Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/23/2009
08:33 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Defense Secretary Orders Cyberspace Command

Initiative aims to unify offense and defense in cyberspace under U.S. military command and enable responses "in Internet time rather than bureaucratic time."

Defense Secretary Robert Gates on Tuesday issued an order establishing the U.S. Cyber Command to oversee military cyberspace operations.

"Cyberspace and its associated technologies offer unprecedented opportunities to the United States and are vital to our nation's security and, by extension, to all aspects of military operations," the memo says. "Yet our increasing dependency on cyberspace, alongside a growing array of cyberthreats and vulnerabilities, adds a new element of risk to our national security."

To address that risk, the memo continues, the Department of Defense must have a command focused on cyberspace that can coordinate online military operations around the globe while also supporting civil authorities and international partners.

Gates' order wasn't unexpected. Unconfirmed reports two months ago indicated that the Department of Defense was planning to set up a cyberspace command.

Gates' memo states that he intends to recommend that the director of the National Security Agency -- a position currently held by Lt. Gen. Keith B. Alexander -- should be granted the command in addition to his current responsibilities.

The memo states that the preferred location for the headquarters for the new command is Fort Meade, Md., but it acknowledges that laws and regulations may dictate otherwise.

Alan Paller, director of research for the SANS Institute, calls the plan a good idea. He expects the new command will unify offense and defense in cyberspace, improve interoperability and information sharing among military services so they can respond "in Internet time rather than bureaucratic time," and improve career paths for cyberwarriors.

"The only downside is the possibility that they will so militarize the Information Assurance Division of NSA that they stop it from fully realizing the promise of S-CAP and the other public-private partnership initiatives that will be critical for turning the tide against the attackers," he said in an e-mail.


InformationWeek and DarkReading.com have published a report on data-centric protection. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10062
PUBLISHED: 2021-05-13
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attri...
CVE-2020-23995
PUBLISHED: 2021-05-13
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.
CVE-2020-23996
PUBLISHED: 2021-05-13
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
CVE-2021-29510
PUBLISHED: 2021-05-13
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patche...
CVE-2021-23906
PUBLISHED: 2021-05-13
An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A Message Length is not checked in the HiQnet Protocol, leading to remote code execution.