<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTOvision.com &#187; CCSA</title>
	<atom:link href="http://ctovision.com/tag/ccsa/feed/" rel="self" type="application/rss+xml" />
	<link>http://ctovision.com</link>
	<description>News, analysis and context on enterprise technology for the CTO</description>
	<lastBuildDate>Thu, 09 Feb 2012 21:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Cyber Conflict Studies Association History Contest</title>
		<link>http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/</link>
		<comments>http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 23:34:52 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Atlantic Council]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Cyber Conflict Studies Association]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=15161</guid>
		<description><![CDATA[Tweet The Cyber Conflict Studies Association (CCSA) is a 501(c)3 non-profit organization dedicated to promoting and leading a diversified research agenda in the field of cyber conflict. CCSA&#8217;s vision is to be the premier thought leader in the field by fostering dialogue, leading research, and developing academic programs focused on the implications of cyber conflict. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fcyber-conflict-studies-association-history-contest%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/"  data-text="Cyber Conflict Studies Association History Contest" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>The <a href="http://cyberconflict.org">Cyber Conflict Studies Association</a> (CCSA) is a 501(c)3 non-profit organization dedicated to promoting and leading a diversified research agenda in the field of cyber conflict. CCSA&#8217;s vision is to be the premier thought leader in the field by fostering dialogue, leading research, and developing academic programs focused on the implications of cyber conflict.</p>
<p>To achieve this, CCSA promotes and leads international intellectual development efforts to advance the field of cyber conflict research. These activities include workshops that bring together professionals from industry, academia and government to discuss strategic issues surrounding cyber conflict and the publication of insightful research articles and position papers in its Journal of Cyber Conflict Studies.</p>
<p>The CCSA is collaborating with others in the community to establish a history writing contest. Please help us spread the word. Details are below:</p>
<blockquote>
<div><span style="font-family: Arial;">The </span><a href="http://www.cyberconflict.org/" target="_blank"><span style="color: #0000ff; font-family: Arial;">Cyber Conflict Studies Association</span></a><span style="font-family: Arial;"> (CCSA), </span><span style="color: #0000ff; font-family: Arial;"><a href="http://www.afcea.org/" target="_blank">AFCEA International</a></span><span style="font-family: Arial;">,</span><span style="font-family: Arial;"> and the </span><a href="http://www.acus.org/" target="_blank"><span style="color: #0000ff; font-family: Arial;">Atlantic Council</span></a><span style="font-family: Arial;"> have collaborated to create a cyber conflict history case studies contest. </span>The contest comprises three entrant categories: university students, military service members and professionals, with six prizes of up to $1,000 to be awarded for the best submissions. The deadline for entering the competition is June 1, 2012. The full call for papers is posted <a href="http://www.cyberconflict.org/storage/Call_for_Cyber_Conflict_Case_Studies.pdf" target="_blank">here.</a></div>
<div></div>
<div>Entries that meet editorial criteria will be considered for inclusion in future CCSA journals or an upcoming <em>Comprehensive History of Cyber Conflict </em>publication. In addition, they may be selected for presentation at a future cyber conflict history conference. Authors of the winning papers automatically will be considered for an internship or employment at the Atlantic Council or the CCSA.</div>
<div><strong><br />
</strong></div>
<div><span style="font-family: Arial;">Additional information about the competition, including the list of case studies and complete competition rules, can be found in the official call for papers posted </span><a href="http://www.cyberconflict.org/storage/Call_for_Cyber_Conflict_Case_Studies.pdf" target="_blank"><span style="color: #0000ff; font-family: Arial;">online</span></a><span style="font-family: Arial;">. More information about CCSA and research resources is available on the </span><span style="color: #0000ff; font-family: Arial; font-size: x-small;"><a href="http://www.cyberconflict.org/studyhistory-of-cyber-conflict/" target="_blank">CCSA website.</a> </span><span style="font-family: Arial;">Participants should email entries or questions to </span><a href="mailto:karl@cyberconflict.org" target="_blank"><span style="color: #0000ff; font-family: Arial;">Karl Grindal</span></a><span style="font-family: Arial;">, writing competition project manager.  Please help CCSA advertise the contest through your social network of colleagues and friends.</span></div>
</blockquote>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=c9c96dec-8a19-4fa8-9b86-f4cae1a58be6" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6375aac65b771cae8ca52a3a5c4b8914_thumb_ccsa-300x117.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">What is the Cyber Conflict Studies Association?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b443047f5471c0cb3dea829d8bf9723f_thumb_lincoln-on-cybersecurity1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/some-thoughts-on-the-iranian-cyber-army-and-what-they-mean-to-cyber/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/dd6c3c9e21e59fb06f2b5c84ae50b770_thumb_Stuxnet-300x199.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Some Thoughts on the Iranian Cyber Army and what they mean to Cyber</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9537392f29a384844a3cdad42bf82da0_thumb_siemenspcs7-300x185.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Stuxnet: An important change in the national security landscape</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/07/pros-and-cons-cyber-command/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6f96223061ef7477c860bacf70a6861b_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pros and Cons: Cyber Command</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.devost.net/2010/09/10/furthering-the-field-a-comprehensive-program-for-cyber-conflict-studies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/blog.devost.net/b2dbdae11e8476f73761486495a6edf6_thumb_devost-net-logo.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Furthering the Field: A Comprehensive Program for Cyber Conflict Studies</span><span class="nr_source">Devost.Net</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/darpa%e2%80%99s-cyber-fast-track-adds-agility-to-research-funding/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DARPA’s Cyber Fast Track Adds Agility to Research Funding</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/president-mentions-cyber-threats-in-state-of-the-union-address/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">President Mentions Cyber-Threats in State of the Union Address</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/trust-enterprise-security-and-autonomous-technology/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cloud-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Trust, Enterprise Security, and Autonomous Technology</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/naval-academy-expands-on-cyber-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Naval Academy Expands on Cyber Security</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Cyber+Conflict+Studies+Association+History+Contest&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fcyber-conflict-studies-association-history-contest%2F&nr_ad_number=0&nr_div_number=1");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.domain = "ctovision.com";nRelate.fixHeight("nrelate_related_1");nRelate.adAnimation("nrelate_related_1");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The most well thought out research agenda for cyber security I have seen to date</title>
		<link>http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/</link>
		<comments>http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 04:46:21 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Gov2.0]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[cyber conflict]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[HSARPA]]></category>
		<category><![CDATA[Research and Development]]></category>
		<category><![CDATA[Software Assurance]]></category>
		<category><![CDATA[United States Department of Homeland Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=11959</guid>
		<description><![CDATA[Tweet Opinion: the most mature research agenda on the topic of cyber security is the one established by our nation&#8217;s Department of Homeland Security. I&#8217;m keeping an open mind, and would love to learn of other cyber security research agenda&#8217;s that might be as well defined. But I have to tell you I have seen [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F02%2Fthe-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/"  data-text="The most well thought out research agenda for cyber security I have seen to date" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com"><img class="alignleft size-medium wp-image-11961" style="margin: 4px;" title="DHS S&amp;T" src="http://ctovision.com/wp-content/uploads/2011/02/dhssnt-300x278.png" alt="" width="240" height="222" /></a><strong>Opinion:</strong> the most mature research agenda on the topic of cyber security is the one established by our nation&#8217;s <a href="http://www.dhs.gov/index.shtm" target="_blank">Department of Homeland Security</a>.</p>
<p>I&#8217;m keeping an open mind, and would love to learn of other cyber security research agenda&#8217;s that might be as well defined. But I have to tell you I have seen research programs associated with cyber for years and this one is impressive.</p>
<p>The details of the topic areas of this research activity are embedded in a Broad Area Announcement (BAA) posted on <a href="https://www.fbo.gov/index?s=opportunity&amp;mode=form&amp;id=3c71c829bc28fcea61aef3a5e0f58ffe&amp;tab=core&amp;tabmode=list&amp;=">FedBizOpps</a>. The PDF of the announcement is located here: <a href="http://ctovision.com/wp-content/uploads/2011/02/Cyber_Security_BAA_11-02-2.pdf">http://ctovision.com/wp-content/uploads/2011/02/Cyber_Security_BAA_11-02-2.pdf</a></p>
<p>You can also find info on this research agenda at:</p>
<p><a href="https://baa2.st.dhs.gov/portal/BAA/">https://baa2.st.dhs.gov/portal/BAA/</a></p>
<p>A summary of the agenda is pasted below for your review, but please visit review the details on the DHS site and at FedBizOpps for more info. And, if you know of any researcher who has an ability to contribute to the cyber mission needs outlined in this BAA, please get word of the BAA to the researcher. Our nation needs research into these topics, and it looks like DHS may be making some funding available for research into these topics.</p>
<p>I&#8217;d also recommend the DHS S&amp;T Topics for Cyber Research by reviewed by computer science students and teachers.  They should also be considered by IT firms large and small, even if the firms are not planning on responding to the DHS announcement.  Anyone doing any research on cyber anywhere would benefit from a review of this agenda, I believe.</p>
<p><strong>Summary from the DHS S&amp;T website:</strong></p>
<table align="center">
<tbody>
<tr>
<td><span style="text-decoration: underline;"><strong>Description</strong></span></td>
</tr>
<tr>
<td>The Department of Homeland Security (DHS) Science and Technology (S&amp;T) Homeland Security Advanced Research Projects Agency (HSARPA) Cyber Security Division&#8217;s (CSD) announce a Broad Agency Announcement (BAA) for Fiscal Year 2011 to improve the security in both Federal networks and the larger Internet. This Broad Agency Announcement (BAA) seeks ideas and proposals for Research and Development (R&amp;D) in 14 Technical Topic Areas (TTAs) related to CSD. The total estimated value of this acquisition is $40 million. Cyber attacks are increasing in frequency and impact. Even though these attacks have not yet had a significant impact on our Nation&#8217;s critical infrastructures, they have demonstrated that extensive vulnerabilities exist in information systems and networks, with the potential for serious damage. The effects of a successful cyber attack might include: serious consequences for major economic and industrial sectors, threats to infrastructure elements such as electric power, and disruption of the response and communications capabilities of first responders. The DHS S&amp;T mission is to conduct, for homeland security purposes, research, development, test and evaluation (RDT&amp;E) and timely transition of cyber security capabilities to operational units within DHS, as well as local, state, Federal and operational end users in critical infrastructure. Cyber security is defined in broad terms to encompass the usual attributes of security, as well as reliability, availability, and survivability in the face of adversary attack and accidental fault, while preserving privacy. DHS S&amp;T invests in programs offering the potential for revolutionary changes in technologies that promote homeland security and accelerate the prototyping and system prototype demonstration in an operational environment of technologies that reduce homeland vulnerabilities. A critical area of focus for DHS is the development and deployment of technologies to protect the nation&#8217;s cyber infrastructure, including the Internet and other critical infrastructures that depend on computer systems for their mission.</td>
</tr>
</tbody>
</table>
<table align="center">
<tbody>
<tr>
<td align="left">
<ul>
<li><span style="text-decoration: underline;"><strong>TTA 01</strong></span> &#8211; Software Assurance</li>
<li><span style="text-decoration: underline;"><strong>TTA 02</strong></span> &#8211; Enterprise-Level Security Metrics</li>
<li><span style="text-decoration: underline;"><strong>TTA 03</strong></span> &#8211; Usable Security</li>
<li><span style="text-decoration: underline;"><strong>TTA 04</strong></span> &#8211; Insider Threat</li>
<li><span style="text-decoration: underline;"><strong>TTA 05</strong></span> &#8211; Secure, Resilient Systems and Networks</li>
<li><span style="text-decoration: underline;"><strong>TTA 06</strong></span> &#8211; Modeling of Internet Attacks</li>
<li><span style="text-decoration: underline;"><strong>TTA 07</strong></span> &#8211; Network Mapping and Measurement</li>
<li><span style="text-decoration: underline;"><strong>TTA 08</strong></span> &#8211; Incident Response Communities</li>
<li><span style="text-decoration: underline;"><strong>TTA 09</strong></span> &#8211; Cyber Economics</li>
<li><span style="text-decoration: underline;"><strong>TTA 10</strong></span> &#8211; Digital Provenance</li>
<li><span style="text-decoration: underline;"><strong>TTA 11</strong></span> &#8211; Hardware-Enabled Trust</li>
<li><span style="text-decoration: underline;"><strong>TTA 12</strong></span> &#8211; Moving-Target Defense</li>
<li><span style="text-decoration: underline;"><strong>TTA 13</strong></span> &#8211; Nature-Inspired Cyber Health</li>
<li><span style="text-decoration: underline;"><strong>TTA 14</strong></span> &#8211; Software Assurance MarketPlace (SWAMP)</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>Summaries of these task areas:</p>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="0">TTA 01</a></strong></p>
