Risk
3/2/2010
03:35 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

RSA: White House Cybersecurity Plan Revealed

The plan strives to provide a road map to better cybersecurity while preserving civil liberties and openness.

White House Internet security adviser Howard A. Schmidt on Tuesday announced the availability of an unclassified version of the Obama administration's Comprehensive National Cybersecurity Initiative, the nation's plan to secure public and private sector computer networks.

Speaking at the RSA Conference in San Francisco, Schmidt said, "Today, I'm pleased to announce that the administration has updated the classification guidance for the Comprehensive National Cybersecurity Initiative, or CNCI, which began in 2008 and forms an important component in our cybersecurity efforts within the federal government. As of noontime today, in about 15 minutes, you will be able to go to whitehouse.gov/cybersecurity and download the unclassified description of the CNCI and each of the 12 initatives under the CNCI."

Schmidt repeated President Obama's statement from last year that the cyber threat is one of the most serious economic and security challenges faced by the nation. And he repeated the frequently heard call for greater cooperation and information sharing to defend against cyber attacks.

"We must all partner together to make sure cybersecurity is secure," he said.

The government's plan aims to strengthen the nation's cyber defenses while protecting civil liberties and maintaining government transparency.

The Obama administration, Schmidt said, is committed to openness in government. Transparency, he said, is necessary to address legitimate questions that have arisen about the role of the intelligence community in cybersecurity.

The CNCI consists of 12 initiatives. These are:

1) Manage the Federal Enterprise Network as a single network enterprise with Trusted Internet Connections. 2) Deploy an intrusion detection system of sensors across the Federal enterprise. 3) Pursue deployment of intrusion prevention systems across the Federal enterprise. 4) Coordinate and redirect research and development (R&D) efforts. 5) Connect current cyber ops centers to enhance situational awareness. 6) Develop and implement a government-wide cyber counterintelligence (CI) plan. 7) Increase the security of our classified networks. 8) Expand cyber education. 9) Define and develop enduring "leap-ahead" technology, strategies, and programs. 10) Define and develop enduring deterrence strategies and programs. 11) Develop a multi-pronged approach for global supply chain risk management. 12) Define the Federal role for extending cybersecurity into critical infrastructure domains.

"Our collective knowledge and our experience are probably the most power tool we have," Schmidt concluded. "We're not going to wind up beating our adversaries because they're weak," he said. "...We'll beat them because we will become stronger."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7266
Published: 2015-02-01
Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2...

CVE-2014-7269
Published: 2015-02-01
ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376....

CVE-2014-7270
Published: 2015-02-01
Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earl...

CVE-2014-8630
Published: 2015-02-01
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shel...

CVE-2014-9200
Published: 2015-02-01
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X8...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.