July 01, 2009
Friday, July 3, 2009
Coordinator in chief (C4ISR Journal)
July 01, 2009
Thursday, June 25, 2009
Harris Corp. expert panel: Cyber-czar faces bureaucracy, other big obstacles ahead (Orlando Sentinel)
Harris Corp. expert panel: Cyber-czar faces bureaucracy, other big obstacles ahead
By Richard Burnett
Sentinel Staff Writer
http://www.orlandosentinel.com/business/orl-biz-harris.cyberczar-062509,0,2955086.story
Entrenched bureaucracy, unclear authority and the fast pace of change in technology are just a few of the challenges ahead for the new top-level cyber-administrator, an expert panel told reporters at the National Press Club in Washington, D.C.
"I think the administration has taken the appropriate first step," said Dale Meyerrose, Harris Corp.'s top cyberspace executive and a former senior intelligence technology officer for the federal government. "They have acknowledged that the status quo is unacceptable and are setting priorities."
But it could take years to overcome the government's entrenched bureaucracy and get a real handle on problems that have developed over the years, the experts agreed.
"There are a lot of competing interests," said former Congressman Tom Davis, now director of federal government affairs for the Deloitte LLP consulting firm. "Key questions will be how much authority the coordinator has and how they will deal with the stovepipes and with getting legislative initiatives through Congress, where everyone will want to have a say."
One of the biggest issues for the cyber-czar will be the relative lack of authority that any "rookie" bureaucrat faces, said James Bamford, a journalist and author of books on cyberspace. As currently defined, the position has no real power or budget, which could make the cyber-czar subordinate to the director of the National Security Agency, who heads the Pentagon's new cyber-command, Bamford said.
"That would present quite a dilemma in terms of public civil liberties," he said. "I'd be much happier to see a very powerful person in charge of the cyber activity with a deputy from the civil liberties side of the spectrum. I also worry about the hype factor regarding vulnerabilities and would like to see the danger rhetoric toned down a bit."
Melbourne-based Harris Corp. sponsored the event as part of its cyber-security business development. The company recently expanded its security technology business by acquiring Crucial Security Inc., a key player in cyberspace solutions for law enforcement and intelligence agencies.
Tuesday, June 23, 2009
Tom Davis Doesn't Want Cyber Czar Job (National Journal)
TUESDAY, JUNE 23, 2009
Tom Davis Doesn't Want Cyber Czar Job
http://techdailydose.nationaljournal.com/2009/06/tom-davis-doesnt-want-cyber-cz.php
Former Rep. Tom Davis, R-Va., said Tuesday that he does not want the job of President Obama's cybersecurity coordinator despite recent rumblings that he was one of the top contenders for the position. "If I'd wanted to stay in government, I would have stayed in Congress," he said at a National Press Club briefing. "I don't have any real interest in going back." Davis joined the federal services team of consulting firm Deloitte last year after serving as chairman and ranking member of the House Government Reform Committee where he took the lead on legislation aimed at improving e-government, information security and critical infrastructure. When pressed further by reporters, Davis said he was "not a candidate for anything... [but] you never say never." He has maintained his departure from public service is only a sabbatical.
His main concern with the cyber czar position, which Obama described on the campaign trail and formally announced last month in conjunction with a wide-sweeping report that examined the federal cybersecurity posture, is the job description remains vague. Davis said it is unclear what the position would entail and how much authority the individual, who would report jointly to the National Security Council and National Economic Council, would have. "For this job to work you'd better get some understandings up front," he said. Davis lauded Obama for recognizing the need for a strong cybersecurity leader but said he thinks the administration has brought on too many czars. Melissa Hathaway, a senior adviser to Director of National Intelligence Dennis Blair, is potential candidate. Former Microsoft security chief Howard Schmidt's name has also come up.
Author James Bamford, who has written extensively about intelligence agencies, said he thinks the cyber coordinator is too low-level a post under Obama's plan and he finds it hard to believe the individual will have the president's ear. A former congressman would the perfect candidate for the job because he or she could "break through bureaucracy" but a powerful figure would not be keen on being so far down the chain of command. Retired Air Force Maj. Gen. Dale Meyerrose, now a vice president at Harris Corp., said the most encouraging aspect of the White House cyber report and Obama's remarks is that both made clear the status quo is unacceptable. The paper has 45 major implied tasks in nearly a half-dozen categories but Meyerrose warned: "You can't have 45 priority number ones."