<p><strong>TITLE: </strong>Software Assurance</p>
<p><strong>DESCRIPTION: </strong></p>
<p>The nation&#8217;s critical infrastructure (energy, transportation, telecommunications, banking and finance, and others), businesses, and services are extensively and increasingly controlled and enabled by software. Vulnerabilities in that software put those resources at risk. The risk is compounded by software size and complexity, the ways in which software is developed and maintained, the use of software produced by unvetted suppliers, and the interdependence of software systems. Software quality addresses the presence of internal flaws and vulnerabilities in software threatening its correct or predictable operation and use. Software assurance deals with the root of the problem by improving software security.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="1">TTA 02</a></strong></p>
<p><strong>TITLE: </strong>Enterprise-Level Security Metrics</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Defining effective information security metrics has proven difficult, even though there is general agreement that such metrics could allow measurement of progress in security measures and, at a minimum, rough comparisons of security between systems. Metrics underlie and quantify progress in many other system security areas. &#8220;You cannot manage what you cannot measure,&#8221; as the saying goes; the lack of sound and practical security metrics is severely hampering progress both in research and engineering of secure systems. However, general community agreement on meaningful metrics has been hard to achieve. This is due in part to the rapid evolution of IT, as well as the shifting locus of adversarial action.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="2">TTA 03</a></strong></p>
<p><strong>TITLE: </strong>Usable Security</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Although the problem of achieving usable security is universal &#8211; it affects everyone, and everyone stands to benefit enormously if usability is successfully addressed as a core aspect of security &#8211; it affects different users in different ways, depending on applications, settings, policies, and user roles. The guiding principles may indeed be universal, but there is certainly no general one-size-fits-all solution.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="3">TTA 04</a></strong></p>
<p><strong>TITLE: </strong>Insider Threat</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Cybersecurity measures are often focused on threats from outside an organization, rather than threats posed by untrustworthy individuals inside an organization. However, insider threats are the source of many losses in many critical infrastructure industries. In addition, well-publicized intelligence community moles such as Aldrich Ames have caused enormous and irreparable harm to national interests. This TTA focuses on insider threats to our cyber systems, and presents a high-impact research program that could aggressively curtail some aspects of this problem. At a high level, opportunities exist to mitigate insider threats through aggressive profiling and monitoring of users of critical systems, &#8220;fishbowling&#8221; suspects, &#8220;chaffing&#8221; data and services by users who are not entitled to access, and finally &#8220;quarantining&#8221; confirmed malevolent actors to contain damage and leaks while collecting actionable counter-intelligence and legally acceptable evidence.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="4">TTA 05</a></strong></p>
<p><strong>TITLE: </strong>Secure, Resilient Systems and Networks</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Survivability is the capability of a system to fulfill its mission, in a timely manner, in the presence of attacks, failures, or accidents. Part of the survivability attribute of systems and networks includes being secure and resilient to attack. This is meaningful, in practice, only with respect to well-defined mission requirements against which the survivability can be evaluated and measured.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="5">TTA 06</a></strong></p>
<p><strong>TITLE: </strong>Modeling of Internet Attacks</p>
<p><strong>DESCRIPTION: </strong></p>
<p>This TTA researches, develops and applies modeling and analysis capabilities to predict the effects of cyber attacks on Federal Government and other critical infrastructures. Two main areas are identified: malware and botnets; and situational understanding and attack attribution.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="6">TTA 07</a></strong></p>
<p><strong>TITLE: </strong>Network Mapping and Measurement</p>
<p><strong>DESCRIPTION: </strong></p>
<p>The protection of cyber infrastructure depends on the ability to identify critical Internet resources, incorporating an understanding of geographic and topological mapping of Internet hosts and routers. A better understanding of connectivity richness among ISPs will help to identify critical infrastructure. Associated data analysis will allow better understanding of peering relationships, and will help identify infrastructure components in greatest need of protection. Improved router level maps (both logical and physical) will enhance Internet monitoring and modeling capabilities to identify threats and predict the cascading impacts of various damage scenarios.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="7">TTA 08</a></strong></p>
<p><strong>TITLE: </strong>Incident Response Communities</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Cyber security incident response (CSIR) teams, individuals, and communities have historically consisted of people and organizations that have been &#8220;in the right place at the right time.&#8221; Only recently has the community begun to specify the skills, abilities, structures, and support to create an effective and sustained incident response capability. While there is a good understanding of the technologies involved in CSIRTs, the operational community has not adequately studied the characteristics of individuals, teams, and communities that distinguish the great CSIR responders from the average technology contributor. In other areas where individual contributions are essential to success, e.g., first responders, commercial pilots, and military personnel, there have studies of the individual and group characteristics essential to success. To optimize the selection, training, and organization of CSIR personnel to support the essential cyber missions of DHS, a much greater understanding and appreciation of these characteristics must be achieved.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="8">TTA 09</a></strong></p>
<p><strong>TITLE: </strong>Cyber Economics</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Today cyber crime pays. So does cyber-espionage. The state of cyber security today is, and in the future will be, significantly affected by economic conditions and factors. Cyber crime and espionage are making their own economic markets today, having gone well beyond the &#8220;script kiddie&#8221; and &#8220;hacker&#8221; personas to mature into big business on a global level. Gaining an understanding of the incentive structure is key to getting stakeholders to behave in a way that will improve overall security. Current cyber-related illegal activities are economically attractive for several reasons.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="9">TTA 10</a></strong></p>
<p><strong>TITLE: </strong>Digital Provenance</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Individuals and organizations routinely work with, and make decisions based on, data that may have originated from many different sources and also may have been processed, transformed, interpreted, and aggregated by numerous entities between the original sources and the consumers. Without good knowledge about the sources and intermediate processors of the data, it can be difficult to assess the data&#8217;s trustworthiness and reliability, and hence its real value to the decision-making processes in which it is used.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="10">TTA 11</a></strong></p>
<p><strong>TITLE: </strong>Hardware-Enabled Trust</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Hardware can be the final sanctuary and foundation of trust in the computing environment, based on the technologies that can be developed in the area of hardware-enabled trust and security. With cyber threats steadily increasing in sophistication, hardware can provide a game-changing foundation upon which to build tomorrow&#8217;s cyber infrastructure. But today&#8217;s hardware still provides limited support for security and capabilities that do exist are often not fully utilized by software. The hardware of the future also must exhibit greater resilience to function effectively under attack.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="11">TTA 12</a></strong></p>
<p><strong>TITLE: </strong>Moving-Target Defense</p>
<p><strong>DESCRIPTION: </strong></p>
<p>In the current environment, our systems are built to operate in a relatively static configuration. For example, addresses, names, software stacks, networks, and various configuration parameters remain relatively static over relatively long periods of time. This static approach is a legacy of information technology system design for simplicity in a time when malicious exploitation of system vulnerabilities was not a concern.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="12">TTA 13</a></strong></p>
<p><strong>TITLE: </strong>Nature-Inspired Cyber Health</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Today, weeks and months may elapse before successful network penetrations are detected through laborious forensic analysis. Despite their potential to function with intelligence, today&#8217;s typical network components have very limited understanding of what passes through them, coupled with a correspondingly short memory. In the future, network components must have heightened ability to observe and record what is happening to and around them. With this new awareness of the system health and safety, these &#8220;self-aware systems&#8221; enjoy a range of options: these system may take preventative measures, rejecting requests which do not fit the profile of what is good, a priori, for the network; these systems can build immunological responses to the malicious agents which they sense in real time; these systems may refine the evidence they capture for the pathologist, as a diagnosis of last resort, or to support the development of new prevention methods. In the future, system owners should be able to monitor and control such dynamic cyber environments.</td>
</tr>
<tr bgcolor="#ffffff">
<td></td>
</tr>
</tbody>
</table>
<table width="100%" bgcolor="#f7f7f7">
<tbody>
<tr bgcolor="#efefef">
<td></td>
</tr>
<tr>
<td>
<strong>TOPIC NUMBER: <a name="13">TTA 14</a></strong></p>
<p><strong>TITLE: </strong>Software Assurance MarketPlace (SWAMP)</p>
<p><strong>DESCRIPTION: </strong></p>
<p>Technical Topic Area #1 on Software Assurance describes the need to address threats throughout the software development process and called for new methods, services, and capabilities in build, test, and analysis phases in order to improve the quality and reliability of software used in the nation&#8217;s critical infrastructures. Specifically, TTA#1 solicits ideas for research and development of new tools and methods for software analysis, and for applying new and existing capabilities in test and evaluation activities. This TTA (#14) focuses on the research infrastructure necessary to enable these software quality assurance and related activities.</td>
</tr>
</tbody>
</table>
<p><strong>Related articles</strong></p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/01/attend-fedscoop-cybersecurity-summit/">Attend FedScoop CyberSecurity Summit</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/01/federal-cyber-security-missions-initiatives-opportunities-and-risks/">Federal Cyber Security: Missions, Initiatives, Opportunities and Risks</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2010/12/ponemon-institute-cost-of-cyber-crime-study/">Ponemon Institute Cost of Cyber Crime Study</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=229200206&amp;cid=RSSfeed_IWK_ALL">DHS To Invest $40 Million On Cybersecurity Research</a> (informationweek.com)</li>
<li class="zemanta-article-ul-li"><a href="http://yro.slashdot.org/story/11/01/31/1559235/DHS-Offers-40M-For-Top-Cybersecurity-Research">DHS Offers $40M For Top Cybersecurity Research</a> (yro.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://marienfeldt.wordpress.com/2010/12/14/enisa-smartphone-security-report/">ENISA smartphone cyber security report</a> (marienfeldt.wordpress.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=d19c489c-1d9e-422d-bce4-e42bd7639a20" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/03/mature-models-for-healthy-and-resilient-cyber-systems/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d9016ac7faff40a974f91c61bc0ccf10_thumb_Department-of-Homeland-Security-300x203.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mature Models for Healthy and Resilient Cyber Systems</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6375aac65b771cae8ca52a3a5c4b8914_thumb_ccsa-300x117.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">What is the Cyber Conflict Studies Association?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/02/govsec-conference-is-march-29-31-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/001468eb33ec5e4590e7ad40cff3c88d_thumb_govsec.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">GovSec conference is March 29-31 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/the-fedcyber-com-cyber-security-summit/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9864e85f16bbc4e2a15784df135f3be0_thumb_newseum.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The FedCyber.com Cyber Security Summit</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/deputy-secretary-of-defense-lynn-cyber-strategy%e2%80%99s-thrust-is-defensive/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fa5ccb5775a00b753a4d3a3d6317d2a6_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Deputy Secretary of Defense Lynn: Cyber Strategy’s Thrust is Defensive</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/darpa%e2%80%99s-cyber-fast-track-adds-agility-to-research-funding/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DARPA’s Cyber Fast Track Adds Agility to Research Funding</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/cyber-conflict-studies-association-history-contest/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyber Conflict Studies Association History Contest</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/10/evolving-approaches-to-cyber-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/former-w-h-official-in-the-event-of-a-cyberwar-dont-call-dhs/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-abstract-glass.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Former W.H. Official: In the Event of a Cyberwar, Don’t Call DHS</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/02/zafesoft-next-generation-content-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/18f83d7e9cabc7f89bd88cb17a17c5d8_thumb_cyber_security-300x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Zafesoft: Next Generation Content Security</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=The+most+well+thought+out+research+agenda+for+cyber+security+I+have+seen+to+date&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F02%2Fthe-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date%2F&nr_ad_number=0&nr_div_number=2");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_2");nRelate.adAnimation("nrelate_related_2");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Stuxnet: An important change in the national security landscape</title>
