Federal cybersecurity director quits, complains of NSA role
Rod Beckstrom quit the post after less than a year
Computerworld - In a move that highlights differences over who should be in charge of national cybersecurity efforts, the director of a federal office set up to protect civilian, military and intelligence networks has submitted his resignation after less than a year in the job.
Rod Beckstrom, director of the National Cyber Security Center (NCSC), on Friday said he is quitting because of concerns over what he said is the National Security Agency's (NSA) domination of the nation's cybersecurity efforts. The NCSC was set up within the U.S. Department of Homeland Security (DHS) last year to oversee and coordinate efforts to shore up the nation's defenses and responses to cyberthreats.
Beckstrom was appointed to lead the NCSC in March 2008 and was required to report directly to then-DHS Secretary Michael Chertoff.
In a sharply worded letter to current DHS Secretary Janet Napolitano, Beckstrom on Friday noted that the NSA effectively controlled DHS cyberefforts "through detailees, technology insertions" and a proposed move of the National Protection and Programs Directorate and the NCSC to an NSA facility in Fort Meade. His letter, dated March 5, noted that allowing the NSA to control national cybersecurity efforts is a "bad strategy on multiple grounds."
Beckstrom also stressed his unwillingness to "subjugate the NCSC underneath the NSA."
The intelligence culture embodied by the NSA is "very different than a network operations or security culture," said Beckstrom in the letter, a copy of which was obtained by Computerworld. Allowing a single agency such as the NSA to handle all top-level government network security and monitoring functions poses a significant threat to "our democratic processes," he said. "Instead, we advocated a model where there is a credible civilian government cybersecurity capability which interfaces with, but is not controlled by, the NSA."
Beckstrom also lamented the lack of "appropriate" support for his office within the DHS during the Bush administration. He noted that over the past year, his office had received just five weeks' worth of funding because of various roadblocks engineered within the DHS and the White House Office of Management and Budget (OMB).
Beckstrom's resignation is sure to focus attention on a 60-day review of national cybersecurity efforts now under way by Melissa Hathaway, a Bush administration official, at the behest of President Barack Obama. Hathaway has been working as a cybercoordination executive for the Office of the Director of National Intelligence Comprehensive National Cyber Security Initiative, or CNCI.
The CNCI is a highly classified multibillion dollar cybersecurity initiative approved by then-President George W. Bush early last year. Hathaway has been in charge of coordinating and monitoring the CNCI's implementation and was recently asked by Obama to do a complete review of CNCI and other governmentwide cybersecurity initiatives.
Beckstrom's resignation is likely to force Hathaway to address the issue of who should run the government's overall national cybersecurity efforts. Even before Beckstrom's announcement, questions had arisen about the idea of letting the NSA taking the lead on cybersecurity issues. At a congressional hearing as far back as February 2008, lawmakers had expressed concern about the NSA's role in the CNCI, especially because of the classified nature of the initiative.
In December, a panel of security experts from the Center for Strategic and International Studies delivered a set of cybersecurity recommendations for the Obama administration explicitly calling on the White House to take overall charge of cyberinitiatives, not the NSA.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts