Cybertelecom
Cybertelecom
Federal Internet Law & Policy
An Educational Project

CyberSecurity: Federal Agencies

Navigation Links:
:: Home :: Feedback ::
:: Disclaimer :: Sitemap ::

Cybersecurity
- Agencies
- - White House
- - DHS
- - NIST
- - NTIA
- - FCC
- Reference
- Cryptography

Crimes Against Network
- Worms, Viruses, Attacks
- Hackers
- DOS
- Wireless Malware
- Cyberwar
- Network Reliability
- Infrastructure Protection
- - Kill Switch

Crimes Over Network
- CyberStalking
- Fraud
- - Auctions
- - Phishing
- Gambling
- Hoaxes
- ID Theft
- Offensive Words

Info Gathering
- Wiretaps
- CALEA
- ECPA
- FISA
- Forensics
- Carnivore
- Patriot Act
- Data Retention
- Safe Web Act

Emergency
- EAS
- Assessment
- Reliability
- Vulnerabilities

| DHS | DOJ | USAO | FBI | NSF | DOD | DOC | NIST | FCC |

Congress

Department of Justice

Derived From: GAO Cybercrime Public and Private Entities Face Challenges in Addressing Cyberthreats (June 2007)

"Implements and supports both the department’s Computer Crime Initiative, designed to combat electronic penetrations, data thefts, and cyber attacks on critical information systems, and the department’s aggressive battle to protect children from individuals who use computers and the Internet to sexually abuse and exploit them.

US Attorney's Office

FBI

Federal Trade Commission

"Both the public and private sectors have noted the importance of user education and consumer awareness relating to emerging cybersecurity threats. The Federal Trade Commission (FTC) has been a leader in this area, issuing consumer alerts and releasing several reports on spam as well as guidance for businesses on how to reduce identity theft. In addition, FTC has sponsored various events, including a spam forum in the spring of 2003, a spyware workshop in April 2004, and an e-mail authentication summit in the fall of 2004. Also notable is its Identity Theft Clearinghouse, an online resource for taking complaints from consumers." [GAO 05 p 7]

DOD

Department of Commerce

National Science Foundation

Department of State, Bureau of Diplomatic Security, Office of Computer Security, Cyber Threat Division

See Protecting Information

Critical Infrastructure Protection Board

Executive Order : Critical Infrastructure Protection in the Information Age, WH 10/16/01 ("I hereby establish the "President's Critical Infrastructure Protection Board" (the "Board")").  The Board has membership from the leadership of federal agencies.  It is not at this time clear what the Board will be doing. Howard Schmidt, Chairman of the PCIP

Other Agencies

One of the oldest and most active internal federal efforts is the US Dept of Energy Computer Incident Advisory Capability (CIAC) "provides on-call technical assistance and information to U.S. Department of Energy  (DOE) sites faced with computer security incidents. This central incident handling  capability is one component of all encompassing service provided to the DOE community.  The other services CIAC provides are: awareness, training, and education; trend, threat,  vulnerability data collection and analysis; and technology watch. CIAC was established in 1989 to serve the DOE Community. CIAC is one of two oldest response teams and is recognized nationally and internationally for its contributions to the Internet community. CIAC is a founding member of FIRST, the Forum of Incident Response and Security Teams, a global organization established to foster cooperation and coordination among computer security teams worldwide." Who is CIAC One of the more interesting services that CIAC provides is Hoaxbusters, an information source debunking many of the popular myths and legends on the Internet.  See HoaxbustersHoaxbusters!


 
NSA/CSS INFOSEC
Information Assurance Directorate

"NSA/CSS provides the Solutions, Products and Services, and conducts Defensive Information Operations, to achieve Information Assurance for information infrastructures critical to U.S. National Security interests."  NSA/CSS Infosec Page

"In order to enable our customers to protect and defend cyber systems, the NSA develops, and supports a variety of products and services. We also conduct ongoing research to aid in the development of next generation solutions. Our IA solutions must encompass a wide range of voice, data and video applications, extending across networked, tactical and satellite systems. IA solutions include the technologies, specifications and criteria, products, product configurations, tools, standards, operational doctrine and support activities needed to implement the protect, detect and report, and respond elements of cyber defense.

"The Information Assurance Framework Forum, developed in a collaborative effort by NSA solution architects, customers with requirements, component vendors, and commercial integrators, guides our solution development. It finds the right solution for environments ranging from outerspace to the office or foxhole. Our framework provides top level guidance in addition to the specification of essential security features and assurances for the security products. It brings producers and consumers together before products are built so that products which better meet our customers' needs will be built.

"The internationally recognized Common Criteria (CC) employs standardized terms to describe the security functionality and assurance of consumers' requirements and manufacturers' products. CC-based Protection Profiles specify what consumers need at both the system and the component level to fulfill their mission. CC-based Security Targets describe how specific products meet consumers' requirements.

"These IA solutions take maximum advantage of commercial components, using NSA developed products and services to fill gaps in areas not satisfied by commercial offerings. Commercial-off-the-shelf (COTS) products include security products (e.g. a firewall) or security enabled or enhanced Information Technology (IT) products (e.g. an e-mail application or secure cellular phone). Our solutions include technologies and tools necessary for a layered defense-in-depth strategy and tools for defensive information operations such as intrusion detection, automated data reduction and modeling/simulation tools.

The NSA constantly works with its government and industry partners to facilitate emerging technology, taking the lead in problems not addressed by industry." About the ISSO

CERT Cordination Center

One of the best known efforts is the CERT Coordination Center.  CERT/CC's scope is Internet security issues.  It is a part Carnegie Mellon University's Software Engineering Institute, a federally funded research and development center.  It was created after the Morris Worm by the Department of Defense DARPA, which continues to be a major sponsor of the effort.  CERT was charged with the task of coordinating communications among experts during emergencies and helping to prevent future situations.  CERT's focus is on network vulnerabilities, advising network operators of the problems and how they can be addressed. CERT has become a model effort and its practices have been adopted by 90 similar efforts worldwide.  CERT disseminates security information through its website, a hotline, a mailing group, and USENET.  It is frequently the authority quoted by the media in coverage of cyber events.  CERT disseminates information through multiple channels:
                    telephone and email
                         hotline: +1 412 268-7090 
                         email: cert@cert.org 
                         mailing list: majordomo@cert.org
                    USENET newsgroup: comp.security.announce 
                    World Wide Web: http://www.cert.org/
See About the CERT/CC; CERT Homepage;SEI Sponsoring and Oversight Organization; Annual Report 2000.

Other Federal Links

International

States


 National Association of State CIOs

"NASCIO represents state chief information officers and information resource executives and managers from the 50 states, six U. S. territories, and the District of Columbia. State members are senior officials from any of the three branches of state government who have executive-level and statewide responsibility for information resource management. Representatives from federal, municipal, and international governments and state officials who are involved in information resource management but do not have chief responsibility for that function participate in the organization as associate members. Private-sector firms and non-profit organizations may join as corporate members."  About NASCIO

Multi State ISAC

 

Web services provided by
Wyoming.com
: Home : About Us : Contact Us : Sitemap : Discussion : Search : Newsletter : RSS :
: ADA : Broadband : Crime : Copyright : DNS : ECommerce : EGovt : First Amendment : Digital Divide :
: Network Neutrality : Intl : Privacy : Security : SPAM : Statistics : VoIP : Vote : And Much More! :
:: Feedback : Disclaimer ::
© Cybertelecom ::