Cybersecurity: Authoritative Reports and Resources, by Topic
Congressional research reportJun 10, 2015
Ask Donna
What actually matters in this document.
Text
.
Cybersecurity: Authoritative Reports and
Resources, by Topic
Rita Tehan
Information Research Specialist
June 10, 2015
Congressional Research Service
7-5700
www.crs.gov
R42507
c11173008
Cybersecurity: Authoritative Reports and Resources, by Topic
.
Summary
This report provides references to analytical reports on cybersecurity from CRS, other
government agencies, trade associations, and interest groups. The reports and related websites are
grouped under the following cybersecurity topics:
•
•
•
•
•
•
•
•
•
Policy overview
National Strategy for Trusted Identities in Cyberspace (NSTIC)
Cloud computing and the Federal Risk and Authorization Management Program
(FedRAMP)
Critical infrastructure
Cybercrime, data breaches, and data security
National security, cyber espionage, and cyberwar (including Stuxnet)
International efforts
Education/training/workforce
Research and development (R&D)
In addition, the report lists selected cybersecurity-related websites for congressional and
government agencies; news; international organizations; and other organizations, associations,
and institutions.
c11173008
Congressional Research Service
Cybersecurity: Authoritative Reports and Resources, by Topic
.
Contents
CRS Reports, by Topic .................................................................................................................... 1
Cybersecurity Policy: CRS Reports and Other CRS Products .................................................. 1
Critical Infrastructure: CRS Reports ....................................................................................... 16
Cybercrime and Data Security: CRS Reports and Other CRS Products ................................. 34
Selected Reports, by Federal Agency ............................................................................................ 92
Department of Defense and National Security: CRS Reports and Other CRS Products ....... 109
CRS Product: Cybersecurity Framework .............................................................................. 116
Related Resources: Other Websites ............................................................................................. 138
Tables
Table 1. Cybersecurity Overview .................................................................................................... 2
Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC) ...................................... 8
Table 3. Cloud Computing, “The Internet of Things,” and FedRAMP ........................................ 10
Table 4. Critical Infrastructure ....................................................................................................... 17
Table 5. Cybercrime, Data Breaches, and Data Security ............................................................... 35
Table 6. National Security, Cyber Espionage, and Cyberwar ........................................................ 47
Table 7. International Efforts ......................................................................................................... 59
Table 8. Education/Training/Workforce......................................................................................... 77
Table 9. Research and Development (R&D) ................................................................................. 86
Table 10. Government Accountability Office (GAO) .................................................................... 92
Table 11. White House and Office of Management and Budget.................................................. 104
Table 12. Department of Defense (DOD) .................................................................................... 110
Table 13. National Institute of Standards and Technology (NIST) .............................................. 117
Table 14. Other Federal Agencies ................................................................................................ 122
Table 15. State, Local, and Tribal Governments .......................................................................... 134
Table 16. Related Resources: Congressional and Government ................................................... 138
Table 17. Related Resources: International Organizations .......................................................... 140
Table 18. Related Resources: News ............................................................................................. 141
Table 19. Related Resources: Other Associations and Institutions .............................................. 141
Contacts
Author Contact Information......................................................................................................... 143
Key Policy Staff ........................................................................................................................... 143
c11173008
Congressional Research Service
Cybersecurity: Authoritative Reports and Resources, by Topic
.
CRS Reports, by Topic1
This section provides references to analytical reports on cybersecurity from CRS, other
government agencies, think tanks, trade associations, trade press, and technology research firms.
For each topic, CRS reports are listed first, followed by tables with reports from other
organizations.
Cybersecurity Policy: CRS Reports and Other CRS Products
•
•
•
•
•
•
•
•
•
•
•
•
CRS Report R43831, Cybersecurity Issues and Challenges: In Brief, by Eric A.
Fischer
CRS Report IF10001, Cybersecurity Issues and Challenges, by Eric A. Fischer
CRS Report R42114, Federal Laws Relating to Cybersecurity: Overview of
Major Issues, Current Laws, and Proposed Legislation, by Eric A. Fischer
CRS Report R43941, Cybersecurity and Information Sharing: Legal Challenges
and Solutions, by Andrew Nolan
CRS Report R41941, The Obama Administration’s Cybersecurity Proposal:
Criminal Provisions, by Gina Stevens
CRS Report R42984, The 2013 Cybersecurity Executive Order: Overview and
Considerations for Congress, by Eric A. Fischer et al.
CRS Report R40150, A Federal Chief Technology Officer in the Obama
Administration: Options and Issues for Consideration, by John F. Sargent Jr.
CRS Report R42409, Cybersecurity: Selected Legal Issues, by Edward C. Liu et
al.
CRS Report R42887, Overview and Issues for Implementation of the Federal
Cloud Computing Initiative: Implications for Federal Information Technology
Reform Management, by Patricia Moloney Figliola and Eric A. Fischer
CRS Report R43015, Cloud Computing: Constitutional and Statutory Privacy
Protections, by Richard M. Thompson II
CRS Legal Sidebar WSLG478, House Intelligence Committee Marks Up
Cybersecurity Bill CISPA, by Richard M. Thompson II
CRS Legal Sidebar WSLG263, Can the President Deal with Cybersecurity Issues
via Executive Order?, by Vivian S. Chu
1
For information on legislation and hearings in the 112th and 113th Congresses, see CRS Report R43317,
Cybersecurity: Legislation, Hearings, and Executive Branch Documents, by Rita Tehan.
c11173008
Congressional Research Service
1
.
Table 1. Cybersecurity Overview
Title
Date
Pages
Notes
Cyber Threat Information Sharing:
Recommendations for Congress and the
Administration
Center for Strategic and
International Studies
March 10, 2015
18
The success of the president’s executive order
promoting cyberthreat information sharing depends on
legislation passing Congress. The report recommends
that legislation should not be one-size-fits-all; have a
minimal role for government; build on existing
information sharing; streamline mechanisms to share
info; add value for all parties participating; protect
information shared from FOIA requests, litigation or
regulatory enforcement; and protect organizations from
civil and criminal liability for monitoring and sharing on
cyberthreats if done in good faith.
The Emergence of Cybersecurity Law
Indiana University Maurer
School of Law
February 2015
31
This paper examines cyberlaw as a growing field of legal
practice and the roles that lawyers play in helping
companies respond to cybersecurity threats. Drawing on
interviews with lawyers, consultants, and academics
knowledgeable in the intersection of law and
cybersecurity, as well as a survey of lawyers working in
general counsel’s offices, this study examines the broader
context of cybersecurity, the current legal framework for
data security and related issues, and the ways in which
lawyers learn about and involve themselves in
cybersecurity issues.
OMG Cyber! Thirteen Reasons Why Hype
Makes for Bad Policy
The RUSI Journal
November 4, 2014
8
The article argues that cyber is “hyped out.” Overstating
the threat does have benefits (for some); it also comes
with significant costs. The benefits are short-lived and
easy to spot, whereas the costs are long-term and harder
to understand—and they are piling up fast and high.
Indeed, the costs are so high that the debate inches
toward a turning point for all parties involved. The
authors list 13 reasons why cybersecurity hype is
counterproductive.
CRS-2
c11173008
Source
.
Title
Source
Date
Pages
Ten Strategies of a World-Class Cybersecurity
Operations Center
MITRE Corporation
October 2014
346
All too often, cybersecurity operations centers (CSOCs)
are set up and operate with a focus on technology
without adequately addressing people and process issues.
The main premise of this book is that a more balanced
approach would be more effective. The book describes
the 10 strategies of effective CSOCs—regardless of their
size, offered capabilities, or type of constituency served
cost.
How Do We Know What Information Sharing
Is Really Worth? Exploring Methodologies to
Measure the Value of Information Sharing and
Fusion Efforts
RAND Corporation
June 27, 2014
33
Since the terrorist attacks of September 11, 2001, the
sharing of intelligence and law enforcement information
has been a central part of U.S. domestic security efforts.
Although much of the public debate about such sharing
focuses on addressing the threat of terrorism,
organizations at all levels of government routinely share
varied types of information through multiagency
information systems, collaborative groups, and other
links. Resource constraints have given rise to concerns
about the effectiveness of information sharing and fusion
activities and, therefore, the value of these efforts
relative to the public funds invested in them. Solid
methods for evaluating these efforts are lacking,
however, limiting the ability to make informed policy
decisions. Drawing on a substantial literature review and
synthesis, this report lays out the challenges of evaluating
information-sharing efforts that frequently seek to
achieve multiple goals simultaneously; reviews past
evaluations of information-sharing programs; and lays out
a path to improve the evaluation of such efforts going
forward.
Defending an Open, Global, Secure, and
Resilient Internet
Council on Foreign Relations
June 2013
127
The task force recommends that the United States
develop a digital policy framework based on four pillars,
the last of which is that U.S.-based industry work rapidly
to establish an industry-led approach to counter current
and future cyberattacks.
CRS-3
c11173008
Notes
.
Title
Source
Measuring What Matters: Reducing Risk by
Rethinking How We Evaluate Cybersecurity
Safegov.org, in coordination
with the National Academy of
Public Administration
March 2013
39
This report recommends that rather than periodically
auditing whether an agency’s systems meet the standards
enumerated in the Federal Information Security
Management Act (FISMA) at a static moment in time,
agencies and their inspectors general should keep
running scorecards of “cyber risk indicators” based on
continual inspector general assessments of a federal
organization’s cyber vulnerabilities.
Developing a Framework to Improve Critical
Infrastructure Cybersecurity (Federal Register
Notice; Request for Information)
National Institute of Standards
and Technology (NIST)
February 12, 2013
5
NIST announced the first step in the development of a
cybersecurity framework, which will be a set of voluntary
standards and best practices to guide industry in reducing
cyber risks to the networks and computers that are vital
to the nation’s economy, security, and daily life.
SEI [Software Engineering Institute] Emerging
Technology Center: Cyber Intelligence
Tradecraft Project
Carnegie Mellon University
January 2013
23
This report addresses the endemic problem of functional
cyber intelligence analysts not effectively communicating
with nontechnical audiences. It also notes organizations’
reluctance to share information within their own entities,
industries, and across economic sectors.
The National Cyber Security Framework
Manual
NATO Cooperative Cyber
Defense Center of Excellence
December 11, 2012
253
This report provides detailed background information
and in-depth theoretical frameworks to help the reader
understand the various facets of national cybersecurity,
according to different levels of public policy formulation.
The four levels of government—political, strategic,
operational, and tactical/technical—each have their own
perspectives on national cybersecurity, and each is
addressed in individual sections within the manual.
20 Critical Security Controls for Effective
Cyber Defense
Center for Strategic and
International Studies (CSIS)
November 2012
89
The top 20 security controls from a public-private
consortium. Members of the consortium include the
National Security Agency, U.S. Computer Emergency
Readiness Team, Department of Defense (DOD) Joint
Task Force-Global Network Operations, Department of
Energy Nuclear Laboratories, Department of State, and
DOD Cyber Crime Center plus commercial forensics
experts in the banking and critical infrastructure
communities.
CRS-4
c11173008
Date
Pages
Notes
.
Title
Date
Pages
Notes
Cyber Security Task Force: Public-Private
Information Sharing
Bipartisan Policy Center
July 2012
24
Outlines a series of proposals that would enhance
information sharing. The recommendations have two
major components: (1) mitigating perceived legal
impediments to information sharing, and (2) incentivizing
private sector information sharing by alleviating statutory
and regulatory obstacles.
Cyber-security: The Vexed Question of Global
Rules
McAfee and the Security
Defense Agenda
February 2012
108
This independent report examines the current state of
cyber-preparedness around the world and is based on
survey results from 80 policymakers and cybersecurity
experts in the government, business, and academic
sectors from 27 countries. The countries were ranked
on their state of cyber-preparedness.
Mission Critical: A Public-Private Strategy for
Effective Cybersecurity
Business Roundtable
October 11, 2011
28
The report suggests that “[p]ublic policy solutions must
recognize the absolute importance of leveraging policy
foundations that support effective global risk
management, in contrast to ‘check-the-box’ compliance
approaches that can undermine security and
cooperation.” The document concludes with specific
policy proposals and activity commitments.
World Cybersecurity Technology Research
Summit (Belfast 2011)
Centre for Secure Information
Technologies (CSIT)
September 12, 2011
14
The Belfast 2011 event attracted international
cybersecurity experts from leading research institutes,
government bodies, and industry who gathered to
discuss current cybersecurity threats, predict future
threats and necessary mitigation techniques, and develop
a collective strategy for further research.
A Review of Frequently Used Cyber Analogies
National Security Cyberspace
Institute
July 22, 2011
7
From the report: “The current cybersecurity crisis can
be described several ways with numerous metaphors.
Many compare the current crisis with the lawlessness to
that of the Wild West and the out-dated tactics and race
to security with the Cold War. When treated as a
distressed ecosystem, the work of both national and
international agencies to eradicate many infectious
diseases serves as a model as how poor health can be
corrected with proper resources and execution. Before
these issues are discussed, what cyberspace actually is
must be identified.”
CRS-5
c11173008
Source
.
Title
Date
Pages
Notes
America’s Cyber Future: Security and
Prosperity in the Information Age
Center for a New American
Security
May 31, 2011
296
To help U.S. policymakers address the growing danger of
cyber insecurity, this two-volume report features
chapters on cybersecurity strategy, policy, and
technology by some of the world’s leading experts on
international relations, national security, and information
technology.
Resilience of the Internet Interconnection
Ecosystem
European Network and
Information Security Agency
(ENISA)
April 11, 2011
238
This study consists of several parts. Part I provides a
summary and recommendations. Part II: State of the Art
Review offers a detailed description of the Internet’s
routing mechanisms and an analysis of their robustness at
the technical, economic, and policy levels. Part III: Report
on the Consultation reports and summarizes the results
of consultation with a broad range of stakeholders. Part
IV includes the bibliography and appendices.
Improving our Nation’s Cybersecurity through
the Public-Private Partnership: A White Paper
Business Software Alliance,
Center for Democracy and
Technology, U.S. Chamber of
Commerce, Internet Security
Alliance, and Tech America
March 8, 2011
26
This paper proposes expanding the existing partnership
within the framework of the National Infrastructure
Protection Plan. Specifically, it makes a series of
recommendations that build upon the conclusions of
President Obama’s Cyberspace Policy Review.
Cybersecurity Two Years Later
CSIS Commission on
Cybersecurity for the 44th
Presidency
January 2011
22
From the report: “We thought then [in 2008] that
securing cyberspace had become a critical challenge for
national security, which our nation was not prepared to
meet.... In our view, we are still not prepared.”
Toward Better Usability, Security, and Privacy
of Information Technology: Report of a
Workshop
National Research Council
(NRC)
September 21, 2010
70
The report discusses computer system security and
privacy, their relationship to usability, and research at
their intersection. It is drawn from remarks made at the
NRC’s July 2009 Workshop on Usability, Security and
Privacy of Computer Systems as well as reports from the
NRC’s Computer Science and Telecommunications
Board on security and privacy.
CRS-6
c11173008
Source
.
Title
National Security Threats in Cyberspace
Source
Date
Pages
Joint Workshop of the
National Security Threats in
Cyberspace and the National
Strategy Forum
September 15, 2009
37
Source: Highlights compiled by the Congressional Research Service (CRS) from the reports.
CRS-7
c11173008
Notes
The two-day workshop brought together more than two
dozen experts with diverse backgrounds, including
physicists; telecommunications executives; Silicon Valley
entrepreneurs; federal law enforcement, military,
homeland security, and intelligence officials;
congressional staffers; and civil liberties advocates.
Participants engaged in an open-ended discussion of
cyber policy as it relates to national security, under
Chatham House Rules: their comments were for the
public record, but they were not for attribution.
.
Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC)
Title
Date
Pages
Notes
National Strategy for Trusted Identities in Cyberspace
(NSTIC)
National
Institute of
Standards
and
Technology
(NIST)
Ongoing
N/A
The NSTIC pilot projects seek to catalyze a marketplace of
online identity solutions that ensures the envisioned Identity
Ecosystem is trustworthy and has the confidence of individuals.
Using privacy-enhancing architectures in real-world
environments, the pilots are testing new methods for
identification online for consumers that increase usability,
security, and interoperability to safeguard online transactions.
Identity Ecosystem Framework Steering Group (IDESG)
IDESG
Ongoing
N/A
The NSTIC called for the establishment of a private sector-led
steering group to administer the development and adoption of
the Identity Ecosystem Framework: the IDESG. The IDESG
receives its authority to operate from the active participation of
its membership in accordance with the rules of association that
follow. The IDESG has been initiated with the support of the
NIST. Following an initial period, the IDESG will transition to a
self-sustaining organization.
NSTIC Pilots: Catalyzing the Identity Ecosystem
NIST
April 2015
68
Since 2012, the NSTIC has awarded approximately $30 million
to pilot projects for shaping the identity ecosystem (a system
for consumers to create online identities). The study finds
common themes, including: the opportunity for increased
revenue, emerging identities architecture, and standards and
interoperability.
NIST Announces Pilot Grants Competition to Improve
Security and Privacy of Online Identity Verification
Systems
NIST
February 12,
2015
N/A
NIST announces a fourth round of grants meant to create
market conditions for a post-password world. The agency says
it anticipates funding several projects with awards of
approximately $1 million to $2 million over two years through
its NSTIC program. Administration officials say the NSTIC end
goal is creation of an “identity ecosystem” that allows
Americans to safely conduct online transactions under a variety
of security and privacy settings.
NIST Awards Grants to Improve Online Security and
Privacy
NIST
September 17,
2013
N/A
NIST announced more than $7 million in grants to support the
NSTIC. The funding will enable five U.S. organizations to
develop pilot identity protection and verification systems that
offer consumers more privacy, security, and convenience online.
CRS-8
c11173008
Source
.
Title
Source
Date
Pages
Notes
Five Pilot Projects Receive Grants to Promote Online
Security and Privacy
NIST
September 20,
2012
N/A
NIST announced more than $9 million in grant awards to
support the NSTIC. Five U.S. organizations will pilot identity
solutions that increase confidence in online transactions,
prevent identity theft, and provide individuals with more control
over how they share their personal information.
Recommendations for Establishing an Identity Ecosystem
Governance Structure
NIST
February 17,
2012
51
NIST responds to comments received in response to the
related notice of inquiry (NOI) published in the Federal Register
on June 14, 2011. This report summarizes the responses to the
NOI and provides recommendations and intended government
actions to serve as a catalyst for establishing such a governance
structure. The recommendations result from comments and
suggestions by the NOI respondents as well as best practices
and lessons learned from similarly scoped governance efforts.
Models for a Governance Structure for the National
Strategy for Trusted Identities in Cyberspace
NIST
June 14, 2011
4
The department seeks public comment on potential models
from all stakeholders, including the commercial, academic and
civil society sectors, and consumer and privacy advocates, in the
form of recommendations and key assumptions in the formation
and structure of the steering group.
Administration Releases Strategy to Protect Online
Consumers and Support Innovation and Fact Sheet on
National Strategy for Trusted Identities in Cyberspace
White
House
April 15, 2011
N/A
Press release on a proposal to administer the processes for
policy and standards adoption for the Identity Ecosystem
Framework in accordance with the NSTIC.
National Strategy for Trusted Identities in Cyberspace
White
House
April 15, 2011
52
The NSTIC aims to make online transactions more trustworthy,
thereby giving businesses and consumers more confidence in
conducting business online.
National Strategy for Trusted Identities in Cyberspace:
Creating Options for Enhanced Online Security and Privacy
White
House
June 25, 2010
39
The NSTIC, which is in response to one of the near-term action
items in the President’s Cyberspace Policy Review, calls for the
creation of an online environment, or an identity ecosystem, in
which individuals and organizations can complete online
transactions with confidence, trusting the identities of each
other and of the infrastructure in which transactions occur.
Source: Highlights compiled by CRS from the reports.
CRS-9
c11173008
.
Table 3. Cloud Computing, “The Internet of Things,”
and FedRAMP
Title
Date
About FedRAMP
General Services
Administration (GSA)
Ongoing
Formation of the Office of Technology Research and
Investigation (OTRI)
Federal Trade Commission
(FTC)
March 23, 2015
Insecurity in the Internet of Things (IoT)
Symantec
March 12, 2015
CRS-10
c11173008
Source
Pages
Notes
N/A
The Federal Risk and Authorization Management
Program (FedRAMP) is a government-wide program
that provides a standardized approach to security
assessment, authorization, and continuous monitoring
for cloud products and services.
The OTRI will provide expert research, investigative
techniques, and further insights to the agency on
technology issues involving all facets of the FTC’s
consumer protection mission, including privacy, data
security, connected cars, smart homes, algorithmic
transparency, emerging payment methods, big data,
and the Internet of Things.
Like the former Mobile Technology Unit (MTU), the
new office will be housed in the Bureau of Consumer
Protection and is the agency’s latest effort to ensure
that its core consumer protection mission keeps
pace with the rapidly evolving digital economy.
Kristin Cohen, the current chief of the MTU, will lead
the work of the OTRI.
20
Symantec analyzed 50 smart home devices that are
available today and found that none of the devices
enforced strong passwords, used mutual
authentication, or protected accounts against bruteforce attacks. Almost 2 out of 10 of the mobile apps
used to control the tested IoT devices did not use
Secure Sockets Layer (SSL) to encrypt
communications to the cloud. The tested IoT
technology also contained many common
vulnerabilities.
.
Title
Date
Pages
Notes
FedRAMP High Baseline
GSA
February 3,
2015
N/A
GSA released a draft of security controls it will
require for cloud-computer systems purchased by
federal agencies for “high-impact” uses. High-impact
data will likely consist of health and law-enforcement
data, but not classified information. Cloud computing
vendors seeking to sell to federal agencies currently
must get security accreditation through FedRAMP.
To date, FedRAMP has offered accreditations up to
the “moderate-impact” level. About 80% of federal IT
systems are low- and moderate-impact.
What is The Internet of Things?
(free; registration required)
O’Reilly Media
January 2015
32
Ubiquitous connectivity is meeting the era of data.
Since working with large quantities of data became
dramatically cheaper and easier a few years ago,
everything that touches software has become
instrumented and optimized. Finance, advertising,
retail, logistics, academia, and practically every other
discipline has sought to measure, model, and tweak
its way to efficiency. Software can ingest data from
lots of inputs, interpret it, and then issue commands
in real time.
FedRAMP Forward: 2 Year Priorities
GSA
December 17,
2014
14
The report addresses how the program will develop
over the next two years. GSA is focusing on three
goals for FedRAMP: increased compliance and agency
participation, improved efficiencies, and continued
adaptation.
The Internet of Things: 2014 OECD Tech Insight Forum
OECD
December 11,
2014
N/A
The Internet of Things extends internet connectivity
beyond traditional machines like computers,
smartphones and tablets to a diverse range of everyday devices that use embedded technology to
interact with the environment, all via the Internet.
How can this collected data be used? What new
opportunities will this create for employment and
economic growth? How can societies benefit from
technical developments to health, transport, safety
and security, business and public services? The
OECD Technology Foresight Forum facilitated
discussion on what policies and practices will enable
or inhibit the ability of economies to seize the
benefits of the Internet of Things.
CRS-11
c11173008
Source
.
Title
Source
DOD Cloud Computing Strategy Needs Implementation
Plan and Detailed Waiver Process
Department of Defense
(DOD) Inspector General
NSTAC Report to the President on the Internet of
Things
Pages
Notes
December 4,
2014
40
Report states that the DOD chief information officer
“did not develop an implementation plan that
assigned roles and responsibilities as well as
associated tasks, resources and milestones,” despite
promises that an implementation plan would directly
follow the cloud strategy’s release.
President's National
Security
Telecommunications
Advisory Committee
November 18,
2014
56
The NSTAC unanimously approved a
recommendation that governmental Internet traffic
could get priority transmission during emergencies.
The government already gets emergency priority in
more traditional communications networks like the
‘phone system through programs such as the
Government Emergency Telecommunications Service
— now NSTAC is proposing a GETS for the Internet.
The Department of Energy’s Management of Cloud
Computing Activities: Audit Report
Department of Energy
(DOE) Inspector General
September 1,
2014
20
DOE should do a better job buying, implementing
and managing its cloud computing services. Programs
and sites department-wide have independently spent
more than $30 million on cloud services, the
inspector general report said, but the chief
information officer’s office could not accurately
account for the money.
Cloud Computing: The Concept, Impacts, and the Role
of Government Policy
Organization for Economic
Co-operation and
Development (OECD)
August 19, 2014
240
This report gives a clear overview of cloud
computing, presenting the concept, the services it
provides, and deployment models. It provides an
overview of how cloud computing changes the way
computing is carried out and evaluates the impacts of
cloud computing (including its benefits and challenges
as well as its economic and environmental impacts).
Finally, the report discusses the policy issues raised
by cloud computing and the role of governments and
other stakeholders in addressing these issues.
Internet of things: the influence of M2M data on the
energy industry
GigaOm Research
March 4, 2014
21
This report examines the drivers of machine-2machine (M2M)-data exploitation in the smart-grid
sector and the oil and gas sector, as well as the risks
and opportunities for buyers and suppliers of the
related core technologies and services.
CRS-12
c11173008
Date
.
Title
Date
Pages
Notes
Software Defined Perimeter
Cloud Security Alliance
December 1,
2013
13
The Software Defined Perimeter (SDP) initiative by
the Cloud Security Alliance aims to make “invisible
networks” accessible to a wider range of government
agencies and corporations. The initiative will foster
development of an architecture for securing the
“Internet of Things” by using the cloud to create
highly secure end-to-end networks between any IPaddressable entities.
Delivering on the Promise of Big Data and the Cloud
Booz Allen Hamilton
January 9, 2013
7
From the report: “Reference architecture does away
with conventional data and analytics silos,
consolidating all information into a single medium
designed to foster connections called a ‘data lake,’
which reduces complexity and creates efficiencies
that improve data visualization to allow for easier
insights by analysts.”
Cloud Computing: An Overview of the Technology and
the Issues facing American Innovators
House Judiciary
Committee, Subcommittee
on Intellectual Property,
Competition, and the
Internet
July 25, 2012
156
Overview and discussion of cloud computing issues.
Information Technology Reform: Progress Made but
Future Cloud Computing Efforts Should be Better
Planned
Government
Accountability Office
(GAO)
July 11, 2012
43
GAO recommends that the Secretaries of
Agriculture, Health and Human Services, Homeland
Security, State, and the Treasury, and the
Administrators of the General Services
Administration (GSA) and Small Business
Administration should direct their respective chief
information officers to establish estimated costs,
performance goals, and plans to retire associated
legacy systems for each cloud-based service discussed
in this report, as applicable.
Cloud Computing Strategy
DOD Chief Information
Officer
July 2012
44
The DOD Cloud Computing Strategy introduces an
approach to move the department from the current
state of a duplicative, cumbersome, and costly set of
application silos to an end state that is agile, secure,
and cost-effective and to a service environment that
can rapidly respond to changing mission needs.
A Global Reality: Governmental Access to Data in the
Cloud—A Comparative Analysis of Ten International
Jurisdictions
Hogan Lovells
May 23, 2012
13
This white paper compares the nature and extent of
governmental access to data in the cloud in many
jurisdictions around the world.
CRS-13
c11173008
Source
.
Title
Date
Pages
Notes
Policy Challenges of Cross-Border Cloud Computing
U.S. International Trade
Commission
May 2012
38
This report examines the main policy challenges
associated with cross-border cloud computing—data
privacy, security, and ensuring the free flow of
information—and the ways countries are addressing
them through domestic policymaking, international
agreements, and other cooperative arrangements.
Cloud Computing Synopsis and Recommendations (SP
800-146)
National Institute of
Standards and Technology
(NIST)
May 2012
81
NIST’s guide explains cloud technologies in plain
terms to federal agencies and provides
recommendations for IT decision makers.
Global Cloud Computing Scorecard a Blueprint for
Economic Opportunity
Business Software Alliance
February 2,
2012
24
This report notes that although many developed
countries have adjusted their laws and regulations to
address cloud computing, the wide differences in
those rules make it difficult for companies to invest in
the technology.
Concept of Operations: FedRAMP
GSA
February 7,
2012
47
Implementation of FedRAMP will be in phases. This
document describes all the services that will be
available at initial operating capability, targeted for
June 2012. The concept of operations will be updated
as the program evolves toward sustained operations.
Federal Risk and Authorization Management Program
(FedRAMP)
Federal Chief Information
Officers Council
January 4, 2012
N/A
FedRAMP has been established to provide a standard
approach to assessing and authorizing (A&A) cloud
computing services and products.
Security Authorization of Information Systems in Cloud
Computing Environments (FedRAMP)
White House/Office of
Management and Budget
(OMB)
December 8,
2011
7
FedRAMP will now be required for all agencies
purchasing storage, applications, and other remote
services from vendors. The Administration promotes
cloud computing as a means to save money and
accelerate the government’s adoption of new
technologies.
U.S. Government Cloud Computing Technology
Roadmap, Volume I, Release 1.0 (Draft). High-Priority
Requirements to Further USG Agency Cloud Computing
Adoption (SP 500-293)
NIST
December 1,
2011
32
Volume I is aimed at interested parties that wish to
gain a general understanding and overview of the
background, purpose, context, work, results, and
next steps of the U.S. Government Cloud Computing
Technology Roadmap initiative.
CRS-14
c11173008
Source
.
Title
Source
Date
Pages
Notes
U.S. Government Cloud Computing Technology
Roadmap, Volume II, Release 1.0 (Draft), Useful
Information for Cloud Adopters (SP 500-293)
NIST
December 1,
2011
85
Volume II is designed as a technical reference for
those actively working on strategic and tactical cloud
computing initiatives including, but not limited to,
U.S. government cloud adopters. This volume
integrates and summarizes the work completed to
date and explains how these findings support the
roadmap introduced in Volume I.
Information Security: Additional Guidance Needed to
Address Cloud Computing Concerns
GAO
October 6,
2011
17
Twenty-two of 24 major federal agencies reported
that they were either concerned or very concerned
about the potential information security risks
associated with cloud computing. GAO
recommended that the NIST issue guidance specific
to cloud computing security.
Cloud Computing Reference Architecture (SP 500-292)
NIST
September 1,
2011
35
This special publication, which is not an official U.S.
government standard, is designed to provide guidance
to specific communities of practitioners and
researchers.
Guide to Cloud Computing for Policy Makers
Software and Information
Industry Association (SAII)
July 26, 2011
27
The SAII concludes that “there is no need for cloudspecific legislation or regulations to provide for the
safe and rapid growth of cloud computing, and in fact,
such actions could impede the great potential of
cloud computing.”
Federal Cloud Computing Strategy
White House
February 13,
2011
43
The strategy outlines how the federal government
can accelerate the safe, secure adoption of cloud
computing and provides agencies with a framework
for migrating to the cloud. It also examines how
agencies can address challenges related to the
adoption of cloud computing, such as privacy,
procurement, standards, and governance.
25 Point Implementation Plan to Reform Federal
Information Technology Management
White House
December 9,
2010
40
The plan’s goals are to reduce the number of
federally run data centers from 2,100 to
approximately 1,300; rectify or cancel one-third of
troubled IT projects, and require federal agencies to
adopt a “cloud first” strategy in which they will move
at least one system to a hosted environment within a
year.
Source: Highlights compiled by CRS from the reports.
Note: These reports analyze cybersecurity issues related to the federal government’s adoption of cloud computing storage options.
CRS-15
c11173008
Cybersecurity: Authoritative Reports and Resources, by Topic
.
Critical Infrastructure: CRS Reports
•
•
•
•
•
•
•
•
•
c11173008
CRS Report R42683, Critical Infrastructure Resilience: The Evolution of Policy and
Programs and Issues for Congress, by John D. Moteff
CRS Report RL30153, Critical Infrastructures: Background, Policy, and Implementation,
by John D. Moteff
CRS Report R42660, Pipeline Cybersecurity: Federal Policy, by Paul W. Parfomak
CRS Report R41536, Keeping America’s Pipelines Safe and Secure: Key Issues for
Congress, by Paul W. Parfomak
CRS Report R41886, The Smart Grid and Cybersecurity—Regulatory Policy and Issues,
by Richard J. Campbell
CRS Report R42338, Smart Meter Data: Privacy and Cybersecurity, by Brandon J.
Murrill, Edward C. Liu, and Richard M. Thompson II
CRS Report RL33586, The Federal Networking and Information Technology Research
and Development Program: Background, Funding, and Activities, by Patricia Moloney
Figliola
CRS Report 97-868, Internet Domain Names: Background and Policy Issues, by Lennard
G. Kruger
CRS Report IN10027, Open-Source Software and Cybersecurity: The Heartbleed Bug, by
Eric A. Fischer, Catherine A. Theohary, and John W. Rollins
Congressional Research Service
16
.
Table 4. Critical Infrastructure
Title
Date
Pages
Notes
HHS Breach Portal: Breaches Affecting 500 or More
Individuals
Health and Human
Services (HHS)
Ongoing
Cybersecurity for Energy Delivery Systems Program
(CEDS)
Department of
Energy (DOE),
Office of Electricity
Delivery and
Energy Reliability
Ongoing
N/A
The program assists the energy sector asset owners (electric,
oil, and gas) by developing cybersecurity solutions for energy
delivery systems through integrated planning and a focused
research and development effort. CEDS co-funds projects with
industry partners to make advances in cybersecurity capabilities
for energy delivery systems.
Cybersecurity Capability Maturity Model (C2M2)
DOE Office of
Electricity Delivery
and Energy
Reliability
Ongoing
N/A
The model was developed by the DOE and industry as a
cybersecurity control evaluation and improvement management
tool for energy sector firms. It tells adherents how to assess and
grade adoption of cybersecurity practices.
GridEx
North American
Electric Reliability
Corporation
(NERC)
Ongoing
N/A
The objectives of the NERC Grid Security Exercise (GridEx)
series are to use simulated scenarios (with no real-world effects)
to exercise the current readiness of participating electricity
subsector entities to respond to cyber- or physical security
incidents and provide input for security program improvements
to the bulk power system. GridEx is a biennial international grid
security exercise that uses best practices and other
contributions from the Department of Homeland Security, the
Federal Emergency Management Agency, and the National
Institute of Standards and Technology.
CRS-17
c11173008
Source
As required by Section 13402(e)(4) of the HITECH Act, the
Secretary must post a list of breaches of unsecured protected
health information affecting 500 or more individuals. These
breaches are now posted in a new, more accessible format that
allows users to search and sort the posted breaches.
Additionally, this new format includes brief summaries of the
breach cases that OCR has investigated and closed, as well as
the names of private practice providers who have reported
breaches of unsecured protected health information to the
Secretary.
.
Title
Date
Pages
Notes
ICBA Data Breach Toolkit
Independent
Community
Bankers of America
Ongoing
N/A
ICBA and Visa have teamed up to bring a special
communications toolkit to community banks. This
comprehensive communications guide gives community banks
the means of communicating with card customers and the media
within 24 hours of a data compromise. Having this contingency
plan in place can make all the difference in a data breach
episode. The toolkit Includes a brochure on communications
best practices following a data breach and customizable template
materials, such as cardholder letters, statement inserts, FAQs,
and media statements.
Appendix J: Strengthening the Resilience of Outsourced
Technology Services
Federal Financial
Institutions
Examination
Council (FFIEC)
Ongoing
N/A
The increasing sophistication and volume of cyber threats and
their ability to disrupt operations or corrupt data can affect the
business resilience of financial institutions and technology service
providers (TSPs). Financial institutions and their TSPs need to
incorporate the potential impact of a cyber event into their
business continuity planning (BCP) process and ensure
appropriate resilience capabilities are in place. The changing
cyber threat landscape may include risks that must be managed
to achieve resilience.
Cybersecurity Risk Management and Best Practices
(WG4): Cybersecurity Framework for the
Communications Sector
Federal
Communications
Commission,
Communications
Security, Reliability
and Interoperability
Council (CSRIC)
March 18,
2015
415
The CSRIC is a federal advisory committee that provides
recommendations to the FCC regarding best practices and
actions the commission can take to help ensure security,
reliability, and interoperability of communications systems and
infrastructure. The CSRIC approved a report that identifies best
practices, provides a variety of important tools and resources
for communications companies of different sizes and types to
manage cybersecurity risks, and recommends a path forward.
Tracking & Hacking: Security & Privacy Gaps Put
American Drivers at Risk
Senator Edward
Markey
February 11,
2015
14
Nearly all modern vehicles have some sort of wireless
connection that hackers could potentially use to gain access to
their critical systems. The company’s protections on those
connections are “inconsistent and haphazard” across the
industry. In addition to security weaknesses, the report also
found that many auto companies are collecting detailed location
data from cars and often transmitting it insecurely.
CRS-18
c11173008
Source
.
Title
Date
Pages
Notes
Senators Alexander, Murray Announce Oversight
Initiative on Security of Health IT
Senate Committee
on Labor, Health,
Education and
Pensions
February 6,
2015
N/A
U.S. Senate health committee Chairman Lamar Alexander (RTenn.) and Ranking Member Patty Murray (D-Wash.) today
announced a bipartisan initiative focused on examining the
security of health information technology and the health
industry’s preparedness for cyber threats. The goal of the
Alexander-Murray initiative is to examine whether Congress can
help ensure the safety of health information technology,
including electronic health records, hospital networks, insurance
records, and network-connected medical devices, like
pacemakers and continuous glucose monitors. Begun last month,
the ongoing staff meetings will include participants from relevant
government oversight agencies, independent cybersecurity
experts, health industry leaders, and others.
Report on Cybersecurity Practices
Financial Industry
Regulatory
Authority
February 2015
46
The report presents an approach to cybersecurity grounded in
risk management to address these threats. It identifies principles
and effective practices for firms to consider, while recognizing
that there is no one-size-fits-all approach to cybersecurity.
Incident Response/Vulnerability Coordination in 2014
ICS/CERT Monitor
September
2014-February
2015
15
In FY2014, the Industrial Control Systems Cyber Emergency
Response Team (ICS-CERT) received and responded to 245
incidents reported by asset owners and industry partners. The
Energy Sector led all others again in 2014 with the most
reported incidents. ICS-CERT’s continuing partnership with the
Energy Sector provides many opportunities to share information
and collaborate on incident response efforts. In addition, in 2014
the Critical Manufacturing Sector reported incidents, some of
which were from control systems equipment manufacturers.
Guidance on Maritime Cybersecurity Standards (Federal
Register Notice of Public Meeting and Request for
Comments)
U.S. Coast Guard
December 12,
2014
2
From the summary: “The U.S. Coast Guard announces a public
meeting to be held in Washington, DC, to receive comments on
the development of cybersecurity assessment methods for
vessels and facilities regulated by the Coast Guard. This meeting
will provide an opportunity for the public to comment on
development of security assessment methods that assist vessel
and facility owners and operators identify and address
cybersecurity vulnerabilities that could cause or contribute to a
Transportation Security Incident. The Coast Guard will consider
these public comments in developing relevant guidance, which
may include standards, guidelines, and best practices to protect
maritime critical infrastructure.”
CRS-19
c11173008
Source
.
Title
Date
Pages
Notes
Federal Financial Institutions Examination Council (FFIEC)
Cybersecurity Assessment: General Observations
FFIEC
November 3,
2014
Inquiry into Cyber Intrusions Affecting U.S.
Transportation Command Contractors
Senate Armed
Services
Committee
September 17,
2014
Critical Infrastructure Protection: DHS [Department of
Homeland Security] Action Needed to Enhance
Integration and Coordination of Vulnerability Assessment
Efforts
Government
Accountability
Office (GAO)
September 15,
2014
82
DHS used 10 different assessment tools and methods from
FY2011 through FY2013 to assess critical infrastructure
vulnerabilities. Four of the 10 assessments did not include
cybersecurity. The differences in the assessment tools and
methods mean DHS is not positioned to integrate its findings in
identifying priorities.
Energy Sector Cybersecurity Framework Implementation
Guidance: Draft For Public Comment and Comment
Submission Form
DOE Office of
Electricity Delivery
and Energy
Reliability
September 12,
2014
N/A
Energy companies need not make a choice between the National
Institute of Standards and Technology (NIST) cybersecurity
framework and the DOE’s C2M2. The NIST framework tells
organizations to grade themselves on a four-tier scale based on
their overall cybersecurity program sophistication. C2M2 tells
users to assess cybersecurity control implementation across 10
domains of cybersecurity practices, such as situational
awareness, according to their specific “maturity indicator level.”
CRS-20
c11173008
Source
Companies are critically dependent on IT. Financial companies
should routinely scan IT networks for vulnerabilities and
anomalous activity and test systems for their potential exposure
to cyberattacks. The study recommends sharing threat data
through such avenues as the Financial Services Information
Sharing and Analysis Center.
52
Hackers associated with the Chinese government successfully
penetrated the computer systems of Transportation Command
(TRANSCOM) contractors 20 times in the course of a single
year. Chinese hackers tried to get into the systems 50 times.
The congressional committee found that only two of the
intrusions were detected. It also found that officials were
unaware due in large part to unclear requirements and methods
for contractors to report breaches and for government agencies
to share information.
.
Title
Date
Pages
Notes
Guidelines for Smart Grid Cybersecurity, Smart Grid
Cybersecurity Strategy, Architecture, and High-Level
Requirements (3 volumes)
NIST
September
2014
668
This three-volume report, Guidelines for Smart Grid
Cybersecurity, presents an analytical framework that
organizations can use to develop effective cybersecurity
strategies tailored to their particular combinations of smart gridrelated characteristics, risks, and vulnerabilities. Organizations in
the diverse community of smart grid stakeholders—from
utilities to providers of energy management services to
manufacturers of electric vehicles and charging stations—can use
the methods and supporting information presented in this
report as guidance for assessing risk and identifying and applying
appropriate security requirements. This approach recognizes
that the electric grid is changing from a relatively closed system
to a complex, highly interconnected environment. Each
organization’s cybersecurity requirements should evolve as
technology advances and as threats to grid security inevitably
multiply and diversify.
A Criticism of the Current Security, Privacy and
Accountability Issues in Electronic Health Records
International
Journal of Applied
Information
Systems
September
2014
8
Unless a different approach is used, the reliant on cryptography
and password or escrow based system for key management will
impede trust of the electronic health records (EHR) system and
hence its acceptability. In addition, users with right access should
also be monitored without affecting the clinician workflow. This
paper presents a detailed review of some selected recent
approaches to ensuring security, privacy, and accountability in
EHR and identifies gaps for future research.
Security in the New Mobile Ecosystem (Free registration
required.)
Ponemon Institute
and Raytheon
August 2014
30
Mobile devices are quickly becoming an integral tool for the
workforce, but the security practices and budgets in most
organizations are not keeping pace with the growing number of
devices that must be managed and kept secure.
Critical Infrastructure: Security Preparedness and
Maturity
Unisys and the
Ponemon Institute
July 2014
34
Unisys and the Ponemon Institute surveyed nearly 600 IT
security executives of utility, energy, and manufacturing
organizations. Overall, the report finds organizations are simply
not prepared to deal with advanced cyber threats. Only half of
companies have actually deployed IT security programs and,
according to the survey, the top threat actually stems from
negligent insiders.
CRS-21
c11173008
Source
.
Title
Source
Date
Pages
Notes
Securing the U.S. Electrical Grid: Understanding the
Threats to the Most Critical of Critical Infrastructure,
While Securing a Changing Grid
Center for the
Study of the
Presidency and
Congress
July 2014
180
From the report: “While [electrical grid] modernization entails
significant challenges in its own right, it also provides an
opportunity to ‘bake security in’—both in the hardware and
software controlling these systems and in the business models,
regulatory systems, financial incentives, and insurance structures
that govern the generation, transmission, and distribution of
electric power.… In this report and the aforementioned dozen
recommendations, we have sought to identify the immediate
action that can be taken by the White House, the Congress, and
the private sector to mitigate current threats to the electrical
grid.”
Maritime Critical Infrastructure Protection: DHS Needs
to Better Address Port Cybersecurity
GAO
June 5, 2014
54
GAO’s objective was to identify the extent to which DHS and
other stakeholders have taken steps to address cybersecurity in
the maritime port environment. GAO examined relevant laws
and regulations, analyzed federal cybersecurity-related policies
and plans, observed operations at three U.S. ports selected for
being high-risk ports and leaders in calls by vessel type (e.g.,
container), and interviewed federal and nonfederal officials.
Executive Leadership of Cybersecurity: What Today’s
CEO Needs To Know About the Threats They Don’t See
FFIEC
May 7, 2014
30
The FFIEC highlighted key focus areas for senior management
and boards of directors of community institutions as they assess
their institutions’ abilities to identify and mitigate cybersecurity
risks.
Sector Risks Snapshots
DHS
May 2014
52
DHS’s snapshots provide an introduction to the diverse array of
critical infrastructure sectors, touching on some of the key
threats and hazards concerning these sectors and highlighting
the common, first-order dependencies and interdependencies
between sectors.
Critical Infrastructure Protection Issues Identified in
Order No. 791
Federal Energy
Regulatory
Commission
(FERC)
April 24, 2014
N/A
FERC will hold a technical meeting on cybersecurity and
communications security standards for power generators.
Among other issues, the meeting will consider possible
disjunctures between FERC’s regulatory standards for grid
reliability and the new voluntary cybersecurity framework for
critical infrastructure that NIST rolled earlier this year.
CRS-22
c11173008
.
Title
Date
Pages
Notes
Notice of Completion of Notification of CyberDependent Infrastructure and Process for Requesting
Reconsideration of Determinations of Cyber Criticality
DHS Programs
Directorate
April 17, 2014
3
The Secretary of DHS has been directed to identify critical
infrastructure in which a cybersecurity incident could reasonably
result in catastrophic regional or national effects on public health
or safety, economic security, or national security. In addition to
identifying such infrastructure, the Secretary has also been
directed to confidentially notify owners and operators of critical
infrastructure identified and establish a mechanism through
which entities can request reconsideration of that identification,
whether inclusion or exclusion from this list. This notice informs
owners and operators of critical infrastructure that the
confidential notification process is complete and describes the
process for requesting reconsideration.
Cybersecurity Procurement Language for Energy Delivery
Systems
DOE Energy
Sector Control
Systems Working
Group
April 2014
46
This guidance suggests procurement strategies and contract
language to help U.S. energy companies and technology suppliers
build in cybersecurity protections during product design and
manufacturing. It was “developed through a public-private
working group including federal agencies and private industry
leaders.”
Benchmarking Trends: Interest in Cyber Insurance
Continues to Climb (Requires free registration to access.)
Marsh USA
March 31,
2014
4
As cyber incidents increased in frequency and severity in 2013,
the percentage of companies that purchased cyber insurance
rose by double digits (see figure 1 in the report). Early signs in
2014 indicate that the trend is not just continuing but
accelerating. Recent high-profile data breaches, growing boardlevel concern, and the increasing vulnerability of operations to
technology failure appear to be influencing purchasing decisions.
Wireless Emergency Alerts (WEA) Cybersecurity Risk
Management Strategy for Alert Originators
Carnegie
Mellon/Pittsburgh
Software Institute
March 2014
183
From the report: “The Wireless Emergency Alerts (WEA)
service depends on computer systems and networks to convey
potentially life-saving information to the public in a timely
manner. However, like other cyber-enabled services, it is
susceptible to risks that may enable attackers to disseminate
unauthorized alerts or to delay, modify, or destroy valid alerts.
Successful attacks may result in property destruction, financial
loss, injury, or death and may damage WEA credibility to the
extent that users ignore future alerts or disable alerting. This
report describes a four-stage cybersecurity risk management
(CSRM) strategy that alert originators can use throughout WEA
adoption, operations, and sustainment, as well as a set of
governance activities for developing a plan to execute the
CSRM.”
CRS-23
c11173008
Source
.
Title
Date
Pages
Notes
Cybersecurity and the North American Electric Grid:
New Policy Approaches to Address an Evolving Threat
Bipartisan Policy
Center
February 28,
2014
Framework for Improving Critical Infrastructure
Cybersecurity
NIST
February 12,
2014
41
The voluntary framework consists of cybersecurity standards
that can be customized to various sectors and adapted by both
large and small organizations. Additionally, so that the private
sector may fully adopt this framework, DHS announced the
Critical Infrastructure Cyber Community (C3)—or “C-cubed”—
Voluntary Program. The C3 program gives companies that
provide critical services such as cell phones, email, banking, and
energy and state and local governments direct access to
cybersecurity experts within DHS who have knowledge about
specific threats, ways to counter those threats, and how, over
the long term, to design and build systems that are less
vulnerable to cyber threats.
ITI Recommendations to the Department of Homeland
Security Regarding its Work Developing a Voluntary
Program Under Executive Order 163636, “Improving
Critical Infrastructure Cybersecurity.”
Information
Technology
Industry Council
(ITI)
February 11,
2014
3
ITI released a set of recommendations eying further
improvement of the framework, changes that call for DHS to
“de-emphasize the current focus on incentives.” Partly, ITI
recognizes the cyber order can produce change even in an
environment in which fiscal constraints and congressional
inaction stall carrots for adoption—but a bigger biz argument,
made in its report yesterday, is that ITI and others do not want
incentives if they come at the cost of “compliance-based
programs.”
CRS-24
c11173008
Source
The Bipartisan Policy Center’s initiative identifies urgent
priorities, including strengthening existing protections, enhancing
coordination at all levels, and accelerating the development of
robust protocols for response and recovery in the event of a
successful attack. The initiative developed recommendations in
four policy areas: standards and best practices, information
sharing, response to a cyberattack, and paying for cybersecurity.
The recommendations are targeted to Congress, federal
government agencies, state public utility commissions (PUCs),
and industry.
.
Title
Date
Pages
Notes
The Federal Government’s Track Record on
Cybersecurity and Critical Infrastructure
Senate Homeland
Security and
Governmental
Affairs Committee
(Minority Staff)
February 4,
2014
19
Since 2006, the federal government has spent at least $65 billion
on securing its computers and networks, according to an
estimate by the Congressional Research Service (CRS). NIST,
the government’s official body for setting cybersecurity
standards, has produced thousands of pages of precise guidance
on every significant aspect of IT security. And yet agencies—
even agencies with responsibilities for critical infrastructure or
vast repositories of sensitive data—continue to leave themselves
vulnerable, often by failing to take the most basic steps toward
securing their systems and information.
Electricity Subsector Cybersecurity Capability Maturity
Model (ES-C2M2) (Case Study)
Carnegie Mellon
University Software
Engineering
Institute
January 23,
2014
39
ES-C2M2 is a White House initiative, led by DOE in partnership
with the Department of Homeland Security and representatives
of electricity subsector asset owners and operators, to manage
dynamic threats to the electric grid. Its objectives are to
strengthen cybersecurity capabilities, enable consistent
evaluation and benchmarking of cybersecurity capabilities, and
share knowledge and best practices.
NIPP 2013: Partnering for Critical Infrastructure Security
and Resilience
DHS
2013
57
The National Infrastructure Protection Plan (NIPP) 2013 meets
the requirements of Presidential Policy Directive-21, “Critical
Infrastructure Security and Resilience,” signed in February 2013.
The plan was developed through a collaborative process
involving stakeholders from all 16 critical infrastructure sectors,
all 50 states, and all levels of government and industry. It
provides a clear call to action to leverage partnerships, innovate
for risk management, and focus on outcomes.
World Federation of Exchanges (WFE) Launches Global
Cyber Security Committee
WFE
December 12,
2013
N/A
The WFE announced the launch of the exchange industry’s first
cybersecurity committee with a mission to aid in the protection
of the global capital markets. The working group will bring
together representation from a number of exchanges and
clearinghouses across the globe to collaborate on best practices
in global security.
The Critical Infrastructure Gap: U.S. Port Facilities and
Cyber Vulnerabilities
Brookings
Institution/ Center
for 21st Century
Security and
Intelligence
July 2013
50
The study argues that the level of cybersecurity awareness and
culture in U.S. port facilities is relatively low and that a
cyberattack at a major U.S. port would quickly cause significant
damage to the economy.
FFIEC Forms Cybersecurity and Critical Infrastructure
Working Group
FFIEC
June 6, 2013
2
FFIEC formed a working group to further promote coordination
across federal and state banking regulatory agencies on critical
infrastructure and cybersecurity issues.
CRS-25
c11173008
Source
.
Title
Source
Date
Pages
Notes
Electric Grid Vulnerability: Industry Responses Reveal
Security Gaps
Representative
Edward Markey
and Representative
Henry Waxman
May 21, 2013
35
The report found that less than one-quarter of investor-owned
utilities and less than one-half of municipally and cooperatively
owned utilities followed through with voluntary standards issued
by the Federal Energy Regulatory Commission after the Stuxnet
worm struck in 2010.
Initial Analysis of Cybersecurity Framework RFI [Request
for Information] Responses
NIST
May 20, 2013
33
Comments on the challenges of protecting the nation’s critical
infrastructure have identified a handful of issues for the more
than 200 people and organizations that responded to a formal
RFI. NIST has released an initial analysis of 243 responses to the
Feb. 26 RFI. The analysis will form the basis for an upcoming
workshop at Carnegie Mellon University in Pittsburgh as NIST
moves forward on creating a cybersecurity framework for
essential energy, utility, and communications systems.
Joint Working Group on Improving Cybersecurity and
Resilience Through Acquisition, Notice of Request for
Information
General Services
Administration
May 13, 2013
3
Among other things, Presidential Policy Directive-21requires the
General Services Administration, in consultation with the
Department of Defense and DHS, to jointly provide and support
government-wide contracts for critical infrastructure systems
and ensure that such contracts include audit rights for the
security and resilience of critical infrastructure.
2013 Annual Report
Financial Stability
Oversight Council
(FSOC)
April 25, 2013
195
Under the Dodd-Frank Act, FSOC must report annually to
Congress on a range of issues, including significant financial
market and regulatory developments and potential emerging
threats to the financial stability of the United States. FSOC’s
recommendations address heightened risk management and
supervisory attention to operational risks, including
cybersecurity and infrastructure.
Version 5 Critical Infrastructure Protection Reliability
Standards (Notice of Proposed Rulemaking)
FERC
April 24, 2013
18
FERC proposes to approve the Version 5 Critical Infrastructure
Protection (CIP) Reliability Standards, CIP-002-5 through CIP011-1, submitted by the North American Electric Reliability
Corporation, the commission-certified Electric Reliability
Organization. The proposed reliability standards, which pertain
to the cybersecurity of the bulk electric system, represent an
improvement over the current commission-approved CIP
Reliability Standards as they adopt new cybersecurity controls
and extend the scope of the systems that are protected by the
existing standards.
CRS-26
c11173008
.
Title
Date
Pages
Notes
Wireless Cybersecurity
Syracuse University
New York,
Department of
Electrical
Engineering and
Computer Science
April 2013
167
This project dealt with various threats in wireless networks,
including eavesdropping in a broadcast channel, noncooperative
eavesdropping in a single-source, single-sink planar network, and
primary user emulation attack in a cognitive radio network. The
major contributions were detailed analysis of performance
trade-off in the presence of the eavesdropping threat, a
combined encoding and routing approach that provides provable
security against noncooperating eavesdropping, and a physical
layer approach to counter the primary emulation attack. The
research results under this effort significantly advanced our
understanding on some of the fundamental trade-offs among
various performance metrics in a wireless system. Practically
feasible wireless security measures were also obtained that
could lead to more assured operations in which secured
wireless networks play an indispensable role. This project led to
one PhD dissertation, one pending patent application, two
archival journal papers, and a number of peer-reviewed
conference papers.
Incentives to Adopt Improved Cybersecurity Practices
NIST and the
National
Telecommunication
s and Information
Administration
March 28,
2013
N/A
The Department of Commerce (DOC) is investigating ways to
incentivize companies and organizations to improve their
cybersecurity. To better understand what stakeholders—such as
companies, trade associations, academics, and others—believe
would best serve as incentives, the department has released a
series of questions to gather public comments in a notice of
inquiry.
Cybersecurity: The Nation’s Greatest Threat to Critical
Infrastructure
U.S. Army War
College
March 2013
38
This paper provides a background on what constitutes national
critical infrastructure and critical infrastructure protection;
discusses the immense vulnerabilities, threats, and risks
associated in the protection of critical infrastructure; and
outlines governance and responsibilities of protecting vulnerable
infrastructure. The paper makes recommendations for federal
responsibilities and legislation to direct nation critical
infrastructure efforts to ensure national security, public safety,
and economic stability.
SCADA [Supervisory Control and Data Acquisition] and
Process Control Security Survey
SANS Institute
February 1,
2013
19
SANS Institute surveyed professionals who work with SCADA
and process control systems. Of the nearly 700 respondents,
70% said they consider their SCADA systems to be at high or
severe risk; one-third of them suspected that these systems had
been already been infiltrated.
CRS-27
c11173008
Source
.
Title
Date
Pages
Notes
Follow-up Audit of the Department’s Cyber Security
Incident Management Program
DOE Inspector
General’s Office
December
2012
25
In 2008, the DOE’s Cyber Security Incident Management
Program (DOE/IG-0787, January 2008) reported the department
and National Nuclear Security Administration (NNSA)
established and maintained a number of independent, at least
partially duplicative, cybersecurity incident management
capabilities. Several issues were identified that limited the
efficiency and effectiveness of the department’s cybersecurity
program and adversely affected the ability of law enforcement to
investigate incidents. In response to the findings, management
concurred with the recommendations and indicated that it had
initiated actions to address the issues identified.
Terrorism and the Electric Power Delivery System
National
Academies of
Science
November
2012
146
Focuses on measures that could make the electric power
delivery system less vulnerable to attacks, restore power faster
after an attack, and make critical services less vulnerable when
delivery of conventional electric power has been disrupted.
New FERC Office to Focus on Cyber Security
DOE
September 20,
2012
N/A
FERC announced the creation of the agency’s new Office of
Energy Infrastructure Security, which will work to reduce
threats to the electric grid and other energy facilities. The goal is
for the office to help FERC, and other agencies and private
companies, better identify potential dangers and solutions.
Canvassing the Targeting of Energy Infrastructure: The
Energy Infrastructure Attack Database
Journal of Energy
Security
August 7,
2012
8
The Energy Infrastructure Attack Database (EIAD) is a
noncommercial dataset that structures information on reported
(criminal and political) attacks to energy infrastructure
worldwide by nonstate actors since 1980. In building this
resource, the objective was to develop a product that could be
broadly accessible and connect to existing available resources.
Smart-Grid Security
Center for
Infrastructure
Protection and
Homeland Security,
George Mason
School of Law
August 2012
26
Highlights the significance of and the challenges with securing the
Smart Grid.
Cybersecurity: Challenges in Securing the Electricity Grid
GAO
July 17, 2012
25
In a prior report, GAO made recommendations related to
electricity grid modernization efforts, including developing an
approach to monitor compliance with voluntary standards.
These recommendations have not yet been implemented.
CRS-28
c11173008
Source
.
Title
Date
Pages
Notes
Energy Department Develops Tool with Industry to Help
Utilities Strengthen Their Cybersecurity Capabilities
DOE
June 28, 2012
N/A
The Cybersecurity Self-Evaluation Tool uses best practices
developed for the Electricity Subsector Cybersecurity Capability
Maturity Model Initiative, which involved a series of workshops
with the private sector to draft a maturity model that can be
used throughout the electric sector to better protect the grid.
ICS-CERT Incident Response Summary Report, 20092011
U.S. Industrial
Control System
Cyber Emergency
Response Team
(ICS-CERT)
May 9, 2012
17
The number of reported cyberattacks on U.S. critical
infrastructure increased sharply—from 9 incidents in 2009 to
198 in 2011. Water sector-specific incidents, when added to the
incidents that affected several sectors, accounted for more than
half of all incidents. In more than half of the most serious cases,
implementing best practices such as log-in limitation or a
properly configured firewall would have deterred the attack,
reduced the time it would have taken to detect an attack, and
minimized its impact.
Cybersecurity Risk Management Process (Electricity
Subsector)
DOE Office of
Electricity Delivery
and Energy
Reliability
May 2012
96
The guideline describes a risk-management process that is
targeted to the specific needs of electricity sector organizations.
Its objective is to build upon existing guidance and requirements
to develop a flexible risk-management process tuned to the
diverse missions, equipment, and business needs of the electric
power industry.
ICT Applications for the Smart Grid: Opportunities and
Policy Implications
Organization for
Economic Cooperation and
Development
(OECD)
January 10,
2012
44
This report discusses “smart” applications of information and
communication technologies (ICTs) for more sustainable energy
production, management, and consumption. The report outlines
policy implications for government ministries dealing with
telecommunications regulation, ICT sector and innovation
promotion, and consumer and competition issues.
The Department’s Management of the Smart Grid
Investment Grant Program
DOE Inspector
General
January 20,
2012
21
According to the DOE inspector general, the department’s rush
to award stimulus grants for projects under the next generation
of the power grid, known as the Smart Grid, resulted in some
firms receiving funds without submitting complete plans for how
to safeguard the grid from cyberattacks.
Critical Infrastructure Protection: Cybersecurity
Guidance Is Available, but More Can Be Done to
Promote Its Use
GAO
December 9,
2011
77
According to GAO, given the plethora of guidance available,
individual entities within the sectors may be challenged in
identifying the guidance that is most applicable and effective in
improving their security posture. Improved knowledge of the
available guidance could help both federal and private-sector
decision makers better coordinate their efforts to protect
critical cyber-reliant assets.
CRS-29
c11173008
Source
.
Title
Source
Date
Pages
Notes
The Future of the Electric Grid
Massachusetts
Institute of
Technology (MIT)
December 5,
2011
39
Chapter 1 provides an overview of the status of the electric
grid, the challenges and opportunities it will face, and major
recommendations. To facilitate selective reading, detailed
descriptions of the contents of each section in Chapters 2–9 are
provided in each chapter’s introduction, and recommendations
are collected and briefly discussed in each chapter’s final section.
(See Chapter 9, “Data Communications, Cybersecurity, and
Information Privacy,” pages 208-234).
FCC’s Plan for Ensuring the Security of
Telecommunications Networks
Federal
Communications
Commission (FCC)
June 3, 2011
1
FCC Chairman Genachowski’s response to letter from
Representative Anna Eshoo dated November 2, 2010, regarding
concerns about the implications of foreign-controlled
telecommunications infrastructure companies providing
equipment to the U.S. market.
Cyber Infrastructure Protection
U.S. Army War
College
May 9, 2011
324
Part 1 deals with strategic and policy cybersecurity-related
issues and discusses the theory of cyberpower, Internet
survivability, large-scale data breaches, and the role of
cyberpower in humanitarian assistance. Part 2 covers social and
legal aspects of cyber infrastructure protection and discusses the
attack dynamics of political and religiously motivated hackers.
Part 3 discusses the technical aspects of cyber infrastructure
protection, including the resilience of data centers, intrusion
detection, and a strong emphasis on Internet protocol (IP)
networks.
In the Dark: Crucial Industries Confront Cyberattacks
McAfee and Center
for Strategic and
International
Studies (CSIS)
April 21, 2011
28
The study reveals an increase in cyberattacks on critical
infrastructure such as power grids, oil, gas, and water; it also
shows that many of the world’s critical infrastructures lacked
protection of their computer networks and reveals the cost and
impact of cyberattacks.
Cybersecurity: Continued Attention Needed to Protect
Our Nation’s Critical Infrastructure and Federal
Information Systems
GAO
March 16,
2011
17
According to GAO, executive branch agencies have made
progress instituting several government-wide initiatives aimed at
bolstering aspects of federal cybersecurity, such as reducing the
number of federal access points to the Internet, establishing
security configurations for desktop computers, and enhancing
situational awareness of cyber events. Despite these efforts, the
federal government continues to face significant challenges in
protecting the nation’s cyber-reliant critical infrastructure and
federal information systems.
CRS-30
c11173008
.
Title
Source
Federal Energy Regulatory Commission’s Monitoring of
Power Grid Cyber Security
DOE Office of
Inspector General
Electricity Grid Modernization: Progress Being Made on
Cybersecurity Guidelines, but Key Challenges Remain to
be Addressed
Pages
Notes
January 26,
2011
30
NERC developed Critical Infrastructure Protection (CIP)
cybersecurity reliability standards, which were approved by the
FERC in January 2008. Although the commission had taken steps
to ensure CIP cybersecurity standards were developed and
approved, NERC’s testing revealed that such standards did not
always include controls commonly recommended for protecting
critical information systems. In addition, the CIP standards
implementation approach and schedule approved by the
commission were not adequate to ensure that systems-related
risks to the nation’s power grid were mitigated or addressed in
a timely manner.
GAO
January 12,
2011
50
From the report: “To reduce the risk that NIST’s smart grid
cybersecurity guidelines will not be as effective as intended, the
Secretary of Commerce should direct the Director of NIST to
finalize the agency’s plan for updating and maintaining the
cybersecurity guidelines, including ensuring it incorporates (1)
missing key elements identified in this report, and (2) specific
milestones for when efforts are to be completed. Also, as a part
of finalizing the plan, the Secretary of Commerce should direct
the Director of NIST to assess whether any cybersecurity
challenges identified in this report should be addressed in the
guidelines.”
Partnership for Cybersecurity Innovation
White House
Office of Science
and Technology
Policy
December 6,
2010
4
The Obama Administration released a memorandum of
understanding signed by DOC’s NIST, DHS’s Science and
Technology Directorate (DHS/S&T), and the Financial Services
Sector Coordinating Council (FSSCC). The goal of the
agreement is to speed up the commercialization of cybersecurity
research innovations that support the nation’s critical
infrastructures.
WIB Security Standard Released
International
Instrument Users
Association (WIB)
November 10,
2010
CRS-31
c11173008
Date
The Netherlands-based WIB, an international organization that
represents global manufacturers in the industrial automation
industry, announced the second version of the Process Control
Domain Security Requirements for Vendors document—the first
international standard that outlines a set of specific
requirements focusing on cybersecurity best practices for
suppliers of industrial automation and control systems.
.
Title
Date
Pages
Notes
Information Security Management System for Microsoft
Cloud Infrastructure
Microsoft
November
2010
15
This study describes the standards Microsoft follows to address
current and evolving cloud security threats. It also depicts the
internal structures within Microsoft that handle cloud security
and risk management issues.
NIST Finalizes Initial Set of Smart Grid Cyber Security
Guidelines
NIST
September 2,
2010
N/A
NIST released a three-volume set of recommendations relevant
to securing the Smart Grid. The guidelines address a variety of
topics, including high-level security requirements, a risk
assessment framework, an evaluation of privacy issues in
residences and recommendations for protecting the evolving
grid from attacks, malicious code, cascading errors, and other
threats.
