Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/15/2010
02:06 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

White House Issues Cybersecurity Report

The report notes progress on developing national and international cybersecurity strategies and national cyber incident response plan.




Image Gallery: Who's Who In U.S. Intelligence
(click for larger image and for full photo gallery)
The White House on Wednesday issued an update of the Obama administration's ongoing cybersecurity work, detailing some of the steps being taken in an effort to secure the nation's networks against cyber attacks and in the process offering some new insight into the administration's future plans.

The progress report, issued immediately after a meeting held by White House cybersecurity coordinator Howard Schmidt with agency secretaries, cybersecurity experts, and industry, notes that the cybersecurity directorate of the White House national security staff is currently in the midst of developing an updated national cybersecurity strategy based on the 12-piece Comprehensive National Cybersecurity Initiative.

The United States is also working to build a framework for international cybersecurity policy as part of the U.N. Group of Governmental Experts on cybersecurity. This work, the progress report says, has included bilateral discussions and other dialogue with partners.

In September, the progress report says, the Department of Homeland Security will finalize the National Cyber Incident Response Plan and carry out its first tests of the plan as part of Cyber Storm III, a cybersecurity simulation exercise.

In addition, the administration is also working to apply a formal three-pronged cybersecurity research and development strategy to develop budget initiatives that will be disclosed sometime this fall.

Among the accomplishments to which the White House points include releasing new guidance for government agency compliance with the Federal Information Security Management Act, designating a privacy and civil liberties official to the White House cybersecurtity staff, developing a cybersecurity awareness and education campaign, creating a military Cyber Command, and developing a draft identity management strategy.

The progress report also notes some specific progress being made on the Comprehensive National Cybersecurity Initiative. For example, two DHS-led cybersecurity efforts, Trusted Internet Connections and Einstein, are now being used at 12 major agencies and new cybersecurity operations centers are online. As part of the Comprehensive National Cybersecurity Initiative, the progress report notes, the national counterintelligence executive is working to implement a new cyber counterintelligence plan.

Finally, the report also points to public-private collaboration on cybersecurity, noting that, for example, the Department of Homeland Security annually conducts 50 cybersecurity assessments of critical infrastructure, and has begun conducting cybersecurity assessments for certain major events, such as this year's Super Bowl.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
Capital One Breach: What Security Teams Can Do Now
Dr. Richard Gold, Head of Security Engineering at Digital Shadows,  8/23/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.
CVE-2019-12400
PUBLISHED: 2019-08-23
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this im...
CVE-2019-15092
PUBLISHED: 2019-08-23
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.