Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Monday, December 14, 2009

The Importance of Background Checks

The Department of Homeland Security recently learned the importance of background checks the hard way, as a fugitive wanted on a national arrest warrant for insurance fraud was found to be working for a DHS office. This serves as a great reminder that background checks are a really inexpensive way to make sure that staff working in potentially sensitive positions (or with access to sensitive data) are worth reviewing.

Saturday, October 17, 2009

1000 Security Experts? Not exactly what the doctor ordered.

Bob Cringely recently discussed the Department of Homeland Security's plan to hire 1,000 "cybersecurity experts" to defend U.S. computer networks. His take? That there aren't 1,000 cybersecurity experts to be found in the U.S. His unnamed cybersecurity expert friends tend to agree in various forms, ranging from a discussion of the semantics of the goal to a more in-depth discussion of the forms of expertise that can be found, and a note that there are 1,000 security experts - on the wrong side of the fence.

Cringely also contends that no matter what the actual intent, this hiring is largely window dressing and that the end result won't be a sea change in how government information security is done. He points to low CCIE graduation rates as a good metric for how many security experts can be found, which may not be the best metric for security expertise across the board - to me, it indicates that holders of one brand of high level network security expertise do exist, but that the demand for CCIEs isn't sufficient to push further qualifiers into the certificate at a high rate. In addition, personal experience indicates to me that many qualified security experts don't carry all of the certifications that they could qualify for for any of a broad variety of reasons - that doesn't mean that we have hundreds of certification-less CCIEs around, but it does mean that we may have experts we're not counting if we only count certificates.

The problem here is that security expertise covers a broad variety of fields from risk assessment to network security to physical security design and back again. Seeking a thousand cybersecurity experts is, in many ways more akin to seeking a thousand expert college professors in engineering. You many not find them all in nuclear engineering at the level that you desire, but you may very well find that many experts across all of the disciplines that you need - and then you'll realize that you really wanted some of them to be TA's, Ph.D. candidates, and others who many not yet be experts - but will be.

Polymath experts with broad experience and deep expertise across the spectrum of information security are definitely necessary to tie those skillsets together, especially when you need to glue complex systems together, but you don't need - or necessary want hundreds of those big guns. Cringely notes that such experts aren't found in packs, and that is one point that I'll agree with. In any field the major experts hold a special place, and some take full advantage of it.

One of Cringely's experts dismisses the DHS plan - "you will end up with 1,000 Security Managers in the government with Sec+, and CISSP certifications". This picture of outsourced expertise and a lack of true change doesn't reflect the fact that skilled security managers are just as necessary as the heavy hitter deep dive experts. If the Department of Homeland Security really wants to change the face of government information security, the program and these new hires must be run adeptly, and that can be a real challenge.

DHS doesn't need to simply hire 1000 identical security superheroes. They need to embed employees with appropriate skillsets in those areas that face risk - after they assess the risk - and then they need to work out a coherent program to improve and manage both their security program and their security staffers. With the right guidance, 1000 security employees of many types could change how government information security is done.

Friday, September 5, 2008

DHS Daily Reports: Another Useful Feed

The Department of Homeland Security Daily Open Source Infrastructure Report is available in feed form at http://dhs-daily-report.blogspot.com - take a look if you're interested in seeing what the DHS is reporting on a daily basis for public consumption. The PDF form is available directly from the DHS at http://www.dhs.gov/xinfoshare/programs/editorial_0542.shtm.

Thursday, December 20, 2007

DHS: CFATS - have you accounted for your chemicals?

Many higher education institutions will be preparing their lists of "chemicals of interest" for the Department of Homeland Security early next year. The rule stipulates that listings be delivered 60 days after the release of the final rule meaning lists will have to be provided by January 19th unless you request and receive a 60 day extension. Chemicals range from chlorine to aluminum chloride to propane, meaning that many departments on campus will likely have to report their totals.

If you haven't thought about what the chemicals on your campus could be used for, take a look. Each chemical lists what it would be potentially useful for, providing a convenient overview of what risks your campus might face.

The Chemical Facility Anti-Terrorism Standards require a variety of things, ranging from risk assessments to reporting of chemical amounts on hand . These apply to many higher education institutions, and responsibility for detailing may have fallen to risk management or facilities staff. If you're an information security staffer, you may want to check with the appropriate department at your school to see how that data is being stored and secured.

Where did all of this come from? It is part of the Department of Homeland Security Appropriations Act of 2007, which President Bush signed in October, 2006. Section 550 of the Act gave DHS the authority to enact the rules above. The Act defines the covered entities as "chemical facilities that, in the discretion of the Secretary, present high levels of security risk." More details can be found in the final rule here.