Sidebar: Is the Genie Out of the E-bottle?
Computerworld - As the three-year anniversary of the Sept. 11, 2001, terrorist attacks approaches, the Web remains a treasure trove of information for terrorists who may be planning or refining attack strategies.
Despite the increased concern about the possible targeting of nuclear or chemical processing facilities in the U.S., a disturbing amount of profile data about these facilities remains accessible online. And while most of the data is useless to a terrorist, security analysts say that critical data elements are available that could assist terrorists in their planning.
The Indian Point nuclear power plant, for example, located on the east bank of the Hudson River in Buchanan, N.Y., and operated by Entergy Corp., remains an open book in terms of providing details of reactor design, including the thickness of the reactor's various layers and the types of steel reinforcement used.
"With this information all you have to do is the math to figure out how much explosive power is needed to breach the wall," said Eric Friedberg, a former computer crime coordinator at the U.S. Department of Justice.
"When we talk about nuclear power plants, the stakes are even higher" than in the financial services sector, said MacDonnell Ulsch, managing director of Janus Risk Management Inc. in Marlborough, Mass. "Such information should be considered proprietary, like bank vault and bank construction details. Is this any way to manage risk? Hell no."
Entergy could not be reached for comment by posting deadline.
Shortly after 9/11, the Environmental Protection Agency removed data from its Web site pertaining to the location of chemical facilities in the U.S., as well as information pertaining to risk management at those facilities. The agency also began restricting access to various online databases that contained information on chemicals and environmental threat issues.
However, a review last week of EPA Web pages found that the locations of hazardous chemical facilities in the U.S. are provided via an interactive map including address and grid coordinates.
John Millett, a spokesman for the EPA, said on Friday that the agency has conducted an extensive review of its Web content and concluded that "very few of the publicly accessible federal geospatial sources appear useful to meeting a potential attacker's information needs."
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts