# Cybersecurity: Authoritative Reports and Resources, by Topic

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/crs%3AR42507

## Record

- **Collection:** Congressional research report
- **Document type:** CRS Report
- **Published:** June 10, 2015
- **Citation:** R42507

## Text

.

Cybersecurity: Authoritative Reports and
Resources, by Topic
Rita Tehan
Information Research Specialist
June 10, 2015

Congressional Research Service
7-5700
www.crs.gov
R42507

c11173008

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Summary
This report provides references to analytical reports on cybersecurity from CRS, other
government agencies, trade associations, and interest groups. The reports and related websites are
grouped under the following cybersecurity topics:
•
•
•
•
•
•
•
•
•

Policy overview
National Strategy for Trusted Identities in Cyberspace (NSTIC)
Cloud computing and the Federal Risk and Authorization Management Program
(FedRAMP)
Critical infrastructure
Cybercrime, data breaches, and data security
National security, cyber espionage, and cyberwar (including Stuxnet)
International efforts
Education/training/workforce
Research and development (R&D)

In addition, the report lists selected cybersecurity-related websites for congressional and
government agencies; news; international organizations; and other organizations, associations,
and institutions.

c11173008

Congressional Research Service

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Contents
CRS Reports, by Topic .................................................................................................................... 1
Cybersecurity Policy: CRS Reports and Other CRS Products .................................................. 1
Critical Infrastructure: CRS Reports ....................................................................................... 16
Cybercrime and Data Security: CRS Reports and Other CRS Products ................................. 34
Selected Reports, by Federal Agency ............................................................................................ 92
Department of Defense and National Security: CRS Reports and Other CRS Products ....... 109
CRS Product: Cybersecurity Framework .............................................................................. 116
Related Resources: Other Websites ............................................................................................. 138

Tables
Table 1. Cybersecurity Overview .................................................................................................... 2
Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC) ...................................... 8
Table 3. Cloud Computing, “The Internet of Things,” and FedRAMP ........................................ 10
Table 4. Critical Infrastructure ....................................................................................................... 17
Table 5. Cybercrime, Data Breaches, and Data Security ............................................................... 35
Table 6. National Security, Cyber Espionage, and Cyberwar ........................................................ 47
Table 7. International Efforts ......................................................................................................... 59
Table 8. Education/Training/Workforce......................................................................................... 77
Table 9. Research and Development (R&D) ................................................................................. 86
Table 10. Government Accountability Office (GAO) .................................................................... 92
Table 11. White House and Office of Management and Budget.................................................. 104
Table 12. Department of Defense (DOD) .................................................................................... 110
Table 13. National Institute of Standards and Technology (NIST) .............................................. 117
Table 14. Other Federal Agencies ................................................................................................ 122
Table 15. State, Local, and Tribal Governments .......................................................................... 134
Table 16. Related Resources: Congressional and Government ................................................... 138
Table 17. Related Resources: International Organizations .......................................................... 140
Table 18. Related Resources: News ............................................................................................. 141
Table 19. Related Resources: Other Associations and Institutions .............................................. 141

Contacts
Author Contact Information......................................................................................................... 143
Key Policy Staff ........................................................................................................................... 143

c11173008

Congressional Research Service

Cybersecurity: Authoritative Reports and Resources, by Topic

.

CRS Reports, by Topic1
This section provides references to analytical reports on cybersecurity from CRS, other
government agencies, think tanks, trade associations, trade press, and technology research firms.
For each topic, CRS reports are listed first, followed by tables with reports from other
organizations.

