• On CHOW: Is it OK to sneak popcorn into a movie?
December 19, 2008 10:39 AM PST

After six years, Homeland Security still without 'cybercrisis' plan

by Declan McCullagh
  • Font size
  • Print
  • 14 comments
Homeland Security

When the U.S. Department of Homeland Security was created, it was supposed to find a way to respond to serious "cybercrises." "The department will gather and focus all our efforts to face the challenge of cyberterrorism," President Bush said when signing the legislation in November 2002.

More than six years later, and after spending more than $400 million on cybersecurity, DHS still has not accomplished that stated goal. "We need to have a plan tailored for a cybercrisis," DHS Secretary Michael Chertoff said on Thursday.

Chertoff told a conference in Washington, D.C., that creating such a plan first requires "a clear awareness of exactly what the dimension of the threat was," meaning the ability to detect intrusions in real time, and probably means taking some of the existing plans for physical attacks and "adapt them and some of the basic principles" to electronic threats.

"I do think that we have work to do in figuring out how to tailor something specific for cybersecurity in the same way that we've done it for natural disasters or terrorist attacks or things of that sort," he added.

Because only a few weeks are left in the Bush administration, any further work will be left to the administration of President-elect Barack Obama.

The Bush administration has spent $115 million on DHS's National Cybersecurity Division for the 2008 fiscal year. Totaling the budgets for the previous four years yields approximately $300 million, or approximately $415 million over five years including 2008.

The cybersecurity division has been plagued by a lack of leadership, with industry representatives unsure of who to contact. The revolving door of leadership within the division prompted a cybersecurity commission to recommend that leadership be moved to the White House, something that DHS opposes.

"There's no one place in charge," said Andy Singer, principal of the cybercampaign team for Booz Allen Hamilton, one of the sponsors of Thursday's conference. "Who does Bank of America go to if they're having a problem?"

Even by Washington standards, the turnover of various cybersecurity "czars" has been remarkable: Richard Clarke, a veteran of the Clinton and first Bush administrations, left the post with a lucrative book deal. Clarke was followed in quick succession by Howard Schmidt, then Amit Yoran and Robert Liscouski. Another DHS cybersecurity official, Jerry Dixon said after he left that "nothing is happening" in the department in this area.

Secretary Michael Chertoff

Secretary Michael Chertoff

(Credit: Department of Homeland Security)

Along the way, DHS was regularly receiving poor grades--including an F--on computer security report cards released by a congressional oversight committee.

Not helping was what Chertoff once described as "initial concerns" about raising the profile of cybersecurity in a bureaucratic culture that was focused on physical threats, and the decision to leave the top DHS cybersecurity post open for over a year. Greg Garcia got the job in September 2006 and is still there, as is Undersecretary Robert Jamison, who oversees "infrastructure protection."

Part of the problem for DHS, though, is out of its immediate control. The commercial Internet has been built by private companies, who constantly monitor their systems for attacks and know the status and performance of their networks much better than a Washington bureaucracy ever could. Moreover, monitoring of private networks by government agencies raises serious security and privacy concerns.

This is what Chertoff said on Thursday:

I want to begin by saying that I'm very sensitive to the fact that the culture of the Internet, as well as the actual architecture, is one which does not lend itself to government regulation and mandates... We are willing to provide capability to those who want us to provide that capability, but we don't make you do it. And if someone doesn't want to have the government involved and they want to live outside of any kind of government assistance or cooperation, I don't know that we would necessarily be wise to try to make them do it...

And that's why I'm really emphatic about the need to not make this a mandatory system but rather a system where we create opportunities for people. I actually think most people in the private sector will take those opportunities and will accept our invitation. But I also know if we try to make it something that we push onto people, the backlash we are going to see will dwarf of the controversies that we've seen with respect to what we've done in the communications field over the last eight years...

And then we're behind the eight ball because we're explaining that we're really not Big Brother. A classic example, before my time, was a search engine--I think it was called Carnivore, which the FBI came up with. And I think it made a lot of sense, but the word "Carnivore" was the absolute wrong thing to have in that program.

Chertoff also said that Bush is has been briefed on these topics as recently as the last week--"he's very, very concerned about making sure this vulnerability is adequately reduced and protected"--and said that the next generation of DHS' early-warning system for cyberincidents, called Einstein 3, would go live in the next six months.

Part of the purpose of arranging this week's cyberthreat simulation conference was to help all the relevant parties develop a plan of response in the event in a cyberattack--something that the DHS National Cyber Response Coordination Group has not accomplished.

Booz Allen Hamilton's Singer said it's too early to tell whether DHS will be able to sufficiently manage cybersecurity.

