<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tales from the Technoverse &#187; cyber-security</title>
	<atom:link href="http://www.ourownlittlecorner.com/tag/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ourownlittlecorner.com</link>
	<description>Commentary on social networking, technology, movies, society, and random musings</description>
	<lastBuildDate>Sun, 04 Jul 2010 13:18:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>The Problem With Government Security</title>
		<link>http://www.ourownlittlecorner.com/2010/06/23/the-problem-with-government-security/</link>
		<comments>http://www.ourownlittlecorner.com/2010/06/23/the-problem-with-government-security/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 02:04:03 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[John Boyd]]></category>
		<category><![CDATA[OODA]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=199</guid>
		<description><![CDATA[During the time I served as the CIO at the US Department of Transportation when I wanted to annoy my Chief Information Security Officer (CISO) of the CISO staff, I would point out that in my opinion there were two things wrong with computer security within the Federal Government. First, we put security in charge. [...]]]></description>
			<content:encoded><![CDATA[<p>During the time I served as the CIO at the US Department of Transportation when I wanted to annoy my Chief Information Security Officer (CISO) of the CISO staff, I would point out that in my opinion there were two things wrong with computer security within the Federal Government.</p>
<p>First, we put security in charge.</p>
<p>Second, we kept secrets.</p>
<p>If we solved for those two issues, we would not have a security problem.</p>
<p>Of course, I was joking. Well sort of.<span id="more-199"></span></p>
<p>The point I was making regarding security being in charge was to illustrate that in the end security was an advisory function supporting the business owner. The business owner needed to make the final call regarding what to do re operational systems.</p>
<p>Taking the extreme example at the Department, which happily we never faced, was what if the air traffic control system had been infected with a virus which we felt might spread to other operational systems. The senior executives who were responsible for air traffic control would be the responsible officials deciding if we could take the systems off-line, not security.</p>
<p>My second point was that if we needed to much more aggressively think through what systems, and data, we really needed to protect. The more we needed to protect the less likely we were able to protect anything. My final line was always if we didn’t have any secrets we wouldn’t have a security issue.</p>
<p>In retrospect, I have more recently realized that in addition to being a bit flippant, I was also wrong. As any security professional knows, even without secrets we still will have a serious security issue – that of integrity. By integrity I mean both of the data and the systems themselves.</p>
<p>Since it remains my contention that in today’s world, all organizations have to ultimately choose if they are going to be great at information sharing or information protection AND that all organizations are going to eventually have to choose information sharing (I’ll do a separate post on this); this leads to a problem.</p>
<p>Recently I have been talking to professionals who touch DoD and military doctrine, an area I am pretty unknowledgeable. A number have mentioned the work of John Boyd, <a href="http://en.wikipedia.org/wiki/John_Boyd_(military_strategist)">http://en.wikipedia.org/wiki/John_Boyd_(military_strategist)</a>. Boyd came up with the concept of decision cycles, what he called an OODA Loop:</p>
<ul>
<li>Observation</li>
<li>Orientation</li>
<li>Decision</li>
<li>Action</li>
</ul>
<p>A simplistic summary of Boyd’s thinking was that in combat, the organization with the fastest, high quality OODA loop would win; where combat could be combat in anything.</p>
<p>Taking this concept to cyber-security, one conceptual approach would be to not try and protect the periphery of a network but to be able to rapidly change the network or access to it, or its contents, so that an adversary would never have the opportunity to penetrate and/or corrupt it.</p>
