Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Friday, January 23, 2009

US: DHS Secretary Napolitano Issues First in a Series of Action Directives


(From 7th Space)
: On her first official day as Secretary of the Department of Homeland Security (DHS), Janet Napolitano issued five Action Directives, all centered on one of the primary missions of DHS: Protection. In the coming days, Secretary Napolitano will issue other action directives focused on other missions critical to the department: Preparedness, Response, Recovery and Immigration.

The action directives Secretary Napolitano issued today on protection instruct specific offices and agencies to gather information, review existing strategies and programs, and to provide oral and written reports back to her by a time certain. The areas in which today’s action directives were issued are: critical infrastructure protection; risk analysis; state and local intelligence sharing; transportation security; and state, local and tribal integration.

“One of my top priorities is to unify this department and to create a common culture. These action directives are designed to begin a review, evaluation and dialogue between the various functions of this department and me,” said Secretary Napolitano. “I look forward to receiving the information and to working with the offices and agencies involved to make DHS a more effective and a more efficient department.”

Monday, December 29, 2008

US: Getting the Ear of the New President


(Americanbanker.com) If you follow the logic of FBI Director Louis Freeh, a cyber attack against America is inevitable and will feel like another September 11. He compares the current lack of coherent strategy and national will to prevent such an attack to the shoulder-shrugging response Americans had when the USS Cole was nearly sunk in the Yemeni port of Aden in 2000. "Neither the country, nor its leadership on both sides of the aisle, were motivated by this," Freeh lamented in a speech to attendees at the SC World Congress in New York in early December.

Freeh's words preceded Congressmen Jim Langevin (D-RI) and Michael T. McCaul (R-TX), who discussed their advice to president-elect Barack Obama on how to address the daily cyber threats and attacks against the nation's government, military and civilian networks. Langevin and McCaul co-chaired the Commission on Cybersecurity for the 44th Presidency, which spent more than 15 months formulating recommendations. The report has two main takeaways: the president should replace the current hodge-podge approach to cyber security with a new National Office for Cybersecurity, which would be part of the Executive Office of the President; and the government should issue strong, mandatory authentication identities for critical cyber infrastructures such as finance.

The first recommendation seems painfully obvious. Several technologists with strong industry credibility have held a variety of cyber "Czar" posts - Richard ClarkAmit YoranGreg Garcia, and the latest, Rod Beckstrom - to little avail. Creating a National Office of CyberSecurity charged with creating a comprehensive national security strategy might actually accomplish that goal.

As for authentication, the committee gave the FFIEC kudos for promoting stronger authentication for online financial services but wants to extend that effort even further. The report envisions a world where the government issues digital credentials that require in-person proofing - similar to a drivers license - which can then be accepted online by merchants and banks with greater certainty. The challenge is twofold: protecting individual privacy while at the same time preventing commercial interests and the government from requiring overly burdensome authentication, which could violate civil liberties.

Another challenge for cybersecurity experts is that many people are vying for the ear of President-elect Obama. Will the issue of cybersecurity prevail? There were four members of the Obama transition team on the committee, notes Jerry Dixon, a former FBI cybersecurity guru who is now director of analysis at cybersecurity consultancy Team Cymru. "It'd be bad form for them to ignore their own writing, wouldn't it?"

Friday, December 19, 2008

Obama is looking for a Cybersecurity Czar

On Forbes you find now an article about the new Cyber-Security Czar position at the Whitehouse. One of the candidates is Rod Beckstrom, a visionary who strongly believes in Information Sharing and Open Collaboration. Co-Author of the best-selling "the Starfhish and the Spider: the unstoppable power of leaderless organizations, from Al-Qaeda to the Internet", is now head of the National Cyber Security Centre at the Department of Homeland Security, US. 



Monday, December 8, 2008

CSIS presents Obama new Cybersecurity strategy proposal


Today, the Centre for the Strategic and International  Studies of the United States (CSIS) published the report Securing Cyberspace for the 44th Presidency. 

