Risk
3/18/2010
11:40 AM
50%
50%

DHS To Share Intelligence With Some CIOs

A Department Of Homeland Security pilot program allows some state, local, and private-sector officials to access classified information about cyberthreats.

Some public- and private-sector CIOs and chief security officers (CSOs) now have access to intelligence about security threats to critical infrastructure from state and local fusion centers through a new Department of Homeland Security (DHS) pilot program.

Through the program, underway now, CIOs and CSOs from state and local governments as well as private-sector organizations that partner with the federal government will periodically be allowed to read classified e-mails from fusion centers regarding cyber threats, said Amy Kudwa, a DHS spokeswoman.

Fusion centers coordinate counter-terrorist information and data collected by both government agencies and private companies.

CIOs and CSOs taking part in the program may also participate in quarterly cybersecurity briefings and discussions via secure video teleconference and/or audio teleconference, and access classified communications channels in the event of a cybersecurity incident, she said.

Greg Schaffer, the DHS assistant secretary for Cybersecurity and Communications, first publicly referenced the pilot in his remarks at the RSA Conference in San Francisco earlier this month.

The DHS hasn't decided whether or not the pilot will become an actual program and has set no deadline for making that decision, Kudwa said.

The DHS collaborated with the Department of Justice in 2003 to set up fusion centers that coordinate counter-terrorist information and data collected by both government agencies and private companies.

According to the DHS, it has invested more than $327 million to fund fusion centers, of which there are now more than 70, between fiscal 2004 and fiscal 2008.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.