DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech examines the intersection of technology and defense from every angle and provides analysis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • ‘Canes
  • Af-Cam
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the “Buzz”
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Crazy Ivan
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT’s Dust
  • Extra! Extra!
  • Eye on China
  • F-35 Watch
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Bubble with Joe Buff
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar’s Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples’ Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward’z Wonderz
  • You can run…

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » Proposed Cyber Security Legislation

Proposed Cyber Security Legislation

cyber-security.jpg

Amid calls for a comprehensive national strategy on cyber security, as well as stronger government leadership to ensure that security initiatives are implemented effectively, Sen. John D. Rockefeller IV and Sen. Olympia Snowe proposed a sweeping piece of legislation to address this significant and growing threat to the United States. This legislation comes in the wake of attacks on the Pentagon late last year and in the shadow of recent news of massive cyber espionage efforts spanning over 100 countries.

The following represent the major provisions of the proposed legislation at this time. Everyone should expect changes to be made as it works its way through the legislative process.

  1. Legislation proposed by Senator John D. Rockefeller IV and Senator Olympia Snowe calls for the establishment of an Office of the National Cyber Security Advisor that would take the lead on Internet security matters and coordinate with the Defense Department, intelligence community and the private sector.
  2. The proposed legislation calls for the creation of a Cyber Security Advisory Panel that is composed of outside experts from industry, academia, and nonprofit groups that would advise the president on related matters.
  3. The proposed legislation calls for the creation of a public/private clearinghouse for cyber threats and vulnerability information sharing, establishment of measurable and auditable cyber security standards from the National Institute of Standards and Technology.
  4. The proposed legislation would also require that cyber security professionals be licensed and certified.
    Provision: The proposed legislation would also require that the Cyber Security Adviser conduct a review of the U.S. cyber security program every four years and require officials to complete a number of reviews and reports.
  5. The proposed legislation calls for the creation of state and regional cyber security centers to help small and midsize businesses adopt security measures.
  6. The proposed legislation would establish a Secure Products and Services Acquisitions Board that would to review and approve the security and integrity of products purchased by the federal government.
  7. The proposed legislation would require government and private sector networks that control the critical infrastructure to comply with a set of cyber security standards established by the National Institute of Standards and Technology (NIST).

This legislation is past due! Report after report has highlighted the increased complexity and frequency of cyber attacks on business, government and our critical infrastructure. Delays in pushing this legislation through could have serious consequences. So time is of the essence in preparing for the passage and enactment of this legislation.

I offer the following recommendation for consideration in order to strengthen the proposed legislation. The legislation as it stands does not address mandatory reporting requirements of cyber security breaches, data and information theft and other cyber security related issues. If we are to track our progress, learn from these events and rapidly identify new cyber threats, mandatory reporting within 24 hours of discovery is critical. Another area of concern is training. While the proposed legislation touches on training, it does not specifically address continuing education. Cyber attack techniques and criminal scams are highly dynamic and rapidly evolving.

These factors combine to make continuing education necessary to stay aware of the latest developments in cyber security. A third concern rests in the area of testing, validation and verification of hardware and software. While this is not specifically addressed, it may be bundled into support and funding for research and development of new validation and verification capabilities that are needed to mitigate this threat. The visibility of this issue has risen significantly after Alex Allan, Chairman of the British Joint Intelligence Committee, expressed his growing concern because government departments, the intelligence services and the military were all exposed to threats from computer and network hardware that came from foreign (citing the new BT Telecom network).

Finally, I was disappointed the legislation did not address an appointee to coordinate and push for an international accord that establishes open cooperation during investigations of cyber attacks and crime and also to stem the development of strategic cyber weapons.

While the devil is in the details, I think the proposed legislation modified to include the four areas identified above is a huge step in securing our nation against cyber threats. And while the proposed legislation is mainly reactive, proactive measures can go a long way to reducing risks.

– Kevin Coleman

Share |

April 2nd, 2009 | Cyber-warfare | 442510 Comments »http://defensetech.org/2009/04/02/proposed-cyber-security-legislation/Proposed+Cyber+Security+Legislation2009-04-02+17%3A15%3A14Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « HULC-ing Out in Afghanistan | Is NLOS Worth It? » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Kevin says:
    April 2, 2009 at 3:54 pm

    ohwilleke
    GREAT POINT — that supports my recommendation that continuing education is required. Cyber Security Intelligence is the best defense. Knowing something is coming or likely to come give you the ability to reinformce your defenses

    Reply
  2. ohwilleke says:
    April 2, 2009 at 4:36 pm

    Kevin, my point is that many very good cyber security professionals have irregular education and training, and sometimes patchy (even criminal) backgrounds). For example, for at least a decade, the industry pay for computer professionals was so high that many of the best are college dropouts with little or no formal credentialing. Many have never even taken classroom instruction in computer technology, even though others have specialized PhDs in the subject. And, ot is not obvious that the PhDs are the more qualified workers in the field.
    Licensing and certification would exclude many qualified people from the profession, while not necessarily improving standards for those who remain. Licensing and certification requirements presume that government regulators know what a cyber security professional needs to know — but they don’t.
    Indeed, there isn’t even a strong consensus on who really is a cyber security professional. Does that include a small business LAN expert who handles the password protections and firewall for the business? What if the small business is a multi-billion dollar hedge fund? Are ISP managers who supervise computer experts charged with spam control cyber security professionals? Are telephone techs cyber security professionals? What if they do wiretap work for police departments?
    Also, to the extent that one is discussing cyber security professionals working for government contractors, there is already backdoor regulation for “inside job” compromise threats through the established security clearance system, although even this minimal regulation has a negative distortion effect giving undue preference to those who already have security clearances from prior employment, even if they aren’t the most qualified, because of the cost and delay involved.

