Information as Battlespace

August 6, 2001, 11:00 PM —  ITworld — 

At the last National Information Systems Security Conference, Lt.
General Michael Hayden, director of the National Security Agency and
chief of the Central Security Service, made some interesting and
thought-provoking remarks in a keynote address.

Titled "The Evolution of Information Assurance: Transformation of the
NSA's Information Assurance Mission," the address featured comments
that I hope readers will be able to use to sensitize their colleagues,
and especially upper management, to how serious information security
has become in our networked society.

According to the speaker, the agency's thought processes have been
evolving. They started historically with communications security,
looking almost exclusively at military systems. Next, they moved to
information security, and the focus moved from output to outcome. They
then expanded their view to emphasize information assurance, detecting
and reacting to attacks against our information systems.

The agency's current mantra is that it must gain, exploit, defend and
attack information. Information has become a battlespace, just like
land, sea and air. The NSA now offers a number of services, including
evaluation or assessment, and research and development in
identification and authentication, such as biometrics. However, the NSA
is no longer the main provider or center of security research and
development; it is cooperating with the private sector.

In the past, military IT security specialists used the notion of a
perimeter defense; today, however, we operate on a network of networks.
During the air war over Kosovo and Serbia, our information for that
operation resided and traveled over the same global network as that of
our enemies. Adversaries are therefore no longer nation-states alone;
we are also threatened by malicious (and even nonmalicious) hackers.

What would an American response to an information-operations attack
involve? It could be a passive defense, just recovering from the
damage, or we could involve law enforcement. But military strategists
can also envisage a counterattack, either by physical attack or
cyberattack. In such a situation, communications security and signals
intelligence become blended and blurred.

The military can't respond effectively to cyberattack without
cooperation with the private sector. The U.S. Air Force, in one sense,
is the security expression of the civilian aircraft industry.
Similarly, the NSA may be developing into the security expression of
the civilian telecommunications industry.

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
peer-to-peer

Brian Proffitt
Microsoft/Novell: Breaking Down the Coupon Numbers

Esther Schindler
Drupal's Dries Buytaert on Building the Next Drupal

Tom Henderson
Top Ten General Operating Systems Rants

pasmith
PS3 motion controller delayed; goes up against Project Natal

sjvn
Neolithic Windows security hole alive and well in Windows 7

claird
Perl source code comparison makes for good reading

mikelgan
Cell phones don't create stress or interrupt much

Sandra Henry-Stocker
How to: The Unix Interview

 

Where Google Chrome security fails: the password
I heard mention that the Chrome OS will have some sort of encryption available a la bitlocker. If it's possible to encrypt personal data using another password or key, then it may have potential for very secure data.... And Ubuntu has an 'encrypt home directory' option, perhaps google should follow suit.
- Dann

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Marketplace