Posts Tagged ‘DHS’

Surprise!!! The White House Acting Cybersecurity Czar Resigns

Monday, August 3rd, 2009

A not so good announcement today from came from Washington, about the resignation of Melissa Hathaway as Acting Cyberczar. This certainly isn’t a surprise given the inability for the White House to find a candidate. As reported a few weeks ago on Forbes.com the Whitehouse has had some difficulty in recruiting the significant high level Industry executive it’s wanted.

So what does this do for cybersecurity and cybercrime investigation in the U.S.? Nothing, but that is what has been happening for some time now. The direction of the past two administrations has focused in other issues (Bush the War in Iraq and Obama the Economy). Both important distractions but multitasking should the name of the game. The Federal government employs enough people to be able to focus on more than one politicized problem. Simplifying the problem and involve multiple stakeholders in addressing the core issues would be of some help. Unfortunately as an outside observer I’ll I see is a waiting game. Wait until the Czar is appointed and wait until he/she develops a plan, and wait until it is reviewed and wait until we can get the plan funded and wait until congress approves the funding and wait until we can build a bureaucracy to support the project and wait and wait and wait….

Obama may shortly appoint his Cyberczar and we might get some progress on cybercrime but, we also may have to wait awhile.

Threat of Cyber Crime Continues to Increase

Friday, February 13th, 2009

Jim Kouri, formerly the Chief of Police of the New York City housing project in Washington Heights, wrote recently in MensNewsDaily.com about Cyber Crime and its increasing popularity as a criminal endeavor. He rightfully identified that there is a difference between critical infrastructure protection (Cyber security threats) and Cyber crimes (traditional crimes committed through the use of technology). This is far too often overlooked at the national level and appropriate consideration given to both areas. Threats to our critical infrastructure are not the same as Cyber criminals stealing from our citizens. However, from the initial look at a crime, say a “Phishing” scam against a bank, a law enforcement investigator does not know if this criminal act is a foreign state attacking our economic system by trying to make the bank fail, or a teenager from one of the old eastern block countries simply scamming unsuspecting customers out of their funds.

Law enforcement from the outset often ignores these crimes due to the investigative complexity of the crime and the lack of training and tools to effective pursue the evidence. The current economic situation is making things even worse for those agency’s who do attempt to address Internet based crime. In California High Tech Crime Task Forces are being shut down due to the budget crisis. The Northern California Computer Crime Task Force has shut down and the San Diego area CATCH Team will shut down on February 16th. Both of these task forces have made a significant impact on criminals using the Internet to commit crimes. Yet, we are allowing them to close and very little is being done to stop it.

The new administration is due to announce the appointment of its new Cyber Czar. I don’t have a hope for the near future with the President saying one thing before his inauguration:

“As president, I’ll make cyber security the top priority that it should be in the 21st century,” … “I’ll declare our cyber-infrastructure a strategic asset and appoint a National Cyber Adviser who will report directly to me.” (from a speech at Purdue University last July)

And doing another, which is by most accounts putting the new Cyber Czar post several layers down in the Department of Homeland Security. If it does end up in DHS it will be another function unable to deal with the national problem, because the appointee will have to facilitate conversations with the FBI and other organizations outside of DHS responsible for Cyber crime investigation. In addition the new Cyber Czar would have to fight for funding within his or her own organization.

As with the intelligence collection and review issues, as determined by the 911 commission, Cyber crime is another area not coordinated nationally with the many different stake holders in the arena. The better model would be to have the Cyber Czar in the White House with positive control over budgets and agency actions responding to the problem. The National Intelligence Director’s position is the best model for this issue. The problem is not for a single agency to try and solve but it should be the responsibility of a single entity to coordinate the response nationally. Cyber crime is dealt with at all levels of law enforcement in this country, from the City police investigator looking into Vice crime on Craig’s list to International Child Porn rings investigated by the FBI. Yet with all this crime occurring there is no coordination of cyber criminal intelligence or investigations from the bottom to the top.

Lastly, the person selected as Cyber Czar should have a concept of operational response to both the Infrastructure Protection space as well as the Cyber crime arena. They are two different animals and require different skill sets, but complementary responses. We will have to wait and see if the President’s pick is up to the challenge and given the proper authority and resources required to accomplish the mission.

Technorati Tags: ,,,,,,

Administration to establish major office for cyber matters

Friday, February 6th, 2009

Shortly after taking office President Obama announced that there would be a “Cyber Czar” (my term not his) named “…who would report directly to the president, greatly increase funding for interoperable first responder communications and spend $5 billion in global counterterrorism cooperation…”

They are addressing Cyber threats and Cyber infrastructure so where in the new administration’s proposals is the part where we as a country deal with the problem of Cyber Crime? Well for the first time an emphasis, albeit small is noted in the Homeland Security Agenda that says:

“Develop a Cyber Crime Strategy to Minimize the Opportunities for Criminal Profit: Shut down the mechanisms used to transmit criminal profits by shutting down untraceable Internet payment schemes. Initiate a grant and training program to provide federal, state, and local law enforcement agencies the tools they need to detect and prosecute cyber crime”

This is significant in that it is a change in direction from the previous administration’s plan that did not address the Cyber Crime problem. The Bush plan was focused on Infrastructure protection and did not effectively address the overall issue of Cyber Crime. Although many of the items described in Obama’s plan are similar to recommendations previously made to and by the Bush administration.

I have been arguing for some time that there needs to be a comprehensive national plan to deal with Cyber Crime. There is currently no clear understanding of how much Cyber Crime is being committed in the U.S. To complicate that there is no requirement for U.S Law Enforcement agencies to collect and report (in the FBI Uniform Crime Reporting-UCR system) on any Cyber Crime that is committed against our citizenry. So exactly how do we know the magnitude of the crime committed and where to apply the resources?

A comprehensive national plan needs to include several things:

  • A clear definition of Cyber Crime.
  • A reporting mechanism for law enforcement to identify the amount and nature of the Cyber Crimes committed.
  • National Stake holder input. This is not just a federal problem it involves law enforcement at all levels including the judiciary and each levels issues need to be addressed.
  • Sufficient funding must be provided to clearly address the problem at multiple levels.
  • Tools to deal with Cyber crime investigations MUST be common and available.
  • Encourage the reporting of Cyber Crime to local law enforcement agencies.
  • Develop better communication on Cyber Crime and its investigation between Federal, State and local LE
  • Development of an interoperable international legal framework to assist in the investigation of cyber related crimes.
  • And lastly, we need to make cyber investigations an everyday policing event for law enforcement.

We will have to wait and see what the Obama administration will do with this proposal in the DHS agenda. The need has not gone away with the “Change”, it will only continue to grow.