<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
 <title>EDUCAUSE | National Strategy to Secure Cyberspace</title>
 <link>http://connect.educause.edu/browse/content/blog/5245</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/browse/content/blog/5245</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>

  <itunes:subtitle>events, concepts, and conversation from EDUCAUSE</itunes:subtitle>
  <itunes:author>The EDUCAUSE Podcast Crew</itunes:author>
  <itunes:summary>EDUCAUSE is a nonprofit association whose mission is to advance higher education by promoting the intelligent use of information technology.  Our podcasts provide information about a range of topics including Leadership, Policy and Law, Teaching and Learning, Emerging Technologies, Open Source, Research Computing, Cyberinfrastructure, and Digitial Libraries. </itunes:summary>
  <itunes:new-feed-url>http://connect.educause.edu/browse/content/node/691/list/feed</itunes:new-feed-url>
  <itunes:image href="http://connect.educause.edu/educause/images/e_rss.png" />
  <itunes:category text="Education">
  	<itunes:category text="Education Technology"/>
  	<itunes:category text="Higher Education"/>
  </itunes:category>
  <itunes:category text="Technology">
  	<itunes:category text="Tech News"/>
  </itunes:category>

 <description>Recent blog entries tagged with National Strategy to Secure Cyberspace.</description>
 <language>en</language>

<item>
 <title>Soliciting Higher Education Input to the Commission on Cyber Security for the 44th Presidency</title>
 <link>http://connect.educause.edu/display/46370</link>
 <description>&lt;p&gt;The Center for Strategic and International Studies (CSIS) has established a &lt;a href=&quot;http://www.csis.org/media/csis/pubs/cyber_commission_factsheet.pdf&quot;&gt;Commission on Cyber Security for the 44th Presidency&lt;/a&gt; &amp;#8211; the administration that will take office in January 2009.&amp;#160; The goal of the nonpartisan Commission is to develop recommendations for a comprehensive strategy to improve cyber security in federal systems and in critical infrastructure.&lt;/p&gt;&lt;p&gt;The &lt;a href=&quot;http://www.educause.edu/security&quot;&gt;EDUCAUSE/Internet2 Security Task Force&lt;/a&gt; has been invited to provide input to the Commission and welcomes your comments in the following areas:&lt;/p&gt;&lt;ul&gt;	&lt;li&gt;What role has the Federal government played to improve cybersecurity these past few years that has been useful for the higher education sector?&lt;/li&gt;	&lt;li&gt;Are there ways in which the Federal government has hindered progress? If so, please describe.&lt;/li&gt;	&lt;li&gt;Are there new initiatives you would like to see from the Federal government help to improve cybersecurity?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Please comment by &lt;strong&gt;Wednesday, March 12th, 2008&lt;/strong&gt;, by using the &amp;quot;Post new comment&amp;quot; section below or sending your comments to &lt;a href=&quot;mailto:Security-Task-Force@educause.edu&quot;&gt;Security-Task-Force@educause.edu&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/46370#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 06 Mar 2008 15:31:21 -0600</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">46370 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Congress Expresses “Apprehension” About DHS Framework for Cybersecurity</title>
 <link>http://connect.educause.edu/display/45442</link>
 <description>&lt;p&gt;In a hearing before the &lt;a href=&quot;http://hsc.house.gov/&quot;&gt;U.S. House of Representatives Homeland Security Committee&lt;/a&gt; &lt;a href=&quot;http://hsc.house.gov/about/subcommittees.asp?subcommittee=12&quot;&gt;Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology&lt;/a&gt;, subcommittee chair Rep. James R. Langevin (Dem.-RI) said, &amp;#8220;I have great apprehension about the current framework DHS is creating with the sector specific plans (SSP&amp;#8217;s) as they relate to cybersecurity.&amp;#8221;&amp;#160; He continued, &amp;#8220;The Federal government and the American people want to ensure there is a high level of cybersecurity protections on our critical infrastructure.&lt;/p&gt;&lt;p&gt;Dr. Lawrence A. Gordon, a professor from the University of Maryland, &lt;a href=&quot;http://hsc.house.gov/SiteDocuments/20071031155020-22632.pdf&quot;&gt;testified&lt;/a&gt; regarding ways of encouraging investments (i.e., incentives) that are directed at improving cybersecurity in profit-oriented organizations.&amp;#160; &amp;#8220;The most powerful incentive for an organization in the private sector to invest in cybersecurity activities is the motivation to increase the organization&amp;#8217;s value to its owners,&amp;#8221; he said.&amp;#160; &amp;#8220;A fundamental problem in coming up with estimates of the benefits derived from cybersecurity investments is that the most important potential losses are due to unobservable lost customers resulting from cyber breaches and the potential liabilities associated with cyber breaches.&amp;#8221; &amp;#160;Sally Katzen, a visiting professor of law at George Mason University (GMU) and senior consultant to the GMU Critical Infrastructure Protection (CIP) Program, observed in her &lt;a href=&quot;http://hsc.house.gov/SiteDocuments/20071031154853-26197.pdf&quot;&gt;testimony&lt;/a&gt; that the key to addressing cybersecurity both within and across sectors is the integration of various existing standards into Enterprise Risk Management (ERM) principles and techniques.