Cyber Security Czar Front-Runner No Friend of Privacy (Threat Level)
Cyber Security Czar Front-Runner No Friend of Privacy
- By Ryan Singel
- June 22, 2009 |
- 7:57 pm
Former Republican Congressman Tom Davis, reportedly President Barack Obama's top candidate for cyber security czar, voted repeatedly to expand the government's internet wiretapping powers, and helped author the now-troubled national identification law known as REAL ID.
Citing White House sources, Time magazineon Friday identified the the former head of the Government Reform Committee as the president's number one candidate for the new position. Davis' reputation as a tech-smart moderate who knows his way around D.C. makes him an attractive pick for the administration, the magazine reported.
But an examination of Davis' record in Congress shows that he's been on the wrong side of key privacy issues, including the controversial REAL ID Act, which aims to turn state driver's licenses into a de facto national identification card linked by shared databases and strict federal authentication standards.
"Given his role in REAL ID, Tom Davis would not be a good choice for privacy, which is something that President Obama specifically promised to protect in his remarks on the cyber security strategy," says Jim Harper, the director of information policy studies at the libertarian Cato Institute. "Many cyber security planners refer obliquely to 'authentication' and 'identity management' programs that would devastate privacy, anonymity and civil liberties. Davis would probably work to roll past these issues rather than solve them."
The creation of a federal "identity management" program is one recommendation in the broad cyber security report published by the White House last month, although the report makes no specific proposals on implementing an internet I.D. card.
If picked as cyber security czar, Davis would be given the difficult and sensitive task of coordinating a government-wide strategy to secure the government's computer networks — as well as help secure the wider internet. That's a job fraught with perils ranging from inter-agency disputes over territory, and significant issues about what the government's role should be in improving security on the internet at large.
Davis, who served seven terms representing Virginia's high tech district, was known as an outspoken moderate in an increasingly base-oriented Republican party. He declined to run for re-election in 2008.
In announcing the creation of the new position last month, Obama stressed that privacy was key to the government's cyber security efforts. But Davis' most notable action on privacy was his failed attempt to undo a measure that put a chief privacy officer in every major government agency.
The ACLU's legislative scorecard on Davis shows he disagrees with that group on many privacy matters.
For instance, he voted consistently to give the government wide latitude to wiretap the internet and spy on Americans' communications. That program, including the NSA's massive database of emails known as "Pinwale," made news recently again when The New York Times reported that the NSA examined Americans' domestic e-mails without authority.
That track record would not put Davis out of the running with Obama, who, after winning his party's nomination, embraced expanded government wiretapping powers, and voted to extend retroactive legal immunity to the telecom companies that helped the Bush's administration's secret spying.
Last summer, Davis joined with then-senator Obama, a wide swath of centrist Democrats, to legalize the Bush program, granting the NSA the right to gather billions of communications records of foreigners and Americans, and read Americans' international communications without warrants. The law includes the caveat that if a particular U.S. person is targeted, the government must get court approval.
But Davis could excel in a new role as cyber security czar, says Marc Rotenberg, who heads the Electronic Privacy Information Center.
"He's a good pick," Rotenberg says.
Davis gets things done, supports bipartisanship, and comes from a civilian and industry background, rather than from the shady intelligence world, according to Rotenberg.
"[It's] much easier for a former House chairman to stand up to the Director of National Intelligence and the NSA than some of the other candidates," Rotenberg says.
That will be important going forward. Bush went through a succession of so-called cyber-security czars, who found they were either powerless or stuck in bureaucratic battles they could not win.
But Rotenberg's organization has not always been a fan of Davis.
After 9/11, Davis pushed for changes to open government laws that created an even larger shield for information that private companies gave to the government. Specifically, Davis won protections for companies that run critical infrastructure — such as railroads and chemical plants — allowing them to tell the Department of Homeland Security about dangerous practices without the fear that the public could petition to see the information.
