Cybersecurity: Authoritative Reports and Resources, by Topic

Congressional research reportJun 10, 2015

Ask Donna

What actually matters in this document.

Text

.

Cybersecurity: Authoritative Reports and

Resources, by Topic

Rita Tehan

Information Research Specialist

June 10, 2015

Congressional Research Service

7-5700

www.crs.gov

R42507

c11173008

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Summary

This report provides references to analytical reports on cybersecurity from CRS, other

government agencies, trade associations, and interest groups. The reports and related websites are

grouped under the following cybersecurity topics:

•

•

•

•

•

•

•

•

•

Policy overview

National Strategy for Trusted Identities in Cyberspace (NSTIC)

Cloud computing and the Federal Risk and Authorization Management Program

(FedRAMP)

Critical infrastructure

Cybercrime, data breaches, and data security

National security, cyber espionage, and cyberwar (including Stuxnet)

International efforts

Education/training/workforce

Research and development (R&D)

In addition, the report lists selected cybersecurity-related websites for congressional and

government agencies; news; international organizations; and other organizations, associations,

and institutions.

c11173008

Congressional Research Service

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Contents

CRS Reports, by Topic .................................................................................................................... 1

Cybersecurity Policy: CRS Reports and Other CRS Products .................................................. 1

Critical Infrastructure: CRS Reports ....................................................................................... 16

Cybercrime and Data Security: CRS Reports and Other CRS Products ................................. 34

Selected Reports, by Federal Agency ............................................................................................ 92

Department of Defense and National Security: CRS Reports and Other CRS Products ....... 109

CRS Product: Cybersecurity Framework .............................................................................. 116

Related Resources: Other Websites ............................................................................................. 138

Tables

Table 1. Cybersecurity Overview .................................................................................................... 2

Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC) ...................................... 8

Table 3. Cloud Computing, “The Internet of Things,” and FedRAMP ........................................ 10

Table 4. Critical Infrastructure ....................................................................................................... 17

Table 5. Cybercrime, Data Breaches, and Data Security ............................................................... 35

Table 6. National Security, Cyber Espionage, and Cyberwar ........................................................ 47

Table 7. International Efforts ......................................................................................................... 59

Table 8. Education/Training/Workforce......................................................................................... 77

Table 9. Research and Development (R&D) ................................................................................. 86

Table 10. Government Accountability Office (GAO) .................................................................... 92

Table 11. White House and Office of Management and Budget.................................................. 104

Table 12. Department of Defense (DOD) .................................................................................... 110

Table 13. National Institute of Standards and Technology (NIST) .............................................. 117

Table 14. Other Federal Agencies ................................................................................................ 122

Table 15. State, Local, and Tribal Governments .......................................................................... 134

Table 16. Related Resources: Congressional and Government ................................................... 138

Table 17. Related Resources: International Organizations .......................................................... 140

Table 18. Related Resources: News ............................................................................................. 141

Table 19. Related Resources: Other Associations and Institutions .............................................. 141

Contacts

Author Contact Information......................................................................................................... 143

Key Policy Staff ........................................................................................................................... 143

c11173008

Congressional Research Service

Cybersecurity: Authoritative Reports and Resources, by Topic

.

CRS Reports, by Topic1

This section provides references to analytical reports on cybersecurity from CRS, other

government agencies, think tanks, trade associations, trade press, and technology research firms.

For each topic, CRS reports are listed first, followed by tables with reports from other

organizations.

Cybersecurity Policy: CRS Reports and Other CRS Products

•

•

•

•

•

•

•

•

•

•

•

•

CRS Report R43831, Cybersecurity Issues and Challenges: In Brief, by Eric A.

Fischer

CRS Report IF10001, Cybersecurity Issues and Challenges, by Eric A. Fischer

CRS Report R42114, Federal Laws Relating to Cybersecurity: Overview of

Major Issues, Current Laws, and Proposed Legislation, by Eric A. Fischer

CRS Report R43941, Cybersecurity and Information Sharing: Legal Challenges

and Solutions, by Andrew Nolan

CRS Report R41941, The Obama Administration’s Cybersecurity Proposal:

Criminal Provisions, by Gina Stevens

CRS Report R42984, The 2013 Cybersecurity Executive Order: Overview and

Considerations for Congress, by Eric A. Fischer et al.

CRS Report R40150, A Federal Chief Technology Officer in the Obama

Administration: Options and Issues for Consideration, by John F. Sargent Jr.

CRS Report R42409, Cybersecurity: Selected Legal Issues, by Edward C. Liu et

al.

CRS Report R42887, Overview and Issues for Implementation of the Federal

Cloud Computing Initiative: Implications for Federal Information Technology

Reform Management, by Patricia Moloney Figliola and Eric A. Fischer

CRS Report R43015, Cloud Computing: Constitutional and Statutory Privacy

Protections, by Richard M. Thompson II

CRS Legal Sidebar WSLG478, House Intelligence Committee Marks Up

Cybersecurity Bill CISPA, by Richard M. Thompson II

CRS Legal Sidebar WSLG263, Can the President Deal with Cybersecurity Issues

via Executive Order?, by Vivian S. Chu

1

For information on legislation and hearings in the 112th and 113th Congresses, see CRS Report R43317,

Cybersecurity: Legislation, Hearings, and Executive Branch Documents, by Rita Tehan.

c11173008

Congressional Research Service

1

.

Table 1. Cybersecurity Overview

Title

Date

Pages

Notes

Cyber Threat Information Sharing:

Recommendations for Congress and the

Administration

Center for Strategic and

International Studies

March 10, 2015

18

The success of the president’s executive order

promoting cyberthreat information sharing depends on

legislation passing Congress. The report recommends

that legislation should not be one-size-fits-all; have a

minimal role for government; build on existing

information sharing; streamline mechanisms to share

info; add value for all parties participating; protect

information shared from FOIA requests, litigation or

regulatory enforcement; and protect organizations from

civil and criminal liability for monitoring and sharing on

cyberthreats if done in good faith.

The Emergence of Cybersecurity Law

Indiana University Maurer

School of Law

February 2015

31

This paper examines cyberlaw as a growing field of legal

practice and the roles that lawyers play in helping

companies respond to cybersecurity threats. Drawing on

interviews with lawyers, consultants, and academics

knowledgeable in the intersection of law and

cybersecurity, as well as a survey of lawyers working in

general counsel’s offices, this study examines the broader

context of cybersecurity, the current legal framework for

data security and related issues, and the ways in which

lawyers learn about and involve themselves in

cybersecurity issues.

OMG Cyber! Thirteen Reasons Why Hype

Makes for Bad Policy

The RUSI Journal

November 4, 2014

8

The article argues that cyber is “hyped out.” Overstating

the threat does have benefits (for some); it also comes

with significant costs. The benefits are short-lived and

easy to spot, whereas the costs are long-term and harder

to understand—and they are piling up fast and high.

Indeed, the costs are so high that the debate inches

toward a turning point for all parties involved. The

authors list 13 reasons why cybersecurity hype is

counterproductive.

CRS-2

c11173008

Source

.

Title

Source

Date

Pages

Ten Strategies of a World-Class Cybersecurity

Operations Center

MITRE Corporation

October 2014

346

All too often, cybersecurity operations centers (CSOCs)

are set up and operate with a focus on technology

without adequately addressing people and process issues.

The main premise of this book is that a more balanced

approach would be more effective. The book describes

the 10 strategies of effective CSOCs—regardless of their

size, offered capabilities, or type of constituency served

cost.

How Do We Know What Information Sharing

Is Really Worth? Exploring Methodologies to

Measure the Value of Information Sharing and

Fusion Efforts

RAND Corporation

June 27, 2014

33

Since the terrorist attacks of September 11, 2001, the

sharing of intelligence and law enforcement information

has been a central part of U.S. domestic security efforts.

Although much of the public debate about such sharing

focuses on addressing the threat of terrorism,

organizations at all levels of government routinely share

varied types of information through multiagency

information systems, collaborative groups, and other

links. Resource constraints have given rise to concerns

about the effectiveness of information sharing and fusion

activities and, therefore, the value of these efforts

relative to the public funds invested in them. Solid

methods for evaluating these efforts are lacking,

however, limiting the ability to make informed policy

decisions. Drawing on a substantial literature review and

synthesis, this report lays out the challenges of evaluating

information-sharing efforts that frequently seek to

achieve multiple goals simultaneously; reviews past

evaluations of information-sharing programs; and lays out

a path to improve the evaluation of such efforts going

forward.

Defending an Open, Global, Secure, and

Resilient Internet

Council on Foreign Relations

June 2013

127

The task force recommends that the United States

develop a digital policy framework based on four pillars,

the last of which is that U.S.-based industry work rapidly

to establish an industry-led approach to counter current

and future cyberattacks.

CRS-3

c11173008

Notes

.

Title

Source

Measuring What Matters: Reducing Risk by

Rethinking How We Evaluate Cybersecurity

Safegov.org, in coordination

with the National Academy of

Public Administration

March 2013

39

This report recommends that rather than periodically

auditing whether an agency’s systems meet the standards

enumerated in the Federal Information Security

Management Act (FISMA) at a static moment in time,

agencies and their inspectors general should keep

running scorecards of “cyber risk indicators” based on

continual inspector general assessments of a federal

organization’s cyber vulnerabilities.

Developing a Framework to Improve Critical

Infrastructure Cybersecurity (Federal Register

Notice; Request for Information)

National Institute of Standards

and Technology (NIST)

February 12, 2013

5

NIST announced the first step in the development of a

cybersecurity framework, which will be a set of voluntary

standards and best practices to guide industry in reducing

cyber risks to the networks and computers that are vital

to the nation’s economy, security, and daily life.

SEI [Software Engineering Institute] Emerging

Technology Center: Cyber Intelligence

Tradecraft Project

Carnegie Mellon University

January 2013

23

This report addresses the endemic problem of functional

cyber intelligence analysts not effectively communicating

with nontechnical audiences. It also notes organizations’

reluctance to share information within their own entities,

industries, and across economic sectors.

The National Cyber Security Framework

Manual

NATO Cooperative Cyber

Defense Center of Excellence

December 11, 2012

253

This report provides detailed background information

and in-depth theoretical frameworks to help the reader

understand the various facets of national cybersecurity,

according to different levels of public policy formulation.

The four levels of government—political, strategic,

operational, and tactical/technical—each have their own

perspectives on national cybersecurity, and each is

addressed in individual sections within the manual.

20 Critical Security Controls for Effective

Cyber Defense

Center for Strategic and

International Studies (CSIS)

November 2012

89

The top 20 security controls from a public-private

consortium. Members of the consortium include the

National Security Agency, U.S. Computer Emergency

Readiness Team, Department of Defense (DOD) Joint

Task Force-Global Network Operations, Department of

Energy Nuclear Laboratories, Department of State, and

DOD Cyber Crime Center plus commercial forensics

experts in the banking and critical infrastructure

communities.

CRS-4

c11173008

Date

Pages

Notes

.

Title

Date

Pages

Notes

Cyber Security Task Force: Public-Private

Information Sharing

Bipartisan Policy Center

July 2012

24

Outlines a series of proposals that would enhance

information sharing. The recommendations have two

major components: (1) mitigating perceived legal

impediments to information sharing, and (2) incentivizing

private sector information sharing by alleviating statutory

and regulatory obstacles.

Cyber-security: The Vexed Question of Global

Rules

McAfee and the Security

Defense Agenda

February 2012

108

This independent report examines the current state of

cyber-preparedness around the world and is based on

survey results from 80 policymakers and cybersecurity

experts in the government, business, and academic

sectors from 27 countries. The countries were ranked

on their state of cyber-preparedness.

Mission Critical: A Public-Private Strategy for

Effective Cybersecurity

Business Roundtable

October 11, 2011

28

The report suggests that “[p]ublic policy solutions must

recognize the absolute importance of leveraging policy

foundations that support effective global risk

management, in contrast to ‘check-the-box’ compliance

approaches that can undermine security and

cooperation.” The document concludes with specific

policy proposals and activity commitments.

World Cybersecurity Technology Research

Summit (Belfast 2011)

Centre for Secure Information

Technologies (CSIT)

September 12, 2011

14

The Belfast 2011 event attracted international

cybersecurity experts from leading research institutes,

government bodies, and industry who gathered to

discuss current cybersecurity threats, predict future

threats and necessary mitigation techniques, and develop

a collective strategy for further research.

A Review of Frequently Used Cyber Analogies

National Security Cyberspace

Institute

July 22, 2011

7

From the report: “The current cybersecurity crisis can

be described several ways with numerous metaphors.

Many compare the current crisis with the lawlessness to

that of the Wild West and the out-dated tactics and race

to security with the Cold War. When treated as a

distressed ecosystem, the work of both national and

international agencies to eradicate many infectious

diseases serves as a model as how poor health can be

corrected with proper resources and execution. Before

these issues are discussed, what cyberspace actually is

must be identified.”

CRS-5

c11173008

Source

.

Title

Date

Pages

Notes

America’s Cyber Future: Security and

Prosperity in the Information Age

Center for a New American

Security

May 31, 2011

296

To help U.S. policymakers address the growing danger of

cyber insecurity, this two-volume report features

chapters on cybersecurity strategy, policy, and

technology by some of the world’s leading experts on

international relations, national security, and information

technology.

Resilience of the Internet Interconnection

Ecosystem

European Network and

Information Security Agency

(ENISA)

April 11, 2011

238

This study consists of several parts. Part I provides a

summary and recommendations. Part II: State of the Art

Review offers a detailed description of the Internet’s

routing mechanisms and an analysis of their robustness at

the technical, economic, and policy levels. Part III: Report

on the Consultation reports and summarizes the results

of consultation with a broad range of stakeholders. Part

IV includes the bibliography and appendices.

Improving our Nation’s Cybersecurity through

the Public-Private Partnership: A White Paper

Business Software Alliance,

Center for Democracy and

Technology, U.S. Chamber of

Commerce, Internet Security

Alliance, and Tech America

March 8, 2011

26

This paper proposes expanding the existing partnership

within the framework of the National Infrastructure

Protection Plan. Specifically, it makes a series of

recommendations that build upon the conclusions of

President Obama’s Cyberspace Policy Review.

Cybersecurity Two Years Later

CSIS Commission on

Cybersecurity for the 44th

Presidency

January 2011

22

From the report: “We thought then [in 2008] that

securing cyberspace had become a critical challenge for

national security, which our nation was not prepared to

meet.... In our view, we are still not prepared.”

Toward Better Usability, Security, and Privacy

of Information Technology: Report of a

Workshop

National Research Council

(NRC)

September 21, 2010

70

The report discusses computer system security and

privacy, their relationship to usability, and research at

their intersection. It is drawn from remarks made at the

NRC’s July 2009 Workshop on Usability, Security and

Privacy of Computer Systems as well as reports from the

NRC’s Computer Science and Telecommunications

Board on security and privacy.

CRS-6

c11173008

Source

.

Title

National Security Threats in Cyberspace

Source

Date

Pages

Joint Workshop of the

National Security Threats in

Cyberspace and the National

Strategy Forum

September 15, 2009

37

Source: Highlights compiled by the Congressional Research Service (CRS) from the reports.

CRS-7

c11173008

Notes

The two-day workshop brought together more than two

dozen experts with diverse backgrounds, including

physicists; telecommunications executives; Silicon Valley

entrepreneurs; federal law enforcement, military,

homeland security, and intelligence officials;

congressional staffers; and civil liberties advocates.

Participants engaged in an open-ended discussion of

cyber policy as it relates to national security, under

Chatham House Rules: their comments were for the

public record, but they were not for attribution.

.

Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC)

Title

Date

Pages

Notes

National Strategy for Trusted Identities in Cyberspace

(NSTIC)

National

Institute of

Standards

and

Technology

(NIST)

Ongoing

N/A

The NSTIC pilot projects seek to catalyze a marketplace of

online identity solutions that ensures the envisioned Identity

Ecosystem is trustworthy and has the confidence of individuals.

Using privacy-enhancing architectures in real-world

environments, the pilots are testing new methods for

identification online for consumers that increase usability,

security, and interoperability to safeguard online transactions.

Identity Ecosystem Framework Steering Group (IDESG)

IDESG

Ongoing

N/A

The NSTIC called for the establishment of a private sector-led

steering group to administer the development and adoption of

the Identity Ecosystem Framework: the IDESG. The IDESG

receives its authority to operate from the active participation of

its membership in accordance with the rules of association that

follow. The IDESG has been initiated with the support of the

NIST. Following an initial period, the IDESG will transition to a

self-sustaining organization.

NSTIC Pilots: Catalyzing the Identity Ecosystem

NIST

April 2015

68

Since 2012, the NSTIC has awarded approximately $30 million

to pilot projects for shaping the identity ecosystem (a system

for consumers to create online identities). The study finds

common themes, including: the opportunity for increased

revenue, emerging identities architecture, and standards and

interoperability.

NIST Announces Pilot Grants Competition to Improve

Security and Privacy of Online Identity Verification

Systems

NIST

February 12,

2015

N/A

NIST announces a fourth round of grants meant to create

market conditions for a post-password world. The agency says

it anticipates funding several projects with awards of

approximately $1 million to $2 million over two years through

its NSTIC program. Administration officials say the NSTIC end

goal is creation of an “identity ecosystem” that allows

Americans to safely conduct online transactions under a variety

of security and privacy settings.

NIST Awards Grants to Improve Online Security and

Privacy

NIST

September 17,

2013

N/A

NIST announced more than $7 million in grants to support the

NSTIC. The funding will enable five U.S. organizations to

develop pilot identity protection and verification systems that

offer consumers more privacy, security, and convenience online.

CRS-8

c11173008

Source

.

Title

Source

Date

Pages

Notes

Five Pilot Projects Receive Grants to Promote Online

Security and Privacy

NIST

September 20,

2012

N/A

NIST announced more than $9 million in grant awards to

support the NSTIC. Five U.S. organizations will pilot identity

solutions that increase confidence in online transactions,

prevent identity theft, and provide individuals with more control

over how they share their personal information.

Recommendations for Establishing an Identity Ecosystem

Governance Structure

NIST

February 17,

2012

51

NIST responds to comments received in response to the

related notice of inquiry (NOI) published in the Federal Register

on June 14, 2011. This report summarizes the responses to the

NOI and provides recommendations and intended government

actions to serve as a catalyst for establishing such a governance

structure. The recommendations result from comments and

suggestions by the NOI respondents as well as best practices

and lessons learned from similarly scoped governance efforts.

Models for a Governance Structure for the National

Strategy for Trusted Identities in Cyberspace

NIST

June 14, 2011

4

The department seeks public comment on potential models

from all stakeholders, including the commercial, academic and

civil society sectors, and consumer and privacy advocates, in the

form of recommendations and key assumptions in the formation

and structure of the steering group.

Administration Releases Strategy to Protect Online

Consumers and Support Innovation and Fact Sheet on

National Strategy for Trusted Identities in Cyberspace

White

House

April 15, 2011

N/A

Press release on a proposal to administer the processes for

policy and standards adoption for the Identity Ecosystem

Framework in accordance with the NSTIC.

National Strategy for Trusted Identities in Cyberspace

White

House

April 15, 2011

52

The NSTIC aims to make online transactions more trustworthy,

thereby giving businesses and consumers more confidence in

conducting business online.

National Strategy for Trusted Identities in Cyberspace:

Creating Options for Enhanced Online Security and Privacy

White

House

June 25, 2010

39

The NSTIC, which is in response to one of the near-term action

items in the President’s Cyberspace Policy Review, calls for the

creation of an online environment, or an identity ecosystem, in

which individuals and organizations can complete online

transactions with confidence, trusting the identities of each

other and of the infrastructure in which transactions occur.

Source: Highlights compiled by CRS from the reports.

CRS-9

c11173008

.

Table 3. Cloud Computing, “The Internet of Things,”

and FedRAMP

Title

Date

About FedRAMP

General Services

Administration (GSA)

Ongoing

Formation of the Office of Technology Research and

Investigation (OTRI)

Federal Trade Commission

(FTC)

March 23, 2015

Insecurity in the Internet of Things (IoT)

Symantec

March 12, 2015

CRS-10

c11173008

Source

Pages

Notes

N/A

The Federal Risk and Authorization Management

Program (FedRAMP) is a government-wide program

that provides a standardized approach to security

assessment, authorization, and continuous monitoring

for cloud products and services.

The OTRI will provide expert research, investigative

techniques, and further insights to the agency on

technology issues involving all facets of the FTC’s

consumer protection mission, including privacy, data

security, connected cars, smart homes, algorithmic

transparency, emerging payment methods, big data,

and the Internet of Things.

Like the former Mobile Technology Unit (MTU), the

new office will be housed in the Bureau of Consumer

Protection and is the agency’s latest effort to ensure

that its core consumer protection mission keeps

pace with the rapidly evolving digital economy.

Kristin Cohen, the current chief of the MTU, will lead

the work of the OTRI.

20

Symantec analyzed 50 smart home devices that are

available today and found that none of the devices

enforced strong passwords, used mutual

authentication, or protected accounts against bruteforce attacks. Almost 2 out of 10 of the mobile apps

used to control the tested IoT devices did not use

Secure Sockets Layer (SSL) to encrypt

communications to the cloud. The tested IoT

technology also contained many common

vulnerabilities.

.

Title

Date

Pages

Notes

FedRAMP High Baseline

GSA

February 3,

2015

N/A

GSA released a draft of security controls it will

require for cloud-computer systems purchased by

federal agencies for “high-impact” uses. High-impact

data will likely consist of health and law-enforcement

data, but not classified information. Cloud computing

vendors seeking to sell to federal agencies currently

must get security accreditation through FedRAMP.

To date, FedRAMP has offered accreditations up to

the “moderate-impact” level. About 80% of federal IT

systems are low- and moderate-impact.

What is The Internet of Things?

(free; registration required)

O’Reilly Media

January 2015

32

Ubiquitous connectivity is meeting the era of data.

Since working with large quantities of data became

dramatically cheaper and easier a few years ago,

everything that touches software has become

instrumented and optimized. Finance, advertising,

retail, logistics, academia, and practically every other

discipline has sought to measure, model, and tweak

its way to efficiency. Software can ingest data from

lots of inputs, interpret it, and then issue commands

in real time.

FedRAMP Forward: 2 Year Priorities

GSA

December 17,

2014

14

The report addresses how the program will develop

over the next two years. GSA is focusing on three

goals for FedRAMP: increased compliance and agency

participation, improved efficiencies, and continued

adaptation.

The Internet of Things: 2014 OECD Tech Insight Forum

OECD

December 11,

2014

N/A

The Internet of Things extends internet connectivity

beyond traditional machines like computers,

smartphones and tablets to a diverse range of everyday devices that use embedded technology to

interact with the environment, all via the Internet.

How can this collected data be used? What new

opportunities will this create for employment and

economic growth? How can societies benefit from

technical developments to health, transport, safety

and security, business and public services? The

OECD Technology Foresight Forum facilitated

discussion on what policies and practices will enable

or inhibit the ability of economies to seize the

benefits of the Internet of Things.

CRS-11

c11173008

Source

.

Title

Source

DOD Cloud Computing Strategy Needs Implementation

Plan and Detailed Waiver Process

Department of Defense

(DOD) Inspector General

NSTAC Report to the President on the Internet of

Things

Pages

Notes

December 4,

2014

40

Report states that the DOD chief information officer

“did not develop an implementation plan that

assigned roles and responsibilities as well as

associated tasks, resources and milestones,” despite

promises that an implementation plan would directly

follow the cloud strategy’s release.

President's National

Security

Telecommunications

Advisory Committee

November 18,

2014

56

The NSTAC unanimously approved a

recommendation that governmental Internet traffic

could get priority transmission during emergencies.

The government already gets emergency priority in

more traditional communications networks like the

‘phone system through programs such as the

Government Emergency Telecommunications Service

— now NSTAC is proposing a GETS for the Internet.

The Department of Energy’s Management of Cloud

Computing Activities: Audit Report

Department of Energy

(DOE) Inspector General

September 1,

2014

20

DOE should do a better job buying, implementing

and managing its cloud computing services. Programs

and sites department-wide have independently spent

more than $30 million on cloud services, the

inspector general report said, but the chief

information officer’s office could not accurately

account for the money.

Cloud Computing: The Concept, Impacts, and the Role

of Government Policy

Organization for Economic

Co-operation and

Development (OECD)

August 19, 2014

240

This report gives a clear overview of cloud

computing, presenting the concept, the services it

provides, and deployment models. It provides an

overview of how cloud computing changes the way

computing is carried out and evaluates the impacts of

cloud computing (including its benefits and challenges

as well as its economic and environmental impacts).

Finally, the report discusses the policy issues raised

by cloud computing and the role of governments and

other stakeholders in addressing these issues.

Internet of things: the influence of M2M data on the

energy industry

GigaOm Research

March 4, 2014

21

This report examines the drivers of machine-2machine (M2M)-data exploitation in the smart-grid

sector and the oil and gas sector, as well as the risks

and opportunities for buyers and suppliers of the

related core technologies and services.

CRS-12

c11173008

Date

.

Title

Date

Pages

Notes

Software Defined Perimeter

Cloud Security Alliance

December 1,

2013

13

The Software Defined Perimeter (SDP) initiative by

the Cloud Security Alliance aims to make “invisible

networks” accessible to a wider range of government

agencies and corporations. The initiative will foster

development of an architecture for securing the

“Internet of Things” by using the cloud to create

highly secure end-to-end networks between any IPaddressable entities.

Delivering on the Promise of Big Data and the Cloud

Booz Allen Hamilton

January 9, 2013

7

From the report: “Reference architecture does away

with conventional data and analytics silos,

consolidating all information into a single medium

designed to foster connections called a ‘data lake,’

which reduces complexity and creates efficiencies

that improve data visualization to allow for easier

insights by analysts.”

Cloud Computing: An Overview of the Technology and

the Issues facing American Innovators

House Judiciary

Committee, Subcommittee

on Intellectual Property,

Competition, and the

Internet

July 25, 2012

156

Overview and discussion of cloud computing issues.

Information Technology Reform: Progress Made but

Future Cloud Computing Efforts Should be Better

Planned

Government

Accountability Office

(GAO)

July 11, 2012

43

GAO recommends that the Secretaries of

Agriculture, Health and Human Services, Homeland

Security, State, and the Treasury, and the

Administrators of the General Services

Administration (GSA) and Small Business

Administration should direct their respective chief

information officers to establish estimated costs,

performance goals, and plans to retire associated

legacy systems for each cloud-based service discussed

in this report, as applicable.

Cloud Computing Strategy

DOD Chief Information

Officer

July 2012

44

The DOD Cloud Computing Strategy introduces an

approach to move the department from the current

state of a duplicative, cumbersome, and costly set of

application silos to an end state that is agile, secure,

and cost-effective and to a service environment that

can rapidly respond to changing mission needs.

A Global Reality: Governmental Access to Data in the

Cloud—A Comparative Analysis of Ten International

Jurisdictions

Hogan Lovells

May 23, 2012

13

This white paper compares the nature and extent of

governmental access to data in the cloud in many

jurisdictions around the world.

CRS-13

c11173008

Source

.

Title

Date

Pages

Notes

Policy Challenges of Cross-Border Cloud Computing

U.S. International Trade

Commission

May 2012

38

This report examines the main policy challenges

associated with cross-border cloud computing—data

privacy, security, and ensuring the free flow of

information—and the ways countries are addressing

them through domestic policymaking, international

agreements, and other cooperative arrangements.

Cloud Computing Synopsis and Recommendations (SP

800-146)

National Institute of

Standards and Technology

(NIST)

May 2012

81

NIST’s guide explains cloud technologies in plain

terms to federal agencies and provides

recommendations for IT decision makers.

Global Cloud Computing Scorecard a Blueprint for

Economic Opportunity

Business Software Alliance

February 2,

2012

24

This report notes that although many developed

countries have adjusted their laws and regulations to

address cloud computing, the wide differences in

those rules make it difficult for companies to invest in

the technology.

Concept of Operations: FedRAMP

GSA

February 7,

2012

47

Implementation of FedRAMP will be in phases. This

document describes all the services that will be

available at initial operating capability, targeted for

June 2012. The concept of operations will be updated

as the program evolves toward sustained operations.

Federal Risk and Authorization Management Program

(FedRAMP)

Federal Chief Information

Officers Council

January 4, 2012

N/A

FedRAMP has been established to provide a standard

approach to assessing and authorizing (A&A) cloud

computing services and products.

Security Authorization of Information Systems in Cloud

Computing Environments (FedRAMP)

White House/Office of

Management and Budget

(OMB)

December 8,

2011

7

FedRAMP will now be required for all agencies

purchasing storage, applications, and other remote

services from vendors. The Administration promotes

cloud computing as a means to save money and

accelerate the government’s adoption of new

technologies.

U.S. Government Cloud Computing Technology

Roadmap, Volume I, Release 1.0 (Draft). High-Priority

Requirements to Further USG Agency Cloud Computing

Adoption (SP 500-293)

NIST

December 1,

2011

32

Volume I is aimed at interested parties that wish to

gain a general understanding and overview of the

background, purpose, context, work, results, and

next steps of the U.S. Government Cloud Computing

Technology Roadmap initiative.

CRS-14

c11173008

Source

.

Title

Source

Date

Pages

Notes

U.S. Government Cloud Computing Technology

Roadmap, Volume II, Release 1.0 (Draft), Useful

Information for Cloud Adopters (SP 500-293)

NIST

December 1,

2011

85

Volume II is designed as a technical reference for

those actively working on strategic and tactical cloud

computing initiatives including, but not limited to,

U.S. government cloud adopters. This volume

integrates and summarizes the work completed to

date and explains how these findings support the

roadmap introduced in Volume I.

Information Security: Additional Guidance Needed to

Address Cloud Computing Concerns

GAO

October 6,

2011

17

Twenty-two of 24 major federal agencies reported

that they were either concerned or very concerned

about the potential information security risks

associated with cloud computing. GAO

recommended that the NIST issue guidance specific

to cloud computing security.

Cloud Computing Reference Architecture (SP 500-292)

NIST

September 1,

2011

35

This special publication, which is not an official U.S.

government standard, is designed to provide guidance

to specific communities of practitioners and

researchers.

Guide to Cloud Computing for Policy Makers

Software and Information

Industry Association (SAII)

July 26, 2011

27

The SAII concludes that “there is no need for cloudspecific legislation or regulations to provide for the

safe and rapid growth of cloud computing, and in fact,

such actions could impede the great potential of

cloud computing.”

Federal Cloud Computing Strategy

White House

February 13,

2011

43

The strategy outlines how the federal government

can accelerate the safe, secure adoption of cloud

computing and provides agencies with a framework

for migrating to the cloud. It also examines how

agencies can address challenges related to the

adoption of cloud computing, such as privacy,

procurement, standards, and governance.

25 Point Implementation Plan to Reform Federal

Information Technology Management

White House

December 9,

2010

40

The plan’s goals are to reduce the number of

federally run data centers from 2,100 to

approximately 1,300; rectify or cancel one-third of

troubled IT projects, and require federal agencies to

adopt a “cloud first” strategy in which they will move

at least one system to a hosted environment within a

year.

Source: Highlights compiled by CRS from the reports.

Note: These reports analyze cybersecurity issues related to the federal government’s adoption of cloud computing storage options.

CRS-15

c11173008

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Critical Infrastructure: CRS Reports

•

•

•

•

•

•

•

•

•

c11173008

CRS Report R42683, Critical Infrastructure Resilience: The Evolution of Policy and

Programs and Issues for Congress, by John D. Moteff

CRS Report RL30153, Critical Infrastructures: Background, Policy, and Implementation,

by John D. Moteff

CRS Report R42660, Pipeline Cybersecurity: Federal Policy, by Paul W. Parfomak

CRS Report R41536, Keeping America’s Pipelines Safe and Secure: Key Issues for

Congress, by Paul W. Parfomak

CRS Report R41886, The Smart Grid and Cybersecurity—Regulatory Policy and Issues,

by Richard J. Campbell

CRS Report R42338, Smart Meter Data: Privacy and Cybersecurity, by Brandon J.

Murrill, Edward C. Liu, and Richard M. Thompson II

CRS Report RL33586, The Federal Networking and Information Technology Research

and Development Program: Background, Funding, and Activities, by Patricia Moloney

Figliola

CRS Report 97-868, Internet Domain Names: Background and Policy Issues, by Lennard

G. Kruger

CRS Report IN10027, Open-Source Software and Cybersecurity: The Heartbleed Bug, by

Eric A. Fischer, Catherine A. Theohary, and John W. Rollins

Congressional Research Service

16

.

Table 4. Critical Infrastructure

Title

Date

Pages

Notes

HHS Breach Portal: Breaches Affecting 500 or More

Individuals

Health and Human

Services (HHS)

Ongoing

Cybersecurity for Energy Delivery Systems Program

(CEDS)

Department of

Energy (DOE),

Office of Electricity

Delivery and

Energy Reliability

Ongoing

N/A

The program assists the energy sector asset owners (electric,

oil, and gas) by developing cybersecurity solutions for energy

delivery systems through integrated planning and a focused

research and development effort. CEDS co-funds projects with

industry partners to make advances in cybersecurity capabilities

for energy delivery systems.

Cybersecurity Capability Maturity Model (C2M2)

DOE Office of

Electricity Delivery

and Energy

Reliability

Ongoing

N/A

The model was developed by the DOE and industry as a

cybersecurity control evaluation and improvement management

tool for energy sector firms. It tells adherents how to assess and

grade adoption of cybersecurity practices.

GridEx

North American

Electric Reliability

Corporation

(NERC)

Ongoing

N/A

The objectives of the NERC Grid Security Exercise (GridEx)

series are to use simulated scenarios (with no real-world effects)

to exercise the current readiness of participating electricity

subsector entities to respond to cyber- or physical security

incidents and provide input for security program improvements

to the bulk power system. GridEx is a biennial international grid

security exercise that uses best practices and other

contributions from the Department of Homeland Security, the

Federal Emergency Management Agency, and the National

Institute of Standards and Technology.

CRS-17

c11173008

Source

As required by Section 13402(e)(4) of the HITECH Act, the

Secretary must post a list of breaches of unsecured protected

health information affecting 500 or more individuals. These

breaches are now posted in a new, more accessible format that

allows users to search and sort the posted breaches.

Additionally, this new format includes brief summaries of the

breach cases that OCR has investigated and closed, as well as

the names of private practice providers who have reported

breaches of unsecured protected health information to the

Secretary.

.

Title

Date

Pages

Notes

ICBA Data Breach Toolkit

Independent

Community

Bankers of America

Ongoing

N/A

ICBA and Visa have teamed up to bring a special

communications toolkit to community banks. This

comprehensive communications guide gives community banks

the means of communicating with card customers and the media

within 24 hours of a data compromise. Having this contingency

plan in place can make all the difference in a data breach

episode. The toolkit Includes a brochure on communications

best practices following a data breach and customizable template

materials, such as cardholder letters, statement inserts, FAQs,

and media statements.

Appendix J: Strengthening the Resilience of Outsourced

Technology Services

Federal Financial

Institutions

Examination

Council (FFIEC)

Ongoing

N/A

The increasing sophistication and volume of cyber threats and

their ability to disrupt operations or corrupt data can affect the

business resilience of financial institutions and technology service

providers (TSPs). Financial institutions and their TSPs need to

incorporate the potential impact of a cyber event into their

business continuity planning (BCP) process and ensure

appropriate resilience capabilities are in place. The changing

cyber threat landscape may include risks that must be managed

to achieve resilience.

Cybersecurity Risk Management and Best Practices

(WG4): Cybersecurity Framework for the

Communications Sector

Federal

Communications

Commission,

Communications

Security, Reliability

and Interoperability

Council (CSRIC)

March 18,

2015

415

The CSRIC is a federal advisory committee that provides

recommendations to the FCC regarding best practices and

actions the commission can take to help ensure security,

reliability, and interoperability of communications systems and

infrastructure. The CSRIC approved a report that identifies best

practices, provides a variety of important tools and resources

for communications companies of different sizes and types to

manage cybersecurity risks, and recommends a path forward.

Tracking & Hacking: Security & Privacy Gaps Put

American Drivers at Risk

Senator Edward

Markey

February 11,

2015

14

Nearly all modern vehicles have some sort of wireless

connection that hackers could potentially use to gain access to

their critical systems. The company’s protections on those

connections are “inconsistent and haphazard” across the

industry. In addition to security weaknesses, the report also

found that many auto companies are collecting detailed location

data from cars and often transmitting it insecurely.

CRS-18

c11173008

Source

.

Title

Date

Pages

Notes

Senators Alexander, Murray Announce Oversight

Initiative on Security of Health IT

Senate Committee

on Labor, Health,

Education and

Pensions

February 6,

2015

N/A

U.S. Senate health committee Chairman Lamar Alexander (RTenn.) and Ranking Member Patty Murray (D-Wash.) today

announced a bipartisan initiative focused on examining the

security of health information technology and the health

industry’s preparedness for cyber threats. The goal of the

Alexander-Murray initiative is to examine whether Congress can

help ensure the safety of health information technology,

including electronic health records, hospital networks, insurance

records, and network-connected medical devices, like

pacemakers and continuous glucose monitors. Begun last month,

the ongoing staff meetings will include participants from relevant

government oversight agencies, independent cybersecurity

experts, health industry leaders, and others.

Report on Cybersecurity Practices

Financial Industry

Regulatory

Authority

February 2015

46

The report presents an approach to cybersecurity grounded in

risk management to address these threats. It identifies principles

and effective practices for firms to consider, while recognizing

that there is no one-size-fits-all approach to cybersecurity.

Incident Response/Vulnerability Coordination in 2014

ICS/CERT Monitor

September

2014-February

2015

15

In FY2014, the Industrial Control Systems Cyber Emergency

Response Team (ICS-CERT) received and responded to 245

incidents reported by asset owners and industry partners. The

Energy Sector led all others again in 2014 with the most

reported incidents. ICS-CERT’s continuing partnership with the

Energy Sector provides many opportunities to share information

and collaborate on incident response efforts. In addition, in 2014

the Critical Manufacturing Sector reported incidents, some of

which were from control systems equipment manufacturers.

Guidance on Maritime Cybersecurity Standards (Federal

Register Notice of Public Meeting and Request for

Comments)

U.S. Coast Guard

December 12,

2014

2

From the summary: “The U.S. Coast Guard announces a public

meeting to be held in Washington, DC, to receive comments on

the development of cybersecurity assessment methods for

vessels and facilities regulated by the Coast Guard. This meeting

will provide an opportunity for the public to comment on

development of security assessment methods that assist vessel

and facility owners and operators identify and address

cybersecurity vulnerabilities that could cause or contribute to a

Transportation Security Incident. The Coast Guard will consider

these public comments in developing relevant guidance, which

may include standards, guidelines, and best practices to protect

maritime critical infrastructure.”

CRS-19

c11173008

Source

.

Title

Date

Pages

Notes

Federal Financial Institutions Examination Council (FFIEC)

Cybersecurity Assessment: General Observations

FFIEC

November 3,

2014

Inquiry into Cyber Intrusions Affecting U.S.

Transportation Command Contractors

Senate Armed

Services

Committee

September 17,

2014

Critical Infrastructure Protection: DHS [Department of

Homeland Security] Action Needed to Enhance

Integration and Coordination of Vulnerability Assessment

Efforts

Government

Accountability

Office (GAO)

September 15,

2014

82

DHS used 10 different assessment tools and methods from

FY2011 through FY2013 to assess critical infrastructure

vulnerabilities. Four of the 10 assessments did not include

cybersecurity. The differences in the assessment tools and

methods mean DHS is not positioned to integrate its findings in

identifying priorities.

Energy Sector Cybersecurity Framework Implementation

Guidance: Draft For Public Comment and Comment

Submission Form

DOE Office of

Electricity Delivery

and Energy

Reliability

September 12,

2014

N/A

Energy companies need not make a choice between the National

Institute of Standards and Technology (NIST) cybersecurity

framework and the DOE’s C2M2. The NIST framework tells

organizations to grade themselves on a four-tier scale based on

their overall cybersecurity program sophistication. C2M2 tells

users to assess cybersecurity control implementation across 10

domains of cybersecurity practices, such as situational

awareness, according to their specific “maturity indicator level.”

CRS-20

c11173008

Source

Companies are critically dependent on IT. Financial companies

should routinely scan IT networks for vulnerabilities and

anomalous activity and test systems for their potential exposure

to cyberattacks. The study recommends sharing threat data

through such avenues as the Financial Services Information

Sharing and Analysis Center.

52

Hackers associated with the Chinese government successfully

penetrated the computer systems of Transportation Command

(TRANSCOM) contractors 20 times in the course of a single

year. Chinese hackers tried to get into the systems 50 times.

The congressional committee found that only two of the

intrusions were detected. It also found that officials were

unaware due in large part to unclear requirements and methods

for contractors to report breaches and for government agencies

to share information.

.

Title

Date

Pages

Notes

Guidelines for Smart Grid Cybersecurity, Smart Grid

Cybersecurity Strategy, Architecture, and High-Level

Requirements (3 volumes)

NIST

September

2014

668

This three-volume report, Guidelines for Smart Grid

Cybersecurity, presents an analytical framework that

organizations can use to develop effective cybersecurity

strategies tailored to their particular combinations of smart gridrelated characteristics, risks, and vulnerabilities. Organizations in

the diverse community of smart grid stakeholders—from

utilities to providers of energy management services to

manufacturers of electric vehicles and charging stations—can use

the methods and supporting information presented in this

report as guidance for assessing risk and identifying and applying

appropriate security requirements. This approach recognizes

that the electric grid is changing from a relatively closed system

to a complex, highly interconnected environment. Each

organization’s cybersecurity requirements should evolve as

technology advances and as threats to grid security inevitably

multiply and diversify.

A Criticism of the Current Security, Privacy and

Accountability Issues in Electronic Health Records

International

Journal of Applied

Information

Systems

September

2014

8

Unless a different approach is used, the reliant on cryptography

and password or escrow based system for key management will

impede trust of the electronic health records (EHR) system and

hence its acceptability. In addition, users with right access should

also be monitored without affecting the clinician workflow. This

paper presents a detailed review of some selected recent

approaches to ensuring security, privacy, and accountability in

EHR and identifies gaps for future research.

Security in the New Mobile Ecosystem (Free registration

required.)

Ponemon Institute

and Raytheon

August 2014

30

Mobile devices are quickly becoming an integral tool for the

workforce, but the security practices and budgets in most

organizations are not keeping pace with the growing number of

devices that must be managed and kept secure.

Critical Infrastructure: Security Preparedness and

Maturity

Unisys and the

Ponemon Institute

July 2014

34

Unisys and the Ponemon Institute surveyed nearly 600 IT

security executives of utility, energy, and manufacturing

organizations. Overall, the report finds organizations are simply

not prepared to deal with advanced cyber threats. Only half of

companies have actually deployed IT security programs and,

according to the survey, the top threat actually stems from

negligent insiders.

CRS-21

c11173008

Source

.

Title

Source

Date

Pages

Notes

Securing the U.S. Electrical Grid: Understanding the

Threats to the Most Critical of Critical Infrastructure,

While Securing a Changing Grid

Center for the

Study of the

Presidency and

Congress

July 2014

180

From the report: “While [electrical grid] modernization entails

significant challenges in its own right, it also provides an

opportunity to ‘bake security in’—both in the hardware and

software controlling these systems and in the business models,

regulatory systems, financial incentives, and insurance structures

that govern the generation, transmission, and distribution of

electric power.… In this report and the aforementioned dozen

recommendations, we have sought to identify the immediate

action that can be taken by the White House, the Congress, and

the private sector to mitigate current threats to the electrical

grid.”

Maritime Critical Infrastructure Protection: DHS Needs

to Better Address Port Cybersecurity

GAO

June 5, 2014

54

GAO’s objective was to identify the extent to which DHS and

other stakeholders have taken steps to address cybersecurity in

the maritime port environment. GAO examined relevant laws

and regulations, analyzed federal cybersecurity-related policies

and plans, observed operations at three U.S. ports selected for

being high-risk ports and leaders in calls by vessel type (e.g.,

container), and interviewed federal and nonfederal officials.

Executive Leadership of Cybersecurity: What Today’s

CEO Needs To Know About the Threats They Don’t See

FFIEC

May 7, 2014

30

The FFIEC highlighted key focus areas for senior management

and boards of directors of community institutions as they assess

their institutions’ abilities to identify and mitigate cybersecurity

risks.

Sector Risks Snapshots

DHS

May 2014

52

DHS’s snapshots provide an introduction to the diverse array of

critical infrastructure sectors, touching on some of the key

threats and hazards concerning these sectors and highlighting

the common, first-order dependencies and interdependencies

between sectors.

Critical Infrastructure Protection Issues Identified in

Order No. 791

Federal Energy

Regulatory

Commission

(FERC)

April 24, 2014

N/A

FERC will hold a technical meeting on cybersecurity and

communications security standards for power generators.

Among other issues, the meeting will consider possible

disjunctures between FERC’s regulatory standards for grid

reliability and the new voluntary cybersecurity framework for

critical infrastructure that NIST rolled earlier this year.

CRS-22

c11173008

.

Title

Date

Pages

Notes

Notice of Completion of Notification of CyberDependent Infrastructure and Process for Requesting

Reconsideration of Determinations of Cyber Criticality

DHS Programs

Directorate

April 17, 2014

3

The Secretary of DHS has been directed to identify critical

infrastructure in which a cybersecurity incident could reasonably

result in catastrophic regional or national effects on public health

or safety, economic security, or national security. In addition to

identifying such infrastructure, the Secretary has also been

directed to confidentially notify owners and operators of critical

infrastructure identified and establish a mechanism through

which entities can request reconsideration of that identification,

whether inclusion or exclusion from this list. This notice informs

owners and operators of critical infrastructure that the

confidential notification process is complete and describes the

process for requesting reconsideration.

Cybersecurity Procurement Language for Energy Delivery

Systems

DOE Energy

Sector Control

Systems Working

Group

April 2014

46

This guidance suggests procurement strategies and contract

language to help U.S. energy companies and technology suppliers

build in cybersecurity protections during product design and

manufacturing. It was “developed through a public-private

working group including federal agencies and private industry

leaders.”

Benchmarking Trends: Interest in Cyber Insurance

Continues to Climb (Requires free registration to access.)

Marsh USA

March 31,

2014

4

As cyber incidents increased in frequency and severity in 2013,

the percentage of companies that purchased cyber insurance

rose by double digits (see figure 1 in the report). Early signs in

2014 indicate that the trend is not just continuing but

accelerating. Recent high-profile data breaches, growing boardlevel concern, and the increasing vulnerability of operations to

technology failure appear to be influencing purchasing decisions.

Wireless Emergency Alerts (WEA) Cybersecurity Risk

Management Strategy for Alert Originators

Carnegie

Mellon/Pittsburgh

Software Institute

March 2014

183

From the report: “The Wireless Emergency Alerts (WEA)

service depends on computer systems and networks to convey

potentially life-saving information to the public in a timely

manner. However, like other cyber-enabled services, it is

susceptible to risks that may enable attackers to disseminate

unauthorized alerts or to delay, modify, or destroy valid alerts.

Successful attacks may result in property destruction, financial

loss, injury, or death and may damage WEA credibility to the

extent that users ignore future alerts or disable alerting. This

report describes a four-stage cybersecurity risk management

(CSRM) strategy that alert originators can use throughout WEA

adoption, operations, and sustainment, as well as a set of

governance activities for developing a plan to execute the

CSRM.”

CRS-23

c11173008

Source

.

Title

Date

Pages

Notes

Cybersecurity and the North American Electric Grid:

New Policy Approaches to Address an Evolving Threat

Bipartisan Policy

Center

February 28,

2014

Framework for Improving Critical Infrastructure

Cybersecurity

NIST

February 12,

2014

41

The voluntary framework consists of cybersecurity standards

that can be customized to various sectors and adapted by both

large and small organizations. Additionally, so that the private

sector may fully adopt this framework, DHS announced the

Critical Infrastructure Cyber Community (C3)—or “C-cubed”—

Voluntary Program. The C3 program gives companies that

provide critical services such as cell phones, email, banking, and

energy and state and local governments direct access to

cybersecurity experts within DHS who have knowledge about

specific threats, ways to counter those threats, and how, over

the long term, to design and build systems that are less

vulnerable to cyber threats.

ITI Recommendations to the Department of Homeland

Security Regarding its Work Developing a Voluntary

Program Under Executive Order 163636, “Improving

Critical Infrastructure Cybersecurity.”

Information

Technology

Industry Council

(ITI)

February 11,

2014

3

ITI released a set of recommendations eying further

improvement of the framework, changes that call for DHS to

“de-emphasize the current focus on incentives.” Partly, ITI

recognizes the cyber order can produce change even in an

environment in which fiscal constraints and congressional

inaction stall carrots for adoption—but a bigger biz argument,

made in its report yesterday, is that ITI and others do not want

incentives if they come at the cost of “compliance-based

programs.”

CRS-24

c11173008

Source

The Bipartisan Policy Center’s initiative identifies urgent

priorities, including strengthening existing protections, enhancing

coordination at all levels, and accelerating the development of

robust protocols for response and recovery in the event of a

successful attack. The initiative developed recommendations in

four policy areas: standards and best practices, information

sharing, response to a cyberattack, and paying for cybersecurity.

The recommendations are targeted to Congress, federal

government agencies, state public utility commissions (PUCs),

and industry.

.

Title

Date

Pages

Notes

The Federal Government’s Track Record on

Cybersecurity and Critical Infrastructure

Senate Homeland

Security and

Governmental

Affairs Committee

(Minority Staff)

February 4,

2014

19

Since 2006, the federal government has spent at least $65 billion

on securing its computers and networks, according to an

estimate by the Congressional Research Service (CRS). NIST,

the government’s official body for setting cybersecurity

standards, has produced thousands of pages of precise guidance

on every significant aspect of IT security. And yet agencies—

even agencies with responsibilities for critical infrastructure or

vast repositories of sensitive data—continue to leave themselves

vulnerable, often by failing to take the most basic steps toward

securing their systems and information.

Electricity Subsector Cybersecurity Capability Maturity

Model (ES-C2M2) (Case Study)

Carnegie Mellon

University Software

Engineering

Institute

January 23,

2014

39

ES-C2M2 is a White House initiative, led by DOE in partnership

with the Department of Homeland Security and representatives

of electricity subsector asset owners and operators, to manage

dynamic threats to the electric grid. Its objectives are to

strengthen cybersecurity capabilities, enable consistent

evaluation and benchmarking of cybersecurity capabilities, and

share knowledge and best practices.

NIPP 2013: Partnering for Critical Infrastructure Security

and Resilience

DHS

2013

57

The National Infrastructure Protection Plan (NIPP) 2013 meets

the requirements of Presidential Policy Directive-21, “Critical

Infrastructure Security and Resilience,” signed in February 2013.

The plan was developed through a collaborative process

involving stakeholders from all 16 critical infrastructure sectors,

all 50 states, and all levels of government and industry. It

provides a clear call to action to leverage partnerships, innovate

for risk management, and focus on outcomes.

World Federation of Exchanges (WFE) Launches Global

Cyber Security Committee

WFE

December 12,

2013

N/A

The WFE announced the launch of the exchange industry’s first

cybersecurity committee with a mission to aid in the protection

of the global capital markets. The working group will bring

together representation from a number of exchanges and

clearinghouses across the globe to collaborate on best practices

in global security.

The Critical Infrastructure Gap: U.S. Port Facilities and

Cyber Vulnerabilities

Brookings

Institution/ Center

for 21st Century

Security and

Intelligence

July 2013

50

The study argues that the level of cybersecurity awareness and

culture in U.S. port facilities is relatively low and that a

cyberattack at a major U.S. port would quickly cause significant

damage to the economy.

FFIEC Forms Cybersecurity and Critical Infrastructure

Working Group

FFIEC

June 6, 2013

2

FFIEC formed a working group to further promote coordination

across federal and state banking regulatory agencies on critical

infrastructure and cybersecurity issues.

CRS-25

c11173008

Source

.

Title

Source

Date

Pages

Notes

Electric Grid Vulnerability: Industry Responses Reveal

Security Gaps

Representative

Edward Markey

and Representative

Henry Waxman

May 21, 2013

35

The report found that less than one-quarter of investor-owned

utilities and less than one-half of municipally and cooperatively

owned utilities followed through with voluntary standards issued

by the Federal Energy Regulatory Commission after the Stuxnet

worm struck in 2010.

Initial Analysis of Cybersecurity Framework RFI [Request

for Information] Responses

NIST

May 20, 2013

33

Comments on the challenges of protecting the nation’s critical

infrastructure have identified a handful of issues for the more

than 200 people and organizations that responded to a formal

RFI. NIST has released an initial analysis of 243 responses to the

Feb. 26 RFI. The analysis will form the basis for an upcoming

workshop at Carnegie Mellon University in Pittsburgh as NIST

moves forward on creating a cybersecurity framework for

essential energy, utility, and communications systems.

Joint Working Group on Improving Cybersecurity and

Resilience Through Acquisition, Notice of Request for

Information

General Services

Administration

May 13, 2013

3

Among other things, Presidential Policy Directive-21requires the

General Services Administration, in consultation with the

Department of Defense and DHS, to jointly provide and support

government-wide contracts for critical infrastructure systems

and ensure that such contracts include audit rights for the

security and resilience of critical infrastructure.

2013 Annual Report

Financial Stability

Oversight Council

(FSOC)

April 25, 2013

195

Under the Dodd-Frank Act, FSOC must report annually to

Congress on a range of issues, including significant financial

market and regulatory developments and potential emerging

threats to the financial stability of the United States. FSOC’s

recommendations address heightened risk management and

supervisory attention to operational risks, including

cybersecurity and infrastructure.

Version 5 Critical Infrastructure Protection Reliability

Standards (Notice of Proposed Rulemaking)

FERC

April 24, 2013

18

FERC proposes to approve the Version 5 Critical Infrastructure

Protection (CIP) Reliability Standards, CIP-002-5 through CIP011-1, submitted by the North American Electric Reliability

Corporation, the commission-certified Electric Reliability

Organization. The proposed reliability standards, which pertain

to the cybersecurity of the bulk electric system, represent an

improvement over the current commission-approved CIP

Reliability Standards as they adopt new cybersecurity controls

and extend the scope of the systems that are protected by the

existing standards.

CRS-26

c11173008

.

Title

Date

Pages

Notes

Wireless Cybersecurity

Syracuse University

New York,

Department of

Electrical

Engineering and

Computer Science

April 2013

167

This project dealt with various threats in wireless networks,

including eavesdropping in a broadcast channel, noncooperative

eavesdropping in a single-source, single-sink planar network, and

primary user emulation attack in a cognitive radio network. The

major contributions were detailed analysis of performance

trade-off in the presence of the eavesdropping threat, a

combined encoding and routing approach that provides provable

security against noncooperating eavesdropping, and a physical

layer approach to counter the primary emulation attack. The

research results under this effort significantly advanced our

understanding on some of the fundamental trade-offs among

various performance metrics in a wireless system. Practically

feasible wireless security measures were also obtained that

could lead to more assured operations in which secured

wireless networks play an indispensable role. This project led to

one PhD dissertation, one pending patent application, two

archival journal papers, and a number of peer-reviewed

conference papers.

Incentives to Adopt Improved Cybersecurity Practices

NIST and the

National

Telecommunication

s and Information

Administration

March 28,

2013

N/A

The Department of Commerce (DOC) is investigating ways to

incentivize companies and organizations to improve their

cybersecurity. To better understand what stakeholders—such as

companies, trade associations, academics, and others—believe

would best serve as incentives, the department has released a

series of questions to gather public comments in a notice of

inquiry.

Cybersecurity: The Nation’s Greatest Threat to Critical

Infrastructure

U.S. Army War

College

March 2013

38

This paper provides a background on what constitutes national

critical infrastructure and critical infrastructure protection;

discusses the immense vulnerabilities, threats, and risks

associated in the protection of critical infrastructure; and

outlines governance and responsibilities of protecting vulnerable

infrastructure. The paper makes recommendations for federal

responsibilities and legislation to direct nation critical

infrastructure efforts to ensure national security, public safety,

and economic stability.

SCADA [Supervisory Control and Data Acquisition] and

Process Control Security Survey

SANS Institute

February 1,

2013

19

SANS Institute surveyed professionals who work with SCADA

and process control systems. Of the nearly 700 respondents,

70% said they consider their SCADA systems to be at high or

severe risk; one-third of them suspected that these systems had

been already been infiltrated.

CRS-27

c11173008

Source

.

Title

Date

Pages

Notes

Follow-up Audit of the Department’s Cyber Security

Incident Management Program

DOE Inspector

General’s Office

December

2012

25

In 2008, the DOE’s Cyber Security Incident Management

Program (DOE/IG-0787, January 2008) reported the department

and National Nuclear Security Administration (NNSA)

established and maintained a number of independent, at least

partially duplicative, cybersecurity incident management

capabilities. Several issues were identified that limited the

efficiency and effectiveness of the department’s cybersecurity

program and adversely affected the ability of law enforcement to

investigate incidents. In response to the findings, management

concurred with the recommendations and indicated that it had

initiated actions to address the issues identified.

Terrorism and the Electric Power Delivery System

National

Academies of

Science

November

2012

146

Focuses on measures that could make the electric power

delivery system less vulnerable to attacks, restore power faster

after an attack, and make critical services less vulnerable when

delivery of conventional electric power has been disrupted.

New FERC Office to Focus on Cyber Security

DOE

September 20,

2012

N/A

FERC announced the creation of the agency’s new Office of

Energy Infrastructure Security, which will work to reduce

threats to the electric grid and other energy facilities. The goal is

for the office to help FERC, and other agencies and private

companies, better identify potential dangers and solutions.

Canvassing the Targeting of Energy Infrastructure: The

Energy Infrastructure Attack Database

Journal of Energy

Security

August 7,

2012

8

The Energy Infrastructure Attack Database (EIAD) is a

noncommercial dataset that structures information on reported

(criminal and political) attacks to energy infrastructure

worldwide by nonstate actors since 1980. In building this

resource, the objective was to develop a product that could be

broadly accessible and connect to existing available resources.

Smart-Grid Security

Center for

Infrastructure

Protection and

Homeland Security,

George Mason

School of Law

August 2012

26

Highlights the significance of and the challenges with securing the

Smart Grid.

Cybersecurity: Challenges in Securing the Electricity Grid

GAO

July 17, 2012

25

In a prior report, GAO made recommendations related to

electricity grid modernization efforts, including developing an

approach to monitor compliance with voluntary standards.

These recommendations have not yet been implemented.

CRS-28

c11173008

Source

.

Title

Date

Pages

Notes

Energy Department Develops Tool with Industry to Help

Utilities Strengthen Their Cybersecurity Capabilities

DOE

June 28, 2012

N/A

The Cybersecurity Self-Evaluation Tool uses best practices

developed for the Electricity Subsector Cybersecurity Capability

Maturity Model Initiative, which involved a series of workshops

with the private sector to draft a maturity model that can be

used throughout the electric sector to better protect the grid.

ICS-CERT Incident Response Summary Report, 20092011

U.S. Industrial

Control System

Cyber Emergency

Response Team

(ICS-CERT)

May 9, 2012

17

The number of reported cyberattacks on U.S. critical

infrastructure increased sharply—from 9 incidents in 2009 to

198 in 2011. Water sector-specific incidents, when added to the

incidents that affected several sectors, accounted for more than

half of all incidents. In more than half of the most serious cases,

implementing best practices such as log-in limitation or a

properly configured firewall would have deterred the attack,

reduced the time it would have taken to detect an attack, and

minimized its impact.

Cybersecurity Risk Management Process (Electricity

Subsector)

DOE Office of

Electricity Delivery

and Energy

Reliability

May 2012

96

The guideline describes a risk-management process that is

targeted to the specific needs of electricity sector organizations.

Its objective is to build upon existing guidance and requirements

to develop a flexible risk-management process tuned to the

diverse missions, equipment, and business needs of the electric

power industry.

ICT Applications for the Smart Grid: Opportunities and

Policy Implications

Organization for

Economic Cooperation and

Development

(OECD)

January 10,

2012

44

This report discusses “smart” applications of information and

communication technologies (ICTs) for more sustainable energy

production, management, and consumption. The report outlines

policy implications for government ministries dealing with

telecommunications regulation, ICT sector and innovation

promotion, and consumer and competition issues.

The Department’s Management of the Smart Grid

Investment Grant Program

DOE Inspector

General

January 20,

2012

21

According to the DOE inspector general, the department’s rush

to award stimulus grants for projects under the next generation

of the power grid, known as the Smart Grid, resulted in some

firms receiving funds without submitting complete plans for how

to safeguard the grid from cyberattacks.

Critical Infrastructure Protection: Cybersecurity

Guidance Is Available, but More Can Be Done to

Promote Its Use

GAO

December 9,

2011

77

According to GAO, given the plethora of guidance available,

individual entities within the sectors may be challenged in

identifying the guidance that is most applicable and effective in

improving their security posture. Improved knowledge of the

available guidance could help both federal and private-sector

decision makers better coordinate their efforts to protect

critical cyber-reliant assets.

CRS-29

c11173008

Source

.

Title

Source

Date

Pages

Notes

The Future of the Electric Grid

Massachusetts

Institute of

Technology (MIT)

December 5,

2011

39

Chapter 1 provides an overview of the status of the electric

grid, the challenges and opportunities it will face, and major

recommendations. To facilitate selective reading, detailed

descriptions of the contents of each section in Chapters 2–9 are

provided in each chapter’s introduction, and recommendations

are collected and briefly discussed in each chapter’s final section.

(See Chapter 9, “Data Communications, Cybersecurity, and

Information Privacy,” pages 208-234).

FCC’s Plan for Ensuring the Security of

Telecommunications Networks

Federal

Communications

Commission (FCC)

June 3, 2011

1

FCC Chairman Genachowski’s response to letter from

Representative Anna Eshoo dated November 2, 2010, regarding

concerns about the implications of foreign-controlled

telecommunications infrastructure companies providing

equipment to the U.S. market.

Cyber Infrastructure Protection

U.S. Army War

College

May 9, 2011

324

Part 1 deals with strategic and policy cybersecurity-related

issues and discusses the theory of cyberpower, Internet

survivability, large-scale data breaches, and the role of

cyberpower in humanitarian assistance. Part 2 covers social and

legal aspects of cyber infrastructure protection and discusses the

attack dynamics of political and religiously motivated hackers.

Part 3 discusses the technical aspects of cyber infrastructure

protection, including the resilience of data centers, intrusion

detection, and a strong emphasis on Internet protocol (IP)

networks.

In the Dark: Crucial Industries Confront Cyberattacks

McAfee and Center

for Strategic and

International

Studies (CSIS)

April 21, 2011

28

The study reveals an increase in cyberattacks on critical

infrastructure such as power grids, oil, gas, and water; it also

shows that many of the world’s critical infrastructures lacked

protection of their computer networks and reveals the cost and

impact of cyberattacks.

Cybersecurity: Continued Attention Needed to Protect

Our Nation’s Critical Infrastructure and Federal

Information Systems

GAO

March 16,

2011

17

According to GAO, executive branch agencies have made

progress instituting several government-wide initiatives aimed at

bolstering aspects of federal cybersecurity, such as reducing the

number of federal access points to the Internet, establishing

security configurations for desktop computers, and enhancing

situational awareness of cyber events. Despite these efforts, the

federal government continues to face significant challenges in

protecting the nation’s cyber-reliant critical infrastructure and

federal information systems.

CRS-30

c11173008

.

Title

Source

Federal Energy Regulatory Commission’s Monitoring of

Power Grid Cyber Security

DOE Office of

Inspector General

Electricity Grid Modernization: Progress Being Made on

Cybersecurity Guidelines, but Key Challenges Remain to

be Addressed

Pages

Notes

January 26,

2011

30

NERC developed Critical Infrastructure Protection (CIP)

cybersecurity reliability standards, which were approved by the

FERC in January 2008. Although the commission had taken steps

to ensure CIP cybersecurity standards were developed and

approved, NERC’s testing revealed that such standards did not

always include controls commonly recommended for protecting

critical information systems. In addition, the CIP standards

implementation approach and schedule approved by the

commission were not adequate to ensure that systems-related

risks to the nation’s power grid were mitigated or addressed in

a timely manner.

GAO

January 12,

2011

50

From the report: “To reduce the risk that NIST’s smart grid

cybersecurity guidelines will not be as effective as intended, the

Secretary of Commerce should direct the Director of NIST to

finalize the agency’s plan for updating and maintaining the

cybersecurity guidelines, including ensuring it incorporates (1)

missing key elements identified in this report, and (2) specific

milestones for when efforts are to be completed. Also, as a part

of finalizing the plan, the Secretary of Commerce should direct

the Director of NIST to assess whether any cybersecurity

challenges identified in this report should be addressed in the

guidelines.”

Partnership for Cybersecurity Innovation

White House

Office of Science

and Technology

Policy

December 6,

2010

4

The Obama Administration released a memorandum of

understanding signed by DOC’s NIST, DHS’s Science and

Technology Directorate (DHS/S&T), and the Financial Services

Sector Coordinating Council (FSSCC). The goal of the

agreement is to speed up the commercialization of cybersecurity

research innovations that support the nation’s critical

infrastructures.

WIB Security Standard Released

International

Instrument Users

Association (WIB)

November 10,

2010

CRS-31

c11173008

Date

The Netherlands-based WIB, an international organization that

represents global manufacturers in the industrial automation

industry, announced the second version of the Process Control

Domain Security Requirements for Vendors document—the first

international standard that outlines a set of specific

requirements focusing on cybersecurity best practices for

suppliers of industrial automation and control systems.

.

Title

Date

Pages

Notes

Information Security Management System for Microsoft

Cloud Infrastructure

Microsoft

November

2010

15

This study describes the standards Microsoft follows to address

current and evolving cloud security threats. It also depicts the

internal structures within Microsoft that handle cloud security

and risk management issues.

NIST Finalizes Initial Set of Smart Grid Cyber Security

Guidelines

NIST

September 2,

2010

N/A

NIST released a three-volume set of recommendations relevant

to securing the Smart Grid. The guidelines address a variety of

topics, including high-level security requirements, a risk

assessment framework, an evaluation of privacy issues in

residences and recommendations for protecting the evolving

grid from attacks, malicious code, cascading errors, and other

threats.

