The Macrosite for News, Analysis and Opinion about the Future of the Internet
Daniel Castro

Cybersecurity Challenge Calls for Multilevel Plan

Written by Daniel Castro
6/1/2009 6 comments
DISCUSS     Email This

On Friday, May 29, the Obama administration announced the results of the 60-day review on cybersecurity conducted by Melissa Hathaway and laid out new priorities for cybersecurity.

Overall, the report delivers a solid overview of the current challenges and presents next steps for grappling with them. Key portions of this strategy include creating a "Cyber Czar" to oversee national cybersecurity initiatives; public-private partnerships to better share data and resources; efforts to create and retain a skilled cybersecurity work force; and plans to increase public awareness of cybersecurity threats and challenges.

The report's near-term action plan also includes updating the national strategy to secure cyberspace; developing a framework for additional research and development of security technology; and preparing a cybersecurity incident response plan.

The fact that the Obama administration is making this a priority speaks volumes about the growing need to secure our critical infrastructure. With two wars, a growing nuclear threat from North Korea, and a still-struggling economy, the President already has more than enough to keep him busy. But many important policy objectives of this administration rely on digital infrastructure -- from modernizing the healthcare system with electronic medical records to building a "smart" energy grid.

Government leadership is needed to make this happen. But responsibility for cybersecurity should not rest with any single government agency, as it has become an important component across all agencies. In particular, this responsibility should not be usurped by the defense agencies, because the threats are much broader than national security.

In addition, many cybersecurity activities need to remain unclassified for continued innovation and adoption on non-military systems. The Pentagon has already released new plans to build a cyber command center to conduct both offensive and defensive online computer warfare. A national cybersecurity strategy needs to be much broader than this and address the broader economic and consumer issues raised by these online threats.

For example, government needs to work with industry to develop secure systems for electronic medical records; but it needs to work even harder to get healthcare providers to start using those systems and make sure the systems are interoperable. Similarly, the electric grid should be secured from online attacks by foreign adversaries, but the more pressing priorities are to upgrade the transmission and distribution networks to increase their overall performance and reliability.

But the path forward will also require new thinking and new ideas. The past problems with cybersecurity were not simply a lack of sufficient government involvement. Nor will these problems be solved by merely shuffling around the government hierarchy.

Government agencies need to actively partner with the private sector to identify risks and mitigate threats as a necessary component of a national cybersecurity strategy. Private industry controls many of the networks, hardware, and software that make up our national digital infrastructure, and it will continue to be on the frontlines of any efforts to improve cybersecurity.

Government also needs to work with industry to facilitate better data sharing and develop better metrics for risk management. Likewise, citizen engagement and education will similarly be important; otherwise, the weakest link will be the American citizen. While attempts to hack into the electric grid are more likely to show up on the president's daily brief, consumers must contend daily with other cybersecurity threats, such as spam, malware attacks, phishing, and identity theft. Fortunately, the administration seems to recognize the limitations of the federal government working alone and has indicated that it will work closely with the private sector on many of these issues.

At the end of the day, the cybersecurity strategy outlined by the new administration will be just one part of a global effort to make digital infrastructure more secure. Just as global climate change cannot be solved by a single country, neither can one nation solve all of the cybersecurity challenges of this century.

Although it has the opportunity to become a global leader on the issue, the United States will be just one country among many working to address cybersecurity threats. But it does have an important role to play in encouraging innovation, setting standards, and building partnerships with other nations.

One more thing: Words matter, but so do actions. The administration has laid out a bold plan for cybersecurity -- now we will have to wait to see how well it can execute this vision.

— Daniel Castro is a Senior Analyst with the Information Technology and Innovation Foundation (ITIF)

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
lenrosen
Rank: Cave Painter
Wednesday June 3, 2009 7:43:47 PM
no ratings

The best outcome is the level of focus on issues related to the importance of the network and Internet infrastructure and the part it plays in the modern world. It's good to have a President who walks the walk in technology usage, and has a basic understanding of the complexities involved in creating what to so many users seems so transparently simple, such as a Google Search.

Mark Odiorne
Rank: Cyborg
Wednesday June 3, 2009 6:44:03 PM
no ratings

They don't need a czar to dictate from on high, they need a coordinator with a great project management staff. Someone who can speak multiple languages (government, business and 'real world') and "herd cats". Has to be respected by all sides and willing to speak the truth.

A guy can dream, can't he?

Mark Odiorne
Rank: Cyborg
Wednesday June 3, 2009 6:36:58 PM
no ratings

Smart people don't always make smart decisions, they make business decisions. Security is almost always an afterthought, bolted on at the end. Bruce Schneier said it very well when he said that there will always be a struggle between security and "getting the work done" because security often gets in the way of the real business of the organization - and the business side most often will win. Until the pain of poor security outweighs the benefits of ignoring it.

no ratings

I don't know if you read the speech the President gave but he began his remarks with a revelation that during the run up to the election hackers managed to penetrate his computer campaign systems, gaining access to emails, campaign files, policy postion papers and travel plans.

The President stated that the fundraising website was at no time compromised but to deal with the security breaches, the team had to call for assistancefrom the FBI, CIA, Secret Service and a number of private consultants to ensure the security of the system.

When you consider the brain power behind the Obama Campaign's web presence, I found this revelation to be disturbing. If that team couldn't anticipate security problems in their network design, what does that mean for the rest of us?

 

 

Terry Sweeney
IQ Crew
Tuesday June 2, 2009 1:16:23 PM
no ratings

A bevy of names are floating to the surface as potential nominess for the new cybersecurity position that Obama envisions, including:

  • Rear Admiral Robert C. “Willie” Williamson, USN (Ret) who's currently Director, Naval Integration and Transformation at Raytheon
  • Paul B. Kurtz, online and homeland security expert, and served in previous White House positions under both Clinton and Bush.
  • Roger Cressey, founder of Good Harbor Consulting and also a veteran of the Clinton and Bush administrations.
  • Richard A. Clarke, security gadlfy, author, battle-scarred White House staffer
  • And for those at home keeping score, the Department of Homeland Security also finally filled Rod Beckstrom's old job and appointed a few other DHS cybersecurity hands.

    Mary Jander
    Thinkernetter
    Tuesday June 2, 2009 10:12:15 AM
    no ratings

    I'm with the gang who've provided the most responses to our latest poll. I would like to think that the Washington bureaucracy could overcome its insularity and political biases long enough to make this work. On the other hand, they've spoiled other admirable projects and there's no reason to believe they won't dig in on this one.

    At least this move has spurred public attention to the urgency of cybersecurity.

    The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
    previous posts from Daniel Castro
    Daniel Castro
    Daniel Castro   5/26/2009   8 comments
    A recent article in The Washington Post has called into question the role of the private sector in setting standards for electronic health record (EHR) systems. Specifically, the article questions the appropriateness of allowing a group that originally pushed for stimulus funds to now have an oversight role in how those funds are spent.
    5
    of
    Mary E. Shacklett
    DR Should Include User Empowerment

    2|1|12   |   2:59   |   6 comments


    Disaster recovery is about restoring service to users, but when restoration times are protracted, companies should empower users so they have maximum flexibility for dealing with their situations.
    Second Shooter
    Collaboration & Spherical Stupidity

    2|24|10   |   2:12   |   18 comments


    A recent scandal involving a school's use of remotely activated Webcams to locate lost or stolen laptops may portend, not only legal action against the school, but also a loss of trust in video that is critical to developing video collaboration over the Internet.
    Wisdom of the Big Chair
    Integrating Security Into Your Cloud Contract

    3|19|13   |   3:35   |   No comments


    Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
    Second Shooter
    Firefox OS Points to Possible New Directions for Google

    3|4|13   |   2:08   |   6 comments


    A "Chromephone" would allow Google to regain the control it lost from Android.
    Second Shooter
    Terrorists Attack Our Refrigerators!

