• On CHOW: Sexy vampire party
February 23, 2009 9:47 AM PST

Defense agencies list top 20 security controls

by Tom Espiner
  • Font size
  • Print
  • 5 comments

A group of U.S. government security organizations has listed the top 20 security actions that they recommend organizations should take to improve computer security.

Called "Twenty Most Important Controls and Metrics for Effective Cyber Defense and Continuous FISMA Compliance," the list was published Monday by a conglomerate of U.S. government agencies, including the NSA, US-CERT, various U.S. Department of Defense computer security groups, and security training organization Sans Institute.

Alan Paller, director of Sans Institute, told CNET News sister site ZDNet UK in an e-mail Friday that the list, also known as the Consensus Audit Guidelines (CAG), would spark "a complete revolution in federal and business cybersecurity."

"I do not know of anything going on in security that will have the impact this initiative can have," said Paller. "If the nation (and the rest of the developed world) cannot make the CAG work we will continue to fall further behind the attackers, at an accelerating rate."

The CAG's first recommendation is that companies should put together an inventory of authorized and unauthorized hardware. According to the CAG, criminal and foreign governmental organizations scan networks to identify and exploit unpatched systems. Companies should compile a dynamic inventory, controlled by automated monitoring and configuration management, to reduce the chance of an attacker finding and exploiting unauthorized and unprotected systems.

Having a whitelist of authorized software, and an inventory of authorized and unauthorized software, is also important, according to the CAG. Software that is extraneous to business use often introduces security vulnerabilities and, once a machine is exploited, attackers can use it as a staging point for collecting sensitive information from other systems, warned the guidelines. The list of security controls is available from the Sans Institute Web site.

Experts began to compile the CAG list in 2008 following a series of "extreme data losses" suffered by U.S. defense industry companies, according to a Sans Institute statement. Federal cyber attack and defense experts, including penetration testing teams, began to pool their knowledge of the attack techniques being used against the government and defense industrial base. The result is the list of 20 security controls.

"We are in a war, a cyber war, and the federal government is one of many large organizations that are being targeted," CAG project leader John Gilligan, who served as chief information officer for both the U.S. Air Force and the Department of Energy, said in a conference call on Monday. "Our ability, at present, to be able to detect and defend against these attacks is really quite weak in many cases."

The CAG will have a 30-day review period following publication, during which time security experts are invited to comment on the document and propose additions. The list of controls will then undergo pilot implementations in several federal agencies, after which it will be reviewed by the CIO council to determine how it can be used across the U.S. government to focus and prioritize security expenditure.

The guidelines have a "high probability of becoming a common set of controls" for private industry, as well, Paller said during the conference call.

Last month U.S. security organizations in conjunction with Sans Institute published a list of the top 25 coding errors that introduce security vulnerabilities into software.

Tom Espiner of ZDNet UK reported from London.

Updated 12:00 p.m. PST with comments from conference call.

advertisement
Click Here
Recent posts from Security
Microsoft warns of IE exploit code in the wild
Chrome OS security: 'Sandboxing' and auto updates
E-tailers snagged in marketing 'scam' blame customers
McAfee warns about '12 Scams of Christmas'
Cisco launches iPhone security app
Town to photograph every car that enters and leaves
New Firefox 3.6 beta aims to cut crashes
Facebook adopts new privacy policy
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by n3td3v February 23, 2009 11:06 AM PST
SANS is not to be trusted they are known to be used by the CIA and government to push out propaganda.
Reply to this comment
by Penguinisto February 23, 2009 11:20 AM PST
...tinfoil much?

Geez.
Reply to this comment
by n3td3v February 23, 2009 2:58 PM PST
[quote]"We are in a war, a cyber war, and the federal government is one of many large organizations that are being targeted," CAG project leader John Gilligan, who served as chief information officer for both the U.S. Air Force and the Department of Energy, said in a conference call on Monday.[/quote]

I'll only ever believe there is a Cyber War in progress when its announced by U.S State Department or The White House, until then its FUD so that government departments and the private sector can get funding. In reality there is no Cyber War, there are no two sides fighting in cyber.
by Dango517 February 24, 2009 2:49 AM PST
The cold war repackaged. We do this, they respond by countering. We try something, they counter. They do something, we counter. In the final analysis, the smartest and most determined will win ............... to face yet another enemy.

Real threats at some point stop the "cat and mouse games" and raise there angry heads. Their first attack with be on cyberspace, against command and control. We should be prepared.
Reply to this comment
by n3td3v February 24, 2009 4:55 AM PST
[quote]Their first attack with be on cyberspace, against command and control. We should be prepared. [/quote]

This comment is absolute FUD propaganda.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

Firefox hopes to one-up IE with fast graphics

Windows 7 features called Direct2D and DirectWrite will speed up Internet Explorer 9 performance. But Firefox hopes it might retool for the same benefit first.

E-tailers linked to 'scam' blame customers

Priceline, Classmates.com, and Orbitz say customers should read the fine print before complaining about being charged to join loyalty programs they didn't want.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right