Risk
5/6/2010
05:08 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Federal Security Chiefs Take On Enhanced Strategic Role

A new survey of chief information security officers in government shows the job is becoming more policy oriented, with funding and shared services among their priorities.

Chief information security officers in federal government see their jobs becoming more policy-oriented, a new survey finds.

The survey, conducted by cybersecurity certification organization (ISC)2, consulting firm Garcia Strategies, and Cisco Systems, found that 55% of CISOs find their jobs gravitating more toward politics and policy. Only 26% see their jobs becoming more technical in nature.

"It's clear that federal CISOs understand that their roles are becoming more strategic," said David Graziano, operations director for security in Cisco's U.S. public sector group, in an interview. "There's better alignment with the idea of driving agency protection and with the agency CIOs on a policy level."

Though the survey didn't ask for reasons for this swing, it may be partly attributable to the growing scrutiny that Congress, the Obama administration, and the public have placed on government cybersecurity for at least the last year. Influencing factors include the release of numerous reports and bills and the appointment of new cybersecurity leadership in many parts of government, including a new cybersecurity coordinator in the White House.

More than half of CISOs, 56%, aren't satisfied with the way Congress has been handling cybersecurity issues.

CISOs seem to be more accepting of the Department of Homeland Security's Einstein intrusion detection and prevention system and strategy and the Internet gateway-consolidating Trusted Internet Connections initiative, both of which they characterized as frustrating in last year's survey.

One of the big issues in government cybersecurity circles is cloud computing. Almost 45% of federal CISOs surveyed express concern about their ability to replicate on-premise security policies in the cloud, and 21% cite concern over data loss prevention.

In terms of advice for new federal cybersecurity coordinator Howard Schmidt, appointed by the White House to oversee federal cybersecurity efforts, survey respondents ranked funding, shared security service implementation, and coordination with the private sector as top priorities.

Open government represents another challenge for CISOs. More than 74% say their agencies have data security policies in place to reconcile the need for both information transparency and protection, and 78% have Web 2.0 security policies in place.

InformationWeek has published an in-depth report on energy-efficient government data centers. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.