[ISN] U.S. Cybersecurity Is Weak, GAO Says

From: InfoSec News <alerts_at_private>
Date: Tue, 16 Sep 2008 03:45:11 -0500 (CDT)
http://www.businessweek.com/technology/content/sep2008/tc20080915_347282.htm

By Keith Epstein
BusinessWeek
September 15, 2008

The federal government cybersecurity team with primary responsibility 
for protecting the computer networks of government and private 
enterprise isn't up to the job, according to a draft Government 
Accountability Office report [1] obtained by BusinessWeek.

The U.S. Computer Emergency Readiness Team, known as US-CERT, mans the 
front line in any cyber-attack. The group monitors computer networks for 
hacker threats, investigates suspicious activity online, and is supposed 
to issue timely alerts to information technology security professionals 
from the White House to corporations and electric utilities. But the GAO 
draft report describes US-CERT as bedeviled by frequent management 
turnover, bureaucratic challenges that prevent timely sounding of 
alarms, a lack of access to networks across wide swaths of critical 
terrain, and an inability to fill large numbers of positions with 
qualified workers.

Five years after the Homeland Security Dept. took charge of the team as 
a critical safeguard against threats to national security, US-CERT 
"still does not exhibit aspects of the attributes essential to having a 
truly national capability," according to the draft report.

[1] http://www.businessweek.com/pdfs/2008/0916_cyberanalysis_and_warning.pdf

[...]


__________________________________________________      
Register now for HITBSecConf2008 - Malaysia! With 
a new triple-track conference featuring 4 keynote 
speakers and over 35 international experts, this 
is the largest network security event in Asia and 
the Middle East! 
http://conference.hackinthebox.org/hitbsecconf2008kl/
Received on Tue Sep 16 2008 - 01:45:11 PDT

This archive was generated by hypermail 2.2.0 : Tue Sep 16 2008 - 02:01:21 PDT