<p>As usual, I am much more able to articulate these kinds of things conceptually than to actually understand the implementation implications. However, I hope to interact with people who can help me understand those details as well as let me know if this is a reasonable approach to security.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2010%2F06%2F23%2Fthe-problem-with-government-security%2F&amp;linkname=The%20Problem%20With%20Government%20Security"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2010/06/23/the-problem-with-government-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Slides from the  University of Maryland University College 2010 Annual Cybersecurity and Homeland Defense Symposium</title>
		<link>http://www.ourownlittlecorner.com/2010/06/20/my-slides-from-the-university-of-maryland-university-college-2010-annual-cybersecurity-and-homeland-defense-symposium/</link>
		<comments>http://www.ourownlittlecorner.com/2010/06/20/my-slides-from-the-university-of-maryland-university-college-2010-annual-cybersecurity-and-homeland-defense-symposium/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 00:10:19 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[presentations]]></category>
		<category><![CDATA[scada]]></category>
		<category><![CDATA[sensors]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[jobs]]></category>
		<category><![CDATA[joke]]></category>
		<category><![CDATA[milliion dollars]]></category>
		<category><![CDATA[steve martin]]></category>
		<category><![CDATA[University of Maryland]]></category>
		<category><![CDATA[University of Maryland University College]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=194</guid>
		<description><![CDATA[Last month I was the keynote speaker at the University of Maryland University College 2010 Annual Cybersecurity and Homeland Defense Symposium and Job Fair, http://www.umuc.edu/securitystudies/cybersymposium_agenda.shtml. A few people asked me to post my presentation, but I have found that my current job as the COO at Powertek Corporation has caused me to miss many of [...]]]></description>
			<content:encoded><![CDATA[<p>Last month I was the keynote speaker at the University of Maryland University College 2010 Annual Cybersecurity and Homeland Defense Symposium and Job Fair, <a href="http://www.umuc.edu/securitystudies/cybersymposium_agenda.shtml">http://www.umuc.edu/securitystudies/cybersymposium_agenda.shtml</a>.</p>
<p>A few people asked me to post my presentation, but I have found that my current job as the COO at Powertek Corporation has caused me to miss many of my self-imposed deadlines for doing many things, including updating my blog.<span id="more-194"></span></p>
<p>However, has now been overcome, at least for a few moments, and here it is.</p>
<p><a title="UMUC Slides" href="http://www.ourownlittlecorner.com/wp-content/uploads/2010/06/umuc-css-201005.pdf" target="_blank">UMUC Slides</a> </p>
<p>My talk was divided into four parts:</p>
<ul>
<li>Context where I discussed what I call First Principals, what I feel are the underlying causes of much of the technological disruptions happening these days</li>
<li>Some thoughts on security trends, after all this was a Cybersecurity Symposium</li>
<li>Comments about the demand for security professionals, after all this also was a Job Fair</li>
<li>Ending with some thoughts on the goals for security and some general advice</li>
</ul>
<p>I think the slides are pretty self-explanatory though I keep hoping to turn some of them into individual blog entries.</p>
<p>I had two key pieces of advice.</p>
<p>First, I related an old joke by Steve Martin that talked about how to make a million dollars and not pay taxes. The first step was to ‘find a million dollars’. I find that many proposed solutions to security, well, actually to almost anything hard is the functional equivalent of that first step.</p>
<p>Second, I told them to remember that the primary mission of almost every organization they will work for is NOT security. Because of that fact, one of the primary jobs of a senior security professional is to learn how to articulate the reasons for security investments in the context of the actual mission goal. Otherwise, organizational senior management will not make the right decisions.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2010%2F06%2F20%2Fmy-slides-from-the-university-of-maryland-university-college-2010-annual-cybersecurity-and-homeland-defense-symposium%2F&amp;linkname=My%20Slides%20from%20the%20%20University%20of%20Maryland%20University%20College%202010%20Annual%20Cybersecurity%20and%20Homeland%20Defense%20Symposium"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2010/06/20/my-slides-from-the-university-of-maryland-university-college-2010-annual-cybersecurity-and-homeland-defense-symposium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webinar on Cybersecurity: Building Secure Federal Systems</title>