&amp;#160; She remarked, &amp;#8220;ERM shines a light on cyber-CIP risks and all other enterprise risks at very high levels of accountability, including the boardroom.&amp;#8221;&lt;/p&gt;&lt;p&gt;The hearing, &lt;a href=&quot;http://hsc.house.gov/hearings/index.asp?ID=100&quot;&gt;&amp;#8220;Enhancing and Implementing the Cybersecurity Elements of the Sector Specific Plans&amp;#8221;&lt;/a&gt;, was designed to highlight the cyber elements of the &lt;a href=&quot;http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm#2&quot;&gt;plans submitted by the critical infrastructure sectors&lt;/a&gt; as required by the &lt;a href=&quot;http://www.dhs.gov/xprevprot/programs/editorial_0827.shtm&quot;&gt;National Infrastructure Protection Plan&lt;/a&gt;.&amp;#160; Although higher education cyber systems are not considered &amp;#8220;critical infrastructure&amp;#8221; according to the Federal government&amp;#8217;s current framework, the U.S. Department of Education has submitted an SSP on behalf of &amp;#8220;educational facilities&amp;#8221; that references the need to maintain the security of college and university cyber systems.&amp;#160; A &lt;a href=&quot;http://www.gao.gov/new.items/d08113.pdf&quot;&gt;report&lt;/a&gt; issued by the Government Accountability Office concluded that the sector specific plans varied in how comprehensively they addressed the cyber security aspects of their sectors.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45442#comments</comments>
 <category domain="http://connect.educause.edu/tag/critical+infrastructure+protection/5458">critical infrastructure protection</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/DHS/5711">DHS</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 01 Nov 2007 17:01:42 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">45442 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Independent Commission to Examine Cyber Security for the 44th President</title>
 <link>http://connect.educause.edu/display/45437</link>
 <description>&lt;p&gt;Rep. Jim Langevin (Dem.-RI) and Rep. Michael McCaul (Rep.-TX) along with &lt;a href=&quot;http://www.csis.org/&quot;&gt;The Center for Strategic and International Studies (CSIS)&lt;/a&gt; have announced the formation of a bipartisan Commission on Cyber Security for the 44th Presidency &amp;#8211; the administration that will take office in January 2009.&amp;#160; This nonpartisan Commission will develop recommendations for a comprehensive strategy for organizing and prioritizing efforts to secure America&amp;#8217;s computer networks and critical infrastructure.&amp;#160; Rep. Langevin is the chair and Rep. McCaul the ranking member of the &lt;a href=&quot;http://hsc.house.gov/about/subcommittees.asp?subcommittee=12&quot;&gt;Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology&lt;/a&gt; of the &lt;a href=&quot;http://hsc.house.gov/&quot;&gt;Homeland Security Committee&lt;/a&gt; of the &lt;a href=&quot;http://www.house.gov&quot;&gt;U.S. House of Representatives&lt;/a&gt;. Scott Charney, corporate vice president for trustworthy computing at Microsoft and retired Navy Admiral Bobby Inman, Lyndon B. Johnson National Policy Chair at the University of Texas at Austin will co-chair the Commission. &lt;/p&gt;&lt;p&gt;The Commission promises to conduct the most comprehensive review of the issues since the release of the &lt;a href=&quot;http://www.whitehouse.gov/pcipb/&quot;&gt;National Strategy to Secure Cyberspace&lt;/a&gt; in February 2003.&amp;#160; The drafters of the 2003 cybersecurity strategy have been widely criticized for the lack of execution upon the recommendations in the plan, especially given the Federal resources that have been applied to the formation of the National Cyber Security Division in the &lt;a href=&quot;http://www.dhs.gov&quot;&gt;U.S. Department of Homeland Security&lt;/a&gt;.&amp;#160; The &lt;a href=&quot;http://www.educause.edu/security&quot;&gt;EDUCAUSE/Internet2 Security Task Force&lt;/a&gt; prepared the &lt;a href=&quot;http://www.educause.edu/ir/library/pdf/NET0027.pdf&quot;&gt;Higher Education Contribution to the National Strategy to Secure Cyberspace&lt;/a&gt; and expects to work closely with the new Commission to report on both the progress and remaining challenges to addressing cybersecurity at our nation&amp;#8217;s colleges and universities.&lt;/p&gt;&lt;p&gt;Scott Charney, corporate vice president for trustworthy computing at Microsoft and retired Navy Admiral Bobby Inman, Lyndon B. Johnson National Policy Chair at the University of Texas at Austin will co-chair the Commission. &amp;#160; &lt;/p&gt;&lt;p&gt;A &lt;a href=&quot;http://www.house.gov/apps/list/press/ri02_langevin/prCSIS103007.html&quot;&gt;press release&lt;/a&gt; concerning the Commission is available from the offices of Rep. Langevin and Rep. McCaul. &lt;/p&gt;&lt;p&gt;&amp;#160;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45437#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 01 Nov 2007 14:37:01 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">45437 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Inaugural Meeting of Critical Infrastructure Partnership Advisory Council</title>
 <link>http://connect.educause.edu/display/44812</link>
