SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> No Category

Cybersecurity:  Yes, but…

Cybersecurity: Yes, but…

By:  Richard Bray  On: 31 Oct 2002 For: Channelworld India 

When U.S. President Bush's Critical Infrastructure Protection Board released its National Strategy to Secure Cyberspace on Sept. 18, the word "draft" figured prominently on every page. That's just as well; it's very much an interim document, with con-sultations and consensus building far from complete.

As a foundation for further work, the document - available at www.whitehouse.gov/pcipb - does well. Some truths, however obvious, were clearly and honestly articulated. For example, the document points out that "by 2002, our economy and national security are fully dependent upon information technology and the information infrastructure." The Strategy is also forthright in its assessment of cyberthreat, noting that "potential adversaries have the intent," the tools with which to attack, and a good idea of the nation's vulnerabilities, which are "many and well known."

That gives a certain weight to the discussion. However, it also means that any agency presuming to dictate solutions from on high must do a good job of anticipating threats and prescribing effective counter-measures. And nobody is quite ready to do that yet. Instead, the Strategy makes recommendations in many areas, points to existing programs and initiates "discussions" that may or may not lead to action.

In effect, the Strategy concedes that the development of the Internet, and U.S. government and business reliance on it, have far outstripped the ability to safeguard its operations. Until the risk is managed and vulnerabilities reduced, if not eliminated, there will be a markedly diminished return on collective investment in the information infrastructure.

The U.S. government seems eager for fresh thinking, allowing two months for comments on this draft and arranging for more "town hall" meetings like those that have already contributed to the Strategy.

A decentralized approach is the only possible answer to the enormous task of public-private sector collaboration, and the government has already divided it into smaller pieces. Lead agencies around critical infrastructure have been assigned to coordinate cybersecurity with the private sector: The Treasury Department deals with financial institutions and banks, for example, and the Environmental Protection Agency with water, chemical industry and hazardous materials.

Unfortunately, where the Strategy should be factual and persuasive, its foundations seem somewhat insecure. For example, unnamed "surveys" are cited for the otherwise reassuring note that the cost of information security is lower than that of a serious attack.

As well, the Strategy is remarkably good-natured about the hardware and software vulnerabilities that are already rooted deep in the Internet. The real threats to the system are considered to be external and motivated by malice. Weaknesses in the software infrastructure in particular are apparently less the fault of manufacturers who release flawed packages than users who are slow to patch them. The document does point to some future date when software works properly, right out of the box, but fails to prescribe remedies for shoddy code that is embedded deep in the network now and will remain in operation, for years in some cases.


Sign up for our Newsletters












Print |  Views: 622   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Richard Bray Richard Bray is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Unlocking data, locking down access
Unlocking data, locking down accessThe federal government is often seen as a laggard in IT, a bloated bureaucracy that runs well behind the innovations of private industry. But look closely and you'll find programs that are truly groundbreaking.
Ottawa doing a poor job on IT security
Ottawa doing a poor job on IT securityThe Canadian government doesn’t meet its own minimum standards for IT security, Canada’s auditor general said. In a report that pulled no punches, Sheila Fraser dubbed the government’s IT security efforts as “unsatisfactory.” “Two and a half years after revising its Government Security Policy the government has…(yet) to translate its policies and standards into consistent, cost-effective practices that will result in a more secure IT environment.”
HP CTO: Security means chains of trust
HP CTO: Security means chains of trustAs vice-president and chief technology officer of Hewlett-Packard Co., Rich DeMillo is responsible for many things: guiding the company's technology strategies, overseeing the chief technology officer of each HP business unit and security, among other things. Now that HP's acquisition of Compaq Computer Corp. seems to have succeeded, DeMillo sat down with the IDG News Service last week after his keynote speech at the Worcester Polytechnic Institute's Molecular Engineering conference to discuss HP, security and where the two will be going over the next few years.
Federal Government Secure Channel boondoggle finally being made visible
an article by kathryn may of the ottawa citizen exposes the "secure channel" boondoggle. this is the same project that was mentioned in the
Dan’s Security Resource Educational Column, No. 21
process improvement involves constantly revisiting of your management practices and their performance. last year stellar performance may become the baseline this year. new technologies may totally “bypass” traditional ways of doing things, on a dime, and so constant searching for new ways of doi
Dan Swanson: Security leaders
dan’s security resource educational column (#027) 
blog comments powered by Disqus