Most Popular Stories
- EU official says identity management must be based on multiple biometrics
- Clapper sounds alarm on cyber capabilities of Iran, China and Russia
- FAA reauthorization would create NextGen czar UPDATED
- NARA, agencies revisit millions of pages to ensure proper declassification
- Agencies not sharing enough information, says Karen Evans
- Malware targets smart ID cards, say researchers
- Top FAA execs lack institutional knowledge, says official; agency must be prepared for cuts
- Air traffic control training gaps will be exacerbated by NextGen, says OIG
- Agencies plan for governmentwide FOIA portal
- FDA issues draft social-media marketing guidelines
- Obama administration announces immigrant visa waiver change
Events
- TECHEXPO Top Secret Career Fair
February 29, 2012 — Colorado Springs, CO 10am - 3pm - TECHEXPO Top Secret POLYGRAPH ONLY Hiring Event
February 9, 2012 — Baltimore, MD 10am - 3pm - Learn With Your Peers at the Federal Senior Management Conference
April 15-18 — Cambridge, MD - TECHEXPO Top Secret Career Fair
February 7, 2012 — Arlington, VA 10am - 3pm
Sponsored Links
HOT TOPICS >> Cloud computing | Cybersecurity | Gov 2.0 | Fiscal 2012 | Mobile | Transparency | GAO reports
AGENCY NEWS >> Defense | NASA | Homeland Security | NIST | OMB | Veterans Affairs | NARA | GSA
Latest News
Free Newsletter
About | View Sample | Privacy
Popular Topics
Whitepapers
- Inside the Federal Cloud: Master the Challenges, Seizing the Opportunities
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Business Intelligence: It's All in the Data
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Innovative Solutions for Database and DBA Management
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
Ross: Defense only goes so far, real cybersecurity is agile
Security breaches are inevitable and no agency can be fully secure in its networks, said Ron Ross, senior computer scientist and information security researcher at the National Institute of Standards and Technology.
A more realistic goal is for government information technology to be resistant; agencies should assess how they operate while under attack to minimize damage, he added while speaking June 15 at a Washington, D.C., event called the Government IT Leadership Forum.
Under the preferred strategy of agile defense, agencies should have a plan for recognizing these malware breaches, bringing back the system to a known, secure state, and quickly removing implanted malware before it is on target long enough to do significant damage, said Ross.
Continuous monitoring, while a critical part of cybersecurity, "is not a strategy, it's a tactic," said Ross. Systems will become infected, at which time, said Ross, a static list of compliance requirements will not be helpful. Ross encouraged attendees to think of cybersecurity as a moving and evolving risk management framework.
Overall, Ross says the federal enterprise architecture desperately needs improvement and overhaul has not been a priority. This is working against government IT from a security standpoint, he said. "You need [cybersecurity] to help enable the mission, not hold it back," he said.
Related Articles:
Lieberman wants to give federal government power over Internet cybersecurity
Is the threat of cyber war exaggerated?
Loose networks sink ships
Bulk power system cannot be fully protected
U.S. electrical grid probed but not yet attacked, says paper
Related Stories
- Ross: Agencies should better manage cybersecurity risk
- Spotlight: Wave of NIST cybersecurity guidance on the way
- NIST preps guidance for mitigating insider threats
- Privacy controls to be included in NIST cybersecurity guidance
- NIST promotes common cybersecurity controls
- Critical infrastructure companies drowning in cybersecurity guidance, says GAO
- FedRAMP baseline controls released
- Congress authorizes offensive cyberspace military operations
- NIST details trusted root BIOS verification model
- Audio: Steven VanRoekel announces FedRAMP
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |


