The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label cybersecurity legislation. Tampilkan semua postingan
Tampilkan postingan dengan label cybersecurity legislation. Tampilkan semua postingan

Senin, 28 November 2011

Rep. Mike Rogers Needs To Re-Think His China Tactics

According to NPR, Rep. Mike Rogers thinks that a piece of legislation is going to help stem the tide of IP theft on the part of foreign states like China. Rep. Rogers deserves credit for recognizing the problem and trying to do something about it, however the solution that he's considering - "naming and shaming" - not only won't work but completely misses the real problem.

The heart of the matter is not that foreign states are stealing U.S. intellectual property. Espionage is the 3rd oldest profession and our reliance upon cyber-space-time has made it easier than ever for agents around the world to not only take what they want but make it look like others are the culprits. The solution doesn't lie in deterrence because deterrence is a laughable concept among sophisticated attackers. While its natural to want to stop the "bad guys" from stealing what is yours, it's also naive to believe that you can do it. You can't stop bad guys from coming in, but you can stop your data from leaving. That's the key to ending China and Russia's relatively free access to U.S. technological secrets.

Don't threaten them. Don't pretend that you can deter them. Don't imagine that you even know which one of them is doing the attacking at any given time. Instead, Rep. Rogers should write legislation that requires U.S. companies to inventory their critical data so that they know where on their network it resides, then implement a set of security controls that monitors the behavior of authorized users and locks that data down when certain norms are violated. The hard truth of the matter is that most companies today don't have a clue about where on their network their critical data resides because they've bought into the old school security model of trying to stop attacks at the perimeter of their network. Until that changes, Rep. Rogers and others like him will just waste more taxpayer money and perpetuate the illusion that the problem is somewhere "out there" and can be stopped with U.S. muscle. 
Add to Cart View detail

Minggu, 15 Mei 2011

The President's Cybersecurity Legislative Proposal Has No Teeth

On May 12, the White House announced its Cybersecurity Legislative Proposal to Capital Hill via a blog post by Cybersecurity Coordinator Howard Schmidt. I reviewed the section on critical infrastructure on my flight back from DC after speaking on this topic at the Cyber Security Strategies Summit. Predictably it's all bark and no bite. To wit:

If the Secretary determines, after conducting such a review, that the covered critical infrastructure is not sufficiently addressing the identified cybersecurity risks, the Secretary may:
(A) enter into discussions, or request another agency with sector-specific expertise to enter into discussions, with the owner or operator of the covered critical infrastructure on ways to improve the cybersecurity plan or the evaluation, which may include the provision of technical assistance;
(B) after discussions permitted in subparagraph (A), issue a public statement that the covered critical infrastructure is not sufficiently addressing the identified cybersecurity risks; and
(C) take such other action as may be determined appropriate by the Secretary;
except that the Secretary shall not, in enforcing the provisions of this Title, issue a shutdown order, require use of a particular measure, or impose fines, civil penalties, or monetary liabilities on the owner or operator of the covered critical infrastructure as a result of such review"
To put this in proper context, imagine that this proposal had to do with any other type of infrastructure: a bridge, an oil pipeline, your house. And let's say that the general contractor for that bridge project doesn't comply with the requirements. What happens then? He could get a stern talking-to (Section A); possibly get some publicity (Section B) which would probably land him a guest spot on Fox news as the little guy standing up to Big Brother's unreasonable demands that make it impossible for him to earn a living; or be subject to some other unidentified action (Section C).

Now here's what cannot happen to the builder of that bridge that you and thousands of others drive across twice a day:

  • He cannot have his project shut down for non-compliance. 
  • He cannot be fined for non-compliance. 
  • He cannot be held financially responsible if the bridge collapses and people are killed or injured. 
  • He cannot, essentially, be told what to do. 

This is clearly a ludicrous scenario for any type of physical infrastructure which is precisely why builders get fined, sued, or arrested and prosecuted if they don't comply with the law. However in the upside down world of "cyber", it's par for the course even when we're speaking about critical infrastructure (telecommunications, energy, financial services, water, and transportation sectors).

Let's move from the example of a bridge to one of a power plant. In the real world, the government regulates the construction of every aspect of a nuclear power plant or a hydro-electric dam except one: the protection of its networks. That's neither rational, nor responsible. The federal government must find a way to bring cyberspace into its existing authorities because if something is truly "critical", compliance cannot be voluntary or somebody doesn't know what "critical" means.
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID