Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/10/2009
02:23 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Obama Readying Appointment Of New Cybersecurity Czar

Former military official from the Clinton administration reportedly is front-runner for the job

The long-awaited appointment of a cybersecurity czar is imminent, with a former Clinton administration Department of Defense official at the top of the list, according to a Reuters report.

Frank Kramer, former assistant secretary of defense, is the front-runner for cybersecurity head, according to an unnamed source in the report. Kramer served as assistant secretary of defense for international security affairs from 1996 to 2001, according to published reports. Most recently Kramer served as an adviser for an international investment firm, and he has written various cybersecurity papers and reports. Kramer also described cybersecurity as a component of national security in Congressional testimony in 2005, according to a report in The Atlantic.

President Obama is expected to announce his cyber czar appointment in the coming weeks.

"Kramer is the right person for cyber security czar. His military and international background give him the perspective needed to lead the U.S. in its cyberdefense preparedness," says Richard Stiennon, chief research analyst for IT-Harvest. "That said, if the position is the recommended cybersecurity policy coordinator job described in Melissa Hathaway's Cybersecurity Policy Review [CPR], then this would be a complete waste of an able man.

"I am keeping my fingers crossed that [Obama] will ignore the CPR and establish a real cybersecurity czar role."

Alan Paller, director of research for SANS, says Kramer is a natural fit for the job. "Kramer is the right person for the future of cybersecurity because that future is very much a matter of deepest national security, demanding huge investments in manpower and technology and extraordinary international cooperation," Paller says. "Those are his strengths and he's focused them on cyberpower and national security."

Paller says Kramer has a reputation as a quick study with a knack for tapping the top technical people. "What particularly impresses me is the quality of the technical content he has produced and the extraordinary technical experts he assembled," Paller says. "The mark of a great policy person in technical fields is that he can tap the top technical people and not have to have some aide run interference for him."

Hathaway last month stepped down from her job as acting White House senior director for cybersecurity after spearheading a 60-day cybersecurity policy review that recommended the administration name a national cybersecurity coordinator.

Chris Painter, a deputy assistant director of the FBI's cyber division, has been serving as an acting coordinator to fill Hathaway's slot.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16772
PUBLISHED: 2019-12-07
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.to...
CVE-2019-9464
PUBLISHED: 2019-12-06
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could dissolve the trust in the platform's permission system, with no additional execution privileges need...
CVE-2019-2220
PUBLISHED: 2019-12-06
In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling application suspend. This could lead to local information disclosure no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers...
CVE-2019-2221
PUBLISHED: 2019-12-06
In hasActivityInVisibleTask of WindowProcessController.java there?s a possible bypass of user interaction requirements due to incorrect handling of top activities in INITIALIZING state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...
CVE-2019-2222
PUBLISHED: 2019-12-06
n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android...