Sept. 11 lessons drive key aspects of Bush cyberdefense plan
Computerworld - The hard lessons of Sept. 11 are never far away, and now they have been sprinkled throughout the Bush administration's draft strategy to defend cyberspace.
Released yesterday (see story), the National Strategy to Secure Cyberspace takes key lessons learned from the destruction of critical digital infrastructure in New York last year -- as well as the results of various government-sponsored exercises focused on critical-infrastructure interdependencies -- and wraps them into several recommendations that integrate physical and network security requirements.
"Owners and operators of information system networks and network data centers should consider developing remediation and contingency plans to reduce the consequences of large-scale physical damage to facilities supporting such networks," the report recommends. The terrorist attacks underscored for many officials the need to consider physical security as another arm of cybersecurity, with one senior administration official calling the damage inflicted on the communications networks owned and operated by Verizon Communications in Manhattan "the most significant challenge that the National Communications System had ever seen."
The recommendation is also important given the fact that months after the attacks, a survey of 459 CIOs by Ernst & Young International found that just 53% of companies had business continuity plans, and less than half had IT security awareness and training programs for employees.
On the cyberterrorism and information warfare front, the strategy urges federal law enforcement agents to work with national security and intelligence agencies to "develop a system to detect a national cyberattack (cyberwar) and a plan for immediate response." Although such a recommendation represents a daunting challenge, it is very timely given current tensions with Iraq and the possibility of war, experts said.
"Every U.S. military initiative over the past several years has been matched by a surge in aggressive cyberactivity," said Steven Aftergood, a defense and intelligence analyst at the Federation of American Scientists in Washington. "It would be surprising if the same pattern did not recur in the event of a U.S. strike against Iraq."
One target of sophisticated terrorist groups or state-sponsored cyberwarriors could be the real-time control systems, known as Supervisory Control and Data Acquisition (SCADA) systems, that manage everything from the flow of electricity to natural gas and oil pipelines. The draft national strategy labels the security of SCADA systems a "high priority" for both the government and private sector, and calls for the development of secure authentication capabilities within two years.
David Kepler, corporate vice president and CIO of The Dow Chemical Co., acknowledged the importance of security for real-time process control systems. "The synergy



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Five Myths of Cloud Computing
- This white paper separates fact from fiction, reality from myth, and, in doing so, will aid senior IT executives as they make decisions...
- Smarter Commerce is redefining value chain visibility
- Smarter Commerce is redefining the value chain in the age of the customer. It starts with putting the customer at the center of...
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- IBM Synchronizes its Commerce 2.0 Strategy with 'Smarter Commerce' Initiative
- On March 14, IBM announced "Smarter Commerce", a strategic initiative that addresses the surging market for Commerce 2.0 solutions that take advantage of... All IT in Government White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All IT in Government Webcasts