The report is the result of a huge work, led by Jim Lewis (CSIS). Among the various proposals, there is the creation of a National Office for Cyberspace (NOC), by merging the existing National Cyber Security Center (NCSC) and the Joint Inter-Agency Cyber Task Force.

The report also says NOC should secure industrial control systems (SCADA), such as those used by Critical Infrastructure, Power and manufacturing plants, by developing regulations they would be forced to follow. 

Here is a summary of the recommendations: 
  1. Create a comprehensive national security strategy for cyberspace
  2. Lead from the Whitehouse: with the creation of a new office for cyberspace in the Executive Office of the President
  3. Reinvent the Public-Private Partnerships: focus on Trust and on operational activities
  4. Regulate Cyberspace: voluntary action is not enough!
  5. Authenticate digital Identities
  6. Modernize Authorities (and law)
  7. Use acquisition policies to improve security: buy security products only
  8. Build Capabilities: research, training and education
  9. Do not start over: Comprehensive National Cybersecurity Initiative (CNCI - Bush administration), is a good starting point

Some additional articles on the same subject: 
Financial Times: US warned over cyber attacks

Saturday, August 9, 2008

Eight homeland security bills make it through House

WashingtonTechnology: The House passed eight homeland security measures today that, among other measures, are designed to strengthen cyber security, promote greater sharing of unclassified information and prevent the over-classification of information. Rep. Bennie G. Thompson (D-MS), Chairman of the Committee on Homeland Security praised measures.
“Passage of these vital measures improves the nation's information sharing capacity, increases privacy protections at the department and further strengthens both our cyber and port security," said Thompson.
Following is a summary of the measures passed by the House: H.R. 3815 - Homeland Security Open Source Information Enhancement Act of 2008 - Sponsored by Rep. Perlmutter (D-CO), this bill requires the Secretary of Homeland Security to make use of open source information to develop and disseminate open source homeland security information products.
H.R. 4806 - Reducing Over-Classification Act of 2008 - Sponsored by Rep. Harman (D-CA), this bill requires the Secretary of Homeland Security to develop a strategy to prevent the over-classification of information and to promote the sharing of unclassified information.
H.R. 6193 - Improving Public Access to Documents Act of 2008 - Sponsored by Rep. Harman (D-CA), this bill requires the Secretary of Homeland Security to promote the implementation of the Controlled Unclassified Information Framework applicable to relevant unclassified information.
H.R. 6098 - Personnel Reimbursement for Intelligence Cooperation and Enhancement of Homeland Security Act - Sponsored by Rep. Reichert (R-WA), this bill ensures that homeland security grants can be applied to retain and acquire intelligence analysts to work in Fusion Centers and engage in information sharing.
H.R. 5170 - Department of Homeland Security Component Privacy Officer Act of 2008 - Sponsored by Rep. Carney (D-PA), this bill provides for a privacy official within each component of the Department of Homeland Security.
H.R. 5983 - Homeland Security Network Defense and Accountability Act of 2008 - Sponsored by Rep. Langevin (D-RI), this measure seeks to enhance information security within DHS by establishing authorities, qualifications, security practices for the Chief Information Officer, creating testing protocols to reduce network vulnerabilities and requiring the examination of contractor security policies.
H.R. 5531 - Next Generation Radiation Screening Act of 2008 - Sponsored by Rep. King (R-NY), this measure clarifies the criteria for certification relating to advanced spectroscopic portal monitors and authorizes the “Secure Our Cities” nuclear detection pilot at $40 million.
H.R. 2490 - Sponsored by Rep. Bilirakis (R-FL), this bill authorizes a successful pilot program that the Coast Guard has been conducting for the mobile biometric identification in the maritime environment of individuals interdicted at sea.

Monday, July 28, 2008

WSJ: U.S. Fears Threat of Cyberspying at Olympics

WASHINGTON -- A debate is brewing in the U.S. government over whether to publicly warn businesspeople and other travelers heading to the Beijing Olympics about the dangers posed by Chinese computer hackers.

