The National Cyber Security Partnership just released the first two of five planned reports concerning various aspects of cybersecurity. The reports are not all that bad, but I have a hard time not dismissing the whole effort as a cynical attempt to avoid facing up to reality.
The National Cyber Security Partnership just released the first two of five planned reports concerning various aspects of cybersecurity. The reports are not all that bad, but I have a hard time not dismissing the whole effort as a cynical attempt to avoid facing up to reality.
The partnership is an outgrowth of the December 2003 National Cyber Security Summit convened in response to last year’s National Strategy to Secure Cyberspace. All the press coverage I have seen about the two new reports says the NCSP was created to forestall governmental regulations in the area of computer and network security. It’s better to volunteer to do something not all that hard than be forced to do something quite painful.
Maybe the “powers that be” will be satisfied, at least for a while, and forget about this particular problem. The first two reports are “Awareness for Home Users and Small Businesses” from the Awareness and Outreach Task Force, and “Cyber Security Early Warning” from the National Early Warning Task Force. Reports from the Technical Standards and Common Criteria Task Force, Security Across the Software Development Lifecycle Task Force and Corporate Governance Task Force are scheduled to be released soon.
The “Awareness for Home Users and Small Businesses” report recommends a bunch of things targeted at educating and helping home Internet users, big and small businesses, schools and governments (other than the federal government). Recommendations include developing a cybersecurity tool kit for home users, and designating September 2004 as “Cyber Security Month” to make CEOs at large companies aware of the cybersecurity problem (assuming, I guess that these CEOs have been in caves for the last few years).
The National Early Warning Task Force report calls for establishing yet another fail-safe national cybersecurity early-warning contact network. The goal of this network would be to “broaden the horizon of shared information regarding cybersecurity vulnerabilities, exploits and incidents, to facilitate the process of information sharing and to provide a facility for the rapid dissemination of critical information, all within the framework of a vetted trust community.” In other words, tell selected people when there is something wrong.
In and of themselves these reports seem to represent some amount of thinking on the problems. They may accomplish the apparent underlying goal of the National Cyber Security Partnership and keep Congress from creating a legal requirement for vendors to pay attention to security (one of the critics of the reports compared such a requirement to the federal mandate for seat belts in cars). Voluntary efforts are fine and often can bring positive results, but there is little that would focus corporate minds better than being told they would be liable for damages their customers suffer because of software failures. There is at least one place that could happen today: If software in a car’s control computer goes wacko and the vehicle crashes I doubt a court would accept a shrink-wrap license liability disclaimer. But apparently applying the same rules to computer operating systems would be too logical.
Disclaimer: Come to think of it, I expect Harvard wouldn’t want the same rules to be applied to educating students, but I didn’t ask, and the above ramble is mine alone.




