April 01, 2004

Cybersecurity group: Everyone has a role to play

Group says there is no silver bullet fix to cybersecurity problems

No one "silver bullet" will solve cybersecurity problems, but everyone from home computer users to cybersecurity vendors are responsible for keeping the Internet secure, said representatives of a new cybersecurity educational group.

A group of cybersecurity vendors, consumer groups, trade associations and e-commerce companies launched Americans for a Secure Internet (ASI) in Washington, D.C., Thursday, with members calling for all Internet users to educate themselves on cybersecurity issues. ASI, whose members include eBay Inc., Internet Security Systems Inc. and the Computing Technology Industry Association (CompTIA), launched a Web site intended to educate users of all levels on cybersecurity issues: http://www.protectingthenet.com/.

ASI called on a number of groups to take action on cybersecurity. Cybersecurity problems that need to be addressed range from Internet user behavior and habits to computer and networking hardware, members said. "We have been playing a kind of technology blame game here in town, or searching for a silver bullet," said Tom Santaniello, manager of U.S. public policy for CompTIA. "The mindset up until now is we can purchase an IT security solution off the shelf."

The efforts of ASI and other cybersecurity groups may keep the U.S. Congress from passing cybersecurity mandates, added Bob Dix, staff director for the technology and information policy subcommittee of the House Government Reform Committee. In late 2003, Representative Adam Putnam, a Florida Republican and the subcommittee's chairman, floated draft legislation that would have required companies to report their cybersecurity efforts to the U.S. Securities and Exchange Commission, but the proposal was shelved after criticism from IT vendors and other companies.

But the threat of the bill, plus efforts from industry groups like ASI, have increased the awareness of cybersecurity among private companies, Dix said during an ASI kick-off lunch. Although the Putnam legislation may never been introduced, the subcommittee will continue to push private companies to deal with cybersecurity issues, Dix said. One such method is for government agencies to push for secure products during the procurement process, he said.

"We looked at procurement practices, and we got a little push-back on that," Dix said. "Some of the people in the vending community feel that the government shouldn't inject itself in procurement, but I'd argue this: The federal government spends US$60 billion a year in IT goods and services. The opportunity to say in the marketplace, 'we want higher quality, more secure products than what we buy', seems to be a reasonable position for a purchaser to take."

ASI's first steps will be to bring together all kinds of IT and consumer groups to start talking about cybersecurity, said Mark Blafkin, director of communications for the Association for Competitive Technology. "Right now, it's about ways to facilitate these diverse interests to come together to talk about cybersecurity," Blafkin said. "We're trying to create the broadest coalition possible."

Unlike some other groups dedicated to cybersecurity, ASI will focus on Internet user issues as well as enterprise issues, Blafkin said. Consumer Alert is among the 11 original members of ASI.

The focus on educating individual users is important, said Jim Dempsey, executive director of the Center for Democracy and Technology. Problems like spam e-mail and spyware in software erode the trust users place in the Internet, he said.

Dempsey also praised ASI speakers for discounting the one quick fix approach to cybersecurity. "This is the first event that I've been to where the lead-in line was people saying, 'there is not a silver bullet'," Dempsey said. "How many one-pagers, or 250-pagers have we read that purported to offer a silver bullet to a problem? Here is a group of companies and trade associations that have come forward and said, 'it's more complicated than it looks'."

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.