|
|
Cybertelecom
Federal Internet Law & Policy
An Educational Project
|
|
CyberSecurity |
There is no doubt that as individuals, as businesses, and as a nation as a whole, we are increasingly at risk if we choose to do nothing in the face of our growing infrastructure vulnerabilities. These risks are real. We don't need to wait for a catastrophe to occur - indeed we must not allow a catastrophe to occur - in order to recognize that much work needs to be done. - Ronald L. Dick, Director US National Infrastructure Protection Center September 5, 2001
Derived From: Public and Private Entities Face Challenges in Addressing Cyber Threats, GAO-07-705 (June 2007)
"Cybercrime is a threat to U.S. national economic and security interests. Various studies and expert opinion estimate the direct economic impact from cybercrime to be in the billions of dollars annually. The annual loss due to computer crime was estimated to be $67.2 billion for U.S. organizations, according to a 2005 Federal Bureau of Investigation (FBI) survey. The estimated losses associated with particular crimes include $49.3 billion in 2006 for identity theft and $1 billion annually due to phishing. These projected losses are based on direct and indirect costs that may include actual money stolen, estimated cost of intellectual property stolen, and recovery cost of repairing or replacing damaged networks and equipment. In addition, there is concern about threats that nation-states and terrorists pose to our national security through attacks on our computer-reliant critical infrastructures and theft of our sensitive information. For example, according to the U.S.-China Economic and Security Review Commission report, Chinese military strategists write openly about exploiting the vulnerabilities created by the U.S. military's reliance on advanced technologies and the extensive infrastructure used to conduct operations. Also, according to FBI testimony, terrorist organizations have used cybercrime to raise money to fund their activities. Despite the reported loss of money and information and known threats from adversaries, there remains a lack of understanding about the precise magnitude of cybercrime and its impact because cybercrime is not always detected or reported (cybercrime reporting is discussed further in our challenges section).
"Numerous public and private entities (federal agencies, state and local law enforcement, industry, and academia) have individual and collaborative responsibilititelephonetelephonees to protect against, detect, investigate, and prosecute cybercrime. The Departments of Justice (DOJ), Homeland Security (DHS), and Defense (DOD), and the Federal Trade Commission (FTC) have prominent roles in addressing cybercrime within the federal government. DOJ's FBI and DHS's U.S. Secret Service (Secret Service) are key federal organizations with responsibility for investigating cybercrime. State and local law enforcement organizations also have key responsibilities in addressing cybercrime. Private entities-Internet service providers, security vendors, software developers, and computer forensics vendors-focus on developing and implementing technology systems to protect against computer intrusions, Internet fraud, and spam and, if a crime does occur, detecting it and gathering evidence for an investigation. In addition, numerous partnerships have been established between public sector entities, between public and private sector entities, and internationally to address various aspects of cybercrime. For example, the Cyber Initiative and Resource Fusion Unit is a partnership established among federal law enforcement, academia, and industry to analyze cybercrime and determine its origin and how to fight it.
"Federal and state governments and other nations have enacted laws that apply to cybercrime and the legal recourse or remedies available. In addition, there are international agreements to improve the laws across nations and international cooperation on addressing cybercrime. Some federal statutes address specific types of cybercrime, while other federal statutes address both traditional crime and cybercrime."
| Threats |
Agency [REVISE THESE LINKS] |
| Threats Against the Network |
|
Worms, Viruses, Attacks
Hacks
DOS
Vulnerabilities |
Whitehouse
- Office Science and Technology Policy
- Homeland Security Council
- National Security Council
DHS Lead Agency (Prevention, Alerts, Info Sharing, Recovery)
- NCSD (Prevention, Alerts, Info Sharing, Recovery)
- - US CERT (Prevention, Alerts, Info Sharing, Recovery)
- - - National Control Systems Center
- - - National Cyber Response Coordination Group (NCRCG)
