The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Digital Life

Topics:   Digital Life : Government IT

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

U.S. Fighting Cyber-Spy Threat


Posted by Michael Hickins, Apr 21, 2009 05:08 PM

UPDATED Spies have breached project plans for a vital U.S. fighter jet project and the Air Force's air traffic control system, reports the Wall Street Journal, hot on the heels of an earlier WSJ report detailing infiltration of the U.S. electrical grid by the Chinese and Russian governments.


Fortunately, the U.S. is no longer asleep at the switch, with concurrent efforts under way spearheaded by government and private groups.

UPDATE: The Obama administration plans to create a new military command to coordinate defense of Pentagon computer networks and improve U.S. offensive capabilities in cyberwarfare, according to a Wall Street Journal report.

The initiative will reshape the military's efforts to protect its networks from attacks by hackers, especially those from countries such as China and Russia. The new command will be unveiled within the next few weeks, Pentagon officials said.
And self-regulating organizations like the North American Electric Reliability Corporation (NERC) will no longer be left to their own devices to determine compliance issues. The NERC had been granted authority to self-regulate the electrical grid by the Federal Electricity Regulatory Commission (FERC), but that will soon change.

Edward Markey, the chairman of the House Energy and Commerce Committee Subcommittee on Energy and the Environment, sent a letter to the FERC last week "regarding the escalating cyber breaches threatening to compromise the electricity grid," stating, "If there are holes in the government’s ability to protect the electricity grid from attack I am committed to doing everything necessary to improving FERC’s ability to defend against these threats."

Sean Sherman, senior compliance architect at IT configuration and compliance vendor Tripwire, told me the U.S. is "going to go into a much more intensive regulatory mode as we we try to target these things and frankly, it's probably appropriate." He also tweaked the very idea of self-regulation embodied by the NERC, saying, "The essence of self-regulation is kind of paradoxical, because compliance assumes some kind of oversight, doesn't it?"

At the heart of this issue, a recent survey conducted by the NERC showed that most utilities claim they don't have any critical cyber assets to protect, exempting them from any related compliance burden.

More than 70% of the owners and operators of power generation systems and about 37% of transmission companies said they did not possess any assets at all which met that description. Only 23% of non-affiliated members-which are typically smaller entities-reported they had at least one critical cyber asset.

Talk about self-serving claims.

The federal government isn't alone in its efforts to shore up the security of critical infrastructure and key resources, noted Larry Shattuck, a spokesperson for InfraGard, a public-private partnership including private sector IT security professionals and the FBI.

Shattuck told me in an email that one of the group's principal activities is educating the general public and corporate leaders so they don't become the weakest link in the infrastructure security chain. "These folks repeatedly, time and time again, ignore the threat THEY pose to our country's security when they ignore simple protocol on their own systems," he noted.

InfraGard has been around for almost ten years, and Shattuck says the organization has been able to help avert attacks and solve cyber-crimes more quickly thanks to cooperation between the private sector and the feds. More is needed, as these recent reports have shown. But if you want to join InfraGard, be aware that you'll have to undergo a background check by the FBI.

« Google Gives Users Fractional Control Over Search Results For 'Me' | Main | Windows 7 Starter Edition Is A Non-Starter »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
Digital Life Video

 

  1. Here's to the First Responders!
  2. HPC Joins the Dummy Revolution?
  3. Detecting Scalability Problems With Intel Parallel Universe Portal


Join The InformationWeek Group On LinkedIn


                           


  1. Motorola Droid Is Gadget Of The Year
  2. Windows Mobile 7 Now A Q4 Release
  3. Nexus One Google Phone: Sorting Fact From Fiction
  4. Verizon Wireless Starts Updating The Motorola Droid
  5. 'Nexus One' Is Google's Android Phone For Consumers


  1. Strong Sales May Delay Apple iMacs
  2. EMC Adds VMware Support To Retrospect
  3. Toshiba Boosts Smartphone Storage
  4. SMS Privacy Case Heads To Supreme Court
  5. Microsoft Taps Into Open Government Market
  6. Full Nelson Video: Cisco's 'Health Presence' Showcase

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007