Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

National Cyber Security Day is a well-kept secret

Event drew little attention

By Paul Roberts, IDG News Service
April 05, 2004
 

U.S. residents adjusting to the daylight savings time change will have to be forgiven for sleeping through much of National Cyber Security Day on Sunday. The semi-annual event passed with nary a mention, even as antivirus software companies warned customers of yet another virulent e-mail worm.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

A spokesman for the National Cyber Security Alliance, a government-industry group that sponsors the event said the group is doing a good job of communicating with the public. However, the lack of fanfare on Sunday had at least one computer security expert wondering about the effectiveness of industry-led efforts to address cybersecurity and improve the security of the U.S.'s information technology infrastructure.

First held in 2002, the semi-annual National Cyber Security Days are coordinated with daylight savings in April and October in the U.S. and are intended to raise the public's awareness of cybersecurity issues and promote safe online practices, said Keith Nahigian, a spokesman for the alliance.

In the past, the group has planned major news and events to coincide with its Cyber Security Days. In October, the Alliance held a press conference to announce the award of a US$650,000 matching grant from the U.S. Department of Homeland Security (DHS) to fund a national advertising campaign promoting safe computing for Internet users and small business owners, Nahigian said.

However, no major news or initiatives were planned for Sunday, when the Alliance's "big deliverable" was an updated list of "security tips" for computer users, which was published on the www.staysafeonline.info Web page, Nahigian said.

That list, which offers oft-heard advice such as "don't open e-mail from unknown sources," "use (antivirus) software," and "back up your computer data" required multiple revisions and took "a lot of time" to complete, Nahigian said.

The group also released public service announcements for radio and worked with universities, including Rutgers in New Jersey and George Mason University in Virginia, to hold security education and awareness events, he said.

Asked about the school's involvement with Cyber Security Day, a spokeswoman for George Mason University cited an article dated March 26 from the school's student newspaper that said the school would hold a series of seminars on subjects like "Desktop Strategies to Secure Your Cyber Space" and "Filesharing: Music, Movies, Software--How to Avoid Being Subpoenaed," in coordination with National Cyber Security Day.

For the most part, the job of marking Cyber Security Day fell to alliance members such as Symantec Corp., America Online Inc. (AOL) and the U.S. Federal Trade Commission (FTC), Nahigian said.

"Individual (member) companies are doing stuff," he said, citing announcements from Symantec and AOL.

The FTC released a statement with the alliance and the Council of Better Business Bureaus on April 2, encouraging small businesses to perform semiannual security audits and providing its own security checklist, which was almost identical to the alliance's list.

A Symantec spokeswoman said that the company didn't do any promotions for Cyber Security Day. AOL did not respond to a request for comment.

The alliance press release, dated April 1, includes quotes praising the alliance and Cyber Security Day from FTC Commissioner Orson Swindle and Amit Yoran, DHS's National Cyber Security Division director. However, the statement is short on new information. Instead, it rehashes well-worn programs such as the FTC's September 2002 educational initiative featuring "Dewie" the turtle, AOL's educational instant messaging robot "AOLSafetyBot" and Symantec's free "Symantec Security Check," when describing "sponsor activities" for the latest National Cyber Security Day.

Cyber Security Day in April may have been the victim of intense planning for the next Cyber Security Day, in October, Nahigian said.

The group is planning something "very large" for that day that will include corporate and government involvement. "We're really reaching out to the Hill," he said, referring to Capitol Hill.

The low-key observance of Cyber Security Day in April belies an "overwhelming" amount of work behind the scenes on alliance task forces to device cybersecurity strategies, he said.

"Members of the alliance have been working across the board," he said.

However, one cybersecurity veteran and an alliance member said he wasn't even aware of the approaching Cyber Security Day and has doubts about the group's effectiveness.

"I didn't even know. I'm embarrassed," said Alan Paller, research director of the SANS Institute when asked about the event on Monday.

"It is so ineffective at anything other than having meetings. ... It's hard to even guess what's going on," Paller said.

Projects like the www.staysafeonline.info Web site are a good idea, but add little to the work already being done by agencies like the FTC, Paller said. Paller also doubts whether improving user awareness -- the ostensible purpose of the alliance -- will make a difference while software security vulnerabilities persist.

"The software (alliance members) sell is so completely flawed (that) user education is useless," he said.





 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




Application Grid: Oracle's Vision for Next-Generation Application Servers and Infrastructure
View this live Webcast to hear senior Oracle executives Hasan Rizvi and Steve Harris discuss the application grid. Learn how Oracle is combining cutting-edge technologies from its recent acquisition of BEA with the Fusion Middleware portfolio. Discover a new level of reliability, performance, and "scale-agility" in your data center, with emphasis on efficiency for today’s challenging economic environment. Sponsored by Oracle

» 
  The Path to Enterprise Security
This is your comprehensive guide to Enterprise Security. In it you'll find solutions to the most pressing security threats facing you and your company. Learn the latest on insider threats and how to effectively minimize risk within your organization. Sponsored by Nokia

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist