Showing posts with label CSO Online. Show all posts
Showing posts with label CSO Online. Show all posts

Sunday, August 2, 2009

Internet Security Alliance News & Information Security Resources

 

From The Internet Security Alliance

In The News…

July 24, Orange County Register – (California) FBI to investigate Placentia library hacking. The FBI is hunting down the hackers that hijacked the Placentia Public Library Web site the morning of July 24, a bureau official said the same afternoon. “The FBI will open and investigation into this incident,” said an FBI spokeswoman. The spokeswoman, who works out of the bureau’s Los Angeles field office, said that the FBI has a special unit that investigates “cyber crimes, computer intrusions, defacements, more traditional crimes like fraud and child exploitation.” Visitors to the Placentia Library Web site were greeted by an image of a flapping flag with a crescent moon and star behind a portrait of famed Turkish leader Mustafa Kemal Ataturk. Underneath was the phrase “Editaarruz is back.” A group calling itself the “Federal Attack Team” has apparently hacked www.placentialibrary.org — disabling the site completely. The word “taarruz” means “attack” or “offensive” in the Turkish language.
Source: http://www.ocregister.com/articles/site-web-search-2506225-google-placentia

Internet Security Alliance News 7-29-09 : Information Security Resources

Saturday, June 13, 2009

Cyberwar - Privacy May Be a Victim in Cyberdefense Plan - Series - NYTimes.com

http://www.nytimes.com/ 

June 13, 2009

Cyberwar - The New York Times

Privacy May Be a Victim in Cyberdefense Plan

By THOM SHANKER and DAVID E. SANGER

WASHINGTON — A plan to create a new Pentagon cybercommand is raising significant privacy and diplomatic concerns, as the Obama administration moves ahead on efforts to protect the nation from cyberattack and to prepare for possible offensive operations against adversaries’ computer networks.

President Obama has said that the new cyberdefense strategy he unveiled last month will provide protections for personal privacy and civil liberties. But senior Pentagon and military officials say that Mr. Obama’s assurances may be challenging to guarantee in practice, particularly in trying to monitor the thousands of daily attacks on security systems in the United States that have set off a race to develop better cyberweapons.

Much of the new military command’s work is expected to be carried out by the National Security Agency, whose role in intercepting the domestic end of international calls and e-mail messages after the Sept. 11, 2001, attacks, under secret orders issued by the Bush administration, has already generated intense controversy.

There is simply no way, the officials say, to effectively conduct computer operations without entering networks inside the United States, where the military is prohibited from operating, or traveling electronic paths through countries that are not themselves American targets.

The cybersecurity effort, Mr. Obama said at the White House last month, “will not — I repeat, will not — include monitoring private sector networks or Internet traffic.”

But foreign adversaries often mount their attacks through computer network hubs inside the United States, and military officials and outside experts say that threat confronts the Pentagon and the administration with difficult questions.

Military officials say there may be a need to intercept and examine some e-mail messages sent from other countries to guard against computer viruses or potential terrorist action. Advocates say the process could ultimately be accepted as the digital equivalent of customs inspections, in which passengers arriving from overseas consent to have their luggage opened for security, tax and health reasons.

“The government is in a quandary,” said Maren Leed, a defense expert at the bipartisan Center for Strategic and International Studies who was a Pentagon special assistant on cyberoperations from 2005 to 2008.

Ms. Leed said a broad debate was needed “about what constitutes an intrusion that violates privacy and, at the other extreme, what is an intrusion that may be acceptable in the face of an act of war.”

In a recent speech, Gen. James E. Cartwright, vice chairman of the Joint Chiefs of Staff and a chief architect of the new cyberstrategy, acknowledged that a major unresolved issue was how the military — which would include the National Security Agency, where much of the cyberwar expertise resides — could legally set up an early warning system.

Unlike a missile attack, which would show up on the Pentagon’s screens long before reaching American territory, a cyberattack may be visible only after it has been launched in the United States.

