Showing posts with label cyber terrorism. Show all posts
Showing posts with label cyber terrorism. Show all posts

Monday, January 08, 2018

Cyber Storm VI: National Cyber Exercise

The Cyber Storm exercise series is the Department of Homeland Security’s (DHS) national, biennial distributed exercise entirely focused on cyber incident response. Mandated by Congress, these exercises are part of the Department’s ongoing efforts to assess and strengthen cyber preparedness, examine incident response processes, and enhance information sharing among federal, state, international, and private sector partners. Each Cyber Storm event builds on lessons learned from previous exercises and real world incidents, ensuring that participants address relevant and timely challenges.
Cyber Storm exercises give the cyber incident response community a safe venue to coordinate and practice plans, response mechanisms and recovery tasks, as well as to build and maintain relationships. Most importantly, the exercises provide the community with the opportunity to identify strengths and areas for improvement, incorporating those lessons into operations to help reduce cyber risks to the nation.
The high-level objectives of Cyber Storm VI include:
  • Exercise the coordination mechanisms and evaluate the effectiveness of the National Cyber Incident Response Plan (NCIRP) in guiding response.
  • Assess information sharing to include thresholds, paths, timeliness, usefulness of information shared, and barriers to sharing both internally and externally within the cyber incident response community.
  • Continue to examine the role, functions, and capabilities of DHS as the Department coordinates with impacted entities during a cyber event.
  • Provide a forum for exercise participants to exercise, evaluate, and improve the processes, procedures, interactions, and information sharing mechanisms within their organization or community of interest
Cyber Storm VI is scheduled for Spring 2018. The exercise will focus on the critical manufacturing and transportation sectors, with participation from the information technology and communications sectors; law enforcement, defense, and intelligence agencies; state, local, and territorial governments; and international partners. For more information, email cyberstorm@hq.dhs.gov.
To review the final reports from previous Cyber Storm exercises, visit https://www.dhs.gov/publication/cyber-storm-final-reports.

Tuesday, August 02, 2016

Cyber Terrorism Roles Clarified

Members of the Democratic Party are accusing the Russians of hacking into DNC party emails and releasing them in order to discredit candidate Clinton in support of Trump.

Clinton’s campaign chief, Robby Mook, told ABC News that “experts are telling us that Russian state actors broke in to the DNC, took all these emails and now are leaking them out through these Web sites. . . . It’s troubling that some experts are now telling us that this was done by the Russians for the purpose of helping Donald Trump.”

Russians hack DNC emails? Do they favor Donald over Hillary?
The accusations appear on the surface to be wild and politically motivated. (Why would the Russians want Trump more than Hillary?) However, the real possibility exists that foreign governments could perform cyber attacks to interfere in U.S. politics. Other more serious threats would be hacking the U.S. Treasury payroll and government personnel records. (Oops! That has already happened.) Or worse attacks on U.S. infrastructure which would cause havoc or stoppage to transportation and utilities. (That may have already happened as well.)

On July 26, 2016 the White House issued Presidential Policy Directive PPD-41 on United States Cyber Incident Coordination to deal specifically with these kinds of threats. The directive indicates which agency handles what and reveals how the administration grades the severity of an event, determining what is significant.

The FBI will be the lead federal agency investigating criminal and national security hacks. The Department of Homeland Security will help organizations reduce the impact of an event and prevent its spread, mainly through preparedness and prevention. The Cyber Threat Intelligence Integration Center, or CTIIC, will gather intelligence to help identify who directed an intrusion or attack. Because the Defense Department does not play a primary role in domestic cybersecurity, it is not mentioned in the directive.

All this has potential for some great spy novels and action movies. It's good to have the roles clarified so we know who the actors will be.

See Presidential Policy Directive PPD-41.