Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/10/2009
02:23 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Obama Readying Appointment Of New Cybersecurity Czar

Former military official from the Clinton administration reportedly is front-runner for the job

The long-awaited appointment of a cybersecurity czar is imminent, with a former Clinton administration Department of Defense official at the top of the list, according to a Reuters report.

Frank Kramer, former assistant secretary of defense, is the front-runner for cybersecurity head, according to an unnamed source in the report. Kramer served as assistant secretary of defense for international security affairs from 1996 to 2001, according to published reports. Most recently Kramer served as an adviser for an international investment firm, and he has written various cybersecurity papers and reports. Kramer also described cybersecurity as a component of national security in Congressional testimony in 2005, according to a report in The Atlantic.

President Obama is expected to announce his cyber czar appointment in the coming weeks.

"Kramer is the right person for cyber security czar. His military and international background give him the perspective needed to lead the U.S. in its cyberdefense preparedness," says Richard Stiennon, chief research analyst for IT-Harvest. "That said, if the position is the recommended cybersecurity policy coordinator job described in Melissa Hathaway's Cybersecurity Policy Review [CPR], then this would be a complete waste of an able man.

"I am keeping my fingers crossed that [Obama] will ignore the CPR and establish a real cybersecurity czar role."

Alan Paller, director of research for SANS, says Kramer is a natural fit for the job. "Kramer is the right person for the future of cybersecurity because that future is very much a matter of deepest national security, demanding huge investments in manpower and technology and extraordinary international cooperation," Paller says. "Those are his strengths and he's focused them on cyberpower and national security."

Paller says Kramer has a reputation as a quick study with a knack for tapping the top technical people. "What particularly impresses me is the quality of the technical content he has produced and the extraordinary technical experts he assembled," Paller says. "The mark of a great policy person in technical fields is that he can tap the top technical people and not have to have some aide run interference for him."

Hathaway last month stepped down from her job as acting White House senior director for cybersecurity after spearheading a 60-day cybersecurity policy review that recommended the administration name a national cybersecurity coordinator.

Chris Painter, a deputy assistant director of the FBI's cyber division, has been serving as an acting coordinator to fill Hathaway's slot.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19012
PUBLISHED: 2019-11-17
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or ...
CVE-2019-19022
PUBLISHED: 2019-11-17
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git r...
CVE-2019-19035
PUBLISHED: 2019-11-17
jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.
CVE-2019-19011
PUBLISHED: 2019-11-17
MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.
CVE-2019-19010
PUBLISHED: 2019-11-16
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.