Bush said to be planning cybersecurity board
Computerworld -
WASHINGTON -- The Bush administration plans to create a board of senior national security officials to oversee the federal government's critical infrastructure protection efforts, effectively eliminating the idea of designating a single cybersecurity "czar," sources said.
The move was said to have been agreed upon during a July 2 meeting with President Bush, who gave National Security Adviser Condoleezza Rice and other officials the green light to prepare a draft executive order setting up a Cybersecurity and Continuity of Operations Board. Sources said the meeting lasted for more than an hour, after initially being scheduled for 20 minutes, and resulted in a proposed plan that's now being circulated for agency comment.
A final version of the order is expected later this year. Sources on Capitol Hill, who asked not to be identified, said the proposed structure eliminates the notion of giving cybersecurity responsibility to one official in favor of appointing a board with representatives from the Defense, State and Commerce Departments, as well as the intelligence community and other agencies.
Richard Clarke, the longtime national coordinator for security, infrastructure protection and counterterrorism at the White House, is seen as the leading contender to be named chairman of the proposed panel. Under the new structure, Clarke would likely give up his coordinator role in favor of exclusive cybersecurity duties, according to the sources.
Ken Watson, director of critical infrastructure protection at Cisco Systems Inc. and president of the private-sector Partnership for Critical Infrastructure Security (PCIS), said the general reaction from corporate officials to the drafted presidential order has been positive.
"No single government agency can do all that's needed [to protect technology infrastructures], especially when that includes liaison with industry, oversight of federal budgets and international cooperation," Watson said. "We [think] that a board headed by a presidential adviser provides the right breadth and emphasis."
Kim Kotlar, an assistant to Rep. Mac Thornberry (R-Texas), said establishing a high-level cybersecurity office would be a good first step in the government's effort to tackle the issue. However, "there are many unanswered questions on how such an organization would work and what its mission would be," she said.
The new plan also leaves open the option of allowing the tenures of the National Infrastructure Assurance Council (NIAC) and the National Security Telecommunications Advisory Committee to expire on Oct. 1, according to sources familiar with the draft order. Just before he left office in January, former President Bill Clinton appointed 21 people, many of them longtime Democratic Party supporters, to the NIAC. Terminating those appointments
Additional Resources


White Papers & Webcasts
Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Beyond PCI Checklists: Securing Cardholder Data with Tripwire's Enhanced File Integrity Monitoring
How do organizations pass their PCI DSS audits yet still suffer security breaches? Paying attention to PCI DSS checklists only partially secures the...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Authentication as a Service by Forrester Research
Authentication-as-a-Service: understand the benefits of two factor authentication and the best ways to implement it....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