- - - Protected Critical Infrastructure Information Program
- - - Cyber Warning and Information Network CWIN
- - NCS (Prevention, Alerts, Info Sharing, Recovery)
- - Cyberstorm game
- Secret Service (investigation, enforcement)
- Partner: NIST ANTD Internet Infrastructure Protection
DOJ (enforcement, investigation)
- FBI (investigation)
- Computer Crime and Intellectual Property Section (investigation, prosecution)
DOD
- DISA
- - Partner: NIST ANTD Internet Infrastructure Protection
- CERT (funding)
(Prevention, Alerts, Info Sharing, Recovery)
- Defense Advanced Research Projects Agency
- Office of the Director, Defense Research and Engineering
- NSA (crypto)
DOC
- NIST
- - Computer Security Division
- - Advanced Network Technologies Division
- - - Internet Infrastructure Protection (DNSSEC, BGP Sec, Reliability, IPSEC)
- - Critical Infrastructure Protection Grants (funding for R&D)
- NTIA
- - Critical Infrastructure Protection
- - DNS
NSA
- Partner: NIST ANTD Internet Infrastructure Protection
CIA
NSF (funding for R&D) |
| Cyberwar |
DoD |
| Telecommunications |
FCC
- NRIC (reliability, Best Practices)
DHS
- NCSD
- - NCS |
| Threats Over the Network |
|
| Spam |
FTC (Prevention, Consumer Info, Info Gathering, Enforcement)
DOJ (Enforcement)
FCC (SMS Spam - Prevention, Enforcement) |
| Fraud |
FTC (Prevention, Consumer Info, Info Gathering, Enforcement)
DOJ (Enforcement) |
| ID Theft |
FTC (Prevention, Consumer Info, Info Gathering, Enforcement)
DOJ (Enforcement) |
| Offensive Content on the Internet |
DOJ (Enforcement)
FCC (Erate Condition: CIPA)
DHS
- Customs
|
| Gambling |
DOJ (Enforcement) |
| eMedicine, Drugs |
DOJ (Enforcement)
- FDA
FTC (Fraud, Consumer Info)
|
| Alcohol Tobacco Sales |
DOJ (Enforcement)
- ATF |
| Hacks to Personal Computers |
DOJ (Enforcement)
- Computer Crimes and Intellectual Property Section
- FBI |
| CyberStalking |
DOJ (Enforcement)
- FBI |
| Financial, Investing |
DOJ (Enforcement)
- FBI
DHS
- Secret Service |
| Illegal Wiretaps |
DOJ (Enforcement)
- FBI
- Computer Crimes and Intellectual Property Section |
Hearings & Reports
- CyberSecurity: Protecting America's Critical Infrastructure, Economy, and Consumers, Subcommittee on Telecom and the Internet, Sept 13, 2006
- “The Economic Impact of Cyber
Attacks.” CRS 2004
- “Cybersecurity—Getting It Right: The Importance of Research in Cybersecurity and What More Our Country Needs to Do,” on July 22, 2003. Subcommittee on Cybersecurity, Science, and Research Development of the US House of Representatives Select Committee on Homeland Security
- "Overview of the Cyber Problem: A
Nation Dependent and Dealing with Risk,” June 2003
Subcommittee on Cybersecurity, Science, and Research Development of the US House of Representatives Select Committee on Homeland Security
- Critical Infrastructure Protection: Who's in Charge, GSA before Committee on Governmental Affairs (Oct 2001)
Links
Books
- Ready to blow the whistle on a cybercrime? Who ya gonna call?, CW 9/12/2007
- ESTABLISHMENT OF THE PUBLIC SAFETY AND HOMELAND SECURITY BUREAU AND OTHER ORGANIZATIONAL CHANGES., FCC 9/26/2006
- FCC Establishes Public Safety and Homeland Security Bureau, Converged Network 9/26/2006
- Fiddling while Rome burned, CNET 9/2/2006
- Federal agencies get a D+ on cybersecurity, CW 2/18/2005
- Clarke: Who leads cybersecurity?, FCW 2/18/2005
- Reports: FBI Shutters Public E-Mail System, eweek 2/8/2005
- Bush backs boost for cybersecurity, FCW 2/8/2005
- Bush's Cyber Security Force Loses Another One, InternetNews 1/14/2005
- F.B.I. May Scrap Vital Overhaul of Its Outdated Computer System, NYT 1/14/2005
- Calling for security leadership, FCW 12/10/2004
- Committee calls for cybersecurity post, FCW 12/10/2004
- Ridge leaves mixed legacy, CNET 12/3/2004
- Former cybersecurity czar: Code-checking tools needed, Infoworld 12/3/2004
- US gets new cyber security chief, BBC 10/8/2004
- Access to Tom Ridge or bust, CNET 10/8/2004
- Howard Schmidt to lead U.S. CERT, CW 10/8/2004
- US cyber security chief resigns, BBC 10/5/2004
- Steps for Creating National CSIRTs, CERT 10/5/2004
- U.S. cybersecurity chief resigns, CNET 10/5/2004
- FTC Continues Education, Enforcement Efforts to Promote Information Security, FTC 9/24/2004
- Cybersecurity czar may get a promotion, CNET 9/21/2004
- Collins praises, Lieberman blasts homeland security orders, FCW 12/19/2003
- Organizational Models for Computer Security Incident Response Teams, CERT 2/10/2004
- U.S. creates cyberalert system, CNET 2/2/2004
- Gov't Rolls Out Cyber Alert System, Internet News 2/2/2004
- Fed cybersecurity chiefs get a council, FCW 12/5/2003
- Feds simulate terrorist cyberattack, CNN 12/2/2003
