Alexander, Rogers Appeal for Cybersecurity Legislation While Lute Says It's a Sure Thing


(Washington, DC) National Cybersecurity Awareness Month is not even upon us yet but the DC hype meter tilted into the red today with three dueling cybersecurity events, each populated by prominent panelists who propounded on their pet topics and theories surrounding the state of systems security.  Some attendees moved from event to event throughout the day, catching one set of speakers and then moving on to the next venue.

The speakers across all three events ranged from the highly technical to the highly political, with most emphasizing the need for better cybersecurity policy and practices.  If one common theme emerged across the two dozen-plus speakers and panelists it is the need for a cyber bill which, at the minimum, facilitates information sharing and encourages better conformance to good cyber schemes.

One day-long event was hosted at the National Press Club (keynote videos here) and generated the most buzz due to its opening keynote speaker, embattled National Security Agency (NSA) Director Keith Alexander.  Alexander first castigated what he considered the media leaks flowing from former contractor Edward Snowden and then shifted into a plaintive plea for help from the public and private industry in maintaining the vast electronic intelligence apparatus his agency has built.

"We first have to address media leaks," Alexander said.  Speaking of the call records collection authorized by the Foreign Intelligence Surveillance Court, Alexander attempted again to explain, as he has many times over the past several months, that media coverage has distorted the kinds of information NSA collects, reiterating that the bulk of the collection focuses on metadata, comprising call details such as date, time, length of call, and not on the content of the calls.  "It’s been sensationalized and inflamed in much of the reporting that we’re listening to people’s calls and reading their emails.  That’s flat wrong."

Alexander frequently asked for help and support in maintaining NSA's activities, saying that the security of the nation depends on the efforts of his and other intelligence groups.  "Our mission is to have to defend this country," he said.  "We can’t do it without your help and without the tools that the nation needs."

He also appealed on behalf of those Internet and technology companies that supply data to NSA, stressing that they only do so under court order.  "Industry isn't driving up to NSA, dumping off U.S. persons' or foreign person's data to us," he said.  "What they’re doing is they’re providing what the courts have directed for them to provide."

He walked through a series of statistics about the "incidents" or "violations" that have occurred with the data NSA collects, saying that only 5% involve U.S. persons, and even then mostly involve typos and not deliberate privacy invasions.  Most of the NSA personnel engaged in the violations either retired, resigned or were appropriately admonished.  "What that means for you and the American people is that you are guaranteed that we will do everything we can to protect your civil liberties and your privacy and defend this country," he said.

At one other big cybersecurity event, hosted by the U.S. Chamber of Commerce, House Intelligence Committee Chairman Mike Rogers (R-MI), bemoaned how much more difficult it now is to pass cybersecurity legislation due to the controversy triggered by the Snowden leaks.  Rogers, like Alexander, hopes that Congress can move past the drama and enact effective cybersecurity legislation.

He was specifically referring to a bill he co-sponsored, the Cyber Intelligence Sharing and Protection Act (CISPA), which would facilitate cyber threat information sharing.  "I haven't given up on CISPA," Rogers said.

At the third cybersecurity event of the day, hosted by DC lobbying and law firm Venable, Jane Holl Lute, CEO of the Council on CyberSecurity and former Deputy Secretary of the Department of Homeland Security (DHS), said that cybersecurity legislation is practically a sure thing.  "I think it's a near certainty that there will be legislation regarding cybersecurity," she said.

A big factor that will drive Congress is the failure of the marketplace to provide adequate security in the cyber realm.  "Of those who say they want to keep government out, government will step in...because frankly we're at an unacceptable level of vulnerability and the market is not taking care of that," Lute said.

NIST Cybersecurity Framework Subject to Major Work Ahead of Public Comment


The National Institute of Standards and Technology (NIST) is racing the clock to whip into shape the comprehensive cybersecurity framework mandated by President Obama's February executive order.  As my most recent piece for CSO Magazine highlights, critical infrastructure providers say there is a lot of work to get done before the framework, a first-time government effort to bolster better cybersecurity across all critical infrastructure, is published in the Federal Register on October 10 and put out for public comment.

The final framework is due in February, but when it comes to the constantly changing world of cybersecurity, the framework could keep evolving indefinitely.  As Patrick Gallagher, the head of NIST, saiid, "in my view the framework is never finished."

Check out the full article here.

