SlideShare a Scribd company logo
Understanding Technology Stakeholders:
Their Progress and Challenges
John M. Gilligan
Software Assurance Forum
November 4, 2009 1
Topics
• Historical Perspectives
• Cyber Security Threats--A National Crisis
• Cyber Security Commission Recommendations
• Near Term Opportunities
• Longer-Term Game Changing Initiatives
• Closing Thoughts
2
Historical Perspectives
• Internet, software industry, (personal) computers
—rooted in creativity not engineering
• Security in the Cold War Era
– Security “Gurus”—Keepers of the Kingdom
• The World Wide Web changes the security
landscape-- forever
• Post Cold War: The Age of Information Sharing
3Legacy of the past is now our “Achilles Heel”
Cyber Security Threats Today—
A New “Ball Game”
• Our way of life depends on a reliable cyberspace
• Intellectual property is being downloaded at an
alarming rate
• Cyberspace is now a warfare domain
• Attacks increasing at an exponential rate
• Fundamental network and system vulnerabilities
cannot be fixed quickly
• Entire industries exist to “Band Aid” over
engineering and operational
Cyber Security is a National Security Crisis! 4
Commission Cyber Security for the 44th
Presidency:
Key Recommendations
• Create a comprehensive national security
strategy for cyberspace
• Lead from the White House
• Reinvent public-private partnerships
• Regulate cyberspace
• Modernize authorities
• Leverage government procurement (Supply
Chain Risk Management)
• Build on recent progress with CNCI
(comprehensive national cyber-security
initiative) 5
Use Government IT Procurement
• Cyber security needs to be reflected in our
contractual requirements
• Many “locked down” configuration defined
• Use government-industry partnership to
accelerate implementation of secure
configurations
• Get started now, improve configuration
guidelines over time and leverage SCAP!
6
Build on FDCC Successes and Lessons Learned
Longer-Term: IT Reliably Enabling Economy
• Change the dialogue: Reliable, resilient IT is
fundamental to future National Security and
Economic Growth
• New business model for software industry
• Redesign the Internet
• Get the “man out of the loop”—use
automated tools (e.g., SCAP)
• Develop professional cyberspace workforce
• Foster new IT services models
Need to Fundamentally “Change the Game” to Make Progress7
Security Content Automation Protocol (SCAP)
• What is it: A set of open standards that
allows for the monitoring, positive control,
and reporting of security posture of every
device in a network.
• How is it implemented: Commercial products
implement SCAP protocols to exchange and
enforce configuration, security policy, and
vulnerability information.
• Where is it going: Extensions in development
to address software design weaknesses,
attack patterns, and malware attributes.
8
SCAP Enables Automated Tools To Implement And Enforce Secure Operations
Consensus Audit Guide (CAG)
• What is it: 20 key actions (called security
“controls”) that organizations must take if they
hope to block or mitigate top known attacks.
• How is it implemented: (Mostly) automated
means used to implement and continuously
enforce/monitor controls.
Consensus Audit Guidelines permits organizations to prioritize
security implementation and continuously enforce controls
9
Summary of Ideas for this Technology Working Group
• How do we make measurable progress in
improving security?
• How do we assess the effectiveness of
security tools?
• How do we change the software industry to
produce reliable and secure products?
It is time to get off the treadmill and start making
measurable progress in securing our systems! 10
Closing Thoughts
• Government and Industry need to treat cyber
security as an urgent priority
• Near-term actions important but need to
fundamentally change the game to get ahead of
threat
• IT community needs to reorient the dialogue on
cyber security—the objective is reliable and
resilient information
• Cyber Security in DoD is more mature—but still
woefully inadequate
11Cyber Security is Fundamentally a Leadership Issue!
Contact Information
jgilligan@gilligangroupinc.com
www.gilligangroupinc.com
John M. Gilligan
12

More Related Content

PPT
Understanding Technology Stakeholders
PPTX
Cyber Security: Past and Future
PPTX
Cyber Security: Past and Future
PPTX
Cyber Security: Threats and Needed Actions
PPTX
Cybersecurity: Challenges, Initiatives, and Best Practices
PPTX
7 Habits of Highly Secure Organizations
PDF
Next-Generation SIEM: Delivered from the Cloud
Understanding Technology Stakeholders
Cyber Security: Past and Future
Cyber Security: Past and Future
Cyber Security: Threats and Needed Actions
Cybersecurity: Challenges, Initiatives, and Best Practices
7 Habits of Highly Secure Organizations
Next-Generation SIEM: Delivered from the Cloud

What's hot (20)

