Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Featured Resource
Featured White Paper
SOX contains provisions relating to numerous aspects of corporate transparency. This paper covers the three elements that have the greatest impact on IT: Sections 302, 404 and 409. Learn how Tripwire can help with your SOX compliance initiatives.
Featured Event
An Unprecedented Exploration of Leadership in the Public Service. IPAC's two-day conference explores this critical position in the public service.Featuring Paul Tellier, former Secretary to Cabinet/Clerk of the Privy Council and CEO of Bombardier, Inc.
Featured Book
Much as privacy has been an almost uniquely American concern, technology offers unique new ways of violating personal privacy. Regan (public affairs, George Mason Univ.) examines congressional policy making regarding privacy in three areas: information services (computerized databases), wiretapping, and polygraph
Featured Product Review
The clear winner in our firewall performance tests, the FG500 delivers rock-solid performance and protection from attack. If management features combined with reasonable VPN support and unmatched persistent connection numbers are important to you, this firewall is worth the price...
Sign-Up for
E-Government
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Making haste slowly

Security task force still awaits a blessing
Advertisement

The arguments for a consistent, coordinated approach to IT security are irrefutable. Our society, and the world in which we live, have become increasingly if not irreversibly dependent on uninterrupted computer systems and computer-mediated communication. Not only is information technology in itself critical infrastructure, it is the horizontal foundation for the other critical infrastructure upon which we depend, from law enforcement and first response to medical care, from antiterrorism to road, rail and air transport.

There is nothing easy about IT security. Even the most straightforward collective initiatives can run into trouble. In recent weeks, one such effort was launched, a common naming protocol for computer viruses, only to encounter a storm of criticism – too many big anti-virus vendors are involved; each anti-virus system perceives viruses differently; who will process incoming data, how will threat notifications be released. On the frontlines, far too many Computer Security Incident Response Teams still work in isolation or through bilateral or regional arrangements. Most would probably prefer to belong to a true international detection, alert and response system, but it does not yet exist. One authoritative source estimates that it may still be years away, after almost two decades of tinkering.

It has been 18 months since the federal government released Securing An Open Society: Canada’s National Security Policy. The new policy came with a shopping list for some big-ticket purchases, like $308 million for Marine Security and $100 million for a Real Time Identification Project for fingerprints. Arguably, however, the most important technology item was the least expensive -- $5 million for a Cyber-Security Task Force.

The new body was billed as essential to Canada’s National Security Policy, to fulfill political commitments to better emergency coordination. Bringing together representatives of both public and private sectors, supported by a secretariat within Public Safety and Emergency Preparedness Canada and operating with a high degree of autonomy, the Task Force would assume the development of a “national cyber-security strategy that is representative of government and private sector interests.”

The terms of reference for the Task Force call for a description of the cyber threats Canada might face; an inventory of the country’s critical IT infrastructure; an assessment of our readiness to face attacks and recover from them, and, above all, recommendations for action plans to better protect our cyber assets.

As the Information Technology Association of Canada has pointed out, it is disappointing that, as of this fall, the Task Force had still not been named. Disappointing – but hardly surprising, given the range of threats that the national security apparatus must address, the inevitable distractions of a minority government, and, quite possibly, an extended period of recruitment, negotiation and tuning of the terms of reference.

In fact, the announcement of the Cyber-Security Task Force might have been either too late or too early for other important events, most notably the process leading up to the modernization of the Emergency Preparedness Act. In a consultation paper released in July, Public Safety and Emergency Preparedness Canada (PSEPC) noted that “the existing legislation does not … provide direction for widespread cooperation and information sharing on cyber threats, incidents and protective measures, which are required in our computer-dependent world.”

As well, the current act was written at a time when information gathering, processing and storage took place on a different scale. Most importantly, however, it “does not provide the statutory basis to address threats to Canada’s critical infrastructure and cyber networks.”

Advertisement

To its credit, the federal government has been extremely busy on homeland security, trying to cover a range of issues, each with a valid claim to priority. Agencies with strong core missions can present their cases and receive ministerial support. IT security does not get the attention it deserves because it is diffused throughout government. Twenty years ago, there was no Minister for Typewriter and Telephone Security, because we didn’t need one. Today there is no Minister for Information Technology Security, but we do need one.

There has been progress. PSEPC has established a 24-hour seven-days-a-week Government Operations Centre to coordinate a national emergency response, and within that, the Canadian Cyber Incident Response Centre provides the same kind of coverage and coordination for cyber incidents involving critical infrastructure.

IT security threats have steadily progressed from vandalism to organized crime. There is credible evidence that terrorists or even national governments may launch the next level of attacks. Threats can never be entirely predictable; some attacks may always lie beyond our power to anticipate and avert. But all the administrative structures to coordinate our defensive measures and the technology and talent needed to implement them are under our control. Leadership is the missing variable. It is increasingly likely that the necessary administrative apparatus to prevent and mitigate disasters will only emerge after they have happened. Richard Bray (rbray@itworldcanada.com) is an Ottawa-based freelance journalist specializing in technology and security issues.

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment

Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields


Related Content
Book Reviews

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.
Address IT costs and streamline operations with IBM service request and asset management solutions.