Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Homeland Security's high tech conundrum

Anne Broache CNET News.com

Published: 08 Nov 2005 15:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A preliminary report released by the Department of Homeland Security seems to scatter cybersecurity responsibilities across the government and the private sector, while sticking to generalities about future plans.

In its 175-page draft of the National Infrastructure Protection Plan (PDF), the department outlines a broad framework for protecting the nation's "critical infrastructure" and "key assets" — bureaucratic argot referring to everything from the power grid to dams to computer systems.

President Bush first commissioned the plan in December 2003 and the Department of Homeland Security released an early version in February. According to a notice announcing the document's availability, the latest version aims to provide greater detail.

The term "cybersecurity" appears 148 times in the draft, and a 16-page appendix devoted to the topic offers some suggestions for threat analysis, response readiness and training.

But the rest is worded in terms of generalities. The plan asserts that cybersecurity responsibilities should ultimately lie with the Department of Homeland Security, but also calls on state and local governments to come up with information security measures and to be aware of vulnerabilities in their systems. The report charges academia and research institutions with devising "best practices" for IT security and the private sector with ensuring that it is "satisfying cyberprotection standards".

The document suggests that work should be done through a "sector partnership model" — that is, informal advisory bodies composed of private-sector and governmental representatives from the same subject area. It proposes several lists of general actions that various sectors should take (for example, "set sector-specific security goals") and allocates deadlines from the adoption of the plan to accomplish them (in that particular case, 90 days).

The recommendations are often vague. For example, the suggestion that the Department of Homeland Security should lead and develop a "national cybersecurity exercise" to simulate responses to an attack is listed as an "ongoing" project with no deadline. And under a category referring to the steps the government should take to deal with "privacy and constitutional freedoms", the department lists no suggested actions.

Department of Homeland Security representatives did not respond to interview requests. The agency plans to accept comments on the proposal until 5 December.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
123 out of 216 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters