NextGov.com

Brought to you by GovernmentExecutive.com Events

Government Executive events provide federal managers with practical insights on current topics. They feature prominent thought leaders addressing key issues facing the federal government. Attendees gain the latest insights and best practices from their colleagues throughout government.

UPCOMING EVENTS

OCTOBER 21
Communication Today: New Generations, New Rules

OCTOBER 23
Developing Effective Records Management Strategies

What's happening in the federal IT community

New CIO for DHS' National Protection and Programs
by Allan Holmes - 10/10/08 6:19 pm EDT

Federal Jobs -- Lookin' Mighty Attractive Now
by Allan Holmes - 10/09/08 5:58 pm EDT

Does Technology Make Us Smarter?
by Allan Holmes - 10/08/08 5:44 pm EDT

Time to Reassess Data Mining
by Allan Holmes - 10/07/08 6:30 pm EDT

Another Call for Getting Serious With Clinger-Cohen
by Allan Holmes - 10/06/08 3:32 pm EDT





















Better communication needed for cybersecurity
By Jill R. Aitoro   04/10/08

The ability to share critical information between public and private sectors during a cyberattack remains a challenge, due in part to inconsistent procedures used by companies and agencies to respond to threats, according to those who participated in a recent simulation of an international cyberattack.

Comment on this article in The Forum.The exercise, called Cyber Storm II and which the Homeland Security Department staged in March, was the largest exercise of its kind, involving more than 40 companies, 18 agencies, nine states and five countries. A panel of participants discussed lessons learned from the exercise during the RSA security conference in San Francisco this week.

“Information sharing is still critical,” said Randy Vickers, associate deputy director within the DHS national cybersecurity division of the U.S. Computer Emergency Readiness Team. “We’re not doing well at this across sectors.”

As part of the exercise, participants responded to simulated threats launched through e-mails, phone, faxes, Web sites and in-person contacts. They then were expected to implement internal crisis response systems and follow policies and procedures to deal with the attacks, which crippled control systems, telephone and Internet service. The ability to communicate across industries is critical, the panel said, because the attacks can affect different kinds industries, agencies and operations.

Before organizations can share information, officials must improve protocols for responding to cyber threats.

“[We] need to integrate communication around cybersecurity within companies,” said Christine Adams, a senior information systems manager with Dow Chemical Co. Ten chemical companies participated in Cyber Storm II. No chemical company participated in the first Cyber Storm exercise held in February 2006.

“When the DHS threat level changed, some individuals said, ‘So what?’…And when [systems were] compromised, people looked around and said, ‘Who has the [authority] to gain access?’” Adams said. “The time of crisis is not the time to find that information out.”

DHS won’t release the after-action report with detailed analysis of Cyber Storm II results until the end of the summer.


E-MAIL THIS ARTICLE    SHARE THIS ARTICLE    PRINT THIS ARTICLE

VENDOR SOLUTIONS

Dynamic Deduplication – Achieving a 50:1 ratio
Free white paper, brought to you by Hewlett Packard.

The Federal SOA Institute's mission is to help
The federal government adopt and benefit from service oriented architecture. From IBM.

Market-based government through innovation:
How public sector leaders are improving collaboration and focus on citizens. From IBM.

Top public sector innovators: Changing the world.
Through government, education and healthcare and life sciences. From IBM.

View more products and services... Purchase a link now...