic Command to coordinate cyberwork among all the services. At about the time of Obama's announcement, The New York Times and The Associated Press reported that the U.S. was on the verge of establishing a new Cyber Command.
Though much is left to be sorted out, industry officials, by and large, said they were pleased that the White House had set a tone of partnership and will establish a high-level authority to define the national cyberstrategy under which the government, in all likelihood, would spend billions of dollars to improve security.
"It's encouraging to watch the United States and President Obama take the lead here in trying to innovate," said David DeWalt, CEO and president of McAfee, the computer security giant. DeWalt was one of those invited to gather in the East Room.
He said the importance of the word partnership, meaning with the industry and government, should not be discounted. "We believe the lack of partnership in the past has actually enabled the criminal behavior and terrorist behavior to emerge quicker, and with more force than had we had this interlock," he said.
Gregory Q. Brown, president and CEO of Motorola, also was in the East Room. "My team has met with [Hathaway], and we're very supportive," he said. He said Motorola is ready to help advise the government about how to keep networks secure, particular during emergency responses.
Budget link
Obama's most significant move, several attendees said, might have been when he underscored the cybercoordinator's relationship with the White House Office of Management and Budget.
"The way you get anyone to do anything is through the budget," said Alan Paller, director of research and defense at the SANS Institute, which researches information security technology. "That's what was wrong before. DHS didn't have any leverage" over spending at other agencies involved in cybersecurity, he said. "DHS could say anything they wanted and everyone could ignore them because there were no consequences."
Agencies have to listen to OMB or risk losing spending for other priorities, he said. "If you ignore OMB, the consequences are very sharp," he said.
Obama said he will designate cybersecurity one of "my key management priorities" and that the office of the cybercoordinator would set cyberpriorities and work "closely" with OMB "to ensure agency budgets reflect those priorities."
How much time the government should take before spending money under the new plan could emerge as an area of disagreement between the government and the industry. The Hathaway review describes refinement of government procurement strategies and establishment of market incentives as "Mid-Term" actions. Even at that, they are listed in line No. 14 of a table showing 14 mid-term actions.
Even so, Paller predicted the Obama administration would begin using the procurement process, in particular the defense process, in the near term "because it's the lever. It's the one you can move."
Also unclear in the Obama announcement was whether the emerging cyberstrategy would affect spending in the 2010 budget, which the administration sent to Capitol Hill three weeks before Hathaway's finding were made public and Obama announced the cybercoordinator office.
DeWalt of McAfee said it would be unwise to wait until the 2011 budget request to start applying funds under the administration's emerging cyberpolicy. "My opinion is, every day that we wait is another day that we're completely vulnerable. And I think, again, this activity [in the White House East Room] was a step in the right direction," he said.
DeWalt said the government already has billions of dollars of cyberdefense money in play because of the Bush administration's cyberinitiative. In 2008, with attempts to penetrate U.S. networks on the rise, the Bush administration launched the largely-classified Comprehensive National Cyber Security Initiative, which was defined by two executive directives, Presidential Directive 54 and Homeland Security Directive 23.
Former-Homeland Security Director Michael Chertoff announced the initiative and his agency oversaw the effort. Observers expect the Obama team to rework much of the Internet monitoring and intelligence-gathering policies contained within the Bush initiative. Obama, for example, said this cyberoffice "will also include an official with a portfolio specifically dedicated to safeguarding the privacy and civil liberties of the American people."
The differences in philosophy are huge, but the money and momentum remain. "This isn't starting from scratch with nothing," DeWalt said. "There is been some budget laid out from the previous administration. There is some opportunity to leverage that into the new programs," he added.
Industry officials said they expect the Obama strategy to focus less on spying on individual Internet users and more on securing private-sector networks related to critical infrastructures, and improving early-warnings of attempts to spread viruses and computer worms.
Federal regulations
One of the great debates among industry officials and analysts has been about the appropriate role for federal regulations, and whether it would be wise for an administration and Congress to create a new regulatory law that would require certain security software and procedures for private-sector networks. Such an act could be patterned after the U.S. Sarbanes-Oxley law that defines the kind of records financial institutions must make public, DeWalt said.
The topic of regulations was a hotly contested one during a series of meetings in 2007 through 2008 organized by the Center for Strategic and International Studies (CSIS), a think tank based in Washington. CSIS officials wanted to recommend a cyberstrategy for the incoming president. The experts met periodically over the course of more than a year, and in December, the group released its report, "Securing Cyberpspace for the 44th Presidency."
"We deliberated for about 14 months on that issue," said Phyllis Schneck, McAfee's director of threat intelligence for the Americas, and a member of the CSIS panel.
In the end, the CSIS panel was not shy about recommending federal cyber-regulations. The panel blasted the Bush administration's 2003 National Strategy to Secure Cyberspace for relying on market forces and ruling out federal regulation as a major player.
"In pursuing the laudable goal of avoiding overregulation, the strategy essentially abandoned cyber defense to ad hoc market forces. We believe it is time to change this. In no other area of national security do we depend on private, voluntary efforts. Companies have little incentive to spend on national defense as they bear all of the cost but do not reap all of the return. National defense is a public good. We should not expect companies, which must earn a profit, to survive, to supply this public good in adequate amounts," the CSIS panel said.
Obama stopped well short of embracing the CSIS wording: "My administration will not dictate security standards for private companies. On the contrary, we will collaborate with industry to find technology solutions that ensure our security and promote prosperity," he said.
Schneck said the Obama administration will need to find incentives. "How do we take a private-sector company that at the end does need to make money, and enable them to not only protect their infrastructure, but do things in the public good, and still remain profitable?" she said.
In the coming months, those in the East Room said one passage in Obama's 16-minute speech makes them certain that cybersecurity will remain a priority for the administration. Obama said that between August and October 2008 — the final stretch of the U.S. election campaign — "hackers gained access to e-mails and a range of campaign files, from policy position papers to travel plans." He said his campaign hired security consultants and met with the FBI and the Secret Service.
"It was a powerful reminder: In this Information Age, one of your greatest strengths — in our case, our ability to communicate to a wide range of supporters through the Internet — could also be one of your greatest vulnerabilities," he said.

Thursday, June 25, 2009

Harris Corp. expert panel: Cyber-czar faces bureaucracy, other big obstacles ahead (Orlando Sentinel)

Harris Corp. expert panel: Cyber-czar faces bureaucracy, other big obstacles ahead

By Richard Burnett

Sentinel Staff Writer

http://www.orlandosentinel.com/business/orl-biz-harris.cyberczar-062509,0,2955086.story


The nation's new federal "cyber-czar" will face serious obstacles to solving the nation's information technology problems, but the Obama administration is making a smart move in creating that position, experts said this week at a national press forum sponsored by Melbourne-based Harris Corp.

Entrenched bureaucracy, unclear authority and the fast pace of change in technology are just a few of the challenges ahead for the new top-level cyber-administrator, an expert panel told reporters at the National Press Club in Washington, D.C.

"I think the administration has taken the appropriate first step," said Dale Meyerrose, Harris Corp.'s top cyberspace executive and a former senior intelligence technology officer for the federal government. "They have acknowledged that the status quo is unacceptable and are setting priorities."

But it could take years to overcome the government's entrenched bureaucracy and get a real handle on problems that have developed over the years, the experts agreed.

"There are a lot of competing interests," said former Congressman Tom Davis, now director of federal government affairs for the Deloitte LLP consulting firm. "Key questions will be how much authority the coordinator has and how they will deal with the stovepipes and with getting legislative initiatives through Congress, where everyone will want to have a say."

One of the biggest issues for the cyber-czar will be the relative lack of authority that any "rookie" bureaucrat faces, said James Bamford, a journalist and author of books on cyberspace. As currently defined, the position has no real power or budget, which could make the cyber-czar subordinate to the director of the National Security Agency, who heads the Pentagon's new cyber-command, Bamford said.

"That would present quite a dilemma in terms of public civil liberties," he said. "I'd be much happier to see a very powerful person in charge of the cyber activity with a deputy from the civil liberties side of the spectrum. I also worry about the hype factor regarding vulnerabilities and would like to see the danger rhetoric toned down a bit."

Melbourne-based Harris Corp. sponsored the event as part of its cyber-security business development. The company recently expanded its security technology business by acquiring Crucial Security Inc., a key player in cyberspace solutions for law enforcement and intelligence agencies.

Tuesday, June 23, 2009

Tom Davis Doesn't Want Cyber Czar Job (National Journal)

TUESDAY, JUNE 23, 2009

Tom Davis Doesn't Want Cyber Czar Job

http://techdailydose.nationaljournal.com/2009/06/tom-davis-doesnt-want-cyber-cz.php

tomdavis.jpgFormer Rep. Tom Davis, R-Va., said Tuesday that he does not want the job of President Obama's cybersecurity coordinator despite recent rumblings that he was one of the top contenders for the position. "If I'd wanted to stay in government, I would have stayed in Congress," he said at a National Press Club briefing. "I don't have any real interest in going back." Davis joined the federal services team of consulting firm Deloitte last year after serving as chairman and ranking member of the House Government Reform Committee where he took the lead on legislation aimed at improving e-government, information security and critical infrastructure. When pressed further by reporters, Davis said he was "not a candidate for anything... [but] you never say never." He has maintained his departure from public service is only a sabbatical.

His main concern with the cyber czar position, which Obama described on the campaign trail and formally announced last month in conjunction with a wide-sweeping report that examined the federal cybersecurity posture, is the job description remains vague. Davis said it is unclear what the position would entail and how much authority the individual, who would report jointly to the National Security Council and National Economic Council, would have. "For this job to work you'd better get some understandings up front," he said. Davis lauded Obama for recognizing the need for a strong cybersecurity leader but said he thinks the administration has brought on too many czars. Melissa Hathaway, a senior adviser to Director of National Intelligence Dennis Blair, is potential candidate. Former Microsoft security chief Howard Schmidt's name has also come up.

Author James Bamford, who has written extensively about intelligence agencies, said he thinks the cyber coordinator is too low-level a post under Obama's plan and he finds it hard to believe the individual will have the president's ear. A former congressman would the perfect candidate for the job because he or she could "break through bureaucracy" but a powerful figure would not be keen on being so far down the chain of command. Retired Air Force Maj. Gen. Dale Meyerrose, now a vice president at Harris Corp., said the most encouraging aspect of the White House cyber report and Obama's remarks is that both made clear the status quo is unacceptable. The paper has 45 major implied tasks in nearly a half-dozen categories but Meyerrose warned: "You can't have 45 priority number ones."

Cyber Security Czar Front-Runner No Friend of Privacy (Threat Level)

Cyber Security Czar Front-Runner No Friend of Privacy

  • 7:57 pm

tom_davisFormer Republican Congressman Tom Davis, reportedly President Barack Obama's top candidate for cyber security czar, voted repeatedly to expand the government's internet wiretapping powers, and helped author the now-troubled national identification law known as REAL ID.

Citing White House sources, Time magazineon Friday identified the the former head of the Government Reform Committee as the president's number one candidate for the new position. Davis' reputation as a tech-smart moderate who knows his way around D.C. makes him an attractive pick for the administration, the magazine reported.

But an examination of Davis' record in Congress shows that he's been on the wrong side of key privacy issues, including the controversial REAL ID Act, which aims to turn state driver's licenses into a de facto national identification card linked by shared databases and strict federal authentication standards.

"Given his role in REAL ID, Tom Davis would not be a good choice for privacy, which is something that President Obama specifically promised to protect in his remarks on the cyber security strategy," says Jim Harper, the director of information policy studies at the libertarian Cato Institute. "Many cyber security planners refer obliquely to 'authentication' and 'identity management' programs that would devastate privacy, anonymity and civil liberties. Davis would probably work to roll past these issues rather than solve them."