- DHS Cuts Tech Funding By 30%, Internet News 11/14/2003
- EU hi-tech crime agency created, BBC 11/21/2003
- Homeland security goes online, BBC 6/9/03
- Government forms cybersecurity unit, CNET 6/9/03
- Homeland Security to tap director, CNET 6/6/03
- Broadband Users Lack Basic Security, Internet News 6/6/03
- When to make the cybersecurity call, FCW 4/4/03
- Creation of cybersecurity post in administration appears imminent, GovExec 4/1/03
- U.S. Government To Get Cybersecurity Chief, Salon 5/28/03
- Blogs play a role in homeland security, CW 5/12/03
- Homeland chief urges firms to bolster cybersecurity, GovExec 5/2/03
- Ridge Asks For Tech Help, Info World 4/30/03
- ITAA Calls For Cybersecurity Czar, Internet News 4/23/03
- Howard Schmidt is leaving the White House, GCN 4/21/03
- Howard Schmidt leaving government cybersecurity job, CW 4/21/03
- White House May Lose Top Cybersecurity Advisor, Internet News 4/21/03
- U.S. Cyber Security Plan A Mosaic, Internet News 4/17/03
- Cybe rsecurity in Europe and EU-Russia Co-operation, RAPID 4/11/03
- Clarke: No One's Minding the Cyber Store, eweek 4/9/03
- NIPC Leadership Questioned, Info World 2/28/03
- Anti-terror Network 'in Disarray', BBC 2/21/03
- Cybersecurity Chief To Quit, Internet News 1/29/03
- U.S. Cybersecurity Czar to Resign, Wired 1/29/03
- Cooper named Homeland Dept. CIO, FCW 1/10/03
- White House trims cybersecurity plan, MSNBC 1/7/03
- Feds Building Internet Monitoring Center, Wash Post 2/10/03
- Homeland Office Is Told to Answer Queries on Its Role, Wash Post 1/3/03
- Feds Delay Launch of Cyber-Security Plan, VOA 12/20/02
- The Year In Security, TechTV 1/2/03
- Sentries on the Net, CNET 1/2/03
|
- Tracking and Tracing Cyber-Attacks: Technical Challenges and Global Policy Issues, CERT 12/4/02
- Homeland Security Is Watching You, Newsfactor 11/25/02
- NIPC Seeks Cyberalert Support, FCW 8/16/02
- NIPC CyberNotes Issue #2002-16, 08/12/2002, NIPC 8/16/02
- OECD Publishes Cyber-Security Guidelines, IDG 8/9/02
- OECD Governments Launch Drive to Improve Security of Online Networks, OECD 8/9/02
- Creating a Computer Security Incident Response Team: A Process for Getting Started, CERT 8/7/02
- Bush Adviser Encourages Hacking, Wash Post 8/2/02
- Cybersecurity Info Sharing Plan Blasted, Wash Post 7/29/02
- Report: Cyber Security Efforts Disorganized, USAToday 7/24/02
- National Strategy Executive Summary, WhiteHouse 7/17/02
- NIPC Reaches Out To Private IT Sector, Internet News 6/26/02
- Government Not Ready For Cyberattacks, Internet News 6/26/02
- White House Stressing IT Security, Wash Post 6/10/02
- Bush Plan Backs IT Infrastructure, FCW 6/5/02
- Homeland security network proposed, USA Today 6/5/02
- InfoSec: GartnerG2 Says Not Enough Being Done to Prepare for Cyberattacks, ITAA 5/22/02
- Ridge wants tech firms to enlist in terrorism fight, USA Today 4/24/02
- Government cyber security chief warns of threats to infrastructure , Nando 2/20/02
- High-Tech Security Czar Warns Against Cyber Complacency , Wash Tech 2/20/02
- White House To Form Cybersecurity Center, FCW 2/15/02
- Cybercrime reporting procedure draws fire , CW 2/20/02
- U.S. Backing for Guidelines on Fighting CyberCrime, NYT 2/13/02
- NIPC Head: Communication Key, Must Do More, IDG 2/4/02
- NIST Prepping Security Guides, Fcw 1/28/02
- White House Cybersecurity 'Strategy' Due In June, Wash Tech 1/28/02
- U.S. Cyber Chief to Map Infrastructure for Security, Reuters 12/6/01
- Feds To Draw 'Map' Of Internet (by the National Infrastructure Simulation and Analysis Center which is a part of the Defense Threat Reduction Agency - NISAC is a partnership between DTRA and Los Alamos), Newsfactor 12/7/01
- Cyber-security czar snubs ID plan, MSNBC 11/9/01
- New Powers In Cybersecurity, Reuters 11/9/01
- Cybersecurity chief warns of Net threat, USAToday 11/9/01
- Security woes dog federal agencies, CNET 11/9/01
- ITAA Calls for Immediate New Federal IT Security Funding, Inews 11/9/01
- President Forms Cyberterrorism Panel, AP 10/17/01
- New Unit Targets Internet Crimes, LAT 7/13/01
- Top DOJ Official Outlines Priority List to Combat Cybercrime, Standard 6/15/01
- Internet warning system under siege (CERT), CNET 5/23/01
- NIPC Gets "F" In Hack Attack Warnings, InternetNews 5/23/01
- Bush considers cybersecurity coordination board, USAToday 5/16/01
- Bush Mulls cybersecurity, USAToday 5/11/01
- White House Site Attack Clues Sought, CW 5/8/01
- Senator: Aid Cyber Security By Secrecy, Reuters 5/8/01
- FBI Names New Chief For Computer Security, Infoworld 3/21/01
- U.S. Cyber-Chief Warns of Weaknesses, Newsfactor 3/21/01
- National Security Adviser sees cyberterrorist threat, USAToday 3/23/01
|
News Archive Continued
|