Showing posts with label Protecting Cyberspace as a National Asset Act of 2010. Show all posts
Showing posts with label Protecting Cyberspace as a National Asset Act of 2010. Show all posts

Saturday, July 16, 2011

Pentagon Declares the Internet a Domain of War

Thursday, July 14, 2011 by The Hill (Washington, DC)
by John T. Bennett

The Pentagon released a long-promised cybersecurity plan Thursday that declares the Internet a domain of war.

The plan notably does not spell out how the U.S. military would use the Web for offensive strikes.

The Defense Department’s first-ever plan for cyberspace calls on the DoD to expand its ability to thwart attacks from other nations and groups, beef up its cyber workforce and expand collaboration with the private sector.

Like major corporations and the rest of the federal government, the military “depends on cyberspace to function,” the DoD plan says. The U.S. military uses cyberspace for everything from carrying out military operations to sharing intelligence data internally to managing personnel.

“The department and the nation have vulnerabilities in cyberspace,” the document states. “Our reliance on cyberspace stands in stark contrast to the inadequacy of our cybersecurity.”

Other nations “are working to exploit DoD unclassified and classified networks, and some foreign intelligence organizations have already acquired the capacity to disrupt elements of DoD’s information infrastructure,” the plan states. “Moreover, non-state actors increasingly threaten to penetrate and disrupt DoD networks and systems.”

Groups are capable of this largely because “small-scale technologies” that have “an impact disproportionate to their size” are relatively inexpensive and readily available.

The Pentagon plans to focus heavily on three areas under the new strategy: the theft or exploitation of data; attempts to deny or disrupt access to U.S. military networks; and any attempts to “destroy or degrade networks or connected systems.”

One problem highlighted in the strategy is a baked-in threat: “The majority of information technology products used in the United States are manufactured and assembled overseas.”

DoD laid out a multi-pronged approach to address those issues.

As foreshadowed by Pentagon officials’ comments in recent years, the plan etches in stone that cyberspace is now an “operational domain” for the military, just as land, air, sea and space have been for decades.

“This allows DOD to organize, train and equip for cyberspace” as in those other areas, the plan states. It also noting the 2010 establishment of U.S. Cyber Command to oversee all DOD work in the cyber realm.

The second leg of the plan is to employ new defensive ways of operating in cyberspace, first by enhancing the DoD’s “cyber hygiene.” That term covers ensuring data on military networks remains secure, using the Internet wisely, and designing systems and networks to guard against cyber strikes.

The military will continue its “active cyber defense” approach of “using sensors, software, and intelligence to detect and stop malicious activity before it can affect DOD networks and systems.” It also will look for new “approaches and paradigms” that will include “development and integration … of mobile media and secure cloud computing.”

The plan underscores efforts long underway at the Pentagon to work with other government agencies and the private sector. It also says the Pentagon will continue strong cyber R&D spending, even in a time of declining national security budgets.

Notably, it calls the Department of Homeland Security the lead for “interagency efforts to identify and mitigate cyber vulnerabilities in the nation’s critical infrastructure.” Some experts have warned against DOD overstepping on domestic cyber matters.

The Pentagon also announced a new pilot program with industry designed to encourage companies to “voluntarily [opt] into increased sharing of information about malicious or unauthorized cyber activity.”

The strategy calls for a larger DoD cyber workforce.

One challenge, Pentagon experts say, will be attracting top IT talent because the private sector can pay much larger salaries — especially in times of shrinking Defense budgets. To that end, “DOD will focus on the establishment of dynamic programs to attract talent early,” the plan states.

On IT acquisition, the plan lays out several changes, including: faster delivery of systems; moving to incremental development and upgrading instead of waiting to buy “large, complex systems”; and improved security measures.

Finally, the strategy states an intention to work more closely with “small- and medium-sized business” and “entrepreneurs in Silicon Valley and other U.S. technology innovation hubs.”

Sunday, June 20, 2010

Lieberman, Collins, Carper introduce bill allowing President to Kill Internet

Senators introduce bill that would allow US to disconnect the Internet
By John Byrne
Friday, June 18th, 2010

Sen. Joe Lieberman (I-CT), along with one Republican and Democratic senator, introduced a bill late last week that would allow the President to effectively disconnect the internet by emergency decree.

The Protecting Cyberspace as a National Asset Act would allow the President to disconnect Internet networks and force private websites to comply with broad cybersecurity measures.

Future US presidents would have their Internet "kill switch" powers renewed indefinitely.

