<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTOvision.com &#187; Information Warfare</title>
	<atom:link href="http://ctovision.com/tag/information-warfare/feed/" rel="self" type="application/rss+xml" />
	<link>http://ctovision.com</link>
	<description>News, analysis and context on enterprise technology for the CTO</description>
	<lastBuildDate>Thu, 09 Feb 2012 21:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Information Warfare: A Historical Approach</title>
		<link>http://ctovision.com/2011/09/information-warfare-a-historical-approach/</link>
		<comments>http://ctovision.com/2011/09/information-warfare-a-historical-approach/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 12:05:44 +0000</pubDate>
		<dc:creator>AdamElkus</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[C2]]></category>
		<category><![CDATA[C3I]]></category>
		<category><![CDATA[Dorothy Denning]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Military History]]></category>
		<category><![CDATA[PLA]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=13709</guid>
		<description><![CDATA[Tweet Information warfare is thought to be a product of what, broadly speaking, is considered the &#8221;information&#8221; era. However, if we correctly understand what information war is, we can see that it stretches back to the dawn of organized conflict itself. Dorothy Denning defines information warfare (IW) as “operations that target or exploit information resources.” Information resources consist of [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F09%2Finformation-warfare-a-historical-approach%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/09/information-warfare-a-historical-approach/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/09/information-warfare-a-historical-approach/"  data-text="Information Warfare: A Historical Approach" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/09/information-warfare-a-historical-approach/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/09/information-warfare-a-historical-approach/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2011/09/Mongols.jpg"><img class="alignleft size-thumbnail wp-image-13717" style="margin: 4px;" title="Mongols" src="http://ctovision.com/wp-content/uploads/2011/09/Mongols-150x150.jpg" alt="" width="150" height="150" /></a>Information warfare is thought to be a product of what, broadly speaking, is considered the &#8221;information&#8221; era. However, if we correctly understand what information war is, we can see that it stretches back to the dawn of organized conflict itself.</p>
<p>Dorothy Denning <a href="http://www.amazon.com/Information-Warfare-Security-Dorothy-Denning/dp/0201433036">defines</a> information warfare (IW) as “operations that target or exploit information resources.” Information resources consist of containers (information media that contain forms of data), transporters (objects and communication systems that transport information from one location to another), sensors (humans and machines that extract information objects and the environment), recorders (objects that place information in containers), and processors (people and objects that manipulate information). Information resources are important because they have value to people, and thus can be disabled, destroyed, or manipulated to accomplish operational and strategic goals.  Hence, it matters little if you destroy a command and control center with a computer network operation or simply blow it to smithereens with a terminally guided submunition. The effect is largely identical.</p>
<p>Using this definition, information warfare becomes less exotic and part of the general toolbox of the commander. Military deception&#8211;one element of IW&#8211;has been crucial to the success of many large operations. Operation Bagration, the Soviet destruction of the Wehrmarcht&#8217;s Army Group Center, was only successful after a <a href="http://en.wikipedia.org/wiki/Operation_Bagration#Strategic_aims_and_deception">massive campaign</a> of <em><a href="http://en.wikipedia.org/wiki/Military_deception">maskirovka</a> </em>designed to hoodwink the German military planners trying to forecast their attack. The deception campaigns that preceded the Normandy invasion and the German invasion of Russia are also well-known to military historians. Although military writers often reach back to Sun Tzu to look at Chinese information warfare theory, some of the biggest influences on current People&#8217;s Liberation Army (PLA) is actually the Chinese Civil War. The<a href="http://books.google.com/books?id=PsoDGLNmU30C&amp;pg=PA3&amp;lpg=PA3&amp;dq=chinese+warfighting+pla&amp;source=bl&amp;ots=gpp0xiMb8Z&amp;sig=qP1ui-dWDuvksoKBwGqzj6YpaNQ&amp;hl=en&amp;ei=KiNwTqH9N6ft0gH_wuDzCQ&amp;sa=X&amp;oi=book_result&amp;ct=result&amp;resnum=10&amp;sqi=2&amp;ved=0CGkQ6AEwCQ#v=onepage&amp;q&amp;f=false"> Beiping-Tianjin campaign</a>, for example, is an example of the seamless employment of psychological operations alongside large-scale maneuver and attrition warfare and looms large in the PLA&#8217;s institutional memory.</p>
<p>Military deception also has been <a href="http://www.airpower.maxwell.af.mil/airchronicles/cc/berger.html">extensively utilized in antiquity</a> by the Mongols and the various armies that contested China to not only delay recognition of the point of the blow but also to fool the foe into exaggerating the size of one&#8217;s force. Genghis Khan, in this sense, was an IW<a href="http://www.airpower.maxwell.af.mil/airchronicles/cc/berger.html"> pioneer</a>.</p>
<blockquote><p>Khan was widely known for leading hordes of savage horsemen across Russia and into Europe. While not totally unfounded, the Mongols&#8217; image of total, barbaric domination was greatly enhanced by Khan&#8217;s use of PSYOP, deception, OPSEC, and targeting his adversaries&#8217; decision-making process. &#8220;Agents of influence&#8221; were sent in advance of his armies to do face-to-face PSYOP, telling of brutality and large numbers in the Mongol army. Khan also used deception to create the illusion of invincible numbers by using rapid troop maneuver, making his army look larger than it really was. He had a network of horsemen called &#8220;arrow riders&#8221; to communicate quickly with his commanders, and he targeted enemy messengers to prevent enemy commanders from communicating with each other.</p></blockquote>
<p>Actual employment of IW capabilities in modern war will not differ much from the means described here&#8211;the capabilities in question will change, but the methods of degrading the opponent&#8217;s information, attempting to bait them into the wrong decisions, targeting their<a href="http://en.wikipedia.org/wiki/C4ISTAR"> C3I</a>, practicing proper operations security, protecting one&#8217;s own information, and trying to undermine enemy morale are basic and recurring elements of IW throughout history. One can also consider Khan&#8217;s &#8220;arrow riders&#8221; as an ancient attempt at increasing &#8220;<a href="http://en.wikipedia.org/wiki/Power_to_the_Edge">power to the edge</a>.&#8221;</p>
<p>One caution, however. Information warfare has never been decisive in and of itself&#8211;it&#8217;s always increased the strategic effectiveness of one&#8217;s own forces and decreased the effectiveness of the enemy. Strategic information warfare&#8211;even in the Gulf Wars, which featured the wholesale destruction of enemy C3I&#8211;did not decide the campaign. Rather, ground and air forces operating as part of the AirLand Battle paradigm utilized capabilities, tactics, and operational plans honed in many rotations at the National Training Center (NTC) against the most fearsome Soviet imitation forces the military could provide. Although future wars will certainly raise the importance of IW as more and more enemy information assets and systems can be targeted, history suggests that a &#8220;cyber Pearl Harbor&#8221; will not in itself be decisive.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/08/the-devil-is-in-the-details-seven-tests-to-apply-to-any-cyber-conflict-concept/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5018f59efeaf250f6a1d7a6f75d42c7f_thumb_p2-269x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Devil is in the Details: Seven Tests to Apply to any Cyber Conflict Concept</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/08/the-twilight-of-network-centric-warfare/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/408771ac0c4aaf4324873a656bb0699f_thumb_AFG-060308-004-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Twilight of Network-Centric Warfare</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/06/i-havent-trusted-my-toaster-for-15-years/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c3ae8a0b3868ae530dda5ef2ecb1dfa8_thumb_National_Defense_University.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">I Haven't Trusted My Toaster for 15 Years</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/covert-action/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6d38e71b30396b54e935d4909958fd88_thumb_SpyvsSpy.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyberattack as Covert Action</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b875f5e7840eb0f6d182aaca405dc07f_thumb_NISTcloudcomputing.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">An Assessment on the Cyber Threat</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/new-onr-technology-will-enable-ship-systems-to-share-information-seamlessly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New ONR technology will enable ship systems to share information seamlessly</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/10/army-establishes-army-cyber-command/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/8c4fe914eba5d90e8ba716371e53feee_thumb_size0-army.mil-87591-2010-10-01-151035-300x198.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Army establishes Army Cyber Command</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/army-activates-first-of-its-kind-cyber-brigade/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cloud-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Army Activates First of its Kind Cyber Brigade</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Information+Warfare%3A+A+Historical+Approach&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F09%2Finformation-warfare-a-historical-approach%2F&nr_ad_number=0&nr_div_number=1");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.domain = "ctovision.com";nRelate.fixHeight("nrelate_related_1");nRelate.adAnimation("nrelate_related_1");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/09/information-warfare-a-historical-approach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An Assessment on the Cyber Threat</title>
		<link>http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/</link>
		<comments>http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 17:37:24 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Gov2.0]]></category>
