Threat Level: green Handler on Duty: Tom Webb

SANS ISC: Hey, what is with all the Government and Private Industry sharing wrt cybersecurity? - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Hey, what is with all the Government and Private Industry sharing wrt cybersecurity?

Seriously, its a good trend and should be encouraged.
Here are two efforts that recently came to my attention.

DOD is launching a program that will send members of their IT teams to industry to improve the government's IT expertise particularly in cyber security.
http://www.washingtonpost.com/wp-dyn/content/article/2010/12/30/AR2010123003292_pf.html

Estonia is building a Cyber Defense League with private sector cyber defense experts and government agencies.
http://www.npr.org/2011/01/04/132634099/in-estonia-volunteer-cyber-army-defends-nation?sc=tw&cc=share


I have been involved in several similar efforts in the past and while not all produced the desired results IMO such sharing benefits the parties involved. Private industry has people that, as part of their day to day job, watch for cyber security threats and trends. Government agencies have personal with the similar responsibilities and similar abilities.

Both have different views into various portions of "cyber land" and may see different things at different times but eventually will probably see whatever the other is seeing. Sharing that type of information just makes sense. The "bad guys" share. If the good guys don't we will always be one step behind them.

Other Government and private industry cyber security sharing forums in no particular order include but are NOT limited to:


nsp-security, ops-trust, infragard, NCFTA, ICASI, ISACS,  and many others.

http://www.ncfta.net/about-ncfta

"Since 1997, the NCFTA, a non-profit corporation, evolved from one of the nation’s first High Tech Task Forces and has established an expansive alliance between subject matter experts (SMEs) in the public and private sectors (more than 500 worldwide) with the goal of addressing complex and often internationally-spawned cyber crimes. These SMEs, from industry, academia and government, each bring specific talents and experiences to the partnership. Through a steady cycling of such cross-sector national and international resources, both embedded at the NCFTA and through initiative-specific intelligence channels, the NCFTA is well positioned to adapt and regularly reinvent itself to better address today’s evolving threat landscape."

http://puck.nether.net/mailman/listinfo/nsp-security

"The nsp-security [NSP-SEC] forum is a volunteer incident response mailing list, which coordinates the interaction between ISPs and NSPs in near real-time and tracks exploits and compromised systems as well as mitigates the effects of those exploits on ISP networks. The list has helped mitigate attacks and will continue to do so."

https://ops-trust.net/

"OPSEC-Trust (or "ops-trust") is a highly vetted community of security professionals focusing on the operational robustness, integrity, and security of the Internet. The community promotes mindful action against malicious behavior vs observation/analysis/research. OPSEC Trust carefully expands membership pulling from talent in many other security forums looking for strong vetting with in three areas ; sphere of trust, sphere of action, and the ability to maintain a "need to know" confidentiality. OPSEC-Trust (or "ops-trust") members are in a position to directly affect Internet security operations in some meaningful way. The community's members span the breath of the industry including service providers, equipment vendors, financial institutions, mail admins, DNS admins, and DNS registrars, content hosting providers, law enforcement organizations/agencies, CSIRT Teams, and third party organizations that provide security-related services for public benefit (e.g. monitoring or filtering service providers). The breadth of membership, along with a an action/trust vetting approach provides creates a community which would be in a position to apply focused attention on the malfeasant behaviors which threaten the Internet."

http://www.infragard.net/

InfraGard is an information sharing and analysis effort serving the interests and combining the knowledge base of a wide range of members. At its most basic level, InfraGard is a partnership between the Federal Bureau of Investigation and the private sector. InfraGard is an association of businesses, academic institutions, state and local law enforcement agencies, and other participants dedicated to sharing information and intelligence to prevent hostile acts against the United States.

http://www.icasi.org/

The Industry Consortium for Advancement of Security on the Internet (ICASI) is a forum of trust through which IT industry leaders address multi-product security challenges to better protect the IT infrastructures that support the world’s enterprises, governments, and citizens.

 


A few articles about Government and private sector sharing wrt cybersecurity intel:

http://www.enisa.europa.eu/act/sr/reports/econ-sec
http://www.nationaljournal.com/njmagazine/id_20090502_5834.php

http://gcn.com/Articles/2006/08/16/Sharing-data-is-crucial-to-cyberdefense.aspx?Page=2

http://www.dailyherald.com/article/20101227/news/101229642/

http://www.ncs.gov/nstac/reports/2009/NSTAC%20CCTF%20Report.pdf

 

If you know of any other good sharing being done feel free to add comments to this diary to educate everyone.

donald

206 Posts
ISC Handler
There are a series of industry-specific Information Sharing and Analysis Centers (ISACs) which were created to facilitate the sharing of security information between government and private sector organizations. You can see a list of them here: http://www.isaccouncil.org
Anonymous
Anyone know of anything similar in Australia? I work for a semi-gov org (state owned enterprise I guess would be the best way of describing us). Would be good to start talking to others in the field, there is general IT Security things like AISA but can't be terribly open there.
Raymond

14 Posts

Sign Up for Free or Log In to start participating in the conversation!