		<link>http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/</link>
		<comments>http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/#comments</comments>
		<pubDate>Tue, 28 Sep 2010 02:19:39 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber conflict]]></category>
		<category><![CDATA[Gary McGraw]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Natanz]]></category>
		<category><![CDATA[Nation state]]></category>
		<category><![CDATA[National security]]></category>
		<category><![CDATA[Nuclear weapon]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Siemens]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[United States]]></category>
		<category><![CDATA[War]]></category>
		<category><![CDATA[Warfare and Conflict]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=7536</guid>
		<description><![CDATA[Tweet There are some important strategic changes occurring in the national security landscape. A new kind of cyber attack has been noted, one that involves use of malicious code to attack infrastructure.  There are some important points in this attack that should be understood by national security decision-makers. With the launch of the code the security community [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F09%2Fstuxnet-a-tipping-point-in-cyber-conflict%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/"  data-text="Stuxnet: An important change in the national security landscape" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div id="attachment_7706" class="wp-caption alignleft" style="width: 310px"><a href="http://ctovision.com"><img class="size-medium wp-image-7706" style="margin: 4px;" title="siemenspcs7" src="http://ctovision.com/wp-content/uploads/2010/09/siemenspcs7-300x185.png" alt="" width="300" height="185" /></a><p class="wp-caption-text">Siemens provides the SIMATIC PCS 7 with &quot;everything you need to completely and safely automate your entire production process.&quot;</p></div>
<p style="text-align: left;">There are some important strategic changes occurring in the national security landscape.</p>
<p style="text-align: left;">A new kind of cyber attack has been noted, one that involves use of malicious code to attack infrastructure.  There are some important points in this attack that should be understood by national security decision-makers.</p>
<p style="text-align: left;">With the launch of the code the security community calls Stuxnet, an attack was made against a programmable logic controller (PLC) that runs a physical system.  This is a new degree of bad in cyber attacks.</p>
<p style="text-align: left;">This code is potentially (probably?) nation-state sponsored.  We might never know which country, but a review of the geo-political situation today can lead to some informed speculation.</p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
<h2>Below is some Stuxnet context:</h2>
<p>Background: A piece of malicious code called Stuxnet was discovered over the summer.  It was highlighted by security experts like<a href="http://www.cs.columbia.edu/~smb/blog/2010-07/2010-07-16.html" target="_blank"> Steve Bellovin</a> in July 2010. Steve pointed out that the use of zero day attacks and the targeting of a SCADA system was of note.</p>
<div id="attachment_7539" class="wp-caption aligncenter" style="width: 490px"><a href="http://ctovision.com"><img class="size-full wp-image-7539" title="stuxnet" src="http://ctovision.com/wp-content/uploads/2010/09/stuxnet1.gif" alt="" width="480" height="153" /></a><p class="wp-caption-text">Piece of Stuxnet Code as analyzed by Ralph Langner</p></div>
<p>Many other security researchers discussed this code but one of the better technical write-ups is captured by Ralph Langner in his report titled &#8220;<a href="http://www.langner.com/en/" target="_blank">Stuxnet is a directed attack&#8211; &#8216;hack of the century&#8217;</a>&#8221;</p>
<h2>Key points made by Ralph Langner are that:</h2>
<ul>
<li>This was a directed attack, aimed at sabotage vice espionage or privacy attacks.</li>
<li>The full effect of the package only occurs at places where are targeted piece of equipment is located. This means knowledge of a specific target was used in designing this weapon.</li>
<li>Many other features point to heavy insider knowledge.</li>
<li>Although smart use of zero day attacks was used, the real expertise was with the specific control system. This was not some hacker or group of hackers. This is a group with knowledge of the target.</li>
</ul>
<p>Some great analysis also comes from Gary McCraw of in a post at InformIT titled &#8220;<a href="http://www.informit.com/articles/article.aspx?p=1636983">Software [In]security: How to p0wn a Control System with Stuxnet.</a>&#8221;</p>
<h2>Gary McGraw makes the points that:</h2>
<ul>
<li>Stuxnet seems to be proof of a sophisticated, narrowly targeted collection of malware controlled by a well resourced entity.</li>
<li>It was discovered accidently  by anti-virus researchers in June 2010, but may have been in the wild since early 2009.</li>
<li>Gary underscores that the delivery means is not what is key here.  An almost infinite number of delivery means could have been used, unfortunately. There is a deep well of zero day attacks waiting to be discovered.  The key thing is the ability of Stuxnet to inject code into a running control system.</li>
<li>Gary also clarifies that this attacks is NOT against the SCADA.  It is against the programmable logic controller (PLC) which runs the physical system directly.  This makes this attack much more sinister.</li>
</ul>
<h2>Some analysis and recommendations:</h2>
<p>I should mention a disclaimer: I don&#8217;t have a clue about how hard it would be to write this code or insert it.  I don&#8217;t have any insider knowledge about this or have any idea who did it.  And, although I am certainly a student of technology my personal coding skills are so weak I could not offer any personal opinions that come close to those of McGraw, Bellovin or Langner.  Those guys are masters I hold in high regard, and they and many other experts are convincing me that this is unique.</p>
<ul>
<li>It is possible that the code could have been written by one very smart coder, but it is more likely the result of a team.</li>
<li>The smart use of well prepared, unknown exploits makes this sophisticated, but that is just the delivery means.  The key point is the weapon- the piece that changes how a control system operates.</li>
<li>This, to me, points to a historical first. I believe, this is the first publicly available evidence of a piece of weaponized code being delivered to have an impact on a SCADA system.</li>
<li>This does not seem to have been designed, at all, to provide data out.  It is not built for espionage.  It is built to impact infrastructure.</li>
<li>And it is built to impact a very specific infrastructure, not all infrastructure.  It is targeted.</li>
<li>We are all put in the awkward position of being tempted to blame Israel for this attack.  If the code does what it seems to do, and if it was targeted against <a href="http://en.wikipedia.org/wiki/Nuclear_program_of_Iran">centrifuges at Natanz</a>, then it is logical to assume Israel could benefit from this.  But in the cyber world it can be very hard to prove who is behind an attack. We should all be on guard for reports that claim to know where this came from (scrutinize any reporting so you know what the facts are).</li>
<li>If a country sponsors an attack against another country, is it an act of war?  Well, if a country bombs another country&#8217;s nuclear weapons program, is that an act of war?  Seems like this is an issue worth additional study.</li>
<li>If a country launches a weapon like this, does it mean they are ready for the &#8220;blow back&#8221; when other country&#8217;s launch weapons like that against them?  I don&#8217;t know of any country that is protected (or protectable) against these sorts of threats.  So why would any country launch an attack like this?</li>
</ul>
<h2>My recommendations:</h2>
<ul>
<li>If you are not already studying cyber issues, seems like now would be a good time to start.  There are many venue available for you to study cyber conflict.  One of my recommended places is the <a href="http://cyberconflict.org">Cyber Conflict Studies Association (CCSA)</a>, but there are many other ways to get involved and get up to speed on these many dynamics of cyber conflict.  Depending on your interest and abilities you can join and learn from and advance the cyber conflict thinking at: <a href="http://sans.org/">SANS</a>, <a href="http://www.afcea.org/">AFCEA</a>, <a href="http://www.insaonline.org/">INSA</a>, <a href="http://www.ieee.org/index.html">IEEE</a>, <a href="http://www.acm.org/">ACM</a>, <a href="http://www.aafs.org/">AAFS</a> , <a href="http://www.cfr.org/">CFR</a>, and/or many others.  One thing I&#8217;m certain about is that we will need contributions from a wide range of experiences and viewpoints as we move forward into the future, so find your path and dive in.</li>
<li>I also recommend that you do what you know you need to do in your own enterprise.  Ensure you are mounting a vigorous defense in depth.</li>
<li>Oh, and don&#8217;t let anyone in your organization tell you that your SCADA systems are protected because they are not directly connected to the Internet. If they can be reached by any network or USB drive or other media, they are not isolated.</li>
</ul>
<h2>And a closing thought:</h2>
<p>I think once again it is an important question for you to ask yourself:  <a href="http://blog.devost.net/essays/">Can you trust your toaster?</a> More later.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.wired.com/threatlevel/2011/01/inl-and-stuxnet/">Did a U.S. Government Lab Help Israel Develop Stuxnet?</a> (wired.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.pcworld.com/article/216852/stuxnet_worm_was_weapon_report_says.html?tk=rss_news">Stuxnet Worm Was Weapon, Report Says</a> (pcworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.gearfuse.com/stuxnet-and-the-uncertain-future-of-the-internet-of-things/">Stuxnet and the Uncertain Future of the Internet of Things</a> (gearfuse.com)</li>
<li class="zemanta-article-ul-li"><a href="http://venturebeat.com/2011/01/15/evidence-builds-that-stuxnet-worm-was-aimed-at-averting-war-over-irans-nuclear-weapons/">Evidence builds that Stuxnet worm was aimed at averting war over Iran&#8217;s nuclear weapons</a> (venturebeat.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.v3.co.uk/v3/news/2274270/israel-stuxnet-security-virus">Israel accused of launching Stuxnet attack on Iran</a> (v3.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.google.com/news/url?sa=t&amp;fd=R&amp;usg=AFQjCNF_M5XZJVrn5cey1rm0YgBAbZ_sIA&amp;url=http://www.pakistanpatriot.com/?p%253D34061">Stuxnet attacks on Iran creating a backlash &#8211; Pakistan Patriot</a> (news.google.com)</li>
<li class="zemanta-article-ul-li"><a href="http://news.google.com/news/url?sa=t&amp;fd=R&amp;usg=AFQjCNEzJefCot1xldOan8fZEscztITL9g&amp;url=http://www.latimes.com/news/nationworld/world/la-fg-iran-cyber-war-20110117,0,2232905.story">Iran&#8217;s nuclear program and a new era of cyber war &#8211; Los Angeles Times</a> (news.google.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www10.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html?_r=5&amp;pagewanted=all">Development and testing of the Stuxnet worm</a> (nytimes.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=bf33c0fa-32ab-4d99-9bce-2e9edd109b61" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_3" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/defending-against-stuxnet-type-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d2333f6f4e0094cfb2b563c4ded3f948_thumb_natanz_visit-300x201.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Defending Against Stuxnet Type Threats</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Stuxnet%3A+An+important+change+in+the+national+security+landscape&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2010%2F09%2Fstuxnet-a-tipping-point-in-cyber-conflict%2F&nr_ad_number=0&nr_div_number=3");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_3");nRelate.adAnimation("nrelate_related_3");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>What is the Cyber Conflict Studies Association?</title>
		<link>http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/</link>
		<comments>http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/#comments</comments>
		<pubDate>Tue, 21 Sep 2010 19:00:33 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Cyber Command]]></category>
		<category><![CDATA[cyber conflict]]></category>
		<category><![CDATA[Matt Devost]]></category>
		<category><![CDATA[National security]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[United States]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=5389</guid>
		<description><![CDATA[Tweet The Cyber Conflict Studies Association (CCSA) is a non-profit organization formed to promote and lead a diversified research agenda in the field of cyber conflict.  The group was formed as a means to foster dialogue, lead research and develop academic programs focused on the implications of cyber conflict. To meet these goals, CCSA promotes [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F09%2Fwhat-is-the-cyber-conflict-studies-association%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"  data-text="What is the Cyber Conflict Studies Association?" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com"><img class="alignleft size-medium wp-image-5391" style="margin: 4px;" title="ccsa" src="http://ctovision.com/wp-content/uploads/2010/09/ccsa-300x117.png" alt="" width="300" height="117" /></a>The <a href="http://cyberconflict.org" target="_blank">Cyber Conflict Studies Association (CCSA)</a> is a non-profit organization formed to promote and lead a diversified research agenda in the field of cyber conflict.  The group was formed as a means to foster dialogue, lead research and develop academic programs focused on the implications of cyber conflict.</p>
<p>To meet these goals, CCSA promotes and leads international intellectual development efforts like workshops and conferences that bring together professionals from industry, academia and government to discuss strategic issues surrounding cyber conflict.</p>
<p>The CCSA also serves as a resource for national security decision-makers.  The CCSA contributes to framing issues promoting national cyber conflict policy.</p>
<p>How do you engage with CCSA?  If you are involved in academic research or studies in the domain, or if you are a policy-maker or thought leader in the community, engaging the CCSA is easy.  The first step is to visit the website at <a href="http://cyberconflict.org" target="_blank">http://cyberconflict.org</a> If you believe you can contribute to or benefit from the dialog please sign up for our low volume e-mail distro list. We use that to announce our workshops and conferences.</p>
<p>Another thing you can do is engage directly with the many writers/thinkers/thought leaders that are helping to move the cyber conflict agenda forward.  How you do that is a matter of personal and professional choice, of course.   But I hope one of the ways to engage with CCSA thought leaders is to read the blogs of CCSA members.  Some to check out:</p>
