Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Government Needs To Get Its Cybersecurity In Gear, Experts Tell Congress

Security industry leaders agree that White House should lead revamped cybersecurity effort

Some of the nation's top cybersecurity experts today told a congressional subcommittee that the United States isn't ready for a major online attack, and called on the White House and the rest of the federal government to get their acts together.

In a hearing held by the House Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology, four top IT security officials expressed concern about the government's slow movement in developing a defense for its own agencies and for the nation's critical infrastructure. All four said the White House should lead the effort with the creation of a civilian agency dedicated to cyberdefense.

"We need to face the fact that we are already dealing with cyberwar, both from criminal elements and from hostile governments," said Dave Powner, director of IT management issues at the Government Accountability Office. "We're constantly under attack."

"We're facing the same sort of attack we faced on 9/11, only on a virtual level," said Amit Yoram, CEO of NetWitness and a former White House cybersecurity official. "And without the right defenses, we'll be just as vulnerable."

The experts said that the White House should lead the effort to swiftly build up the nation's defenses against cyberattack. Jim Lewis, project director at the Center for Strategic and International Studies, said the White House is the only part of the government that has the budget and power to drive the initiative, and that only the president can make the decision as to when a cyberattack constitutes an act of war.

Mary Ann Davidson, CSO at Oracle, called on the federal government to develop an analog to the Monroe Doctrine that would clearly establish a U.S. "cyberturf" and a commitment to defend it with both offensive and defensive cyberweapons.

All of the experts, as well as some members of the subcommittee, expressed concern that the National Security Agency should be given the primary authority over U.S. cybersecurity initiatives. "Intelligence-gathering efforts often work at cross purposes with agencies that are developing defensive strategies," Yoran said.

Rod Beckstrom, the former director of the National Cybersecurity Center who resigned last week in a turf battle with the NSA, was present at the hearing, but did not speak.

The White House is currently conducting a 60-day review of the cybersecurity situation; the review is expected to result in organizational recommendations for the Obama administration. The GAO has not yet met with the review committee, but Powner said his organization is recommending the formation of a White House office responsible for cybersecurity. The GAO also is recommending the creation of a "board of directors" to monitor cybersecurity initiatives and an "accountable" cyberorganization that will speed the development of online defenses.

The members of the congressional subcommittee said they had many more questions for the experts, but they generally favored the recommendations made by the experts.

"The cybersecurity effort has been plagued by ineffective leadership," said Bennie Thompson, chairman of the subcommittee. "We were optimistic about the capabilities of Rod Beckstrom, but it became clear that he did not have experience in working miracles. He did not have the budget or the authority to get the job done. This committee believes, as he does, that there should be a civilian agency that interfaces with, but is not controlled by, the NSA."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Cybersecurity Industry: It's Time to Stop the Victim Blame Game
Jessica Smith, Senior Vice President, The Crypsis Group,  2/25/2020
Google Adds More Security Features Via Chronicle Division
Robert Lemos, Contributing Writer,  2/25/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9431
PUBLISHED: 2020-02-27
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.
CVE-2020-9432
PUBLISHED: 2020-02-27
openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
CVE-2020-9433
PUBLISHED: 2020-02-27
openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
CVE-2020-9434
PUBLISHED: 2020-02-27
openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
CVE-2020-6383
PUBLISHED: 2020-02-27
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.