Feds plan cybersecurity center
The White House is denying it's looking to monitor data as part of the president's National Plan for Protecting Cyberspace.
Computerworld - Washington
As the White House last week began putting the final touches on its long-awaited National Plan for Protecting Cyberspace, administration officials took issue with a press report that suggested the plan would include provisions to expand the government's data collection and surveillance.
The plan, which is scheduled to be released Sept. 18 during a ceremony at Stanford University, does include a provision to build a cybersecurity network operations center. However, a published report suggesting that the NOC would collect and examine e-mail and data traffic from major Internet service providers and other private-sector companies is misleading and inaccurate, said Tiffany Olson, an assistant to Richard Clarke, chairman of the President's Critical Infrastructure Protection Board and the principal force behind the strategy.
Olson said the published report is necessarily inaccurate because the plan hasn't even been finished.
"There were many initial drafts, and many organizations provided input," she said. "But we've just started to finalize it this week."
The concept of developing a federal NOC is definitely in the strategy, but not with the aim of gathering e-mail data or expanding government surveillance, Olson said. Rather, the federal NOC would be modeled after the Bethesda, Md.-based SANS Institute's Incidents.org Web site and Internet Storm Center, a virtual organization of advanced intrusion-detection analysts, forensics experts and incident handlers from across the globe.
Howard Schmidt, co-chairman of the Critical Infrastructure Protection Board, told Computerworld last week that the plan is to simply ask for greater voluntary data sharing on matters such as viruses and worms. He also stressed that establishing a central NOC isn't part of a plan to increase the government's surveillance of private data.
Schmidt said the need for a central government NOC stems from the lack of a single collection point where government security can be analyzed. This central NOC would collect data from other government NOCs, such as the FBI's National Infrastructure Protection Center and the Pentagon's Joint Task Force for Computer Network Defense.
These NOCs, in turn, would function in a fashion similar to the private sector's Information Sharing and Analysis Centers (ISAC)alliances formed within vertical industries to improve information sharing about security vulnerabilities and threats.
The SANS Storm Center uses advanced data correlation and visualization techniques to analyze data collected from more than 3,000 firewalls and intrusion-detection systems in more than 60 countries. "We're hoping the [ISACs] one day establish their own independent Storm Center network," said Alan Paller, director of the SANS Institute.
And that may be much easier to do now that Redwood City, Calif.-based Check Point Software Technologies Ltd., which operates more than 63% of all firewalls worldwide, is adding a Storm Center client in every one of its 260,000 gateways, said Paller. "That means anyone who wants to set up a Storm Center network can just tell their members to turn on the client and point it to their network node," he said.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Gov't Legislation/Regulation White Papers | Webcasts