"If you look at some of the constructs in DHS--they have Undersecretary Jameson and the NCSC, the NCSD--it's a pretty tough task to make sure all of those pieces fit together," he said. "Whenever there's people involved, you always have the potential for seams, for things to fall through the cracks. On the first day of the simulation, people were looking for government to solve problems, but by the end of today, people were saying government can't save everything."

CNET's Stephanie Condon contributed to this report

Declan McCullagh, CNET News' chief political correspondent, chronicles the intersection of politics and technology. He has covered politics, technology, and Washington, D.C., for more than a decade, which has turned him into an iconoclast and a skeptic of anyone who says, "We oughta have a new federal law against this." E-mail Declan.
Recent posts from Politics and Law
What kind of virus has Fiorina's ad spread?
FBI wants records kept of Web sites visited
DOJ not pleased with latest Google Book agreement
Lawmakers grill execs over Comcast-NBC deal
U.S. House passes cybersecurity research bill
Web video gets H.264 royalty reprieve
Police survey provides glimpse of Net-surveillance figures
Government warns of looming cyberthreats
Add a Comment (Log in or register) (14 Comments)
  • prev
  • next
by Orion Blastar December 19, 2008 11:22 AM PST
If the DHS really was monitoring the entire Internet, they'd be able to detect the intrusions. But since they are not monitoring the entire Internet for the USA, it is clear that they are not domestic spying on the Internet. Take that liberals. :)
Reply to this comment
by ferretboy88 December 19, 2008 2:33 PM PST
We can't spy on these people but its ok for LIberals to spy on Joe the Plumber and put all of his personal info in the newspapers. That was spying. Why do I know what he owes on his credit card?
by Dalkorian December 22, 2008 10:00 AM PST
Retardicans amaze me. We have an article here stating that fuhrer bushit and his criminal cabal have robbed America of another $400 million for nothing and retardicans show up to make up stories about liberal abuses and try to twist reality to prove they really aren't stupid and evil.

That's why you were fired last month.
by michaelo1966 December 19, 2008 11:47 AM PST
"Who does Bank of America go to if they're having a problem?" Duh -- they go to Bush & Paulson, who gives them $25B with no strings attached. Oh ... an IT problem? I'm guessing they've figured this out on their own, just like they figured out how to guard people's money without a $400MM government report.
Reply to this comment
by n3td3v December 19, 2008 1:09 PM PST
Don't counter attack, simply track down who done it in real-time then go arrest them in real life.
Reply to this comment
by ferretboy88 December 19, 2008 2:32 PM PST
NO find them and kill them.
by ferretboy88 December 19, 2008 2:32 PM PST
When you find out where the attack is coming from launch a large missile to the guys house. That way people in Russia or China will stop hacking into our systems.
Reply to this comment
by BSinton December 19, 2008 5:43 PM PST
Another trigger happy American, who would be suitable for employment by a firm called Blackwater.
by DrollTroll December 21, 2008 5:20 PM PST
That missle might land in your neighbor's yard. BTW you never hear about Western nations' geeks hacking into other countries' systems...you think USA, UK, Norway, Denmark, Iceland geeks don't?
by Dalkorian December 22, 2008 9:57 AM PST
by ferretboy88 December 19, 2008 2:32 PM PST
When you find out where the attack is coming from launch a large missile to the guys house.
---------------------------------------------------------------------
You can't help it, can you. You just have to prove to the entire world what an idiot you really are. Pity.
by SenorFrog December 19, 2008 5:38 PM PST
The attacks are coming from our own computers, here in the good old U.S. of A.

http://www.mxlogic.com/securitynews/web-security/usa-number-1-in-malware253.cfm
Reply to this comment
by robvme December 19, 2008 7:52 PM PST
Of course they don't have a solution....its the government.....
Reply to this comment
by CBCyber December 19, 2008 8:50 PM PST
Stop one they send 2, stop100, they send 10,000. Vicious circle comes to mind. This is another example of why the government can not be our protection in all situations.

Myself, I get more frustrated by the piles of money that our government throws at things they can not understand or control. That's almost 1/2 Billion for nothing I believe the article says.
Reply to this comment
by globalist_agenda December 20, 2008 7:33 AM PST
Bald men can't run anything. Chertoff. Paulson. Bernanke. Greenspan. We should only hire men with good hair.
Reply to this comment
(14 Comments)
  • prev
  • next
advertisement

Tech at the Olympics: 'No room to fail'

Q&A The Olympics relies on thousands of servers and PCs to manage all the athletes and scores. Magnus Alvarsson is the guy who must make sure everything works.

How CoverItLive lost it on iPad day

The live-blogging tool fell apart under the strain of a Steve Jobs keynote. Here's what happened, and what comes next for the company.

About Politics and Law

News at the intersection of technology, politics, and law, ranging from intellectual property to censorship to tech policy.

Add this feed to your online news reader

Politics and Law topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right