According to government officials and security consultants, U.S. intelligence agencies are worried about the potential threat to U.S. laptops and cellphones. But others, including the State and Commerce departments and some companies, are trying to quiet the issue for fear of offending the Chinese, these people say.
Barack Obama became the first major presidential candidate to propose new cybersecurity policies Wednesday when he unveiled his cybersecurity strategy, which includes combating corporate espionage, shielding the country's Internet infrastructure and establishing a national cybersecurity adviser.
U.S. intelligence and security officials are concerned by the frequency with which spies in China and other countries are targeting traveling U.S. corporate and government officials. The Department of Homeland Security issued a warning last month to certain government and private-sector officials stating that business and government travelers' electronic devices are often targeted by foreign governments. The warning wasn't available to the public. [...]

Sunday, July 20, 2008

US: Sensors could plug leak in nation's infrastructure

Metro: Remember the water main break in March that opened a crater the size of a basketball court in Public Square? What if the pipe itself had been able to alert engineers ahead of time that its walls were thinning and in danger of rupture?
And the warped, rusted steel plates on the Inner Belt Bridge that required emergency repairs this winter after previous inspections missed the deterioration - could such parts send a warning signal when they first start to go bad?
Federal officials think a web of tiny, permanently embedded sensors might someday safeguard the nation's "critical infrastructure" of roads, bridges and water pipes, providing round-the-clock checks of vulnerable components and potentially saving money and lives.
But not without a major leap in technology.
So they're offering companies, universities and labs millions of dollars in research funds to goose the sluggish pace of sensor development.
The new program -- which could tap the sensing and micro-electronics expertise of Case Western Reserve University and other local groups -- aims to create advanced monitoring gear for inspectors who now must heavily rely on their eyes and ears to detect problems.

Tuesday, July 15, 2008

Energy "Cyber Security: Are We Doing Enough"

http://uaelp.pennnet.com/display_article/330162/34/ARTCL/none/none/1/Cyber-Security:-Are-We-Doing-Enough?/

We can’t afford to live in a virtual world when it comes to cyber attacks on our electric grid—this pain would be real. A disruption of our critical infrastructure would be life threatening and could cripple our economy.
U.S. utilities know this and are working around the clock to ensure the safety of their networks and systems. Yes, the electric power system is vulnerable but with constant vigilance and sound cyber security policies we can protect the grid—we just have to be sure we are doing enough.

Last year, the number of cyber attacks on utilities per day almost doubled, according to SecureWorks, a managed security services provider to more than 1,800 clients, including 100 utilities. From January through April 2007, the company blocked an average of 49 attackers per utility client per day, while from May through September of that year, it saw an average of 93 unique hackers attempting attacks on each of its utility clients per day.

Monday, June 30, 2008

US - DHS says 7,000 sites at 'high risk' of terrorist attack

Agency says 7,000 sites at 'high risk' of terrorist attack - CNN.com
WASHINGTON (CNN) -- More than 7,000 facilities, from chemical plants to colleges, have been designated "high-risk" sites for potential terrorist attacks, according to the Department of Homeland Security.
Experts long have worried that U.S. industrial facilities could be used as terrorist weapons.
Next week, the department will send letters to the facilities notifying them that they present the highest potential consequences in the event of a successful terrorist attack, said Robert Stephan, the agency's assistant secretary for infrastructure protection.
The facilities include chemical plants, hospitals, colleges and universities, oil and natural gas production and storage sites, and food and agricultural processing and distribution centers, Stephan said.
The names of the sites will not be released to the public.
The department compiled the list after reviewing information submitted by 32,000 facilities nationwide. It considered factors such as proximity to population centers, the volatility of chemicals on site and how the chemicals are stored and handled.
Experts long have worried that terrorists could attack chemical facilities near large cities, in essence turning them into large bombs. Experts say it is a hallmark of al Qaeda, in particular, to leverage a target nation's technological or industrial strength against it, as terrorists did in the September 11 terrorist attacks