The creation of a federal "identity management" program is one recommendation in the broad cyber security report published by the White House last month, although the report makes no specific proposals on implementing an internet I.D. card.

If picked as cyber security czar, Davis would be given the difficult and sensitive task of coordinating a government-wide strategy to secure the government's computer networks — as well as help secure the wider internet. That's a job fraught with perils ranging from inter-agency disputes over territory, and significant issues about what the government's role should be in improving security on the internet at large.

Davis, who served seven terms representing Virginia's high tech district, was known as an outspoken moderate in an increasingly base-oriented Republican party. He declined to run for re-election in 2008.

In announcing the creation of the new position last month, Obama stressed that privacy was key to the government's cyber security efforts. But Davis' most notable action on privacy was his failed attempt to undo a measure that put a chief privacy officer in every major government agency.

The ACLU's legislative scorecard on Davis shows he disagrees with that group on many privacy matters.

For instance, he voted consistently to give the government wide latitude to wiretap the internet and spy on Americans' communications. That program, including the NSA's massive database of emails known as "Pinwale," made news recently again when The New York Times reported that the NSA examined Americans' domestic e-mails without authority.

That track record would not put Davis out of the running with Obama, who, after winning his party's nomination, embraced expanded government wiretapping powers, and voted to extend retroactive legal immunity to the telecom companies that helped the Bush's administration's secret spying.

Last summer, Davis joined with then-senator Obama, a wide swath of centrist Democrats, to legalize the Bush program, granting the NSA the right to gather billions of communications records of foreigners and Americans, and read Americans' international communications without warrants. The law includes the caveat that if a particular U.S. person is targeted, the government must get court approval.

But Davis could excel in a new role as cyber security czar, says Marc Rotenberg, who heads the Electronic Privacy Information Center.

"He's a good pick," Rotenberg says.

Davis gets things done, supports bipartisanship, and comes from a civilian and industry background, rather than from the shady intelligence world, according to Rotenberg.

"[It's] much easier for a former House chairman to stand up to the Director of National Intelligence and the NSA than some of the other candidates," Rotenberg says.

That will be important going forward. Bush went through a succession of so-called cyber-security czars, who found they were either powerless or stuck in bureaucratic battles they could not win.

But Rotenberg's organization has not always been a fan of Davis.

After 9/11, Davis pushed for changes to open government laws that created an even larger shield for information that private companies gave to the government. Specifically, Davis won protections for companies that run critical infrastructure — such as railroads and chemical plants — allowing them to tell the Department of Homeland Security about dangerous practices without the fear that the public could petition to see the information.

David Sobel, a Freedom of Information Act attorney, testified against that provision in 2002, when he worked for Rotenberg at EPIC.

"We are discussing the desire of private companies to keep secret potentially embarrassing information at a time when the disclosure practices of many in the business world are being scrutinized," Sobel said, referring to the overstated corporate profits that were being discovered in 2002. "If a company is willing to fudge its financial numbers to maintain its stock price, what assurance would we have that it was not hiding behind a 'critical infrastructure' FOIA exemption in order to conceal gross negligence in its maintenance and operation of a chemical plant or a transportation system?"

Davis did not return a call to his office at the consulting firm Deloite.

A White House spokesman declined to comment on Davis, saying only that "no decision has been made yet, so any reporting of anyone being offered the job is not accurate."

Saturday, June 20, 2009

Is Tom Davis Too Qualified to be Cyber Czar? (The Public Eye)

Is Tom Davis Too Qualified to be Cyber Czar?

June 19, 2009 - Eric Chabrow

Eric Chabrow
Former Rep. Tom Davis' name has popped up before and it's come up again as President Obama's new cybersecurity czar.