		<link>http://www.ourownlittlecorner.com/2010/03/08/webinar-on-cybersecurity-building-secure-federal-systems/</link>
		<comments>http://www.ourownlittlecorner.com/2010/03/08/webinar-on-cybersecurity-building-secure-federal-systems/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 21:44:29 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[government business]]></category>
		<category><![CDATA[scada]]></category>
		<category><![CDATA[government executive]]></category>
		<category><![CDATA[nrc]]></category>
		<category><![CDATA[nuclear regulatory commission]]></category>
		<category><![CDATA[powertek corporation]]></category>
		<category><![CDATA[SANS Institute]]></category>
		<category><![CDATA[secure federal systems]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=174</guid>
		<description><![CDATA[I was pleased to be asked to be part of a webinar sponsored by Government Executive this Thursday at 2:00pm EST and even happier when Pat Howard, the CISO from the Nuclear Regulatory Commission accepted an invitation to join me. The webinar, moderated by Adam Ross, the Managing Editor from the SANS Institute, will focus [...]]]></description>
			<content:encoded><![CDATA[<p>I was pleased to be asked to be part of a webinar sponsored by Government Executive this Thursday at 2:00pm EST and even happier when Pat Howard, the CISO from the Nuclear Regulatory Commission accepted an invitation to join me.</p>
<p>The webinar, moderated by Adam Ross, the Managing Editor from the SANS Institute, will focus on some of the challenges faced in creating secure Federal Systems. With the growing movement for speed-to-market and the movement to the cloud, and associated buzz words, and with the increased publicity about cyber-attacks, how we should best deal with such issues is becoming a still greater issue.<span id="more-174"></span></p>
<p>Pat and I will look at these issues in three parts.</p>
<p>First, we will look at the context that we now face. I find that without understanding the context of a problem, it becomes difficult to really deal with the systemic issues. Second, I will review some of the high-level goals that I would focus on, putting on my now dusty CIO hat from my Department of Transportation days. Finally, Pat will tackle real-world issues with implementation suggestions, looking at how to integrate security planning rather than dealing with it as an afterthought. He will also offer his thoughts relating to SCADA design issues (Supervisory Control and Data Acquisiton – e.g. computers managing things like the electrical grid, power plants, and so forth).</p>
<p>Registration details are at:</p>
<p><a href="http://event.on24.com/r.htm?e=195825&amp;s=1&amp;k=D14C3C31F1889E77A82E235253D58190">http://event.on24.com/r.htm?e=195825&amp;s=1&amp;k=D14C3C31F1889E77A82E235253D58190</a></p>
<p>The Government Executive website is at: <a href="http://www.govexec.com/">http://www.govexec.com/</a></p>
<p>Powertek Corporation’s web site is at: <a href="http://www.powertekcorporation.com/">http://www.powertekcorporation.com/</a></p>
<p>The Nuclear Regulatory Commission’s web site is at: <a href="http://www.nrc.gov">http://www.nrc.gov</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2010%2F03%2F08%2Fwebinar-on-cybersecurity-building-secure-federal-systems%2F&amp;linkname=Webinar%20on%20Cybersecurity%3A%20Building%20Secure%20Federal%20Systems"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2010/03/08/webinar-on-cybersecurity-building-secure-federal-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber-Security Discussion at the Fedscoop Conference</title>
		<link>http://www.ourownlittlecorner.com/2009/10/15/cyber-security-discussion-at-the-fedscoop-conference/</link>
		<comments>http://www.ourownlittlecorner.com/2009/10/15/cyber-security-discussion-at-the-fedscoop-conference/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 13:08:12 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[government 2.0]]></category>
		<category><![CDATA[government business]]></category>
		<category><![CDATA[federal cio council]]></category>
		<category><![CDATA[fedscoop]]></category>
		<category><![CDATA[goldy kamali]]></category>
		<category><![CDATA[newseum]]></category>
		<category><![CDATA[rob carey]]></category>
		<category><![CDATA[security metrics task force]]></category>
		<category><![CDATA[vivek kundra]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=91</guid>
		<description><![CDATA[I was lucky enough to be part of a panel discussing cyber-security at a Fedscoop conference Wednesday, October 14, at the Newseum. The agenda for the conference is here: http://fedscoopevents.com/agenda.php. I thought it might be useful to summarize my general points for those who were not able to attend. The theme of the conference was [...]]]></description>