		<category><![CDATA[cyber conflict]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[George Tenet]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Moonlight Maze]]></category>
		<category><![CDATA[National security]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=1745</guid>
		<description><![CDATA[Tweet How would you describe the threat to the US information infrastructure? If you are a technologist or a national security expert or both I hope you would use your background and experience and expertice and produced a fused-all source assessment based on facts. But it is also ok to cite the masters, folks who [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2010%2F03%2Fan-assessment-on-the-cyber-threat%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/"  data-text="An Assessment on the Cyber Threat" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2009/07/NISTcloudcomputing.jpg"><img class="alignleft size-full wp-image-1060" style="margin: 4px; border: 0pt none;" title="NISTcloudcomputing" src="http://ctovision.com/wp-content/uploads/2009/07/NISTcloudcomputing.jpg" alt="" width="225" height="158" /></a>How would you describe the threat to the US information infrastructure?  If you are a technologist or a national security expert or both I hope you would use your background and experience and expertice and produced a fused-all source assessment based on facts.  But it is also ok to cite the masters, folks who really know what they are talking about and are paid to produce the most accurate possible reports.  Below is an assessment I extracted from a source I know to be reliable, but to most of you technologists and national security professionals I hope this list will be seen as intutive statements that ring true to your experience.  Please look it over and let me know what you think (I&#8217;ll inject some thoughts at the end):</p>
<p>Judgements:</p>
<p>&#8220;The fact is that we are currently building an information infrastructure &#8212; the most complex systems the world has ever known &#8212; on an insecure foundation. We have ignored the need to build trust into our systems. Simply hoping that someday we can add the needed security before it is too late is not a strategy.&#8221;</p>
<p>Additionally:</p>
<ul>
<li>We are growing increasingly dependent on information systems for commercial and government activities.</li>
<li>Our adversaries recognize this dependence and are developing tools to attack our information systems.</li>
<li>Protecting our systems will require an unprecedented level of cooperation between government and the private sector.</li>
<li>Protecting our critical information systems and the data on them will be key to our survival as the world&#8217;s leading economic power and as the world&#8217;s leader in information technology.</li>
<li>Our heavy and growing societal and strategic dependence on information technologies and information systems has created vulnerabilities &#8212; vulnerabilities to our economic institutions, to the systems that support public needs, to our privacy, and to our military capabilities.</li>
<li>The number of known potential adversaries conducting research on information attacks is increasing rapidly and includes intelligence services, military organizations and non-state entities such as terrorism groups.<br />
Technology will increase the sophistication of their capabilities and will continue to reduce the cost of attack and the risk if security remains where it is today.</li>
<li>And the attackers have enormous incentives.Trillions of dollars in financial transactions and commerce moving over a medium that has minimal protection and sporadic law enforcement. Increasing quantities of intellectual property residing on networked systems. And the opportunity to disrupt military effectiveness and public safety, with elements of surprise and anonymity.</li>
<li>The state sponsored terrorists and military Information Warfare people pose the greatest risk to our critical infrastructure because they have the greatest knowledge and resources.</li>
<li>Foreign governments and their military services are paying increasing attention to the concept of &#8221;Information Warfare&#8221;. Foreign military writings discuss the importance of disrupting the flow of information in combat. The battlespace of the future also will extend to our domestic information infrastructure, such as our electric power grids and our telecommunications networks &#8211; in short, the very foundations of our economy.</li>
<li>We cannot keep building new capabilities on a poor foundation of security. We cannot ignore the need to build trust into our information systems any longer.</li>
<li>It is folly to hope that someday we can add needed elements before it&#8217;s too late. The longer we wait, the more our country is exposed, and the costlier it will be to address the problem.If we are going to lead the world in information technology we must recreate the trust that existed between our government and our industry that allowed us to lead the free world for over forty years. We still have the power to lead by our example, and we still have the time to do what is right.</li>
</ul>
<p>I think the information and assessments and powerful thoughts above are right on and should be considered by anyone in the national security and technology space.</p>
<p>The source?  1998 speeches and testimony by then Director of Central Intelligence George Tenet.  I think he pretty much nailed what would happen with the assessment above (read more online at: <a href="https://www.cia.gov/news-information/speeches-testimony/1998/dci_speech_040698.html" target="_blank">https://www.cia.gov/news-information/speeches-testimony/1998/dci_speech_040698.html</a> and <a href="https://www.cia.gov/news-information/speeches-testimony/1998/dci_testimony_062498.html" target="_blank">https://www.cia.gov/news-information/speeches-testimony/1998/dci_testimony_062498.html</a></p>
<p>In fact, seems like he provided clear an unambiguous warning.</p>
<p>Since then, it seems like very leader in the national security, DoD and Intelligence Space that comes into office seems to muddle on oblivous to the cyber threat till some incident hits them, like Moonlight Maze or the series of intrusions into DoD and other nets over 2007 or the attacks vs Estonia or the attacks vs. Georgia or the attacks vs. Google.  And in each time you get folks saying something like &#8220;oh well that was a wake up call.&#8221;</p>
<p>Any thoughts on that?</p>
<p>Is there anything that can be done so 12 years from now we are not asking ourselves why people in key positions are still saying things like &#8220;oh that was a wake-up call!&#8221;?</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=53a251c1-3510-45b9-bceb-0ff4831c056b" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/08/the-devil-is-in-the-details-seven-tests-to-apply-to-any-cyber-conflict-concept/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5018f59efeaf250f6a1d7a6f75d42c7f_thumb_p2-269x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Devil is in the Details: Seven Tests to Apply to any Cyber Conflict Concept</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/02/continued-evolution-of-dod-cyber-policy/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/f2876285073e178a1e0082ce2d029417_thumb_lynn-240x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Continued Evolution of DoD Cyber Policy</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/11/geospatial-ttps-contribute-to-cyber-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/f92ec5b14c9eb2d303497bbb6098f3e0_thumb_dprk.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Geospatial TTPs Contribute To Cyber Security</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/calling-all-federal-cybersecurity-practitioners-contribute-ideas-and-actions-to-enhance-the-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/051005048d7941003b800b4011f29136_thumb_iwantyou.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Calling All Federal Cybersecurity Practitioners: Contribute ideas and actions ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/president-mentions-cyber-threats-in-state-of-the-union-address/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">President Mentions Cyber-Threats in State of the Union Address</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/01/federal-cyber-security-missions-initiatives-opportunities-and-risks/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7211aac7adbb945cc945ba4e55d660ad_thumb_cybersecurityconference-300x195.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Federal Cyber Security: Missions, Initiatives, Opportunities and Risks</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/10/defending-against-stuxnet-type-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d2333f6f4e0094cfb2b563c4ded3f948_thumb_natanz_visit-300x201.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Defending Against Stuxnet Type Threats</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/02/the-most-well-thought-out-research-agenda-for-cyber-security-i-have-seen-to-date/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/83f75632acd4334438d5e0390761a168_thumb_dhssnt-300x278.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The most well thought out research agenda for cyber security I have seen to date</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/03/mature-models-for-healthy-and-resilient-cyber-systems/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d9016ac7faff40a974f91c61bc0ccf10_thumb_Department-of-Homeland-Security-300x203.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mature Models for Healthy and Resilient Cyber Systems</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=An+Assessment+on+the+Cyber+Threat&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2010%2F03%2Fan-assessment-on-the-cyber-threat%2F&nr_ad_number=0&nr_div_number=2");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_2");nRelate.adAnimation("nrelate_related_2");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>White House Cyber Policy Review: And a Cyber Czar</title>
		<link>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/</link>
		<comments>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/#comments</comments>
		<pubDate>Fri, 29 May 2009 20:16:49 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Russian government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Vladimir Putin]]></category>
		<category><![CDATA[White House]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=405</guid>
