Home > Security News > Black Hat 2007: NSA official stumps for information sharing
Security News:
EMAIL THIS

Black Hat 2007: NSA official stumps for information sharing

By Dennis Fisher, Executive Editor
01 Aug 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LAS VEGAS -- Few government organizations have the aura and mystique of the National Security Agency, and it's well-earned.

The NSA is the most secretive of the country's intelligence agencies, and its rare that any of its officials speak publicly. So the speech by Tony Sager that kicked off the Black Hat USA Briefings Wednesday offered a rare peek behind the curtain at Fort Meade's vulnerability information-sharing program.

Sager, the chief of the vulnerability analysis and operations group in the NSA's Information Assurance Directorate, has been in the business of finding and fixing vulnerabilities for 30 years. He said that the major difference between today's security landscape and that of the 1970s is the ability to share data and ideas with a large community of practitioners.

"When I started in 1977, it was a government monopoly business. The government cared about security, the government controlled the technology, knew what the bad guys looked like and could pay for the technology," Sager said. "We could overwhelm the problem with technology.

Special Black Hat coverage

Check out more of SearchSecurity.com's special news coverage of Black Hat USA 2007.
"Those days are gone. Now, we're in the game, we're in the fight. The way we think about the vulnerability problem is as a full-spectrum problem."

Like many security professionals, Sager said he and his team have faced the challenge in recent years of trying to translate important security and vulnerability concepts into plain English for business leaders, technology buyers and end-users. Sager's group spends its time identifying and trying to fix software and network vulnerabilities, but making those efforts understandable to the rest of the organization can be difficult. However, doing so is vital to the success of any security's professional's efforts, Sager said.

For more information

Private sector should learn from government insecurity

Group gives government low marks on data protection

Federal government pushes full-disk encryption

HSPD-12 proving to be a struggle for government agencies
"When I started in this business, you could make a good living poking holes in people's products," he said. "The time has come for us to translate that into actionable intelligence. It changed because we started talking about things like registry settings that operational people care about, and business problems that the leaders cared about."

To that end, the NSA began working with other information security groups in the Department of Defense -- as well as in the government at large -- to develop methods for sharing vulnerability information, reporting and remediation. His group, along with teams from the Department of Homeland Security, the National Institute of Standards and Technology (NIST) and other agencies, developed a model called the Information Security Content Automation Program , which is a method for using open standards and tools to automate vulnerability management and assessment. It includes a number of checklists and a specific protocol for information sharing.

The group also puts on a number of events throughout the year to train security professionals in the use of the program.

Sager urged security practitioners to make the effort to share information with their peers and with their executive teams.

"This is a business that's been about folklore and reading Bugtraq," he said. "We're too big for that now. We can't do that anymore. The key for me has been linking geeky security stuff to other business areas."



Tags: Information Security Laws, Investigations and EthicsSecurity Industry Market Trends, Predictions and ForecastsInformation Security Policies, Procedures and GuidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Security Industry Market Trends, Predictions and Forecasts
Healthcare security spending remains sluggish, report shows
How to use Internet security threat reports
M86 buys Web security gateway vendor Finjan
Information Security Decisions 2009: Presentation downloads
Bruce Schneier on outsourcing, awareness training
Marcus Ranum on cyberwarfare, infosec careers
McAfee survey finds faults in midmarket enterprise security
Email archiving vendor sues Gartner over Magic Quadrant
Information Security magazine October issue PDF
Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
Security Industry Market Trends, Predictions and Forecasts Research

Information Security Policies, Procedures and Guidelines
Essential guide: Pandemic planning for H1N1
Whitelists, SaaS modify traditional security, tackle flaws
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Reuters: Obama ready to select cyber security czar
How a corporate Twitter policy can combat social network threats
Should enterprises be concerned with Twitter in the workplace?
Information security management hype: Debunking best practices
Data breach avoidance begins with security basics, panel says
Expert: Information security spending often restricts innovation
GAO report cites government weaknesses, data leakage

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts