Risk
3/9/2009
06:29 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

U.S. Cybersecurity Director Resigns, Blames NSA

Rod Beckstrom criticizes the NSA's dominance of most of the nation's cybersecurity initiatives.

The government's director of cybersecurity resigned Thursday, warning that the National Security Agency's control of national cybersecurity efforts poses a potential threat to U.S. democratic processes.

Rod Beckstrom, a former Silicon Valley entrepreneur, was appointed in March 2008 to run the National Cybersecurity Center, a group created to oversee government cybersecurity efforts.

In his March 5 resignation letter, a copy of which was published by The Wall Street Journal, Beckstrom criticized the NSA's dominance of most of the nation's cybersecurity initiatives.

"While acknowledging the critical important of the NSA to our intelligence efforts, I believe this is a bad strategy on multiple grounds," he wrote. "The intelligence culture is very different than a network operations or security culture. In addition, the threats to our democratic processes are significant if all top-level government network security and monitoring are handled by one organization (either directly or indirectly)."

Beckstrom said he supports a model that allows for a civilian government cybersecurity capability operating in partnership with the NSA, but not controlled by it. He also made it clear that he was unhappy with the lack of funding at the NCSC, noting that the organization "received only five weeks of funding, due to various roadblocks engineered with the [Department of Homeland Security] and by the Office of Management and Budget."

U.S. Rep. Yvette Clarke, D-NY, who chairs the House Subcommittee on Emerging Threats, Cybersecurity, Science, and Technology, expressed regret over Beckstrom's departure and blamed the Bush administration for hobbling Beckstrom's efforts by withholding funds.

"Mr. Beckstrom's departure is a huge loss for the department," Clarke said in an e-mailed statement. "If the last administration had provided him with the appropriate resources and staffing, he would have been extremely effective."

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3653
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

CVE-2014-5406
Published: 2015-07-06
The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, ...

CVE-2014-9737
Published: 2015-07-06
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.

CVE-2014-9738
Published: 2015-07-06
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.

CVE-2014-9739
Published: 2015-07-06
Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report