A story posted on Time's website Friday says the moderate Republican from northern Virginia has emerged as a leading candidate for a job Obama describes as cybersecurity coordinator. White House sources quoted by Time who say the administration feels a Washington power player would make a better candidate than a tech guru. "They want someone who understands technology issues, but more importantly, knows how to get things done in Washington," says a cybersecurity expert who has been consulted by the White House. "There are very few people who have that combination of skills, and Davis is at the top of that short list." 

There are very few people who have that combination of skills, and Davis is at the top of that short list. 

Davis, indeed, is among the most qualified and influential people in Washington when it comes to information technology, IT security and getting things done. He's a wheeler-dealer in the best sense of that term. Indeed, as chairman of House panels overseeing government IT, Davis shepherd through Congress the E-Government Act and the Federal Information Security Management Act, which governs cybersecurity in the federal government. He's also a whiz at understanding the ins and outs of government procurement, important knowledge considering the amount of technology and services the government will acquire to in the coming years to secure IT systems and data.

But unless Obama boosts the cybersecurity adviser's job on the White House organizational chart a few notches to guarantee greater, direct access to the president, would someone of Davis' stature accept the job? So far, Obama has characterized the post as a cybersecurity coordinator, and coordinator doesn't sound very much like an influential of a role.

In an interview with GovInfoSecurity.com earlier this year, before Obama outlined his cybersecurity agenda in late May, Davis saw the need for the government to spend heavily on IT security, and expressed disappointment that no money was earmarked for cybersecurity in Obama's stimulus package. Davis said:

You are competing for dollars and priorities at this point ... but you know, at this point, we are not where we need to be and I think everybody understands that.

Davis sees the power of the buck in getting things done, and says Congressional appropriation process is a good vehicle to get federal agencies to improve federal IT security.

You have got to get the appropriators involved in this or I think otherwise there is no and you have got to make sure that this comes down from the top from the president that this is a priority. I get the feeling sometimes that everybody is hoping this won't happen on their shift. They are not getting additional dollars in any of these cases, they try to secure your networks but without any additional money they have a lot of other missions that they are trying to accomplish and you get no credit for doing anything here. It doesn't help you accomplish your mission, and you are trying to make sure you don't get a cyber attack, but you don't get any credit if an attack doesn't come whether you put FISMA or not and you are just taking the chance that it doesn't hit on your watch. Now, though, we are getting more and more penetrations and I think people are starting to get worried.

And, here's how Davis describes the government's current cyber defense stature:

It is still very stovepipe and we are going to have some cyber attack somewhere and there are going to be some damages done and at that point people are going to what to know what have you done about it. A lot of us have been screaming about this for years, Republicans and Democrats, but at the end of the day you can't legislate this stuff because it comes from the executive branch. Hopefully, after they have finished their study at this point they will put some money behind this. That is our goal and that is the hope.

Besides Davis, others mentioned as the potential White House cybersecurity adviser, according to Time and others:

  • Melissa Hathaway, who led the administration's 60-day cybersecurity review and former cybersecurity advisor to President Bush (read our profile on Hathaway).
  • Fred Kramer, assistant defense secretary for international security affairs under President Clinton;
  • Howard Schmidt, a onetime Microsoft chief security advisor and former adviser to Bush on cyberspace security and protection of critical infrastructure (read BankInfoSecurity.com's interview with Schmidt on the war on cyber crime)
  • Paul Kurtz, an Obama advisor who served in the National Security Council under Bush and Clinton (read/listen to our interview with Kurtz);
  • Susan Landeau, a Sun Microsystems's distinguished engineer with cybersecurity and public policy expertise;
  • Maureen Bainski, a former FBI intelligence leader; and
  • Scott Charney, head of Microsoft's cybersecurity division.

Wednesday, June 17, 2009

Hathaway: National cyber incident response plan coming by year end (FCW)

Hathaway: National cyber incident response plan coming by year end

Hathaway also confirms she's in running for White House cybersecurity coordinator

The Cyberspace Policy Review released by the White House last month was only the beginning of an effort being driven by President Barack Obama to reshape and strengthen the nation's cybersecurity, according to Melissa Hathaway, who headed up the review.

