Welcome Guest. | Log In | Register | Membership Benefits

Commerce Department Proposes Voluntary Security Best Practices For Businesses

DNSSec gets the nod as a key ingredient to the "codes of conduct" to strengthen the cybersecurity of online commerce

Jun 08, 2011 | 11:18 PM | 

By Kelly Jackson Higgins
Dark Reading
The Obama administration today published a green paper calling for voluntary codes of conduct aimed at beefing up security for online business, including adopting DNSSec and creating incentives such as cyber insurance premiums.

The U.S. Commerce Department report proposes several voluntary best practices for organizations outside of the critical infrastructure sector doing business online in its new "Cybersecurity, Innovation and the Internet Economy" report. Written by the Internet Policy Task Force at Commerce, the report recommends national, voluntary "codes of conduct" to reduce the security vulnerabilities such as DNSSec; incentives such as the reduction of cyber-insurance premiums for organizations that employ best practices and that share information about cyberattacks with others; public education on cybersecurity threats and weaknesses; and better global collaboration in cybersecurity.

But it was the report's shout-out to DNSSec that caught the attention of security experts. Renowned researcher and DNS expert Dan Kaminsky says this is yet another example of how DNSSec is catching on. "There are two things we are not used to in security: good news and engineering projects that take a few years," Kaminsky says. "DNSSec is special in that it really has been a complicated, extraordinarily long engineering effort and political effort … It's been a massive project, but it's working."

Kaminsky is the author of the open source Phreebird Suite 1.0, a real-time DNSSEC proxy that sits in front of a DNS server and digitally signs its responses.

DNSSEC has hit several milestones over the past year, with the root servers being signed and then, the .com domain following several other big domains like .gov and .edu.

"You're seeing the Department of Commerce really throwing its weight behind this," Kaminsky says. "If you're going to have a secure Internet, you're going to need to be able to authenticate servers and systems. We can't do that now with what we have, but we can do that with DNSSec."

The Commerce Department's Internet Policy Task Force plans to work with businesses to come up with security best practices that ultimately would be considered industry policy standards—the heart of the codes of conduct.

“Our economy depends on the ability of companies to provide trusted, secure services online. As new cybersecurity threats evolve, it’s critical that we develop policies that better protect businesses and their customers to ensure the Internet remains an engine for economic growth,” Secretary of Commerce Gary Locke said in a statement. “By increasing the adoption of standards and best practices, we are working with the private sector to promote innovation and business growth, while at the same time better protecting companies and consumers from hackers and cyber theft.”

Craig Spiezle, executive director of the Online Trust Alliance, whose organization provided input for the report, applauded the Commerce Department's proposal for businesses to adopt voluntary, accepted best security practices for online commerce. "As participants in the process, the Online Trust Alliance is pleased to see findings that reflect upon the work we've done in promoting private and public sector adoption of best security and privacy practices," Spiezle says.

The report calls for the consideration of providing incentives to businesses that adopt the best practices and codes of conduct for security or share details about attacks to help other businesses -- a reduced premium for cyber-insurance, for instance.

And aside from the National Initiative for Cybersecurity Education, the report calls for coming up with ways to provide cost-benefit analyses for security budgets and purchases and more global cooperation on cybersecurity best practices.

The full report can be downloaded the .comhere (PDF).

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Cloud Security Reports

report Monitoring And Measuring Cloud Providers' Security Performance
There is no ignoring the cloud, which means that IT professionals must find ways to monitor and measure the performance of cloud providers. While moving even in part to a cloud model is a big change for many reasons, the most significant difference is a loss of direct control. Just as security groups often struggle with managing security inside a corporation when in a governance role, we struggle even more with governing the security of assets that no longer sit within our own data centers. The challenge is to develop and implement a strong governance model for these cloud offerings that ensures that security is part of the conversation.

report How to Manage Identity in the Public Cloud
Use of the public cloud for enterprise applications complicates what was already a complicated task: identity management. As companies increase their use of cloud-based applications, IT and security professionals must make some tough and far-reaching decisions about how to provision, deprovision and otherwise manage user access. This Dark Reading report examines the options and provides recommendations for determining which one is right for your organization.

report Spot Trouble In The Cloud: Adapting Security Monitoring & Incident Response.
Security monitoring, incident response and forensics are essential, even in the cloud. But the cloud by definition implies relinquishing at least some control, which can make these practices problematic. In this report, we identify the challenges of detecting and responding to security issues in the cloud and discuss the most effective ways to address them.

Other reports from the Cloud Security Tech Center:




Featured Webcasts
Featured Whitepapers
Featured Reports