<ul>
<li>Halt of the Spear: <a href="http://www.haftofthespear.com" target="_blank">http://www.haftofthespear.com</a> Mike Tanji writes from experience in and out of government and his blog belongs on the reading list of anyone studying cyber conflict.</li>
<li>Devost.net: <a href="http://www.devost.net/blog" target="_blank">http://www.devost.net/blog</a> Matt Devost provides insights in issues of cyber security, counterterror and modern IT.</li>
<li>Selil.com:  <a href="http://selil.com" target="_blank">http://selil.com</a> This is the site of professors Sam and Sydney Liles. They write on cyber warfare, privacy, computer security and more.</li>
<li>CTOvision.com: <a href="http://ctovision.com" target="_blank">http://ctovision.com</a> The point and purpose of this blog is more about enterprise technology and disruptive IT, things enterprise CTOs need to track and prepare for. But the background of the blog&#8217;s <a href="http://bobgourley.com" target="_blank">founder and editor</a> causes it to hit on cyber conflict matters as well.</li>
</ul>
<p>Pulling together that quick list makes me think of another service the CCSA can provide the cyber conflict community.  We should probably ask the CCSA to establish a list of good cyber conflict blogs and twitter feeds.  As a start to that list, can you tell me please what your favorite cyber conflict blogs are?  Do you write a blog on that topic yourself?</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=b0504fd6-3476-4846-9480-6aa08bf41150" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_4" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/cyber-conflict-studies-association-history-contest/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/64bc609d4094e451d7df5fa64015c702_thumb_cyberglobe.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyber Conflict Studies Association History Contest</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b443047f5471c0cb3dea829d8bf9723f_thumb_lincoln-on-cybersecurity1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/some-thoughts-on-the-iranian-cyber-army-and-what-they-mean-to-cyber/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/dd6c3c9e21e59fb06f2b5c84ae50b770_thumb_Stuxnet-300x199.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Some Thoughts on the Iranian Cyber Army and what they mean to Cyber</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/stuxnet-a-tipping-point-in-cyber-conflict/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9537392f29a384844a3cdad42bf82da0_thumb_siemenspcs7-300x185.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Stuxnet: An important change in the national security landscape</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.devost.net/2010/09/10/furthering-the-field-a-comprehensive-program-for-cyber-conflict-studies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/blog.devost.net/b2dbdae11e8476f73761486495a6edf6_thumb_devost-net-logo.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Furthering the Field: A Comprehensive Program for Cyber Conflict Studies</span><span class="nr_source">Devost.Net</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/darpa%e2%80%99s-cyber-fast-track-adds-agility-to-research-funding/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/great-red-wood-circle-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DARPA’s Cyber Fast Track Adds Agility to Research Funding</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/trust-enterprise-security-and-autonomous-technology/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Trust, Enterprise Security, and Autonomous Technology</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/07/the-fedcyber-com-cyber-security-summit/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9864e85f16bbc4e2a15784df135f3be0_thumb_newseum.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The FedCyber.com Cyber Security Summit</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/08/calling-all-federal-cybersecurity-practitioners-contribute-ideas-and-actions-to-enhance-the-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/051005048d7941003b800b4011f29136_thumb_iwantyou.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Calling All Federal Cybersecurity Practitioners: Contribute ideas and actions ...</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=What+is+the+Cyber+Conflict+Studies+Association%3F&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2010%2F09%2Fwhat-is-the-cyber-conflict-studies-association%2F&nr_ad_number=0&nr_div_number=4");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_4");nRelate.adAnimation("nrelate_related_4");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>CTO Perspectives on Cyber Security Bill</title>
		<link>http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/</link>
		<comments>http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/#comments</comments>
		<pubDate>Sat, 12 Jun 2010 18:56:54 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Gov2.0]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=2205</guid>
		<description><![CDATA[Tweet On June 10, 2010, the US Senate Homeland Security and Governmental Affairs Committee (HSGAC) unveiled a major cybersecurity bill designed to modernize, strengthen, and coordinate US Cyber defenses. Senators Collins, Carper and Lieberman introduced this bill with the clear articulation to defend not just federal networks but the Internet itself.  As portion of the [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F06%2Fcto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"  data-text="CTO Perspectives on Cyber Security Bill" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com"><img class="alignleft size-full wp-image-2206" style="margin: 4px;" title="hsgac-liberman-collins" src="http://ctovision.com/wp-content/uploads/2010/06/hsgac-liberman-collins.jpg" alt="" width="223" height="128" /></a>On June 10, 2010, the US Senate Homeland Security and Governmental Affairs Committee (HSGAC) unveiled a major cybersecurity bill designed to modernize, strengthen, and coordinate US Cyber defenses.</p>
<p>Senators Collins, Carper and Lieberman introduced this bill with the clear articulation to defend not just federal networks but the Internet itself.  As portion of the announcement recorded by TalkRadioNews is below:<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/DhZlESsqaqk&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="385" src="http://www.youtube.com/v/DhZlESsqaqk&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>The bill itself is named the &#8220;Protecting Cyberspace as a National Asset Act of 2010.&#8221;</p>
<p>It creates an Office of Cyber Policy in the White House with a director accountable to the public to lead all federal cyberspace efforts and devise national cyberspace strategy.  A National Center for Cybersecurity and Communications within the Department of Homeland Security, also led by a director accountable to the public, to enforce cybersecurity policies through the government and even the private sector.</p>
<p><strong>Some key aspects of this Bill, from the site of the </strong><a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Press.MajorityNews&amp;ContentRecord_id=227d9e1e-5056-8059-765f-2239d301fb7f" target="_blank"><strong>HSGAC</strong></a><strong>:<br />
</strong></p>
<ol>
<li>Creation of an Office of Cyberspace Policy in the Executive Office of the President run by a Senate-confirmed Director, who will advise the President on all cybersecurity matters. The Director will lead and harmonize federal efforts to secure cyberspace and will develop a national strategy that incorporates all elements of cyberspace policy, including military, law enforcement, intelligence, and diplomatic.  The Director will oversee all related federal cyberspace activities to ensure efficiency and coordination.</li>
<li>Creation of a National Center for Cybersecurity and Communications (NCCC) at the Department of Homeland Security (DHS) to elevate and strengthen the Department’s cyber security capabilities and authorities. The Director will regularly advise the President on efforts to secure federal networks.  The NCCC will be led by a Senate-confirmed Director, who will report to the Secretary. The NCCC will include the United States Computer Emergency Response Team (US-CERT), and will lead federal efforts to protect public and private sector cyber and communications networks.</li>
<li>Updates the Federal Information Security Management Act (FISMA) to modernize federal agencies practices of protecting their internal networks and systems. With strong leadership from DHS, these reforms will allow agencies to move away from the system of after-the-fact paperwork compliance to real-time monitoring to secure critical systems.</li>
<li>Requiring the NCCC to work with the private sector to establish risk-based security requirements that strengthen cyber security for the nation’s most critical infrastructure that, if disrupted, would result in a national or regional catastrophe.</li>
<li>Requiring covered critical infrastructure to report significant breaches to the NCCC to ensure the federal government has a complete picture of the security of these sensitive networks.  The NCCC must share information, including threat analysis, with owners and operators regarding risks to their networks. The Act will provide specified liability protections to owners/operators that comply with the new risk-based security requirements.Creation of a responsible framework, developed in coordination with the private sector, for the President to authorize emergency measures to protect the nation’s most critical infrastructure if a cyber vulnerability is being exploited or is about to be exploited. The President must notify Congress in advance before exercising these emergency powers. Any emergency measures imposed must be the least disruptive necessary to respond to the threat and will expire after 30 days unless the President extends them.  The bill authorizes no new surveillance authorities and does not authorize the government to “take over” private networks.</li>
<li>Development of a comprehensive supply chain risk management strategy to address risks and threats to the information technology products and services the federal government relies upon. This strategy will allow agencies to make informed decisions when purchasing IT products and services.</li>
<li>Requiring the Office of Personnel Management to reform the way cyber security personnel are recruited, hired, and trained to ensure that the federal government has the talent necessary to lead the national cyber security effort and protect its own networks.</li>
</ol>
<p><strong>Now some analysis:</strong></p>
<ol>
<li>By ensuring the White House will have a Senate-confirmed Director, it will help underscore for the executive branch that this issue should be taken a bit more serious.  Sounds like a prudent thing for the Congress to do.</li>
<li>Creating a National Center for Cybersecurity and Communications (NCCC) in DHS with a leader also confirmed by the Senate sends a similar message, but it also empowers an individual and group to do something that no one has been authorized to do before (at least no one under the rank of President). This office will have authority to lead across government.  As a CTO with enterprise experience I respect this kind of position.  I am convinced you cannot defend large enterprises without the smart application of both central authority and decentralized action.  If you try with either of those missing you fail.  I am not worried about too much technical authority being drawn into one location, there are too many forces at play to keep that power from being abused and, if the person and staff are picked carefully, they will avoid making decisions that impact missions in a negative way.  Notice I have caveated my opinion here.  The nation must choose wisely and put a very smart technology leader in this position.  Someone who can enforce the right standards and give direction when required but can back off and let agency IT leaders run things when required and that person must be smart enough to know when and how to decide what to decide about.</li>
<li>Updating FISMA is long overdue.  Moving towards real-time monitoring is GREAT!  It is the only way I know of to move towards enhancing <a href="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/">both security and functionality at the same time</a>.</li>
<li>Naming the NCCC as the focal point for coordination with the federal sector is also a solid move.  It goes without saying, but the NCCC should be staffed and led by very savvy, very social, very action-oriented people.  Without social leaders with high emotional intelligence we stand the risk of getting what we have always gotten here.</li>
<li>As a CTO, I applaud the measures this Bill describes for removing artificial impediments to information sharing.  Government and industry need trust-based relationships and unfortunately too many laws and behaviors that flow from those laws, like FOIA, have damaged those relationships.  Addressing them head on is the right thing to do.  Technologically there are few issues here.  Issues are in policy and the Bill seems to do a good job at addressing some big ones.</li>
<li>Development of a comprehensive supply chain management strategy is another great goal I am glad to see.  There has been a great deal of action lately in establishing coordination mechanisms with senior IT leadership in the country and I believe this will serve as a good foundation for development of a strategy like this.</li>
<li>The human side of technology is one that also needs significant attention and it is good seeing the Bill address this head-on by requiring OPM to reform the way the government leads cyber security personnel.</li>
</ol>
<p><strong>Some concluding thoughts:</strong></p>
<ul>
<li>I wish I would have raised another issue with the staffers.  I feel bad about this, but I have something I would like to add to the Bill.  I guess I&#8217;m too late, but maybe I can get my input to the SSCI or HPSCI instead.  I want to suggest that the US Intelligence Community be tasked with providing a detailed yearly cyber intelligence threat assessment  for unclassified dissemination. The IC does a good job of providing some counterintelligence assessments and frequently mentions cyber in open fora like Congressional Testimony, but I believe this issue deserves a focused, NIE-like report dedicated to this topic.  Of course the IC should also be tasked with support to the NCCC.</li>
<li>I found the Bill was full of smart information coordination and information sharing language and constructs.</li>
<li>The great work of folks at NSA, <a href="http://ctovision.com/2010/05/intelligence-community-executive-forum/">Cyber Command</a> (including legacy organizations like JTF-GNO and JFCC-NW), STRATCOM, DHS, NCICC, US CERT, FBI, DC3 and many others must continue and I believe the language in this bill is very respectful of the great work that these groups have been doing.</li>
<li>I wonder who the first CTO of the NCCC will be?  That is going to be one cool job!</li>
</ul>

<div class="nr_clear"></div>	