Hathaway, acting senior director for cyberspace for the National and Economic Security Councils, said today her team plans to produce a comprehensive national incident response plan by the end of the year that will guide response to the cyber equivalent of a major natural disaster. The team also will be working to unravel the overlapping and sometimes contradictory laws and regulations identified in the study that get in the way of effective cooperation and responses to cyber threats.

"You can expect a dialog on this issue with the private sector," Hathaway said at the Symantec Government Symposium in Washington. "You will also see us working with Congress because many issues will require a legislative fix."

As a result of the Cyberspace Policy Review, Obama announced last month the creation of a White House office of cyberspace coordinator, who will oversee government cybersecurity policy.

Hathaway on June 12 told Federal Computer Week, that she is a candidate for the White House cybersecurity coordinator position. According to Hathaway, officials hope to select a cybersecurity coordinator in the coming weeks, but no definite date had been set.

"In the coming weeks there will be an announcement of a cyberspace coordinator," Hathaway said. She said the president is personally engaged in the selection, which should be made soon.

The efforts reflect what Hathaway called an '"unprecedented level" of presidential leadership in cybersecurity. It is being established as one of Obama's management priorities, which means performance metrics are being established that will make department heads, not just chief information officers, accountable for their agencies' security posture.

Hathaway illustrated the scope of the cybersecurity issue with a familiar litany of challenges. The Internet and its associated information infrastructure now underpin much of the global economy and are essential to continued economic growth. However, it has expanded in scope and functionality at a pace that has outstripped efforts to secure it.

"It is not secure enough nor is it resilient enough to be move us forward," she said. "We are faced with a dangerous combination of known and unknown vulnerabilities."

The infrastructure is being challenged and attacked not by amateurs, but by professional criminals and spies backed with substantial resources.

There are no coordinated plans for protecting the critical infrastructure or responding to incidents, either by government or the private sector, she said. At the same time, three of the most important initiatives in moving the nation's economy ahead — building out universal broadband networks, a smart energy grid and electronic health records — are all threatened by these vulnerabilities and exploits.

"These are some of the things that keep the president up at night," Hathaway said.

The incident response plan will be vetted by the Homeland Security Department and private industry, and Hathaway said a wiki might be established to allow the private sector to collaborate in its development.

Difficult issues of liability and confidentiality will have to be resolved to enable the kind of pubic/private partnership that everyone agrees is necessary to improve cybersecurity. "We can no longer talk about a public-private partnership, but need to act on it," she said.

Greater international cooperation also is needed, and achieving this will require establishing common standards of behavior in cyberspace. Norms need to be established for defining criminal activity, warfare and terrorism, so that appropriate responses can be agreed upon, she said.

And to achieve all of this, a greater pool of manpower and expertise is required. Educational efforts must be extended past universities into primary and secondary schools to provide an adequate flow to the pipeline.

Tuesday, June 16, 2009

Lawmakers fear White House cybersecurity czar would undercut DHS role (Computerworld)

Lawmakers fear White House cybersecurity czar would undercut DHS role

June 15, 2009 12:01 AM ET

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=340091&intsrc=news_ts_head


Computerworld - Some lawmakers are questioning President Barack Obama's plan to appoint a White House cybersecurity coordinator, fearing that the new post will dilute the role of the U.S. Department of Homeland Security.

The misgivings were expressed during a U.S. Senate confirmation hearing held earlier this month for Rand Beers, the president's nominee for the post of undersecretary of the DHS's National Protection and Programs Directorate, just days after the Obama announcement.

Sen. Joseph Lieberman (I-Conn.), who chairs the Senate Committee on Homeland Security and Governmental Affairs, said he fears that a new cybersecurity czar will "undercut the role of the DHS."

"To me, it's not just turf. It's a very critical element of homeland security," Lieberman said.