Critical Infrastructure Protection: Key Private and Public

Cyber Expectations Need to Be Consistently Addressed

GAO

July 15, 2010

38

Private-sector stakeholders reported that they expect their

federal partners to provide usable, timely, and actionable cyber

threat information and alerts; access to sensitive or classified

information; a secure mechanism for sharing information;

security clearances; and a single centralized government

cybersecurity organization to coordinate government efforts.

However, according to private-sector stakeholders, federal

partners are not consistently meeting these expectations.

The Future of Cloud Computing

Pew Research

Center’s Internet

and American Life

Project

June 11, 2010

26

Technology experts and stakeholders expect they will “live

mostly in the cloud” in 2020 and not on the desktop, working

mostly through cyberspace-based applications accessed through

networked devices.

The Reliability of Global Undersea Communications Cable

Infrastructure (The ROGUCCI Report)

Institute of

Electrical and

Electronics

Engineers and the

EastWest Institute

May 26, 2010

186

This study submits 12 major recommendations to privatesector, government, and other stakeholders—especially the

financial sector—for the purpose of improving the reliability,

robustness, resilience, and security of the world’s undersea

communications cable infrastructure.

NSTB Assessments Summary Report: Common Industrial

Control System Cyber Security Weaknesses

DOE, Idaho

National

Laboratory

May 2010

123

This report by the National SCADA Test Bed (NSTB) program

notes that computer networks controlling the electric grid are

plagued with security holes that could allow intruders to

redirect power delivery and steal data. Many of the security

vulnerabilities are strikingly basic and fixable problems.

Explore the reliability and resiliency of commercial

broadband communications networks

FCC

April 21, 2010

N/A

The FCC launched an inquiry into the ability of existing

broadband networks to withstand significant damage or severe

overloads as a result of natural disasters, terrorist attacks,

pandemics, or other major public emergencies, as recommended

in the National Broadband Plan.

CRS-32

c11173008

Source

.

Title

Source

Date

Security Guidance for Critical Areas of Focus in Cloud

Computing V2.1

Cloud Security

Alliance

21 Steps to Improve Cyber Security of SCADA Networks

DOE,

Infrastructure

Security and Energy

Restoration

Source: Highlights compiled by CRS from the reports.

CRS-33

c11173008

Pages

Notes

December

2009

76

From the report, “Through our focus on the central issues of

cloud computing security, we have attempted to bring greater

clarity to an otherwise complicated landscape, which is often

filled with incomplete and oversimplified information. Our focus

... serves to bring context and specificity to the cloud computing

security discussion: enabling us to go beyond gross

generalizations to deliver more insightful and targeted

recommendations.”

January 1,

2007

10

The President’s Critical Infrastructure Protection Board and

DOE have developed steps to help any organization improve the

security of its SCADA networks. The steps are divided into two

categories: specific actions to improve implementation and

actions to establish essential underlying management processes

and policies.

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Cybercrime and Data Security: CRS Reports and Other CRS

Products

•

•

•

•

•

•

•

•

•

•

•

•

•

•

•

•

•

•

•

c11173008

CRS Report 97-1025, Cybercrime: An Overview of the Federal Computer Fraud

and Abuse Statute and Related Federal Criminal Laws, by Charles Doyle

CRS Report 94-166, Extraterritorial Application of American Criminal Law, by

Charles Doyle

CRS Report R43955, Cyberwarfare and Cyberterrorism: In Brief, by Catherine

A. Theohary and John W. Rollins

CRS Report R42403, Cybersecurity: Cyber Crime Protection Security Act (S.

2111, 112th Congress)—A Legal Analysis, by Charles Doyle

CRS Report 98-326, Privacy: An Overview of Federal Statutes Governing

Wiretapping and Electronic Eavesdropping, by Gina Stevens and Charles Doyle

CRS Report RL32706, Spyware: Background and Policy Issues for Congress, by

Patricia Moloney Figliola

CRS Report CRS Report R41975, Illegal Internet Streaming of Copyrighted

Content: Legislation in the 112th Congress, by Brian T. Yeh

CRS Report R42112, Online Copyright Infringement and Counterfeiting:

Legislation in the 112th Congress, by Brian T. Yeh

CRS Report R40599, Identity Theft: Trends and Issues, by Kristin Finklea

CRS Report R41927, The Interplay of Borders, Turf, Cyberspace, and

Jurisdiction: Issues Confronting U.S. Law Enforcement, by Kristin Finklea

CRS Report RL34651, Protection of Children Online: Federal and State Laws

Addressing Cyberstalking, Cyberharassment, and Cyberbullying, by Alison M.

Smith

CRS Report R42547, Cybercrime: Conceptual Issues for Congress and U.S. Law

Enforcement, by Kristin Finklea and Catherine A. Theohary

CRS Report R43382, Data Security and Credit Card Thefts: CRS Experts, by

Eric A. Fischer

CRS Legal Sidebar WSLG483, Obstacles to Private Sector Cyber Threat

Information Sharing, by Edward C. Liu and Edward C. Liu

CRS Legal Sidebar WSLG672, Online Banking Fraud: Liability for

Unauthorized Payment from Business Checking Account, by M. Maureen

Murphy

CRS Legal Sidebar WSLG831, Federal Securities Laws and Recent Data

Breaches, by Michael V. Seitzinger

CRS Legal Sidebar WSLG 906, Hackers Cannot Always Be Tried Where ThirdParty Victims Reside, by Charles Doyle

CRS Legal Sidebar WSLG 959, In the Matter of LabMD: The FTC Must Publicly

Disclose Its Data Security Standards, by Gina Stevens

CRS Report IN10218, Information Warfare: Cyberattacks on Sony, by Catherine

A. Theohary

Congressional Research Service

34

.

Table 5. Cybercrime, Data Breaches, and Data Security

Title

c11173008

Source

Date

Pages

Notes

ThreatExchange

Facebook

Ongoing

ThreatExchange is a set of application programming interfaces, or

APIs, that let disparate companies trade information about the

latest online attacks. Built atop the Facebook Platform—the

standard set of tools for coding applications atop the company’s

worldwide social network—ThreatExchange is used by Facebook

and a handful of other companies, including Tumblr, Pinterest,

Twitter, and Yahoo. Access to the service is strictly controlled,

but [Facebook] hopes to include other companies as time goes

on.

HHS Breach Portal: Breaches Affecting 500 or

More Individuals

Health and Human

Services (HHS)

Ongoing

As required by Section 13402(e)(4) of the HITECH Act, the

Secretary must post a list of breaches of unsecured protected

health information affecting 500 or more individuals. These

breaches are now posted in a new, more accessible format that

allows users to search and sort the posted breaches. Additionally,

this new format includes brief summaries of the breach cases that

OCR has investigated and closed, as well as the names of private

practice providers who have reported breaches of unsecured

protected health information to the Secretary.

ThreatWatch

NextGov

Ongoing

N/A

ThreatWatch is a snapshot of the data breaches hitting

organizations and individuals, globally, on a daily basis. It is not an

authoritative list because many compromises are never reported

or even discovered. The information is based on accounts

published by outside news organizations and researchers.

Criminal Underground Economy Series

Trend Micro

Ongoing

N/A

A review of various cybercrime markets around the world.

Digital Attack Map

Arbor Networks

Ongoing

N/A

The map is powered by data fed from 270+ ISP customers

worldwide who have agreed to share network traffic and attack

statistics. The map displays global activity levels in observed attack

traffic, which it collected anonymously, and does not include any

identifying information about the attackers or victims involved in

any particular attack.

Global Botnet Map

Trend Micro

Ongoing

N/A

Trend Micro continuously monitors malicious network activities

to identify command-and-control (C&C) servers and help increase

protection against botnet attacks. The real-time map indicates the

locations of C&C servers and victimized computers they control

that have been discovered in the previous six hours.

CRS-35

.

Title

c11173008

Source

Date

Pages

Notes

HoneyMap

Honeynet Project

Ongoing

N/A

The HoneyMap displays malicious attacks as they happen. Each red

dot represents an attack on a computer. Yellow dots represent

honeypots or systems set up to record incoming attacks. The

black box on the bottom gives the location of each attack. The

Honeynet Project is an international 501c3 nonprofit security

research organization, dedicated to investigating the latest attacks

and developing open source security tools to improve Internet

security.

The Cyberfeed

Anubis Networks

Ongoing

N/A

This site provides real-time threat intelligence data worldwide.

Regional Threat Assessment: Infection Rates and

Threat Trends by Location Regional Threat

Assessment: Infection Rates and Threat Trends by

Location (Note: Select “All Regions” or a specific

country or region to view threat assessment

reports)

Microsoft Security

Intelligence Report (SIR)

Ongoing

N/A

This report provides data on infection rates, malicious websites,

and threat trends by regional location, worldwide.

Meet ‘Tox': Ransomware for the Rest of Us

McAfee Labs

May 23, 2015

N/A

The packaging of malware and malware-construction kits for

cybercrime “consumers” has been a long-running trend. Various

turnkey kits that cover remote access plus botnet plus stealth

functions are available just about anywhere. Ransomware, though

very prevalent, has not yet appeared in force in easy-to-deploy

kits. However, Tox is now available–and it’s free.

2014 Internet Crime Report

Internet Crime

Complaint Center (IC3)

May 19, 2015

48

IC3, a joint project of the National White Collar Crime Center

and the FBI, received 269,422 complaints last year consisting of a

wide array of scams affecting victims across all demographic

groups. In 2014, victims of Internet crimes in the United States

lost more than $800 million. On average, approximately 22,000

complaints were received each month.

Fifth Annual Benchmark Study on Privacy and

Security of Healthcare Data

Ponemon Institute

May 2015

7

A rise in cyberattacks against doctors and hospitals is costing the

U.S. health-care system $6 billion a year as organized criminals

who once targeted retailers and financial firms increasingly go

after medical records. Criminal attacks are up 125% compared

with five years ago replacing lost laptops as the leading threat.

The study also found most organizations are unprepared to

address new threats and lack adequate resources to protect

patient data.

CRS-36

.

c11173008

Title

Source

Best Practices for Victim Response and Reporting

of Cyber Incidents

Department of Justice

2015 Data Breach Investigations Report (DBIR)

Pages

Notes

April 29,

2015

15

DOJ issued new guidance for businesses on best practices for

handling cyber incidents. The guidance is broken down into what

companies should do— and should not do— before, during and

after an incident. The recommendations include developing an

incident response plan, testing it, identifying highly sensitive data

and risk management priorities, and connecting with law

enforcement and response firms in advance.

Verizon

April 14,

2015

70

A full three-quarters of attacks spread from the first victim to the

second in 24 hours or less, and more than 40% spread from the

first victim to the second in under an hour. On top of the speed

with which attackers compromise multiple victims, the useful

lifespan of shared information can sometimes be measured in

hours. Researchers also found that of the IP addresses observed in

current information sharing feeds, only 2.7% were valid for more

than a day, and the number dwindles from there. Data show that

information sharing has to be good to be effective.

2014 Global Threat Intel Report

CrowdStrike

February 6,

2015

N/A

This report summarizes CrowdStrike’s year-long daily scrutiny of

more than 50 groups of cyber threat actors, including 29 different

state-sponsored and nationalist adversaries. Key findings explain

how financial malware changed the threat landscape and point of

sale malware became increasingly prevalent. The report also

profiles a number of new and sophisticated adversaries from

China and Russia, including Hurricane Panda, Fancy Bear, and

Berserk Bear.

Unique in the shopping mall: On the

reidentifiability of credit card metadata

Science Magazine

January 30,

2015

5

MIT scientists showed they can identify an individual with more

than 90% accuracy by looking at just four purchases, three if the

price is included—and this is after companies “anonymized" the

transaction records, saying they wiped away names and other

personal details.

Ransomware on the Rise: FBI and Partners

Working to Combat This Cyber Threat

FBI

January 20,

2015

N/A

Ransomware scams involve a type of malware that infects

computers and restricts users’ access to their files or threatens

the permanent destruction of their information unless a ransom—

anywhere from hundreds to thousands of dollars—is paid. The

site offers information on the FBI’s and federal, international, and

private-sector partners’ proactive steps to neutralize some of the

more significant ransomware scams through law enforcement

actions against major botnets.

CRS-37

Date

.

Title

c11173008

Source

Date

Pages

Notes

26

Sophos Labs Hungary evaluated the malware and APT campaigns

of several groups that all leveraged a particular exploit—a

sophisticated attack against a specific version of Microsoft Office.

The report found that none of the groups were able to modify the

attack enough to infect other versions of Office, even though

several versions were theoretically vulnerable to the same type of

attack. Despite the aura of skill and complexity that seems to

surround APTs, they are much less sophisticated than they are

given credit for. The APT groups are lacking in quality assurance.

Many attacks are not thoroughly tested and attackers fail to

recognize when some functionality of the attack is not working

properly.

Exploit This: Evaluating the Exploit Skills of

Malware Groups

Sophos Labs Hungary

January 2015

The Cost of Malware Containment

(free registration required)

Ponemon Institute

January 2015

Addressing the cybersecurity Malicious Insider

threat

Schluderberg, Larry

(Utica College Master's

Thesis)

January 2015

80

The purpose of this research was to investigate who constitutes

MI threats, why and how they initiate attacks, the extent to which

MI activity can be modeled or predicted, and to suggest some risk

mitigation strategies. The results reveal that addressing the

Malicious Insider threat is much more than just a technical issue.

Dealing effectively with the threat involves managing the dynamic

interaction between employees, their work environment and

work associates, the systems with which they interact, and

organizational policies and procedures.

The Underground Hacker Markets are Booming

with Counterfeit Documents, Premiere Credit

Cards, Hacker Tutorials, and 1000% Satisfaction

Guarantees

Dell Secure Works

December

2014

16

Researchers examined dozens of underground hacker markets for

this second annual survey and found that business is booming.

Prices have gone down for many items, and the offerings have

expanded. As the report puts it: “Underground hackers are

monetizing every piece of data they can steal or buy and are

continually adding services so other scammers can successfully

carry out online and in-person fraud."

CRS-38

A survey of more than 600 U.S. IT and IT security practitioners

found that in a typical week, organizations receive an average of

nearly 17,000 malware alerts; only 19% are deemed reliable, or

worthy of action. Compounding the problem, respondents believe

their prevention tools miss 40% of malware infections in a typical

week.

.

Title

c11173008

Source

Date

Pages

Notes

What Happens When You Swipe Your Card?

60 Minutes

November

30, 2014

N/A

From the script for the segment “Swiping Your Card”:

“Sophisticated cyberthieves steal your credit card information.

Common criminals buy it and go on shopping sprees—racking up

billions of dollars in fraudulent purchases. The cost of the fraud is

calculated into the price of every item you buy. When computer

crooks swipe your card number, we all end up paying the price.

2014 is becoming known as the ‘year of the data breach.’"

Continuing Federal Cyber Breaches Warn Against

Cybersecurity Regulation

Heritage Foundation

October 27,

2014

N/A

This is a list of federal government cybersecurity breaches and

failures, most of which occurred during 2013 and 2014. The list is

part of a continuing series published by Heritage that serves as a

long-term compilation of open-source data about federal

cybersecurity breaches dating back to 2004.

2014 Cost of Cybercrime Global Report (Email

registration required.)

Hewlett-Packard

Enterprise Security and

the Ponemon Institute

October 8,

2014

30

This 2014 global study of U.S.-based companies, which spanned

seven nations, found that over the course of a year the average

cost of cybercrime climbed by more than 9% to $12.7 million for

companies in the United States, up from $11.6 million in the 2013

study. The average time to resolve a cyberattack is also rising,

climbing to 45 days from 32 days in 2013.

How Consumers Foot the Bill for Data Breaches

(infographic)

NextGov.com

August 7,

2014

Is Ransomware Poised for Growth?

Symantec

July 14, 2014

N/A

Ransomware usually masquerades as a virtual “wheel clamp” for

the victim’s computer. For example, pretending to be from the

local law enforcement, it might suggest the victim had been using

the computer for illicit purposes and claim that to unlock his or

her computer the victim would have to pay a fine—often between

$100 and $500. The use of Ransomware escalated in 2013, with a

500% (sixfold) increase in attack numbers between the start and

end of the year.

iDATA: Improving Defences Against Targeted

Attack

Centre for the

Protection of National

Infrastructure (UK)

July 2014

8

The iDATA program consists of a number of projects aimed at

addressing threats posed by nation-states and state-sponsored

actors. iDATA has resulted in several outputs for the

cybersecurity community. This document provides a description

of the iDATA program and a summary of the reports.

CRS-39

More than 600 data breaches occurred in 2013 alone, with an

average organizational cost of more than $5 million. But in the

end, it is the customers who are picking up the tab, from higher

retail costs to credit card reissue fees.

.

Title

c11173008

Source

Date

Pages

Notes

Cyber Risks: The Growing Threat

Insurance Information

Institute

June 27,

2014

27

Although cyber risks and cybersecurity are widely acknowledged

to be serious threats, many companies today still do not purchase

cyber risk insurance. Insurers have developed specialist cyber

insurance policies to help businesses and individuals protect

themselves from the cyber threat. Market intelligence suggests

that the types of specialized cyber coverage being offered by

insurers are expanding in response to this fast-growing market

need.

Hackers Wanted: An Examination of the

Cybersecurity Labor Market

RAND Corporation

June 24,

2014

110

RAND examined the current status of the labor market for

cybersecurity professionals—with an emphasis on their being

employed to defend the United States. This effort was in three

parts: first, a review of the literature; second, interviews with

managers and educators of cybersecurity professionals,

supplemented by reportage; and third, an examination of the

economic literature about labor markets. RAND also

disaggregated the broad definition of “cybersecurity professionals”

to unearth skills differentiation as relevant to this study.

Global Cybercrime: The Interplay of Politics and

Law

Centre for International

Governance Innovation

June 20,

2014

23

This paper explores the recent unsealing of a 31-count indictment

against 5 Chinese government officials and a significant cyber

breach perpetrated by Chinese actors against Western oil, energy,

and petrochemical companies. The paper concludes by noting that

increased cooperation between governments is necessary but

unlikely to occur as long as the discourse surrounding cybercrime

remains so heavily politicized and securitized. If governments

coalesced around the notion of trying to prevent the long-term

degradation of trust in the online economy, then they might

profitably advance the dialogue away from mutual suspicion and

toward mutual cooperation.

Net Losses: Estimating the Global Cost of

Cybercrime

Center for Strategic and

International Studies and

McAfee

June 2014

24

This report explores the economic impact of cybercrime,

including estimation, regional variances, IP theft, opportunity and

recovery costs, and the future of cybercrime.

2014 U.S. State of Cybercrime Survey

PricewaterhouseCooper

s, CSO Magazine, the

CERT Division of the

Software Engineering

Institute at Carnegie

Mellon University, and

the U.S. Secret Service

May 29, 2014

21

The cybersecurity programs of U.S. organizations do not rival the

persistence, tactical skills, and technological prowess of their

potential cyber adversaries. This year, three out of four (77%)

respondents to the survey had detected a security event in the

past 12 months, and more than one-third (34%) said the number

of security incidents detected had increased over the previous

year.

CRS-40

.

Title

c11173008

Source

Date

Pages

Notes

Privileged User Abuse and The Insider Threat

(Requires free registration to access.)

Ponemon Institute and

Raytheon

May 21, 2014

32

The report looks at what companies are doing right and the

vulnerabilities that need to be addressed with policies and

technologies. One problematic area is the difficulty in actually

knowing if an action taken by an insider is truly a threat. Sixty-nine

percent of respondents say they do not have enough contextual

information from security tools to make this assessment, and 56%

say security tools yield too many false positives.

Online Advertising and Hidden Hazards to

Consumer Security and Data Privacy

Senate Permanent

Subcommittee on

Investigations

May 15, 2014

47

The report found consumers could expose themselves to malware

just by visiting a popular website. It noted that the complexity of

the industry made it possible for both advertisers and host

websites to defer responsibility and that consumer safeguards

failed to protect against online abuses. The report also warned

that current practices do not create enough incentives for “online

advertising participants” to take preventive measures.

Sharing Cyberthreat Information Under 18 USC §

2702(a)(3)

Department of Justice

May 9, 2014

7

The Department of Justice issued guidance for Internet service

providers to assuage legal concerns about information sharing.

The white paper interprets the Stored Communications Act,

which prohibits providers from voluntarily disclosing customer

information to governmental entities. The white paper says the

law does not prohibit companies from divulging data in the

aggregate, without any specific details about identifiable

customers.

The Rising Strategic Risks of Cyberattacks

McKinsey and Company

May 2014

N/A

Companies are struggling with their capabilities in cyber risk

management. As highly visible breaches occur with increasing

regularity, most technology executives believe they are losing

ground to attackers. Organizations large and small lack the facts to

make effective decisions, and traditional “protect the perimeter”

technology strategies are proving insufficient.

Big Data: Seizing Opportunities, Preserving Values

White House

May 2014

85

Findings include a set of consumer protection recommendations,

such as national data-breach legislation, and a fresh call for

baseline consumer-privacy legislation first recommended in 2012.

The Target Breach, by the Numbers

Krebs on Security

May 6, 2014

N/A

A synthesis of numbers associated with the Target data breach of

December 19, 2013 (e.g., number of records stolen, estimated

dollar cost to credit unions and community banks, amount of

money Target estimates it will spend upgrading payment terminals

to support Chip-and-PIN enabled cards).

CRS-41

.

Title

c11173008

Source

Date

Pages

Notes

Heartbleed’s Impact

Pew Research Center

April 30,

2014

13

The Heartbleed security flaw on one of the most widely used

“secure socket” encryption programs on the Internet had an

impact on a notable share of Internet users. Some 60% of adults

(and 64% of Internet users) said they had heard about the bug.

Some 19% of adults said they had heard a lot about it, and 41%

said they had heard a little about it. However, the Heartbleed

story drew much less intensity and scope of attention than other

big news stories.

Russian Underground Revisited

Trend Micro

April 28,

2014

25

The price of malicious software—designed to enable online bank

fraud, identity theft, and other cybercrimes—is falling dramatically

in some of the Russian-language criminal markets in which it is

sold. Falling prices are a result not of declining demand but rather

of an increasingly sophisticated marketplace. This report outlines

the products and services being sold and what their prices are.

A “Kill Chain” Analysis of the 2013 Target Data

Breach

Senate Commerce

Committee

March 26,

2014

18

This report analyzes what has been reported to date about the

Target data breach, using the intrusion kill chain framework, an

analytical tool introduced by Lockheed Martin security

researchers in 2011 and today widely used by information security

professionals in both the public and private sectors. This analysis

suggests that Target missed a number of opportunities along the

kill chain to stop the attackers and prevent the massive data

breach.

Markets for Cybercrime Tools and Stolen Data

RAND Corporation

National Security

Research Division and

Juniper Networks

March 25,

2014

83

This report, part of a multiphase study on the future security

environment, describes the fundamental characteristics of the

criminal activities in cyberspace markets and how they have grown

into their current state to explain how their existence can harm

the information security environment.

CRS-42

.

Title

c11173008

Source

Date

Pages

Notes

Merchant and Financial Trade Associations

Announce Cybersecurity Partnership

Retail Industry Leaders

Association

February 13,

2014

N/A

Trade associations representing the merchant and financial

services industries announced a new cybersecurity partnership.

The partnership will focus on exploring paths to increased

information sharing, better card security technology, and

maintaining the trust of customers. Discussion regarding the

partnership was initiated by the Retail Industry Leaders

Association and the Financial Services Roundtable, joined by the

American Bankers Association, the American Hotel and Lodging

Association, the Clearing House, the Consumer Bankers

Association, the Food Marketing Institute, the Electronic

Transactions Association, the Independent Community Bankers of

America, the International Council of Shopping Centers, the

National Associations of Convenience Stores, the National

Grocers Association, the National Restaurant Association, and the

National Retail Federation.

FTC Statement Marking the FTC’s 50th Data

Security Settlement

Federal Trade

Commission (FTC)

January 31,

2014

2

The FTC announces its 50th data security settlement. What

started in 2002 with a single case applying established FTC Act

precedent to the area of data security has grown into an

enforcement program that has helped to increase protections for

consumers and encouraged companies to make safeguarding

consumer data a priority.

Worst Practices Guide to Insider Threats: Lessons

from Past Mistakes

American Academy of

Arts and Sciences

January 2014

32

From the report: “Here, we are presenting a kind of ‘worst

practices’ guide of serious mistakes made in the past regarding

insider threats. While each situation is unique, and serious insider

problems are relatively rare, the incidents we describe reflect

issues that exist in many contexts and that every nuclear security

manager should consider. Common organizational practices—such

as prioritizing production over security, failure to share

information across subunits, inadequate rules or inappropriate

waiving of rules, exaggerated faith in group loyalty, and excessive

focus on external threats—can be seen in many past failures to

protect against insider threats.”

ENISA Threat Landscape 2013—Overview of

Current and Emerging Cyber-Threats

European Union Agency

for Network and

Information Security

(ENISA)

December

11, 2013

70

The report is a collection of top cyber threats that have been

assessed in the reporting period (i.e., within 2013). ENISA has

collected more than 250 reports regarding cyber threats, risks,

and threat agents. This report is a comprehensive compilation of

the top 15 cyber threats assessed.

CRS-43

.

Title

c11173008

Source

Date

Pages

Notes

Cyber-enabled Competitive Data Theft: A

Framework for Modeling Long-Run Cybersecurity

Consequences

Brookings Institution

December

2013

18

Economic espionage has existed at least since the industrial

revolution, but the scope of modern cyber-enabled competitive

data theft may be unprecedented. In this paper, the authors

present what they believe is the first economic framework and

model to understand the long-run impact of competitive data theft

on an economy by taking into account the actual mechanisms and

pathways by which theft harms the victims.

Trends in Incident Response in 2013

U.S. Industrial Control

System Cyber

Emergency Response

Team (ICS-CERT)

Monitor

OctoberDecember

2013

14

In 2013, ICS-CERT responded to 256 incidents reported either

directly from asset owners or through other trusted partners.

Most of these incidents were initially detected in business

networks of critical infrastructure organizations that operate

industrial control systems. Of the 256 reported incidents, 59%, or

151 incidents, occurred in the energy sector, which exceeded all

incidents reported in other sectors combined.

Illicit Cyber Activity Involving Fraud

Carnegie Mellon

University Software

Engineering Institute

August 8,

2013

28

Technical and behavioral patterns were extracted from 80 fraud

cases—67 insider and 13 external—that occurred between 2005

and the present. These cases were used to develop insights and

risk indicators to help private industry, government, and law

enforcement more effectively prevent, deter, detect, investigate,

and manage malicious insider activity within the banking and

finance sectors.

The Economic Impact of Cybercrime and Cyber

Espionage

Center for Strategic and

International Studies

July 22, 2013

20

Losses to the United States (the country in which data is most

accessible) may reach $100 billion annually. The cost of

cybercrime and cyber espionage to the global economy is some

multiple of this, likely measured in hundreds of billions of dollars.

Cyber-Crime, Securities Markets, and Systemic

Risk

World Federation of

Exchanges and the

International

Organization of

Securities Commissions

July 16, 2013

59

This report explores the nature and extent of cybercrime in

securities markets so far and the potential systemic risk aspects of

this threat. It presents the results of a survey to the world’s

exchanges on their experiences with cybercrime, cybersecurity

practices, and perceptions of the risk.

Towards Trustworthy Social Media and

Crowdsourcing

Wilson Center

May 2013

12

Individuals and organizations interested in using social media and

crowdsourcing currently lack two key sets of information: a

systematic assessment of the vulnerabilities in these technologies

and a comprehensive set of best practices describing how to

address those vulnerabilities. Identifying those vulnerabilities and

developing those best practices are necessary to address a

growing number of cybersecurity incidents ranging from innocent

mistakes to targeted attacks that have claimed lives and cost

millions of dollars.

CRS-44

.

c11173008

Title

Source

Date

Pages

Notes

Remaking American Security: Supply Chain

Vulnerabilities and National Security Risks Across

the U.S. Defense Industrial Base

Alliance for American

Manufacturing

May 2013

355

Because the supply chain is global, it makes sense for U.S. officials

to cooperate with other nations to ward off cyberattacks.

Increased international cooperation to secure the integrity of the

global IT system is a valuable long-term objective.

Comprehensive Study on Cybercrime

United Nations Office

on Drugs and Crime

February

2013

320

The study examined the problem of cybercrime from the

perspective of governments, the private sector, academia, and

international organizations. It presents its results in eight chapters,

covering Internet connectivity and cybercrime; the global

cybercrime picture; cybercrime legislation and frameworks;

criminalization of cybercrime; law enforcement and cybercrime

investigations; electronic evidence and criminal justice;

international cooperation in criminal matters involving cybercrime;

and cybercrime prevention.

HoneyMap - Visualizing Worldwide Attacks in

Real-Time and Honeynet Map

The Honeynet Project

October 1,

2012

N/A

The HoneyMap shows a real-time visualization of attacks against

the Honeynet Project’s sensors deployed around the world.

Does Cybercrime Really Cost $1 Trillion?

ProPublica

August 1,

2012

N/A

In a news release to announce its 2009 report, Unsecured

Economies: Protecting Vital Information, computer security firm

McAfee estimated a $1 trillion global cost for cybercrime. The

number does not appear in the report itself. This estimate is

questioned even by the three independent researchers from

Purdue University whom McAfee credits with analyzing the raw

data from which the estimate was derived. An examination by

ProPublica has found new grounds to question the data and

methods used to generate these numbers, which McAfee and

Symantec say they stand behind.

Information Security: Cyber Threats Facilitate

Ability to Commit Economic Espionage

Government

Accountability Office

(GAO)

June 28,

2012

20

This statement discusses (1) cyber threats facing the nation’s

systems, (2) reported cyber incidents and their impacts, (3)

security controls and other techniques available for reducing risk,

and (4) the responsibilities of key federal entities in support of

protecting Internet protocol.

Measuring the Cost of Cybercrime

11th Annual Workshop

on the Economics of

Information Security

June 25,

2012

N/A

From the report: “For each of the main categories of cybercrime

we set out what is and is not known of the direct costs, indirect

costs and defence costs—both to the UK and to the world as a

whole.”

The Impact of Cybercrime on Businesses

Ponemon Institute

May 2012

21

The study found that targeted attacks on businesses cost

enterprises an average of $214,000. The expenses are associated

with forensic investigations, investments in technology, and brand

recovery costs.

CRS-45

.

Title

Source

Date

Pages

Notes

Proactive Policy Measures by Internet Service

Providers against Botnets

Organization for

Economic Co-operation

and Development

(OECD)

May 7, 2012

25

This report analyzes initiatives in a number of countries through

which end-users are notified by Internet service providers (ISPs)

when their computers are identified as being compromised by

malicious software and encouraged to take action to mitigate the

problem.

Developing State Solutions to Business Identity

Theft: Assistance, Prevention and Detection Efforts

by Secretary of State Offices

National Association of

Secretaries of State

(NASS)

January 2012

23

This white paper is the result of efforts by the 19-member NASS

Business Identity Theft Task Force to develop policy guidelines

and recommendations for state leaders dealing with identity fraud

cases involving public business records.

Twenty Critical Security Controls for Effective

Cyber Defense: Consensus Audit Guidelines

SANS Institute

October 3,

2011

77

The 20 security measures are intended to focus agencies’ limited

resources on plugging the most common attack vectors.

Revealed: Operation Shady RAT: an Investigation

Of Targeted Intrusions Into 70+ Global

Companies, Governments, and Non-Profit

Organizations During the Last 5 Years

McAfee

August 2,

2011

14

A cyber-espionage operation lasting many years penetrated 72

government and other organizations, most of them in the United

States, and has copied everything from military secrets to

industrial designs, according to technology security company

McAfee. (See page 4 for the types of compromised parties, page 5

for the geographic distribution of victim’s country of origin, pages

7-9 for the types of victims, and pages 10-13 for the number of

intrusions for 2007-2010).

The Role of Internet Service Providers in Botnet

Mitigation: an Empirical Analysis Based on Spam

Data

OECD

November

12, 2010

31

This working paper considers whether ISPs can be critical control

points for botnet mitigation, how the number of infected machines

varies across ISPs, and why.

Untangling Attribution: Moving to Accountability in

Cyberspace (Testimony)

Council on Foreign

Relations

July 15, 2010

14

Robert K. Knake’s testimony before the House Committee on

Science and Technology on the role of attack attribution in

preventing cyberattacks and how attribution technologies can

affect the anonymity and privacy of Internet users.

Technology, Policy, Law, and Ethics Regarding U.S.

Acquisition and Use of Cyberattack Capabilities

National Research

Council

2009

368

This report explores important characteristics of cyberattacks. It

describes the current international and domestic legal structure as

it might apply to cyberattacks and considers analogies to other

domains of conflict to develop relevant insights.

Source: Highlights compiled by CRS from the reports.

c11173008

CRS-46

.

Table 6. National Security, Cyber Espionage, and Cyberwar

Title

c11173008

Source

Date

Pages

Notes

Cyberthreat: Real-Time Map

Kaspersky Labs

Ongoing

N/A

Kaspersky Labs has launched an interactive cyber threat map that

lets viewers see cybersecurity incidents as they occur around the

world in real time. The interactive map includes malicious objects

detected during on-access and on-demand scans, email and web

antivirus detections, and objects identified by vulnerability and

intrusion detection subsystems.

Cybersecurity: Jihadism and the internet

European

Parliament Think

Tank

May 18,

2015

2

Since the beginning of the conflict in Syria in March 2011, the

numbers of European citizens supporting or joining the ranks of

ISIL/Da'esh have been growing steadily, and may now be as high

as 4,000 individuals. At the same time, the possible avenues for

radicalisation are multiplying and the risks of domestic terrorism

increasing. The proliferation of global jihadi messaging online and

their reliance on social networks suggest that the Internet is

increasingly a tool for promoting jihadist ideology, collecting funds

and mobilizing their ranks.

APT30 and the Mechanics of a Long-Running CyberEspionage Operation: How a Cyber Threat Group

Exploited Governments and Commercial Entities Across

Southeast Asia and India for Over a Decade

FireEye

April 2015

70

A Chinese government hacking team has used the same basic set

of tools to spy on Southeast Asian and Indian dignitaries for a

decade, demonstrating the low level of cyber defenses protecting

government information across broad swaths of the world. The

fact this group, APT30, has been able to use the same basic set of

malware tools against government networks since at least 2005

suggests its targets remained unaware for more than a decade

they were being spied on, or were incapable of countering the

threat.

Excepted Service (DoD)

Office of

Personnel

Management

March 5,

2015

3

DOD is given authority to make permanent, time-limited and

temporary appointments not to exceed 3,000 positions that

require unique cybersecurity skills and knowledge to perform

cyber risk and strategic analysis, incident handling and

malware/vulnerability analysis, program management, distributed

control systems security, cyber incident response, cyber exercise

facilitation and management, cyber vulnerability detection and

assessment, network and systems engineering, enterprise

architecture, investigation, investigative analysis and cyber-related

infrastructure inter-dependency analysis.

CRS-47

.

Title

c11173008

Source

Date

Pages

Notes

Worldwide Threat Assessment of the US Intelligence

Community

Director of

National

Intelligence

February 26,

2015

29

Cybersecurity is the first threat listed in this annual review of

worldwide threats to the United States. Despite ever-improving

network defenses, the diverse possibilities for remote hacking

intrusions, supply chain operations to insert compromised

hardware or software, and malevolent activities by human insiders

will hold nearly all ICT systems at risk for years to come. In

short, the cyber threat cannot be eliminated; rather, cyber risk

must be managed. Moreover, the risk calculus employed by some

private-sector entities does not adequately account for foreign

cyber threats or the systemic interdependencies between

different critical infrastructure sectors.

The Impact of the Dark Web on Internet Governance and

Cyber Security

Global

Commission on

Internet

Governance

February

2015

18

There has not been much consideration of the governance of the

deep Web and the dark Web. The term deep Web is used to

denote a class of content on the Internet that, for various

technical reasons, is not indexed by search engines. The dark

Web is a part of the deep Web that has been intentionally hidden

and is inaccessible through standard Web browsers. The deep

Web has the potential to host an increasingly high number of

malicious services and activities. To formulate comprehensive

strategies and policies for governing the Internet, it is important

to consider insights on its farthest reaches— the deep Web and,

more importantly, the dark Web. The paper endeavors to

provide a broader understanding of the dark Web and its impact

on people lives.

Attributing Cyber Attacks

Thomas Rid and

Ben Buchanan,

Journal of

Strategic Studies

December

23, 2014

36

“This article argues that attribution is what states make of it. To

show how, we introduce the Q Model: designed to explain, guide,

and improve the making of attribution. Matching an offender to an

offence is an exercise in minimizing uncertainty on three levels:

tactically, attribution is an art as well as a science; operationally,

attribution is a nuanced process not a black-and-white problem;

and strategically, attribution is a function of what is at stake

politically. Successful attribution requires a range of skills on all

levels, careful management, time, leadership, stress-testing,

prudent communication, and recognizing limitations and

challenges.”

CRS-48

.

Title

c11173008

Source

Date

Pages

Notes

Operation Cleaver

Cylance

December

2, 2014

86

A sophisticated hacking group with ties to Iran has probed and

infiltrated targets across the United States and 15 other nations

during the past two years in a series of cyberattacks dubbed

“Operation Cleaver.” The Cleaver group has evolved faster than

any previous Iranian campaign, according to the report, which

calls Iran “the new China” and expresses concern that the

group’s surveillance operations could evolve into sophisticated,

destructive attacks.

Legal Issues Related to Cyber

NATO Legal

Gazette

December

2014

74

The NATO Legal Gazette contains thematically organized articles

usually written by authors who are military or civilian legal

personnel working at NATO or in the governments of NATO

and partner nations. Its purpose is to share articles of significance

for the large NATO legal community and connect legal

professionals of the Alliance. It is not a formal NATO document.

The National Intelligence Strategy of the United States of

America 2014

Office of the

Director of

National

Intelligence

September

18, 2014

24

Cyber intelligence is one of four “primary topical missions” the

intelligence community must accomplish. Both state and nonstate

actors use digital technologies to achieve goals, such as fomenting

instability or achieving economic and military advantages. They do

so “often faster than our ability to understand the security

implications and mitigate potential risks,” the strategy states. To

become more effective in the cyber arena, the intelligence

community will improve its ability to correctly attribute attacks.

Today’s Rising Terrorist Threat and the Danger to the

United States: Reflections on the Tenth Anniversary of the

9/11 Commission Report

The Annenberg

Public Policy

Center and the

Bipartisan Policy

Center

July 22, 2014

48

Members of the panel that studied the 2001 attacks urge

Congress to enact cybersecurity legislation, the White House to

communicate the consequences of potential cyberattacks to

Americans, and leaders to work with allies to define what

constitutes an online attack on another country.

Surviving on a Diet of Poisoned Fruit: Reducing the

National Security Risks of America’s Cyber Dependencies

Center for a

New American

Security

July 2014

64

In the report, the author examines existing information on

technology security weaknesses and provides nine specific

recommendations for the U.S. government and others to cope

with these insecurities.

CRS-49

.

Title

c11173008

Source

Date

Pages

Notes

Baseline Review: ICT-Related Processes and Events,

Implications for International and Regional Security (20112013)

ICT4Peace

May 1, 2014

50

The report is structured around the following three areas: (1)

international and regional security (the predominant focus); (2)

transnational crime and terrorism; and (3) governance, human

rights, and development. These areas are obviously

interdependent, with developments in one area often impacting

another, yet they have traditionally been approached separately

through distinct communities of practice and fora. The report will

serve as a baseline for future annual reports. It covers the period

spanning from January 2011 to December 2013 and provides

background on earlier events.

M Trends: Beyond the Breach: 2014 Threat Report

Mandiant

April 2014

28

From the report: “One conclusion is inescapable: the list of

potential targets has increased, and the playing field has grown,

Cyber-threat actors are expanding the uses of computer network

exploitation to fulfill an array of objectives, from the economic to

the political. Threat actors are not only interested in seizing the

corporate crown jewels but are also looking for ways to publicize

their views, cause physical destruction and influence global

decision makers. Private organizations have increasingly become

collateral damage in political conflicts. With no diplomatic

solution in sight, the ability to detect and respond to attacks has

never been more important.”

Emerging Cyber Threats Report 2014

Georgia Institute

of Technology

January 2014

16

Brief compilation of academic research on losing control of cloud

data, insecure but connected devices, attackers adapting to

mobile ecosystems, the high costs of defending against

cyberattacks, and advances in information manipulation.

Cybersecurity and Cyberwar: What Everyone Needs to

Know

Brookings

Institution

January 2014

306

Authors Peter W. Singer and Allan Friedman look at

cybersecurity issues faced by the military, government, businesses,

and individuals and examine what happens when these entities try

to balance security with freedom of speech and the ideals of an

open Internet.

Cyber-enabled Competitive Data Theft: A Framework for

Modeling Long-Run Cybersecurity Consequences

Brookings

Institution

December

2013

18

Economic espionage has existed at least since the industrial

revolution, but the scope of modern cyber-enabled competitive

data theft may be unprecedented. In this paper, the authors

present what they believe is the first economic framework and

model to understand the long-run impact of competitive data

theft on an economy by taking into account the actual

mechanisms and pathways by which theft harms the victims.

CRS-50

.

Title

c11173008

Source

Date

Pages

To Kill a Centrifuge: A Technical Analysis of What

Stuxnet’s Creators Tried to Achieve

The Langner

Group

November

2013

36

This document summarizes the most comprehensive research on

the Stuxnet malware so far. It combines results from reverse

engineering the attack code with intelligence on the design of the

attacked plant and background information on the attacked

uranium enrichment process. It looks at the attack vectors of the

two different payloads contained in the malware and provides an

analysis of the bigger and much more complex payload that was

designed to damage centrifuge rotors by overpressure. With both

attack vectors viewed in context, conclusions are drawn about

the reasoning behind a radical change of tactics between the

complex earlier attack and the comparatively simple later attack

that tried to manipulate centrifuge rotor speeds.

2013 Annual Report to Congress

U.S.-China

Economic

Commission

October 20,

2013

465

In 2013, the commission continued its close examination of

China’s cyber capabilities. Strong evidence has emerged that the

Chinese government is directing and executing a large-scale cyber

espionage campaign against the United States, including the U.S.

government and private companies. However, public exposure of

Chinese cyber espionage in 2013 has apparently not changed

China’s attitude about the use of cyber espionage to steal

intellectual property and proprietary information. (See Chapter 2,

Section 2: “China’s Cyber Activities.”)

W32.Duqu: The Precursor to the Next Stuxnet

Symantec

November

14, 2013

N/A

On October 14, 2011, a research lab with strong international

connections alerted Symantec to a sample that appeared to be

very similar to Stuxnet, the malware that wreaked havoc in Iran’s

nuclear centrifuge farms. The lab named the threat Duqu because

it creates files with the file name prefix DQ. The research lab

provided Symantec with samples recovered from computer

systems located in Europe as well as a detailed report with initial

findings, including analysis comparing the threat to Stuxnet.

Offensive Cyber Capabilities at the Operational Level The Way Ahead

Center for

Strategic and

International

Studies (CSIS)

September

16, 2013

CRS-51

20

Notes

The specific question this report examines is whether the

Defense Department should make a more deliberate effort to

explore the potential of offensive cyber tools at levels below that

of a combatant command.

.

Title

c11173008

Source

Date

Pages

Cyber Warfare: Is the risk of cyber warfare overrated?

The Economist

August 2,

2013

N/A

(Economist Debates adapt the Oxford style of debating to an

online forum. Each side has three chances to persuade readers:

opening, rebuttal, and closing.) From the debate: “Separating hype

from the urgent questions is hard. Amid talk of a ‘digital Pearl

Harbour’ and ‘advanced persistent threats’ it is hard to know

whether we are really ‘losing the war’ against the purveyors and

users of malware and digital weapons.”

The Economic Impact of Cybercrime and Cyber Espionage

Center for

Strategic and

International

Studies (CSIS)

July 22, 2013

20

Losses to the United States (the country in which data is most

accessible) may reach $100 billion annually. The cost of

cybercrime and cyber espionage to the global economy is some

multiple of this, likely measured in hundreds of billions of dollars.

Strategies for Resolving the Cyber Attribution Challenge

Air University,

Maxwell Air

Force Base

May 2013

109

Private-sector reports have proven that it is possible to

determine the geographic reference of threat actors to varying

degrees. Based on these assumptions, nation-states, rather than

individuals, should be held culpable for the malicious actions and

other cyber threats that originate in or transit information

systems within their borders or that are owned by their

registered corporate entities. This work builds on other appealing

arguments for state responsibility in cyberspace.

Role of Counterterrorism Law in Shaping ‘ad Bellum’

Norms for Cyber Warfare

International Law

Studies (U.S.

Naval War

College)

April 1,

2013

42

From the report: “The prospect of cyber war has evolved from

science fiction and over-the-top doomsday depictions on

television, films, and in novels to reality and front-page news.…

To date there has been little attention given to the possibility that

international law generally and counterterrorism law in particular

could and should develop a subset of cyber-counterterrorism law

to respond to the inevitability of cyberattacks by terrorists and

the use of cyber weapons by governments against terrorists, and

to supplement existing international law governing cyber war

where the intrusions do not meet the traditional kinetic

thresholds.”

CRS-52

Notes

.

Title

c11173008

Source

Date

Pages

Cyber Incidents Attributed to China

Center for

Strategic and

International

Studies

March 11,

2013

15

Evidence that China and Chinese hackers are responsible for the

many incidents attributed to them. CSIS did a review of open

source literature identifying China as the source of hacking and

cyber espionage incidents. This is an initial list, as we know of

other major cyber incidents attributed to China by officials in

Australia, Canada, France, Germany, India, Japan, the UK, and

other countries not discussed here. We have broken our list into

two parts. The first section lists reports that identify specific

individuals and entities; the second section refers to incidents

ascribed generally to China. These reports identify six groups and

fourteen individuals, all but one connected to the Chinese

government and most with connections to the PLA, as

responsible for cyber espionage

The Tallinn Manual on the International Law Applicable to

Cyber Warfare

Cambridge

University Press/

NATO

Cooperative

Cyber Defence

Center of

Excellence

March 5,

2013

302

The Tallinn Manual identifies the international law applicable to

cyber warfare and sets out 95 “black-letter rules” governing such

conflicts. An extensive commentary accompanies each rule, which

sets forth the rule’s basis in treaty and customary law, explains

how the group of experts interpreted applicable norms in the

cyber context, and outlines any disagreements within the group

as to the rule’s application. (Note: The manual is not an official

NATO publication but rather an expression of opinions of a

group of independent experts acting solely in their personal

capacities.)

Cyberterrorism: A Survey of Researchers

Swansea

University

March 2013

21

This report provides an overview of findings from a project

designed to capture current understandings of cyberterrorism

within the research community. The project ran between June

2012 and November 2012, and it employed a questionnaire that

was distributed to more than 600 researchers, authors, and other

experts. Potential respondents were identified using a

combination of methods, including targeted literature reviews,

standing within relevant academic communities, snowballing from

earlier participants or contacts, and the use of two mailing lists. A

total of 118 responses were received from individuals working in

24 countries across 6 continents. Please contact the research

team with any enquiries on the project’s methods and findings

(see p. 21 for contact details).

CRS-53

Notes

.

Title

c11173008

Source

Date

Pages

Notes

APT1 [Advanced Persistent Threat 1]: Exposing One of

China’s Cyber Espionage Units

Mandiant

February 19,

2013

76

Mandiant conducted hundreds of investigations on computer

security breaches around the world. The details analyzed during

these investigations signal that the groups conducting these

breaches are based primarily in China and that the Chinese

government is aware of them.

Video demo of Chinese hacker activity

(Click on “APT1 Video” at top right of screen.)

Mandiant

February 19,

2013

N/A

Five-minute video of APT1 attacker sessions and intrusion

activities.

Responding to Cyber Attacks and the Applicability of

Existing International Law

Army War

College

January 2013

34

This paper identifies how the United States should respond to the

threat of cyber operations against essential government and

private networks. First, it examines the applicability of established

international law to cyber operations. Next, it proposes a method

for categorizing cyber operations across a spectrum synchronized

with established international law. Finally, it discusses actions

already taken by the United States to protect critical government

and private networks and concludes with additional steps the

United States should take to respond to the threat of cyber

operations.

Crisis and Escalation in Cyberspace

RAND

Corporation

December

2012

200

The report considers how the Air Force should integrate kinetic

and nonkinetic operations. Central to this process was careful

consideration of how escalation options and risks should be

treated, which, in turn, demanded a broader consideration across

the entire crisis-management spectrum. Such crises can be

managed by taking steps to reduce the incentives for other states

to step into crisis, controlling the narrative, understanding the

stability parameters of the crises, and trying to manage escalation

if conflicts arise from crises.

Cyberattacks Among Rivals: 2001-2011 (from the article,

“The Fog of Cyberwar” by Brandon Variano and Ryan

Maness [subscription required])

Foreign Affairs

November

21, 2012

N/A

A chart showing cyberattacks by initiator and victim, 2001-2011.

Emerging Cyber Threats Report 2013

Georgia Institute

of Technology

November

14, 2012

9

An examination of the cyber challenges of 2013, including new

and increasingly sophisticated means to capture and exploit user

data, escalating battles over the control of online information, and

continuous threats to the U.S. supply chain from global sources.

(From the annual Georgia Tech Cyber Security Summit 2012.)

CRS-54

.

Title

c11173008

Source

Date

Pages

Proactive Defense for Evolving Cyber Threats

Sandia National

Labs

November

2012

98

The project applied rigorous predictability-based analytics to two

central and complementary aspects of the network defense

problem—attack strategies of the adversaries and vulnerabilities

of the defenders’ systems—and used the results to develop a

scientifically grounded, practically implementable methodology for

designing proactive cyber defense systems.

Safeguarding Cyber-Security, Fighting in Cyberspace

International

Relations and

Security

Network (ISN)

October 22,

2012

N/A

Looks at the militarization of cybersecurity as a source of global

tension and makes the case that cyber warfare is already an

essential feature of many leading states’ strategic calculations,

followed by its opposite (i.e., the case that the threat posed by

cyber warfare capabilities is woefully overstated).

Before We Knew It: An Empirical Study of Zero-Day

Attacks In The Real World

Symantec

Research Labs

October 16,

2012

12

The paper describes a method for automatically identifying zeroday attacks from field-gathered data that records when benign

and malicious binaries are downloaded on 11 million real hosts

around the world. Searching this data set for malicious files that

exploit known vulnerabilities indicates which files appeared on the

Internet before the corresponding vulnerabilities were disclosed.

Investigative Report on the U.S. National Security Issues

Posed by Chinese Telecommunications Companies

Huawei and ZTE

House

Permanent Select

Committee on

Intelligence

October 8,

2012

60

The committee initiated this investigation in November 2011 to

inquire into the counterintelligence and security threat posed by

Chinese telecommunications companies doing business in the

United States.

Federal Support for and Involvement in State and Local

Fusion Centers

Senate

Permanent

Subcommittee on

Investigations

October 3,

2012

141

A two-year bipartisan investigation found that U.S. Department of

Homeland Security efforts to engage state and local intelligence

“fusion centers” have not yielded significant useful information to

support federal counterterrorism intelligence efforts. In Section

VI, “Fusion Centers Have Been Unable to Meaningfully

Contribute to Federal Counterterrorism Efforts,” Part G, “Fusion

Centers May Have Hindered, Not Aided, Federal

Counterterrorism Efforts,” the report discusses the Russian

“cyberattack” in Illinois.

Putting the “war” in cyberwar: Metaphor, analogy, and

cybersecurity discourse in the United States

First Monday

July 2, 2012

N/A

This essay argues that current contradictory tendencies are

unproductive and even potentially dangerous. It argues that the

war metaphor and nuclear deterrence analogy are neither natural

nor inevitable and that abandoning them would open up new

possibilities for thinking more productively about the full

spectrum of cybersecurity challenges, including the as-yet

unrealized possibility of cyberwar.

CRS-55

Notes

.

Title

c11173008

Source

Date

Pages

Notes

Nodes and Codes: The Reality of Cyber Warfare

U.S. Army School

of Advanced

Military Studies,

Command and

General Staff

May 17,

2012

62

Explores the reality of cyber warfare through the story of

Stuxnet. Three case studies evaluate cyber policy, discourse, and

procurement in the United States, Russia, and China before and

after Stuxnet to illustrate their similar, yet unique, realities of

cyber warfare.

United States Counter Terrorism Cyber Law and Policy,

Enabling or Disabling?

Triangle Institute

for Security

Studies

March 2012

34

From the report: “The incongruence between national

counterterrorism (CT) cyber policy, law, and strategy degrades

the abilities of federal CT professionals to interdict transnational

terrorists from within cyberspace. Specifically, national CT cyber

policies that are not completely sourced in domestic or

international law unnecessarily limit the latitude cyber CT

professionals need to effectively counter terrorists through the

use of organic cyber capabilities. To optimize national CT assets

and to stymie the growing threat posed by terrorists’ everexpanding use of cyberspace, national decision-makers should

modify current policies to efficiently execute national CT

strategies, albeit within the framework of existing CT cyberrelated statutes.”

A Cyberworm that Knows No Boundaries

RAND

Corporation

December

21, 2011

55

Stuxnet-like worms pose a serious threat even to infrastructure

and computer systems that are not connected to the Internet.

Defending against such attacks is an increasingly complex

prospect.

Department of Defense Cyberspace Policy Report: A

Report to Congress Pursuant to the National Defense

Authorization Act for Fiscal Year 2011, Section 934

Department of

Defense

November

2011

14

From the report: “When warranted, we will respond to hostile

attacks in cyberspace as we would to any other threat to our

country. We reserve the right to use all necessary means diplomatic, informational, military and economic - to defend our

nation, our allies, our partners and our interests.”

Cyber War Will Not Take Place

Journal of Strategic

Studies

October 5,

2011

29

The paper argues that cyber warfare has never taken place, is not

currently taking place, and is unlikely to take place in the future.

Foreign Spies Stealing U.S. Economic Secrets in

Cyberspace: Report to Congress on Foreign Economic

Collection and Industrial Espionage, 2009-2011

Office of the

National

Counterintelligen

ce Executive

October

2011

31

Because the United States is a leader in the development of new

technologies and a central player in global financial and trade

networks, foreign attempts to collect U.S. technological and

economic information will continue at a high level and will

represent a growing and persistent threat to U.S. economic

security. The nature of the cyber threat will evolve with

continuing technological advances in the global information

environment.

CRS-56

.

Title

c11173008

Source

Date

Pages

Notes

USCYBERCOM [U.S. Cyber Command] and Cyber

Security: Is a Comprehensive Strategy Possible?

Army War

College

May 12,

2011

32

Examines five aspects of USCYBERCOM: organization, command

and control, computer network operations, synchronization, and

resourcing. Identifies areas that currently present significant risk

to USCYBERCOM’s ability to create a strategy that can achieve

success in its cyberspace operations and recommends potential

solutions that can increase the effectiveness of the

USCYBERCOM strategy.

A Four-Day Dive Into Stuxnet’s Heart

Threat Level Blog

(Wired)

December

27, 2010

N/A

From the article: “It is a mark of the extreme oddity of the

Stuxnet computer worm that Microsoft’s Windows vulnerability

team learned of it first from an obscure Belarusian security

company that even they had never heard of.”

Did Stuxnet Take Out 1,000 Centrifuges at the Natanz

Enrichment Plant? A Preliminary Assessment

Institute for

Science and

International

Security

December

22, 2010

10

This report indicates that commands in the Stuxnet code

intended to increase the frequency of devices targeted by the

malware exactly match several frequencies at which rotors in

centrifuges at Iran’s Natanz enrichment plant are designed to

operate optimally or are at risk of breaking down and flying apart.

Stuxnet Analysis

European

Network and

Information

Security Agency

October 7,

2010

N/A

A European Union cybersecurity agency warns that the Stuxnet

malware is a game changer for critical information infrastructure

protection; programmable logic controllers of supervisory

control and data acquisition systems infected with the worm

might be programmed to establish destructive over/under

pressure conditions by running pumps at different frequencies.

Proceedings of a Workshop on Deterring Cyberattacks:

Informing Strategies and Developing Options for U.S.

Policy

National

Research Council

October 5,

2010

400

Per request of the Office of the Director of National Intelligence,

the National Research Council undertook a two-phase project

aimed to foster a broad, multidisciplinary examination of

strategies for deterring cyberattacks on the United States and of

the possible utility of these strategies for the U.S. government.

CRS-57

.

Title

Cyber Warfare: Armageddon in a Teacup?

Source: Highlights compiled by CRS from the reports.

c11173008

CRS-58

Source

Date

Pages

Army Command

and General Staff,

Fort

Leavenworth

December

11, 2009

106

Notes

This study examines cyber warfare conducted against Estonia in

2007, Georgia in 2008, and Israel in 2008. From the report: “In all

three cases Cyber Warfare did not achieve strategic political

objectives on its own. Cyber Warfare employed in the three

cases consisted mainly of Denial of Service attacks and website

defacement. These attacks were a significant inconvenience to the

affected nations, but the attacks were not of sufficient scope,

sophistication, or duration to force a concession from the

targeted nation. Cyber Warfare offensive capability does not

outmatch defensive capability to the extent that would allow the

achievement of a strategic political objective through Cyber

Warfare alone. The possibility of strategic-level Cyber Warfare

remains great, but the capability has not been demonstrated at

this time.”

.

Table 7. International Efforts

Title

c11173008

Source

Date

Pages

Notes

European Cybercrime Center (EC3)

Europol

Ongoing

N/A

The European Commission decided to establish a

European Cybercrime Centre (EC3) at Europol. The

center will be the focal point in the EU’s fight against

cybercrime, contributing to faster reactions in the event

of online crimes. It will support EU member states and

institutions in building operational and analytical

capacity for investigations and cooperation with

international partners.

Global Cybersecurity Index

International

Telecommunications Union

Ongoing

N/A

Based on questionnaire responses received by member

states of the International Telecommunications Union, a

first analysis of cybersecurity development in the Arab

region was compiled and one for the Africa region is

under way. The objective is to release a global status of

cybersecurity for 2014.

The Cyber Hub

Booz Allen Hamilton and

the Economist Intelligence

Unit

Ongoing

N/A

The Cyber Hub’s content was built on several integral

parts: an index that assesses specific aspects of the

cyber environment of the G20 countries and a series of

research papers that examine the implications for the

business community.

Cybersecurity Legislation

International

Telecommunications Union

Ongoing

N/A

An integral and challenging component of any national

cybersecurity strategy is the adoption of regionally and

internationally harmonized, appropriate legislation

against the misuse of information and communication

technologies (ICTs) for criminal or other purposes.

Cyber Security Strategy: Progress So Far

Cabinet Office, United

Kingdom

Ongoing

N/A

From the report: “To support the Strategy we put in

place a National Cyber Security Programme (NCSP)

backed by £650 million of funding to 2015. This year we

increased that investment with a further £210 million in

2015 to 2016. This funding will build on existing

projects and also support new investment, enabling the

UK to retain its emerging reputation as a leader in the

field of cyber security.”

CRS-59

.

Title

c11173008

Source

Date

Pages

Notes

FACT SHEET: The 2015 G-7 Summit at Schloss

Elmau, Germany

White House

June 8, 2015

N/A

Member nations of the Group of Seven today

announced a new cooperative effort to guard the

energy sector from hackers, cyber-spies, and other

online attackers. The seven industrialized democracies

will exchange information on methodologies for

identifying cyber threats and vulnerabilities within the

energy sector, sharing best practices and making

“investment in cybersecurity capabilities and capacity

building.” See "Launching New Work on Energy Sector

Cybersecurity" on the Fact Sheet.

OAS and FIRST Sign Agreement to Improve

Hemispheric Response to Cyber Incidents

Organization of American

States

May 28, 2015

N/A

The Organization of American States and the Forum of

Incident Response and Security Teams plan to

cooperate on cybersecurity incident response and to

promote good cyber hygiene across the Americas. OAS

and FIRST signed an agreement pledging to “jointly

organize technical incident response activities focused

on the needs and challenges of OAS member states”

and to help implement OAS’s Comprehensive InterAmerican Strategy to Combat Threats to Cyber

Security and its Declaration on Strengthening Cyber

Security in the Americas, adopted by member states in

2004 and 2012, respectively.

Global Cybersecurity Index: Updated Report

International

Telecommunication Union

and ABI Research

May 28, 2015

528

Each country profile features information on measures

contained in the five key pillars of the GCI, as enshrined

in the ITU’s Global Cybersecurity Agenda, notably:

legal, technical, organizational, capacity building and

cooperation. Information on child online protection

measures will be added to each profile. The GCI has

been an ongoing project between ITU and ABI

Research to map out cybersecurity efforts undertaken

at the national level. Each of the six regions (Africa,

Americas, Arab States, Asia Pacific, the Commonwealth

of Independent States, and Europe) saw regional

champions emerge. Good practices from each region

and from each of the pillars are highlighted.

CRS-60

.

Title

c11173008

Source

Date

Pages

Notes

European Agenda on Security

European Commission

April 28, 2015

21

The agenda pledges EU nations to review obstacles to

cross-border cybercrime investigations, especially

related to jurisdiction and evidence sharing. It also

pledges EU institutions to follow through on

commitments in the 28-nation bloc’s 2013

Cybersecurity Strategy, especially by adopting a

proposal for a binding EU-wide directive on network

and information security.

EU Cybersecurity Dashboard: A Path to a Secure

European Cyberspace

Business Software Alliance

(BSA)

March 4, 2015

20

The report analyzes the current status of all 28 member

states against pre-determined criteria for cybersecurity

best practices.

Joint Committee Report on Risks and

Vulnerabilities in the EU Financial System

European Banking Authority

March 2015

15

Cybercrime and computer failure are areas of “great

concern” and should be included in financial firms’ risk

management procedures, according to a report by EU

bank, insurance, and market regulators. Financial

institutions should be encouraged to integrate IT

security and resilience into their proprietary risk

models. System security and IT strategy carry their own

risks and complexities that can bleed across into more

traditional forms of risk.

Fact Sheet: US-United Kingdom Cybersecurity

Cooperation

White House

January 16, 2015

N/A

The UK’s Government Communications Headquarters

(GCHQ) and Security Service (MI5) are working with

their U.S. partners—the National Security Agency and

the Federal Bureau of Investigation—to further

strengthen U.S.-UK collaboration on cybersecurity by

establishing a joint cyber cell, with an operating

presence in each country. The cell, which will allow staff

from each agency to be co-located, will focus on

specific cyber defense topics and enable cyber threat

information and data to be shared at pace and at

greater scale.

Threat Landscape and Good Practice Guide for

Internet Infrastructure

European Union Agency for

Network and Information

Security (ENISA)

January 2015

64

The report details the assets composing an Internet

infrastructure and classifies the threats applicable,

highlighting “important specific threats” that disrupt

connectivity. These include routing threats, DNS

threats, and (Distributed) Denial of Service. Each threat

is linked with a list of assets exposed. Overall, there is

an increase in the occurrence of these threats.

CRS-61

.

Title

c11173008

Source

Date

Pages

Notes

Managing the Cyber Security Threat

Hoover Institution Working

Group on Foreign Policy and

Grand Strategy

December 12, 2014

6

From the report: “The cyber threat needs to be

managed through a combination of being realistic and

honest about our willingness and capacity to guarantee

security in this area; accepting multilateral arrangements

to protect commerce and critical infrastructure and

leaving traditional forms of intelligence and military

activities unregulated; and allowing private companies

and individuals to use strong encryption or open-source

software without built-in vulnerabilities.”

“Joint Elements” from U.S.-EU Cyber Dialogue

U.S. State Department and

European Union (EU)

December 5, 2014

N/A

U.S. and EU officials said an inaugural cyber dialogue

meeting in Belgium that they had reaffirmed numerous

shared principles, including a commitment to a

multistakeholder Internet governance model and

international cooperation on cybersecurity. In a joint

preliminary statement, the officials also reiterated their

support for a 2013 United Nations Governmental

Group of Experts consensus that international law

applies in cyberspace just as it does on land or at sea

and for the 2012 Budapest Convention, a treaty focused

on international cooperation to fight cybercrime.

Legal Issues Related to Cyber

NATO Legal Gazette

December 2014

74

The NATO Legal Gazette contains thematically organized

articles usually written by authors who are military or

civilian legal personnel working at NATO or in the

governments of NATO and partner nations. Its purpose

is to share articles of significance for the large NATO

legal community and connect legal professionals of the

Alliance. It is not a formal NATO document.

Cyber defence in the EU: Preparing for cyber

warfare?

European Parliamentary

Research Service

October 31, 2014

10

A number of EU member states are among those

developing their capabilities, and the EU’s own Defence

Agency is also working on projects to augment cyber

defenses in the union. This report includes summaries

of EU member nations and NATO’s national cyberdefense policies.

CRS-62

.

Title

c11173008

Source

Date

Pages

Notes

Inquiry into Cyber Intrusions Affecting U.S.

Transportation Command Contractors

Senate Armed Services

Committee

September 17, 2014

52

Hackers associated with the Chinese government

successfully penetrated the computer systems of

Transportation Command (TRANSCOM) contractors

20 times in the course of a single year. Chinese hackers

tried to get into the systems 50 times. The

congressional committee found that only two of the

intrusions were detected. It also found the officials

were unaware due in large part to unclear requirements

and methods for contractors to report breaches and

for government agencies to share information.

A Role for Civil Society in Cybersecurity Affairs?

ICT4Peace Foundation

September 3, 2014

26

From the report: “The paper is aimed at civil society

organisations, national governments, international and

regional organisations and other key actors concerned

with ICTs and their impact on international and regional

security. They perform a wide range of functions,

including policy-oriented research, advocacy, [and]

networking. In the Internet/cyber security world, civil

society organisations often work in specific issues areas,

many technical or functional in nature and tied to the

maintenance of the Internet. Civil society does not

include the private sector. Nevertheless, natural

alliances are emerging between certain of the more

tech-oriented civil society organisations (for example,

the Internet Society or the IEEE) and some Tier 1

carriers (i.e., those carriers that have a direct

connection to the Internet and the networks it uses to

deliver voice and data services), and major transnational

vendors and Internet Service Providers (ISPs).”

European Cybersecurity Implementation Series

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

Cybersecurity: Authoritative Reports and Resources, by Topic · R42507 | Frix