		<description><![CDATA[Tweet I enjoyed listening to the President today as he provided an update on where we are in our efforts to enhance our freedom of action in cyberspace.  All the details are on the White House website and I hope you visit there yourself to download the 60-day cyberspace policy review. Details are here: http://www.whitehouse.gov/CyberReview/ [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fwhite-house-cyber-policy-review-and-a-cyber-czar%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"  data-text="White House Cyber Policy Review: And a Cyber Czar" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-medium wp-image-411" style="border: 1px solid black; margin: 4px;" title="obama1" src="http://ctovision.com/wp-content/uploads/2009/05/obama1-300x168.jpg" alt="obama1" width="270" height="151" />I enjoyed listening to the President today as he provided an update on where we are in our efforts to enhance our freedom of action in cyberspace.  All the details are on the White House website and I hope you visit there yourself to download the 60-day cyberspace policy review. Details are here: <a href="http://www.whitehouse.gov/CyberReview/" target="_blank">http://www.whitehouse.gov/CyberReview/</a></p>
<p>I have been reading the report already&#8211; and will also read all the papers and studies referenced there.</p>
<p>So far I have three comments:</p>
<p>1) I really enjoyed hearing the President reference Melissa Hathaway.  She has done an incredible job and to hear him praise her was music to my ears.  Melissa deserves the thanks of the nation.</p>
<p>2) A great deal of work remains to be done. The policy review provides a framework for action and guidance that will help prioritize activities, but don&#8217;t expect instant miracles.</p>
<p>3) Number one on the list of near term actions is to appoint a cybersecurity policy official. The President did not do that today.  That will be done in due time.  I should also point out that no one in government is using the term &#8220;Cyber Czar&#8221; for this position.  That term Czar is used by all the reporters and all the pundits.  It sounds cool.  It also brings lots of baggage.  The typical &#8220;Czar&#8221; in DC is a powerless position that has little or no effect.</p>
<p>To underscore that point I&#8217;d like to close with a little self-plagerization.  A reprint of a blog post I first wrote in January 2009 titled &#8220;<a href="http://ctovision.com/2009/01/we-have-a-cyber-czar-and-he-has-spoken/" target="_blank">We have a cyber czar, and he has spoken.</a>&#8220;  In the post, now below, I try to make the point that if Putin can accomplish his objectives in our networks then he is our cyber czar.  I also hope to make the point that we should not be happy with him being in this position.</p>
<h1>We Have A Cyber Czar, and He Has Spoken</h1>
<p><img class="alignleft size-medium wp-image-401" title="DAVOS/" src="http://ctovision.com/wp-content/uploads/2009/01/putinatdavos-300x200.jpg" alt="DAVOS/" width="209" height="139" /></p>
<p>A debate has been running for months both among government thought leaders and the technical literati on whether or not the US should appoint a &#8220;Cyber Czar&#8221; who can exert authority over IT security in the federal space or perhaps even aspects of the nation&#8217;s IT defenses.  This is a complex discussion that has had some of the greatest thinkers in and out of government involved.   A great snapshot of issues and the opinions of many well reasoned experts are expressed in the CSIS report &#8220;<a href="http://ctovision.com/2008/12/ctos-global-cyberwar-and-our-collective-future/">Securing Cyberspace for the 44th Presidency</a>&#8220;   and other thoughts are here: <a href="http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/">The Future of Cyber Security</a> and here: <a href="http://ctovision.com/2009/01/threats-in-the-age-of-obama/">Threats In the Age of Obama</a> .</p>
<p>Unfortunately for those who would like to still debate and discuss this issue, there is already a Cyber Czar who can accomplish most all his objectives in our networks.  His name is Russian Prime Minister Vladimir Putin.  This former KGB operative now controls Russia with an iron fist and has shown others again and again he will exert influence anywhere he needs to in order to accomplish his objectives.  He will use tanks when required and cyber when desired and combinations when it suits him.  There are indications his agents are also in our networks now.  If our objectives are to keep players like him out, we cannot say we are accomplishing them.  If his objectives are to get in, then we can say he is accomplishing them.  Till this situation changes, we need to confront then this new reality:  <strong>Vladimir Putin is the Cyber Czar.</strong></p>
<p>We have our own great technologists and wizards of cyber, of course. And we have great hero entrepreneurs of technology who have built the cyber world we all use today.  One of those greats is Michael Dell, creator of an idea and corporation that develops, manufactures, sells and distributes personal computers we all depend on.</p>
<p>But he is someone who will now think twice before thinking he can interact as a peer to Cyber Czar Putin.  After listening to Putin&#8217;s speech at the <a href="http://www.weforum.org/en/index.htm">World Economic Forum</a> in Davos, Michael Dell praised Russia&#8217;s technical and scientific prowess and asked a nice, friendly question:  &#8220;How can we help.&#8221;  As a former govie CTO I would get asked that type of question all the time from industry and really appreciated it whenever a senior thought leader would ask that.  But not Czar Putin.  He did not appreciate that at all.   Putin was offended by the assertion that the mighty Russia might need help in anything Cyber. The exchange is captured here on YouTube:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/OMR1BZ9aYM8&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;feature=player_embedded&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p><a href="http://money.cnn.com/2009/01/28/news/companies/dell.davos.fortune/">Fortune</a>: described the exchange this way:</p>
<p>&#8220;Putin&#8217;s withering reply to Dell: &#8220;We don&#8217;t need help. We are not invalids. We don&#8217;t have limited mental capacity.&#8221; The slapdown took many of the people in the audience by surprise. Putin then went on to outline some of the steps the Russian government has taken to wire up the country, including remote villages in Siberia. And, in a final dig at Dell, he talked about how Russian scientists were rightly respected not for their hardware, but for their software. The implication: Any old fool can build a PC outfit.&#8221;</p>
<p>Clearly cyber domination is personal with Putin.  He is the Cyber Czar.</p>
<p>I think I should end with a plea to all who care about cyber freedom and all who know the potential positive contributions of IT:  Please don&#8217;t be pleased with this current situation.  Please don&#8217;t just think the title of Cyber Czar I&#8217;ve now used to describe Putin is something we should be proud of.  It is not.  We should continue to act till we are able to assert that we are masters of our own networks.  Our nation&#8217;s intellectual property, including the intellectual property of all our companies and citizens, is too important to let it be given away without at least a cyber fight.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_3" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/interested-in-cyber-security-read-and-support-the-new-cybersecurity-legislative-proposal/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22287c15091f7562d56a24afb02c8118_thumb_CNO-pic.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Interested in Cyber Security? Read (and support) the new Cybersecurity Legisl ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/deputy-secretary-of-defense-lynn-cyber-strategy%e2%80%99s-thrust-is-defensive/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fa5ccb5775a00b753a4d3a3d6317d2a6_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Deputy Secretary of Defense Lynn: Cyber Strategy’s Thrust is Defensive</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/calling-all-federal-cybersecurity-practitioners-contribute-ideas-and-actions-to-enhance-the-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/051005048d7941003b800b4011f29136_thumb_iwantyou.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Calling All Federal Cybersecurity Practitioners: Contribute ideas and actions ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/05/the-u-s-international-strategy-for-cyberspace/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a8a2beedd8b0fdd27d42eac052551cb1_thumb_Department_of_state.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The U.S. International Strategy for Cyberspace</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/09/jtf-cnd-to-jtf-cno-to-jtf-gno-to-cybercom/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0a356c95fe882b318e7d87a475ce381e_thumb_300px-Jtf-gno1.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">JTF-CND to JTF-CNO to JTF-GNO to Cybercom</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/07/the-fedcyber-com-cyber-security-summit/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9864e85f16bbc4e2a15784df135f3be0_thumb_newseum.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The FedCyber.com Cyber Security Summit</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/cyber-conflict-studies-association-history-contest/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyber Conflict Studies Association History Contest</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=White+House+Cyber+Policy+Review%3A+And+a+Cyber+Czar&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fwhite-house-cyber-policy-review-and-a-cyber-czar%2F&nr_ad_number=0&nr_div_number=3");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_3");nRelate.adAnimation("nrelate_related_3");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/05/white-house-cyber-policy-review-and-a-cyber-czar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Melissa Hathaway speaks at Intelligence and National Security Alliance</title>
		<link>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/</link>
		<comments>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/#comments</comments>
		<pubDate>Fri, 01 May 2009 10:28:22 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[White House]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=279</guid>
		<description><![CDATA[Tweet INSA, the Intelligence and National Security Alliance, is a group of professionals from academia, industry and government who seek to enhance innovation, discussion, debate and progress on key national security issues.  I&#8217;ve been involved as a member for years and get the pleasure of interacting with folks from a wide swath of the community. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fmelissa-hathaway-speaks-at-intelligence-and-national-security-alliance%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"  data-text="Melissa Hathaway speaks at Intelligence and National Security Alliance" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2009/05/melissa-hathaway.jpg"><img class="alignleft size-full wp-image-297" style="border: 2px solid black; margin: 4px;" title="melissa-hathaway" src="http://ctovision.com/wp-content/uploads/2009/05/melissa-hathaway.jpg" alt="melissa-hathaway" width="117" height="137" /></a>INSA, the <a href="http://insaonline.org/" target="_blank">Intelligence and National Security Alliance</a>, is a group of professionals from academia, industry and government who seek to enhance innovation, discussion, debate and progress on key national security issues.  I&#8217;ve been involved as a member for years and get the pleasure of interacting with folks from a wide swath of the community.</p>
