Risk
3/21/2011
04:00 PM
Connect Directly
LinkedIn
Google+
Twitter
RSS
E-Mail
50%
50%

How Wall Street Works With The Feds

Banks and other financial firms learn to share sensitive cybersecurity information with federal agencies.

Beyond Info Sharing

What does the relationship look like from the government's perspective? Given that 85% of the nation's critical infrastructure is owned and operated by the private sector, "we can't execute our mission without public-private partnership," says Jenny Menna, director of critical infrastructure cyber protection and awareness with Homeland Security's National Cyber Security Division.

Toward that end, the National Cyber Security Division aims to take an even more active role in working with companies that operate critical infrastructure, such as utilities. Its largest program for critical infrastructure is the one for securing control systems, which monitor and run devices and processes used by utilities, manufacturers, and industrial operations. The DHS works with vendors and operators that build control systems software, and it has a facility at Idaho National Laboratory, where it tests software, dissects malware, and develops and shares mitigation strategies. The agency also runs training programs for energy sector operators and has trained more than 10,000 staff in basic and advanced security.

"We have people on the road doing site assessments, working with owners and operators to look at their security posture," Menna says. The department conducted more than 50 site assessments last year. In addition, Menna's team responds to security incidents, remotely or on site, by providing support and helping with remediation.

The DHS sees its role as going beyond threat assessment and response. Menna talks of helping companies "make the business case" for cybersecurity.

The DHS has formed a cybersecurity working group that includes representatives from the private sector. In addition, the agency meets regularly with security and business execs through roundtables conducted with the U.S. Chamber of Commerce and the National Cyber Security Alliance, with a goal of raising awareness about threats.

"We help CISOs make the case that cybersecurity is a critical part of the integrated risk management process," Menna says. "It needs to be understood by business people in the C-suites and the board. That's what DHS brings to the table."

Go to the main story:
Why Cybersecurity Partnerships Matter

Previous
3 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5142
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the src parameter.

CVE-2010-5302
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

CVE-2010-5303
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.

CVE-2014-0965
Published: 2014-08-21
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.

CVE-2014-3022
Published: 2014-08-21
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.