Agencies Join in Security Plan

Friday, November 9, 2012 @ 09:11 AM gHale


A new program is starting up to implement automated monitoring of a set of critical security controls in government IT security this year, to provide a standardized cyber security baseline for agencies.

The effort, launched by the Department of Homeland Security (DHS), will include a set of technical specifications developed in cooperation with industry that would enable the automation of the controls in off-the-shelf products. There also would be a governmentwide dashboard to provide visibility into each agency’s status on the controls and help establish priorities for improvement during the current fiscal year.

RELATED STORIES
Ensuring Software Security Policies
Trojan that Supports Windows 8
Tracking Software Settlement
Pushdo Trojan a Master of Disguise

DHS unveiled the plans in conjunction with the release Nov. 5 of the latest version of the top 20 Critical Controls for Effective Cyber Defense and the news of a new international organization to oversee development of the consensus controls and promote their use in government and industry.

DHS, along with the National Security Agency, the Defense Department, the Defense Information Systems Agency and the DoD Cyber Crime Center, are among the members of the Consortium for Cybersecurity Action, which will maintain and update the list.

The critical controls, formerly the Consensus Audit Guidelines, are a set of security requirements developed in cooperation by government and private sector experts and published by the Center for Strategic and International Studies (CSIS) and the SANS Institute. Growing adoption of the controls in both government and industry has created the need for a more formal organization to house and maintain them, said former NSA official Tony Sager, who will lead the effort.

“It had to be a little more standardized,” said Sager, who retired as chief operating officer of the NSA’s Information Assurance Directorate in June. “If major organizations are going to make IT policy and spending decisions based on it, they have to know it will be there in two or five years.”

The critical controls are a reflection of the 80/20 rule at work in cyber security: Twenty percent of the effort produces 80 percent of the results. The controls are an effort to identify the 80 percent payoff that can prevent or mitigate the bulk of the attacks against IT systems today. By automating the application and monitoring of these basic security functions, resources and manpower could be free to address remaining more sophisticated challenges that require greater attention.

Development of the critical controls began in 2008 under the auspices of the CSIS in cooperation with other groups including NSA, US-CERT, DoD, Energy Department Nuclear Laboratories and the State Department. Their use at the State Department has gained attention as a way to measure and reduce meaningful vulnerabilities in widespread IT systems. The new consortium will have no power to require use of the control list, and its authority will come from the combined weight of its members.

Such a system does not provide complete security, but advocates said it helps focus security investment in the most needed areas and frees needed resources for more complex threats. By updating the list regularly to reflect changes in the threat landscape, the consortium will try to ensure that priorities remain properly focused.

The DHS program for implementing an initial set of five critical controls has been funded for fiscal 2013, which began Oct. 1. Capabilities will expand to other controls if funding is available. The department expects to issue a request for proposals that would provide a blanket purchase agreement for off-the-shelf automated monitoring tools for the initial set of controls:
• Hardware asset management
• Software asset management
• Configuration management
• Vulnerability management
• Network access control management



Leave a Reply

You must be logged in to post a comment.