	<div id="nrelate_related_5" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/calling-all-federal-cybersecurity-practitioners-contribute-ideas-and-actions-to-enhance-the-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/051005048d7941003b800b4011f29136_thumb_iwantyou.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Calling All Federal Cybersecurity Practitioners: Contribute ideas and actions ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/security-innovation-network-announces-the-2011-sinet-showcase-innovators/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a28140b464425a7c7fb26f56108bb248_thumb_sinet2011.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Security Innovation Network Announces the 2011 SINET Showcase Innovators</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/us-cyber-command-conducts-tactical-cyber-exercise/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/080b432ff56b98a2de6bccba83893b04_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">US Cyber Command Conducts Tactical Cyber Exercise</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/homeland-security-committee-unveils-cybersecurity-bill/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Homeland Security Committee Unveils Cybersecurity Bill</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/dodaro-key-challenges-remain-for-dhs-in-cybersecurity-mission/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Dodaro: Key challenges remain for DHS in cybersecurity mission</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/house-panel-approves-cybersecurity-bill/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">House Panel Approves Cybersecurity Bill</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/president-mentions-cyber-threats-in-state-of-the-union-address/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">President Mentions Cyber-Threats in State of the Union Address</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/chain-links/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Chain Links</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=CTO+Perspectives+on+Cyber+Security+Bill&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2010%2F06%2Fcto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee%2F&nr_ad_number=0&nr_div_number=5");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_5");nRelate.adAnimation("nrelate_related_5");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Intelligence Community Executive Forum on Cyber Operations</title>
		<link>http://ctovision.com/2010/05/intelligence-community-executive-forum/</link>
		<comments>http://ctovision.com/2010/05/intelligence-community-executive-forum/#comments</comments>
		<pubDate>Fri, 14 May 2010 01:24:23 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cyber Command]]></category>
		<category><![CDATA[DIA]]></category>
		<category><![CDATA[DNI]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[R&D]]></category>
		<category><![CDATA[Technology Leadership]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=1969</guid>
		<description><![CDATA[Tweet Carahsoft is a unique, trusted firm that helps government find and rapidly acquire the right technologies and helps high tech firms successfully interact with government (which has famously onerous processes for businesses that want to serve the federal mission).  Carahsoft is a client of my firm and one of the things I&#8217;m particularly proud [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F05%2Fintelligence-community-executive-forum%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/05/intelligence-community-executive-forum/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/05/intelligence-community-executive-forum/"  data-text="Intelligence Community Executive Forum on Cyber Operations" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/05/intelligence-community-executive-forum/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/05/intelligence-community-executive-forum/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://carahsoft.com" target="_blank">Carahsoft</a> is a unique, trusted firm that helps government find and rapidly acquire the right technologies and helps high tech firms successfully interact with government (which has famously onerous processes for businesses that want to serve the federal mission).  Carahsoft is a client of <a href="http://crucialpointllc.com" target="_blank">my firm</a> and one of the things I&#8217;m particularly proud about is their sponsorship of venues where government and industry tech leaders can interact together.  One venue of note is a series they coordinate called the <a href="http://www.carahsoft.com/event-detail/402/bg/" target="_blank">Intelligence Community Executive Forum</a>.</p>
<p>This periodic event focuses on executives from the IC and the industry companies around the IC.  Today&#8217;s session of the ICEF focused on industry and commercial technologies addressing the Comprehensive National Cybersecurity Initiative.</p>
<p>It is hard to capture the content of a venue like this.  Its true value comes from the dynamic interactions and high data rate conversations that take place throughout.  But I thought I should try to provide some gist of what happened so you can determine whether or not you should participate in future venues like this. Give the agenda below a quick glance then I&#8217;ll add some additional context:</p>
<p><span style="font-size: small;"><strong>Agenda:</strong></span></p>
<table border="1" cellspacing="0" cellpadding="6" bordercolor="#404040">
<tbody>
<tr>
<td width="120" align="center" bgcolor="#d3d3d3"><strong>7:30am &#8211;  8:00am</strong></td>
<td><strong>Registration &amp; Breakfast</strong></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>8:00am &#8211; 9:00am</strong></td>
<td><strong>Welcome and Morning Keynote</strong><br />
<strong><em>Don Boian, Technical Director, J3 Consolidated  JFCC-NW/JTF-GNO Staff</em></strong></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>9:00am &#8211; 9:45am</strong></td>
<td><strong>Information Overload and Situational Awareness</strong><br />
<strong>Moderator:</strong> <a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Landolf">Francis  Landolf</a>, <em>Principal, Core Consulting, LLC</em><br />
<strong>Government Panelist:</strong><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Ramsay">Sherri  Ramsay</a>, <em>Director of the NTOC (NSA Threat Operations Center)</em><br />
<strong>Industry Panelists:</strong><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Breissinger">Marc  Breissinger</a>, <em>Executive Vice President, Composite Software</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Frutchey">Brian  Frutchey</a>, <em>Federal Subject Matter Expert, Endeca</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Griffith">Kevin  Griffith</a>, <em>District Manager, DOD and Intelligence, Informatica</em></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>9:45am-10:30am</strong></td>
<td><strong>Information Sharing and Collaboration for Cyber Operations</strong><br />
<strong>Moderator:</strong> <a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Landolf">Francis  Landolf</a>, <em>Principal, Core Consulting, LLC</em><br />
<strong>Government Panelist:</strong><br />
Jim Bieda, <em>Deputy Chief Technology Officer, NSA</em><br />
<strong>Industry Panelists:</strong><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Kovach">Jim  Kovach</a>, <em>Director of Federal Operations, Jive</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Pianta">Dean  Pianta</a>, <em>CTO</em>, <em>EnvolveMEDIA LLC (formerly with Adobe)</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Cardwell">Rob  Cardwell</a>, <em>Vice President Middleware Technology, Red Hat</em></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>10:30am  &#8211; 11:15am</strong></td>
<td><strong>Securing the Cloud</strong><br />
<strong>Moderator:</strong> <a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Gourley">Bob  Gourley</a>, <em>Founder and CTO, Crucial Point LLC and editor of  CTOvision.com</em><br />
<strong>Government Panelists:</strong><br />
Robert Vietmeyer, <em>Director, Forge.mil, DISA</em><br />
<strong>Industry Panelists:</strong><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Trentley">Fran  Trentley</a>, <em>Senior Service Line Director, Akamai</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Randell">Rob  Randell</a>, <em>Senior Security and Compliance Specialist, VMware</em><br />
Dr. Steven Armentrout, <em>Founder and CEO, Parabon</em></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>11:15am &#8211; 12:00pm</strong></td>
<td><strong>Networking Break and Exhibits</strong></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>12:00pm &#8211; 1:00pm</strong></td>
<td><strong>Lunch Keynote</strong><br />
Tony Sager, <em>Chief of Vulnerability Analysis and Operations, NSA</em></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>1:00pm &#8211; 1:45pm</strong></td>
<td><strong>Efficiently Automating Security with Industry Best  Practices and Tools</strong><br />
<strong>Moderator:</strong> <a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Gourley">Bob  Gourley</a>, <em>Founder and CTO, Crucial Point LLC and editor of  CTOvision.com</em><br />
<strong>Government Panelist:<br />
</strong>Dr. Ted Kircher, <em>Chief Architect, NSA Threat Operations  Center</em><br />
<strong>Industry Panelists:</strong><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Cahill">Doug  Cahill</a>, <em>Vice President of Corporate Development and Product  Management, Bit9</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Unterberger">Fred  Unterberger</a>,  <em>Senior Manager, Sales Engineering, Symantec</em><br />
<a href="http://www.intelligencecommunityexecutiveforum.com/speakers.php#Hecker">Frank  Hecker</a>, <em>Federal Sales Engineer, IronKey</em></td>
</tr>
<tr>
<td align="center" bgcolor="#d3d3d3"><strong>1:45pm &#8211; 2:00pm</strong></td>
<td><strong>Q+A Session and Closing</strong></td>
</tr>
</tbody>
</table>
<p>During breaks several sponsors were providing demos and additional information on their technology including:</p>
<p><a href="http://ctovision.com/wp-content/uploads/2010/05/ICEFsponsors.jpg"></a><a href="http://ctovision.com"><img class="aligncenter size-full wp-image-1971" title="ICEFsponsors" src="http://ctovision.com/wp-content/uploads/2010/05/ICEFsponsors1.jpg" alt="" width="735" height="228" /></a><br />
<strong>A quick gist:</strong></p>
<p>Don Boian of Cyber Command provided great context and a good kickoff to dialog.  Then throughout the event, cyber thought leaders in and out of government discussed the state of current technologies and current mission needs in cyber-focused organizations.  Some of these mission needs are truly enduring.  For example, the need for defense in depth as a strategy and approach vice just point solutions.  But today, defense in depth is not enough.  Adversaries always find a way in and defenders must continuously monitor and prepare for remedial action.  With the incredibly high volumes of data and information around those intrusions new means must be found to gain insights into what is occurring and then determine the appropriate action to take.  This must be done so fast new operational constructs around &#8220;dynamic defense&#8221; are required.  Defenders require capabilities that can increase the speed of good guy decision-making.  There must be speed in vulnerability detection, speed in intrusion detection, speed in decision-making and speed in execution.  Cyber Command defenders use the phrase &#8220;operate at network speeds.&#8221;</p>
<p>Another common theme throughout the event was a call for enhanced situational awareness in the cyber domain. The bad news is that call has been made for decades now.  There has been movement in enhancing situational awareness, but nothing yet fills the need.  More work is required.</p>
<p>Another theme was the need to enable humans to interact with data in far better, far faster ways.  Cyber data needs to be rapidly run through automated tools that can enable not just search but discovery using tools like Endeca.</p>
<p>Collaboration for cyber related commands and organization is another area where many enhancements have been made lately.  In a very good trend, it seems most organizations working cyber defense/cyber operations now know of each other and have frequent interactions.  There is more need for enhanced human to human collaboration and even enterprise grade social networking/social media around cyber defense as an aide to bringing the right understanding to situations.  A capability to watch here is Jive.</p>
<p>It is not only network defenders that need collaborative capabilities.  Developers of software and those that lead/manage/interact with them, including users, need ways to collaborate.  The ICEF was treated to an overview of a very positive capability to do that, the DISA led Forge.mil .  In my opinion, the positive disruptions from this activity have just begun, far more goodness will come from this project as more and more developers make use of it.  It is speeding development of new capabilities and is also laying the foundation of what may be the biggest positive improvement in the security and testing environment in years.</p>
<p>The security aspects of Cloud Computing were discussed in detail.  A general statement: If security is engineered into cloud computing capabilities, cloud concepts can significantly enhance the security of enterprises.  However, the reverse is also true.  If security is neglected in cloud constructs it can doom us all!</p>
<p>The ICEF was treated to an interaction with Tony Sager, one of the nation&#8217;s greatest thinkers in cyber security. Tony&#8217;s ability to express technological concepts in ways we can all understand is always appreciated.  A key conclusion from Tony: we are entering a phase in cyber defense that will require enhanced information management.   Note:  Tony provided us all with context on some very important concepts that all network defenders should be tracking, SCAP, NDV and FDCC.   My personal sense from the interaction was that most in the venue who work closely with security technology new of these constructs, however, it is getting to the point where all IT professionals and all leaders in an out of government need to know these capabilities, even if you are not a security professional.  So, a recommendation:  accept it as your civic duty to study up on <a href="http://scap.nist.gov/" target="_blank">SCAP</a>, <a href="http://nvd.nist.gov/" target="_blank">NVD</a> and <a href="http://nvd.nist.gov/fdcc/index.cfm" target="_blank">FDCC</a>.</p>
<p>Other speakers, including Dr. Ted Kirscher, Chief Architect of the NSA Threat Operations Center, underscored again the need for new means to conduct highspeed assessment of the right data from defensive devices.  Ted, like everyone else who spoke, also ensured we all knew the collaborative nature of the work in front of us all.</p>
