Risk
10/6/2010
08:24 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Inside DHS' Classified Cyber Coordination Headquarters

The Department of Homeland Security recently brought its classified National Cybersecurity and Communications Integration Center down to an unclassified level for one day only, and InformationWeek Government was there to take photos. The facility looks and functions like a state-of-the-art network operations center and much more. The NCCIC, as it's called, is the locus of DHS-led inter-agency cybersecurity work in the federal government. That includes providing an integrated response to cyber th
Previous
1 of 11
Next


Typically, the National Cybersecurity and Communications Integration Center, the agency's hub for coordinated responses to cyber attacks, is a classified facility, residing several floors above a chain restaurant in a non-descript Arlington, Va., office building. Visitors to the Department of Homeland Security facility are required to go through several layers of security before they can actually enter the office space, including locking up their cell phones in tiny lockers. But for one day only, the DHS brought the NCCIC offices down to an unclassified level and InformationWeek Government was there to take photos.

The occasion for DHS briefly opening the doors of NCCIC to reporters was a preview of Cyber Storm III, an international, coordinated cybersecurity simulation that entailed mock attacks on the Internet's domain name system. The exercise tested both the draft National Cyber Incident Response Plan, an effort to provide a coordinated response to major cybersecurity incidents NCCIC. The large-scale exercise included representatives from seven cabinet-level federal departments, intelligence agencies, 11 states, 12 international partners and 60 private sector companies in multiple critical infrastructure sectors like banking, defense, energy and transportation. Though the facility may have been brought down to an unclassified level for the event, we were still warned against taking pictures of cyber-analysts' faces, photos of physical security sensors on the walls and ceilings, and wandering off into areas of the facility where classified work might still be going on.

SEE ALSO:

DHS Launches Cyber Attack Exercise

Next Generation Defense Technologies

NSA Official Says Cybersecurity Starts At The Top

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.