phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, please share.


ISC StormCast for Monday, February 6th 2012 http://isc.sans.edu/podcastdetail.html?id=2305

Cybersecurity Legislation Components

Published: 2012-02-05,
Last Updated: 2012-02-05 02:43:14 UTC
by Tony Carothers (Version: 1)
Rate this diary:

1 comment(s)

As many of us have seen in the media recently, the United States and other world governments are deeply entrenched in discussions over proposed cybersecurity legislation.  There are many different flavors of legislation currently being discussed by governments across the globe, of which I don’t intend to cover here.  In the US it appears the government has finally started to address cybersecurity issues that have been discussed in this forum for years. One piece of the legislation currently being discussed is a proposal sponsored by Rep. Dan Lungren (R-Calif.) is House Resolution 3674 - the Promoting and Enhancing Cybersecurity and Information Sharing Enhancement Act of 2011 or PrECISE.  The thrust of the bill is “to amend the current Homeland Security Act of 2002" which will give additional authority to the US Government in the national cybersecurity effort.


I want to highlight some of the ideas being presented in this bill and how they are going to be a huge win for the cyber security community.  These are just a few of the items being discussed, but these will pay huge dividends in the security effort.

The coordination and sharing of information between the civilian and government agencies is one of the topics some of the bills being considered address, and is a critical component in the cybersecurity effort.  As it is written in PrECISE SEC. 2. Sec.226 (2) “foster the development, in conjunction with other governmental entities and the private sector, of essential information security technologies and capabilities for protecting Federal systems and critical infrastructure information systems, including comprehensive protective capabilities and other technological solutions”.  Organizations that have previously developed implementation strategies for information systems have a leg up on organizations that have not.  The Black Hat community has excelled at this type of sharing, and has been an excellent vehicle for their efforts.   They are not impeded by corporate policy, federal guidelines, or other governing regulations. 

The silos of information that exist in the enterprise today have also led to silos of security information.  The production, collection, and correlation of that information is often difficult because different vendor technologies, implemented at different stages, lead to disparate systems.  PrECISE SEC. 2, Sec 226 Para. (3) states the need to “acquire, integrate, and facilitate the adoption of new cybersecurity technologies and practices in a technologically and vendor-neutral manner to keep pace with emerging terrorist and other cybersecurity threats”.  There are many great minds and methods to approach this, and the solution will not be easy.  It is a critical solution that needs to be addressed.

User awareness and education is critical for every aspect of information security.  With the increase of reliance on technology throughout, the importance of user education increases accordingly.  PrECISE SEC. 2, Sec 226 Para.(6) states “develop and lead a nationwide awareness and outreach effort to educate the public about--
-(A) the importance of cybersecurity and cyber ethics;
-(B) ways to promote cybersecurity best practices at home and in the workplace; and
-(C) training opportunities to support the development of an effective national cybersecurity workforce and educational paths to cybersecurity professions” 

User education and awareness training, coupled with the information sharing efforts mentioned in Para. (2) will go a long way towards improving the overall security of the information and systems we use every day.
 

I am excited to see the governments taking cybersecurity seriously, and hope the politicians can produce something that is useable and applicable to the world today.  The implementation of some of the ideas discussed in this bill will be a huge undertaking, and needs to be done.As a society we have moved beyond the point where cybersecurity is merely desirable by the people who rely on technology.  it is a fundamental need, and in some instances, desperately.

Tony Carothers

tony d0t carothers at g_mail

Keywords: Policy
1 comment(s)

If you have more information or corrections regarding our diary, please share.

Diary Archive

DateAuthorTitle
2012-02-05 Tony Carothers Cybersecurity Legislation Components
2012-02-04 Scott Fendley Apple Security Advisory 2012-001 v1.1
2012-02-03 Johannes Ullrich Critical PHP bug patched
2012-02-03 Guy Bruneau Sophos 2012 Security Threat Report
2012-02-01 Adam Swanger ISC Feature of the Week: ISC Search
2012-02-01 Russ McRee Apple and Apache security fixes and releases
2012-01-31 Russ McRee OSINT tactics: parsing from FOCA for Maltego
2012-01-31 Russ McRee Firefox 10 and VMWare advisories and updates
2012-01-27 Mark Hofman SSH Password attacks using domain name elements as userid
2012-01-27 Mark Hofman CISCO Ironport C & M Series telnet vulnerability
Folder Icon Complete Archive
Search Diaries:

Diary Tagslink arrow

  javascript     pcanywhere     sophos     maltego     0 day     tcpflow     ddos     zappos     microsoft     mac os x security update     vmware advisory     black tuesday     dns sinkhole     acrobat     microsoft msft patch tuesday patches prerelease     scripting stderr     data breach     printer     html5     ironport     workaround     isc feature     mailbag     windows     dos     opendlp     aspnet     0day     firefox     malware     type a     symantec     policy     windows 7     2012     ssl     adobe     nbns spoofing     wps     dns     stratfor     flash     chrome     java     wifi     whois info     holiday tips     win32ksys     patch     oracle     foca     vulnerability     breach     nmap     vmware patches     microsoft patch tuesday     anonymous     flex     scam     firefox release     apple     holiday greetings     dnssec     php     advertising     webattacks     gtdl     microsoft security bulletin advance notification     netbios     osint     vulnerabilities     exploit     firefox security advisories     cisco     badware     obfuscation     coldfusion     oracle patches     adobe black tuesday     webserver     quarterly     password security     patch tuesday     mac os x     spidermonkey     stratford  
site/port/ip search:

DSHIELD Polllink arrow

What security issue concerns you the most this year?

World Map

world map

Trends

trend graph