• On TechRepublic: 10 cool USB flash drive tricks
September 19, 2008 10:20 AM PDT

Should NSA take over federal cybersecurity efforts?

by Stephanie Condon
  • Font size
  • Print
  • 2 comments

Political pressure is mounting to eliminate the U.S. Department of Homeland Security's lead role over cybersecurity, a move that that would effectively admit the agency's failure to adequately perform its assigned duties.

But that invites the obvious question: Who should take over? One option would be, as we heard earlier this week, the White House itself. Another choice would be the more shadowy world of intelligence agencies such as the CIA or National Security Agency, which already is responsible for protecting government computers through its "information assurance" arm.

Congress tech

All week, members of a cybersecurity commission forming recommendations for the next administration have been telling Congress that cybersecurity requires senior level policy and program coordination from the White House.

Even though Homeland Security claims that cybersecurity is one of its top priorities, the department is not equipped to handle cyberthreats, says the Center for Strategic and International Studies' Commission on Cybersecurity for the 44th Presidency, a private effort that includes representatives of the so called "intelligence community."

A new White House program on cybersecurity, the commission says, should have clear authority over all the agencies and departments that help keep the country's networks secure. At a hearing on Thursday, members of the commission specifically warned the House Select Committee on Intelligence against letting too much authority fall into the hands of intelligence agencies.

It might be easy for politicians to hand over power to agencies like the CIA or NSA since they already can claim to have critical expertise needed to maintain cybersecurity. "The intelligence community has a vital supporting role," said Paul Kurtz, a partner and COO for Good Harbor Consulting,

In the case of a cybersecurity breach on a critical network, intelligence agencies can be useful in dissecting and analyzing the code found to determine the threat level of the breach as well as the source. Once the enormity and source of a cyberattack is determined, the intelligence community can help the rest of the federal government weigh its response options.

"It doesn't necessarily have to be a response in cyberspace," Kurtz said, adding that the White House could consider military action in response to a cyberattack.

However, cybersecurity "will fall prey to over-classification" if too much authority is given to the intelligence community, said Suzanne Spaulding, an attorney with Bingham McCutchen.

"The intelligence community operates in an environment of secrecy," she said, and "secrecy has significant costs," such as weakening the trust the government has with the private sector and the international community.

The White House has already been inexplicably secretive about its DHS-led National Cyber Security Initiative, Kurtz said. The Defense Department, FBI, Office of the Director of National Intelligence, and other departments have discussed the initiative with the CSIS commission "despite White House wishes," he said.

The CSIS commission is still considering how much authority should be left to the DHS, Kurtz said, such as oversight over certain cybersecurity domains like the U.S. Computer Emergency Readiness Team.

Committee Chairman Silvestre Reyes, D-Texas., said he found it interesting the White House had put the DHS in charge of the initiative in the first place. He called it "the equivalent of somebody drowning and tossing him an anchor."

Congress should step up its oversight of the cyberinitiative, Kurtz said, and form a joint cybersecurity committee. He also suggested the House Intelligence Committee request briefings from the intelligence agencies about how they communicate with the private sector.

He suggested that Congress should implement a common authentication system for critical infrastructure networks, rather than continuing to let states maintain their own.

The federal government also needs to encourage other countries to ratify the Convention on Cybercrime, said Martha Stansell-Gamm, former chief of the Justice Department's Computer Crime and Intellectual Property Section. The convention, she said, gives countries "the permission and capabilities to put their (cybercrime) laws to the service other countries."

CNET's Declan McCullagh contributed to this report

Stephanie Condon is a staff writer for CNET News focused on the intersection of technology and politics. She is based in Washington, D.C. E-mail Stephanie.
Recent posts from Politics and Law
Baidu launching online-video company
'Kill Obama' Facebook group active for a month
'Don't-be-evil' Google spurns no-evil software
White House appoints cybersecurity chief
U.S. cap and trade looks out of reach in 2010
FTC's new strategy: Kick 'em when they're down
Plurk holding Microsoft's feet to code-copying fire
FTC wants Intel to mend its ways
Add a Comment (Log in or register)
by Vurk September 19, 2008 3:16 PM PDT
Why not let the NSA handle national cybersecurity? Theyre already spying on everyone, so this wouldnt be *that* much more of an intrusion.
Reply to this comment
by September 22, 2008 10:53 AM PDT
NSA has the skills and the personnel to run "RED TEAM" exercises against domestic agencies and bases they also have a secure position outside the chain of command that could cripple the effectiveness of persons who although they have the skills, would be fired for running a realistic threat assessment against their own people who are guarded by agency heads who do not want their agencies to be known for weak policies, procedures, and management.

NSA for the same reason does NOT need to be involved with leading cybersecurity because they could not be embarrassing other organizations and branches of government and still be in a leadership position.
Reply to this comment
advertisement

E-readers' next chapter--no happy ending?

There were plenty of e-book readers on display at CES 2010, but many question whether the market for such dedicated devices can support all the new entrants.
• Photos: E-readers at CES 2010

Inside the world's long-lost first microcomputer

Vintage computer historians have long revered the Altair 8800. As it turns out, an unknown computer project at Sacramento State beat the Altair by three years.
• Images: The first microcomputers

About Politics and Law

News at the intersection of technology, politics, and law, ranging from intellectual property to censorship to tech policy.

Add this feed to your online news reader

Politics and Law topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right