Risk
3/21/2011
04:00 PM
Connect Directly
LinkedIn
Google+
Twitter
RSS
E-Mail
50%
50%

How Wall Street Works With The Feds

Banks and other financial firms learn to share sensitive cybersecurity information with federal agencies.

Beyond Info Sharing

What does the relationship look like from the government's perspective? Given that 85% of the nation's critical infrastructure is owned and operated by the private sector, "we can't execute our mission without public-private partnership," says Jenny Menna, director of critical infrastructure cyber protection and awareness with Homeland Security's National Cyber Security Division.

Toward that end, the National Cyber Security Division aims to take an even more active role in working with companies that operate critical infrastructure, such as utilities. Its largest program for critical infrastructure is the one for securing control systems, which monitor and run devices and processes used by utilities, manufacturers, and industrial operations. The DHS works with vendors and operators that build control systems software, and it has a facility at Idaho National Laboratory, where it tests software, dissects malware, and develops and shares mitigation strategies. The agency also runs training programs for energy sector operators and has trained more than 10,000 staff in basic and advanced security.

"We have people on the road doing site assessments, working with owners and operators to look at their security posture," Menna says. The department conducted more than 50 site assessments last year. In addition, Menna's team responds to security incidents, remotely or on site, by providing support and helping with remediation.

The DHS sees its role as going beyond threat assessment and response. Menna talks of helping companies "make the business case" for cybersecurity.

The DHS has formed a cybersecurity working group that includes representatives from the private sector. In addition, the agency meets regularly with security and business execs through roundtables conducted with the U.S. Chamber of Commerce and the National Cyber Security Alliance, with a goal of raising awareness about threats.

"We help CISOs make the case that cybersecurity is a critical part of the integrated risk management process," Menna says. "It needs to be understood by business people in the C-suites and the board. That's what DHS brings to the table."

Go to the main story:
Why Cybersecurity Partnerships Matter

Previous
3 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.