Ads by TechWords

See your link here
Receive the latest technology news and information.
Storage
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

DHS publishes sector-specific protection plan for IT infrastructure

It aims to protect 17 specific sectors against a range of terrorist and natural threats

May 22, 2007 12:00 PM ET

Computerworld - The U.S. Department of Homeland Security (DHS) yesterday released a broad blueprint of actions that technology companies and government entities can take to mitigate terrorist and other threats against the nation's IT infrastructure.

The Sector Specific Plan (SSP) for IT was released as part of a broader National Infrastructure Protection Plan (NIPP) developed by the DHS under a 2003 presidential mandate. That mandate called for the development of risk-mitigation strategies for protecting critical infrastructure targets in 17 specific sectors against a range of terrorist and natural threats.

The plans are designed to help infrastructure stakeholders in each area to identify and prioritize key assets that need to be protected and to provide recommendations on how to go about doing that. The plans for each of the 17 sectors were developed jointly by participants from government and private industry, which owns a large portion of the critical infrastructure in question.

According to an official description, the IT sector specific plan establishes shared security goals and initiatives, describes roles and responsibilities for each of the stakeholders, and provides opportunities for integrating public and private sector preparedness efforts and technologies. Among the issues that are discussed in the document are strategies for preventing, protecting and responding to threats to the IT infrastructure, identifying vulnerabilities, analyzing and sharing threat information, data recovery and out-of-band data delivery. It also lays out a plan for measuring progress and assigning responsibility for implementing recommendations.

The stakeholders in the IT sector include hardware and software companies, network and security vendors, Domain Name System and Top Level Domain operators and Internet Service Providers.

"It's not just a puff piece," said John Sabo, president of the IT-Information Sharing and Analysis Center (IT-ISAC) and director of global government relations at CA Inc. "It's very much saying these are our challenges and here's a set of action steps we need to take if we are to mitigate those challenges," Sabo said. IT-ISAC was one of the entities involved in helping develop the sector-specific plan for IT.

At the same time, though, it is important that the strategies spelled out in the sector-specific plan are used, Sabo said. "Planning is very, very important. But without effective implementation in an operational environment, such plans will have no value. We believe that operational capability is the end game," he said.

"We like the collaborative approach that [the Sector Specific Plan] was based on," said Kevin Simzer, senior vice president of product development of Addison, Texas-based security vendor Entrust Inc. "I personally like the accountability and the measurement [of progress]" embodied in the plan, Simzer said. "It is consumable by government as sort of a visionary document. It is consumable by industry in that it gives us a sense of where the gaps are and where we need to head. With it, we can all start rowing in the same direction," he said.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

Department of Homeland Security

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.  

Insight from an Auditor: Ensuring a Successful PCI Audit
Ensure a successful PCI audit. Watch this webcast now.

Preventing Data Loss When Migrating to Microsoft 2007
Download this new white paper today!  

Beyond Basic Back-Up: Disaster Recovery
It's not always a flood or fire- 50% of "disasters" are caused by users. Learn more now!

Serving Up Faster Registration
Download this Case Study now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

HP StorageWorks EVA4400 & Microsoft
Download this video, free, compliments of HP.

Virtual Workforce: The Key to Expanding The Business While Cutting Costs
How to cut costs while growing your business. Learn more now!  


IT Jobs

 

Forrester Analyst Report: X86 Server Virtualization For High Availability and Disaster Recovery
According to a recent Forrester study, 49% of enterprises surveyed that are implementing or interested in x86 server virtualization. In particular, x86 server virtualization can improve the availability of business-critical systems that are important to the business but not critical enough to warrant the investment in expensive and complex resiliency technologies like fault-tolerant hardware or clustering.

Download this whitepaper 
Yankee Group. "Disaster Strikes! Is Your Business Ready? Disaster Preparedness for Mid-Sized Firms"
Mid-sized businesses have long struggled to protect their IT systems. Many firms are inadequately protected and mistakenly think that a disaster is rare and won't happen to them anytime soon. This custom Yankee Group Report studies the newest technology trends, such as virtualization and storage replication, which make powerful DR solutions attainable and affordable even for mid-sized businesses.

Download this whitepaper 
VMware White Paper: Transforming Disaster Recovery - VMware Infrastructure for rapid, reliable and cost-effective Disaster Recovery
VMware Infrastructure transforms disaster recovery by providing you fast, reliable and cost-effective disaster recovery. Why suffer from the slow, expensive and unreliable problems associated with traditional disaster recovery solution? VMware makes disaster recovery affordable through consolidation savings and re-use of existing servers for your disaster recovery site. Experience the speed of virtualization!

Download this whitepaper