*I'd love to see somebody sell a few metric tons of Brussels-approved european cyberspace.
–EU Calls For Development of Strategy to Protect European Cyber Space
(31st March 2009)
The European Commission has called for the development of a strategy to protect Europe from disruption to critical networks resulting from cyber attacks or natural disasters. The EC highlights that the region is becoming more and more dependent on the continuous availability of IT
and communications systems for supporting electronic commerce and for playing a crucial role in the management of other critical services such as transportation and the supply of food, energy and water. The strategy highlights the cyber attacks against Estonia and calls for a minimum standard of preparedness that organizations in the public and private sector in all member states should reach in order to ensure the overall security of the region.
http://www.theregister.co.uk/2009/03/31/eu_cyberattack_strategy/
http://www.vnunet.com/vnunet/news/2239455/eu-pledges-protect-cyber
*Yet another American Potemkin cyberczar – the "national cybersecurity adviser."
Where's his badge, where is his budget? I wonder if the Chinese, currently rampaging gleefully over everything Microsoft ever built, have any
"Chinese cyberspace." They've got a Great Firewall. Maybe that's a start.
TOP OF THE NEWS
–New Senate Bill Proposes Mandatory Security Standards and Certifications
(1st April 2009) (((A new bill, sponsored by Senators John D. Rockefeller IV and Olympia J
Snowe, would see the introduction of a new cyber security czar, the
National Cybersecurity Advisor, who would report directly to the White
House. Included in the bill is the granting of authority to the
National Cybersecurity Advisor to isolate computer networks that are part of the critical network infrastructure, including those in the private sector, should there be a cyber attack. The bill would also see the introduction of mandatory security standards, developed by the
National Institute of Standards and Technology, applied to both private and public sector organizations that control parts of the critical network infrastructure. Included in the bill is the proposal that a licensing and certification program be introduced for cyber security professionals.
http://www.washingtonpost.com/wp-dyn/content/article/2009/03/31/AR2009033103684.html http://fcw.com/Articles/2009/04/01/Web-cybersecurity-bill.aspx http://www.vnunet.com/vnunet/news/2239646/plans-national-cybersecurity http://lastwatchdog.com/senate-bill-mandates-strong-federal-role-internet/
[Editor's Note (Schultz): Like it or not, mandatory security standards are inevitable in the US at some point in time. Without them, the US
will continue to have too many weak links in its critical computing infrastructure. (((They've been saying that for 25 years now.)))
(Northcutt): This is a fairly ambitious bill. We need to be aware of it and decide what parts we want to support, which parts might need more discussion. This seems to be a first step at professionalization for security workers as well. ]