<p>One of the many services INSA provides the community is providing a venue for speakers and community leaders to interact.  INSA did that again just last night when their Distinguished Speaker Series featured <a href="http://insaonline.org/index.php?id=608" target="_blank">Melissa Hathaway</a>.  Melissa, who I have previously called the most effective and efficient senior executive in government today, spoke on the topic  of the White House Cyber Security 60-day review.</p>
<p>I watched Melissa&#8217;s RSA presentation, and for those who did or for those who have been engaged with her during this review, last nights presentation was in consonance with what we know of the hard task she has been working on (if you haven&#8217;t watched it yet, I&#8217;d recommend you take a look now, at:  <a href="http://media.omediaweb.com/rsa2009/keynote_catalog.htm" target="_blank">http://media.omediaweb.com/rsa2009/keynote_catalog.htm</a> )</p>
<p>A couple thoughts from a CTO perspective:</p>
<p>- Like so many other problems, tackling this one requires both a knowledge of technology and of people. Both technology and people must be influenced.</p>
<p>- When it comes to people, Melissa mentioned the book  <a href="http://www.amazon.com/gp/product/007148499X?ie=UTF8&amp;tag=netbooks00&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=007148499X">Influencer: The Power to Change Anything</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=netbooks00&amp;l=as2&amp;o=1&amp;a=007148499X" border="0" alt="" width="1" height="1" /> .  I haven&#8217;t read it yet, but have just added it to my Amazon wish list and will be getting it soon. Melissa said the authors of the &#8220;Influencer&#8221; book say there is power in everyone to make a change and therefore everyone should get engaged, and in this cyber context she asked everyone at INSA to stay engaged.  She wants folks to continue to dive in and stay involved and form views and move out.</p>
<p>- One of the most important ways the federal government influences is through law.  Our great government flows from a great Constitution and, although it was not a civics lesson last night, Melissa did mention the incredible legal review that these many cyber issues have been through.  She said over 80 significant legal issues were reviewed.  The report, when it is released, will have a 150 page legal annex that captures some of the opinion of federal legal experts from across the government.   As for me, I intend on reading every page of the report, and will pay particular attention to this legal section.</p>
<p>- Now that I&#8217;ve had time to think about what Melissa said, I think we (the nation, and we humans everywhere) are going to need more work to be done on how we influence technology.   I&#8217;ve tried hard to think through this from a security perspective, and I know there are things we can do right now to improve things in this regard (and I&#8217;ve provided papers to Melissa&#8217;s study team on a couple significant constructs like enhancing security through smart use of cloud computing and through smart use of open source).  But there is still much much more work to be done in this area.   CTOs cannot rest on this topic, yet.  In fact, I am not comfortable with the state of technology leadership in this area and I think all of us technologists need to follow Melissa&#8217;s advice.  We all need to get engaged and get a view and move out.</p>
<p>Part of the event last night was a networking reception where INSA members from academia, industry and government could chat.  The gist of the conversations confirmed what I have long thought, everyone wants Melissa to succeed and a wide swath of people are lining up to follow her lead.  She has done a great job at building a broad team and we are all looking forward to her continued leadership on things cyber.</p>
<p>For more on this topic see:  <a href="http://ctovision.com/category/cyber-initiative/" target="_self">http://ctovision.com/category/cyber-initiative/</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_4" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/melissa-hathaway-compelling-action-along-a-broad-front/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/860c2d78b8b85c4eb1767454fe06f887_thumb_MelissaHathaway.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Melissa Hathaway: Compelling action along a broad front</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/prediction-bluecat-networks-is-one-you-should-watch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/25d9b473e4d7b18a8df83ca74b587b44_thumb_bluecat-networks-300x92.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Prediction: BlueCat Networks is one you should watch</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/dodiis-conference-agenda-published/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DoDIIS Conference Agenda Published</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/new-boeing-intelligence-collaboration-center/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Boeing Intelligence Collaboration Center</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/2010-dodiis-worldwide-conference/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/19e6131b6d2ff09319fb2031d793a30a_thumb_300px-DIAC.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">2010 DoDIIS Worldwide Conference</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/how-much-freedom-will-you-give-up-to-fight-international-cybercrime/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">How Much Freedom Will You Give Up to Fight International Cybercrime?</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/us-needs-to-kick-network-security-intelligence-up-a-notch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">US needs to kick network security intelligence up a notch</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/a-first-for-the-nation-nerc-completes-first-grid-security-exercise/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A First For The Nation: NERC Completes First Grid Security Exercise</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/former-head-of-national-counterterrorism-center-michael-leiter-to-keynote-counter-terror-expo-us/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Former Head of National Counterterrorism Center, Michael Leiter, to Keynote C ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Melissa+Hathaway+speaks+at+Intelligence+and+National+Security+Alliance&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F05%2Fmelissa-hathaway-speaks-at-intelligence-and-national-security-alliance%2F&nr_ad_number=0&nr_div_number=4");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_4");nRelate.adAnimation("nrelate_related_4");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/05/melissa-hathaway-speaks-at-intelligence-and-national-security-alliance/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Cyberpower and National Security</title>
		<link>http://ctovision.com/2009/04/cyberpower-and-national-security/</link>
		<comments>http://ctovision.com/2009/04/cyberpower-and-national-security/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 12:57:16 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[William Gibson]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=245</guid>
		<description><![CDATA[Tweet Last week at the InfowarCon my friend Dan Kuehl handed me a copy of Cyberpower and National Security.  Cyberwar has been a topic Dan has been exploring in some detail for quite a while.  I first met Dan in 1996 when I was a student at the USMC Command and Staff College, and at [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F04%2Fcyberpower-and-national-security%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/04/cyberpower-and-national-security/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/04/cyberpower-and-national-security/"  data-text="Cyberpower and National Security" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/04/cyberpower-and-national-security/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/04/cyberpower-and-national-security/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-medium wp-image-537" title="ndu4" src="http://ctovision.com/wp-content/uploads/2009/04/ndu4-300x208.jpg" alt="ndu4" width="300" height="208" />Last week at the <a href="http://infowarcon.com" target="_blank">InfowarCon</a> my friend <a href="http://www.ndu.edu/IRMC/ia/kuehl.html" target="_blank">Dan Kuehl</a> handed me a copy of <a href="http://www.amazon.com/gp/product/1597974234?ie=UTF8&amp;tag=netbooks00&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1597974234">Cyberpower and National Security</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=netbooks00&amp;l=as2&amp;o=1&amp;a=1597974234" border="0" alt="" width="1" height="1" />.   Cyberwar has been a topic Dan has been exploring in some detail for quite a while.   I first met Dan in 1996 when I was a student at the USMC Command and Staff College, and at that time Dan was already writing and exploring concepts related to cyber power and information warfare.  His deep focus and insights into this still emerging mission area continues today.</p>
<p>[amtap amazon:asin=1597974234]</p>
<p>About the book, it is big.  Not just in pages (it weighs in at 642 pages).  It is big in info.  Chapters are written by some of the greatest thinkers of the Cyber War mission area.  Folks like Dan Kuehl, Edward Skoudis, Greg Rattray, Martin Libicki, Irving Lachow, Tim Thomas, Tom Wingfield and of course the editors Franklin Kramer, Stuart Starr and Larry Wentz.  These and the other contributors are all well respected thought leaders and each provide insights I believe will be of use to today&#8217;s strategic planners.</p>
<p>As for the content, it starts with a great foundation and overview of what is meant by Cyberspace (building on Dan Kuelh&#8217;s well articulated definition) and also spells out key issues that policy makers and national security strategists must tackle.  It then analyzes and explores changes in cyberspace including projections into the near future, and ends with an analysis of the impact of all these changes- including the considerations we must think through in our strategic deliberations.</p>
<p>I now consider this book a critical foundational work that should be studied by anyone who seeks to dialog on modern national security issues.  This book does for the strategic domain what the Common Audit Guidelines did for the operational cyber domain.</p>