    2|28|13   |   2:22   |   No comments


    50 billion household devices will be on the Internet by 2020, according to Cisco. And we're hearing foreign governments are hacking our infrastructure. Surely our refrigerators are next!
    Second Shooter
    YouTube Payment Plan Could Get Complicated

    2|4|13   |   2:10   |   5 comments


    YouTube's move to a partial pay-for-view model could help relieve a dearth of good new content but it could also complicate debates in many parts of the world over payment by content providers for delivery of their material to customers.
    Second Shooter
    Google's Larry Page: We Are Living in Uncharted Territory

    1|29|13   |   2:11   |   7 comments


    That's what Larry Page said on Google's earnings call, referring to the conjunction of mobile and the cloud. Well, let's chart it then! We need to be thinking about an Internet where 90% of our traffic goes to 70 destinations within 40 miles of us.
    Wisdom of the Big Chair
    Reaping the Benefits of Software-Defined Networks

    1|28|13   |   2:20   |   No comments


    Software-defined networks, which deliver virtualization functions to enterprise networks, have the potential to dramatically change network design and significantly reduce costs and maintenance.
    Second Shooter
    Europe Considers One Network to Cover them All

    1|17|13   |   1:45   |   12 comments


    EU operators are considering joining up to create a pan-European network to reduce competitive overbuild and cost. This might lower costs and focus operators on higher-level, more interesting services.
    Kim Davis
    Aaron Swartz, RIP

    1|14|13   |   2:36   |   6 comments


    The Internet freedom activist, threatened with jail time, seems to have taken his own life last week.
    IETV: the thinkerNet on film
    5
    of
    John Kennedy
    How Big-Data Is Changing Marketing

    6|13|13   |   1:07   |   1 comment


    Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
    Kim Davis
    Big-Data Can’t Always Sell Wine

    5|21|13   |   2:23   |   10 comments


    Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
    Paul J. Fleuranges
    Digital Signage Keeps NYC Subway Straphangers on Track

    5|6|13   |   3:51   |   1 comment


    New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
    Kim Davis
    Fast Forward to the Future

    4|23|13   |   2:29   |   20 comments


    A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
    Mitch Wagner
    Google Launches Its Most Depressing Service Yet

    4|15|13   |   2:59   |   10 comments


    Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
    Second Shooter
    Argument Over Top-Level Domains Is 'Stupid'

    4|11|13   |   2:07   |   3 comments


    The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
    Kim Davis
    Ladies, Your Tablet Awaits

    3|21|13   |   2:22   |   37 comments


    ePad Femme is the world’s first tablet “made exclusively for women.”
    Wisdom of the Big Chair
    NFC Moves Into the Mainstream

    3|20|13   |   2:16   |   No comments


    While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
    Wisdom of the Big Chair
    Integrating Security Into Your Cloud Contract

    3|19|13   |   3:35   |   No comments


    Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
    Brian Baron
    How Edmunds.com Collects Customer Information

    3|18|13   |   1:15   |   No comments


    Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
    2pm EDT
    Fri
    Jun 21st
    an IBM information resource
    sponsored content
    big blue blog
    Todd Watson
    Todd Watson   6/18/2013   Post a comment
    The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
    an IBM information resource
    sponsored content
    Expert Integrated Systems: Changing the Experience & Economics of IT
    In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

    READ THIS eBOOK
    your weekly update of news, analysis, and
    opinion from Internet Evolution - FREE!

    REGISTER HERE
    Wanted! Site Moderators
    Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

    Please email: moderators@internetevolution.com
    Internet Evolution – not for thickies
    NSA Leaks Shine Spotlight on Perils of Contractor Partnerships
    Jason Mick
    The US National Security Agency learned the
    hard way that it can be dangerous to give a contractor too much money and access, with too little scrutiny. The NSA and other government agencies hire tens of thousands of contractors a year to analyze data. Edward Snowden -- who revealed himself as the NSA leaker after fleeing the country -- was one such contractor, reportedly holding a $122,000 salaried position at Booz Allen Hamilton at the time of his departure.

    CLICK FOR MORE