Home > Security News > Black Hat 2007: NSA official stumps for information sharing
Security News:
EMAIL THIS

Black Hat 2007: NSA official stumps for information sharing

By Dennis Fisher, Executive Editor
01 Aug 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LAS VEGAS -- Few government organizations have the aura and mystique of the National Security Agency, and it's well-earned.

The NSA is the most secretive of the country's intelligence agencies, and its rare that any of its officials speak publicly. So the speech by Tony Sager that kicked off the Black Hat USA Briefings Wednesday offered a rare peek behind the curtain at Fort Meade's vulnerability information-sharing program.

Sager, the chief of the vulnerability analysis and operations group in the NSA's Information Assurance Directorate, has been in the business of finding and fixing vulnerabilities for 30 years. He said that the major difference between today's security landscape and that of the 1970s is the ability to share data and ideas with a large community of practitioners.

"When I started in 1977, it was a government monopoly business. The government cared about security, the government controlled the technology, knew what the bad guys looked like and could pay for the technology," Sager said. "We could overwhelm the problem with technology.

Special Black Hat coverage

Check out more of SearchSecurity.com's special news coverage of Black Hat USA 2007.
"Those days are gone. Now, we're in the game, we're in the fight. The way we think about the vulnerability problem is as a full-spectrum problem."

Like many security professionals, Sager said he and his team have faced the challenge in recent years of trying to translate important security and vulnerability concepts into plain English for business leaders, technology buyers and end-users. Sager's group spends its time identifying and trying to fix software and network vulnerabilities, but making those efforts understandable to the rest of the organization can be difficult. However, doing so is vital to the success of any security's professional's efforts, Sager said.

For more information

Private sector should learn from government insecurity

Group gives government low marks on data protection

Federal government pushes full-disk encryption

HSPD-12 proving to be a struggle for government agencies
"When I started in this business, you could make a good living poking holes in people's products," he said. "The time has come for us to translate that into actionable intelligence. It changed because we started talking about things like registry settings that operational people care about, and business problems that the leaders cared about."

To that end, the NSA began working with other information security groups in the Department of Defense -- as well as in the government at large -- to develop methods for sharing vulnerability information, reporting and remediation. His group, along with teams from the Department of Homeland Security, the National Institute of Standards and Technology (NIST) and other agencies, developed a model called the Information Security Content Automation Program , which is a method for using open standards and tools to automate vulnerability management and assessment. It includes a number of checklists and a specific protocol for information sharing.

The group also puts on a number of events throughout the year to train security professionals in the use of the program.

Sager urged security practitioners to make the effort to share information with their peers and with their executive teams.

"This is a business that's been about folklore and reading Bugtraq," he said. "We're too big for that now. We can't do that anymore. The key for me has been linking geeky security stuff to other business areas."



Tags: Information Security Laws, Investigations and EthicsSecurity Industry Market Trends, Predictions and ForecastsInformation Security Policies, Procedures and GuidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Information Security Laws, Investigations and Ethics
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity
Federal efforts to secure cyberinfrastrucure

Security Industry Market Trends, Predictions and Forecasts
Cybersecurity czar candidate questions clout of new position
Gartner sees better days ahead for security budgets
Sophos CEO on Symantec, McAfee after Utimaco acquisition
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Security budgets take hit in media, tech industry, survey finds
Cybersecurity Act of 2009: Power grab, or necessary step?
Opinion: Gartner gets NAC wrong, again
Cloud computing security group releases report outlining trouble areas
White House cybersecurity advisor calls for public-private cooperation
Security Industry Market Trends, Predictions and Forecasts Research

Information Security Policies, Procedures and Guidelines
Twitter risks, Facebook threats trouble security pros
Cybersecurity czar candidate questions clout of new position
Incident response planning
The basics of enterprise GRC project management
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
DHS fills National Cybersecurity Center post
New partnerships, creative thinking help security bust recession
Experts optimistic of Obama cybersecurity plan

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
cypherpunk  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts