Cyber threats are real and abundant and the government is keenly aware it needs to lock in security policies and procedures.
Just look at what is going on. The Senate keeps pushing for legislation to improve information-sharing on threats and attacks. President Barack Obama is looking to issue an executive order on cyber security and the Department of Defense (DoD) is looking for a massive increase in the number of trained cyber security professionals to defend the country’s private and public networks.
Security professionals working on these assignments right now is difficult to narrow down as quite a few work in agencies that don’t discuss their operations. Also, some work in dual-tasked positions and don’t focus on just one assignment. However, officials from the Department of Defense have been pushing for more funding to hire more trained security professionals.
Now, that push seems to be paying dividends. The Pentagon’s goal is to increase the number of security professionals from fewer than 1,000 to 5,000 in the next few years. Those personnel will comprise military and civilian security professionals, and the goal will be to defend the country’s critical infrastructure as well as government and military networks.
This all comes just a few days after Janet Napolitano, secretary of the Department of Homeland Security, warned a nation-level incident of the scale of 9/11 could occur sometime soon as a result of a cyber attack. Napolitano is not the first to warn about the possibility of such an attack, but is rather the latest in a long line of government officials, presidential advisers and security experts to raise that specter. Security researchers also have warned in recent years about serious vulnerabilities in the SCADA and ICS systems that run much of the network infrastructure in utilities, financial systems and other critical areas.
In October, DHS officials warned SCADA system operators about an increase in the level of malicious activity targeting those systems.
“Asset owners should not assume that their control systems are secure or that they are not operating with an Internet accessible configuration. Instead, asset owners should thoroughly audit their networks for Internet facing devices, weak authentication methods, and component vulnerabilities,” the alert said.
The new plan from the Pentagon contemplates the creation of several separate groups of cyber security personnel, each with a different set of responsibilities. One group will defend networks used by critical infrastructure entities like utilities. Another team will be responsible for defensive and offensive military operations in cyberspace, and the third group will work on fortifying the DoD’s networks.
All of the groups will report up to the U.S. Cyber Command, a relatively new arm of the military headed by Gen. Keith Alexander, the director of the National Security Agency.