* A look at “Cyber Security: A Crisis of Prioritization”
Last month, the President’s Information Technology Advisory Committee (PITAC) released its latest report, “Cyber Security: A Crisis of Prioritization.”
The report can be found here (in PDF):
https://www.nitrd.gov/pitac/reports/20050301_cybersecurity/cybersecurity.pdf
The authors include a number of luminaries from academia and industry. In their cover letter to the president, Co-Chairs Marc R. Benioff and Edward D. Lazowska write:
“The IT infrastructure is highly vulnerable to premeditated attacks with potentially catastrophic effects. Thus, it is a prime target for cyber terrorism as well as criminal acts. The IT infrastructure encompasses not only the best-known uses of the public Internet – e-commerce, communication, and Web services – but also the less visible systems and connections of the Nation’s critical infrastructures such as power grids, air traffic control systems, financial systems, and military and intelligence systems. The growing dependence of these critical infrastructures on the IT infrastructure means that the former cannot be secure if the latter is not.”
The major recommendations of PITAC are as follows (quoting directly):
* Increase Federal support for fundamental research in civilian cyber security by $90 million annually at NSF and by substantial amounts at agencies such as DARPA and DHS to support work in 10 high-priority areas identified by PITAC.
* Intensify Federal efforts to promote recruitment and retention of cyber security researchers and students at research universities, with an aim of doubling this profession’s numbers by the end of the decade.
* Provide increased support for the rapid transfer of Federally developed cutting-edge cyber security technologies to the private sector.
* Strengthen the coordination of the Interagency Working Group on Critical Information Infrastructure Protection and integrate it under the Networking and Information Technology Research and Development (NITRD) Program.
Each of these major issues is expanded in the Executive Summary and then explored in detail in the body of the 72-page report. The document includes a useful bibliography with URLs in “Appendix C: Selected Major Reports on Cyber Security Research and Development.” There is also a convenient summary of acronyms in Appendix D.
I urge everyone to take the time to read and think about this important contribution to the national discussion of information assurance policy in the U.S. Network and security managers must play their role in this discussion by bringing their unique experience and perspective to bear on the problems raised in the report. We must not allow legislators and bureaucrats to move forward without careful oversight and involvement by working experts in the field; only by direct participation will we prevent these proposals from being politicized and taken over by special interests who can distort priorities to meet their particular needs without regard for the wider national interest.
Get involved, people.