“How do you understand sovereignty in the cyberdomain?” General Cartwright asked. “It doesn’t tend to pay a lot of attention to geographic boundaries.”

For example, the daily attacks on the Pentagon’s own computer systems, or probes sent from Russia, China and Eastern Europe seeking chinks in the computer systems of corporations and financial institutions, are rarely seen before their effect is felt inside the United States.

Some administration officials have begun to discuss whether laws or regulations must be changed to allow law enforcement, the military or intelligence agencies greater access to networks or Internet providers when significant evidence of a national security threat was found.

Ms. Leed said that while the Defense Department and related intelligence agencies were the only organizations that had the ability to protect against such cyberattacks, “they are not the best suited, from a civil liberties perspective, to take on that responsibility.”

Under plans being completed at the Pentagon, the new cybercommand will be run by a four-star general, much the way Gen. David H. Petraeus runs the wars in Afghanistan and Iraq from Central Command in Tampa, Fla. But the expectation is that whoever is in charge of the new command will also direct the National Security Agency, an effort to solve the turf war between the spy agency and the military over who is in charge of conducting offensive operations.

While the N.S.A.’s job is chiefly one of detection and monitoring, the agency also possesses what Michael D. McConnell, the former director of national intelligence, called “the critical skill set” to respond quickly to cyberattacks. Yet the Defense Department views cyberspace as its domain as well, a new battleground after land, sea, air and space.

The complications are not limited to privacy concerns. The Pentagon is increasingly worried about the diplomatic ramifications of being forced to use the computer networks of many other nations while carrying out digital missions — the computer equivalent of the Vietnam War’s spilling over the Cambodian border in the 1960s. To battle Russian hackers, for example, it might be necessary to act through the virtual cyberterritory of Britain or Germany or any country where the attack was routed.

General Cartwright said military planners were trying to write rules of engagement for scenarios in which a cyberattack was launched from a neutral country that might have no idea what was going on. But, with time of the essence, it may not be possible, the scenarios show, to ask other nations to act against an attack that is flowing through their computers in milliseconds.

“If I pass through your country, do I have to talk to the ambassador?” General Cartwright said. “It is very difficult. Those are the questions that are now really starting to emerge vis-à-vis cyber.”

Frida Berrigan, a longtime peace activist who is a senior program associate at the New America Foundation’s arms and security initiative, expressed concerns about whether the Obama administration would be able to balance its promise to respect privacy in cyberspace even as it appeared to be militarizing cybersecurity.

“Obama was very deliberate in saying that the U.S. military and the U.S. government would not be looking at our e-mail and not tracking what we do online,” Ms. Berrigan said. “This is not to say there is not a cyberthreat out there or that cyberterrorism is not a significant concern. We should be vigilant and creative. But once again we see the Pentagon being put at the heart of it and at front lines of offering a solution.”

Ms. Berrigan said that just as the counterinsurgency wars in Iraq and Afghanistan had proved that “there is no front line anymore, and no demilitarized zone anymore, then if the Pentagon and the military services see cyberspace as a battlefield domain, then the lines protecting privacy and our civil liberties get blurred very, very quickly.”

Cyberwar - Privacy May Be a Victim in Cyberdefense Plan - Series - NYTimes.com

Friday, June 5, 2009

Guide to Global Leadership: Two Recommended “Must Reads” for Corporate Executives

By Kevin M. Nixon, MSA, CISSP©, CISM©, CGEIT©

“The Age of the Unthinkable” by Joshua Cooper Ramo

Do not pass Go! Do not collect $200!  Go directly online and buy “The Age of the Unthinkable” by Joshua Cooper Ramo.  I have been telling everyone I know about this book and now I am writing about it too.

We can all agree, that each day we hear yet another discouraging news report on how something else unexpected has gone to hell in a hand-basket.  Just this past November 2008, Alan Greenspan in testimony before Congress said “I’ve discovered a flaw.”  The Congressman questioning Mr. Greenspan asked him to explain, and with much bewilderment Mr. Greenspan said that “using the vast knowledge he had accumulated of the last 40 years and on which he had based his most trusted decisions, was no longer valid.” 

Hearing that from Alan Greenspan must have had the same impact as someone overhearing Warren Buffet say “oops, I only wanted to buy 10% of that company and I accidentally added an extra zero.  Now I own 100%.  Can I change that order?”

Here is some background on the author: 

Joshua Cooper Ramo is the managing director at Kissinger Associates, one of the world’s leading geostrategic advisory firms and the former foreign editor and assistant managing editor of Time magazine.

Mr. Ramo has recently released an audio book entitled “The Age of the Unthinkable – Why the new world disorder constantly surprises us and what we can do about it”

Here is a brief section of the book’s introduction:

“Just a few years into a new century, we’ve arrived at a moment of peril that not long ago would have seemed unimaginable.  All around us, the ideas and institutions that we once relied on for our safety and security are failing, and the best ideas of our leaders seem to make our problems worse, not better.  A global war on terror produces,  in the end, more dangerous terrorists.  The fight to stop financial crisis seems to accelerate its arrival.  Carefully negotiated  peace plans produce less peace.

This wasn’t always the case.  For decades, our engagement with the world was based on the seductive belief that there was a logical relationship between the power of states and the physics of change.  But that traditional physics of power has been replaced by something radically different.  Drawing upon history, economics, complexity theory, psychology, human immunology, and the science of networks we learn about a landscape of inherent unpredictability and remarkable possibility.”

"ALL I REALLY NEED TO KNOW I LEARNED IN KINDERGARTEN" by Robert Fulghum

Most of what we really need to know about how to live, and what to do, and how to be, we learned in kindergarten. Wisdom was not at the top of the graduate school mountain, but there in the sand box at nursery school.

These are the things we learned.

    • Share everything.
    • Play fair.
    • Don't hit people.
    • Put things back where you found them.
    • Clean up your own mess.
    • Don't take things that aren't yours.
    • Say you are sorry when you hurt somebody.
    • Wash your hands before you eat.
    • Flush.
    • Warm cookies and cold milk are good for you.
    • Live a balanced life.
    • Learn some and think some and draw some and paint and sing and dance and play and work everyday.
    • Take a nap every afternoon.
    • When you go out in the world, watch for traffic, hold hands, and stick together.
    • Be aware of wonder.
    • Remember the little seed in the plastic cup? The roots go down and the plant goes up and nobody really knows how or why. We are like that.

And then remember that book about Dick and Jane and the first word you learned, the biggest word of all: LOOK! Everything you need to know is there somewhere. The Golden Rule and love and basic sanitation, ecology, and politics and the sane living.

Think of what a better world it would be if we all, the whole world, had cookies and milk about 3 o'clock every afternoon and then lay down with our blankets for a nap. Or we had a basic policy in our nation and other nations to always put things back where we found them and clean up our own messes. And it is still true, no matter how old you are, when you go out in the world, it is best to hold hands and stick together.

Kevin M. Nixon, MSA, CISSP®, CISM®, CGEIT®, has testified as an expert witness before the Congressional High Tech Task Force, the Chairman of the Senate Armed Services Committee, and the Chairman of the House Ways and Means Committee. He has also served on infrastructure security boards and committees including the Disaster Recovery Workgroup for the Office of Homeland Security, and as a consultant to the Federal Trade Commission.

The Author gives permission to link, post, distribute, or reference the above article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com

Saturday, May 30, 2009

Speculation, Rumors and Whispers - Who could become the Cyber Tsar – Will Willie Win?

By Kevin M. Nixon, MSA, CISSP©, CISM©, CGEIT©

Got to thinking about all of the speculation, rumors and whispers, circulating around Washington DC tonight about who is on the short list with Tsar-like skills.   

First, disregard all of the qualifications, in-depth security knowledge etc. that are on the typical everyday run of the mill Tsar Job Postings.