The bill was introduced by Lieberman, Sen. Susan Collins (R-ME) and Sen. Tom Carper (D-DE). A parallel bill was drafted last year by Sen. Jay Rockefeller (D-WV) and Sen. Olympia Snowe (R-ME) which would allow the federal government to unilaterally "order the disconnection" of certain websites.

“For all of its ‘user-friendly’ allure, the Internet can also be a dangerous place with electronic pipelines that run directly into everything from our personal bank accounts to key infrastructure to government and industrial secrets," Lieberman said in a release announcing his bill. "Our economic security, national security and public safety are now all at risk from new kinds of enemies -- cyber-warriors, cyber-spies, cyber-terrorists and cyber-criminals.

“The need for this legislation is obvious and urgent,” the Connecticut senator added.

"We cannot afford to wait for a cyber 9/11 before our government realises the importance of protecting our cyber resources," Sen. Collins said.

The bill would give a newly-formed National Center for Cybersecurity and Communications the authority to monitor the "security status" of private websites, ISPs and other net-related business within the U.S. as well as critical internet components in other countries. Companies would be required to take part in "information sharing" with the government and certify to the NCCC that they have implemented approved security measures. Furthermore, any company that "relies on" the internet, telephone system or any other part of the U.S. "information infrastructure" would also be "subject to command" by the NCCC under the proposed new law.
Lieberman's bill would also create a cadre of cybersecurity agencies and order strategy planning with private firms. The legislation is supported by anti-virus giant Symantec.

“The Internet may have started out as a communications oddity some 40 years ago but it is now a necessity of modern life, and sadly one that is under constant attack,” Lieberman added in his release. “It must be secured... The Protecting Cyberspace as a National Asset Act of 2010 is designed to bring together the disjointed efforts of multiple federal agencies and departments to prevent cyber theft, intrusions, and attacks across the federal government and the private sector. The bill would establish a clear organizational structure to lead federal efforts in safeguarding cyber networks. And it would build a public/private partnership to increase the preparedness and resiliency of those private critical infrastructure cyber networks upon which our way of life depends."

Saturday, June 12, 2010

Homeland Security's Cyber Bill Would Codify Executive Emergency Powers

Published on 06-11-2010
The Atlantic

At the beginning of the year, the chances that some sort of cybersecurity legislation would reach the president's desk by the end of 2010 were remote. But as of today, there are a half dozen such bills circulating, and the sense of urgency is there, thanks to a huge and largely unremarked upon public lobbying campaign by the defense industry that may or may not comport with the actual level of threat. I don't mean that as a snide aside; I just don't know how vulnerable we are at this moment.

Today, the Senate Homeland Security and Government Affairs Committee unveils its legislation, which would create a Senate-confirmable cyber director in the executive office of the president and imbue him or her with significant emergency powers.

The Protecting Cyberspace as a National Asset Act of 2010 (PC-NAA) is "designed to bring together the disjointed efforts of multiple federal agencies and departments to prevent cyber theft, intrusions, and attacks across the federal government and the private sector," its chief author, Sen. Joe Lieberman, will say in prepared remarks today. "The bill would establish a clear organizational structure to lead federal efforts in safeguarding cyber networks. And it would build a public/private partnership to increase the preparedness and resiliency of those private critical infrastructure cyber networks upon which our way of life depends."

The bill would create another Senate-confirmable position, the head of a new National Cybersecurity and Communications Center inside the Department of Homeland Security; the new NCCC would be responsible for threat prevention and mitigation. It would develop risk-based standards for infrastructure with industry and oversee their implementation. Private entities whose power plants or grids or systems are considered vulnerable and critical could choose among a menu of standards.

According to a summary of the legislation, the Act would also create a "responsible" framework for giving the executive branch significant emergency power in the event of a major intrusion or threat.

The President must notify Congress in advance about the threat and the emergency measures that will be taken to mitigate it. Any emergency measures imposed must be the least disruptive necessary to respond to the threat. These emergency measures will expire after 30 days unless the President orders an extension. The bill does not authorize any new surveillance authorities, or permit the government to "take over" private networks.

Industry will read this part of the bill very carefully, as will civil libertarians. The White House believes it already has a lot of these powers, although it welcomes Congress's attempt to codify them, but my sense is that the National Security Staff does not want to create any new cyber infrastructure within the already over-burdened executive office of the president, and isn't keen on having the top two cyber positions be Senate confirmable.