<p>I know NDU will continue to examine these topics, and look forward to more material from them.  I also look forward to continuing to enage with others in academia via the <a href="http://cyberconflict.org" target="_blank">Cyber Conflict Studies Association</a>, a group that includes many of the authors of this Cyberpower and National Security work.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_5" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/congrats-to-sony-corp-this-is-a-very-good-move/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/54dac2956db1669b0dfb06748c32613d_thumb_logo-sony.gif" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Congrats To Sony Corp! This is a very good move</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/a-look-at-gsas-managed-trusted-internet-protocol-service/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cloud-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at GSA's Managed Trusted Internet Protocol Service</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/prediction-bluecat-networks-is-one-you-should-watch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/25d9b473e4d7b18a8df83ca74b587b44_thumb_bluecat-networks-300x92.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Prediction: BlueCat Networks is one you should watch</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/03/save-the-date-geoint-will-be-16-19-oct-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Save the date: Geoint will be 16-19 Oct 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/fedcyber-webinar-the-security-development-lifecycle/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/2b92a75001fe1fd94119e58176a95e50_thumb_sdl.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber Webinar: The Security Development Lifecycle</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/fisma-mandates-monthly-security-reports-for-agencies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FISMA Mandates Monthly Security Reports For Agencies</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/dhs-outlines-new-monthly-fisma-compliance-requirements/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/spiral-seashells-painted-gold.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DHS Outlines New Monthly FISMA Compliance Requirements</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/dhss-national-cyber-security-division-and-idaho-national-laboratory-win-cybersecurity-award/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">DHS’s National Cyber Security Division and Idaho National Laboratory win cybe ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/fedramp-includes-168-security-controls/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mountains-dust.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedRAMP includes 168 security controls</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/interagency-group-looks-to-common-cyber-security-language-skills/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-abstract-glass.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Interagency group looks to common cyber security language, skills</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Cyberpower+and+National+Security&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F04%2Fcyberpower-and-national-security%2F&nr_ad_number=0&nr_div_number=5");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_5");nRelate.adAnimation("nrelate_related_5");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/04/cyberpower-and-national-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enhancing Security and Functionality At The Same Time</title>
		<link>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/</link>
		<comments>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 21:07:30 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[Thin Client]]></category>
		<category><![CDATA[Triumfant]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=130</guid>
		<description><![CDATA[Tweet Have you ever been sucked into the false debate over how much IT spending should be spent on security?  I used to all the time.  Some folks point to a rule of thumb that goes something like &#8220;ten percent of the IT budget should be applied to security.&#8221;  That old school formula may well [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F02%2Fenhancing-security-and-functionality-at-the-same-time%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"  data-text="Enhancing Security and Functionality At The Same Time" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Have you ever been sucked into the false debate over how much IT spending should be spent on security?  I used to all the time.  Some folks point to a rule of thumb that goes something like &#8220;ten percent of the IT budget should be applied to security.&#8221;  That old school formula may well be part of the reason we got into the mess we are currently in.  It contributes to thoughts that lead you to think security can be separated.  By my way of thinking, 100% of the budget goes to security and functionality and that is the calculus.</p>
<p>Really, security is about ensuring information confidentiality, availability and integrity. And those constructs are totally connected to functionality of IT.   I try whenever possible to use the term security and functionality in the same context just to underscore that point.</p>
<p>For example, the goal I continually push regarding security in the federal space is not just one dealing with security.  I put it this way:  &#8220;Security and functionality of all federal IT will be increased by two orders of magnitude in the next 24 months.&#8221;  Putting the goal this ways also underscores that it is not security vs. functionality.  Both need to increase.</p>
<p>This goal also cries out for the need for metrics in security and functionality.  For functionality there are many customer focused survey methods that can help collect the right metrics.  For security, I think one metric stands out above all others:  Detected unauthorized intrusions.  There are many other important metrics for other dimensions of the security problem, but that one is key.  So, a goal that expects both security and functionality of federal enterprise IT to improve by two orders of magnitude will expect customer survey satisfaction to go through the roof, and will expect detected intrusions to drop significantly.  If there were 50,000 detected intrusions in 2008, there should be less than 5000 in 2010.</p>
<p>That is a dramatic goal.  What makes me think it is achievable?  In part the dramatic action being put in place today in the federal space.  And in part by dramatic new technologies and approaches like private clouds and thin client computing and enhanced identity management and authorization methods.  But of more importance and more relevance than all of that, in my opinion, is the coordinated action and leadership underway by CIOs and CISOs and the security  experts in the federal space today.</p>
<p>As evidence of this incredible positive action I&#8217;d like to bring your attention to a release by a Consortium of US Federal Cybersecurity Experts on Consensus Audit Guidelines.  Details of this effort are at <a href="http://www.sans.org/cag/">http://www.sans.org/cag/</a></p>
<p>The Consensus Audit Guidelines provide the twenty most important controls and metrics for effective cyber defense and continuous FISMA compliance.   These controls and metrics include:</p>
<p><strong>Critical Controls Subject to Automated Measurement and Validation:</strong></p>
<ol>
<li>Inventory of Authorized and Unauthorized Hardware.</li>
<li>Inventory of Authorized and Unauthorized Software.</li>
<li>Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers.</li>
<li>Secure Configurations of Network Devices Such as Firewalls and Routers.</li>
<li>Boundary Defense</li>
<li>Maintenance and Analysis of Complete Security Audit Logs</li>
<li>Application Software Security</li>
<li>Controlled Use of Administrative Privileges</li>
<li>Controlled Access Based On Need to Know</li>
<li>Continuous Vulnerability Testing and Remediation</li>
<li>Dormant Account Monitoring and Control</li>
<li>Anti-Malware Defenses</li>
<li>Limitation and Control of Ports, Protocols and Services</li>
<li>Wireless Device Control</li>
<li>Data Leakage Protection</li>
</ol>
<p><strong>Additional Critical Controls (not directly supported by automated measurement and validation):</strong></p>
<ol>
<li>Secure Network Engineering</li>
<li>Red Team Exercises</li>
<li>Incident Response Capability</li>
<li>Data Recovery Capability</li>
<li>Security Skills Assessment and Training to Fill Gaps</li>
</ol>
<p>The site at <a href="http://www.sans.org/cag">http://www.sans.org/cag</a> provides more details on each, including detailed descriptions of the controls, how to implement them, how to measure them, and how to continuously improve them.   The site also spells out the fact that this is a work in progress and processes are in place to ensure this great effort remains relevant and maximizes our ability to protect ourselves.</p>
<p>What should CTOs think about this guidance?  As for me, I most strongly endorse it. In my mind the appropriate implementation of these controls will reduce unauthorized intrusions in any enterprise.</p>
<p>The deeply respected community leader Alan Paller said it this way:</p>
<p>&#8220;This is the best example of risk-based security I have ever seen,&#8221; said<br />
Alan Paller, director of research at the SANS Institute.  &#8220;The team that was<br />
brought together represents the nation&#8217;s most complete understanding of<br />
the risk faced by our systems. In the past cybersecurity was driven by<br />
people who had no clue of how the attacks are carried out. They created an<br />
illusion of security. The CAG will turn that illusion to reality.&#8221;</p>
<p>Please give these controls a read, and please help get them into the hands of the security and functionality professionals in your enterprise.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_6" class="nrelate nrelate_related nrelate_default nr_100"><!-- no data found 200 --></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_6");nRelate.adAnimation("nrelate_related_6");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/02/enhancing-security-and-functionality-at-the-same-time/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Blog I Like: Haft of the Spear</title>
		<link>http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/</link>
		<comments>http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 19:18:19 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Great CTOs]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[Web/Tech]]></category>
		<category><![CDATA[Weblogs]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=116</guid>
