
White House cybersecurity order aims to defend against critical hack
0Posted on 27th Feb 2013 by Ray Wizbowski
Cybersecurity rarely receives much attention in the US political arena, when it should be a top priority. After all, it’s inextricably linked to the strength of our national security so it was great to hear President Obama emphasize the importance of cybersecurity in his State of the Union address last week.
The President has signed an executive order aimed at motivating the private sector to work alongside the federal government, collaborating on the best way to share data, and develop a new framework of practices to better protect our nation’s critical infrastructure from hackers and cyberthreats.
What do we mean when we say “critical infrastructure”? Think electrical grids, banking networks, water treatment facilities, communication systems, transportation and public health systems – all of the systems and assets we need to keep our society going. If accessed by a hacker or terrorist, a threat to any of these assets would have a debilitating impact on our national security. This order aims to strengthen the defense of our critical infrastructure.
If you’re still wondering what exactly the White House has in mind for the framework, I found some clarification in a blog post from Michael Daniel, special assistant to the President and cybersecurity coordinator:
“The framework does not dictate “one-size fits all” technological solutions. Instead, it promotes a collaborative approach to encourage innovation and recognize the differing needs among critical infrastructure sectors. Organizations who want to upgrade their cybersecurity will have the flexibility to decide how best to do so using a wide range of innovative products and services available in the marketplace.”
This makes sense. In essence, the framework seeks to offer critical infrastructure providers all the tools they may require to protect themselves, while giving them freedom to implement it in a way that works best for them. Vital to every system, though, will be building strong authentication into the framework for access systems – physical and logical – so that we can be sure that those accessing buildings or networks and data have the clearance to do so.
The good news is, such technology is already available to make this happen. The same technology used today by government agencies for physical and logical access, Personal Identification Verification (PIV) credentials, is available for critical infrastructure providers in the form of the PIV-Interoperable (PIV-I) credential, and to commercial organizations in the form of the Commercial Identity Verification (CIV) credential. These credentials are standards-based, trusted, and proven to provide the highest levels of security, and certainly deserve a spot in the framework.
The National Institute of Standards and Technology (NIST) must now work with the industry on best practice and identifying areas of existing consensus. If we pay enough attention to protecting our critical infrastructure now, we can avoid a critical situation should our systems come under attack.
Contact: Ray Wizbowski
-
Tags
Apple authentication biometric BYOD CES 2012 CIO cloud convenience cybercrime data data breach digital digital security eBanking EMV enterprise Facebook FFIEC fraud Gaming Gemalto Google hack hacker hackers hacking identity internet IT security LinkedIn malware Microsoft mobile multi-factor authentication NFC one-time password online banking OTP password passwords PIN policy research risk security smartphone strong authentication token Twitter two-factor authentication
-
Around the site
Recent Posts- mCommerce: or pay the price - 22/05/13 @ 02:10
- Collaborating to drive mobile commerce in the Middle East - 22/05/13 @ 07:50
- The future is mobile – The Gemalto Netsize Guide is here - 21/05/13 @ 10:52
- CTIA 2013: The Way to Wireless - 20/05/13 @ 12:56
- Wallet Wars – Coming to a Mobile Near You Soon - 20/05/13 @ 09:19
Recent Comments- These tips are brilliant, thanks for sharing this i... - 20/05/13 @ 02:42
- I agree with digital ID certification. As a police... - 08/05/13 @ 07:43
- Can't wait for the driverless car. Wouldn't want to... - 29/04/13 @ 06:25
- Yes Reena, I fully understand your worries. Regardi... - 16/03/13 @ 12:11
- Thank you Monika for bringing to light a very impor... - 15/03/13 @ 09:52
-
Twitter
-
Blogroll
- Amrit Williams Blog
- HIT Consultant
- Independent Identity
- Joey Muniz – The Security Blogger
- Kantara Initiative
- Kim Cameron's Identity Blog
- Krebs on Security
- Life as a Healthcare CIO
- Michael N. Dundas
- Naked Security
- Network Security Blog
- SC Magazine Security Cats
- Schneier on Security
- Security Nirvana
- Social Tech Editor™
- TechMarket Editor™
- Virginia Benedict, Managing Curator, Network Monitoring & Incident Response™ SIG
