| Security Gurus www.security-gurus.com Security from the Security Guru is x y z information security by the Security Gurus security audits |
Cybersecurity Internet SecuritySecurity Gurus |
|
|
computer security computer security system cybersecurity Security Gurus www.security-gurus.com contact the czar data security department of homeland security email security homeland security Security from the Security Guru is x y z information security by the Security Gurus internet security network security Alabama security Alaska guru Alberta security All guru find Arizona security good Arkansas guru better British Columbia guru California security best Canada guru Canada security Colorado security Now Connecticut guru guru Delaware guru District of Columbia security Florida guru Florida guru Georgia guru Georgia guru Hawaii guru Hawaii guru Home guru Home guru Idaho guru and Illinois security Illinois security Indiana is security less guru Iowa security more guru norton internet security security security audit resources security audits security camera security company security encryption security equipment security software security system social security |
Abstract of Technology Assessment: Cybersecurity for Critical Infrastructure
Protection GAO-04-321 May
28, 2004 "Computers are crucial to the operations of government and business. Computers and networks essentially run the critical infrastructures that are vital to our national defense, economic security, and public health and safety. Unfortunately, many computer systems and networks were not designed with security in mind. As a result, the core of our critical infrastructure is riddled with vulnerabilities that could enable an attacker to disrupt operations or cause damage to these infrastructures. Critical infrastructure protection (CIP) involves activities that enhance the security of our nation's cyber and physical infrastructure. Defending against attacks on our information technology infrastructure-- cybersecurity--is a major concern of both the government and the private sector. Consistent with guidance provided by the Senate's Fiscal Year 2003 Legislative Branch Appropriations Report (S. Rpt. 107-209), GAO conducted this technology assessment on the use of Security technologies for CIP in response to a request from congressional committees. This assessment addresses the following questions: (1) What are the key Security requirements in each of the CIP sectors? (2) What Security technologies can be applied to CIP? (3) What are the implementation issues associated with using Security technologies for CIP, including policy issues such as privacy and information sharing? Many Security technologies that can be used to protect critical infrastructures from cyber attack are currently available, while other technologies are still being researched and developed. These technologies, including access control technologies, system integrity technologies, cryptography, audit and monitoring tools, and configuration management and assurance technologies, can help to protect information that is being processed, stored, and transmitted in the networked computer systems that are prevalent in critical infrastructures. Although many Security technologies are available, experts feel that these technologies are not being purchased or implemented to the fullest extent. An overall Security framework can assist in the selection of technologies for CIP. Such a framework can include (1) determining the business requirements for security; (2) performing risk assessments; (3) establishing a security policy; (4) implementing a Security solution that includes people, processes, and technologies to mitigate identified security risks; and (5) continuously monitoring and managing security. Even with such a framework, other demands often compete with cybersecurity. For instance, investing in Security technologies often needs to make business sense. It is also important to understand the limitations of some Security technologies. Security technologies do not work in isolation; they must work within an overall security process and be used by trained personnel. Despite the availability of current Security technologies, there is a demonstrated need for new technologies. Long-term efforts are needed, such as the development of standards, research into Security vulnerabilities and technological solutions, and the transition of research results into commercially available products. There are three broad categories of actions that the federal government can undertake to increase the use of Security technologies. First, it can take steps to help critical infrastructures determine their Security needs, such as developing a national CIP plan, assisting with risk assessments, and enhancing Security awareness. Second, the federal government can take actions to protect its own systems, which could lead others to emulate it or could lead to the development and availability of more Security technology products. Third, it can undertake long-term activities to increase the quality and availability of Security technologies in the marketplace. Ultimately, the responsibility for protecting critical infrastructures falls on the critical infrastructure owners. However, the federal government has several options at its disposal to manage and encourage the increased use of Security technologies, research and develop new Security technologies, and generally improve the Security posture of critical infrastructure sectors. Subject Terms
Technology Assessment: Security for Critical Infrastructure
Protection GAO-04-321 May
28, 2004 |
Security Audits Information Security Audits www.4terrorism.com PM 101 Project Management Training www.projectbailout.com Second Opinions Technology Projects Thousands to save Millions www.projectbailout.com live-blues Blues Music Venues www.blues-fest.com Software Architecture Architecture by the Hour www.projectbailout.com Blues Music Blues Music Venues www.blues-fest.com |
cybersecurity auto security health security car security home security Internet Security business Security czar department of security Internet Security security company