PPT
Information Assurance And Security - Chapter 1 - Lesson 3
PPT
Commercial And Government Cyberwarfare
PPT
Intro to Security
PPTX
Process Whitelisting and Resource Access Control For ICS Computers, Kuniyasu ...
PPTX
Leveraging Federal Procurement to Improve Cyber Security
PDF
Cybersecurity Summit AHR20 Protect Cimetrics
PDF
Network and Endpoint Security v1.0 (2017)
PPTX
Technology: Built for Attack : Dr. Emma Garrison-Alexander
PPTX
The privacy and security implications of AI, big data and predictive analytics
PPTX
It and-cyber-module-2
PDF
Cybersecurity Summit 2020 Slide Deck
PPTX
What's New In CompTIA Security+ - Course Technology Computing Conference
PPT
Qualys user group presentation - vulnerability management - November 2009 v1 3
PPTX
Recent changes to the 20 critical controls
PPT
Leone ct#4 presentation
PPTX
Overview of the 20 critical controls
PPTX
More practical insights on the 20 critical controls
PPT
Chapter 1 Presentation
Information Assurance And Security - Chapter 1 - Lesson 3
Commercial And Government Cyberwarfare
Intro to Security
Process Whitelisting and Resource Access Control For ICS Computers, Kuniyasu ...
Leveraging Federal Procurement to Improve Cyber Security
Cybersecurity Summit AHR20 Protect Cimetrics
Network and Endpoint Security v1.0 (2017)
Technology: Built for Attack : Dr. Emma Garrison-Alexander
The privacy and security implications of AI, big data and predictive analytics
It and-cyber-module-2
Cybersecurity Summit 2020 Slide Deck
What's New In CompTIA Security+ - Course Technology Computing Conference
Qualys user group presentation - vulnerability management - November 2009 v1 3
Recent changes to the 20 critical controls
Leone ct#4 presentation
Overview of the 20 critical controls
More practical insights on the 20 critical controls
Chapter 1 Presentation
Ad

Viewers also liked (13)

PDF
Campa A Animaauna Amiga
PDF
Lindsey Hamilton, Exploring drivers of fecal coliform pollution trends in Sou...
PPTX
Tendencias pedagógicas
PPT
Social media
PDF
Obra cultural resumen de catecismo
PDF
Expresión corporal y creatividad
PDF
Fundamentos de marketing
PDF
Factores de riesgo
PDF
Shipbuilding Industry Final
PPTX
Construindo e realizando o roteiro de plano por
DOC
Limpiando la memoria celular
PPT
MBF Publication
PDF
APRESENTAÇÃO_JMC ENTERPRISES_email
Campa A Animaauna Amiga
Lindsey Hamilton, Exploring drivers of fecal coliform pollution trends in Sou...
Tendencias pedagógicas
Social media
Obra cultural resumen de catecismo
Expresión corporal y creatividad
Fundamentos de marketing
Factores de riesgo
Shipbuilding Industry Final
Construindo e realizando o roteiro de plano por
Limpiando la memoria celular
MBF Publication
APRESENTAÇÃO_JMC ENTERPRISES_email
Ad

Similar to Understanding Technology Stakeholders: Their Progress and Challenges (20)

PPTX
Cyber Security: Threats and Needed Actions
PDF
Embedded Systems Security
PPTX
Lecture 3 Country Specific Strategy.pptx
PPTX
Federal Cybersecurity: The latest challenges, initiatives and best practices
PDF
Soc analyst course content v3
PDF
Soc analyst course content
PPTX
Keynote Information Security days Luxembourg 2015
PPTX
Cyber Crimes: The next five years.
PPTX
2016 to 2021
PPTX
CRI Cyber Board Briefing
PPT
Lecture 4 presentation of cyber security
PPT
Leveraging Purchase Power and Standards to Improve Security in the IT Supply ...
PDF
Today's Cyber Challenges: Methodology to Secure Your Business
PPT
CyberCrime in the Cloud and How to defend Yourself
PPTX
Solving the CIO’s Cybersecurity Dilemma
PDF
ICION 2016 - Cyber Security Governance
PPTX
An introduction to SOC (Security Operation Center)
KEY
Application Security Done Right
PPTX
Cyber security for business
PDF
Vulnerability Management: A Comprehensive Overview
Cyber Security: Threats and Needed Actions
Embedded Systems Security
Lecture 3 Country Specific Strategy.pptx
Federal Cybersecurity: The latest challenges, initiatives and best practices
Soc analyst course content v3
Soc analyst course content
Keynote Information Security days Luxembourg 2015
Cyber Crimes: The next five years.
2016 to 2021
CRI Cyber Board Briefing
Lecture 4 presentation of cyber security
Leveraging Purchase Power and Standards to Improve Security in the IT Supply ...
Today's Cyber Challenges: Methodology to Secure Your Business
CyberCrime in the Cloud and How to defend Yourself
Solving the CIO’s Cybersecurity Dilemma
ICION 2016 - Cyber Security Governance
An introduction to SOC (Security Operation Center)
Application Security Done Right
Cyber security for business
Vulnerability Management: A Comprehensive Overview

More from John Gilligan (8)