<p>For the many people I heard from this was a day well spent, a time to reflect on progress and to think through the next priorities to address.  There are some huge challenges that confront cyber defenders, but with new organizational constructs and new focus being placed on the mission these challenges are certainly achievable.  Some might still look impossible, but hey, like Walt Disney said, &#8220;It&#8217;s kind of fun to do the impossible.&#8221;</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_6" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/technology-firms-at-the-dodiis-worldwide/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/f69cb0fcf79815b4d0ba395f43cfcae3_thumb_accentureLogo.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Technology Firms at the DoDIIS Worldwide</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/03/symantec-government-technology-summit-16-march-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6a1b665c6e5a93856236951c17478392_thumb_hyatt-300x148.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Symantec Government Technology Summit 16 March 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/how-is-the-dodiis-conference-going/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/66177614662b68b13ee8888f88f04139_thumb_computer-technology-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">How is the DoDIIS Conference Going?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/federal-government-deduplication-strategies-worth-duplicating/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/8da76c1aab9f1f514f0996b6ee9958b2_thumb_uscapital.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Federal Government Deduplication Strategies Worth Duplicating</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/fdcci-preparation-with-virtual-instruments-and-carahsoft/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/great-red-wood-circle-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FDCCI Preparation with Virtual Instruments and Carahsoft</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/cloudera-and-carahsoft-webinar-big-data-success-in-government-19-jan-2012/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera and Carahsoft Webinar: Big Data Success in Government 19 Jan 2012</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/12/government-big-data-forum-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7b0a9844161550a1efff7169611f0270_thumb_3.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Government Big Data Forum 2011</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/04/ctolabs-com-survey-finds-data-deduplication-aids-in-managing-data-growth-in-federal-agencies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTOlabs.com Survey Finds Data Deduplication Aids in Managing Data Growth in F ...</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Intelligence+Community+Executive+Forum+on+Cyber+Operations&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2010%2F05%2Fintelligence-community-executive-forum%2F&nr_ad_number=0&nr_div_number=6");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_6");nRelate.adAnimation("nrelate_related_6");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/05/intelligence-community-executive-forum/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Twelve Principles of DoD Cyber Conflict</title>
		<link>http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/</link>
		<comments>http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/#comments</comments>
		<pubDate>Sun, 14 Feb 2010 04:01:29 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CTO Principles]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=1689</guid>
		<description><![CDATA[Tweet While rummaging through old files on my hard drive I encountered a piece I wrote in June 2002 which captured in writing something I had been briefing for several years.  I had been briefing &#8220;Principles&#8221; which I had observed/learned while the J2 of DoD&#8217;s JTF-CND and then later J2 of JTF-CNO.   My theory was [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F02%2Ftwelve-principles-of-dod-cyber-conflict%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/"  data-text="Twelve Principles of DoD Cyber Conflict" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>While rummaging through old files on my hard drive I encountered a piece I wrote in June 2002 which captured in writing something I had been briefing for several years.  I had been briefing &#8220;Principles&#8221; which I had observed/learned while the J2 of DoD&#8217;s JTF-CND and then later J2 of JTF-CNO.   My theory was that just as Admiral Bill Studeman has helped intelligence professionals understand their craft better by articulating principles, I could help build understanding of the new field of cyber conflict by generating dialog on principles.</p>
<p>I can&#8217;t take credit for any of these principles.  I really just wrote them down.  Many are things I observed or heard from others in the JTF at that time, like Marc Sachs, John Owens, Jay Healey and Michele Iverson.  There are also many common themes I learned from Rick Forno, Dan Kuehl and Matt Devost and others.</p>
<p>Now about a decade after I started briefing these principles I just reviewed them and think they still meet key requirements you would expect true principles to hold.  They still ring true and they still have insights relevant to operational decision-making, and, although they are definitely general in nature, I believe they still have a role in helping orient people to the missions of computer network defense (CND), computer network exploitation (CNE) and computer network attack (CNA).</p>
<p>Please give these a glance, and if you know a cyber warrior somewhere who you think would appreciate them please route them on.</p>
<p>One of these days I&#8217;ll re-write this to update the acronyms and get rid of the reference to the ancient US Space Command. So please let me know if you think I&#8217;ve missed something that should be captured  as a principle, or if you think I have put any of these in the wrong  context.</p>
<p><!-- 		@page { margin: 0.79in } 		P.sdfootnote { margin-left: 0.2in; text-indent: -0.2in; margin-bottom: 0in; font-size: 10pt } 		P { margin-bottom: 0.08in } 		A.sdfootnoteanc { font-size: 57% } --></p>
<p style="text-align: center;"><strong><span style="font-family: Arial,sans-serif;">Twelve Principles of Computer Network Operations<br />
June 2002<br />
Bob Gourley</span></strong></p>
<p><span style="font-family: Arial,sans-serif;">A growing number of uniformed military and government civilians practice the new military discipline of Computer Network Operations (CNO).   CNO in the Department of Defense (DoD) consists of two specific yet complementary mission areas: Computer Network Defense (CND) and Computer Network Attack (CNA).</span></p>
<p><span style="font-family: Arial,sans-serif;">The CND mission is to protect and defend DoD computer networks, systems and the data that resides in them any unauthorized event whether it be a probe, scan, virus incident, or intrusion.</span><sup><span style="font-family: Arial,sans-serif;"><a name="sdfootnote1anc" href="#sdfootnote1sym"><sup>1</sup></a></span></sup><span style="font-family: Arial,sans-serif;"> The CNA mission is to coordinate, support and conduct, at the direction of the National Command Authority (NCA), computer network attack operations in support of regional and national objectives.  CNA operations are designed to disrupt, deny, degrade or destroy adversary information resident in computers and computer networks.</span><sup><span style="font-family: Arial,sans-serif;"><a name="sdfootnote2anc" href="#sdfootnote2sym"><sup>2</sup></a></span></sup><span style="font-family: Arial,sans-serif;"> </span></p>
<p><span style="font-family: Arial,sans-serif;">Operational lead for the DoD&#8217;s CNO efforts is USSPACECOM&#8217;s Joint Task Force for Computer Network Operations (JTF-CNO).   But increasingly, traditional military forces are being called upon to conduct CNO operations by enhancing the defensive posture of networks under their control, by taking action against attacks, or by participating in attack planning or operations. </span></p>
<p><span style="font-family: Arial,sans-serif;">In most other warfare areas, Commanders can rely on established military doctrine to guide them in implementing and executing their missions.</span><sup><span style="font-family: Arial,sans-serif;"> <a name="sdfootnote3anc" href="#sdfootnote3sym"><sup>3</sup></a> </span></sup><span style="font-family: Arial,sans-serif;"> The CNO mission is new, however, and little formal joint doctrine exists in this mission area. </span></p>
<p><span style="font-family: Arial,sans-serif;">This article provides firsthand observations on twelve key principles of CNO.   I believe these observations can provide other CNO practitioners with a critical foundation required for successful CNO.  These principles will also be of use to officers who whish to engage in the ongoing national security and policy discussions concerning CNO.  After further examination and feedback from the field and the fleet, we expect them to become cornerstones of a new joint doctrine for CNO.  Until then, I offer, Twelve Principles of CNO.  They are:</span></p>
<p><span style="font-family: Arial,sans-serif;">#1  The Chain</span></p>
<p><span style="font-family: Arial,sans-serif;">#2  The Perimeter</span></p>
<p><span style="font-family: Arial,sans-serif;">#3  Interconnection</span></p>
<p><span style="font-family: Arial,sans-serif;">#4  The Laundry</span></p>
<p><span style="font-family: Arial,sans-serif;">#5  Prior Planning Prevents Poor Performance</span></p>
<p><span style="font-family: Arial,sans-serif;">#6  Know the Enemy</span></p>
<p><span style="font-family: Arial,sans-serif;">#7  Experience Counts</span></p>
<p><span style="font-family: Arial,sans-serif;">#8  Users Need Help</span></p>
<p><span style="font-family: Arial,sans-serif;">#9  Relativity</span></p>
<p><span style="font-family: Arial,sans-serif;">#10  One Basket?</span></p>
<p><span style="font-family: Arial,sans-serif;">#11  Unintended Consequences</span></p>
<p><span style="font-family: Arial,sans-serif;">#12  The Beauty of Attack</span></p>
<p><span style="font-family: Arial,sans-serif;">A bit more on all of the above is provided below:<br />
</span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#1 The Principle of the Chain.</strong> CNO is a chain; it&#8217;s only as strong as the weakest link.  Like most of the rest of the principles outlined here, this sounds intuitive.  But it is very important to stress this concept in the CNO world.  Inattention to detail will ruin your CNO plans, whether for defense or offense.  Two short illustrations: </span></p>
<p><span style="font-family: Arial,sans-serif;">- You fortify and protect an enclave by putting firewalls and IDS&#8217;s on gateways and hardening workstation software.  But there are so many configuration choices for your IDS and firewall, and so many other settings you must make to ensure your enclave is secure.  Did you overlook anything?  Are your users trained?  Do you have a response policy in place?  Are you running the most up to date anti-virus software on your mail server?  Should it be on individual workstations?  These and many other questions must be considered by security professionals or any one could be the link that breaks the security chain. </span></p>
<p><span style="font-family: Arial,sans-serif;">- The chain for attack will also have weak links.  This is easy for military professionals from any discipline to understand.  All combat actions in any warfare area have potential weak links that can frustrate your attack or even lead to exploitation of your own forces.  In the CNO realm the weak link may be the ability of an adversary to repair a patch in an application or the ability of an adversary to re-boot a router. </span></p>
<p><span style="font-family: Arial,sans-serif;">How do you protect against the weakest link?  Attention to detail. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#2 The Principle of the Perimeter.</strong> Defenders must protect against every vulnerability.  Attackers must only find one security flaw.  A rough analogy is the requirement to continuously defend an Aircraft Carrier Battle Group in a high threat environment where attacks might come from below the sea or from the air or even from land.  This principle calls for constant vigilance along every potential avenue of approach.   CNO defenses must be robust and mobile. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#3 The Interconnection Principle.</strong> CNO is a multi-faceted discipline that includes military, civil, foreign, domestic, offense, defense, technology and human factor issues.    It is an observable fact that we are all interconnected in this business.  Decisions made in one area frequently have impacts in the other areas.  That makes coordination between stakeholders and leaders in those areas an important goal that will result in better community-wide solutions.  However, if taken to the extreme, this coordination can be a recipe for paralysis.  Sometimes unilateral decisions must be made. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#4 The Principle of the Laundry.</strong> CNO is a continual process (like laundry, something always needs cleaning). Vulnerabilities in old software are discovered daily and new software is continually being produced and integrated into our architectures.  All indications are that new software is just as buggy and has just as many vulnerabilities as old software, so we can expect the continued stream of vulnerability announcements to continue.  Vulnerabilities that must be cleaned up and repaired as they are discovered.  This is a never ending process. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#5 The Principle of Prior Planning.</strong> CNO must be pre-planned; you don&#8217;t just do it at the last minute and expect it to be done well.  Too frequently the developers of systems and networks pay too little attention to security when they design their systems.  We have found out the hard way that tacking it on the end just doesn&#8217;t work.  This adage applies to users as well.  If an organization does not think through the policies its users must adhere to, and does not train its users to be secure till it is too late, then the result will be poor security.   The same thoughts hold true in the offensive sides to CNO.  CNA requires extensive planning and coordination in advance. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#6 Know the Enemy.</strong> You must know your enemy better than your enemy knows you.  This is easy to say but in practice very hard to accomplish, especially in the interconnected world of the Internet, where adversaries can take steps to hide their identify.   But steps can be taken that let you make reasonable assumptions about your adversary before you know exactly who it is.  These assumptions, combined with a continual study of threat actors will lead to a better ability to prevent, detect, react and defeat adversary activity. </span></p>
<p><span style="font-family: Arial,sans-serif;">You can and should also take steps to hide key information from your adversaries.  All DoD unclassified networks should be under the umbrella of the NIPRNET, which affords some obscurity and protection from enumeration by an adversary.  Enclaves should be configured to deny as much information as possible to potential adversaries.  There is no reason why we should make the attacker&#8217;s job easier. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#7 The Principle of Professional Experience</strong>.  Inexperienced CNO professionals are not CNO professionals.    It is so easy in this business to find pseudo experts who can give a great brief or can market a CNO concept but have no first hand knowledge of how networks work or how to defend them.  How do you tell a pseudo expert from a real expert?   Be skeptical of anyone in this field till they have proven themselves to you.  Ask for credentials, certifications, degrees or what their on the job experience is.  Don&#8217;t be afraid to quiz them.  No matter how polished they look, you want experience in this business. </span></p>
