Risk
9/26/2011
03:22 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Homeland Security Revamps Cyber Arm

National Protection and Programs Directorate will add a new deputy undersecretary for cybersecurity and shift other non-cybersecurity responsibilities onto another official.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
The National Protection and Programs Directorate, the Department of Homeland Security agency that handles many of the government's cybersecurity responsibilities is about to get a makeover in the wake of the departure of former deputy undersecretary Phil Reitinger. The directorate, among other things, is in works to secure federal civilian agency networks and coordinate cybersecurity with the private sector.

In an email obtained by InformationWeek, DHS undersecretary Rand Beers announced to staff that, in response to "the growing importance of cybersecurity to DHS and the nation as a whole," DHS is splitting Reitinger's former job in two. DHS will now have one new deputy undersecretary position that exclusively deals with cybersecurity and another that helps protect critical infrastructure, secures federal facilities, and the manages the US-VISIT biometric identity management system used to identify and track foreign visitors.

Beers wrote that the agency would "shortly" announce the name of the permanent deputy undersecretary for cybersecurity, but in the interim, Greg Schaffer, a former Alltel and PricewaterhouseCoopers exec who had been Reitinger's second-in-command since 2009, will serve as acting deputy undersecretary for cybersecurity.

[ The federal government is seeking help in fighting cyber criminals. Read: Feds Seek Advice To Battle Botnets ]

The DHS has taken on a growing role in cybersecurity over the last several years. "This position will help the directorate ensure robust operations and strengthened partnerships in the constantly evolving field of cybersecurity," Beers wrote in the email, the authenticity of which was confirmed by a DHS spokesman.

Whoever takes the new position will have to deal with significant recent turnover in top leadership. In addition to the departure of Reitinger, Sean McGurk, the former director of DHS' National Cybersecurity and Communications Integration Center, left his post effective last Friday, and Randy Vickers, former director of the United States Computer Emergency Response Team (US-CERT), abruptly resigned in July.

In managing US-VISIT, facilities security, and DHS' work with critical infrastructure sectors, the other new deputy undersecretary job, to be filled by long-time intelligence community and congressional staffer Suzanne Spaulding, will continue to have IT-related responsibilities.

Spaulding, who will join DHS in October, was most recently a principal for the Bingham Consulting Group. Spaulding has served as senior counsel to former Sen. Arlen Specter, R-Penn., a top staffer for both the House of Representatives' and Senate's Select Committee on Intelligence, assistant general counsel at the Central Intelligence Agency, and a member of numerous government commissions on national security issues.

In the new, all-digital issue of InformationWeek Government: As federal agencies close data centers, they must drive up utilization of their remaining systems. That requires a well-conceived virtualization strategy. Download the issue now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
8 Key Building Blocks for Enterprise Network Defense
Networks are changing rapidly -- and so are strategies for protecting them. This Tech Digest looks at the fundamentals for the next-gen environment.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In this episode of Dark Reading Radio, veteran CISOs will share their experience and insight into how organizations can get the best bang for their security buck.