David Sobel, a Freedom of Information Act attorney, testified against that provision in 2002, when he worked for Rotenberg at EPIC.
"We are discussing the desire of private companies to keep secret potentially embarrassing information at a time when the disclosure practices of many in the business world are being scrutinized," Sobel said, referring to the overstated corporate profits that were being discovered in 2002. "If a company is willing to fudge its financial numbers to maintain its stock price, what assurance would we have that it was not hiding behind a 'critical infrastructure' FOIA exemption in order to conceal gross negligence in its maintenance and operation of a chemical plant or a transportation system?"
Davis did not return a call to his office at the consulting firm Deloite.
A White House spokesman declined to comment on Davis, saying only that "no decision has been made yet, so any reporting of anyone being offered the job is not accurate."
Saturday, June 20, 2009
Is Tom Davis Too Qualified to be Cyber Czar? (The Public Eye)
Is Tom Davis Too Qualified to be Cyber Czar?
A story posted on Time's website Friday says the moderate Republican from northern Virginia has emerged as a leading candidate for a job Obama describes as cybersecurity coordinator. White House sources quoted by Time who say the administration feels a Washington power player would make a better candidate than a tech guru. "They want someone who understands technology issues, but more importantly, knows how to get things done in Washington," says a cybersecurity expert who has been consulted by the White House. "There are very few people who have that combination of skills, and Davis is at the top of that short list."
| | There are very few people who have that combination of skills, and Davis is at the top of that short list. |
But unless Obama boosts the cybersecurity adviser's job on the White House organizational chart a few notches to guarantee greater, direct access to the president, would someone of Davis' stature accept the job? So far, Obama has characterized the post as a cybersecurity coordinator, and coordinator doesn't sound very much like an influential of a role.
In an interview with GovInfoSecurity.com earlier this year, before Obama outlined his cybersecurity agenda in late May, Davis saw the need for the government to spend heavily on IT security, and expressed disappointment that no money was earmarked for cybersecurity in Obama's stimulus package. Davis said:
You are competing for dollars and priorities at this point ... but you know, at this point, we are not where we need to be and I think everybody understands that.
Davis sees the power of the buck in getting things done, and says Congressional appropriation process is a good vehicle to get federal agencies to improve federal IT security.
You have got to get the appropriators involved in this or I think otherwise there is no and you have got to make sure that this comes down from the top from the president that this is a priority. I get the feeling sometimes that everybody is hoping this won't happen on their shift. They are not getting additional dollars in any of these cases, they try to secure your networks but without any additional money they have a lot of other missions that they are trying to accomplish and you get no credit for doing anything here. It doesn't help you accomplish your mission, and you are trying to make sure you don't get a cyber attack, but you don't get any credit if an attack doesn't come whether you put FISMA or not and you are just taking the chance that it doesn't hit on your watch. Now, though, we are getting more and more penetrations and I think people are starting to get worried.
And, here's how Davis describes the government's current cyber defense stature:
It is still very stovepipe and we are going to have some cyber attack somewhere and there are going to be some damages done and at that point people are going to what to know what have you done about it. A lot of us have been screaming about this for years, Republicans and Democrats, but at the end of the day you can't legislate this stuff because it comes from the executive branch. Hopefully, after they have finished their study at this point they will put some money behind this. That is our goal and that is the hope.
Besides Davis, others mentioned as the potential White House cybersecurity adviser, according to Time and others:
- Melissa Hathaway, who led the administration's 60-day cybersecurity review and former cybersecurity advisor to President Bush (read our profile on Hathaway).
- Fred Kramer, assistant defense secretary for international security affairs under President Clinton;
- Howard Schmidt, a onetime Microsoft chief security advisor and former adviser to Bush on cyberspace security and protection of critical infrastructure (read BankInfoSecurity.com's interview with Schmidt on the war on cyber crime)
- Paul Kurtz, an Obama advisor who served in the National Security Council under Bush and Clinton (read/listen to our interview with Kurtz);
- Susan Landeau, a Sun Microsystems's distinguished engineer with cybersecurity and public policy expertise;
- Maureen Bainski, a former FBI intelligence leader; and
- Scott Charney, head of Microsoft's cybersecurity division.
