Risk
3/3/2010
07:45 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

RSA: DHS Chief Launches Cybersecurity Competition

Secretary of the Department of Homeland Security, Janet Napolitano, is asking for help to engage the public in a discussion about cybersecurity.

Speaking at the RSA Conference in San Francisco on Wednesday, Secretary of the Department of Homeland Security (DHS) Janet Napolitano announced the National Cybersecurity Awareness Campaign Challenge Competition, a contest to solicit ideas from individuals and industry about how to best engage the American public in a discussion about cybersecurity.

"A secure cyber environment is as much about people and habits and culture as it is about machines," said Napolitano. "...We need to have an ongoing, two-way conversation between the public and private sectors [about how to improve cybersecurity]."

Proposals submitted to DHS before the April 30 deadline will be evaluated based on factors that include teamwork, effective metrics for distribution and engagement, use of Web 2.0 technology, compliance with spam laws, privacy, repeatability, feedback mechanism, list building, transparency, and message.

Winners will be invited to a DHS event in Washington D.C. in late May or early June and will have the opportunity to help plan the National Cybersecurity Awareness Campaign with DHS and to prepare the campaign for its launch in October, during Cybersecurity Awareness Month.

Further details are available at the DHS Web site.

Napolitano offered reassurance that DHS understands the challenges of cybersecurity and repeated President Obama's acknowledgment of the seriousness of the cyber threat faced by the nation.

At the same time, she came to ask for help. Success, she said, will depend on our ability to interface with the private sector.

"We're working with our private sector partners in the financial services arena and with other key industries about what needs to be done and what can be done," she said, adding that this can be expected to continue.

As DHS addresses the cybersecurity challenge, it needs more than ideas about public outreach strategy. It needs cybersecurity talent.

"In fact, we may be trying to recruit some of your talent right now," she said, scanning the audience of cybersecurity professionals. "We need it."

She described how the government has been deploying and improving its Einstein intrusion detection system to spot, identify, and (eventually) disable cyber threats to government agencies.

And she called on the private sector to "redouble efforts to increase the security, reliability, and quality of products you have that enter the global supply chain."

The goal, she said, is an IT ecosystem that offers security automation, speed and interoperability, and privacy.

"We need to do more and we need to do it faster," she said.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
5 Reasons the Cybersecurity Labor Shortfall Won't End Soon
Steve Morgan, Founder & CEO, Cybersecurity Ventures,  12/11/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.