		<description><![CDATA[Tweet Michael Tanji brings a perspective forged in years of intelligence work and a successful stint protecting information in the financial sector.&#160; He is a well published author who focuses on national security issues and is also a thought leader in the computer security domain. At Haft of the Spear he writes primarily about technology [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F02%2Fa-blog-i-like-haft-of-the-spear%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/"  data-text="A Blog I Like: Haft of the Spear" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>Michael Tanji brings a perspective forged in years of intelligence work and a successful stint protecting information in the financial sector.&nbsp; He is a well published author who focuses on national security issues and is also a thought leader in the computer security domain. </p>
<p>At Haft of the Spear he writes primarily about technology related/enabled national security issues, which includes a heavy dose of information warfare.&nbsp; </p>
<p>Read HOTS at: <a href="http://haftofthespear.com/">http://haftofthespear.com/</a></p>
<p>Next week I write about Nicholas Carr and his <a href="http://haftofthespear.com/">Rough Type</a> blog. <br />
<a href="http://blog.devost.net/"><br />
</a></p>
<p></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_7" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/increasing-%e2%80%9cjointness%e2%80%9d-and-reducing-duplication-in-dod-intelligence/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/427fd7c1e01d15ebf8bd66360e07f397_thumb_JointProductLine1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Increasing “Jointness” and Reducing Duplication in DoD Intelligence</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/pros-and-cons-bill-clinton-as-dni/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pros and Cons: Bill Clinton as DNI</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/2010-dodiis-worldwide-conference/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/19e6131b6d2ff09319fb2031d793a30a_thumb_300px-DIAC.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">2010 DoDIIS Worldwide Conference</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/09/what-is-the-cyber-conflict-studies-association/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6375aac65b771cae8ca52a3a5c4b8914_thumb_ccsa-300x117.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">What is the Cyber Conflict Studies Association?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/03/an-assessment-on-the-cyber-threat/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b875f5e7840eb0f6d182aaca405dc07f_thumb_NISTcloudcomputing.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">An Assessment on the Cyber Threat</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/information-warfare-a-historical-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Information Warfare: A Historical Approach</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Could Pick One Thing For Congress To Do Regarding CyberSecurity, What  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=A+Blog+I+Like%3A+Haft+of+the+Spear&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F02%2Fa-blog-i-like-haft-of-the-spear%2F&nr_ad_number=0&nr_div_number=7");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_7");nRelate.adAnimation("nrelate_related_7");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/02/a-blog-i-like-haft-of-the-spear/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unrestricted Warfare Symposium, Sponsored by JHU&#8217;s APL and SAIS</title>
		<link>http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/</link>
		<comments>http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 03:28:20 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[JFCOM]]></category>
		<category><![CDATA[Johns Hopkins University]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=124</guid>
		<description><![CDATA[Tweet For enterprise technologists and national security professionals and most of all for those who fit both of those descriptions, please check out Johns Hopkins University&#8217;s 2009 Unrestricted Warfare Symposium at: http://www.jhuapl.edu/urw_symposium This symposium seeks to advance our understanding of and solutions for some very complex problems related to our nation&#8217;s defense.  I&#8217;ll be speaking [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2009%2F02%2Funrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/"  data-text="Unrestricted Warfare Symposium, Sponsored by JHU&#8217;s APL and SAIS" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>For enterprise technologists and national security professionals and most of all for those who fit both of those descriptions, please check out Johns Hopkins University&#8217;s 2009 Unrestricted Warfare Symposium at: <a href="http://www.jhuapl.edu/urw_symposium"> http://www.jhuapl.edu/urw_symposium</a> This symposium seeks to advance our understanding of and solutions for some very complex problems related to our nation&#8217;s defense.  I&#8217;ll be speaking on a panel at the conference (on issues of <a href="http://www.ctovision.com/cyber-war/"><a href="http://ctovision.com/category/cyber-initiative/">cyber war and cyber defense</a>)</a> and hope to see you there.</p>
<p>The following is from an e-mail from <a href="http://www.jhuapl.edu/areas/warfare/staff/luman.asp">Dr. Ron Luman</a> (Johns Hopkins University Applied Physics Laboratory National Security Analysis Department Head)</p>
<p>QUOTE:</p>
<p>National Security Community Colleagues:  This is a reminder that the Johns Hopkins University&#8217;s 2009 Unrestricted Warfare Symposium will be held 24-25 March 2009, and I encourage you to register now at <a href="http://www.jhuapl.edu/urw_symposium">http://www.jhuapl.edu/urw_symposium</a>/.</p>
<p>The fourth annual symposium is in Laurel, MD at JHU&#8217;s Applied Physics Laboratory (APL), and is jointly sponsored by APL and the Paul H. Nitze School of Advanced International Studies (SAIS).   Last year more than 300 participants from government, industry, and academia interacted with distinguished speakers and expert panelists who addressed national security issues from three perspectives:  strategy, analysis, and technology. In 2009, this uniquely synergistic approach will be applied to the challenge of identifying interagency imperatives and capabilities.</p>
<p>The symposium presentations and panels are organized around four potential unrestricted lines of attack &#8211; cyber, resource, economic/financial, and terrorism. We&#8217;ll begin each session with a discussion of the potential for such attacks and then expert roundtable panelists will discuss imperatives for interagency action, offering ideas for enhancing interagency capabilities. A fifth session will focus on the role of analysis in identifying and assessing interagency approaches for preventing and combating these types of attacks.</p>
<p>I am particularly pleased that The Honorable James R. Locher, III, Executive Director of the Project for National Security Reform, will open the symposium as our keynote speaker, providing the Project&#8217;s timely findings and recommendations for interagency reform. Throughout the two days featured speakers and distinguished panelists, include:  Dr. George Akst, MCCDC; Mr. Eric Coulter, OSD(PA&amp;E); Dr. Richard Cooper, Harvard University; Dr. Stephen Flynn, Council on Foreign Relations; Representative Jane Harman; Professor Bruce Hoffman, Georgetown University; Professor Michael Klare, Hampshire College; Dr. Michael Levi, Council on Foreign Relations; Dr. Matthew Levitt, Washington Institute; Dr. Pete Nanos (DTRA); Mr. James Rickards, Omnis, Inc.; Mr. Frank Ruggiero (Department of State); Dr. Khatuna Salukvadze, Georgian Ministry of Foreign Affairs;  Mr. Dan Wolf, Cyber Pack Ventures Inc.; Mr. Bob Work, CSBA, to name a few.</p>
<p>The attached announcement identifies confirmed speakers and other essential information. We encourage dynamic networking, and to facilitate audience participation, we will again be utilizing electronic groupware to collect comments, insights, and questions.  The collection of papers and transcripts of discussions will again be published as Proceedings, in both hard copy and electronic form.  The 2006 -2008 Proceedings, the current agenda/speakers, and 2009 registration details can be found at the symposium website: <a href="http://www.jhuapl.edu/urw_symposium">http://www.jhuapl.edu/urw_symposium</a>/.</p>
<p>Your experience in national security and defense will contribute unique perspectives and challenging questions to our understanding of Unrestricted Warfare, and I look forward to seeing you next month.</p>
<p>Best regards,</p>
<p>Ron Luman, General Chair</p>
<p>I hope to see you all there.<br />
Symposium Attachment:<br />
<span class="mt-enclosure mt-enclosure-file" style="display: inline;"><a href="http://www.ctovision.com/URW2009Flyer%204Feb-1.pdf">URW2009Flyer 4Feb-1.pdf</a></span></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_8" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/geoint-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">GEOINT 2010</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/information-warfare-a-historical-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Information Warfare: A Historical Approach</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/fixmo-the-mobile-risk-management-company/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/spiral-seashells-painted-gold.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo: The Mobile Risk Management Company</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Unrestricted+Warfare+Symposium%2C+Sponsored+by+JHU%26%238217%3Bs+APL+and+SAIS&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2009%2F02%2Funrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais%2F&nr_ad_number=0&nr_div_number=8");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_8");nRelate.adAnimation("nrelate_related_8");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2009/02/unrestricted-warfare-symposium-sponsored-by-jhus-apl-and-sais/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Future of Cyberspace Security: The Law of The Rodeo</title>
		<link>http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/</link>
		<comments>http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 14:35:58 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[The Future]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[CTO Principles]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[DoDIIS]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Flash memory]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Great CTOs]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Moore's Law]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[ODNI]]></category>
		<category><![CDATA[Open Source Software]]></category>
		<category><![CDATA[R&D]]></category>
		<category><![CDATA[Ray Kurzweil]]></category>
		<category><![CDATA[Robots]]></category>
		<category><![CDATA[sites/tools]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[Thin Client]]></category>
		<category><![CDATA[Triumfant]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Verizon]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[Web/Tech]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=15</guid>