NIST's Latest Draft Cybersecurity Framework: Not Yet Ready for Primetime


The National Institute of Standards and Technology (NIST) released the latest version of its draft cybersecurity framework on August 28 and the reviews are...mixed.  The voluntary framework, mandated under President Obama's February executive order and intended to help critical infrastructure providers establish better cybersecurity programs, needs a lot more work, experts say, despite the greater detail NIST provided between versions one and two of the document.

But little time remains between a final workshop on the framework that NIST will host in Dallas next week and the October 10th deadline for publishing the preliminary framework in the Federal Register.  Read my latest take on the framework in this article commissioned by CSO Magazine.

Image from the August 28th document released by NIST.

China Not Out to Destroy the Electric Grid or Other Networks, Former NSA, CIA Director Hayden Says


U.S. networks, including the electric grid, are less threatened by cyber attacks from nation-states than from damage inflicted by rogue entities such as web activists, former CIA and NSA Director Michael Hayden said today.  And although China is a major cyber threat from an economic perspective, it does not seem a likely source of destruction to U.S. networks.

"Without question the country that is out there stealing most of our stuff is China," Hayden said at a Bipartisan Policy Center conference on protecting the electric grid from cyber threats.  "There is evidence that they are out there on SCADA networks as well as just penetrating networks just to steal our stuff."

But, Hayden said, "frankly I find it hard to imagine circumstances where China would want to do something incredibly destructive to any American network, the grid, absent a far more problematic international environment in which the cyber attack itself is part of a larger package of really, really bad things."

The real threat to the grid and other networks may not be nation-states such as China or criminals out to make a buck but unpredictable rogue players, including terrorist groups and web transparency activists. "Sooner or later governments can be held to account.  Fundamentally criminals want to make money and they enter into a symbiotic relation with the host," Hayden said.

Those loosely defined players, though, are "beginning to acquire capacities that a year or two or three ago we equated with the more competent groups" and their "demands may be unsatisfiable," according to Hayden. "This is going to get worse before it gets better."

The philosophy embedded in the U.S. Constitution makes it hard to create adequate cyber defenses because "we have not yet created a consensus as to what we want our government to do..or what we will let our government do," Hayden said.  "I’m willing to accept the proposition that forever the United States will have one of the least well-defended networks on this planet because of James Madison and Alexander Hamilton and all of those good folks who wrote the Federalist papers."

Addressing the revelations flowing from the leaks of former NSA contractor Edward Snowden, Hayden said that the ensuing fears of an overly aggressive government will "freeze" the government's ability to protect private industry and that private industry must learn to protect itself.  "The next sound you hear will not be a bugle and the sound of pounding hoofs as the federal cavalry comes over the ridge line to your rescue," he said. "To the degree that you never expected it down here in the physical domain, you are responsible for your safety in the digital domain personally and corporately."

The federal government, though, needs to step up its cybersecurity efforts, particularly in the arena of information sharing, electric industry representatives speaking at the same event said.  Speaking of state regulator capabilities for addressing cybersecurity issues, Doug Myers, CIO of Pepco Holdings, said "if the conversation at the state level could be informed by a clear and compelling federal vision…I think would be very helpful."

"The issue has to be addressed at the federal level," Ed Goetz, VP of Corporate and Information Security at Exelon said. "I think the president’s executive order opened the door to this possibility."

However, information sharing works best as a two-way street, Scott Saunders, Information Security Officer at Sacramento Municipal Utility District said.  "if we pull together in a more cohesive manner we can provide information back to the government about what is happening to us."

Is it “Cybersecurity,” “Cyber Security” or (Please No) “Cyber-Security?" I Asked the Experts.


While conducting a search of a government database, I encountered a problem all too common for those interested in the topic of security in the digital realm.  Namely, the frequency with which the topic is spelled and written in three different ways –  “cybersecurity,” or “cyber security” or, far less frequently, “cyber-security.”

In conducting my search, I realized that my analysis would be inaccurate and incomplete if I didn’t search at least three different ways using the three different spellings.  Frustrated, I tweeted that we should all settle on one common spelling and I picked cybersecurity for ease of use.

That was not the right answer it seems. One immediate response I received, from Jeffrey Carr, CEO of Security Firm Taia Global and author of Inside Cyber Warfare:  Mapping the Cyber Underworld, is to stop making up words.
The problem is that the world is making up words, not me, and there is almost no consistency among writers, scientists, official government usage, corporations or anybody else about the proper spelling for a word or phrase that everyone is using a lot these days.   While it might seem merely annoying and trivial, the answers you receive when searching for information on this topic can vary depending on how you spell the term.  In my case, the data I was compiling told me something completely different if I only used one or the other phrase – I would have reached the wrong conclusion if I didn’t take the extra steps to conduct three different searches.

It really doesn’t matter which resource you turn to, Google or scientific or engineering or government databases, the variation in spelling poses problems.  Searches on Google produce different, and differently ranked, results depending on how you spell it.  Here’s what you might think the top news items were this morning if you conducted a Google search for “cybersecurity:”


Here’s what you might think the top news items were this morning if you conducted a Google search for “cyber security:”
And forget searching on “cyber-security.”  Here's a search I conducted yesterday which features in the top three news items all three variants of spelling and usage.
But what if you’re searching for technical information on the topic, where the difference in results might matter more?  The same annoying outcome occurs – what you see depends on how you spell it.  Here are the top three search results from the IEEE database using “cybersecurity.”

Here are the top three search results from the same database using “cyber security.”  No overlap at all and differently prioritized answers.
Hoping to contribute to clarity on this problem and advocate a single solution, I polled some of the top experts on neologisms, the creation of new words, to see if there is a correct usage that we can huddle around over time.  Here are the answers I received:

Suzanne Kemmer, Associate Professor of Linguistics at Rice University:
From the standpoint of the usual lexical conventions, cybersecurity is better, because 'cyber' is not a free-standing word but instead what linguists call a bound morpheme - a combining form used to form new words. It is of Classical Greek origin like many of our scientific and technical vocabulary elements-- and the usual pattern for such borrowings is to combine them with other elements into one word. Bio, neo, photo are all parallel examples - when made into new compounds they are written together with the element following: not bio informatics but bioinformatics, etc.

Sometimes a group of specialists will make their own convention, but the language at large typically doesn't follow it because there are so many instances of the more general pattern. It looks like that has happened in the technical community in this case . They probably don't know the general lexical patterns of English and just have made their own specialists' convention. I predict that for this word the general (one-word) pattern will win out in the language at large.

David K. Barnhart, Editor, The Barnhart DICTIONARY COMPANION:
The search of Nexis [which Barnhart prefers when searching for usage frequency] suggests that the usage of these terms in the United States is dominated by cybersecurity while British and World English usage appears to prefer cyber security.  Cyber-security is the least prominent of the possibilities.  So, I guess, this has been a long-winded way of getting around to saying: It may depend on where you live.

Wayne Glowka, Professor of English and Dean of the School of Arts and Humanities, Reinhardt University:
You have come across a common occurrence with compound words. Typically, they start as two-word phrases. In time, you will see them as hyphenated words and then as compound words written as one word. Different dictionaries will offer different ways of spelling them, often noting that all three forms are acceptable.

Normally, a good linguistic sign that we have a compound word in American English is stress on the first syllable. So the phrase "black bird" (as in "I see some kind of black bird over there") has its strongest stress on "bird." The compound word "blackbird" has its strongest stress on "black."

The big exception to the congruence of spelling and pronunciation is the compound word "White House" (the house with the POTUS lives). It is stressed like a compound word (WHITE house), but it is spelled like a phrase.

Figuring out the most strongly stressed syllable of "cybersecurity" vs. "cyber security" would be a challenge akin to pronouncing the difference between "a light housekeeper" and "a lighthouse keeper." And where is the stress in "an elevator operator"?

Ben Zimmer, Executive Producer of Vocabulary.com and the Visual Thesaurus, language columnist for The Wall Street Journal, and former language columnist for The Boston Globe and The New York Times Magazine:
As it happens, I recently wrote about "cyber-" and "cyber" in my Wall Street Journal column.

Historically, "cybersecurity" has been the standard form, since "cyber-" has been understood as a combining form, not a standalone word. But as I describe in the column, "cyber" is increasingly being viewed as a word on its own, either as an adjective or a noun. So the fact that we now have phrases like "Cyber Monday" encourages people to think of "cyber" as an adjective (or possibly an attributive noun) modifying the noun it precedes.

So while I would personally prefer "cybersecurity," I can see how "cyber security" could eventually displace it.

-----------------------------

So, with all that, here’s what we know about which term is more correct:  not much.  While the preference leans toward “cybersecurity,” it might depend on where you live, what you’re trying to emphasize or whether you’re part of a technical community that for its own reasons prefers to use one or the other term. But seriously it would be great if we all just agreed on one form over the other.

I vote for cybersecurity.

NIST Cybersecurity Framework Gets a Lot of Love from Congress in Oversight Hearings


Over the past eight days both the House of Representatives and the Senate have held oversight hearings on the voluntary critical infrastructure cybersecurity framework that the National Institute of Standards and Technology (NIST) is developing pursuant to President Obama’s February 12, 2013 executive order.   On July 18, the House Homeland Security’s Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies held a hearing on the development of the framework, which was followed by a Senate Commerce Committee hearing yesterday on the partnership between NIST and the private sector to hammer out the framework.

Little in the way of controversy or news emerged during either hearing, with both arms of Congress expressing strong support for the NIST initiative, which will appear in preliminary form in October and final form in February 2014.  “I believe that the outline of NIST’s framework provides an important step to increasing our nation’s awareness and ability to protect our networks from crippling cyber attacks,” House Subcommittee Chairman Patrick Meehan (R-PA) said.

“Getting NIST involved in cybersecurity makes a lot of sense, because NIST already has decades of experience working with the private sector on computer security issues,” Senator Jay Rockefeller (D-WV), Chairman of the Senate Commerce Committee said.  Rockefeller along with Ranking Member John Thune (R-SD) have introduced a bill, The Cybersecurity Act of 2013, that will codify into law the voluntary framework that NIST produces, legislation that Rockefeller said yesterday will go to mark-up before Congress recesses in August.

All of the witnesses at both hearings said that the framework process is humming along nicely.  “I’m actually quite excited by the progress we have made and the response we’ve got from the private sector,” Charles Romine, Director of NIST’s Information Technology Laboratory told the House Subcommittee, referring to the three workshops NIST has held with the private sector in developing the framework. “We’ve achieved over the course of a relatively short time a consensus on the framework.”

And all of the witnesses said that the framework is an excellent initiative to tackle the cybersecurity challenges that industry and government face.  “The approach to the cybersecurity framework set out in the executive order will allow  industry to protect our nation from the growing cybersecurity threat while enhancing America’s ability to innovate and compete in a global market,” NIST Director Patrick Gallagher told the Senate Committee.

A few interesting points were briefly touch upon in both hearings.  The first is whether Congress should recommit to passing comprehensive cybersecurity legislation.  During the waning days of the last Congress, efforts to pass tougher cybersecurity legislation were derailed in the face of opposition by both industry interests and privacy advocates, prompting President Obama to issue his executive order to compensate for the failure.

“I have concerns that a self-assessment may not be sufficient to incentivize action to bolster cyber defenses,” Rep. Meehan said during the Subcommittee hearing, referring to the public-private partnership underlying the voluntary standards. “Ultimately, I believe it is the consensus of this committee that Congress must pass legislation, in order to address many of these outstanding issues.”

Meehan was specifically referring to cyberthreat information-sharing among private sector and government entities which most experts believe requires an act of Congress.  Rockefeller, who is also a member of the Senate Intelligence Committee, said during yesterday’s hearing that the Intelligence Committee plans to introduce a bill that would permit and facilitate information sharing.

A related issue is the degree to which the voluntary standards should ever become mandatory requirements either through legislation or existing or new regulatory authorities.   “If we can create confidence in the marketplace [with the framework] then I don’t think government needs to get involved,” Robert Kolasky, Director of the Integrated Task Force assigned with implementing the executive order at the Department of Homeland Security, told the House Subcommittee.

As to whether regulatory or other government agencies can enforce the framework in some fashion through their existing authorities, a subject of examination under the executive order, “until the agency actually tries to create regulations one doesn’t really know what’s going to happen,” Eric Fischer, Senior Specialist at the Congressional Research Service told the House Subcommittee.  “If they do have the authority they may do it anyway.”

NIST Closer to Solidifying Critical Infrastructure Cybersecurity Framework


The National Institute of Standards and Technology (NIST) held in San Diego last week the third of four workshops to develop a comprehensive cybersecurity framework for critical infrastructure as required under an executive order signed by President Obama on February 12, 2013.  As my latest piece for CSO discusses, it won't be clear what the 500 participants produced until NIST releases its summary document later this month.

But several cracks in the process continued to emerge during the workshop, including doubts about whether NIST is trying to recreate the wheel, whether enough critical infrastructure sectors are actually participating in the process, whether DHS and NIST are coordinating well enough and whether this whole thing might slip from the voluntary to the mandatory category.

Check out the piece here.

Twitter Delicious Facebook Digg Stumbleupon Favorites More