Think about alternative candidates that have additional supplemental income to take the sting out of that capitated $150K pay grade.  Perhaps someone retired from the military, perhaps someone who has retained top level security clearance while in the private sector.  Perhaps someone with experience dealing with huge software suppliers and with experience in Government Relations and Federal Programs with companies located in Washington State.  And certainly someone with former responsibility for sales, business development, and the capture/proposal process for public sector opportunities.  Consider also, someone with experience developing a company's Network Centric Systems, for Military Integration and Transformation.  After all of those additional qualifications, perhaps someone currently in the private sector with very close government ties.  

willieRear Admiral Robert C. “Willie” Williamson, USN (Ret) joined Raytheon, Network Centric Systems in March 2004. He assumed the newly created position of Director, Naval Integration and Transformation and was assigned additional responsibilities as the Director of Business Development for Integrated Communications Systems (ICS) in December 2004. Currently, Willie is the vice president of International Programs for Integrated Communications Systems (ICS).paul Kurtz

Another Washington whisper includes Paul B. Kurtz, a recognized cyber security and homeland security expert. He served in senior positions on the White House's National Security and Homeland Security Councils under Presidents Clinton and Bush and is currently an on-air consultant to CBS News.   Paul Kurtz, is currently a Partner and security consultant with Arlington, Va.-based Good Harbor Consulting.  

Roger Cressey Good Harbor Consulting Good Harbor Consulting, LLC was founded in 2002 by Good Harbor President Roger W. Cressey after he served in cyber security and counterterrorism positions in the Clinton and Bush administrations. He sought to establish a boutique consulting firm combining public and private sector knowledge and experience to develop a unique offering for government and commercial clients.

In 2003, Richard A. Clarke joined as Chairman of the firm and John S. Tritak joined as CEO. Clarke, an internationally recognized expert on security, including homeland security, national security, cyber security, and counterterrorism, has served the last three U.S. Presidents as a senior White House advisor. Prior to his 11 consecutive White House years, Clarke served for 19 years in the Pentagon, the Intelligence Community, and State Department.

So, President Obama has a number of players sitting on the bench and ready to play the game.  But something just keeps nagging me as I tried to figure out who might have the best odds in Vegas.  Add all of those ingredients together, stir and filtered and studied and still came up with Retired U.S. Navy Rear Admiral Robert C. "Willie" Williamson. 

Just as I had noticed the mysterious change in Melissa Hathaway’s title on the White House Blog, at the moment that the President was speaking, I also noticed something very interesting, “Why would Raytheon remove Rear Admiral Williamson’s distinguished service Bio from the corporate website?”  Will Raytheon be doing an executive search for a new VP of International Programs?  (Just imagine job search skills would include:  “Successful candidate should possess Tsar like qualities and drive for advancement.)

It just seems to me that if one studies the subtle, nuance moves which Washington perfected and patented it would seems that Willie is the pick.  That is just my personal opinion and random thinking.

Friday, May 29, 2009

Washington is Whispering

Speculation, Rumors and Whispers - Who could become the Cyber Tsar

Got to thinking about all of the speculation, rumors and whispers, circulating around Washington DC tonight about who is on the short list with Tsar-like skills.   

First, disregard all of the qualifications, in-depth security knowledge etc. that are on the typical everyday run of the mill Tsar Job Postings.

Think about alternative candidates that have additional supplemental income to take the sting out of that capitated $150K pay grade.  Perhaps someone retired from the military, perhaps someone who has retained top level security clearance while in the private sector.  Perhaps someone with experience dealing with huge software suppliers and with experience in Government Relations and Federal

Programs with companies located in Washington State.  And certainly someone with former responsibility for sales, business development, and the capture/proposal process for public sector opportunities.  Consider also, someone with experience developing a company's Network Centric Systems, for Military Integration and Transformation.  After all of those additional qualifications, perhaps someone currently in the private sector with very close government ties.  

Add all of those ingredients together, stir and filter.  One name comes to pops to the top of the list.  Wonder if Retired U.S. Navy Rear Admiral Robert C. "Willie" Williamson is considering his time with Raytheon might be limited.  That is just my personal opinion and random thinking.

 

Powered By Blogger