SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Feds falter on staged cyber crisis exercise

Feds falter on staged cyber crisis exercise

By:  Kathleen Lau  On: 26 Apr 2007 For: Network World Canada Creator
 

A simulated exercise to assess the federal government’s ability to adequately respond to national emergencies has revealed several shortcomings.

A simulated exercise to assess the federal government’s ability to adequately respond to national emergencies has revealed several shortcomings.

An “anti-hacker” exercise dubbed Cyber Storm tests a country’s communications, policy and procedures in the face of cyber attacks. The mock crisis also evaluates how a government responds to emergencies, on its own, as well as in tandem with other countries. Canada, along with the United States, Australia, New Zealand and the United Kingdom, participated in the five-day simulation. It was conducted by the U.S. Department of Homeland Security. While the exercise itself was conducted last February, detailed reports analyzing this country’s response were published by Canada’s Public Safety and Emergency Preparedness Department (PSEPC).

The exercise mimicked a sophisticated cyber attack, which included scenarios, such as a leak of social insurance numbers, an aviation control meltdown and tampering with government Web sites. The PSEPC reports highlighted several weak spots in the federal government’s response. In particular:

• National and international secure communications channels are insufficient;

• Coordination with international counterparts has not been established; and,

• Some officials have trouble accessing secure documents in times of crisis.

In addition, it was noted that the mandate of the National Emergency Response System (NERS) had not yet evolved from concept to reality, despite its creation in 2003. An “all-hazards” response unit, NERS was established to coordinate federal responses to emergencies of national significance. Developed by PSEPC, it is staffed by PSEPC and other federal departments. Highlighting NERS’ lack of progress in these reports is a good thing, sa

id Michelle Warren, senior research analyst with Info-Tech Research Group in London, Ont. “It will really help light the fire under NERS to get them moving. I wish this had come out a little sooner, actually.” Warren said although most people like to think NERS had made more progress, the reality is that government agencies typically move at a slow pace. “Getting an association of that sort mobilized and moving forward can be very time-consuming, given multiple layers and various influencers trying to steer the organization.” A

s a government agency, NERS is not alone in the category of slow-movers, agreed Joe Greene, vice-president of IT security research with analyst firm IDC Canada Ltd. in Toronto.

The same reasons underlie the recent reports of a lack of coordination with international counterparts, he said. “Coordinating any government, let alone several governments, is usually quite difficult, given procedures and red tape.”

He said not only must a government ensure that its actions align with the best interests of its country, it needs to reconcile differences between governments.

Despite this, Greene expects that some progress, at least, should have been made in this area. “Obviously, they’ve got a lot of work to do to get this in the order they want.” Warren doesn’t believe the public has been made aware of the entire review of the Cyber Storm initiative. “When it comes to security, so much happens behind the scenes that the average person is not made privy to,” she said. “I suspect it’s a way for the public to know that [the government] is working on it without giving away too much.”


Sign up for our Newsletters

 












Print |  Views: 789   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Recent Canadian IT Jobs




Related Content

Plan to expand government network monitoring raises privacy flags
Plan to expand government network monitoring raises privacy flagsThe U.S. government's CIO and other federal officials have downplayed privacy concerns related to the expanded monitoring of federal networks that is planned under a multiyear initiative ordered by President Bush to boost cyber security at agencies.
Cyber spies turn governments into targets
Cyber spies turn governments into targetsEspionage is setting up shop on the Internet as governments around the world increasingly use the Web for intelligence gathering, according to McAfee Inc.'s Virtual Criminology Report. Security analysts believe cyber espionage will be one of the biggest threats to governments and national security in 2008 and will spur what analysts are calling a "cyber cold war."
Cyber crisis test sends Feds back to security school
Cyber crisis test sends Feds back to security schoolA simulation exercise to assess the federal government's ability to adequately respond to national emergencies has revealed several shortcomings. An anti-hacker exercise dubbed Cyber Storm tests a country's communications, policies and procedures in the face of cyber attacks.
Dan Swanson: Security leaders
dan’s security resource educational column (#027) 
blog comments powered by Disqus