<p><span style="font-family: Arial,sans-serif;">- An important corollary for Commanders is that like in every other warfighting area, your people are paramount.   Commanders must take responsibility to ensure that their CNO operators are trained and ready for the tasks that will face them. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#8  The Principle of User Faith.</strong> Users have no good way of comparing the security or vulnerability of systems.  How can an individual user really tell that a system is secure?  Is PKI secure?  Is DMS secure?   Who and what should a user trust?  The current answer in DoD is that users must trust the systems managers in their organization, and those leaders must in turn trust accrediting authorities and program managers.  We hope the corollary to this adage becomes &#8220;Trust, but verify.&#8221;</span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#9 The Principle of CNO Relativity.</strong> CNO is relative; no system will ever be 100% secure.  This truism was realized long ago by the greats of the information security business, and has been witnessed again and again in DoD&#8217;s efforts. </span></p>
<p><span style="font-family: Arial,sans-serif;">- This truism is especially important in DoD, where we face some very sophisticated adversaries.  Since no system can ever be 100% secure, if you want to be 100% certain that your information is protected, do not store it in any computer system anywhere.  Of course this is unrealistic.  But the point is that owners of information should weigh the risks vs. rewards of storing information in a computer system, and should take appropriate steps to protect computers and networks storing sensitive information. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#10 The Principle of the Single Basket.</strong> Never rely on technology (or anything else) as your only line of defense.   This principle should seem intuitive to any operational military professional.    No defender in combat would try to mount a defense with only one type of weapon, tool or technique.   This is just as important in the CNO world, where true hackers will never give up, and where more sophisticated adversaries will try attacking through paths we may not have even considered yet. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#11 The Principle of Unintended Consequences.</strong> This applies to all aspects of the art of CNO, both offense and defense.  Keep in mind that no matter how much you think these things through, there will age some risks of unintended consequences. </span></p>
<p><span style="font-family: Arial,sans-serif;"><strong>#12 The Principle of the Beauty of Attack.</strong> Sometimes you must take the fight to the enemy.  To the military this frequently means the ability to use force on a battlefield to compel an enemy to do our will.  But this principle is meant to bring to mind far more than that.  In some cases, the US Government will have an ability to carry the fight to an adversary by attacking their computers.  Individuals and individual units cannot do this, of course.  This is a response reserved for decision-makers at the highest levels of government.  But there are means for individuals and individual units to take action against attackers.  Action can be taken by collecting detailed logs of the attacks and contacting law enforcement officials at the earliest possible moment. </span></p>
<p><span style="font-family: Arial,sans-serif;">The principles presented here are meant to explain the workings of a well-functioning computer network operations effort.  They will be of use to any military professional struggling with the best ways to implement successful CNO in their organizations. </span></p>
<p><span style="font-family: Arial,sans-serif;">Are there other principles of CNO?  Almost certainly.  The disciplines of Computer Network Defense and Computer Network Attack are still new ones, and as they spread throughout the combat forces of DoD more principles, best practices and even doctrine will arise to help guide us as we prepare for combat.   Consider the list above a start.  It contains basic generalizations that I hold as true, that I propose to you as a starting point as you reason through your role in this mission. </span></p>
<div id="sdfootnote1">
<p><a name="sdfootnote1sym" href="#sdfootnote1anc">1</a><span style="font-family: Arial,sans-serif;"> Joint Publication 1-02, &#8220;DOD Dictionary of Military and 	Associated Terms.&#8221;  Available online at: 	http://www.dtic.mil/doctrine/jel/doddict/</span></p>
</div>
<div id="sdfootnote2">
<p><a name="sdfootnote2sym" href="#sdfootnote2anc">2</a><span style="font-family: Arial,sans-serif;"> Joint Publication 1-02, &#8220;DOD Dictionary of Military and 	Associated Terms.&#8221;  Available online at: 	http://www.dtic.mil/doctrine/jel/doddict/</span></p>
</div>
<div id="sdfootnote3">
<p><a name="sdfootnote3sym" href="#sdfootnote3anc">3</a><span style="font-family: Arial,sans-serif;"> Doctrine is the &#8220;Fundamental principles by which the military 	forces or elements thereof guide their actions in support of 	national objectives. It is authoritative but requires judgment in 	application.&#8221; Joint Publication 1-02, &#8220;DOD Dictionary of 	Military and Associated Terms.&#8221;  Available online at: 	http://www.dtic.mil/doctrine/jel/doddict/</span></p>
</div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_7" class="nrelate nrelate_related nrelate_default nr_100"><!-- no data found 200 --></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_7");nRelate.adAnimation("nrelate_related_7");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/02/twelve-principles-of-dod-cyber-conflict/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>White House Cyber Policy Review: And a Cyber Czar</title>
		<link>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/</link>
		<comments>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/#comments</comments>
		<pubDate>Fri, 29 May 2009 20:16:49 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Russian government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Vladimir Putin]]></category>
		<category><![CDATA[White House]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=405</guid>
		<description><![CDATA[Tweet I enjoyed listening to the President today as he provided an update on where we are in our efforts to enhance our freedom of action in cyberspace.  All the details are on the White House website and I hope you visit there yourself to download the 60-day cyberspace policy review. Details are here: http://www.whitehouse.gov/CyberReview/ [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fwhite-house-cyber-policy-review-and-a-cyber-czar%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"  data-text="White House Cyber Policy Review: And a Cyber Czar" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-medium wp-image-411" style="border: 1px solid black; margin: 4px;" title="obama1" src="http://ctovision.com/wp-content/uploads/2009/05/obama1-300x168.jpg" alt="obama1" width="270" height="151" />I enjoyed listening to the President today as he provided an update on where we are in our efforts to enhance our freedom of action in cyberspace.  All the details are on the White House website and I hope you visit there yourself to download the 60-day cyberspace policy review. Details are here: <a href="http://www.whitehouse.gov/CyberReview/" target="_blank">http://www.whitehouse.gov/CyberReview/</a></p>
<p>I have been reading the report already&#8211; and will also read all the papers and studies referenced there.</p>
<p>So far I have three comments:</p>
<p>1) I really enjoyed hearing the President reference Melissa Hathaway.  She has done an incredible job and to hear him praise her was music to my ears.  Melissa deserves the thanks of the nation.</p>
<p>2) A great deal of work remains to be done. The policy review provides a framework for action and guidance that will help prioritize activities, but don&#8217;t expect instant miracles.</p>
<p>3) Number one on the list of near term actions is to appoint a cybersecurity policy official. The President did not do that today.  That will be done in due time.  I should also point out that no one in government is using the term &#8220;Cyber Czar&#8221; for this position.  That term Czar is used by all the reporters and all the pundits.  It sounds cool.  It also brings lots of baggage.  The typical &#8220;Czar&#8221; in DC is a powerless position that has little or no effect.</p>
<p>To underscore that point I&#8217;d like to close with a little self-plagerization.  A reprint of a blog post I first wrote in January 2009 titled &#8220;<a href="http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/" target="_blank">We have a cyber czar, and he has spoken.</a>&#8220;  In the post, now below, I try to make the point that if Putin can accomplish his objectives in our networks then he is our cyber czar.  I also hope to make the point that we should not be happy with him being in this position.</p>
<h1>We Have A Cyber Czar, and He Has Spoken</h1>
<p><img class="alignleft size-medium wp-image-401" title="DAVOS/" src="http://ctovision.com/wp-content/uploads/2009/01/putinatdavos-300x200.jpg" alt="DAVOS/" width="209" height="139" /></p>
<p>A debate has been running for months both among government thought leaders and the technical literati on whether or not the US should appoint a &#8220;Cyber Czar&#8221; who can exert authority over IT security in the federal space or perhaps even aspects of the nation&#8217;s IT defenses.  This is a complex discussion that has had some of the greatest thinkers in and out of government involved.   A great snapshot of issues and the opinions of many well reasoned experts are expressed in the CSIS report &#8220;<a href="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/">Securing Cyberspace for the 44th Presidency</a>&#8220;   and other thoughts are here: <a href="http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/">The Future of Cyber Security</a> and here: <a href="http://ctovision.com/2009/01/threats-in-the-age-of-obama/">Threats In the Age of Obama</a> .</p>
<p>Unfortunately for those who would like to still debate and discuss this issue, there is already a Cyber Czar who can accomplish most all his objectives in our networks.  His name is Russian Prime Minister Vladimir Putin.  This former KGB operative now controls Russia with an iron fist and has shown others again and again he will exert influence anywhere he needs to in order to accomplish his objectives.  He will use tanks when required and cyber when desired and combinations when it suits him.  There are indications his agents are also in our networks now.  If our objectives are to keep players like him out, we cannot say we are accomplishing them.  If his objectives are to get in, then we can say he is accomplishing them.  Till this situation changes, we need to confront then this new reality:  <strong>Vladimir Putin is the Cyber Czar.</strong></p>
<p>We have our own great technologists and wizards of cyber, of course. And we have great hero entrepreneurs of technology who have built the cyber world we all use today.  One of those greats is Michael Dell, creator of an idea and corporation that develops, manufactures, sells and distributes personal computers we all depend on.</p>
<p>But he is someone who will now think twice before thinking he can interact as a peer to Cyber Czar Putin.  After listening to Putin&#8217;s speech at the <a href="http://www.weforum.org/en/index.htm">World Economic Forum</a> in Davos, Michael Dell praised Russia&#8217;s technical and scientific prowess and asked a nice, friendly question:  &#8220;How can we help.&#8221;  As a former govie CTO I would get asked that type of question all the time from industry and really appreciated it whenever a senior thought leader would ask that.  But not Czar Putin.  He did not appreciate that at all.   Putin was offended by the assertion that the mighty Russia might need help in anything Cyber. The exchange is captured here on YouTube:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p><a href="http://money.cnn.com/2009/01/28/news/companies/dell.davos.fortune/">Fortune</a>: described the exchange this way:</p>
<p>&#8220;Putin&#8217;s withering reply to Dell: &#8220;We don&#8217;t need help. We are not invalids. We don&#8217;t have limited mental capacity.&#8221; The slapdown took many of the people in the audience by surprise. Putin then went on to outline some of the steps the Russian government has taken to wire up the country, including remote villages in Siberia. And, in a final dig at Dell, he talked about how Russian scientists were rightly respected not for their hardware, but for their software. The implication: Any old fool can build a PC outfit.&#8221;</p>
<p>Clearly cyber domination is personal with Putin.  He is the Cyber Czar.</p>
<p>I think I should end with a plea to all who care about cyber freedom and all who know the potential positive contributions of IT:  Please don&#8217;t be pleased with this current situation.  Please don&#8217;t just think the title of Cyber Czar I&#8217;ve now used to describe Putin is something we should be proud of.  It is not.  We should continue to act till we are able to assert that we are masters of our own networks.  Our nation&#8217;s intellectual property, including the intellectual property of all our companies and citizens, is too important to let it be given away without at least a cyber fight.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_8" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/interested-in-cyber-security-read-and-support-the-new-cybersecurity-legislative-proposal/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22287c15091f7562d56a24afb02c8118_thumb_CNO-pic.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Interested in Cyber Security? Read (and support) the new Cybersecurity Legisl ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/deputy-secretary-of-defense-lynn-cyber-strategy%e2%80%99s-thrust-is-defensive/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fa5ccb5775a00b753a4d3a3d6317d2a6_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Deputy Secretary of Defense Lynn: Cyber Strategy’s Thrust is Defensive</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/calling-all-federal-cybersecurity-practitioners-contribute-ideas-and-actions-to-enhance-the-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/051005048d7941003b800b4011f29136_thumb_iwantyou.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Calling All Federal Cybersecurity Practitioners: Contribute ideas and actions ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/05/the-u-s-international-strategy-for-cyberspace/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a8a2beedd8b0fdd27d42eac052551cb1_thumb_Department_of_state.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The U.S. International Strategy for Cyberspace</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/09/jtf-cnd-to-jtf-cno-to-jtf-gno-to-cybercom/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0a356c95fe882b318e7d87a475ce381e_thumb_300px-Jtf-gno1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">JTF-CND to JTF-CNO to JTF-GNO to Cybercom</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/07/the-fedcyber-com-cyber-security-summit/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9864e85f16bbc4e2a15784df135f3be0_thumb_newseum.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The FedCyber.com Cyber Security Summit</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/cyber-conflict-studies-association-history-contest/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyber Conflict Studies Association History Contest</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=White+House+Cyber+Policy+Review%3A+And+a+Cyber+Czar&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fwhite-house-cyber-policy-review-and-a-cyber-czar%2F&nr_ad_number=0&nr_div_number=8");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_8");nRelate.adAnimation("nrelate_related_8");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DoDIIS Worldwide Conference 17-21 May 2009</title>
