Cybersecurity Is Everyone's Responsibility

By Elana Varon

Wed, January 01, 2003CIO When the Pacific Northwest Economic Region (PNWER) needed a regional cybersecurity vulnerability assessment, it didn’t run to the feds. Instead, the group developed its own exercise, called Blue Cascades, that explored what would happen if critical services like the electric grid or the Internet were lost. PNWER?a partnership of elected officials and corporate executives from five U.S. states, two Canadian provinces and one Canadian territory?sought advice from federal agencies but ran its own exercise in Welches, Ore., last June 12. "There has to be a place where industry is playing a lead role and there’s a climate of trust," concludes Matt Morrison, PNWER’s executive director. "Every federal agency has been saying, Give us data about your vulnerabilities, but nobody knows what they’re going to do with it."

Cyberthreats may be global, but cybersecurity is everyone’s responsibility. Regional, statewide or local partnerships can map out a ground-level view of critical services and what’s needed to defend them. Watch for more partnerships like PNWER’s Partnership for Regional Infrastructure Security to emerge this year. "This is our home turf, and we know it," says Ray Nelson, executive director with the Commonwealth of Kentucky’s Office for Security Coordination. "What may be critical to the feds may not be critical to a county."

Companies have an incentive to work with the government because it’s cheaper than going it alone. "You can spend all your own money trying to [be secure], or you can learn from other people in your industry and the government," says Jacques Gansler, the Roger C. Lipitz chair in public policy and private enterprise at the University of Maryland School of Public Affairs. So far, most information-sharing has occurred between companies and the federal agencies that regulate them. The feds have also encouraged companies within the same industry to share information about specific threats, vulnerabilities, and countermeasures through Information Sharing and Analysis Centers (ISACs).

While the ISACs have developed industry-specific security plans, companies are often more comfortable sharing vulnerabilities with the business next door. "They have built relationships on trust," notes Richard Clarke, special adviser to President Bush on cyberspace security. He says regional groups also know best, for example, which bridges carry fiber-optic cables or which local experts could secure a city’s 911 system.

William F. Pelgrin, director of the New York State Cybersecurity and Critical Infrastructure Coordination Office, wants to bring industry and government representatives together every quarter. "It’s not only so we don’t reinvent the wheel, but also so we can build relationships across sectors." Those relationships are essential to address interdependencies, he says.

Loading...
Security MarketSpace
White Papers
5 Tips for Data Loss Prevention Solutions
RSA® The Security Division of EMC has identified 5 key considerations to help organizations simplify the evaluation process for selecting a DLP solution that is right for their business. Learn more »
Secure Training Videos to Prevent Theft
Learn how Dream Force extended their marketing reach without being constricted. Learn more »
Prevent Intellectual Property Theft
Learn what the key components were in Hock International's purchasing decision. Learn more »
Webcasts
Maximizing the Business Value of the PC Infrastructure
Reduced IT budgets have CIOs hunting for ways to maximize their PC infrastructure, while saving money and IT staff time. Diane Bryant, CIO of Intel Corp., talks with CIO magazine's Gary Beach about how her organization is addressing these challenges. Learn more »
 
SPONSORED LINKS
 

Data Loss Prevention: A Better Way to Approach Security

Software Executives: Take Control of Your Organization's Code Quality

Delivering Secure and Reliable Data through Spreadsheet Automation

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Accenture IT Consulting: Logical meets technological. More . . .

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Gartner Shares Predictions for 2009

64-page prescriptive guide to security, compliance, and IT operations.

Stop Application Fraud at the Source with Device Reputation

Ready to Act: 3 Recommendations for Agile Processes

Automating the Generation and Secure Distribution of Excel Reports

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Reduce risk, gain agility. See how Progress can help your business.

Improve ROI, lower TCO and reduce energy consumption.

 
 
RESOURCE CENTER