Wednesday, June 17, 2009
Hathaway: National cyber incident response plan coming by year end (FCW)
Hathaway: National cyber incident response plan coming by year end
Hathaway also confirms she's in running for White House cybersecurity coordinator
- By William Jackson
- Jun 16, 2009
The Cyberspace Policy Review released by the White House last month was only the beginning of an effort being driven by President Barack Obama to reshape and strengthen the nation's cybersecurity, according to Melissa Hathaway, who headed up the review.
Hathaway, acting senior director for cyberspace for the National and Economic Security Councils, said today her team plans to produce a comprehensive national incident response plan by the end of the year that will guide response to the cyber equivalent of a major natural disaster. The team also will be working to unravel the overlapping and sometimes contradictory laws and regulations identified in the study that get in the way of effective cooperation and responses to cyber threats.
"You can expect a dialog on this issue with the private sector," Hathaway said at the Symantec Government Symposium in Washington. "You will also see us working with Congress because many issues will require a legislative fix."
As a result of the Cyberspace Policy Review, Obama announced last month the creation of a White House office of cyberspace coordinator, who will oversee government cybersecurity policy.
Hathaway on June 12 told Federal Computer Week, that she is a candidate for the White House cybersecurity coordinator position. According to Hathaway, officials hope to select a cybersecurity coordinator in the coming weeks, but no definite date had been set.
"In the coming weeks there will be an announcement of a cyberspace coordinator," Hathaway said. She said the president is personally engaged in the selection, which should be made soon.
The efforts reflect what Hathaway called an '"unprecedented level" of presidential leadership in cybersecurity. It is being established as one of Obama's management priorities, which means performance metrics are being established that will make department heads, not just chief information officers, accountable for their agencies' security posture.
Hathaway illustrated the scope of the cybersecurity issue with a familiar litany of challenges. The Internet and its associated information infrastructure now underpin much of the global economy and are essential to continued economic growth. However, it has expanded in scope and functionality at a pace that has outstripped efforts to secure it.
"It is not secure enough nor is it resilient enough to be move us forward," she said. "We are faced with a dangerous combination of known and unknown vulnerabilities."
The infrastructure is being challenged and attacked not by amateurs, but by professional criminals and spies backed with substantial resources.
There are no coordinated plans for protecting the critical infrastructure or responding to incidents, either by government or the private sector, she said. At the same time, three of the most important initiatives in moving the nation's economy ahead — building out universal broadband networks, a smart energy grid and electronic health records — are all threatened by these vulnerabilities and exploits.
"These are some of the things that keep the president up at night," Hathaway said.
The incident response plan will be vetted by the Homeland Security Department and private industry, and Hathaway said a wiki might be established to allow the private sector to collaborate in its development.
Difficult issues of liability and confidentiality will have to be resolved to enable the kind of pubic/private partnership that everyone agrees is necessary to improve cybersecurity. "We can no longer talk about a public-private partnership, but need to act on it," she said.
Greater international cooperation also is needed, and achieving this will require establishing common standards of behavior in cyberspace. Norms need to be established for defining criminal activity, warfare and terrorism, so that appropriate responses can be agreed upon, she said.
And to achieve all of this, a greater pool of manpower and expertise is required. Educational efforts must be extended past universities into primary and secondary schools to provide an adequate flow to the pipeline.
Tuesday, June 16, 2009
Lawmakers fear White House cybersecurity czar would undercut DHS role (Computerworld)
Lawmakers fear White House cybersecurity czar would undercut DHS role
Computerworld - Some lawmakers are questioning President Barack Obama's plan to appoint a White House cybersecurity coordinator, fearing that the new post will dilute the role of the U.S. Department of Homeland Security.
The misgivings were expressed during a U.S. Senate confirmation hearing held earlier this month for Rand Beers, the president's nominee for the post of undersecretary of the DHS's National Protection and Programs Directorate, just days after the Obama announcement.
Sen. Joseph Lieberman (I-Conn.), who chairs the Senate Committee on Homeland Security and Governmental Affairs, said he fears that a new cybersecurity czar will "undercut the role of the DHS."
"To me, it's not just turf. It's a very critical element of homeland security," Lieberman said.
Sen. Susan Collins (R-Maine), a ranking member of the committee, added that concentrating power in the White House could make oversight more difficult -- because DHS officials are more likely to appear before the committee when asked.
"[I have a] lot of reservations about the establishment of a White House cybersecurity czar," she said.
Obama told reporters at a press conference announcing the move that the as-yet-unnamed coordinator will be responsible for "orchestrating and integrating" all cybersecurity policies for the government.
In his testimony before the committee, Beers said the White House position will have no operational authority and will serve a purely coordinating function. There will be "no realignment of roles and mission for the [DHS]," and the department's operational role will not be undercut, he added.
The limits of a cyber czar (FCW)
The limits of a cyber czar
Many of the government's chief security challenges are for agencies to address
- By Alan Paller
- Jun 15, 2009
As President Barack Obama announces plans to appoint a cybersecurity coordinator, cybersecurity continues to challenge agencies in ways that the eventual appointee might find difficult to fight.
Identifying the chief vulnerabilities in federal cybersecurity is easy: incomplete inventories of systems so agencies do not know what computers they are running; insecure configurations; delays of weeks or months in installing patches; a critical shortage of employees with advanced technical skills to do forensics and intrusion detection and code reviews; and custom software with programming errors that provide easy access for attackers. A more complete list is embedded in the report, "Twenty Critical Security Controls," published by the Center for Strategic and International Studies.
Sadly, solving most of the problems falls to individual agencies more than a cyber czar. Agencies would have fixed most problems if they had the means. So the question is: What are the most critical impediments stopping agencies from doing the right things.
Here are three of the biggest.
1. Chief information officers and procurement officials allow systems integrators and software vendors to deliver systems and software with security flaws. When the flaws are discovered, integrators demand more money to fix their errors — more than the cost of the flawed software. The Federal Desktop Core Configuration is not widely implemented because CIOs still have not forced integrators and software vendors to guarantee their software works on FDCC-equipped systems.
2. Federal managers lower standards to not embarrass unqualified people. An example is the Defense Department's failed effort to ensure its security people have certified technical skills to do hands-on security work. Fixing the skills shortage is one of the nation's top priorities. But when DOD discovered that many security people do not have strong hands-on technical skills, officials simply ordered a security certification that avoided the tough technical questions.
The result is that nearly everybody passes, and the nation wastes the opportunity to improve security. Several civilian agencies meet the requirement to provide technical training for their security employees by offering online training, but the agencies do not require the employees to pass tests to prove they have mastered the material or even ensure they take the training. One agency reported privately that no one — not one person — completed the online training. That agency still gave itself full credit for providing technical training to its security people, and its auditors concurred.
3. Auditors measure what is easy to count instead of measuring what is critical to do. The Government Accountability Office has repeatedly told Congress that federal cybersecurity auditors generally do not measure the effectiveness of critical controls. They might measure whether a policy is in place but not whether the policy has been implemented effectively. Why? Because it is easier to count the paper documents than to ensure that effective technical controls are in place.
So what can the cyber czar do? Shine a public light on those anti-security practices, and when those caught in the spotlight complain, give them the White House support they need to do the job right, along with deadlines and consequences. Every person mentioned above — CIOs, training managers and auditors — want to do the right thing. But they have not been given the spine-stiffening top cover they need from the White House. It's time they got it.
About the Author
Alan Paller is the Director of Research for the SANS Institute.
Sunday, June 14, 2009
Hathaway confirms she's a candidate for cyber chief (FCW)
Hathaway confirms she's a candidate for cyber chief
- By Ben Bain
- Jun 12, 2009
Hathaway details cybersecurity review, confirms she's a canditate for cybersecurity coordinator position
Melissa Hathaway, the official that led the Obama administration's 60-day review of cybersecurity policy, confirmed Friday that she is a candidate for the White House cybersecurity coordinator position.
