Technology Sectors

Market Sectors

U.S. Cyber Security Coordinator Howard Schmidt announces declassification of CNCI initiatives

Howard Schmidt at RSA

In his keynote speech at the RSA 2010 Conference, U.S. Cybersecurity Coordinator Howard Schmidt reminded the audience of President Obama’s memo to all federal departments and agencies, which says, “My administration is committed to creating an unprecedented openness in government.”

Schmidt went on to say, “I’m pleased to announce that the Administration has updated the classified guidance for the Comprehensive National Cybersecurity Initiative, or CNCI, which began in 2008 and forms an important component of the efforts within the national government. As of noontime today, in about 15 minutes, you’ll be able to go to whitehouse.gov/cybersecurity and download the unclassified description of CNCI in each of the 12 efforts under CNCI.”

With this declassification, Schmidt stated, “The American people can partner with government.” But, to be successful in protecting the nation’s cyber-security, he added, “We must continue to seek out new and innovative partnerships involving government, industry, academia and the public at large.”

Schmidt’s presentation described some of the steps that led to the administration’s present policies. In May 2009, he recalled, the President declared that cyber-threats are one of the most serious threats we face as a nation, and America’s economic security will depend on cyber-security. Schmidt then described the progress that has been made in the near-term recommendations of the cyber policy review, which Obama had commissioned.

  • The first recommendation, said Schmidt, was that a senior policy adviser be appointed, “and here I am.”
  • The second was to update strategy, which is an ongoing effort. “We still have vulnerabilities, we still have resiliencies, we still have issues,” he said, “but we need to look at it in today’s terminology so that we can adapt.”
  • The third was to bring the private sector into the discussion, to maintain the richness and robustness of our efforts. There’s been a lot of discussion about FISMA [the Federal Information Security Management Act], he said, which argued that you can be FISMA-compliant and still not be secure. “And we agree with that,” Schmidt added. “Work needs to be done. And that is why we have developed real-time metrics with continuous monitoring that provides real-time situational awareness.”
  • Fourth, designate a privacy and civil liberties professional. This has been done, Schmidt said, and the person is already on board.
  • Fifth, government inter-agency legal analysis. There are about 40 legal questions that need to be addressed, said Schmidt, and this will require ongoing legal analyses.
  • Sixth, how do we create a national and international awareness campaign to promote cyber-security? This is a question that has been divided into four tracks: (1) national awareness, which is being handled by the Department of Homeland Security; (2) cyber-security education, which is being handled by the Department of Education; (3) the Federal Infrastructure Workforce, which is now being handled by the Office of Personnel Management and the Department of Defense; and (4) national workforce training, which is being handled by the Department of Homeland Security, the Department of Defense and the Director of National Intelligence.
  • Seventh, the International Cybersecurity Program. A policy framework need to be established, said Schmidt, but without impeding the private sector’s research and development efforts.
  • Eighth, the Cyber Security Instant Response. There should never be a question, said Schmidt, where the private sector should go during a cyber incident.
  • Ninth, the development framework for research and development. Schmidt indicated there is a lot of research to be done, and the Office of Science and Technology is working on questions such as, “How do you deal with the moving target defense.”
  • Tenth, cyber-security identity management strategy, with particular emphasis on a secure online transaction capability. It must be interoperable, said Schmidt, and it must not try to make one size fit all.

Transparency and partnerships, Schmidt reiterated throughout his presentation, must go hand-in-hand. The government and industry must work together with the American people to develop a harmonized and systematized cyber-security policy that is effective and efficient.

 

Recent Videos

It's been a banner year for the Whitestone Group, according to John Clark, CEO of the facility security, asset/force protection and investigations...
Jeff Horne explains that Denver, CO-based Accuvant , Inc has two different businesses – the Value Added Reseller (VAR) side, in which it is one of...
GSN caught up with Dave Natelson for a quick interview at the Cocktail Reception at the 2011 Awards Dinner, before he learned that Nasatka had earned...
Ann Pickren discusses MIR3’s Mass Notification System that was awarded a Winner’s Trophy in GSN’s 2011 Homeland Security Awards Program. She explains...
Former Coast Guard Commandant Thad Allen, who served through a long and distinguished career in the United States Coast Guard and later answered the...

Upcoming Events

Event Details Dates of Event
SANS Monterey 2012 Jan 30 - Feb 4
2012 Adobe Government Assembly Feb 8
SANS Phoenix 2012 Feb 13 - 18
SANS Secure India 2012 Feb 20 - 25
The Airport Law Enforcement Symposium Feb 23-24, 2012 Feb 23 - 24
Physical Security: Introductory Applications and Technology Feb 27 - Mar 1
Conducting Corporate Investigations Feb 27 - 28
ISC CHINA 2012 (International Security Conference & Exposition CHINA) Feb 27 - 29
RSA Conference 2012 Feb 27 - Mar 2
SAP Public Sector Partner Exchange Feb 28 - 28
SANS Secure Singapore 2012 Mar 5 - 17
SANS Germany 2012 Mar 5 - 10
Homeland Security Finance Forum 2012 Mar 6 - 6
Basic Hands-On CAMEO Training Mar 12 - 14
ASIS Assets Protection Course: Principles of Security (APC I) Mar 12 - 15
SANS Mobile Device Security Summit 2012 Mar 12 - 15
Aviation Week's Innovation Challenge Showcase Mar 13 - 14
Symantec Government Technology Summit Mar 20 - 20
STI at SANS 2012 Mar 23 - 30
SANS 2012 Mar 23 - 30
The 9th Two Day Conference On Indian Medical Devices & Plastics Disposables Industry 2012 Mar 23 - 24
SANS Northern Virginia 2012 Apr 15 - 20
Active Shooter Apr 18 - 19
SANS AppSec 2012 Apr 24 - May 2
SANS Cyber Guardian 2012 Apr 30 - May 7
Telework Exchange Spring 2012 Town Hall Meeting May 2 - 2
5th Sample Prep - Sample Preparation for Virus, Toxin, & Pathogen Detection & Identification May 3 - 4
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
Counter Terror Expo US May 16 - 17
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
SANS Rocky Mountain 2012 Jun 4 - 9
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10