		<description><![CDATA[Tweet This is an update of my now annual assessment of the future of technology associated with good and evil in cyberspace which was first posted here. Predictions of the future of technology are increasingly starting to sound like science fiction, with powerful computing grids giving incredible computational power to users and with autonomous robots [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fthe-future-of-cyberspace-security-the-law-of-the-rodeo%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/"  data-text="The Future of Cyberspace Security: The Law of The Rodeo" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a title="The law of the rodeo" href="http://flickr.com/photos/9422878@N08/3213398742"><img class="alignleft" style="margin: 4px;" src="http://farm4.static.flickr.com/3107/3213398742_22d60ac404_m.jpg" alt="" width="213" height="240" /></a>This is an update of my now annual assessment of the future of technology associated with good and evil in cyberspace which was first posted <a href="http://ctovision.com/2007/10/good-and-evil-in-the-future-of-cyberspace/">here</a>.</p>
<div class="entry-body">
<p>Predictions  of the future of technology are increasingly starting to sound like  science fiction, with powerful computing grids giving incredible computational power to users and with autonomous robots becoming closer and closer to being in our daily lives vice just in computer science departments. Infotech, nanotech and biotech are fueling each other and each of those three dominate fields are generating more and more benefits that impact the other, propelling us even faster into a new world.   Depending on your point of view the increasing pace of science and technology can be good or  bad.  As for me, I&#8217;m an optimist, and I know we humans will find a way  to ensure technology serves our best interests.</p></div>
<p>But a sad fact of the human condition is that bad people will likely  be with us long into the future.  And sometimes good people can be  tempted to do bad things, so we really need to engineer solutions that<br />
keep the bad guys from benefiting from technology and keep those who  can sometimes be tempted from giving in to their darker side.</p>
<p>So is is possible to engineer perfectly secure systems?  Consider the law of the rodeo:  &#8220;There&#8217;s not a horse that&#8217;s never been rode, and not a rider that&#8217;s never been throwed.&#8221;  I like the analogy since it reminds us that all computer evil can be mitigated.  But it always fights back.  Good and evil will continue a fast paced rodeo dance long into the future.</p>
<p>To engineer secure systems for the future we need to continually  assess where we are and what the near term future holds for our  technologies.  Here is a couple short predictions that could be useful<br />
in this discussion.</p>
<p>- Remote power is here today and will soon be widely distributed.   This will allow small power consumption devices (like keyboards, mice,  bluetooth headsets, hearing aides, small sensors) to be provided power  by RF energy.</p>
<div class="entry-more">
<p>- Power generation from motion is almost ready for prime time.  This  will allow devices to gain energy from vibrations, like the vibrations  in a bridge when a car passes over it, or the vibrations in a wall of a<br />
building when the wind blows past it, or the vibrations caused by a  person&#8217;s movement through the day.</p>
<p>- Communication capability (bandwidth) between fixed facilities will increase 1000 fold over the next five years. Cellular systems are on a dramatic improvement slope.  My view: AT&amp;T seems to lead in speed this year.  Verizon will probably lead next year.</p>
<p>- More users will be on the net.  There are about 1.3Billion PC&#8217;s connected to the Internet today.  There are about 3.3Billion active cell phone subscriber accounts today.  Those numbers will grow.</p>
<p>- Storage, especially flash storage technologies, is decreasing in  price so much we can afford to store data anywhere on almost anything.</p>
<p>- Chips are being designed in ways that actually beat the old  Moore&#8217;s Law projections.  This is being done by placing many cores on  one chip.  Very high data rate capabilities are being connected  directly to the cores on these chips.</p>
<p>- RFID is becoming so widespread we can place devices on everything  that allows devices to report back what they are and what they are for  and where they have been.</p>
<p>- All this capabilities are being networked together, including  increasingly direct device to device connections via capabilities  provided by enhanced protocols (especially IPv6).</p>
<p>- Consumer devices, especially consumer communication devices, are  becoming increasingly capable.  What used to be called a cell phone is  now a phone/video recorder/video editor/entertainment/mobile office  device with location aware data (GPS).</p>
<p>- Web2.0 and Social networking sites/tools such as Facebook will expand till one day 100% of the population will have active, up to date, authoratative online profiles.</p>
<p>- Cloud computing capabilities are not only being delivered to companies, but to end users.  Google leads the pack in this space, but Microsoft and Adobe are up and comers.</p>
<p>There are many other elements of the future relevant to security  discussions, but the projections above lead to some interesting  conclusions on their own.   So lets think through some of the impacts<br />
of the above.</p>
<p>- Bad actors who want to exploit systems will increasingly not have  to worry about them being powered off.  They will be on all the time.</p>
<p>- Bad actors will increasinly be able to expoit social systems to gather data pre-attack.  However, the powerful trust models of social networks may offer a counter to some of these attacks.</p>
<p>- Many paths into devices will be available for unauthorized users  to exploit.   And if they are compromised by people or code that intend  on generating denial of service attacks, huge amounts of bandwidth will  exist for them to attack from.</p>
<p>- When a bad actor gets through defenses into data stores, they will  likely find a wide range of data to exploit, since it is becoming so  easy and low cost for us to store everything.</p>
<p>- Having things networked together means it can be easier to  penetrate a target by finding one weak link that is connected to the  infrastructure.</p>
<p>- Areas of people&#8217;s lives they once thought private, especially  their cell phones and the data on their cell phones, are increasingly  becoming attractive targets to hackers.</p>
<p>What is needed in an environment like this?  I can&#8217;t pretend to know all the solutions but here are a few points I support:</p>
<p>- Enhanced firewalls and intrusion detection devices.</p>
<p>- Better configuration control, for all devices.  When a device is  out of configuration is must be brought back into compliance  immediately.</p>
<p>- Better laws and treaties concerning cyberspace. Deterrence policies by governments.</p>
<p>- More attention to standards and to industry organizations (including supply chain quality  organizations) is a must.</p>
<p>- Better training and education for all (I mean ALL) humans connected to the grid.</p>
<p>- Better, continuous upgraded anti-virus solutions.</p>
<p>- Automated response to attacks.</p>
<p>- Enhanced, easier to use encryption.</p>
<p>- Enhanced, more secure identity and authorization technologies.</p></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_9" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/interested-in-cyber-security-read-and-support-the-new-cybersecurity-legislative-proposal/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22287c15091f7562d56a24afb02c8118_thumb_CNO-pic.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Interested in Cyber Security? Read (and support) the new Cybersecurity Legisl ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/05/the-u-s-international-strategy-for-cyberspace/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a8a2beedd8b0fdd27d42eac052551cb1_thumb_Department_of_state.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The U.S. International Strategy for Cyberspace</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/federal-rd-priorities/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/374a6220632b469ef56ad107944f9496_thumb_NSTC.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Federal R&D Priorities</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/07/pros-and-cons-cyber-command/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/6f96223061ef7477c860bacf70a6861b_thumb_200px-2010-05-14-USCYBERCOM_Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pros and Cons: Cyber Command</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.haftofthespear.com/?p=1899"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/www.haftofthespear.com/65008238cd4f0cfc80b47d90b89940a0_thumb_Cyber-Spreadsheet-Bullshit-300x297.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Killing Trees for Cyberspace</span><span class="nr_source">Haft of the Spear</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/white-house-roadmap-lays-out-federal-cybersecurity-rd-priorities/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">White House roadmap lays out federal cybersecurity R&D priorities</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.haftofthespear.com/?p=1860"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/65008238cd4f0cfc80b47d90b89940a0_thumb_Cyber-Spreadsheet-Bullshit-300x297.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The End of Cyber Security (Part IV)</span><span class="nr_source">Haft of the Spear</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/dodaro-key-challenges-remain-for-dhs-in-cybersecurity-mission/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Dodaro: Key challenges remain for DHS in cybersecurity mission</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/cyberterrorism-a-threat-that-won%e2%80%99t-go-away/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cyberterrorism a threat that won’t go away</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=The+Future+of+Cyberspace+Security%3A+The+Law+of+The+Rodeo&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fthe-future-of-cyberspace-security-the-law-of-the-rodeo%2F&nr_ad_number=0&nr_div_number=9");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_9");nRelate.adAnimation("nrelate_related_9");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/10/the-future-of-cyberspace-security-the-law-of-the-rodeo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Melissa Hathaway Op-Ed on Cyber Security</title>
		<link>http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/</link>
		<comments>http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/#comments</comments>
		<pubDate>Wed, 15 Oct 2008 03:52:44 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[AFCEA]]></category>
		<category><![CDATA[CCSA]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[DNI]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[Melissa Hathaway]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[spy]]></category>