    Reply
  3. stephen russell says:
    April 2, 2009 at 7:47 pm

    Cut the bureaucracy alone to Fund this
    Combine like agencies etc into 1.
    Place within estd AF CyberCommand.
    Maybe the Cyberspace Panel for the WH.
    But merge the rest, save time & money.
    & expand to US Emb in China alone or Taiwan.
    Prior cyberstrikes came from China.
    We dont need More Govt, we need Less & More Efficent at that esp for DoD.

    Reply
  4. The Cenobyte says:
    April 2, 2009 at 10:44 pm

    I have to agree with Ohwilleke here. A licensed and certified professional in the IT industry usually means someone with a lot of paper from a school somewhere that bascily doesn’t even know a SYN from an ACK. Don’t get me wrong there are lots of guys with lots of paper that know what they are doing, but they either got it cause the business unit wanted to look kewl (That’s me) or got it and then got lots of experense. The paper it self means nothing.
    I know guys that just got their MCSE or A+ and I am not sure they are qualified to work on my helpdesk and these are exams writen by IT companies, do we think the govt. can do a better idea.
    I am not sure I even want the govt. writing rules about what to do and no do. I have found that most times rules just end up just breeding in some new unknown weak point in the system. We use best practices and try to follow them but even they tend to make people think they are rules.

    Reply
  5. Ptsfp says:
    April 3, 2009 at 4:38 pm

    I agree, the training would need to be continuous because the threat is always evolving. Just look at the anti-virus game.
    A virus is written to exploit a hole in the operating system. The operating system is patched, and the anti-virus is updated to look for the threat. The virus is updated to look different, or attack a different hole in the OS. Again, the hole is patched, anti-virus is updated. And on and on…
    It is for all intents and purposes an arms race. The bad guys attack with a new “weapon”, the good guys update their defense and close the holes, the bad guys create something new.
    Most current computer industry training is very linear. They teach you the basics of the OS or software product. They teach you how to use the wizards, or if you have done steps one, two and three, your network should be protected. Many admins do not even go back and recheck servers after they are up and running. They are too busy fighting fires all day.
    The hackers are successful, because they think “out of the box”. They do not follow checklists, or established rules. They have the time to spend to find the hole in your system.
    Those involved in cyber security would need to be as active in upgrading their skill sets as the hackers are. We as a nation need to be in the forefront of this arms race. Staying static in this game will find us falling behind and becomming more of a target.

    Reply
  6. Bradley says:
    April 5, 2009 at 4:00 pm

    Well Mr. Coleman you really made an ass out of Rob Rosenberger of Vmyths !!!! Your were dead on target and he, of course slammed you on his blog. You think he would be professionally enough to say he was wrong. OH, wait a minute — he is not a professional!!! True professionals admit when they are wrong. I have followed your blog for over a year now and I must say you are RIGHT about cyber warfare/terrorism far more than anyone should be who is not on the inside. SO you must be connected. KEEP UP THE GREAT WORK!!!

    Reply
  7. Kevin says:
    April 5, 2009 at 5:22 pm

    Thanks Bradley

    Reply
  8. Thinker 1 says:
    September 4, 2009 at 10:34 am

    We had better be careful with this one. Giving control of the internet to our government puts us in the same league as Iran and N. Korea. Let’s not forget how Iran used that control after their last election.

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

NOTE: Comments are limited to 2500 characters and spaces.

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Recent Articles
    • JSF Price Tag Jumps to $135 Million
    • EADS Tanker, Not Dead Yet
    • JFCOM’s Mattis Pushes Light IW Aircraft
    • And, the Vertical Landing
    • NLOS-LS Missile Fail Could Impact Navy’s LCS
    • JFCOM’s JOE Whacks Defense Industry
    • New F-35B Hover Video
    • China’s Shipbuilding in a Regional Context
    • Debating the Pros and Cons of LCS
    • Bigger, Badder IEDs in Afghanistan
    Recent Comments
    • JSF Price Tag Jumps to $135 Million
      'Nor really stealthy'? LOL! – Only in...
      SMSgt Mac
    • Army Fast Tracks GPS Mortar Round
      That is not a 120mm mortar please check it out. My was 11C...
      Jim
    • JSF Price Tag Jumps to $135 Million
      With the exception of his Boeing Tanker blindspot ;-) ...
      SMSgt Mac
    • Bigger, Badder IEDs in Afghanistan
      i heard recently that rules of engagement in...
      mad mike
    • Army Fast Tracks GPS Mortar Round
      Would I be correct in assuming that means a noise or...
      bduff509
    • JSF Price Tag Jumps to $135 Million
      RE: But their advantage is reduced by daytime...
      SMSgt Mac
    • JSF Price Tag Jumps to $135 Million
      And to get back on topic…Don’t think...
      SMSgt Mac
    • JSF Price Tag Jumps to $135 Million
      RE: "shown your contempt for every service...
      SMSgt Mac
    • JSF Price Tag Jumps to $135 Million
      135,000,000 $ each for a fighter aircraft that's...
      Joseph
    • JSF Price Tag Jumps to $135 Million
      Dumb and dumber………. The F35 is a...
      blackbull
  • Channels:Military.com | Military Benefits | Military News | Off Duty |Join the Military | Military Education | Veteran Jobs | Military Money |Military Deals | Military Family | Military Community
  • Military.com Network:Military.com | MilBlogging | Defense Tech | DoD Buzz |SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps |Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program |Monster Network | Help | Feedback | Privacy Policy |User Agreement| © 2010 Military Advantage