- Recommend:
- 0 Comments
Senator Pushes for Stronger Cybersecurity
Two proposed bills would increase security on government computers and train more security specialists.
Citing the Code Red worm and an attack on U.S. Department of Defense computers, Senator John Edwards (D-North Carolina) Monday introduced two new cybersecurity bills seeking to increase both government computer security and general education in the field.
If passed, the Cybersecurity Preparedness Act of 2002 would establish a nonprofit consortium of academic and private sector computer security experts who would create and help spread a set of "best practices" that could be used to enhance cybersecurity. The bill would require that set of best practices first be applied to government computers.
Under the measure, a study would be undertaken to determine how to obtain acceptance of those best practices in the private sector. One possibility in the proposed legislation requires federal grantees and contractors who accept government funding to use those best practices.
Time for Training
The second bill, the Cybersecurity Research and Education Act of 2002, aims to train more specialists in computer security. The bill would fund new Information Assurance Fellowships designed to attract doctoral students to cybersecurity, as well as creating a Distinguished Faculty Sabbatical Program allowing top researchers to visit other research facilities and work on new projects. The bill would also create an online university for cybersecurity training.
The Cybersecurity Preparedness Act is "different from any other law I've seen because it makes explicit the single most difficult task--figuring out what makes systems safe," says Alan Paller, director of systems administration at the SANS Institute, an organization for systems administrators.
Part of figuring this out, Paller says, will be testing the best practices recommendations, something he says the bill requires. Other best practices lists exist, but "people don't implement [the lists] because [they] break things," or cause problems, he says. Since the list will be tested to see if it causes problems, that will be another step that systems administrators won't have to worry about it, he adds.
This legislation "takes the fear out" of implementing best practices list, he says.
Money Talks
The research and education bill is also important, he says, because there aren't enough people being educated in the field, as it is seen boring by many. Adding financial backing to cybersecurity studies will likely make people take notice, he says.
"The way you make something not pedestrian is to put money behind it," he says.
Though he thinks there is enough in the first bill "to get 70 percent to 80 percent of what we want done" regarding cybersecurity, the measure is not perfect.
Although it requires testing the best practices list, it does not require the adoption of the practices outside of government computers. This discrepancy is "the long-term problem" with the proposed legislation, Paller says.
Despite this problem, Paller expects that having such a law in place would help create more secure software. Because government agencies will be able to require that vendors they do business with comply with the best practices in their products, the level of security in many software products will likely rise, leading to greater overall security, he says.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- ISP Data-Retention Bill Rankles Privacy Advocates
- Senate Bill May Require 'critical' Networks to Adopt Cyber Standards
- Kerry-McCain Privacy Bill: What You Need to Know
- Cybersecurity Bill Would Create Costly Regulations, Say Critics
- Hackers Said to be Planning to Launch Own Satellites to Combat Censorship
- McAfee Warns of Massive 5-Year Hacking Plot
- PC Tune-Up
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.
















