IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live one-hour teleconferences:

* Transforming IT Teams
September 16

* Global CIOs: How to Lead on the World Stage
September 18

* Social Responsibility's Strategic Benefits
October 29

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 

Top 5 Concerns about Reporting Security Incidents: A Reality Check

 

October 15, 2002CIO

Stanley "Stash" Jarocki doesn’t act like the agreement he recently signed with the FBI’s National Infrastructure Protection Center (NIPC) is a big deal. "It’s a prenuptial?nothing exotic," says Jarocki, chairman of the Financial Services Information Sharing and Analysis Center (ISAC) and vice president of information security engineering at Morgan Stanley.

But, in fact, it’s a huge deal. With the memorandum of understanding Jarocki signed last June, the ISAC?which was formed in 1999 to give financial companies a place to exchange information about security threats out of the earshot of regulators and law enforcement?has agreed to talk at least once a week to the NIPC, a law enforcement coordination agency.

So what caused the change of heart? Jarocki says it’s because Ron Dick, head of the NIPC, is placing

the agency’s emphasis on preventing crime rather than on catching perpetrators. "Now if I call Ron’s people up and say I’ve got a problem, I’m not necessarily going to have a guy with a gun and badge here tomorrow," says Jarocki. "He’s changed things. I’ll get a [computer] analyst before I get a criminal investigator." The NIPC has also offered the ISAC something in return for the information it shares about security threats such as unknown viruses or new kinds of attacks on firewalls: expertise in computer forensics and data analysis.

The agreement is good news for Dick. "When it was first created, the Financial Services ISAC indicated that it would share information amongst its members and receive information from the government but found it highly unlikely that they would ever share information back to the government," says Dick. "We have been able to demonstrate that we can protect that information, so certain sectors like the financial services sector have seen the value-added associated with two-way information sharing." For instance, last winter the NIPC briefed the ISAC on a newly discovered vulnerability in the common Simple Network Management Protocol (SNMP). Once the vulnerability became public, the ISAC stayed in touch about attacks on SNMP-based hardware and software.

Not that the ISAC members are ready to tell the government all. When members report security incidents to the ISAC, the information is stripped of identifying information, first by a software "scrubber" that erases trademarks, acronyms and other identifying information based on lists provided by members, and then by a human one. Even so, Jarocki says companies are nervous enough about inadvertently revealing weaknesses that they will refuse to share some kinds of information?such as diagrams of network architecture?until they’re convinced that that information could not be accessed through a request under the Freedom of Information Act (FOIA). (See "Fact, Fiction and FOIA," Page 65.)

Loading...
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Solving Online Credit Fraud Using Device Reputation

Weigh the trade-offs between outsourcing communications and keeping it on-premise.

Stimulating Innovation: Meeting IT's New Mission

Fuel the Responsive Enterprise Through Oracle Fusion Middleware

Balance Your Innovation and Efficiency Platforms for Competitive Advantage and Responsiveness

The Challenge of Network Access Control -- Is a Managed Service the Answer?

Unified Communications: "More Than Just Talk"

A Closer Look at SaaS Purchasing Behaviors and Attitudes

31 Best Practices for the Service Desk

Enhancing Online Sales and Support

Extending the Enterprise Network Through Mobility

Spam-proof your business with Google's hosted security solutions

Global Crossing is the most viable alternative for voice, video and data

Plan better, manage better

Dell Latitude: Battery life up to 19 hours. Learn more

Video: 21st Century Networking for a 12th Century Castle

Speed, agility, flexibility - The HP BladeSystem c-Class

Secure your virtual and physical environments with the same software

GET YOUR VoIP ONTM! Win 2 Years of Hosted VoIP from Cypress. $100,000 retail value. Enter today!

Getting in Compliance with Government Data Regulations

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Document Management 2.0 -- Web-based Collaboration and the Road to Compliance

Accelerating ITIL at the Service Desk

Putting Open source to the test

Protecting Data in a Highly Networked World

The Benefits of Data Deduplication for Data Protection in the Enterprise

Webcast: Roundtable discusses industry trends for Enterprise Content Management

How the Mac is Becoming an IT Standard in the Enterprise

Drive More Effective Business Processes with SOA

Reap the Benefits of Unified Communications

Strategic IT Financial Management - Achieve Higher Organizational Performance

New research validates telepresence solutions.

How to Calculate the ROI of Remote Support

Implementing Knowledge Management

Putting Windows Server and Citrix to Work in the Enterprise

HP Puts Its Disaster-tolerant Capabilities to the Test

Compuware.com - See how we make IT rock around the world

CA delivers deeper insight into your assets, resources, projects & services so you can make more informed IT decisions

Discover PMI's credentials and career path tools

SOA Educational Library at the TIBCO SOA Resource Center

TDWI Report shows strong validation for investing in predictive analytics

Learn about the software-based VoIP solution from Microsoft

Microsoft System Center - Designed For Big

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Destination: Intelligent Data Center Automation

Build up or Tear down? See how UC makes sense with Nortel. Calculate your UC ROI

Virtual Support Technology Delivers Quantifiable Gains in Productivity and Performance

File Integrity Monitoring: Secure Your Virtual & Physical IT Environments

Consolidation: Just the Starting Point for Virtualization