Sen. Susan Collins (R-Maine), a ranking member of the committee, added that concentrating power in the White House could make oversight more difficult -- because DHS officials are more likely to appear before the committee when asked.

"[I have a] lot of reservations about the establishment of a White House cybersecurity czar," she said.

Obama told reporters at a press conference announcing the move that the as-yet-unnamed coordinator will be responsible for "orchestrating and integrating" all cybersecurity policies for the government.

In his testimony before the committee, Beers said the White House position will have no operational authority and will serve a purely coordinating function. There will be "no realignment of roles and mission for the [DHS]," and the department's operational role will not be undercut, he added.

The limits of a cyber czar (FCW)

The limits of a cyber czar

Many of the government's chief security challenges are for agencies to address

As President Barack Obama announces plans to appoint a cybersecurity coordinator, cybersecurity continues to challenge agencies in ways that the eventual appointee might find difficult to fight.

Identifying the chief vulnerabilities in federal cybersecurity is easy: incomplete inventories of systems so agencies do not know what computers they are running; insecure configurations; delays of weeks or months in installing patches; a critical shortage of employees with advanced technical skills to do forensics and intrusion detection and code reviews; and custom software with programming errors that provide easy access for attackers. A more complete list is embedded in the report, "Twenty Critical Security Controls," published by the Center for Strategic and International Studies.

Sadly, solving most of the problems falls to individual agencies more than a cyber czar. Agencies would have fixed most problems if they had the means. So the question is: What are the most critical impediments stopping agencies from doing the right things.

Here are three of the biggest.

1. Chief information officers and procurement officials allow systems integrators and software vendors to deliver systems and software with security flaws. When the flaws are discovered, integrators demand more money to fix their errors — more than the cost of the flawed software. The Federal Desktop Core Configuration is not widely implemented because CIOs still have not forced integrators and software vendors to guarantee their software works on FDCC-equipped systems.

2. Federal managers lower standards to not embarrass unqualified people. An example is the Defense Department's failed effort to ensure its security people have certified technical skills to do hands-on security work. Fixing the skills shortage is one of the nation's top priorities. But when DOD discovered that many security people do not have strong hands-on technical skills, officials simply ordered a security certification that avoided the tough technical questions.

The result is that nearly everybody passes, and the nation wastes the opportunity to improve security. Several civilian agencies meet the requirement to provide technical training for their security employees by offering online training, but the agencies do not require the employees to pass tests to prove they have mastered the material or even ensure they take the training. One agency reported privately that no one — not one person — completed the online training. That agency still gave itself full credit for providing technical training to its security people, and its auditors concurred.

3. Auditors measure what is easy to count instead of measuring what is critical to do. The Government Accountability Office has repeatedly told Congress that federal cybersecurity auditors generally do not measure the effectiveness of critical controls. They might measure whether a policy is in place but not whether the policy has been implemented effectively. Why? Because it is easier to count the paper documents than to ensure that effective technical controls are in place.

So what can the cyber czar do? Shine a public light on those anti-security practices, and when those caught in the spotlight complain, give them the White House support they need to do the job right, along with deadlines and consequences. Every person mentioned above — CIOs, training managers and auditors — want to do the right thing. But they have not been given the spine-stiffening top cover they need from the White House. It's time they got it.

About the Author

Alan Paller is the Director of Research for the SANS Institute. 

Sunday, June 14, 2009

Hathaway confirms she's a candidate for cyber chief (FCW)

Hathaway confirms she's a candidate for cyber chief

Hathaway details cybersecurity review, confirms she's a canditate for cybersecurity coordinator position

Melissa Hathaway, the official that led the Obama administration's 60-day review of cybersecurity policy, confirmed Friday that she is a candidate for the White House cybersecurity coordinator position.

Hathaway said there is a list of candidates -- she wasn't sure how long -- being considered for the position, but that  President Barack Obama hadn't yet conducted any interviews. Obama, in a May 29 speech on cybersecurity policy, said he would "personally select" the cybersecurity coordinator. She said officials hoped to have a cybersecurity coordinator selected in the coming weeks, but that no definite date had been set.  