Thursday, June 26, 2008

US: A National Fusion Centre Network

A National Fusion Center Network
The Department and states have made a lot of progress in making the State and Local Fusion Center Program -- a key provision of the 9/11 Commission Implementation Act -- a success in the last three years. Now we are committed to building on that success by supporting the implementation of a National Fusion Center Network.What do I mean by that? Working with our colleagues in the Department of Justice, Office of the Director of National Intelligence, Federal Bureau of Investigation and the Program Manager-Information Sharing Environment, the National Fusion Center Network strategy will connect more than 50 state and major city fusion centers and the federal government in a partnership to protect America.I envision a community of state, local and federal intelligence and law enforcement professionals working together – supported by appropriate tools – to achieve a common goal: protection of the nation.These men and women would leverage federal as well as state and local networks; move relevant information and intelligence quickly; and enable rapid analytic and operational judgments. That is what this National Fusion Center Network is all about.Our ability to move, analyze and act on information is our greatest strength. We must use the network and the information in that network to push our defensive perimeter outward. That’s what the National Fusion Center Network will do for us.We in the federal government recognize that state and local authorities have been working at this for years. We, particularly those of us in the Office of Intelligence and Analysis and the rest of the National Intelligence Community, must aggressively support the states in this endeavor and become a committed partner in creating the National Fusion Center Network.That is exactly what we are doing.Intelligence officers equipped with exiting capabilities are helping local authorities as needed and appropriate. In addition, information once only available in cities and states can be shared with the federal government and used to protect the nation as a whole.This is all very new and different for the Intelligence Community. We are working hard to educate ourselves on the information needs of our state, local and tribal partners, as well as increase our ability to provide them information.And we all must do this while paying the utmost respect to the civil liberties and privacy of our citizens.Creating this National Fusion Center Network is a challenging but achievable task. We are doing many things for the first time, and will likely make mistakes. But we will learn from those mistakes, do better, and create what the country should have had before 9/11.Charlie Allen
Under Secretary for Intelligence & Analysis
Published by the U.S. Department of Homeland Security Washington, D.C.

Tuesday, June 24, 2008

National Information Exchange Model

One of my favourit topics is Information Sharing and you find many articles in my blog about it. In US, to address the Homeland Security Presidential Directive HSPD-5 on Information Sharing, a partnership between US DOK and DHS launched the National Information Echange Model (NIEM) Initiative.
Below you find the links to their website, together with the link to an introductory presentation. Enjoy

Presentation: http://www.niem.gov/ppt/Chicago_EB_082007_FINAL.pdf

Website: www.niem.gov

Friday, June 13, 2008

Hezbollah Has Hacking Chops - Security Blog - InformationWeek

Hezbollah Has Hacking Chops - Security Blog - InformationWeek: "
Michael Chertoff, Homeland Security secretary, recently stated that Hezbollah is the greatest threat to U.S. national security. And Western intelligence agencies are increasingly taking the organization's cyberattack skills more seriously. What do you think their targets would be?
The topic of cyberwarfare reared its head again in this DefenseTech.org post. There's been talk about cyberwar for quite some time. Kevin Coleman writes that a 2002 CIA report noted that several groups were beginning to plan attacks on Western networks. I wrote this cover story about cyberwarfare on the eve of the Iraqi war."

Wednesday, June 11, 2008

DHS moves ahead on info sharing network

DHS moves ahead on info sharing network:
The Homeland Security Department plans to pay General Dynamics One Source at least $18 million to upgrade its Homeland Security Information Network (HSIN), which shares sensitive but unclassified data among federal, state, local and private sector organizations.The HSIN Next Generation (NextGen) will be a secure and trusted national platform for information management, collaboration capabilities and search services with enhanced capabilities, DHS said in a statement. The department also said the upgraded network will help users meet their collaboration and information-sharing needs.DHS’ plans to consolidate the more than 100 aging Web portals on the legacy HSIN into the new enterprise collaboration Web portal.

