Risk
10/6/2010
08:24 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Inside DHS' Classified Cyber Coordination Headquarters

The Department of Homeland Security recently brought its classified National Cybersecurity and Communications Integration Center down to an unclassified level for one day only, and InformationWeek Government was there to take photos. The facility looks and functions like a state-of-the-art network operations center and much more. The NCCIC, as it's called, is the locus of DHS-led inter-agency cybersecurity work in the federal government. That includes providing an integrated response to cyber th
Previous
1 of 11
Next


Typically, the National Cybersecurity and Communications Integration Center, the agency's hub for coordinated responses to cyber attacks, is a classified facility, residing several floors above a chain restaurant in a non-descript Arlington, Va., office building. Visitors to the Department of Homeland Security facility are required to go through several layers of security before they can actually enter the office space, including locking up their cell phones in tiny lockers. But for one day only, the DHS brought the NCCIC offices down to an unclassified level and InformationWeek Government was there to take photos.

The occasion for DHS briefly opening the doors of NCCIC to reporters was a preview of Cyber Storm III, an international, coordinated cybersecurity simulation that entailed mock attacks on the Internet's domain name system. The exercise tested both the draft National Cyber Incident Response Plan, an effort to provide a coordinated response to major cybersecurity incidents NCCIC. The large-scale exercise included representatives from seven cabinet-level federal departments, intelligence agencies, 11 states, 12 international partners and 60 private sector companies in multiple critical infrastructure sectors like banking, defense, energy and transportation. Though the facility may have been brought down to an unclassified level for the event, we were still warned against taking pictures of cyber-analysts' faces, photos of physical security sensors on the walls and ceilings, and wandering off into areas of the facility where classified work might still be going on.

SEE ALSO:

DHS Launches Cyber Attack Exercise

Next Generation Defense Technologies

NSA Official Says Cybersecurity Starts At The Top

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

CVE-2014-3991
Published: 2014-07-11
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hide_leftmenu, (6) mainmenu, or (7) leftmenu pa...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.