Hathaway, who has been serving as the acting senior director for cyberspace on the White House's National Security Council, said that she is interested in the job.

She made the comments while speaking with reporters after an event hosted by the Center for Strategic and International Studies in which she detailed the findings of the administration's review and highlighted areas of future focus.

She also said the administration was reviewing the many cybersecurity-related bills that lawmakers have introduced in recent months and working to put together a comprehensive view of the legislation for Congress.

During her speech she said the administration will make cybersecurity a core management responsibility – on a par with human capital and fiscal management – for heads of executive agencies and departments. 

Throughout the speech Hathaway emphasized the importance of privacy and civil liberties concerns as the administration's cybersecurity efforts move forward, saying the goal is to have an official on the national security staff with that responsibility hired in the next few weeks.

Ex-Government Cyber Official, Exec Mulled for Czar Job (Epicenter)

Ex-Government Cyber Official, Exec Mulled for Czar Job

WASHINGTON (Reuters) - Microsoft's security chief and a veteran of Clinton's and Bush's national security teams are leading candidates for cybersecurity czar, a job that needs White House access and clout to protect networks that underpin the U.S. economy.

President Barack Obama promised last month that he would personally decide who would lead the fight against an epidemic of cybercrime and organize a response to any major cyber attack.

A leading candidate for the post is Scott Charney, head of Microsoft's cybersecurity division, who has said he won't take the job, according to a source who had direct knowledge of the matter but was not authorized to discuss it. The source said, however, that Charney would change his mind if pressed.

Charney also led PricewaterhouseCoopers' cybercrime unit and headed the Justice Department's computer crime section.

His main competitor is likely Paul Kurtz, who led Obama's cybersecurity transition team and who worked on the National Security Council under both Bush and Clinton, the source said.

Others under consideration include former Rep. Tom Davis, a moderate Virginia Republican; Sun Microsystems executive Susan Landau; Maureen Baginski, a veteran of the National Security Agency and Federal Bureau of Investigation, and Frank Kramer, an assistant defense secretary under Clinton, the source told Reuters.

Also in the running but less likely to be picked are Melissa Hathaway, who led a cybersecurity review for the president, and James Lewis of the Center for Strategic and International Studies think tank, the source said.

John Thompson, chairman of the board of Symantec Corp, had been under consideration but turned it down, the source said.

The exact responsibilities of the new job remain largely undefined, although the position described in a report by Hathaway's team describes a coordinator who reports to both the National Security Council and the National Economic Council.

Holes in U.S. cybersecurity defenses have allowed major incidents of thefts of identity, money, intellectual property and corporate secrets. In one incident, a bank lost $10 million in cash in a day.

There have also been thefts of sensitive military information and a penetration of the U.S. electrical grid.

Susan Landau, who declined to discuss if she has been short-listed for the job, said she would urge Obama to make it a top-level position, as he promised.

"The job is very important," said Landau. "We have all sorts of different kinds of threats. … What you want is ubiquitous security."

Landau is a Sun Microsystems engineer who has worked on digital rights, privacy and export control.

Lewis, who also declined to discuss on the record whether he was being considered, said the White House must emphasize national security expertise in picking a cybersecurity czar.

"Some guy from industry is going to write a national security strategy? No, they aren't. You don't just pick this up," said Lewis. "You need somebody who knows the national security game, who knows government and who knows about the technology."

Before becoming a senior fellow at CSIS on technology and national security, Lewis worked for the federal government as a foreign service officer with assignments on such disparate topics as global arms sales, encryption and high-tech trade with China.

Lawmakers on Capitol Hill shared Lewis' and Landau's views, said a senate staffer who has been briefed on the issue.

"The president's vision is a heavyweight," said a Senate staffer. "I'm concerned that he or she will get sort of tied up, like Gulliver, tied down by a million different reporting requirements."