2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

download 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

of 31

Transcript of 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    1/31

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    2/31

    Whosin

    Charge

    Howard

    Schmidt

    Problemsand

    Solu9ons

    TrueandFalse

    Potpourri

    100 100 100 100 100

    202 202 202 202 202

    303 303 303 303 303

    406 406 406 406 406

    509 509 509 509 509

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    3/31

    In2004,Congressestablished

    thena@onalCyberSecurity

    Divisioninthisfederal

    department

    DepartmentofHomelandSecurity

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    4/31

    In2000,theUS.Governmentestablishedthisen@tyfocused

    onna@onalcyberdefense,locateatFt.Meade,MD.

    CyberCommand

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    5/31

    Presiden@alDirec@ve63,promulgatedin1998,created

    thesesector-specificprivate

    sectoren@@estoincrease

    coordina@onaboutcyberthreats

    andvulnerabili@es

    Informa9onSharingandAnalysisCenters(ISACs)

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    6/31

    Attheconclusionofthe111thCongressthiswasthenumberof

    CongressionalCommiOeesclaimingjurisdic@onovercyber

    security.

    4

    8

    12

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    7/31

    InhisWhiteHousemee@ngwithpublicandprivatepartnersoncybersecurity

    inJuly2010,Presidentbamacitedthis

    factasthereasonthatregula@ngtoachievecybersecuritywasunlikelyto

    beeffec@ve.

    LackofCongressionalawarenessoftheproblem TheinterconnectednatureoftheInternet LackofTechnicalsolu@ons

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    8/31

    Priortoworkinginthebama

    WhiteHouse,heheldasimilar

    posi@onforthis43rdPresident.

    GeorgeW.Bush

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    9/31

    Priortotakinghiscurrentposi@onattheWhiteHousehe

    wasCISandChiefSecurity

    Strategistforthismajoron-line

    shoppingsite---whatsyourbid?

    ebay

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    10/31

    Contrarytopressreportshisofficial@tleisCyberCoordinator.

    Hehasneverheldthis@tle---and

    hedoesnthaveadaughter

    namedAnastasia.

    CyberCzar

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    11/31

    neofhisfirstactsasPresidentbamascyberadvisorwastodeclassifymuchofthecontent

    includedinthismajorcyberprogramlaunchedattheendofPresidentBushssecondterm.

    ComprehensiveNa9onalCyberSecurityIni9a9ve(CNCI)

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    12/31

    AsamemberoftheExecu@vebranchofgovernment,this

    cons@tu@onaldoctrineprevents

    Congressfromrequiringhimto

    appearbeforeit.

    Separa9onofPowers

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    13/31

    AccordingtoresearchfromPricewaterhouseCoopers,this

    methodofaOack---nothackingfromtheoutside---isthemost

    frequentformofcyberaOack---justlikeWikiLeaks.

    InsiderThreats

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    14/31

    AccordingtoSymantec,we

    havenowmovedintothe

    posteraofthisPhormof

    PhrequentcyberaOacks

    Phishing

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    15/31

    AccordingtoresearchbytheU.S.SecretServiceandVerizon,this

    percentageofcyberaOackscouldbe

    successfullypreventedormi@gated

    simplybyusingexis@ngstandards

    andprac@ces. 50 65 94

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    16/31

    Accordingtoa2009studybyCSIS,thisisthenumberone

    reasoncompaniesarenotdeployingmorecybersecurity

    solu@ons. Lackofawarenessoftheproblem

    Lackofeffec@vesolu@ons Cost

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    17/31

    Theonlythemarketincen@velisted

    herethatwasNTspecifically

    recommendedbyPresidentbamas

    CyberspacePolicyReviewfordeploymenttotheprivatesectorto

    improvecybersecurity

    Procurementincen@vesInsuranceincen@vesTaxincen@vesLiabilityincen@ves

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    18/31

    In2006and2007theRussianmilitarylaunchedcyberaOacks

    againstthegovernmentsofEstoniaandGeorgia

    FALSE

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    19/31

    AccordingtoPWCandCSIS,between2008and2010,

    approximately50%to66%of

    Americancompaniesdeferredorreducedtheirinvestmentsin

    informa@onsecurity

    TRUE

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    20/31

    Virtuallyeveryelectronicinforma@onsystemusedbyour

    federalgovernmenthas,atsomepoint,beenmanufactured

    orassembledoutsidetheUS

    TRUE

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    21/31

    AccordingtoMandiantSecretServices,Themostrevealing

    differencewhenyoucombattheAPTisyourpreven@onefforts

    willeventuallyfail.

    TRUE

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    22/31

    User-friendlycyberaOacktoolscanbepurchasedeasilyover

    theInternetforlessthattheaverageCongressionalstaffers

    bi-monthlypaycheck.TRUE

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    23/31

    AccordingtoSymantec,thepercentageofnewcyberthreatsincreasedbythis

    percentagebetween2007and2009.

    100% 500% 1000%

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    24/31

    AccordingtoCarnegieMellonUniversity,thispercentageof

    privatesectorenterpriseshada

    cross-organiza@onalprivacysecurity

    teamasof2010.

    17% 65% 95%

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    25/31

    TheDHSapprovedsloganfortheirna@onaleduca@onandawarenesscampaigntoincrease

    individualcyberresponsibility.

    Lookbeforeyouleapintocyberspace Stop,thinkconnect nlyyoucanpreventyourcyberIDfrombeingstolen

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    26/31

    Thepercentageofcri@calinfrastructurecurrentlycovered

    byprivateinsuranceincaseofaKatrina-levelcyberincident.

    Lessthan1% 25% 50%

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    27/31

    AccordingtoPricewaterhouseCoopers,

    nearlyhalfofallenterprisesarenow

    deployingsomeformofcloudcompu@ng.

    However,thisisthepercentagethatexpressesliOleornoconfidenceinthe

    abilitytosecuretheirassetsinthecloud.

    20% 62% 90%

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    28/31

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    29/31

    nFeb.8,2011,theChiefUSIrequiredeachfederal

    agencytoevaluatedeployingthisbeforemakinganynew

    investments.

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    30/31

    CLUDCMPUTING

  • 7/31/2019 2011 05 11 ISA Cyber Jeopardy Game Before a Capitol Hill Crowd

    31/31

    Presentedbythe

    InternetSecurityAlliance