Tuesday, February 10, 2015

Coordinating Cyber Security

In today's Politico, there is a story of woe for Congress which has to approve a lengthy and detailed budget.  In this case [ Lawmakers not briefed on White House cyber center http://www.politico.com/story/2015/02/white-house-cyber-center-lawmakers-115078.html#ixzz3RNYPxA00 ]  there is another "coordination center" being built for a Federal Agency when there are already many of them doing next to nothing to coordinate anything.  Every major agency already has a cyber center [ DHS has at least 2 ] that is supposed to coordinate threats and report incidents.  None of them do much of any value to organizations that detect and report to them.  The Feds would be better served to put the same resources into scanning, investigation and incident handling that works against attacks.  These are technical bodies that can do forensics and trace long-haul communications through their endless paths to government computers.  We don't need coordination centers.  

When we used to do analysis and event management, some of these agencies thought we were intruding on their missions.  One in particular did everything it could to have our operations shut down. They didnt do forensics, incident analysis, correlations, or anything of value, but they didn't want anyone else doing it either.  This is the way of coordination centers.  They coordinate but don't do much of anything of value to anyone.  It becomes obvious when someone else does.  

Before we fund any coordinatiion centers we should have a rule established which forces the agency establishing a new one to reduce their forces by the same number of people going into the new one.  The Defense Information Systems Agency (DISA) had a center where I worked, and managed to tear it apart and scatter it out over the rest of the agency.  Ten years later, I was in a high level Defense Department meeting where they asked for the exact number of people we had before they broke it up, and they wanted to do the same functions.  When I asked them what they did with the people who were in the center before, they looked completely surprised.  They didn't remember that they had the people and the organization before they broke it up.  The Assistant Secretary running the meeting said they would have to look at the request further before making a decision.  I doubt that it even slowed progress on establishment of another center.  

No comments:

Post a Comment