Cybersecurity Policy: CRS Reports and Other CRS Products
•
•
•
•
•
•
•
•
•

•
•
•

CRS Report R43831, Cybersecurity Issues and Challenges: In Brief, by Eric A.
Fischer
CRS Report IF10001, Cybersecurity Issues and Challenges, by Eric A. Fischer
CRS Report R42114, Federal Laws Relating to Cybersecurity: Overview of
Major Issues, Current Laws, and Proposed Legislation, by Eric A. Fischer
CRS Report R43941, Cybersecurity and Information Sharing: Legal Challenges
and Solutions, by Andrew Nolan
CRS Report R41941, The Obama Administration’s Cybersecurity Proposal:
Criminal Provisions, by Gina Stevens
CRS Report R42984, The 2013 Cybersecurity Executive Order: Overview and
Considerations for Congress, by Eric A. Fischer et al.
CRS Report R40150, A Federal Chief Technology Officer in the Obama
Administration: Options and Issues for Consideration, by John F. Sargent Jr.
CRS Report R42409, Cybersecurity: Selected Legal Issues, by Edward C. Liu et
al.
CRS Report R42887, Overview and Issues for Implementation of the Federal
Cloud Computing Initiative: Implications for Federal Information Technology
Reform Management, by Patricia Moloney Figliola and Eric A. Fischer
CRS Report R43015, Cloud Computing: Constitutional and Statutory Privacy
Protections, by Richard M. Thompson II
CRS Legal Sidebar WSLG478, House Intelligence Committee Marks Up
Cybersecurity Bill CISPA, by Richard M. Thompson II
CRS Legal Sidebar WSLG263, Can the President Deal with Cybersecurity Issues
via Executive Order?, by Vivian S. Chu

1

For information on legislation and hearings in the 112th and 113th Congresses, see CRS Report R43317,
Cybersecurity: Legislation, Hearings, and Executive Branch Documents, by Rita Tehan.

c11173008

Congressional Research Service

1

.

Table 1. Cybersecurity Overview
Title

Date

Pages

Notes

Cyber Threat Information Sharing:
Recommendations for Congress and the
Administration

Center for Strategic and
International Studies

March 10, 2015

18

The success of the president’s executive order
promoting cyberthreat information sharing depends on
legislation passing Congress. The report recommends
that legislation should not be one-size-fits-all; have a
minimal role for government; build on existing
information sharing; streamline mechanisms to share
info; add value for all parties participating; protect
information shared from FOIA requests, litigation or
regulatory enforcement; and protect organizations from
civil and criminal liability for monitoring and sharing on
cyberthreats if done in good faith.

The Emergence of Cybersecurity Law

Indiana University Maurer
School of Law

February 2015

31

This paper examines cyberlaw as a growing field of legal
practice and the roles that lawyers play in helping
companies respond to cybersecurity threats. Drawing on
interviews with lawyers, consultants, and academics
knowledgeable in the intersection of law and
cybersecurity, as well as a survey of lawyers working in
general counsel’s offices, this study examines the broader
context of cybersecurity, the current legal framework for
data security and related issues, and the ways in which
lawyers learn about and involve themselves in
cybersecurity issues.

OMG Cyber! Thirteen Reasons Why Hype
Makes for Bad Policy

The RUSI Journal

November 4, 2014

8

The article argues that cyber is “hyped out.” Overstating
the threat does have benefits (for some); it also comes
with significant costs. The benefits are short-lived and
easy to spot, whereas the costs are long-term and harder
to understand—and they are piling up fast and high.
Indeed, the costs are so high that the debate inches
toward a turning point for all parties involved. The
authors list 13 reasons why cybersecurity hype is
counterproductive.

CRS-2
c11173008

Source

.

Title

Source

Date

Pages

Ten Strategies of a World-Class Cybersecurity
Operations Center

MITRE Corporation

October 2014

346

All too often, cybersecurity operations centers (CSOCs)
are set up and operate with a focus on technology
without adequately addressing people and process issues.
The main premise of this book is that a more balanced
approach would be more effective. The book describes
the 10 strategies of effective CSOCs—regardless of their
size, offered capabilities, or type of constituency served
cost.

How Do We Know What Information Sharing
Is Really Worth? Exploring Methodologies to
Measure the Value of Information Sharing and
Fusion Efforts

RAND Corporation

June 27, 2014

33

Since the terrorist attacks of September 11, 2001, the
sharing of intelligence and law enforcement information
has been a central part of U.S. domestic security efforts.
Although much of the public debate about such sharing
focuses on addressing the threat of terrorism,
organizations at all levels of government routinely share
varied types of information through multiagency
information systems, collaborative groups, and other
links. Resource constraints have given rise to concerns
about the effectiveness of information sharing and fusion
activities and, therefore, the value of these efforts
relative to the public funds invested in them. Solid
methods for evaluating these efforts are lacking,
however, limiting the ability to make informed policy
decisions. Drawing on a substantial literature review and
synthesis, this report lays out the challenges of evaluating
information-sharing efforts that frequently seek to
achieve multiple goals simultaneously; reviews past
evaluations of information-sharing programs; and lays out
a path to improve the evaluation of such efforts going
forward.