			<content:encoded><![CDATA[<p>I was lucky enough to be part of a panel discussing cyber-security at a Fedscoop conference Wednesday, October 14, at the Newseum. The agenda for the conference is here: <a href="http://fedscoopevents.com/agenda.php">http://fedscoopevents.com/agenda.php</a>. I thought it might be useful to summarize my general points for those who were not able to attend.</p>
<p>The theme of the conference was Lowering the Cost of Government with Technology though the panel&#8217;s comments ranged from cost issues to government 2.0 and social networking to cyber-security in general.</p>
<p>The panel was moderated by Chris Dorobek, the afternoon co-anchor for WFED. The other panelists included Vance Hitch, the Department of Justice CIO, Pat Howard, the Chief Information Security Officer, CISO, for the Nuclear Regulatory Commission, Dr. Ron Ross, a key figure in defining security requirements and policy at the National Institute of Standards and Technology, NIST, Gary Galloway, the Deputy Director for Information Assurance at the Department of State, and Rue Moody, the Director of Strategic Technology at Citrix.</p>
<p><span id="more-91"></span></p>
<p>I was called on first after the introductions to frame the conversation based on the pre-meeting discussions the panelists had held. I discussed four issues.</p>
<p>First, there is an inherent conflict between data sharing and data protection. In my opinion, you cannot do both perfectly. Even though almost everyone will take the position that you will have to pay attention to both, it is important to pay attention to which way you lean and why and the implications. I noted how impressed I was towards the end of the last administration, when Mike McConnell, then the Director of National Intelligence, DNI, talked about if he had to take some security risks in order to increase the ability to share information within the Intelligence Community, he would. I am sure that I am not capturing the nuances of his talk, but the messaging was very powerful. It is a position that those who know me recognize I agree with very strongly.</p>
<p>Second, security is difficult to measure and more importantly there is little agreement among security experts as to what metrics to use. This is a particular problem for those agencies and departments who do not have security as part of their day job.</p>
<p>What I mean by that last sentence is that those departments who have security as part of their primary mission have a great deal of day-to-day experience in making tradeoffs involving security spending. Even if the rationale for decisions is merely experiential as opposed to quantitative, over time senior management gets to be fairly experienced at making these kinds of decisions.</p>
<p>For most civilian departments and agencies this is not as true. Trying to decide if taking money from safety inspections, which might be an agencies primary mission, and spending it on cyber-security is a difficult decision to make. Without defined metrics the likelihood of making the correct decision isn&#8217;t very high.</p>
<p>I was heartened in reading recently about the establishment of a Security Metrics Task Force by Vivek Kundra and the Federal CIO Council, <a href="http://it.usaspending.gov/?q=content/blog">http://it.usaspending.gov/?q=content/blog</a>, chaired by Vance Hitch, who discussed this during his remarks at the panel, and Rob Carey, the Department of the Navy CIO.</p>
<p>Third, it is hard for people in large organizations, especially governmental organizations to prioritize; that is, to implement the results of risk analysis. The fundamental reason is that prioritization requires someone to decide to work on one set of requirements and thus to NOT work on the rest of the requirements. Few, if anyone, wants to be the person who is associated with the latter decision, the not work on part. If anything bad happens that could be associated with a requirement that is in the lower set of priorities, that will get extra attention from the various oversight groups that look over the shoulders of IT providers in the Federal Government. As someone who had the pleasure of testifying on the hill I can promise you it is not a goal for most people.</p>
<p>The end result is that often organizations try to do everything and thus end up doing very little of anything.</p>