Hathaway said there is a list of candidates -- she wasn't sure how long -- being considered for the position, but that President Barack Obama hadn't yet conducted any interviews. Obama, in a May 29 speech on cybersecurity policy, said he would "personally select" the cybersecurity coordinator. She said officials hoped to have a cybersecurity coordinator selected in the coming weeks, but that no definite date had been set.
Hathaway, who has been serving as the acting senior director for cyberspace on the White House's National Security Council, said that she is interested in the job.
She made the comments while speaking with reporters after an event hosted by the Center for Strategic and International Studies in which she detailed the findings of the administration's review and highlighted areas of future focus.
She also said the administration was reviewing the many cybersecurity-related bills that lawmakers have introduced in recent months and working to put together a comprehensive view of the legislation for Congress.
During her speech she said the administration will make cybersecurity a core management responsibility – on a par with human capital and fiscal management – for heads of executive agencies and departments.
Throughout the speech Hathaway emphasized the importance of privacy and civil liberties concerns as the administration's cybersecurity efforts move forward, saying the goal is to have an official on the national security staff with that responsibility hired in the next few weeks.
Ex-Government Cyber Official, Exec Mulled for Czar Job (Epicenter)
Ex-Government Cyber Official, Exec Mulled for Czar Job
- By Diane Bartz
- June 11, 2009 |
- 2:55 pm
WASHINGTON (Reuters) - Microsoft's security chief and a veteran of Clinton's and Bush's national security teams are leading candidates for cybersecurity czar, a job that needs White House access and clout to protect networks that underpin the U.S. economy.
President Barack Obama promised last month that he would personally decide who would lead the fight against an epidemic of cybercrime and organize a response to any major cyber attack.
A leading candidate for the post is Scott Charney, head of Microsoft's cybersecurity division, who has said he won't take the job, according to a source who had direct knowledge of the matter but was not authorized to discuss it. The source said, however, that Charney would change his mind if pressed.
Charney also led PricewaterhouseCoopers' cybercrime unit and headed the Justice Department's computer crime section.
His main competitor is likely Paul Kurtz, who led Obama's cybersecurity transition team and who worked on the National Security Council under both Bush and Clinton, the source said.
Others under consideration include former Rep. Tom Davis, a moderate Virginia Republican; Sun Microsystems executive Susan Landau; Maureen Baginski, a veteran of the National Security Agency and Federal Bureau of Investigation, and Frank Kramer, an assistant defense secretary under Clinton, the source told Reuters.
Also in the running but less likely to be picked are Melissa Hathaway, who led a cybersecurity review for the president, and James Lewis of the Center for Strategic and International Studies think tank, the source said.
John Thompson, chairman of the board of Symantec Corp, had been under consideration but turned it down, the source said.
The exact responsibilities of the new job remain largely undefined, although the position described in a report by Hathaway's team describes a coordinator who reports to both the National Security Council and the National Economic Council.
Holes in U.S. cybersecurity defenses have allowed major incidents of thefts of identity, money, intellectual property and corporate secrets. In one incident, a bank lost $10 million in cash in a day.
There have also been thefts of sensitive military information and a penetration of the U.S. electrical grid.
Susan Landau, who declined to discuss if she has been short-listed for the job, said she would urge Obama to make it a top-level position, as he promised.
"The job is very important," said Landau. "We have all sorts of different kinds of threats. … What you want is ubiquitous security."
Landau is a Sun Microsystems engineer who has worked on digital rights, privacy and export control.
Lewis, who also declined to discuss on the record whether he was being considered, said the White House must emphasize national security expertise in picking a cybersecurity czar.
"Some guy from industry is going to write a national security strategy? No, they aren't. You don't just pick this up," said Lewis. "You need somebody who knows the national security game, who knows government and who knows about the technology."
Before becoming a senior fellow at CSIS on technology and national security, Lewis worked for the federal government as a foreign service officer with assignments on such disparate topics as global arms sales, encryption and high-tech trade with China.
Lawmakers on Capitol Hill shared Lewis' and Landau's views, said a senate staffer who has been briefed on the issue.
"The president's vision is a heavyweight," said a Senate staffer. "I'm concerned that he or she will get sort of tied up, like Gulliver, tied down by a million different reporting requirements."