Cyber Intelligence Sharing and Protection Act (CISPA) passed in House

From http://www.digitaltrends.com/web/cispa-what-now/:
“What happened in the House

During hours of debate, the House approved 11 amendments to CISPA. You can see the full list here (2 through 12 were approved; 1, 13, and 14 were not). Of these, perhaps the most important amendment is the one proposed by Rep. Bob Goodlatte (R-VA), which limits the way information shared under CISPA to that which is “directly pertaining to” threats, vulnerabilities, or unauthorized access to a system or network. The Goodlatte amendment (pdf) also makes it explicitly clear that information pertaining to the violation of businesses’ Terms of Service do not qualify as “cyber threat intelligence” under CISPA, and thus may not be shared. Continue reading

Books on Risk

Half or more of the business books now published deal with risk. Or, so it seems.

I just got back from Barnes & Noble. As a past author, I check out new hard cover books, which are a window into important business trends.

Maybe, it’s a situation of ‘where you sit is what you see.’ So, I sit in the risk space and all I see is risk. Risk in crossing the street. Risk in buying this or doing that.

But, the new hard cover business books point to a hard realization that risk is the new normal or new reset. And, it’s not going away.

Some implications: All if not most of the business rules are changing. Organizations and people are not ready for the changes. We need new: 1. Risk based, problem solving and 2. Risk based, decision making tools.

Hence, we are getting lots of business trade books explaining what to do to deal with risk.

Cyber ERM

Cyber Security is going ERM.

The US Department of Energy (DOE) released for public comment the Electricity Subsector CyberSecurity Risk Management Process.  You can download it at:

(http://energy.gov/sites/prod/files/RMP%20Guideline%20Second%20Draft%20for%20Public%20Comment%20-%20March%202012.pdf

It may be a game changer in risk frameworks.  Most risk frameworks are linear risk assessment processes.

The DOE standard is ERM process based, inputs  => activities => outputs, hierarchal (tiered), and follows a novel cycle.

Let’s discuss a few of these:

The RM model is tiered: 1. Tier 1: Organization; 2. Tier 2: Mission and Business Processes; and Tier 3: IT and Industrial Control Systems.

The RM model has a cycle of: Frame => Assess => Respond => Monitor.

Each tier follows a process, much like the Project Management Institute Body of Knowledge (PMBOK)

Different RM model.  ERM based.  Interesting.  Novel.  Check it out.

Hackers Eyeing Android Devices/SCADA Systems

Trend Micro predicts that the proliferation of Android devices, smartphones and tablets is making all systems based on Android an attractive target for hackers.

http://www.mobilitytechzone.com/topics/4g-wirelessevolution/articles/244561-hackers-eyeing-android-devices-scada-systems-2012-prediction.htm

The NSA has released a Secure Android Version:

http://www.informationweek.com/news/government/security/232400479

Security Enhanced Android can be found here:  http://selinuxproject.org/page/SEAndroid

Then there is Project Fishbowl, Secure Android on a Secure Network:

http://www.theverge.com/2012/3/2/2838729/nsa-project-fishbowl-secure-android-devices-network

ACTA’s Aviation Cyber Security Day: June 28, 2012

From http://www.atca.org/cybersecurity:

Last year’s debut of ATCA’s Aviation Cyber Security Day was so successful that it’s back again.

ATCA’s 2012 Aviation Cyber Security Day will take place June 28, 2012

Registration details will be posted soon and sponsorship opportunities are already available. Contact Claire.Rusk@atca.org or +1 703 299 2430 x309.

The Cyber Security Committee meets regularly in preparation for the event, and your input and suggested topics are welcome. Discussions will include: cyber threats in the NextGen (http://www.faa.gov/nextgen/) environment, different roles played within the aviation community in the event of a cyber attack, and much more.