Friday, May 29, 2009

Is she or isn’t she – America’s New Cybersecurity Tsarina?

By Kevin M. Nixon, MSA, CISSP©, CISM©, CGEIT©

Information Security Resources staff had received an advance copy of the official White House Press Release (05/29/2009) and was all ears today during President Obama’s East Room remarks on the highly anticipated and long awaited release of the “Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure”. The report has become known as “The Hathaway 60-Day Report” in “homage” to Melissa Hathaway, the person President Obama picked as “Acting Senior Director for Cyberspace of the National Security Council (NSC) and the Homeland Security Council (HSC)”. Not only did the President bestow a title too long to technically print on a normal sized business card, also he gave her a the shortest runway I have ever seen to assemble recommendations, gain consensus, and publish a report for the Chief Executive. Just pulling together all agencies, departments, stove-piped information while overcoming all the turf battles can only be likened to attempting a huge worm wrestle.

Ms Hathaway accomplished the task and delivered the goods and so everyone anticipated that the President would recognize her “get it done” work ethic and also announce from the East Room today, her appointment as America’s Cybersecurity Tsarina. However, everyone holding their breath in the East Room today probably passed out from lack of oxygen. The President was blatantly and conspicuously silent on his appointment.

The President’s silence left everyone wondering “does she or doesn’t she” and left reports attempting to find any hints of the President’s plan. ISR think that we may be on to something. As POTUS stepped in front of the gathered experts, somewhere in the back offices of the White House there was a shadowy figure hunkered over a keyboard waiting for the exact moment to press enter and publish an article on the White House Blog. Could that person have even been sitting in the East Room audience with the President holding onto her three Blackberry devices just waiting for President Obama to give the secret word or phrase to “press the send” button?

We may never know, but President Obama did acknowledge Melissa Hathaway at about the same time that an article by her was posted on the White House Blog. What is noticeable is in Ms Hathaway’s article is her title in the article’s by-line. Gone is “Melissa Hathaway, Acting Senior Director for Cyberspace of the National Security Council (NSC) and the Homeland Security Council (HSC)”. The new by-line reads: Melissa Hathaway, Cybersecurity Chief at the National Security Council.

Which still leaves us wondering and waiting? Is the White House making new robes as the Catholic church does when a new Pope is elected or has Ms Hathaway been appointed “Camerlingo” (1st runner up in a papal contest). Guess we will just have to wait. Melissa Hathaway’s Blog post “Security Our Digital Future” is re-published on the ISR website.


Securing Our Digital Future

Melissa Hathaway, Cybersecurity Chief at the National Security Council, discusses securing our nation's digital future:

Published: FRI, MAY 29, 10:00 AM EST -- The White House Blog

The globally-interconnected digital information and communications infrastructure known as cyberspace underpins almost every facet of modern society and provides critical support for the U.S. economy, civil infrastructure, public safety and national security.  The United States is one of the global leaders on embedding technology into our daily lives and this technology adoption has transformed the global economy and connected people in ways never imagined.  My boys are 8 and 9 and use the Internet daily to do homework, blog with their friends and teacher, and email their mom; it is second nature to them.  My mom and dad can read the newspapers about their daughter on-line and can reach me anywhere in the world from their cell phone to mine.  And people all over the world can post and watch videos and read our blogs within minutes of completion.  I can’t imagine my world without this connectivity and I would bet that you cannot either.   Now consider that the same networks that provide this connectively also increasingly help control our critical infrastructure.  These networks deliver power and water to our households and businesses, they enable us to access our bank accounts from almost any city in the world, and they are transforming the way our doctors provide healthcare.  For all of these reasons, we need a safe Internet with a strong network infrastructure and we as a nation need to take prompt action to protect cyberspace for what we use it for today and will need in the future.

Protecting cyberspace requires strong vision and leadership and will require changes in policy, technology, education, and perhaps law.  The 60-day cyberspace policy review summarizes our conclusions and outlines the beginning of a way forward in building a reliable, resilient, trustworthy digital infrastructure for the future.  There are opportunities for everyone—individuals, academia, industry, and governments—to contribute toward this vision.  During the review we engaged in more than 40 meetings and received and read more than 100 papers that informed our recommendations.   As you will see in our review there is a lot of work for us to do together and an ambitious action plan to accomplish our goals.  It must begin with a national dialogue on cybersecurity and we should start with our family, friends, and colleagues.

We are late in addressing this critical national need and our response must be focused, aggressive, and well-resourced.  We have garnered great momentum in the last few months, and the vision developed in our review is based on the important input we received from industry, academia, the civil liberties and privacy communities, others in the Executive Branch, State governments, Congress, and our international partners.  We now have a strong and common view of what is needed to achieve change.   Ensuring that cyberspace is sufficiently resilient and trustworthy to support U.S. goals of economic growth, civil liberties and privacy protections, national security, and the continued advancement of democratic institutions requires making cybersecurity a national priority.

THE WHITE HOUSE - Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure

Office of the Press Secretary
_____________________________________________
FOR IMMEDIATE RELEASE          May 29, 2009

Below is a fact sheet and list of expected attendees at today’s event:

FACT SHEET
In February 2009, President Obama directed the National Security Council (NSC) and Homeland Security Council to conduct a 60-day review of the plans, programs, and activities underway throughout government that address our communications and information infrastructure (i.e., "cyberspace"), in order to develop a strategic framework to ensure that the U.S. government’s initiatives in this area are appropriately integrated, resourced, and coordinated.

Threats to the information and communications infrastructure pose one of the most serious economic and national security challenges of the 21st Century for the United States and our allies.  In this environment, the status quo is no longer acceptable, and a national dialogue on cybersecurity must begin today.  The U.S. Government cannot succeed in securing cyberspace in isolation, but it also cannot entirely delegate or abrogate its role in securing the Nation from a cyber incident or accident.  Ensuring that cyberspace is sufficiently resilient and trustworthy to support U.S. goals of economic growth, civil liberties and privacy protections, national security, and the continued advancement of global democratic institutions requires working with individuals, academia, industry, and governments.  We must make cybersecurity a national priority and lead from the White House.

The review team’s report to the President contains five main chapters, outlined below, and includes a near-term action plan for U.S. Government activities to strengthen cybersecurity.

       (U) Chapter I: Leading from the Top – Makes the case for strengthening cybersecurity    leadership for the United States through 1) the establishment of a Presidential cybersecurity policy official and supporting structures, 2) reviewing laws and policies, and 3) strengthening cybersecurity leadership and accountability at federal, state, local, and tribal levels.
       (U) Chapter II: Building Capacity for a Digital Nation – Advocates a national dialogue on cybersecurity to increase public awareness of the threats and risks and how to reduce them.  Outlines the need for increased education efforts at all levels to ensure a technologically advanced workforce in cybersecurity and related areas, similar to the United States’ focus on mathematics and science education in the 1960s.  Identifies the need to expand and improve the federal information technology workforce and for the Federal government to facilitate programs and information sharing on cybersecurity threats, vulnerabilities, and effective practices across all levels of government and industry.
        (U) Chapter III: Sharing Responsibility for Cybersecurity – Discusses the need for improving and expanding partnerships between the Federal government and both the private sector and key U.S. allies.
        (U) Chapter IV: Creating Effective Information Sharing and Incident Response – The United States needs a comprehensive framework to facilitate coordinated responses by government, the private sector, and allies to a significant cyber incident.  This chapter explores elements of such a framework and suggests enhancements to information sharing mechanisms to improve incident response capabilities.
        (U) Chapter V: Encouraging Innovation – The chapter addresses ways for the United States to harness the benefits of innovation to address cybersecurity concerns, including work with the private sector to define performance and security objectives for future infrastructure, linking research and development to infrastructure development and expanding coordination of government, industry, and academic research efforts.  It also addresses supply chain security and national security / emergency preparedness telecommunications efforts.

Expected attendees at today’s East Room event:

Secretary Steven Chu, Department of Energy
Secretary  Janet Napolitano, Department of Homeland Security
General James Jones, National Security Advisor
Deputy Secretary William Lynn, Department of Defense
Deputy Secretary Neal Wolin, Department of Treasury
Lawrence Summers, Director of the National Economic Council
Lynne Osmus, Acting Administrator of the Federal Aviation Administration
Jon Wellinghoff, Chairman of the Federal Energy Regulatory Commission
Michael Copps, Acting Chairman of the Federal Communications Commission
Jon Leibowitz, Chair of the Federal Trade Commission
James Cartwright, Vice Chairman of the Joint Chiefs of Staff
Robert Mueller, Director of the Federal Bureau of Investigation
John P. Holdren, Director of the Office of Science and Technology
John Kimmons, Lieutenant-general, Director of National Intelligence Office
John O. Brennan, Assistant to the President for Homeland Security and Counterterrorism
Maryland Governor Martin O’Malley, Chair of National Governors Association, Homeland Security Committee
Congressman Bart Gordon
Congressman Peter King
William Pelgrin, Chair of the Multi-State Information Sharing and Analysis Center
Heather Hogsett, National Governors Association, Director, Public  Safety and Homeland Security Office of Federal Relations

