At Senate hearing, cyberterrorism fears on the rise
Computerworld -
With every passing day and with every new network installed, the U.S. becomes more vulnerable to terrorist activity online, federal officials said this week.
Since Sept. 11, national security officials have redoubled their efforts to find ways to better protect the nation's telecommunications and electric power grids, financial institutions, oil, gas and water systems, and transportation and emergency services, all of which constitute what is known as critical infrastructure.
There's a "new urgency" in Washington to find ways to protect critical infrastructure from future attacks, said Sen. Joseph I. Lieberman (D-Conn.), chairman of the Senate Governmental Affairs Committee. At a hearing on information-sharing efforts between the government and the private sector, which owns and operates 90% of the nation's critical infrastructure, Lieberman characterized these private systems as "our nation's vital organs" and echoed concerns that if the nation doesn't act now, it could find itself trying to recover from another massive terrorist attack.
Sen. Robert Bennett (R-Utah) introduced a bill that would foster more information-sharing about cybervulnerabilities by exempting private-sector data from inadvertent disclosure under the Freedom of Information Act. He also said "the future battlefield is in private, not public hands." Bennett cited a quote attributed to terrorist leader Osama bin Laden instructing his followers to "concentrate on hitting the U.S. economy."
However, John Malcolm, head of the U.S. Justice Department's Criminal Division, took the cyberterrorism threat a step further, warning lawmakers about the potential links between physical attacks and those in cyberspace. "A vulnerability in the [Federal Aviation Administration] control system could allow a hacker to crash an airplane," said Malcom. "That example is not entirely hypothetical."
Meanwhile, no mention was made during the hearing of that opinion of some prominent terrorism experts who fear that the U.S. may be wasting vital resources by focusing too heavily on a threat that isn't imminent.
For example, Eric Shaw, a former CIA profiler and a clinical psychologist who now works as a cybercrime specialist at New York-based Stroz Associates LLC, fears that the government's electronic "Pearl Harbor" rhetoric is generated by outdated approaches to threat assessment and by political goals.
"When threat assessment is based on all possible scenarios or mirror-imaging [what one party would or could do if roles were reversed] the threat is often misconstrued or exaggerated," said Shaw. "Considering all possible threats is a nice, creative process, but there is little evidence to suggest its practical benefit, other than funding of security-related projects that may not be needed."
In addition, Vince Cannistraro, the former chief of counterintelligence at the CIA, in recent interviews with Computerworld has acknowledged that there is little evidence to suggest that terrorists value the outcome of cyberattacks. "They're not bloody," said Cannistraro.
Additional Resources


White Papers & Webcasts
Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Beyond PCI Checklists: Securing Cardholder Data with Tripwire's Enhanced File Integrity Monitoring
How do organizations pass their PCI DSS audits yet still suffer security breaches? Paying attention to PCI DSS checklists only partially secures the...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Authentication as a Service by Forrester Research
Authentication-as-a-Service: understand the benefits of two factor authentication and the best ways to implement it....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