Saturday, June 7, 2008

DHS: Remarks by Homeland Security Secretary Michael Chertoff at the 2008 S&T Stakeholders Conference East

DHS: Remarks by Homeland Security Secretary Michael Chertoff at the 2008 S&T Stakeholders Conference East: Secretarty Chertoff: Jay, thank you for that introduction. Let me thank the National Defense Industry Association and our own Science and Technology Directorate for their roles in making this year’s conference possible. I appreciate the opportunity to speak to you about the increasingly prominent role that science and technology play in homeland security in a post-9/11 world. When I spoke to you last year, I summarized our progress in applying science and technology to the protection of our country, and this year I’d like to update you further on what we’ve been doing to continue to make this kind of progress as we move forward.
What I want to do is provide you with this update in the context of the five major goals that we have laid out for the Department of Homeland Security: protecting our country from dangerous people; protecting our country from dangerous things; securing the nation’s critical infrastructure; strengthening our emergency preparedness and response; and ensuring that the department continues to become a fully integrated single entity driven by an overall critical mission." [...]

Thursday, May 22, 2008

Critical infrastructure central to cyber threat

Critical infrastructure central to cyber threat: "Critical infrastructure central to cyber threat
The United States is increasingly vulnerable to cyberattacks that could have catastrophic effects on critical physical infrastructure, and severely damage the country’s economic, military and strategic interests, cybersecurity specialists said today.

The conventional strategic thinking that has driven defense efforts over the past century is becoming irrelevant in today’s networked world, according to specialists from the U.S. Cyber Consequences Unit (US-CCU), who spoke at the GovSec, U.S. Law and Ready Conference and Exposition today in Washington.
[...]
Borg said the distinction between physical and information attacks is disappearing, and he cited the lasting effects the terrorist attacks of 2001 had on the information technology infrastructure. Borg said Industrial-era distinctions between the local and the remote, personal and public communications, and military and economic targets are fading and very sophisticated cyberattacks could damage major nations. Scalable cyberattacks could physically destroy large numbers of electricity generators that would take years to replace, Borg said, adding that if a sizable region’s electricity was shut down for an extended period, a majority of that economy would shut down and people likely would die. Security experts worry that last spring’s denial-of-service attacks on facilities in Estonia may be a precursor. Developed countries are considered to be most susceptible to the threats.“Looking at the many wake-up calls that the international community has had over the past decade…I would say that we have entered an era of cyberterror and perhaps even an era of cyberwar,” said Lauri Almann, Estonia’s Permanent Undersecretary of Defence, at the conference.Also, cybersecurity specialists warned that a cyberattack could cause greater economic and physical damage than the United States has suffered.“We are talking about things much bigger than the Great Depression,” said Borg. “We are talking about consequences that are only exceeded by use of nuclear weapons.” His colleague at US-CCU, John Bumgarner, said attacks that could cripple an entire industry can be carried out by a handful of knowledgeable people. The specialists said the primary target of cyberattacks presently is business information that has been consolidated in a company’s information system. This can allow thieves to open a new factory with the exact specifications and settings it took the business they victimized years to perfect. [...]

Congress Alarmed At Cyber-Vulnerability Of Power Grid - Forbes.com

Congress Alarmed At Cyber-Vulnerability Of Power Grid - Forbes.com: "Congress Alarmed At Cyber-Vulnerability Of Power Grid
[...]
"I think we could search far and wide and not find a more disorganized response to a national security issue of this import," said Rep. James Langevin (D-R.I.), chairman of the Subcommittee on Emerging Threats, Cybersecurity and Science and Technology. He pointed a finger to several groups: the DHS for giving scanty details of its video-taped simulation; the power industry for working too slowly to mitigate the threat; and the North American Electric Reliability Corporation, an industry group, for failing in its role as the self-regulatory body assigned to ensure a consistent national power supply. "Everything about the way this vulnerability was handled … leaves me with little confidence that we're ready or willing to deal with the cyber security threat," he said.
The House's criticisms focused primarily on the electric utility industry group, NERC. They argued that the advisories issued by NERC are ineffective and that it has repeatedly misled the House in its investigation of the Aurora vulnerability.

Friday, May 16, 2008

DHS | National Infrastructure Protection Plan

DHS National Infrastructure Protection Plan

At the SARMA conference (Arlington VA 13-15 May 2008), the Honorable Joel. B. Bagnal, deputy Assistant to the president for Homeland Security, announced that soon DHS will release an updated version of the National Infrastructure Protection Plan.

In the mean time, here is the link to the actual version, published in 2006.