Commentary

Mitch Wagner
Executive Editor, Community  

Common-Sense Cybersecurity Recommendations For Our Next President

Our next president is going to have a big job securing our nation's IT against criminals and foreign enemies. Our data networks are an important part of the national infrastructure -- and therefore tempting military targets -- along with traditional infrastructure such as dams, power plants, factories, and hospitals. Security expert Bruce Schneier has some short, sensible advice for what the next president will need to do.

Our next president is going to have a big job securing our nation's IT against criminals and foreign enemies. Our data networks are an important part of the national infrastructure -- and therefore tempting military targets -- along with traditional infrastructure such as dams, power plants, factories, and hospitals. Security expert Bruce Schneier has some short, sensible advice for what the next president will need to do.Memo to Next President: How To Get Cybersecurity Right

Schneier is chief security technology officer at BT and author of Beyond Fear: Thinking Sensibly About Security in an Uncertain World (Springer; 2003). He blogs at Schneier on Security. He's a rare voice of calm common sense in an industry which thrives on pumping up fear and hysteria.


More Government Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Schneier makes three points:

1) The government is a huge customer of IT products, and that gives the government enormous clout in setting the direction the entire industry goes. The government needs to demand security of its vendors. We "all benefit because they'll include those improvements in the same products and services they sell to the rest of us," Schneier says.

2) "Two, legislate results and not methodologies." For example, a "law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not," Schneier says.

3) "[B]roadly invest in research." Basic research is financially risky, which is why the private sector is cutting back, but it results in important advances. Some basic research looks ridiculous to the average person, but do it anyway, Schneier says.

He's skeptical that the normal legislative process will achieve good security, because security, by its nature, always makes someone angry -- the information brokers, manufacturers of voting machines, and telcos, to name three.

Schneier made his recommendations last month, following both Barack Obama and John McCain describing their visions for cybersecurity. Neither candidate's vision was breathtakingly original for anyone who's been following cybersecurity closely. Obama wants to make cybersecurity a top priority and appoint a cybersecurity czar reporting directly to him, rather than to the Department of Homeland Security. McCain wants to make sure government agencies have interoperable systems on the state, local, and federal levels.

Blogger frankpoole at DailyKos says that the next president should name Schneier as the nation's cybersecurity czar (a position Barack Obama said he would create).

One of the biggest priorities for the next president should be to avoid boondoggles, says Richard Stiennon, founder of Secom Global, a managed security service provider, writing at Network World. "Yes, raise the cybersecurity issue. OK, hire a specialist to advise you, or better yet a bunch of specialists, but, do NOT create huge spending programs. Do NOT create laws and regulations requiring industry to 'be secure.' They just are not needed," he says.

What cybersecurity goals do you think the next president should have? Which candidate has the best cybersecurity platform? Let us know.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links