PPTX
Practical approaches to address government contracting problems
PPTX
The Economics of Cyber Security
PPTX
Top Level Cyber Security Strategy
PPTX
Automating Enterprise IT Management by Leveraging Security Content Automation...
PDF
Is Cyber Resilience Really That Difficult?
PPTX
Implementing Continuous Monitoring
PPTX
Federal Risk and Authorization Management Program: Assessment and Recommendat...
PPTX
Cybersecurity Priorities and Roadmap: Recommendations to DHS
Practical approaches to address government contracting problems
The Economics of Cyber Security
Top Level Cyber Security Strategy
Automating Enterprise IT Management by Leveraging Security Content Automation...
Is Cyber Resilience Really That Difficult?
Implementing Continuous Monitoring
Federal Risk and Authorization Management Program: Assessment and Recommendat...
Cybersecurity Priorities and Roadmap: Recommendations to DHS

Recently uploaded (20)

PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPT
Teaching material agriculture food technology
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Tartificialntelligence_presentation.pptx
PDF
Encapsulation theory and applications.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
A comparative analysis of optical character recognition models for extracting...
Mobile App Security Testing_ A Comprehensive Guide.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Network Security Unit 5.pdf for BCA BBA.
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Teaching material agriculture food technology
Building Integrated photovoltaic BIPV_UPV.pdf
MIND Revenue Release Quarter 2 2025 Press Release
Spectral efficient network and resource selection model in 5G networks
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Reach Out and Touch Someone: Haptics and Empathic Computing
Group 1 Presentation -Planning and Decision Making .pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Encapsulation_ Review paper, used for researhc scholars
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Tartificialntelligence_presentation.pptx
Encapsulation theory and applications.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?

Understanding Technology Stakeholders: Their Progress and Challenges

  • 1. Understanding Technology Stakeholders: Their Progress and Challenges John M. Gilligan Software Assurance Forum November 4, 2009 1
  • 2. Topics • Historical Perspectives • Cyber Security Threats--A National Crisis • Cyber Security Commission Recommendations • Near Term Opportunities • Longer-Term Game Changing Initiatives • Closing Thoughts 2
  • 3. Historical Perspectives • Internet, software industry, (personal) computers —rooted in creativity not engineering • Security in the Cold War Era – Security “Gurus”—Keepers of the Kingdom • The World Wide Web changes the security landscape-- forever • Post Cold War: The Age of Information Sharing 3Legacy of the past is now our “Achilles Heel”
  • 4. Cyber Security Threats Today— A New “Ball Game” • Our way of life depends on a reliable cyberspace • Intellectual property is being downloaded at an alarming rate • Cyberspace is now a warfare domain • Attacks increasing at an exponential rate • Fundamental network and system vulnerabilities cannot be fixed quickly • Entire industries exist to “Band Aid” over engineering and operational Cyber Security is a National Security Crisis! 4
  • 5. Commission Cyber Security for the 44th Presidency: Key Recommendations • Create a comprehensive national security strategy for cyberspace • Lead from the White House • Reinvent public-private partnerships • Regulate cyberspace • Modernize authorities • Leverage government procurement (Supply Chain Risk Management) • Build on recent progress with CNCI (comprehensive national cyber-security initiative) 5
  • 6. Use Government IT Procurement • Cyber security needs to be reflected in our contractual requirements • Many “locked down” configuration defined • Use government-industry partnership to accelerate implementation of secure configurations • Get started now, improve configuration guidelines over time and leverage SCAP! 6 Build on FDCC Successes and Lessons Learned
  • 7. Longer-Term: IT Reliably Enabling Economy • Change the dialogue: Reliable, resilient IT is fundamental to future National Security and Economic Growth • New business model for software industry • Redesign the Internet • Get the “man out of the loop”—use automated tools (e.g., SCAP) • Develop professional cyberspace workforce • Foster new IT services models Need to Fundamentally “Change the Game” to Make Progress7
  • 8. Security Content Automation Protocol (SCAP) • What is it: A set of open standards that allows for the monitoring, positive control, and reporting of security posture of every device in a network. • How is it implemented: Commercial products implement SCAP protocols to exchange and enforce configuration, security policy, and vulnerability information. • Where is it going: Extensions in development to address software design weaknesses, attack patterns, and malware attributes. 8 SCAP Enables Automated Tools To Implement And Enforce Secure Operations
  • 9. Consensus Audit Guide (CAG) • What is it: 20 key actions (called security “controls”) that organizations must take if they hope to block or mitigate top known attacks. • How is it implemented: (Mostly) automated means used to implement and continuously enforce/monitor controls. Consensus Audit Guidelines permits organizations to prioritize security implementation and continuously enforce controls 9
  • 10. Summary of Ideas for this Technology Working Group • How do we make measurable progress in improving security? • How do we assess the effectiveness of security tools? • How do we change the software industry to produce reliable and secure products? It is time to get off the treadmill and start making measurable progress in securing our systems! 10
  • 11. Closing Thoughts • Government and Industry need to treat cyber security as an urgent priority • Near-term actions important but need to fundamentally change the game to get ahead of threat • IT community needs to reorient the dialogue on cyber security—the objective is reliable and resilient information • Cyber Security in DoD is more mature—but still woefully inadequate 11Cyber Security is Fundamentally a Leadership Issue!