		<category><![CDATA[spy services]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[Technology Leadership]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[Thin Client]]></category>
		<category><![CDATA[Triumfant]]></category>
		<category><![CDATA[Web/Tech]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=20</guid>
		<description><![CDATA[Tweet Below I&#8217;m going to post, in its entirety, the text of an e-mail I received from the ODNI notification service.   The subject is an op-ed written by Melissa Hathaway, a senior leader who has been spearheading significant coordination action in the federal government (opinion: Melissa is perhaps the most effective SES-level leader in the [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fmelissa-hathaway-op-ed-on-cyber-security%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/"  data-text="Melissa Hathaway Op-Ed on Cyber Security" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div style="text-align: left;">Below I&#8217;m going to post, in its entirety, the text of an e-mail I received from the ODNI notification service.   The subject is an op-ed written by Melissa Hathaway, a senior leader who has been spearheading significant coordination action in the federal government (opinion: Melissa is perhaps the most effective SES-level leader in the US government today, IMHO).</p>
<p>I wanted to post this in totality for a couple reasons.  One is it is something all of us should read.  Although I believe most readers of this blog will find no surprises in this op-ed, Melissa has a real talent for capturing information in easy to understand ways and I think we can all borrow lessons from the way she explains things.</p></div>
<p><span id="more-20"></span></p>
<p>Another reason to read this is to take a queue from Melissa on what else is needed in this space.  I&#8217;ve known Melissa long enough to say that what ever she supports I support.  She says the nation needs many things to be worked in this area, including more work in alliances and partnering, re-thinking relationships between government and the private sector regarding cyber security, enhancing ways to share sensitive info with industry.</p>
<p>She also calls for a continuing public commitment to securing cyberspace.  I&#8217;m certainly with her on that one.   And I hope all our public officials are too.</p>
<p>Here is the Op-Ed:</p>
<p style="text-align: center;"><strong><span style="font-size: medium;">Melissa Hathaway Op-Ed on Cyber Security</p>
<p></span></strong></p>
<p><span style="font-size: small;"><em>The following Op-Ed by Melissa Hathaway,<br />
Cyber Coordination Executive for the Office of the Director of National<br />
Intelligence, was published by the McClatchy-Tribune News Service on<br />
Wednesday, October 8, 2008:</em></span></p>
<p><span style="font-size: small;"><strong>Safeguarding our cyber borders</strong></span></p>
<p><span style="font-size: small;">By Melissa Hathaway &#8211; Op-Ed &#8211; McClatchy-Tribune News Service</span></p>
<p><span style="font-size: small;">London shoppers who bought groceries with bankcards over the last two years paid a higher price than they bargained for.</span></p>
<p><span style="font-size: small;">Cyber<br />
thieves had implanted unauthorized circuitry in keypads sold to<br />
supermarkets in the Barking and Dagenham area of the British capital.<br />
The corrupted keypads were then used to capture account information and<br />
Personal Identification Numbers (PINs). The data were siphoned off and<br />
used to skim from or in some cases empty shoppers&#8217; bank accounts. </span></p>
<p><span style="font-size: small;">The thieves covered their tracks by encrypting the<br />
numbers they stole, then storing them on a computer server abroad. It<br />
took more than a year for the authorities to catch on. </span></p>
<p><span style="font-size: small;">Stories such as that aren&#8217;t only sobering news for<br />
consumers. For folks charged with securing and protecting the nation&#8217;s<br />
defense and intelligence infrastructure, however, increasingly<br />
sophisticated cyber assaults are a chilling &#8212; and increasingly<br />
familiar &#8212; challenge. </span></p>
<p><span style="font-size: small;">The same devices that thieves use to sneak into bank<br />
accounts, the same techniques that hackers use to disrupt Internet<br />
service or alter a digital profile, are being used by foreign military<br />
and spy services to besiege information systems that are vital to our<br />
nation&#8217;s defense. </span></p>
<p><span style="font-size: small;">Because defense and other national security contractors<br />
share data and systems with their government partners, an attack on one<br />
can be an attack on many. Plans are only as secure as the weakest link<br />
in the information chain. These days, those links are being tested as<br />
never before. </span></p>
<p><span style="font-size: small;">The attackers&#8217; goals fall into three categories:</span></p>
<p><span style="font-size: small;">•<br />
Information theft. Stealing data from a target personal device, system<br />
or network is the most common threat. For example, a disgruntled Boeing<br />
employee was charged last year with lifting more than 320,000 sensitive<br />
company files by using a thumb drive to tap the corporate system.<br />
Boeing estimated that the stolen documents would have cost it between<br />
$5 billion and $15 billion in lost revenue had they been given to<br />
competitors. </span></p>
<p><span style="font-size: small;">• Information disruption. Hackers who sneak into<br />
government systems and alter crucial operating data are a growing<br />
concern. In 2006, a disgruntled Navy contractor inserted malicious code<br />
into five computers at the Navy&#8217;s European Planning and Operations<br />
Command in Naples, Italy. Two computers were rendered inoperable when<br />
the program was executed. Had the other three computers been knocked<br />
offline, the network that tracks U.S. and NATO ships in the<br />
Mediterranean Sea and helps prevent military and commercial vessels<br />
from colliding would have been shut down. </span></p>
<p><span style="font-size: small;">• Information denial. Cases in which private or<br />
government computer systems are shut down by floods of automated hits<br />
are also on the rise. In April 2007, Russian nationalists used such a<br />
&#8221;distributed denial of service&#8221; attack to block access to the<br />
networks of the Estonian parliament, the president&#8217;s office and many of<br />
that country&#8217;s banks, news organizations and Internet service<br />
providers. </span></p>
<p><span style="font-size: small;">The &#8221;What Ifs&#8221; are an even greater concern. Could an<br />
adversary insert erroneous data that would cause weapons, early warning<br />
systems and other elements of national security to fail at critical<br />
times? What if financial or medical records were altered, or rail or<br />
air traffic control systems were corrupted? What if malicious code were<br />
secretly installed during the manufacture or shipping of computer<br />
equipment, to be activated at some future date? How would we even know<br />
what threats we face? </span></p>
<p><span style="font-size: small;">Defensive measures are being taken. In January,<br />
President Bush proposed a 12-point Comprehensive National Cybersecurity<br />
Initiative whose solutions range from a public awareness campaign to<br />
sophisticated new systems for identifying and deterring intrusions.<br />
Congress approved funding in late September. </span></p>
<p><span style="font-size: small;">A key element of the plan &#8212; reducing the number of<br />
access points between federal agencies and external computer networks<br />
&#8211; is under way. The federal government has closed about 3,500 such<br />
access points this year, leaving about 1,000 still open. The goal is to<br />
reduce the final number to fewer than 100. </span></p>
<p><span style="font-size: small;">Much more needs to be done, however.</span></p>
<p><span style="font-size: small;">We<br />
need stronger international alliances to share the responsibility for<br />
securing cyberspace. We must do more to convince our allies and<br />
strategic partners of the benefits to them of taking an active role. </span></p>
<p><span style="font-size: small;">We also need a fundamental re-thinking of our<br />
government&#8217;s traditional relationship with the private sector. A high<br />
percentage of our critical information infrastructure is privately<br />
owned, and industry needs to know what government knows about our<br />
adversaries&#8217; targets and, to the extent we understand them, their<br />
methods of operation. </span></p>
<p><span style="font-size: small;">When it comes to cyber security, government and the<br />
private sector need to recognize that an individual vulnerability is a<br />
common weakness. </span></p>
<p><span style="font-size: small;">There&#8217;s time, though not unlimited time, to get the job<br />
done. We must make a continuing public commitment to securing cyber<br />
space &#8212; and we must do so now.<br />
<em></p>
<p>Melissa Hathaway is the cyber coordination executive<br />
for the director of national intelligence. The Department of Homeland<br />
Security has designated October National Cyber Security Awareness<br />
Month. </em></span></p>
<p>For related posts on this topic see:  <a href="http://www.ctovision.com/cyber_initiative/">http://www.ctovision.com/cyber_initiative/</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_10" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/melissa-hathaway-compelling-action-along-a-broad-front/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/860c2d78b8b85c4eb1767454fe06f887_thumb_MelissaHathaway.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Melissa Hathaway: Compelling action along a broad front</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/02/continuing-focus-on-mission-it-at-odni-cio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b87e7886a7ecc8472442a1dec461006b_thumb_tarasiukhallbarlow-300x207.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Keeping Focus on Mission IT at ODNI CIO</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/a-first-for-the-nation-nerc-completes-first-grid-security-exercise/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A First For The Nation: NERC Completes First Grid Security Exercise</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Melissa+Hathaway+Op-Ed+on+Cyber+Security&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2008%2F10%2Fmelissa-hathaway-op-ed-on-cyber-security%2F&nr_ad_number=0&nr_div_number=10");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_10");nRelate.adAnimation("nrelate_related_10");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2008/10/melissa-hathaway-op-ed-on-cyber-security/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