<p>Finally, I noted that the general overemphasis on protecting the end-points of networks is starting to be balanced against the need for creating systems that are resiliant and have high-availability. Obviously, it would not be a good plan to ignore investments in protection against bad guys getting into networks. But it is equally important to recognize that regardless of the level of protection built into an architecture, at least some bad guys will get through. Therefore, it is also important to think about how to make sure systems stay up and running with protected data even while a system has been otherwise penetrated.</p>
<p>As hard as it is to build in protections and to measure the results, it is harder still to do the same for regarding building resiliant systems. Thus the greater emphasis on protection first, which i believe still needs to be adjusted further.</p>
<p>One point which I didn&#8217;t make as well as I would have liked at the Conference is the fact that security has both positive and negative cost implications. It can be positive if there is greater standardization which tends to lower support costs and can do so dramatically if done well. It can be negative if there is no clearcut methodology to making investment decisions. Without associated risk management and security metrics, security spending becomes an endless investment with no well-defined result.</p>
<p>Many thanks to Goldy Kamali for inviting me to be part of the panel and for putting together a great conference. Everyone who missed it missed some great discussions and networking opportunities.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2009%2F10%2F15%2Fcyber-security-discussion-at-the-fedscoop-conference%2F&amp;linkname=Cyber-Security%20Discussion%20at%20the%20Fedscoop%20Conference"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2009/10/15/cyber-security-discussion-at-the-fedscoop-conference/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>CIO Magazine Article On Cybersecurity</title>
		<link>http://www.ourownlittlecorner.com/2009/07/16/cio-magazine-article-on-cybersecurity/</link>
		<comments>http://www.ourownlittlecorner.com/2009/07/16/cio-magazine-article-on-cybersecurity/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 21:51:04 +0000</pubDate>
		<dc:creator>Daniel</dc:creator>
				<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[cio magazine]]></category>
		<category><![CDATA[csc]]></category>
		<category><![CDATA[cto]]></category>
		<category><![CDATA[obama administration]]></category>

		<guid isPermaLink="false">http://www.ourownlittlecorner.com/?p=30</guid>
		<description><![CDATA[The lead story in the July 1, 2009 issue of CIO Magazine deals with cyber-security. The Editor&#8217;s Letter headline is: &#8220;Whac-A-Mole&#8221; Approach to Security and contains the following paragraph: &#8220;It&#8217;s hard to imagine more appropriate imagery for our cover story (&#8220;Moving Target&#8221;) about the widespread frustration with mounting cybersecurity threats and the lack of an [...]]]></description>
			<content:encoded><![CDATA[<p>The lead story in the July 1, 2009 issue of CIO Magazine deals with cyber-security.</p>
<p>The Editor&#8217;s Letter headline is:</p>
<p>&#8220;Whac-A-Mole&#8221; Approach to Security</p>
<p>and contains the following paragraph:</p>
<p>&#8220;It&#8217;s hard to imagine more appropriate imagery for our cover story (<a href="http://www.ourownlittlecorner.com/article/496125/">&#8220;Moving Target&#8221;</a>) about the widespread frustration with mounting cybersecurity threats and the lack of an effective U.S. government response. CTO Daniel Mintz of consulting firm CSC aptly describes the feds&#8217; &#8220;Whac-A-Mole security&#8221; approach as one where long-term strategy takes a back seat to daily tactical responses.&#8221;</p>
<p><a href="http://www.cio.com/article/495811/A_Whac_A_Mole_Approach_to_Security">http://www.cio.com/article/495811/A_Whac_A_Mole_Approach_to_Security</a></p>
<p>I appreciate the mention and anyone who has heard me talk about cyber-security will know I use that term a lot. My one question is whether it should be &#8220;whack&#8221; or whac&#8221; &#8230;</p>
<p>The full article is located here:<br />
<a href="http://www.cio.com/article/496125/Obama_s_Cybersecurity_Push_What_It_Means_for_CIOs">http://www.cio.com/article/496125/Obama_s_Cybersecurity_Push_What_It_Means_for_CIOs</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.ourownlittlecorner.com%2F2009%2F07%2F16%2Fcio-magazine-article-on-cybersecurity%2F&amp;linkname=CIO%20Magazine%20Article%20On%20Cybersecurity"><img src="http://www.ourownlittlecorner.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.ourownlittlecorner.com/2009/07/16/cio-magazine-article-on-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