THE WHITE HOUSE - Statement by the President on the White House Organization for Homeland Security and Counterterrorism

FOR IMMEDIATE RELEASE – May 29, 2007

 

Office of the White House Press Secretary

As President, my highest priority is the safety and security of the American people. That is why, in February, I issued a Presidential Study Directive to look at how the White House should be organized to deal with the critical issues of homeland security and counterterrorism.  I have carefully reviewed the findings and recommendations of that study, and am announcing a new approach which will strengthen our security and the safety of our citizens. These decisions reflect the fundamental truth that the challenges of the 21st Century are increasingly unconventional and transnational, and therefore demand a response that effectively integrates all aspects of American power.  

Key decisions that I have made include:

  • The full integration of White House staff supporting national security and homeland security.  The new "National Security Staff" will support all White House policymaking activities related to international, transnational, and homeland security matters.  The establishment of the new National Security Staff, under the direction of the National Security Advisor, will end the artificial divide between White House staff who have been dealing with national security and homeland security issues.    
  • Maintaining the Homeland Security Council as the principle venue for interagency deliberations on issues that affect the security of the homeland such as terrorism, weapons of mass destruction, natural disasters, and pandemic influenza.  The Homeland Security Council, like its National Security Council counterpart, will be supported by the National Security Staff.
  • The establishment of new directorates and positions within the National Security Staff to deal with new and emerging 21st Century challenges associated with cybersecurity, WMD terrorism, transborder security, information sharing, and resilience policy, including preparedness and response.
  • Retaining the position of Assistant to the President for Homeland Security and Counterterrorism (AP/HSCT) as my principal White House advisor on these issues, with direct and immediate access to me.  The security of our homeland is of paramount importance to me, and I will not allow organizational impediments to stand in the way of timely action that ensures the safety of our citizens.
  • Creating a new Global Engagement Directorate to drive comprehensive engagement policies that leverage diplomacy, communications, international development and assistance, and domestic engagement and outreach in pursuit of a host of national security objectives, including those related to homeland security.

The United States faces a wide array of challenges to its security, and the White House must be organized to effectively and efficiently leverage the tremendous talent and expertise of the dedicated Americans who work within it.  The creation of the National Security Staff and the other recommendations from the study that I have approved will help to keep our country safe and our Homeland secure.   

###

Tuesday, May 26, 2009

Whitehouse to Release Long Awaited Cyber Security Report May 29th

By Kevin M. Nixon, MSA, CISSP©, CISM©, CGEIT©

Washington, DC – Tuesday, May 26, 2009 – 3:00 pm ET

The Whitehouse made the following statement today at the daily Press Office Press Briefing by Whitehouse Press Secretary Robert Gibbs.

60-Day Cyber Space Policy Review Report To be released May 29th, 2009

“The President will release the 60-Day Cyber Space policy review report at the Whitehouse on Friday, May 29, 2009. The administration recognizes the very serious threats Public & Private sector Networks face from cyber-crime and cyber-attack. Recognizing these threats the President has elevated cybersecurity to a major administration priority by undertaking an early comprehensive interagency review. The administration is also committed to establishing the proper structure within the government to insure that cybersecurity issues continue to receive top-level attention and enhanced coordination. The report is an important first step toward securing the nation’s cyber-infrastructure.”

In the early edition of Washington Post, staff writer by Ellen Nakashima in her article entitled “Obama Set to Create a Cybersecurity Czar with Broad Mandate - Shielding Public, Private Networks Is Goal” reported “President Obama is expected to announce late this week that he will create a "cyber czar," a senior White House official who will have broad authority to develop strategy to protect the nation's government-run and private computer networks, according to people who have been briefed on the plan. The adviser will have the most comprehensive mandate granted to such an official to date and will probably be a member of the National Security Council but will report to the national security adviser as well as the senior White House economic adviser, said the sources, who spoke on the condition of anonymity because the deliberations are not final.

The announcement will coincide with the long-anticipated release of a 40-page report that evaluates the government's cybersecurity initiatives and policies. The report is intended to outline a "strategic vision" and the range of issues the new adviser must handle.

Kevin has testified as an expert witness before the Congressional High Tech Task Force, the Chairman of the Senate Armed Services Committee, and the Chairman of the House Ways and Means Committee. He has also served on infrastructure security boards and committees including the Disaster Recovery Workgroup for the Office of Homeland Security, and as a consultant to the Federal Trade Commission.

The Author gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com.

Powered By Blogger