Risk

1/30/2008
10:27 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Federal Government To Spend $30 Billion On New Security Efforts

One of the most interesting IT security news stories to hit this week is that the Bush administration is apparently proposing $6 billion (maybe this is an increase on existing spending. That's not yet clear) be invested to shore up federal network security next year, and up to $30 billion across seven years. This is good news. Maybe.

One of the most interesting IT security news stories to hit this week is that the Bush administration is apparently proposing $6 billion (maybe this is an increase on existing spending. That's not yet clear) be invested to shore up federal network security next year, and up to $30 billion across seven years. This is good news. Maybe.There's little in the way of details on how this money will be spent. All we know is that the Bush administration is proposing about $6 billion be spent, starting next year, with $30 billion over the next seven years, to improve the security of U.S. communication networks.

It's about time the federal government, including this administration, got serious about IT security. There's been plenty of lip service flapped about since 2001 -- but except for some improvements in FISMA (Federal Information Security Management Act), and better focus on IT security from NIST, little has been done.

The so-called plan to secure cyberspace has done nothing but collect dust. Part of this plan to protect communication systems includes reducing the number of Internet connections to government systems, and the use of sensors to detect intrusions.

All that makes sense. And would be a good start.

But $6 billion? Unless you are a close follower of the security market, that may not seem to be a startling figure to you. But it is an astonishingly high figure. And $30 billion -- even over a handful of years -- is absolutely astronomical.

To give you an idea of how big an investment in network security that is, last year Infonetics Research estimated the entire worldwide network security appliance and software market to have reached $5 billion in 2007.

That means that the entire network security hardware and software market -- worldwide -- is $2 billion less than what the federal government may spend to secure U.S. communication networks in one year.

Something else is going on here.

Unfortunately, the White House is being tight-lipped about the plan, citing that to explain the plan publicly would jeopardize security.

And here I thought security-by-obscurity went out of fashion a few years ago. Aside from the feds publishing password, private keys, or explaining where the IDS sensors will lay, among other obvious no-nos, detailing the essence of this security plan will not reduce its effectiveness.

There's more details on the plan here. While it's great to see a real investment by the federal government on IT network security, we need more details to judge how well this money is being spent.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11505
PUBLISHED: 2018-05-26
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
CVE-2018-6409
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVE-2018-6410
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CVE-2018-6411
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CVE-2018-11500
PUBLISHED: 2018-05-26
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.