		<link>http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/</link>
		<comments>http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/#comments</comments>
		<pubDate>Thu, 07 May 2009 20:07:20 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DIA]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[DoDIIS]]></category>
		<category><![CDATA[endeca]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Mashup]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[NRO]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=302</guid>
		<description><![CDATA[Tweet The DoDIIS Worldwide Conference will be held in Orlando Florida this year, at the Orlando World Center Marriott. I really like this conference.  It is filled with folks I like and centers around a hard enterprise mission that cries out for strong IT solutions. The theme of this years conference is &#8220;Empowering Decision Advantage.&#8221;  [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fdodiis-worldwide-conference-17-21-may-2009%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/"  data-text="DoDIIS Worldwide Conference 17-21 May 2009" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2009/05/dodiis09_image.jpg"><img class="alignleft size-full wp-image-305" title="dodiis09_image" src="http://ctovision.com/wp-content/uploads/2009/05/dodiis09_image.jpg" alt="dodiis09_image" width="80" height="80" /></a>The<a href="http://www.ncsi.com/dodiis09/index.shtml" target="_blank"> DoDIIS Worldwide Conference </a>will be held in Orlando Florida this year, at the Orlando World Center Marriott. I really like this conference.  It is filled with folks I like and centers around a hard enterprise mission that cries out for strong IT solutions.</p>
<p>The theme of this years conference is &#8220;Empowering Decision Advantage.&#8221;  The plenary speakers this year are GREAT! (as usual).  They include Grant Schneider, CIO for DIA, LTG Ron Burgess, Director of DIA, Sherrill Nicely, ODNI CIO, Pres Winter, Info Integration at ODNI, Major General John Custer of the Army Intelligence Center, and an incredible panel of all key IC CIOs.  This panel includes Grant Schneider, Al Tarasiuk (CIO CIA), Charles Barlow (CIO, NRO), Kelly Miller (CIO, NSA), Chad Fulgum (CIO FBI), Craig Kaucher (CIO DHS), Bobby Laurine, CIO NGA, Sherrill Nicely and Pres Winter.   This is going to be an awesome panel.  Really.</p>
<p>I&#8217;ve been asked to speak at a breakout session and am honored to do that.  The presentation I&#8217;ve been working on is an updated version of a briefing I used to track the future of IT.  This briefing considers five &#8220;Mega Trends&#8221; in the IT world and then talks about some specific technologies that hold high potential of changing the IT landscape.  I&#8217;ll be presenting Tuesday at 1500.  If you are a CTO or other enterprise technologist I would really appreciate seeing you there.</p>
<p>A key thing I really like about this conference is the expo floor.  I&#8217;ve been known to roam around in there for hours, going from one technology demo to the next.  This is where America&#8217;s greatest technologies are demonstrated.  Every major IT firm will be there, and so will every IT savvy integrator.  Every great application developer and every great mashup capability will be there.   Companies like Carahsoft, Endeca, Adobe, Symantec, Sun, Cisco, Microsoft, Oracle, JackBe and many more will be there.  I can&#8217;t wait to catch up with all of them there.</p>
<p>For more on the conference please see:  <a href="http://ncsi.com" target="_blank">http://ncsi.com</a>.  NCSI always puts on a great event.</p>
<p>If you are going to be there and will be up on Twitter please drop me a note or connect to me on Twitter <a href="http://www.twitter.com/bobgourley" target="_blank">@bobgourley</a>.  I&#8217;d like to track what you are putting out there.  I hope to be on twitter a bit myself there, but may be too excited to type.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_9" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/how-is-the-dodiis-conference-going/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/66177614662b68b13ee8888f88f04139_thumb_computer-technology-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">How is the DoDIIS Conference Going?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/03/2011-dodiis-worldwide-conference/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/cdddf8d442c8c7c2e702356bdbffe164_thumb_dia_seal.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">2011 DoDIIS Worldwide Conference</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/dodiis-conference-agenda-published/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DoDIIS Conference Agenda Published</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/general-dynamics-press-release-on-site/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-abstract-glass.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">General Dynamics Press Release on SITE</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/technology-firms-at-the-dodiis-worldwide/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/f69cb0fcf79815b4d0ba395f43cfcae3_thumb_accentureLogo.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Technology Firms at the DoDIIS Worldwide</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/latest-dodgeretort-%e2%80%93-gao-federal-cio%e2%80%99s-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort – GAO: Federal CIO’s need to focus more on information man ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/nominating-technologies-for-review-at-ctolabs-com/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Nominating Technologies For Review At CTOlabs.com</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/04/dodiistech-com-is-a-new-reference-for-dodiis-technologists/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DoDIISTech.com is a new reference for DoDIIS technologists</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/05/2010-dodiis-worldwide-conference/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/19e6131b6d2ff09319fb2031d793a30a_thumb_300px-DIAC.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">2010 DoDIIS Worldwide Conference</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/05/dodiis-technology-a-need-for-better-ways-to-understand-and-assess/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/ad7622531f28dfc1212d8e7266ce65c8_thumb_dtw-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DoDIIS Technology: A need for better ways to understand and assess</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=DoDIIS+Worldwide+Conference+17-21+May+2009&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fdodiis-worldwide-conference-17-21-may-2009%2F&nr_ad_number=0&nr_div_number=9");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_9");nRelate.adAnimation("nrelate_related_9");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/05/dodiis-worldwide-conference-17-21-may-2009/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Melissa Hathaway speaks at Intelligence and National Security Alliance</title>
		<link>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/</link>
		<comments>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/#comments</comments>
		<pubDate>Fri, 01 May 2009 10:28:22 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=279</guid>
		<description><![CDATA[Tweet INSA, the Intelligence and National Security Alliance, is a group of professionals from academia, industry and government who seek to enhance innovation, discussion, debate and progress on key national security issues.  I&#8217;ve been involved as a member for years and get the pleasure of interacting with folks from a wide swath of the community. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fmelissa-hathaway-speaks-at-intelligence-and-national-security-alliance%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"  data-text="Melissa Hathaway speaks at Intelligence and National Security Alliance" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2009/05/melissa-hathaway.jpg"><img class="alignleft size-full wp-image-297" style="border: 2px solid black; margin: 4px;" title="melissa-hathaway" src="http://ctovision.com/wp-content/uploads/2009/05/melissa-hathaway.jpg" alt="melissa-hathaway" width="117" height="137" /></a>INSA, the <a href="http://insaonline.org/" target="_blank">Intelligence and National Security Alliance</a>, is a group of professionals from academia, industry and government who seek to enhance innovation, discussion, debate and progress on key national security issues.  I&#8217;ve been involved as a member for years and get the pleasure of interacting with folks from a wide swath of the community.</p>
<p>One of the many services INSA provides the community is providing a venue for speakers and community leaders to interact.  INSA did that again just last night when their Distinguished Speaker Series featured <a href="http://insaonline.org/index.php?id=608" target="_blank">Melissa Hathaway</a>.  Melissa, who I have previously called the most effective and efficient senior executive in government today, spoke on the topic  of the White House Cyber Security 60-day review.</p>
<p>I watched Melissa&#8217;s RSA presentation, and for those who did or for those who have been engaged with her during this review, last nights presentation was in consonance with what we know of the hard task she has been working on (if you haven&#8217;t watched it yet, I&#8217;d recommend you take a look now, at:  <a href="http://media.omediaweb.com/rsa2009/keynote_catalog.htm" target="_blank">http://media.omediaweb.com/rsa2009/keynote_catalog.htm</a> )</p>
<p>A couple thoughts from a CTO perspective:</p>
<p>- Like so many other problems, tackling this one requires both a knowledge of technology and of people. Both technology and people must be influenced.</p>
<p>- When it comes to people, Melissa mentioned the book  <a href="http://www.amazon.com/gp/product/007148499X?ie=UTF8&amp;tag=netbooks00&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=007148499X">Influencer: The Power to Change Anything</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=netbooks00&amp;l=as2&amp;o=1&amp;a=007148499X" border="0" alt="" width="1" height="1" /> .  I haven&#8217;t read it yet, but have just added it to my Amazon wish list and will be getting it soon. Melissa said the authors of the &#8220;Influencer&#8221; book say there is power in everyone to make a change and therefore everyone should get engaged, and in this cyber context she asked everyone at INSA to stay engaged.  She wants folks to continue to dive in and stay involved and form views and move out.</p>
<p>- One of the most important ways the federal government influences is through law.  Our great government flows from a great Constitution and, although it was not a civics lesson last night, Melissa did mention the incredible legal review that these many cyber issues have been through.  She said over 80 significant legal issues were reviewed.  The report, when it is released, will have a 150 page legal annex that captures some of the opinion of federal legal experts from across the government.   As for me, I intend on reading every page of the report, and will pay particular attention to this legal section.</p>
<p>- Now that I&#8217;ve had time to think about what Melissa said, I think we (the nation, and we humans everywhere) are going to need more work to be done on how we influence technology.   I&#8217;ve tried hard to think through this from a security perspective, and I know there are things we can do right now to improve things in this regard (and I&#8217;ve provided papers to Melissa&#8217;s study team on a couple significant constructs like enhancing security through smart use of cloud computing and through smart use of open source).  But there is still much much more work to be done in this area.   CTOs cannot rest on this topic, yet.  In fact, I am not comfortable with the state of technology leadership in this area and I think all of us technologists need to follow Melissa&#8217;s advice.  We all need to get engaged and get a view and move out.</p>
<p>Part of the event last night was a networking reception where INSA members from academia, industry and government could chat.  The gist of the conversations confirmed what I have long thought, everyone wants Melissa to succeed and a wide swath of people are lining up to follow her lead.  She has done a great job at building a broad team and we are all looking forward to her continued leadership on things cyber.</p>
<p>For more on this topic see:  <a href="http://ctovision.com/category/cyber-initiative/" target="_self">http://ctovision.com/category/cyber-initiative/</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_10" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/melissa-hathaway-compelling-action-along-a-broad-front/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/860c2d78b8b85c4eb1767454fe06f887_thumb_MelissaHathaway.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Melissa Hathaway: Compelling action along a broad front</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/prediction-bluecat-networks-is-one-you-should-watch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/25d9b473e4d7b18a8df83ca74b587b44_thumb_bluecat-networks-300x92.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Prediction: BlueCat Networks is one you should watch</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/dodiis-conference-agenda-published/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DoDIIS Conference Agenda Published</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/new-boeing-intelligence-collaboration-center/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Boeing Intelligence Collaboration Center</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/2010-dodiis-worldwide-conference/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/19e6131b6d2ff09319fb2031d793a30a_thumb_300px-DIAC.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">2010 DoDIIS Worldwide Conference</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/how-much-freedom-will-you-give-up-to-fight-international-cybercrime/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mountains-dust.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">How Much Freedom Will You Give Up to Fight International Cybercrime?</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/us-needs-to-kick-network-security-intelligence-up-a-notch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">US needs to kick network security intelligence up a notch</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/a-first-for-the-nation-nerc-completes-first-grid-security-exercise/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A First For The Nation: NERC Completes First Grid Security Exercise</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/former-head-of-national-counterterrorism-center-michael-leiter-to-keynote-counter-terror-expo-us/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Former Head of National Counterterrorism Center, Michael Leiter, to Keynote C ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Melissa+Hathaway+speaks+at+Intelligence+and+National+Security+Alliance&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fmelissa-hathaway-speaks-at-intelligence-and-national-security-alliance%2F&nr_ad_number=0&nr_div_number=10");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_10");nRelate.adAnimation("nrelate_related_10");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