Critical Infrastructure Protection: Key Private and Public
Cyber Expectations Need to Be Consistently Addressed
GAO
July 15, 2010
38
Private-sector stakeholders reported that they expect their
federal partners to provide usable, timely, and actionable cyber
threat information and alerts; access to sensitive or classified
information; a secure mechanism for sharing information;
security clearances; and a single centralized government
cybersecurity organization to coordinate government efforts.
However, according to private-sector stakeholders, federal
partners are not consistently meeting these expectations.
The Future of Cloud Computing
Pew Research
Center’s Internet
and American Life
Project
June 11, 2010
26
Technology experts and stakeholders expect they will “live
mostly in the cloud” in 2020 and not on the desktop, working
mostly through cyberspace-based applications accessed through
networked devices.
The Reliability of Global Undersea Communications Cable
Infrastructure (The ROGUCCI Report)
Institute of
Electrical and
Electronics
Engineers and the
EastWest Institute
May 26, 2010
186
This study submits 12 major recommendations to privatesector, government, and other stakeholders—especially the
financial sector—for the purpose of improving the reliability,
robustness, resilience, and security of the world’s undersea
communications cable infrastructure.
NSTB Assessments Summary Report: Common Industrial
Control System Cyber Security Weaknesses
DOE, Idaho
National
Laboratory
May 2010
123
This report by the National SCADA Test Bed (NSTB) program
notes that computer networks controlling the electric grid are
plagued with security holes that could allow intruders to
redirect power delivery and steal data. Many of the security
vulnerabilities are strikingly basic and fixable problems.
Explore the reliability and resiliency of commercial
broadband communications networks
FCC
April 21, 2010
N/A
The FCC launched an inquiry into the ability of existing
broadband networks to withstand significant damage or severe
overloads as a result of natural disasters, terrorist attacks,
pandemics, or other major public emergencies, as recommended
in the National Broadband Plan.
CRS-32
c11173008
Source
.
Title
Source
Date
Security Guidance for Critical Areas of Focus in Cloud
Computing V2.1
Cloud Security
Alliance
21 Steps to Improve Cyber Security of SCADA Networks
DOE,
Infrastructure
Security and Energy
Restoration
Source: Highlights compiled by CRS from the reports.
CRS-33
c11173008
Pages
Notes
December
2009
76
From the report, “Through our focus on the central issues of
cloud computing security, we have attempted to bring greater
clarity to an otherwise complicated landscape, which is often
filled with incomplete and oversimplified information. Our focus
... serves to bring context and specificity to the cloud computing
security discussion: enabling us to go beyond gross
generalizations to deliver more insightful and targeted
recommendations.”
January 1,
2007
10
The President’s Critical Infrastructure Protection Board and
DOE have developed steps to help any organization improve the
security of its SCADA networks. The steps are divided into two
categories: specific actions to improve implementation and
actions to establish essential underlying management processes
and policies.
Cybersecurity: Authoritative Reports and Resources, by Topic
.
Cybercrime and Data Security: CRS Reports and Other CRS
Products
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
c11173008
CRS Report 97-1025, Cybercrime: An Overview of the Federal Computer Fraud
and Abuse Statute and Related Federal Criminal Laws, by Charles Doyle
CRS Report 94-166, Extraterritorial Application of American Criminal Law, by
Charles Doyle
CRS Report R43955, Cyberwarfare and Cyberterrorism: In Brief, by Catherine
A. Theohary and John W. Rollins
CRS Report R42403, Cybersecurity: Cyber Crime Protection Security Act (S.
2111, 112th Congress)—A Legal Analysis, by Charles Doyle
CRS Report 98-326, Privacy: An Overview of Federal Statutes Governing
Wiretapping and Electronic Eavesdropping, by Gina Stevens and Charles Doyle
CRS Report RL32706, Spyware: Background and Policy Issues for Congress, by
Patricia Moloney Figliola
CRS Report CRS Report R41975, Illegal Internet Streaming of Copyrighted
Content: Legislation in the 112th Congress, by Brian T. Yeh
CRS Report R42112, Online Copyright Infringement and Counterfeiting:
Legislation in the 112th Congress, by Brian T. Yeh
CRS Report R40599, Identity Theft: Trends and Issues, by Kristin Finklea
CRS Report R41927, The Interplay of Borders, Turf, Cyberspace, and
Jurisdiction: Issues Confronting U.S. Law Enforcement, by Kristin Finklea
CRS Report RL34651, Protection of Children Online: Federal and State Laws
Addressing Cyberstalking, Cyberharassment, and Cyberbullying, by Alison M.
Smith
CRS Report R42547, Cybercrime: Conceptual Issues for Congress and U.S. Law
Enforcement, by Kristin Finklea and Catherine A. Theohary
CRS Report R43382, Data Security and Credit Card Thefts: CRS Experts, by
Eric A. Fischer
CRS Legal Sidebar WSLG483, Obstacles to Private Sector Cyber Threat
Information Sharing, by Edward C. Liu and Edward C. Liu
CRS Legal Sidebar WSLG672, Online Banking Fraud: Liability for
Unauthorized Payment from Business Checking Account, by M. Maureen
Murphy
CRS Legal Sidebar WSLG831, Federal Securities Laws and Recent Data
Breaches, by Michael V. Seitzinger
CRS Legal Sidebar WSLG 906, Hackers Cannot Always Be Tried Where ThirdParty Victims Reside, by Charles Doyle
CRS Legal Sidebar WSLG 959, In the Matter of LabMD: The FTC Must Publicly
Disclose Its Data Security Standards, by Gina Stevens
CRS Report IN10218, Information Warfare: Cyberattacks on Sony, by Catherine
A. Theohary
Congressional Research Service
34
.
Table 5. Cybercrime, Data Breaches, and Data Security
Title
c11173008
Source
Date
Pages
Notes
ThreatExchange
Ongoing
ThreatExchange is a set of application programming interfaces, or
APIs, that let disparate companies trade information about the
latest online attacks. Built atop the Facebook Platform—the
standard set of tools for coding applications atop the company’s
worldwide social network—ThreatExchange is used by Facebook
and a handful of other companies, including Tumblr, Pinterest,
Twitter, and Yahoo. Access to the service is strictly controlled,
but [Facebook] hopes to include other companies as time goes
on.
HHS Breach Portal: Breaches Affecting 500 or
More Individuals
Health and Human
Services (HHS)
Ongoing
As required by Section 13402(e)(4) of the HITECH Act, the
Secretary must post a list of breaches of unsecured protected
health information affecting 500 or more individuals. These
breaches are now posted in a new, more accessible format that
allows users to search and sort the posted breaches. Additionally,
this new format includes brief summaries of the breach cases that
OCR has investigated and closed, as well as the names of private
practice providers who have reported breaches of unsecured
protected health information to the Secretary.
ThreatWatch
NextGov
Ongoing
N/A
ThreatWatch is a snapshot of the data breaches hitting
organizations and individuals, globally, on a daily basis. It is not an
authoritative list because many compromises are never reported
or even discovered. The information is based on accounts
published by outside news organizations and researchers.
Criminal Underground Economy Series
Trend Micro
Ongoing
N/A
A review of various cybercrime markets around the world.
Digital Attack Map
Arbor Networks
Ongoing
N/A
The map is powered by data fed from 270+ ISP customers
worldwide who have agreed to share network traffic and attack
statistics. The map displays global activity levels in observed attack
traffic, which it collected anonymously, and does not include any
identifying information about the attackers or victims involved in
any particular attack.
Global Botnet Map
Trend Micro
Ongoing
N/A
Trend Micro continuously monitors malicious network activities
to identify command-and-control (C&C) servers and help increase
protection against botnet attacks. The real-time map indicates the
locations of C&C servers and victimized computers they control
that have been discovered in the previous six hours.
CRS-35
.
Title
c11173008
Source
Date
Pages
Notes
HoneyMap
Honeynet Project
Ongoing
N/A
The HoneyMap displays malicious attacks as they happen. Each red
dot represents an attack on a computer. Yellow dots represent
honeypots or systems set up to record incoming attacks. The
black box on the bottom gives the location of each attack. The
Honeynet Project is an international 501c3 nonprofit security
research organization, dedicated to investigating the latest attacks
and developing open source security tools to improve Internet
security.
The Cyberfeed
Anubis Networks
Ongoing
N/A
This site provides real-time threat intelligence data worldwide.
Regional Threat Assessment: Infection Rates and
Threat Trends by Location Regional Threat
Assessment: Infection Rates and Threat Trends by
Location (Note: Select “All Regions” or a specific
country or region to view threat assessment
reports)
Microsoft Security
Intelligence Report (SIR)
Ongoing
N/A
This report provides data on infection rates, malicious websites,
and threat trends by regional location, worldwide.
Meet ‘Tox': Ransomware for the Rest of Us
McAfee Labs
May 23, 2015
N/A
The packaging of malware and malware-construction kits for
cybercrime “consumers” has been a long-running trend. Various
turnkey kits that cover remote access plus botnet plus stealth
functions are available just about anywhere. Ransomware, though
very prevalent, has not yet appeared in force in easy-to-deploy
kits. However, Tox is now available–and it’s free.
2014 Internet Crime Report
Internet Crime
Complaint Center (IC3)
May 19, 2015
48
IC3, a joint project of the National White Collar Crime Center
and the FBI, received 269,422 complaints last year consisting of a
wide array of scams affecting victims across all demographic
groups. In 2014, victims of Internet crimes in the United States
lost more than $800 million. On average, approximately 22,000
complaints were received each month.
Fifth Annual Benchmark Study on Privacy and
Security of Healthcare Data
Ponemon Institute
May 2015
7
A rise in cyberattacks against doctors and hospitals is costing the
U.S. health-care system $6 billion a year as organized criminals
who once targeted retailers and financial firms increasingly go
after medical records. Criminal attacks are up 125% compared
with five years ago replacing lost laptops as the leading threat.
The study also found most organizations are unprepared to
address new threats and lack adequate resources to protect
patient data.
CRS-36
.
c11173008
Title
Source
Best Practices for Victim Response and Reporting
of Cyber Incidents
Department of Justice
2015 Data Breach Investigations Report (DBIR)
Pages
Notes
April 29,
2015
15
DOJ issued new guidance for businesses on best practices for
handling cyber incidents. The guidance is broken down into what
companies should do— and should not do— before, during and
after an incident. The recommendations include developing an
incident response plan, testing it, identifying highly sensitive data
and risk management priorities, and connecting with law
enforcement and response firms in advance.
Verizon
April 14,
2015
70
A full three-quarters of attacks spread from the first victim to the
second in 24 hours or less, and more than 40% spread from the
first victim to the second in under an hour. On top of the speed
with which attackers compromise multiple victims, the useful
lifespan of shared information can sometimes be measured in
hours. Researchers also found that of the IP addresses observed in
current information sharing feeds, only 2.7% were valid for more
than a day, and the number dwindles from there. Data show that
information sharing has to be good to be effective.
2014 Global Threat Intel Report
CrowdStrike
February 6,
2015
N/A
This report summarizes CrowdStrike’s year-long daily scrutiny of
more than 50 groups of cyber threat actors, including 29 different
state-sponsored and nationalist adversaries. Key findings explain
how financial malware changed the threat landscape and point of
sale malware became increasingly prevalent. The report also
profiles a number of new and sophisticated adversaries from
China and Russia, including Hurricane Panda, Fancy Bear, and
Berserk Bear.
Unique in the shopping mall: On the
reidentifiability of credit card metadata
Science Magazine
January 30,
2015
5
MIT scientists showed they can identify an individual with more
than 90% accuracy by looking at just four purchases, three if the
price is included—and this is after companies “anonymized" the
transaction records, saying they wiped away names and other
personal details.
Ransomware on the Rise: FBI and Partners
Working to Combat This Cyber Threat
FBI
January 20,
2015
N/A
Ransomware scams involve a type of malware that infects
computers and restricts users’ access to their files or threatens
the permanent destruction of their information unless a ransom—
anywhere from hundreds to thousands of dollars—is paid. The
site offers information on the FBI’s and federal, international, and
private-sector partners’ proactive steps to neutralize some of the
more significant ransomware scams through law enforcement
actions against major botnets.
CRS-37
Date
.
Title
c11173008
Source
Date
Pages
Notes
26
Sophos Labs Hungary evaluated the malware and APT campaigns
of several groups that all leveraged a particular exploit—a
sophisticated attack against a specific version of Microsoft Office.
The report found that none of the groups were able to modify the
attack enough to infect other versions of Office, even though
several versions were theoretically vulnerable to the same type of
attack. Despite the aura of skill and complexity that seems to
surround APTs, they are much less sophisticated than they are
given credit for. The APT groups are lacking in quality assurance.
Many attacks are not thoroughly tested and attackers fail to
recognize when some functionality of the attack is not working
properly.
Exploit This: Evaluating the Exploit Skills of
Malware Groups
Sophos Labs Hungary
January 2015
The Cost of Malware Containment
(free registration required)
Ponemon Institute
January 2015
Addressing the cybersecurity Malicious Insider
threat
Schluderberg, Larry
(Utica College Master's
Thesis)
January 2015
80
The purpose of this research was to investigate who constitutes
MI threats, why and how they initiate attacks, the extent to which
MI activity can be modeled or predicted, and to suggest some risk
mitigation strategies. The results reveal that addressing the
Malicious Insider threat is much more than just a technical issue.
Dealing effectively with the threat involves managing the dynamic
interaction between employees, their work environment and
work associates, the systems with which they interact, and
organizational policies and procedures.
The Underground Hacker Markets are Booming
with Counterfeit Documents, Premiere Credit
Cards, Hacker Tutorials, and 1000% Satisfaction
Guarantees
Dell Secure Works
December
2014
16
Researchers examined dozens of underground hacker markets for
this second annual survey and found that business is booming.
Prices have gone down for many items, and the offerings have
expanded. As the report puts it: “Underground hackers are
monetizing every piece of data they can steal or buy and are
continually adding services so other scammers can successfully
carry out online and in-person fraud."
CRS-38
A survey of more than 600 U.S. IT and IT security practitioners
found that in a typical week, organizations receive an average of
nearly 17,000 malware alerts; only 19% are deemed reliable, or
worthy of action. Compounding the problem, respondents believe
their prevention tools miss 40% of malware infections in a typical
week.
.
Title
c11173008
Source
Date
Pages
Notes
What Happens When You Swipe Your Card?
60 Minutes
November
30, 2014
N/A
From the script for the segment “Swiping Your Card”:
“Sophisticated cyberthieves steal your credit card information.
Common criminals buy it and go on shopping sprees—racking up
billions of dollars in fraudulent purchases. The cost of the fraud is
calculated into the price of every item you buy. When computer
crooks swipe your card number, we all end up paying the price.
2014 is becoming known as the ‘year of the data breach.’"
Continuing Federal Cyber Breaches Warn Against
Cybersecurity Regulation
Heritage Foundation
October 27,
2014
N/A
This is a list of federal government cybersecurity breaches and
failures, most of which occurred during 2013 and 2014. The list is
part of a continuing series published by Heritage that serves as a
long-term compilation of open-source data about federal
cybersecurity breaches dating back to 2004.
2014 Cost of Cybercrime Global Report (Email
registration required.)
Hewlett-Packard
Enterprise Security and
the Ponemon Institute
October 8,
2014
30
This 2014 global study of U.S.-based companies, which spanned
seven nations, found that over the course of a year the average
cost of cybercrime climbed by more than 9% to $12.7 million for
companies in the United States, up from $11.6 million in the 2013
study. The average time to resolve a cyberattack is also rising,
climbing to 45 days from 32 days in 2013.
How Consumers Foot the Bill for Data Breaches
(infographic)
NextGov.com
August 7,
2014
Is Ransomware Poised for Growth?
Symantec
July 14, 2014
N/A
Ransomware usually masquerades as a virtual “wheel clamp” for
the victim’s computer. For example, pretending to be from the
local law enforcement, it might suggest the victim had been using
the computer for illicit purposes and claim that to unlock his or
her computer the victim would have to pay a fine—often between
$100 and $500. The use of Ransomware escalated in 2013, with a
500% (sixfold) increase in attack numbers between the start and
end of the year.
iDATA: Improving Defences Against Targeted
Attack
Centre for the
Protection of National
Infrastructure (UK)
July 2014
8
The iDATA program consists of a number of projects aimed at
addressing threats posed by nation-states and state-sponsored
actors. iDATA has resulted in several outputs for the
cybersecurity community. This document provides a description
of the iDATA program and a summary of the reports.
CRS-39
More than 600 data breaches occurred in 2013 alone, with an
average organizational cost of more than $5 million. But in the
end, it is the customers who are picking up the tab, from higher
retail costs to credit card reissue fees.
.
Title
c11173008
Source
Date
Pages
Notes
Cyber Risks: The Growing Threat
Insurance Information
Institute
June 27,
2014
27
Although cyber risks and cybersecurity are widely acknowledged
to be serious threats, many companies today still do not purchase
cyber risk insurance. Insurers have developed specialist cyber
insurance policies to help businesses and individuals protect
themselves from the cyber threat. Market intelligence suggests
that the types of specialized cyber coverage being offered by
insurers are expanding in response to this fast-growing market
need.
Hackers Wanted: An Examination of the
Cybersecurity Labor Market
RAND Corporation
June 24,
2014
110
RAND examined the current status of the labor market for
cybersecurity professionals—with an emphasis on their being
employed to defend the United States. This effort was in three
parts: first, a review of the literature; second, interviews with
managers and educators of cybersecurity professionals,
supplemented by reportage; and third, an examination of the
economic literature about labor markets. RAND also
disaggregated the broad definition of “cybersecurity professionals”
to unearth skills differentiation as relevant to this study.
Global Cybercrime: The Interplay of Politics and
Law
Centre for International
Governance Innovation
June 20,
2014
23
This paper explores the recent unsealing of a 31-count indictment
against 5 Chinese government officials and a significant cyber
breach perpetrated by Chinese actors against Western oil, energy,
and petrochemical companies. The paper concludes by noting that
increased cooperation between governments is necessary but
unlikely to occur as long as the discourse surrounding cybercrime
remains so heavily politicized and securitized. If governments
coalesced around the notion of trying to prevent the long-term
degradation of trust in the online economy, then they might
profitably advance the dialogue away from mutual suspicion and
toward mutual cooperation.
Net Losses: Estimating the Global Cost of
Cybercrime
Center for Strategic and
International Studies and
McAfee
June 2014
24
This report explores the economic impact of cybercrime,
including estimation, regional variances, IP theft, opportunity and
recovery costs, and the future of cybercrime.
2014 U.S. State of Cybercrime Survey
PricewaterhouseCooper
s, CSO Magazine, the
CERT Division of the
Software Engineering
Institute at Carnegie
Mellon University, and
the U.S. Secret Service
May 29, 2014
21
The cybersecurity programs of U.S. organizations do not rival the
persistence, tactical skills, and technological prowess of their
potential cyber adversaries. This year, three out of four (77%)
respondents to the survey had detected a security event in the
past 12 months, and more than one-third (34%) said the number
of security incidents detected had increased over the previous
year.
CRS-40
.
Title
c11173008
Source
Date
Pages
Notes
Privileged User Abuse and The Insider Threat
(Requires free registration to access.)
Ponemon Institute and
Raytheon
May 21, 2014
32
The report looks at what companies are doing right and the
vulnerabilities that need to be addressed with policies and
technologies. One problematic area is the difficulty in actually
knowing if an action taken by an insider is truly a threat. Sixty-nine
percent of respondents say they do not have enough contextual
information from security tools to make this assessment, and 56%
say security tools yield too many false positives.
Online Advertising and Hidden Hazards to
Consumer Security and Data Privacy
Senate Permanent
Subcommittee on
Investigations
May 15, 2014
47
The report found consumers could expose themselves to malware
just by visiting a popular website. It noted that the complexity of
the industry made it possible for both advertisers and host
websites to defer responsibility and that consumer safeguards
failed to protect against online abuses. The report also warned
that current practices do not create enough incentives for “online
advertising participants” to take preventive measures.
Sharing Cyberthreat Information Under 18 USC §
2702(a)(3)
Department of Justice
May 9, 2014
7
The Department of Justice issued guidance for Internet service
providers to assuage legal concerns about information sharing.
The white paper interprets the Stored Communications Act,
which prohibits providers from voluntarily disclosing customer
information to governmental entities. The white paper says the
law does not prohibit companies from divulging data in the
aggregate, without any specific details about identifiable
customers.
The Rising Strategic Risks of Cyberattacks
McKinsey and Company
May 2014
N/A
Companies are struggling with their capabilities in cyber risk
management. As highly visible breaches occur with increasing
regularity, most technology executives believe they are losing
ground to attackers. Organizations large and small lack the facts to
make effective decisions, and traditional “protect the perimeter”
technology strategies are proving insufficient.
Big Data: Seizing Opportunities, Preserving Values
White House
May 2014
85
Findings include a set of consumer protection recommendations,
such as national data-breach legislation, and a fresh call for
baseline consumer-privacy legislation first recommended in 2012.
The Target Breach, by the Numbers
Krebs on Security
May 6, 2014
N/A
A synthesis of numbers associated with the Target data breach of
December 19, 2013 (e.g., number of records stolen, estimated
dollar cost to credit unions and community banks, amount of
money Target estimates it will spend upgrading payment terminals
to support Chip-and-PIN enabled cards).
CRS-41
.
Title
c11173008
Source
Date
Pages
Notes
Heartbleed’s Impact
Pew Research Center
April 30,
2014
13
The Heartbleed security flaw on one of the most widely used
“secure socket” encryption programs on the Internet had an
impact on a notable share of Internet users. Some 60% of adults
(and 64% of Internet users) said they had heard about the bug.
Some 19% of adults said they had heard a lot about it, and 41%
said they had heard a little about it. However, the Heartbleed
story drew much less intensity and scope of attention than other
big news stories.
Russian Underground Revisited
Trend Micro
April 28,
2014
25
The price of malicious software—designed to enable online bank
fraud, identity theft, and other cybercrimes—is falling dramatically
in some of the Russian-language criminal markets in which it is
sold. Falling prices are a result not of declining demand but rather
of an increasingly sophisticated marketplace. This report outlines
the products and services being sold and what their prices are.
A “Kill Chain” Analysis of the 2013 Target Data
Breach
Senate Commerce
Committee
March 26,
2014
18
This report analyzes what has been reported to date about the
Target data breach, using the intrusion kill chain framework, an
analytical tool introduced by Lockheed Martin security
researchers in 2011 and today widely used by information security
professionals in both the public and private sectors. This analysis
suggests that Target missed a number of opportunities along the
kill chain to stop the attackers and prevent the massive data
breach.
Markets for Cybercrime Tools and Stolen Data
RAND Corporation
National Security
Research Division and
Juniper Networks
March 25,
2014
83
This report, part of a multiphase study on the future security
environment, describes the fundamental characteristics of the
criminal activities in cyberspace markets and how they have grown
into their current state to explain how their existence can harm
the information security environment.
CRS-42
.
Title
c11173008
Source
Date
Pages
Notes
Merchant and Financial Trade Associations
Announce Cybersecurity Partnership
Retail Industry Leaders
Association
February 13,
2014
N/A
Trade associations representing the merchant and financial
services industries announced a new cybersecurity partnership.
The partnership will focus on exploring paths to increased
information sharing, better card security technology, and
maintaining the trust of customers. Discussion regarding the
partnership was initiated by the Retail Industry Leaders
Association and the Financial Services Roundtable, joined by the
American Bankers Association, the American Hotel and Lodging
Association, the Clearing House, the Consumer Bankers
Association, the Food Marketing Institute, the Electronic
Transactions Association, the Independent Community Bankers of
America, the International Council of Shopping Centers, the
National Associations of Convenience Stores, the National
Grocers Association, the National Restaurant Association, and the
National Retail Federation.
FTC Statement Marking the FTC’s 50th Data
Security Settlement
Federal Trade
Commission (FTC)
January 31,
2014
2
The FTC announces its 50th data security settlement. What
started in 2002 with a single case applying established FTC Act
precedent to the area of data security has grown into an
enforcement program that has helped to increase protections for
consumers and encouraged companies to make safeguarding
consumer data a priority.
Worst Practices Guide to Insider Threats: Lessons
from Past Mistakes
American Academy of
Arts and Sciences
January 2014
32
From the report: “Here, we are presenting a kind of ‘worst
practices’ guide of serious mistakes made in the past regarding
insider threats. While each situation is unique, and serious insider
problems are relatively rare, the incidents we describe reflect
issues that exist in many contexts and that every nuclear security
manager should consider. Common organizational practices—such
as prioritizing production over security, failure to share
information across subunits, inadequate rules or inappropriate
waiving of rules, exaggerated faith in group loyalty, and excessive
focus on external threats—can be seen in many past failures to
protect against insider threats.”
ENISA Threat Landscape 2013—Overview of
Current and Emerging Cyber-Threats
European Union Agency
for Network and
Information Security
(ENISA)
December
11, 2013
70
The report is a collection of top cyber threats that have been
assessed in the reporting period (i.e., within 2013). ENISA has
collected more than 250 reports regarding cyber threats, risks,
and threat agents. This report is a comprehensive compilation of
the top 15 cyber threats assessed.
CRS-43
.
Title
c11173008
Source
Date
Pages
Notes
Cyber-enabled Competitive Data Theft: A
Framework for Modeling Long-Run Cybersecurity
Consequences
Brookings Institution
December
2013
18
Economic espionage has existed at least since the industrial
revolution, but the scope of modern cyber-enabled competitive
data theft may be unprecedented. In this paper, the authors
present what they believe is the first economic framework and
model to understand the long-run impact of competitive data theft
on an economy by taking into account the actual mechanisms and
pathways by which theft harms the victims.
Trends in Incident Response in 2013
U.S. Industrial Control
System Cyber
Emergency Response
Team (ICS-CERT)
Monitor
OctoberDecember
2013
14
In 2013, ICS-CERT responded to 256 incidents reported either
directly from asset owners or through other trusted partners.
Most of these incidents were initially detected in business
networks of critical infrastructure organizations that operate
industrial control systems. Of the 256 reported incidents, 59%, or
151 incidents, occurred in the energy sector, which exceeded all
incidents reported in other sectors combined.
Illicit Cyber Activity Involving Fraud
Carnegie Mellon
University Software
Engineering Institute
August 8,
2013
28
Technical and behavioral patterns were extracted from 80 fraud
cases—67 insider and 13 external—that occurred between 2005
and the present. These cases were used to develop insights and
risk indicators to help private industry, government, and law
enforcement more effectively prevent, deter, detect, investigate,
and manage malicious insider activity within the banking and
finance sectors.
The Economic Impact of Cybercrime and Cyber
Espionage
Center for Strategic and
International Studies
July 22, 2013
20
Losses to the United States (the country in which data is most
accessible) may reach $100 billion annually. The cost of
cybercrime and cyber espionage to the global economy is some
multiple of this, likely measured in hundreds of billions of dollars.
Cyber-Crime, Securities Markets, and Systemic
Risk
World Federation of
Exchanges and the
International
Organization of
Securities Commissions
July 16, 2013
59
This report explores the nature and extent of cybercrime in
securities markets so far and the potential systemic risk aspects of
this threat. It presents the results of a survey to the world’s
exchanges on their experiences with cybercrime, cybersecurity
practices, and perceptions of the risk.
Towards Trustworthy Social Media and
Crowdsourcing
Wilson Center
May 2013
12
Individuals and organizations interested in using social media and
crowdsourcing currently lack two key sets of information: a
systematic assessment of the vulnerabilities in these technologies
and a comprehensive set of best practices describing how to
address those vulnerabilities. Identifying those vulnerabilities and
developing those best practices are necessary to address a
growing number of cybersecurity incidents ranging from innocent
mistakes to targeted attacks that have claimed lives and cost
millions of dollars.
CRS-44
.
c11173008
Title
Source
Date
Pages
Notes
Remaking American Security: Supply Chain
Vulnerabilities and National Security Risks Across
the U.S. Defense Industrial Base
Alliance for American
Manufacturing
May 2013
355
Because the supply chain is global, it makes sense for U.S. officials
to cooperate with other nations to ward off cyberattacks.
Increased international cooperation to secure the integrity of the
global IT system is a valuable long-term objective.
Comprehensive Study on Cybercrime
United Nations Office
on Drugs and Crime
February
2013
320
The study examined the problem of cybercrime from the
perspective of governments, the private sector, academia, and
international organizations. It presents its results in eight chapters,
covering Internet connectivity and cybercrime; the global
cybercrime picture; cybercrime legislation and frameworks;
criminalization of cybercrime; law enforcement and cybercrime
investigations; electronic evidence and criminal justice;
international cooperation in criminal matters involving cybercrime;
and cybercrime prevention.
HoneyMap - Visualizing Worldwide Attacks in
Real-Time and Honeynet Map
The Honeynet Project
October 1,
2012
N/A
The HoneyMap shows a real-time visualization of attacks against
the Honeynet Project’s sensors deployed around the world.
Does Cybercrime Really Cost $1 Trillion?
ProPublica
August 1,
2012
N/A
In a news release to announce its 2009 report, Unsecured
Economies: Protecting Vital Information, computer security firm
McAfee estimated a $1 trillion global cost for cybercrime. The
number does not appear in the report itself. This estimate is
questioned even by the three independent researchers from
Purdue University whom McAfee credits with analyzing the raw
data from which the estimate was derived. An examination by
ProPublica has found new grounds to question the data and
methods used to generate these numbers, which McAfee and
Symantec say they stand behind.
Information Security: Cyber Threats Facilitate
Ability to Commit Economic Espionage
Government
Accountability Office
(GAO)
June 28,
2012
20
This statement discusses (1) cyber threats facing the nation’s
systems, (2) reported cyber incidents and their impacts, (3)
security controls and other techniques available for reducing risk,
and (4) the responsibilities of key federal entities in support of
protecting Internet protocol.
Measuring the Cost of Cybercrime
11th Annual Workshop
on the Economics of
Information Security
June 25,
2012
N/A
From the report: “For each of the main categories of cybercrime
we set out what is and is not known of the direct costs, indirect
costs and defence costs—both to the UK and to the world as a
whole.”
The Impact of Cybercrime on Businesses
Ponemon Institute
May 2012
21
The study found that targeted attacks on businesses cost
enterprises an average of $214,000. The expenses are associated
with forensic investigations, investments in technology, and brand
recovery costs.
CRS-45
.
Title
Source
Date
Pages
Notes
Proactive Policy Measures by Internet Service
Providers against Botnets
Organization for
Economic Co-operation
and Development
(OECD)
May 7, 2012
25
This report analyzes initiatives in a number of countries through
which end-users are notified by Internet service providers (ISPs)
when their computers are identified as being compromised by
malicious software and encouraged to take action to mitigate the
problem.
Developing State Solutions to Business Identity
Theft: Assistance, Prevention and Detection Efforts
by Secretary of State Offices
National Association of
Secretaries of State
(NASS)
January 2012
23
This white paper is the result of efforts by the 19-member NASS
Business Identity Theft Task Force to develop policy guidelines
and recommendations for state leaders dealing with identity fraud
cases involving public business records.
Twenty Critical Security Controls for Effective
Cyber Defense: Consensus Audit Guidelines
SANS Institute
October 3,
2011
77
The 20 security measures are intended to focus agencies’ limited
resources on plugging the most common attack vectors.
Revealed: Operation Shady RAT: an Investigation
Of Targeted Intrusions Into 70+ Global
Companies, Governments, and Non-Profit
Organizations During the Last 5 Years
McAfee
August 2,
2011
14
A cyber-espionage operation lasting many years penetrated 72
government and other organizations, most of them in the United
States, and has copied everything from military secrets to
industrial designs, according to technology security company
McAfee. (See page 4 for the types of compromised parties, page 5
for the geographic distribution of victim’s country of origin, pages
7-9 for the types of victims, and pages 10-13 for the number of
intrusions for 2007-2010).
The Role of Internet Service Providers in Botnet
Mitigation: an Empirical Analysis Based on Spam
Data
OECD
November
12, 2010
31
This working paper considers whether ISPs can be critical control
points for botnet mitigation, how the number of infected machines
varies across ISPs, and why.
Untangling Attribution: Moving to Accountability in
Cyberspace (Testimony)
Council on Foreign
Relations
July 15, 2010
14
Robert K. Knake’s testimony before the House Committee on
Science and Technology on the role of attack attribution in
preventing cyberattacks and how attribution technologies can
affect the anonymity and privacy of Internet users.
Technology, Policy, Law, and Ethics Regarding U.S.
Acquisition and Use of Cyberattack Capabilities
National Research
Council
2009
368
This report explores important characteristics of cyberattacks. It
describes the current international and domestic legal structure as
it might apply to cyberattacks and considers analogies to other
domains of conflict to develop relevant insights.
Source: Highlights compiled by CRS from the reports.
c11173008
CRS-46
.
Table 6. National Security, Cyber Espionage, and Cyberwar
Title
c11173008
Source
Date
Pages
Notes
Cyberthreat: Real-Time Map
Kaspersky Labs
Ongoing
N/A
Kaspersky Labs has launched an interactive cyber threat map that
lets viewers see cybersecurity incidents as they occur around the
world in real time. The interactive map includes malicious objects
detected during on-access and on-demand scans, email and web
antivirus detections, and objects identified by vulnerability and
intrusion detection subsystems.
Cybersecurity: Jihadism and the internet
European
Parliament Think
Tank
May 18,
2015
2
Since the beginning of the conflict in Syria in March 2011, the
numbers of European citizens supporting or joining the ranks of
ISIL/Da'esh have been growing steadily, and may now be as high
as 4,000 individuals. At the same time, the possible avenues for
radicalisation are multiplying and the risks of domestic terrorism
increasing. The proliferation of global jihadi messaging online and
their reliance on social networks suggest that the Internet is
increasingly a tool for promoting jihadist ideology, collecting funds
and mobilizing their ranks.
APT30 and the Mechanics of a Long-Running CyberEspionage Operation: How a Cyber Threat Group
Exploited Governments and Commercial Entities Across
Southeast Asia and India for Over a Decade
FireEye
April 2015
70
A Chinese government hacking team has used the same basic set
of tools to spy on Southeast Asian and Indian dignitaries for a
decade, demonstrating the low level of cyber defenses protecting
government information across broad swaths of the world. The
fact this group, APT30, has been able to use the same basic set of
malware tools against government networks since at least 2005
suggests its targets remained unaware for more than a decade
they were being spied on, or were incapable of countering the
threat.
Excepted Service (DoD)
Office of
Personnel
Management
March 5,
2015
3
DOD is given authority to make permanent, time-limited and
temporary appointments not to exceed 3,000 positions that
require unique cybersecurity skills and knowledge to perform
cyber risk and strategic analysis, incident handling and
malware/vulnerability analysis, program management, distributed
control systems security, cyber incident response, cyber exercise
facilitation and management, cyber vulnerability detection and
assessment, network and systems engineering, enterprise
architecture, investigation, investigative analysis and cyber-related
infrastructure inter-dependency analysis.
CRS-47
.
Title
c11173008
Source
Date
Pages
Notes
Worldwide Threat Assessment of the US Intelligence
Community
Director of
National
Intelligence
February 26,
2015
29
Cybersecurity is the first threat listed in this annual review of
worldwide threats to the United States. Despite ever-improving
network defenses, the diverse possibilities for remote hacking
intrusions, supply chain operations to insert compromised
hardware or software, and malevolent activities by human insiders
will hold nearly all ICT systems at risk for years to come. In
short, the cyber threat cannot be eliminated; rather, cyber risk
must be managed. Moreover, the risk calculus employed by some
private-sector entities does not adequately account for foreign
cyber threats or the systemic interdependencies between
different critical infrastructure sectors.
The Impact of the Dark Web on Internet Governance and
Cyber Security
Global
Commission on
Internet
Governance
February
2015
18
There has not been much consideration of the governance of the
deep Web and the dark Web. The term deep Web is used to
denote a class of content on the Internet that, for various
technical reasons, is not indexed by search engines. The dark
Web is a part of the deep Web that has been intentionally hidden
and is inaccessible through standard Web browsers. The deep
Web has the potential to host an increasingly high number of
malicious services and activities. To formulate comprehensive
strategies and policies for governing the Internet, it is important
to consider insights on its farthest reaches— the deep Web and,
more importantly, the dark Web. The paper endeavors to
provide a broader understanding of the dark Web and its impact
on people lives.
Attributing Cyber Attacks
Thomas Rid and
Ben Buchanan,
Journal of
Strategic Studies
December
23, 2014
36
“This article argues that attribution is what states make of it. To
show how, we introduce the Q Model: designed to explain, guide,
and improve the making of attribution. Matching an offender to an
offence is an exercise in minimizing uncertainty on three levels:
tactically, attribution is an art as well as a science; operationally,
attribution is a nuanced process not a black-and-white problem;
and strategically, attribution is a function of what is at stake
politically. Successful attribution requires a range of skills on all
levels, careful management, time, leadership, stress-testing,
prudent communication, and recognizing limitations and
challenges.”
CRS-48
.
Title
c11173008
Source
Date
Pages
Notes
Operation Cleaver
Cylance
December
2, 2014
86
A sophisticated hacking group with ties to Iran has probed and
infiltrated targets across the United States and 15 other nations
during the past two years in a series of cyberattacks dubbed
“Operation Cleaver.” The Cleaver group has evolved faster than
any previous Iranian campaign, according to the report, which
calls Iran “the new China” and expresses concern that the
group’s surveillance operations could evolve into sophisticated,
destructive attacks.
Legal Issues Related to Cyber
NATO Legal
Gazette
December
2014
74
The NATO Legal Gazette contains thematically organized articles
usually written by authors who are military or civilian legal
personnel working at NATO or in the governments of NATO
and partner nations. Its purpose is to share articles of significance
for the large NATO legal community and connect legal
professionals of the Alliance. It is not a formal NATO document.
The National Intelligence Strategy of the United States of
America 2014
Office of the
Director of
National
Intelligence
September
18, 2014
24
Cyber intelligence is one of four “primary topical missions” the
intelligence community must accomplish. Both state and nonstate
actors use digital technologies to achieve goals, such as fomenting
instability or achieving economic and military advantages. They do
so “often faster than our ability to understand the security
implications and mitigate potential risks,” the strategy states. To
become more effective in the cyber arena, the intelligence
community will improve its ability to correctly attribute attacks.
Today’s Rising Terrorist Threat and the Danger to the
United States: Reflections on the Tenth Anniversary of the
9/11 Commission Report
The Annenberg
Public Policy
Center and the
Bipartisan Policy
Center
July 22, 2014
48
Members of the panel that studied the 2001 attacks urge
Congress to enact cybersecurity legislation, the White House to
communicate the consequences of potential cyberattacks to
Americans, and leaders to work with allies to define what
constitutes an online attack on another country.
Surviving on a Diet of Poisoned Fruit: Reducing the
National Security Risks of America’s Cyber Dependencies
Center for a
New American
Security
July 2014
64
In the report, the author examines existing information on
technology security weaknesses and provides nine specific
recommendations for the U.S. government and others to cope
with these insecurities.
CRS-49
.
Title
c11173008
Source
Date
Pages
Notes
Baseline Review: ICT-Related Processes and Events,
Implications for International and Regional Security (20112013)
ICT4Peace
May 1, 2014
50
The report is structured around the following three areas: (1)
international and regional security (the predominant focus); (2)
transnational crime and terrorism; and (3) governance, human
rights, and development. These areas are obviously
interdependent, with developments in one area often impacting
another, yet they have traditionally been approached separately
through distinct communities of practice and fora. The report will
serve as a baseline for future annual reports. It covers the period
spanning from January 2011 to December 2013 and provides
background on earlier events.
M Trends: Beyond the Breach: 2014 Threat Report
Mandiant
April 2014
28
From the report: “One conclusion is inescapable: the list of
potential targets has increased, and the playing field has grown,
Cyber-threat actors are expanding the uses of computer network
exploitation to fulfill an array of objectives, from the economic to
the political. Threat actors are not only interested in seizing the
corporate crown jewels but are also looking for ways to publicize
their views, cause physical destruction and influence global
decision makers. Private organizations have increasingly become
collateral damage in political conflicts. With no diplomatic
solution in sight, the ability to detect and respond to attacks has
never been more important.”
Emerging Cyber Threats Report 2014
Georgia Institute
of Technology
January 2014
16
Brief compilation of academic research on losing control of cloud
data, insecure but connected devices, attackers adapting to
mobile ecosystems, the high costs of defending against
cyberattacks, and advances in information manipulation.
Cybersecurity and Cyberwar: What Everyone Needs to
Know
Brookings
Institution
January 2014
306
Authors Peter W. Singer and Allan Friedman look at
cybersecurity issues faced by the military, government, businesses,
and individuals and examine what happens when these entities try
to balance security with freedom of speech and the ideals of an
open Internet.
Cyber-enabled Competitive Data Theft: A Framework for
Modeling Long-Run Cybersecurity Consequences
Brookings
Institution
December
2013
18
Economic espionage has existed at least since the industrial
revolution, but the scope of modern cyber-enabled competitive
data theft may be unprecedented. In this paper, the authors
present what they believe is the first economic framework and
model to understand the long-run impact of competitive data
theft on an economy by taking into account the actual
mechanisms and pathways by which theft harms the victims.
CRS-50
.
Title
c11173008
Source
Date
Pages
To Kill a Centrifuge: A Technical Analysis of What
Stuxnet’s Creators Tried to Achieve
The Langner
Group
November
2013
36
This document summarizes the most comprehensive research on
the Stuxnet malware so far. It combines results from reverse
engineering the attack code with intelligence on the design of the
attacked plant and background information on the attacked
uranium enrichment process. It looks at the attack vectors of the
two different payloads contained in the malware and provides an
analysis of the bigger and much more complex payload that was
designed to damage centrifuge rotors by overpressure. With both
attack vectors viewed in context, conclusions are drawn about
the reasoning behind a radical change of tactics between the
complex earlier attack and the comparatively simple later attack
that tried to manipulate centrifuge rotor speeds.
2013 Annual Report to Congress
U.S.-China
Economic
Commission
October 20,
2013
465
In 2013, the commission continued its close examination of
China’s cyber capabilities. Strong evidence has emerged that the
Chinese government is directing and executing a large-scale cyber
espionage campaign against the United States, including the U.S.
government and private companies. However, public exposure of
Chinese cyber espionage in 2013 has apparently not changed
China’s attitude about the use of cyber espionage to steal
intellectual property and proprietary information. (See Chapter 2,
Section 2: “China’s Cyber Activities.”)
W32.Duqu: The Precursor to the Next Stuxnet
Symantec
November
14, 2013
N/A
On October 14, 2011, a research lab with strong international
connections alerted Symantec to a sample that appeared to be
very similar to Stuxnet, the malware that wreaked havoc in Iran’s
nuclear centrifuge farms. The lab named the threat Duqu because
it creates files with the file name prefix DQ. The research lab
provided Symantec with samples recovered from computer
systems located in Europe as well as a detailed report with initial
findings, including analysis comparing the threat to Stuxnet.
Offensive Cyber Capabilities at the Operational Level The Way Ahead
Center for
Strategic and
International
Studies (CSIS)
September
16, 2013
CRS-51
20
Notes
The specific question this report examines is whether the
Defense Department should make a more deliberate effort to
explore the potential of offensive cyber tools at levels below that
of a combatant command.
.
Title
c11173008
Source
Date
Pages
Cyber Warfare: Is the risk of cyber warfare overrated?
The Economist
August 2,
2013
N/A
(Economist Debates adapt the Oxford style of debating to an
online forum. Each side has three chances to persuade readers:
opening, rebuttal, and closing.) From the debate: “Separating hype
from the urgent questions is hard. Amid talk of a ‘digital Pearl
Harbour’ and ‘advanced persistent threats’ it is hard to know
whether we are really ‘losing the war’ against the purveyors and
users of malware and digital weapons.”
The Economic Impact of Cybercrime and Cyber Espionage
Center for
Strategic and
International
Studies (CSIS)
July 22, 2013
20
Losses to the United States (the country in which data is most
accessible) may reach $100 billion annually. The cost of
cybercrime and cyber espionage to the global economy is some
multiple of this, likely measured in hundreds of billions of dollars.
Strategies for Resolving the Cyber Attribution Challenge
Air University,
Maxwell Air
Force Base
May 2013
109
Private-sector reports have proven that it is possible to
determine the geographic reference of threat actors to varying
degrees. Based on these assumptions, nation-states, rather than
individuals, should be held culpable for the malicious actions and
other cyber threats that originate in or transit information
systems within their borders or that are owned by their
registered corporate entities. This work builds on other appealing
arguments for state responsibility in cyberspace.
Role of Counterterrorism Law in Shaping ‘ad Bellum’
Norms for Cyber Warfare
International Law
Studies (U.S.
Naval War
College)
April 1,
2013
42
From the report: “The prospect of cyber war has evolved from
science fiction and over-the-top doomsday depictions on
television, films, and in novels to reality and front-page news.…
To date there has been little attention given to the possibility that
international law generally and counterterrorism law in particular
could and should develop a subset of cyber-counterterrorism law
to respond to the inevitability of cyberattacks by terrorists and
the use of cyber weapons by governments against terrorists, and
to supplement existing international law governing cyber war
where the intrusions do not meet the traditional kinetic
thresholds.”
CRS-52
Notes
.
Title
c11173008
Source
Date
Pages
Cyber Incidents Attributed to China
Center for
Strategic and
International
Studies
March 11,
2013
15
Evidence that China and Chinese hackers are responsible for the
many incidents attributed to them. CSIS did a review of open
source literature identifying China as the source of hacking and
cyber espionage incidents. This is an initial list, as we know of
other major cyber incidents attributed to China by officials in
Australia, Canada, France, Germany, India, Japan, the UK, and
other countries not discussed here. We have broken our list into
two parts. The first section lists reports that identify specific
individuals and entities; the second section refers to incidents
ascribed generally to China. These reports identify six groups and
fourteen individuals, all but one connected to the Chinese
government and most with connections to the PLA, as
responsible for cyber espionage
The Tallinn Manual on the International Law Applicable to
Cyber Warfare
Cambridge
University Press/
NATO
Cooperative
Cyber Defence
Center of
Excellence
March 5,
2013
302
The Tallinn Manual identifies the international law applicable to
cyber warfare and sets out 95 “black-letter rules” governing such
conflicts. An extensive commentary accompanies each rule, which
sets forth the rule’s basis in treaty and customary law, explains
how the group of experts interpreted applicable norms in the
cyber context, and outlines any disagreements within the group
as to the rule’s application. (Note: The manual is not an official
NATO publication but rather an expression of opinions of a
group of independent experts acting solely in their personal
capacities.)
Cyberterrorism: A Survey of Researchers
Swansea
University
March 2013
21
This report provides an overview of findings from a project
designed to capture current understandings of cyberterrorism
within the research community. The project ran between June
2012 and November 2012, and it employed a questionnaire that
was distributed to more than 600 researchers, authors, and other
experts. Potential respondents were identified using a
combination of methods, including targeted literature reviews,
standing within relevant academic communities, snowballing from
earlier participants or contacts, and the use of two mailing lists. A
total of 118 responses were received from individuals working in
24 countries across 6 continents. Please contact the research
team with any enquiries on the project’s methods and findings
(see p. 21 for contact details).
CRS-53
Notes
.
Title
c11173008
Source
Date
Pages
Notes
APT1 [Advanced Persistent Threat 1]: Exposing One of
China’s Cyber Espionage Units
Mandiant
February 19,
2013
76
Mandiant conducted hundreds of investigations on computer
security breaches around the world. The details analyzed during
these investigations signal that the groups conducting these
breaches are based primarily in China and that the Chinese
government is aware of them.
Video demo of Chinese hacker activity
(Click on “APT1 Video” at top right of screen.)
Mandiant
February 19,
2013
N/A
Five-minute video of APT1 attacker sessions and intrusion
activities.
Responding to Cyber Attacks and the Applicability of
Existing International Law
Army War
College
January 2013
34
This paper identifies how the United States should respond to the
threat of cyber operations against essential government and
private networks. First, it examines the applicability of established
international law to cyber operations. Next, it proposes a method
for categorizing cyber operations across a spectrum synchronized
with established international law. Finally, it discusses actions
already taken by the United States to protect critical government
and private networks and concludes with additional steps the
United States should take to respond to the threat of cyber
operations.
Crisis and Escalation in Cyberspace
RAND
Corporation
December
2012
200
The report considers how the Air Force should integrate kinetic
and nonkinetic operations. Central to this process was careful
consideration of how escalation options and risks should be
treated, which, in turn, demanded a broader consideration across
the entire crisis-management spectrum. Such crises can be
managed by taking steps to reduce the incentives for other states
to step into crisis, controlling the narrative, understanding the
stability parameters of the crises, and trying to manage escalation
if conflicts arise from crises.
Cyberattacks Among Rivals: 2001-2011 (from the article,
“The Fog of Cyberwar” by Brandon Variano and Ryan
Maness [subscription required])
Foreign Affairs
November
21, 2012
N/A
A chart showing cyberattacks by initiator and victim, 2001-2011.
Emerging Cyber Threats Report 2013
Georgia Institute
of Technology
November
14, 2012
9
An examination of the cyber challenges of 2013, including new
and increasingly sophisticated means to capture and exploit user
data, escalating battles over the control of online information, and
continuous threats to the U.S. supply chain from global sources.
(From the annual Georgia Tech Cyber Security Summit 2012.)
CRS-54
.
Title
c11173008
Source
Date
Pages
Proactive Defense for Evolving Cyber Threats
Sandia National
Labs
November
2012
98
The project applied rigorous predictability-based analytics to two
central and complementary aspects of the network defense
problem—attack strategies of the adversaries and vulnerabilities
of the defenders’ systems—and used the results to develop a
scientifically grounded, practically implementable methodology for
designing proactive cyber defense systems.
Safeguarding Cyber-Security, Fighting in Cyberspace
International
Relations and
Security
Network (ISN)
October 22,
2012
N/A
Looks at the militarization of cybersecurity as a source of global
tension and makes the case that cyber warfare is already an
essential feature of many leading states’ strategic calculations,
followed by its opposite (i.e., the case that the threat posed by
cyber warfare capabilities is woefully overstated).
Before We Knew It: An Empirical Study of Zero-Day
Attacks In The Real World
Symantec
Research Labs
October 16,
2012
12
The paper describes a method for automatically identifying zeroday attacks from field-gathered data that records when benign
and malicious binaries are downloaded on 11 million real hosts
around the world. Searching this data set for malicious files that
exploit known vulnerabilities indicates which files appeared on the
Internet before the corresponding vulnerabilities were disclosed.
Investigative Report on the U.S. National Security Issues
Posed by Chinese Telecommunications Companies
Huawei and ZTE
House
Permanent Select
Committee on
Intelligence
October 8,
2012
60
The committee initiated this investigation in November 2011 to
inquire into the counterintelligence and security threat posed by
Chinese telecommunications companies doing business in the
United States.
Federal Support for and Involvement in State and Local
Fusion Centers
Senate
Permanent
Subcommittee on
Investigations
October 3,
2012
141
A two-year bipartisan investigation found that U.S. Department of
Homeland Security efforts to engage state and local intelligence
“fusion centers” have not yielded significant useful information to
support federal counterterrorism intelligence efforts. In Section
VI, “Fusion Centers Have Been Unable to Meaningfully
Contribute to Federal Counterterrorism Efforts,” Part G, “Fusion
Centers May Have Hindered, Not Aided, Federal
Counterterrorism Efforts,” the report discusses the Russian
“cyberattack” in Illinois.
Putting the “war” in cyberwar: Metaphor, analogy, and
cybersecurity discourse in the United States
First Monday
July 2, 2012
N/A
This essay argues that current contradictory tendencies are
unproductive and even potentially dangerous. It argues that the
war metaphor and nuclear deterrence analogy are neither natural
nor inevitable and that abandoning them would open up new
possibilities for thinking more productively about the full
spectrum of cybersecurity challenges, including the as-yet
unrealized possibility of cyberwar.
CRS-55
Notes
.
Title
c11173008
Source
Date
Pages
Notes
Nodes and Codes: The Reality of Cyber Warfare
U.S. Army School
of Advanced
Military Studies,
Command and
General Staff
May 17,
2012
62
Explores the reality of cyber warfare through the story of
Stuxnet. Three case studies evaluate cyber policy, discourse, and
procurement in the United States, Russia, and China before and
after Stuxnet to illustrate their similar, yet unique, realities of
cyber warfare.
United States Counter Terrorism Cyber Law and Policy,
Enabling or Disabling?
Triangle Institute
for Security
Studies
March 2012
34
From the report: “The incongruence between national
counterterrorism (CT) cyber policy, law, and strategy degrades
the abilities of federal CT professionals to interdict transnational
terrorists from within cyberspace. Specifically, national CT cyber
policies that are not completely sourced in domestic or
international law unnecessarily limit the latitude cyber CT
professionals need to effectively counter terrorists through the
use of organic cyber capabilities. To optimize national CT assets
and to stymie the growing threat posed by terrorists’ everexpanding use of cyberspace, national decision-makers should
modify current policies to efficiently execute national CT
strategies, albeit within the framework of existing CT cyberrelated statutes.”
A Cyberworm that Knows No Boundaries
RAND
Corporation
December
21, 2011
55
Stuxnet-like worms pose a serious threat even to infrastructure
and computer systems that are not connected to the Internet.
Defending against such attacks is an increasingly complex
prospect.
Department of Defense Cyberspace Policy Report: A
Report to Congress Pursuant to the National Defense
Authorization Act for Fiscal Year 2011, Section 934
Department of
Defense
November
2011
14
From the report: “When warranted, we will respond to hostile
attacks in cyberspace as we would to any other threat to our
country. We reserve the right to use all necessary means diplomatic, informational, military and economic - to defend our
nation, our allies, our partners and our interests.”
Cyber War Will Not Take Place
Journal of Strategic
Studies
October 5,
2011
29
The paper argues that cyber warfare has never taken place, is not
currently taking place, and is unlikely to take place in the future.
Foreign Spies Stealing U.S. Economic Secrets in
Cyberspace: Report to Congress on Foreign Economic
Collection and Industrial Espionage, 2009-2011
Office of the
National
Counterintelligen
ce Executive
October
2011
31
Because the United States is a leader in the development of new
technologies and a central player in global financial and trade
networks, foreign attempts to collect U.S. technological and
economic information will continue at a high level and will
represent a growing and persistent threat to U.S. economic
security. The nature of the cyber threat will evolve with
continuing technological advances in the global information
environment.
CRS-56
.
Title
c11173008
Source
Date
Pages
Notes
USCYBERCOM [U.S. Cyber Command] and Cyber
Security: Is a Comprehensive Strategy Possible?
Army War
College
May 12,
2011
32
Examines five aspects of USCYBERCOM: organization, command
and control, computer network operations, synchronization, and
resourcing. Identifies areas that currently present significant risk
to USCYBERCOM’s ability to create a strategy that can achieve
success in its cyberspace operations and recommends potential
solutions that can increase the effectiveness of the
USCYBERCOM strategy.
A Four-Day Dive Into Stuxnet’s Heart
Threat Level Blog
(Wired)
December
27, 2010
N/A
From the article: “It is a mark of the extreme oddity of the
Stuxnet computer worm that Microsoft’s Windows vulnerability
team learned of it first from an obscure Belarusian security
company that even they had never heard of.”
Did Stuxnet Take Out 1,000 Centrifuges at the Natanz
Enrichment Plant? A Preliminary Assessment
Institute for
Science and
International
Security
December
22, 2010
10
This report indicates that commands in the Stuxnet code
intended to increase the frequency of devices targeted by the
malware exactly match several frequencies at which rotors in
centrifuges at Iran’s Natanz enrichment plant are designed to
operate optimally or are at risk of breaking down and flying apart.
Stuxnet Analysis
European
Network and
Information
Security Agency
October 7,
2010
N/A
A European Union cybersecurity agency warns that the Stuxnet
malware is a game changer for critical information infrastructure
protection; programmable logic controllers of supervisory
control and data acquisition systems infected with the worm
might be programmed to establish destructive over/under
pressure conditions by running pumps at different frequencies.
Proceedings of a Workshop on Deterring Cyberattacks:
Informing Strategies and Developing Options for U.S.
Policy
National
Research Council
October 5,
2010
400
Per request of the Office of the Director of National Intelligence,
the National Research Council undertook a two-phase project
aimed to foster a broad, multidisciplinary examination of
strategies for deterring cyberattacks on the United States and of
the possible utility of these strategies for the U.S. government.
CRS-57
.
Title
Cyber Warfare: Armageddon in a Teacup?
Source: Highlights compiled by CRS from the reports.
c11173008
CRS-58
Source
Date
Pages
Army Command
and General Staff,
Fort
Leavenworth
December
11, 2009
106
Notes
This study examines cyber warfare conducted against Estonia in
2007, Georgia in 2008, and Israel in 2008. From the report: “In all
three cases Cyber Warfare did not achieve strategic political
objectives on its own. Cyber Warfare employed in the three
cases consisted mainly of Denial of Service attacks and website
defacement. These attacks were a significant inconvenience to the
affected nations, but the attacks were not of sufficient scope,
sophistication, or duration to force a concession from the
targeted nation. Cyber Warfare offensive capability does not
outmatch defensive capability to the extent that would allow the
achievement of a strategic political objective through Cyber
Warfare alone. The possibility of strategic-level Cyber Warfare
remains great, but the capability has not been demonstrated at
this time.”
.
Table 7. International Efforts
Title
c11173008
Source
Date
Pages
Notes
European Cybercrime Center (EC3)
Europol
Ongoing
N/A
The European Commission decided to establish a
European Cybercrime Centre (EC3) at Europol. The
center will be the focal point in the EU’s fight against
cybercrime, contributing to faster reactions in the event
of online crimes. It will support EU member states and
institutions in building operational and analytical
capacity for investigations and cooperation with
international partners.
Global Cybersecurity Index
International
Telecommunications Union
Ongoing
N/A
Based on questionnaire responses received by member
states of the International Telecommunications Union, a
first analysis of cybersecurity development in the Arab
region was compiled and one for the Africa region is
under way. The objective is to release a global status of
cybersecurity for 2014.
The Cyber Hub
Booz Allen Hamilton and
the Economist Intelligence
Unit
Ongoing
N/A
The Cyber Hub’s content was built on several integral
parts: an index that assesses specific aspects of the
cyber environment of the G20 countries and a series of
research papers that examine the implications for the
business community.
Cybersecurity Legislation
International
Telecommunications Union
Ongoing
N/A
An integral and challenging component of any national
cybersecurity strategy is the adoption of regionally and
internationally harmonized, appropriate legislation
against the misuse of information and communication
technologies (ICTs) for criminal or other purposes.
Cyber Security Strategy: Progress So Far
Cabinet Office, United
Kingdom
Ongoing
N/A
From the report: “To support the Strategy we put in
place a National Cyber Security Programme (NCSP)
backed by £650 million of funding to 2015. This year we
increased that investment with a further £210 million in
2015 to 2016. This funding will build on existing
projects and also support new investment, enabling the
UK to retain its emerging reputation as a leader in the
field of cyber security.”
CRS-59
.
Title
c11173008
Source
Date
Pages
Notes
FACT SHEET: The 2015 G-7 Summit at Schloss
Elmau, Germany
White House
June 8, 2015
N/A
Member nations of the Group of Seven today
announced a new cooperative effort to guard the
energy sector from hackers, cyber-spies, and other
online attackers. The seven industrialized democracies
will exchange information on methodologies for
identifying cyber threats and vulnerabilities within the
energy sector, sharing best practices and making
“investment in cybersecurity capabilities and capacity
building.” See "Launching New Work on Energy Sector
Cybersecurity" on the Fact Sheet.
OAS and FIRST Sign Agreement to Improve
Hemispheric Response to Cyber Incidents
Organization of American
States
May 28, 2015
N/A
The Organization of American States and the Forum of
Incident Response and Security Teams plan to
cooperate on cybersecurity incident response and to
promote good cyber hygiene across the Americas. OAS
and FIRST signed an agreement pledging to “jointly
organize technical incident response activities focused
on the needs and challenges of OAS member states”
and to help implement OAS’s Comprehensive InterAmerican Strategy to Combat Threats to Cyber
Security and its Declaration on Strengthening Cyber
Security in the Americas, adopted by member states in
2004 and 2012, respectively.
Global Cybersecurity Index: Updated Report
International
Telecommunication Union
and ABI Research
May 28, 2015
528
Each country profile features information on measures
contained in the five key pillars of the GCI, as enshrined
in the ITU’s Global Cybersecurity Agenda, notably:
legal, technical, organizational, capacity building and
cooperation. Information on child online protection
measures will be added to each profile. The GCI has
been an ongoing project between ITU and ABI
Research to map out cybersecurity efforts undertaken
at the national level. Each of the six regions (Africa,
Americas, Arab States, Asia Pacific, the Commonwealth
of Independent States, and Europe) saw regional
champions emerge. Good practices from each region
and from each of the pillars are highlighted.
CRS-60
.
Title
c11173008
Source
Date
Pages
Notes
European Agenda on Security
European Commission
April 28, 2015
21
The agenda pledges EU nations to review obstacles to
cross-border cybercrime investigations, especially
related to jurisdiction and evidence sharing. It also
pledges EU institutions to follow through on
commitments in the 28-nation bloc’s 2013
Cybersecurity Strategy, especially by adopting a
proposal for a binding EU-wide directive on network
and information security.
EU Cybersecurity Dashboard: A Path to a Secure
European Cyberspace
Business Software Alliance
(BSA)
March 4, 2015
20
The report analyzes the current status of all 28 member
states against pre-determined criteria for cybersecurity
best practices.
Joint Committee Report on Risks and
Vulnerabilities in the EU Financial System
European Banking Authority
March 2015
15
Cybercrime and computer failure are areas of “great
concern” and should be included in financial firms’ risk
management procedures, according to a report by EU
bank, insurance, and market regulators. Financial
institutions should be encouraged to integrate IT
security and resilience into their proprietary risk
models. System security and IT strategy carry their own
risks and complexities that can bleed across into more
traditional forms of risk.
Fact Sheet: US-United Kingdom Cybersecurity
Cooperation
White House
January 16, 2015
N/A
The UK’s Government Communications Headquarters
(GCHQ) and Security Service (MI5) are working with
their U.S. partners—the National Security Agency and
the Federal Bureau of Investigation—to further
strengthen U.S.-UK collaboration on cybersecurity by
establishing a joint cyber cell, with an operating
presence in each country. The cell, which will allow staff
from each agency to be co-located, will focus on
specific cyber defense topics and enable cyber threat
information and data to be shared at pace and at
greater scale.
Threat Landscape and Good Practice Guide for
Internet Infrastructure
European Union Agency for
Network and Information
Security (ENISA)
January 2015
64
The report details the assets composing an Internet
infrastructure and classifies the threats applicable,
highlighting “important specific threats” that disrupt
connectivity. These include routing threats, DNS
threats, and (Distributed) Denial of Service. Each threat
is linked with a list of assets exposed. Overall, there is
an increase in the occurrence of these threats.
CRS-61
.
Title
c11173008
Source
Date
Pages
Notes
Managing the Cyber Security Threat
Hoover Institution Working
Group on Foreign Policy and
Grand Strategy
December 12, 2014
6
From the report: “The cyber threat needs to be
managed through a combination of being realistic and
honest about our willingness and capacity to guarantee
security in this area; accepting multilateral arrangements
to protect commerce and critical infrastructure and
leaving traditional forms of intelligence and military
activities unregulated; and allowing private companies
and individuals to use strong encryption or open-source
software without built-in vulnerabilities.”
“Joint Elements” from U.S.-EU Cyber Dialogue
U.S. State Department and
European Union (EU)
December 5, 2014
N/A
U.S. and EU officials said an inaugural cyber dialogue
meeting in Belgium that they had reaffirmed numerous
shared principles, including a commitment to a
multistakeholder Internet governance model and
international cooperation on cybersecurity. In a joint
preliminary statement, the officials also reiterated their
support for a 2013 United Nations Governmental
Group of Experts consensus that international law
applies in cyberspace just as it does on land or at sea
and for the 2012 Budapest Convention, a treaty focused
on international cooperation to fight cybercrime.
Legal Issues Related to Cyber
NATO Legal Gazette
December 2014
74
The NATO Legal Gazette contains thematically organized
articles usually written by authors who are military or
civilian legal personnel working at NATO or in the
governments of NATO and partner nations. Its purpose
is to share articles of significance for the large NATO
legal community and connect legal professionals of the
Alliance. It is not a formal NATO document.
Cyber defence in the EU: Preparing for cyber
warfare?
European Parliamentary
Research Service
October 31, 2014
10
A number of EU member states are among those
developing their capabilities, and the EU’s own Defence
Agency is also working on projects to augment cyber
defenses in the union. This report includes summaries
of EU member nations and NATO’s national cyberdefense policies.
CRS-62
.
Title
c11173008
Source
Date
Pages
Notes
Inquiry into Cyber Intrusions Affecting U.S.
Transportation Command Contractors
Senate Armed Services
Committee
September 17, 2014
52
Hackers associated with the Chinese government
successfully penetrated the computer systems of
Transportation Command (TRANSCOM) contractors
20 times in the course of a single year. Chinese hackers
tried to get into the systems 50 times. The
congressional committee found that only two of the
intrusions were detected. It also found the officials
were unaware due in large part to unclear requirements
and methods for contractors to report breaches and
for government agencies to share information.
A Role for Civil Society in Cybersecurity Affairs?
ICT4Peace Foundation
September 3, 2014
26
From the report: “The paper is aimed at civil society
organisations, national governments, international and
regional organisations and other key actors concerned
with ICTs and their impact on international and regional
security. They perform a wide range of functions,
including policy-oriented research, advocacy, [and]
networking. In the Internet/cyber security world, civil
society organisations often work in specific issues areas,
many technical or functional in nature and tied to the
maintenance of the Internet. Civil society does not
include the private sector. Nevertheless, natural
alliances are emerging between certain of the more
tech-oriented civil society organisations (for example,
the Internet Society or the IEEE) and some Tier 1
carriers (i.e., those carriers that have a direct
connection to the Internet and the networks it uses to
deliver voice and data services), and major transnational
vendors and Internet Service Providers (ISPs).”
European Cybersecurity Implementation Series
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.