 <description>&lt;p&gt;The &lt;a href=&quot;http://www.dhs.gov/cipac&quot;&gt;Critical Infrastructure Partnership Advisory Council (CIPAC)&lt;/a&gt; held its first open session since its establishment in March of 2006.&amp;#160; The CIPAC, co-chaired by Robert B. Stephan, Assistant Secretary for Infrastructure Protection in the U.S. Department of Homeland Security, and Michael Wallace, President of the Constellation Generation Group, represents a partnership between government and critical infrastructure/key resource (CI/KR) owners and operators and provides a forum in which they can engage in a broad spectrum of activities to support and coordinate critical infrastructure protection.&lt;/p&gt;&lt;p&gt; Among the charges for the CIPAC is implementation of the National Infrastructure Protection Plan (NIPP) that establishes a Risk Management Framework for addressing human, physical, and cyber risks.&amp;#160; Although higher education is not specifically identified as a critical infrastructure, the &amp;#8220;cyber risk&amp;#8221; components of the NIPP are the equivalent concerns that are addressed by the EDUCAUSE/Internet2 Computer and Network Security Task Force.&amp;#160; The Security Task Force collaborates closely with the Communications Sector and Information Technology Sectors, who are represented in the CIPAC, because of their focus and expertise on cybersecurity matters.&amp;#160; Additionally, the Security Task Force is represented on the Cross-Sector Cyber Security Working Group which is working closely with all of the CI/KR owners and operators.&lt;/p&gt;&lt;p&gt; More information about the CIPAC, including the agenda and presentations from the inaugural plenary meeting, is available at &lt;a href=&quot;http://www.dhs.gov/cipac&quot;&gt;http://www.dhs.gov/cipac&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44812#comments</comments>
 <category domain="http://connect.educause.edu/tag/critical+infrastructure+protection/5458">critical infrastructure protection</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law%3A+Federal/101">Policy and Law: Federal</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Tue, 24 Jul 2007 17:51:24 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">44812 at http://connect.educause.edu</guid>
</item>
<item>
 <title>DHS on Its Own Cybersecurity:  &quot;Do As I Say, Not As I Do&quot;</title>
 <link>http://connect.educause.edu/display/44538</link>
 <description>&lt;p&gt;The Emerging Threats, Cybersecurity, and Science and Technology Subcommittee of the Homeland Security Committee in the U.S. House of Representatives held a hearing yesterday on the topic of &amp;#8220;Hacking the Homeland: Investigating Cybersecurity Vulnerabilities at the Department of Homeland Security&amp;#8221;. Chairman Rep. James Langevin (Dem-RI) commented, &amp;quot;It was a shock and disappointment to learn that the Department of Homeland Security - the agency charged with being the &lt;em&gt;lead&lt;/em&gt; in our national cybersecurity - has suffered so many significant security incidents on its networks.&amp;quot;&lt;/p&gt;&lt;p&gt;The full committee chairman, Rep. Bennie Thompson (Dem-Miss), asked:&lt;/p&gt;	&lt;p&gt;How can the Department of Homeland Security be a real advocate for sound cybersecurity practices without following some of its own advice?&amp;#160; How can we expect improvements in private infrastructure cyberdefense when DHS bureaucrats aren&amp;#8217;t fixing their own configurations? How can we ask others to invest in upgraded security technologies when the Chief Information Officer grows the Department&amp;#8217;s IT security budget at a snail&amp;#8217;s pace?&amp;#160; How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified emails over unclassified networks and contractors to attach unapproved laptops to the network?&amp;#160;&lt;/p&gt;&lt;p&gt;Witnesses which included the CIO from DHS and representatives of the Government Accountability Office were cautious to acknowledge that progress is being made despite shortcomings in DHS information security program. Rep. Thompson remarked, &amp;quot;The American people are tired of hearing that getting a &#039;D&#039; is a security improvement,&amp;quot; referring to the recent &lt;a href=&quot;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&quot; title=&quot;http://republicans.oversight.house.gov/Media/PDFs/FY06FISMA.pdf&quot;&gt;Annual Report Card on Computer Security for Federal Departments and Agencies&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;More information regarding the hearing, including witness testimony and a recorded webcast, is available at &lt;a href=&quot;http://homeland.house.gov/hearings/index.asp?ID=65&quot; title=&quot;http://homeland.house.gov/hearings/index.asp?ID=65&quot;&gt;http://homeland.house.gov/hearings/index.asp?ID=65&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44538#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Department+of+Homeland+Security/2000">Department of Homeland Security</category>
 <category domain="http://connect.educause.edu/tag/Federal+Policy/943">Federal Policy</category>
 <category domain="http://connect.educause.edu/tag/National+Strategy+to+Secure+Cyberspace/5245">National Strategy to Secure Cyberspace</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Thu, 21 Jun 2007 09:28:04 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">44538 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
