Washington D.C. Watch: Eye on Computer Security, IT Policy

By Edited by Elana Varon
Sun, July 15, 2001

CIO

Hacks? What Hacks?

Sen. Robert Bennett (R-Utah), the Senate’s computer security point man, wants you to start reporting hacks of your company networks to the government. But he thinks you need a little incentive. His plan? To pass a new law that exempts any information that businesses share on hacks from disclosure under the Freedom of Information Act (FOIA).

It sounds reasonable enough. The government needs this information to understand why attacks occur and to develop better security protections. FOIA is a law that lets the public request internal government documents?like memos about Gulf War veterans’ illnesses or FBI files about criminal gangs. Companies fear that if reports of their security weaknesses are aired publicly (the press is a major FOIA user), the information would cast doubt on their future health and their stock prices could slide.

Bennett’s critics, however, see a slippery slope, leading to companies covering up problems that investors and customers should know about. Scott Armstrong, a journalist and founder of the National Security Archive, says it’s not clear how the government would define what constitutes protected information about a network intrusion. Hypothetically, a software company could use such a law to cover up that it knew there were vulnerabilities in its product before it was sold but did nothing about it.

Armstrong thinks most information that companies would legitimately want to keep secret is already protected by existing FOIA exemptions. The statute shields proprietary information about companies and data about law enforcement investigations.

At press time, Bennett was planning to introduce his bill this summer. Similar legislation sponsored by Reps. Tom Davis (R-Va.) and Jim Moran (D-Va.) went nowhere last year, but the idea has influential friends. Backers include companies in the banking, telecommunications, electricity and IT industries. For more on this issue, see "Break Glass, Pull Handle, Call FBI" (June 1, 2001).

-Stephanie Viscasillas

The Man to See About IT Policy

John Graham, head of The Harvard Center for Risk Analysis, is a leading skeptic of the value of government regulation. And he’s the man President Bush hopes to put in charge of deciding which regulations?including those relating to IT policy?go on the books. If he’s instated he’ll pass judgment on everything from whether agencies will put their forms online to what companies have to do to protect the privacy of financial or medical data they keep about customers.

Graham, whose confirmation by the Senate as head of the Office of Information and Regulatory Affairs (OIRA) was imminent at press time, is controversial. He’s taken strong stands against some regulations, like proposals to prohibit using cell phones while driving, arguing their costs outweigh their benefits. And he’s been criticized for kowtowing to companies that fund his research (consumer advocates jumped on the fact that AT&T had funded his cell phone research). Meanwhile, some detractors contend he’s ill-qualified to make IT policy. Gary Bass, executive director of OMB Watch, a government watchdog group, thinks the OIRA head should have some technology expertise (Graham is a professor of policy and decision sciences). No past OIRA administrators have been technologists, though former Presi-dent Clinton’s appointee, Sally Katzen, was an expert in telecommunications law. At his confirmation hearings in May, Graham said he simply calls things as he sees them. No senators on the Governmental Affairs Committee asked for his views on IT issues during the confirmation hearings, and he didn’t volunteer any.

-S. Viscasillas

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center