Defending an Open, Global, Secure, and
Resilient Internet

Council on Foreign Relations

June 2013

127

The task force recommends that the United States
develop a digital policy framework based on four pillars,
the last of which is that U.S.-based industry work rapidly
to establish an industry-led approach to counter current
and future cyberattacks.

CRS-3
c11173008

Notes

.

Title

Source

Measuring What Matters: Reducing Risk by
Rethinking How We Evaluate Cybersecurity

Safegov.org, in coordination
with the National Academy of
Public Administration

March 2013

39

This report recommends that rather than periodically
auditing whether an agency’s systems meet the standards
enumerated in the Federal Information Security
Management Act (FISMA) at a static moment in time,
agencies and their inspectors general should keep
running scorecards of “cyber risk indicators” based on
continual inspector general assessments of a federal
organization’s cyber vulnerabilities.

Developing a Framework to Improve Critical
Infrastructure Cybersecurity (Federal Register
Notice; Request for Information)

National Institute of Standards
and Technology (NIST)

February 12, 2013

5

NIST announced the first step in the development of a
cybersecurity framework, which will be a set of voluntary
standards and best practices to guide industry in reducing
cyber risks to the networks and computers that are vital
to the nation’s economy, security, and daily life.

SEI [Software Engineering Institute] Emerging
Technology Center: Cyber Intelligence
Tradecraft Project

Carnegie Mellon University

January 2013

23

This report addresses the endemic problem of functional
cyber intelligence analysts not effectively communicating
with nontechnical audiences. It also notes organizations’
reluctance to share information within their own entities,
industries, and across economic sectors.

The National Cyber Security Framework
Manual

NATO Cooperative Cyber
Defense Center of Excellence

December 11, 2012

253

This report provides detailed background information
and in-depth theoretical frameworks to help the reader
understand the various facets of national cybersecurity,
according to different levels of public policy formulation.
The four levels of government—political, strategic,
operational, and tactical/technical—each have their own
perspectives on national cybersecurity, and each is
addressed in individual sections within the manual.

20 Critical Security Controls for Effective
Cyber Defense

Center for Strategic and
International Studies (CSIS)

November 2012

89

The top 20 security controls from a public-private
consortium. Members of the consortium include the
National Security Agency, U.S. Computer Emergency
Readiness Team, Department of Defense (DOD) Joint
Task Force-Global Network Operations, Department of
Energy Nuclear Laboratories, Department of State, and
DOD Cyber Crime Center plus commercial forensics
experts in the banking and critical infrastructure
communities.

CRS-4
c11173008

Date

Pages

Notes

.

Title

Date

Pages

Notes

Cyber Security Task Force: Public-Private
Information Sharing

Bipartisan Policy Center

July 2012

24

Outlines a series of proposals that would enhance
information sharing. The recommendations have two
major components: (1) mitigating perceived legal
impediments to information sharing, and (2) incentivizing
private sector information sharing by alleviating statutory
and regulatory obstacles.

Cyber-security: The Vexed Question of Global
Rules

McAfee and the Security
Defense Agenda

February 2012

108

This independent report examines the current state of
cyber-preparedness around the world and is based on
survey results from 80 policymakers and cybersecurity
experts in the government, business, and academic
sectors from 27 countries. The countries were ranked
on their state of cyber-preparedness.

Mission Critical: A Public-Private Strategy for
Effective Cybersecurity

Business Roundtable

October 11, 2011

28

The report suggests that “[p]ublic policy solutions must
recognize the absolute importance of leveraging policy
foundations that support effective global risk
management, in contrast to ‘check-the-box’ compliance
approaches that can undermine security and
cooperation.” The document concludes with specific
policy proposals and activity commitments.

World Cybersecurity Technology Research
Summit (Belfast 2011)

Centre for Secure Information
Technologies (CSIT)

September 12, 2011

14

The Belfast 2011 event attracted international
cybersecurity experts from leading research institutes,
government bodies, and industry who gathered to
discuss current cybersecurity threats, predict future
threats and necessary mitigation techniques, and develop
a collective strategy for further research.

A Review of Frequently Used Cyber Analogies

National Security Cyberspace
Institute

July 22, 2011

7

From the report: “The current cybersecurity crisis can
be described several ways with numerous metaphors.
Many compare the current crisis with the lawlessness to
that of the Wild West and the out-dated tactics and race
to security with the Cold War. When treated as a
distressed ecosystem, the work of both national and
international agencies to eradicate many infectious
diseases serves as a model as how poor health can be
corrected with proper resources and execution. Before
these issues are discussed, what cyberspace actually is
must be identified.”

CRS-5
c11173008

Source

.

Title

Date

Pages

Notes

America’s Cyber Future: Security and
Prosperity in the Information Age

Center for a New American
Security

May 31, 2011

296

To help U.S. policymakers address the growing danger of
cyber insecurity, this two-volume report features
chapters on cybersecurity strategy, policy, and
technology by some of the world’s leading experts on
international relations, national security, and information
technology.

Resilience of the Internet Interconnection
Ecosystem

European Network and
Information Security Agency
(ENISA)

April 11, 2011

238

This study consists of several parts. Part I provides a
summary and recommendations. Part II: State of the Art
Review offers a detailed description of the Internet’s
routing mechanisms and an analysis of their robustness at
the technical, economic, and policy levels. Part III: Report
on the Consultation reports and summarizes the results
of consultation with a broad range of stakeholders. Part
IV includes the bibliography and appendices.

Improving our Nation’s Cybersecurity through
the Public-Private Partnership: A White Paper

Business Software Alliance,
Center for Democracy and
Technology, U.S. Chamber of
Commerce, Internet Security
Alliance, and Tech America

March 8, 2011

26

This paper proposes expanding the existing partnership
within the framework of the National Infrastructure
Protection Plan. Specifically, it makes a series of
recommendations that build upon the conclusions of
President Obama’s Cyberspace Policy Review.

Cybersecurity Two Years Later

CSIS Commission on
Cybersecurity for the 44th
Presidency

January 2011

22

From the report: “We thought then [in 2008] that
securing cyberspace had become a critical challenge for
national security, which our nation was not prepared to
meet.... In our view, we are still not prepared.”

Toward Better Usability, Security, and Privacy
of Information Technology: Report of a
Workshop

National Research Council
(NRC)

September 21, 2010

70

The report discusses computer system security and
privacy, their relationship to usability, and research at
their intersection. It is drawn from remarks made at the
NRC’s July 2009 Workshop on Usability, Security and
Privacy of Computer Systems as well as reports from the
NRC’s Computer Science and Telecommunications
Board on security and privacy.

CRS-6
c11173008

Source

.

Title
National Security Threats in Cyberspace

Source

Date

Pages

Joint Workshop of the
National Security Threats in
Cyberspace and the National
Strategy Forum

September 15, 2009

37

Source: Highlights compiled by the Congressional Research Service (CRS) from the reports.

CRS-7
c11173008

Notes
The two-day workshop brought together more than two
dozen experts with diverse backgrounds, including
physicists; telecommunications executives; Silicon Valley
entrepreneurs; federal law enforcement, military,
homeland security, and intelligence officials;
congressional staffers; and civil liberties advocates.
Participants engaged in an open-ended discussion of
cyber policy as it relates to national security, under
Chatham House Rules: their comments were for the
public record, but they were not for attribution.

.

Table 2. National Strategy for Trusted Identities in Cyberspace (NSTIC)
Title

Date

Pages

Notes

National Strategy for Trusted Identities in Cyberspace
(NSTIC)

National
Institute of
Standards
and
Technology
(NIST)

Ongoing

N/A

The NSTIC pilot projects seek to catalyze a marketplace of
online identity solutions that ensures the envisioned Identity
Ecosystem is trustworthy and has the confidence of individuals.
Using privacy-enhancing architectures in real-world
environments, the pilots are testing new methods for
identification online for consumers that increase usability,
security, and interoperability to safeguard online transactions.

Identity Ecosystem Framework Steering Group (IDESG)

IDESG

Ongoing

N/A

The NSTIC called for the establishment of a private sector-led
steering group to administer the development and adoption of
the Identity Ecosystem Framework: the IDESG. The IDESG
receives its authority to operate from the active participation of
its membership in accordance with the rules of association that
follow. The IDESG has been initiated with the support of the
NIST. Following an initial period, the IDESG will transition to a
self-sustaining organization.

NSTIC Pilots: Catalyzing the Identity Ecosystem

NIST

April 2015

68

Since 2012, the NSTIC has awarded approximately $30 million
to pilot projects for shaping the identity ecosystem (a system
for consumers to create online identities). The study finds
common themes, including: the opportunity for increased
revenue, emerging identities architecture, and standards and
interoperability.

NIST Announces Pilot Grants Competition to Improve
Security and Privacy of Online Identity Verification
Systems

NIST

February 12,
2015

N/A

NIST announces a fourth round of grants meant to create
market conditions for a post-password world. The agency says
it anticipates funding several projects with awards of
approximately $1 million to $2 million over two years through
its NSTIC program. Administration officials say the NSTIC end
goal is creation of an “identity ecosystem” that allows
Americans to safely conduct online transactions under a variety
of security and privacy settings.

NIST Awards Grants to Improve Online Security and
Privacy

NIST

September 17,
2013

N/A

NIST announced more than $7 million in grants to support the
NSTIC. The funding will enable five U.S. organizations to
develop pilot identity protection and verification systems that
offer consumers more privacy, security, and convenience online.

CRS-8
c11173008

Source

.

Title

Source

Date

Pages

Notes

Five Pilot Projects Receive Grants to Promote Online
Security and Privacy

NIST

September 20,
2012

N/A

NIST announced more than $9 million in grant awards to
support the NSTIC. Five U.S. organizations will pilot identity
solutions that increase confidence in online transactions,
prevent identity theft, and provide individuals with more control
over how they share their personal information.

Recommendations for Establishing an Identity Ecosystem
Governance Structure

NIST

February 17,
2012

51

NIST responds to comments received in response to the
related notice of inquiry (NOI) published in the Federal Register
on June 14, 2011. This report summarizes the responses to the
NOI and provides recommendations and intended government
actions to serve as a catalyst for establishing such a governance
structure. The recommendations result from comments and
suggestions by the NOI respondents as well as best practices
and lessons learned from similarly scoped governance efforts.

Models for a Governance Structure for the National
Strategy for Trusted Identities in Cyberspace

NIST

June 14, 2011

4

The department seeks public comment on potential models
from all stakeholders, including the commercial, academic and
civil society sectors, and consumer and privacy advocates, in the
form of recommendations and key assumptions in the formation
and structure of the steering group.

Administration Releases Strategy to Protect Online
Consumers and Support Innovation and Fact Sheet on
National Strategy for Trusted Identities in Cyberspace

White
House

April 15, 2011

N/A

Press release on a proposal to administer the processes for
policy and standards adoption for the Identity Ecosystem
Framework in accordance with the NSTIC.

National Strategy for Trusted Identities in Cyberspace

White
House

April 15, 2011

52

The NSTIC aims to make online transactions more trustworthy,
thereby giving businesses and consumers more confidence in
conducting business online.

National Strategy for Trusted Identities in Cyberspace:
Creating Options for Enhanced Online Security and Privacy

White
House

June 25, 2010

39

The NSTIC, which is in response to one of the near-term action
items in the President’s Cyberspace Policy Review, calls for the
creation of an online environment, or an identity ecosystem, in
which individuals and organizations can complete online
transactions with confidence, trusting the identities of each
other and of the infrastructure in which transactions occur.

Source: Highlights compiled by CRS from the reports.

CRS-9
c11173008

.

Table 3. Cloud Computing, “The Internet of Things,”
and FedRAMP
Title

Date

About FedRAMP

General Services
Administration (GSA)

Ongoing

Formation of the Office of Technology Research and
Investigation (OTRI)

Federal Trade Commission
(FTC)

March 23, 2015

Insecurity in the Internet of Things (IoT)

Symantec

March 12, 2015

CRS-10
c11173008

Source

Pages

Notes

N/A

The Federal Risk and Authorization Management
Program (FedRAMP) is a government-wide program
that provides a standardized approach to security
assessment, authorization, and continuous monitoring
for cloud products and services.
The OTRI will provide expert research, investigative
techniques, and further insights to the agency on
technology issues involving all facets of the FTC’s
consumer protection mission, including privacy, data
security, connected cars, smart homes, algorithmic
transparency, emerging payment methods, big data,
and the Internet of Things.
Like the former Mobile Technology Unit (MTU), the
new office will be housed in the Bureau of Consumer
Protection and is the agency’s latest effort to ensure
that its core consumer protection mission keeps
pace with the rapidly evolving digital economy.
Kristin Cohen, the current chief of the MTU, will lead
the work of the OTRI.

20

Symantec analyzed 50 smart home devices that are
available today and found that none of the devices
enforced strong passwords, used mutual
authentication, or protected accounts against bruteforce attacks. Almost 2 out of 10 of the mobile apps
used to control the tested IoT devices did not use
Secure Sockets Layer (SSL) to encrypt
communications to the cloud. The tested IoT
technology also contained many common
vulnerabilities.

.

Title

Date

Pages

Notes

FedRAMP High Baseline

GSA

February 3,
2015

N/A

GSA released a draft of security controls it will
require for cloud-computer systems purchased by
federal agencies for “high-impact” uses. High-impact
data will likely consist of health and law-enforcement
data, but not classified information. Cloud computing
vendors seeking to sell to federal agencies currently
must get security accreditation through FedRAMP.
To date, FedRAMP has offered accreditations up to
the “moderate-impact” level. About 80% of federal IT
systems are low- and moderate-impact.

What is The Internet of Things?
(free; registration required)

O’Reilly Media

January 2015

32

Ubiquitous connectivity is meeting the era of data.
Since working with large quantities of data became
dramatically cheaper and easier a few years ago,
everything that touches software has become
instrumented and optimized. Finance, advertising,
retail, logistics, academia, and practically every other
discipline has sought to measure, model, and tweak
its way to efficiency. Software can ingest data from
lots of inputs, interpret it, and then issue commands
in real time.

FedRAMP Forward: 2 Year Priorities

GSA

December 17,
2014

14

The report addresses how the program will develop
over the next two years. GSA is focusing on three
goals for FedRAMP: increased compliance and agency
participation, improved efficiencies, and continued
adaptation.

The Internet of Things: 2014 OECD Tech Insight Forum

OECD

December 11,
2014

N/A

The Internet of Things extends internet connectivity
beyond traditional machines like computers,
smartphones and tablets to a diverse range of everyday devices that use embedded technology to
interact with the environment, all via the Internet.
How can this collected data be used? What new
opportunities will this create for employment and
economic growth? How can societies benefit from
technical developments to health, transport, safety
and security, business and public services? The
OECD Technology Foresight Forum facilitated
discussion on what policies and practices will enable
or inhibit the ability of economies to seize the
benefits of the Internet of Things.

CRS-11
c11173008

Source

.

Title

Source

DOD Cloud Computing Strategy Needs Implementation
Plan and Detailed Waiver Process

Department of Defense
(DOD) Inspector General

NSTAC Report to the President on the Internet of
Things

Pages

Notes

December 4,
2014

40

Report states that the DOD chief information officer
“did not develop an implementation plan that
assigned roles and responsibilities as well as
associated tasks, resources and milestones,” despite
promises that an implementation plan would directly
follow the cloud strategy’s release.

President's National
Security
Telecommunications
Advisory Committee

November 18,
2014

56

The NSTAC unanimously approved a
recommendation that governmental Internet traffic
could get priority transmission during emergencies.
The government already gets emergency priority in
more traditional communications networks like the
‘phone system through programs such as the
Government Emergency Telecommunications Service
— now NSTAC is proposing a GETS for the Internet.

The Department of Energy’s Management of Cloud
Computing Activities: Audit Report

Department of Energy
(DOE) Inspector General

September 1,
2014

20

DOE should do a better job buying, implementing
and managing its cloud computing services. Programs
and sites department-wide have independently spent
more than $30 million on cloud services, the
inspector general report said, but the chief
information officer’s office could not accurately
account for the money.

Cloud Computing: The Concept, Impacts, and the Role
of Government Policy

Organization for Economic
Co-operation and
Development (OECD)

August 19, 2014

240

This report gives a clear overview of cloud
computing, presenting the concept, the services it
provides, and deployment models. It provides an
overview of how cloud computing changes the way
computing is carried out and evaluates the impacts of
cloud computing (including its benefits and challenges
as well as its economic and environmental impacts).
Finally, the report discusses the policy issues raised
by cloud computing and the role of governments and
other stakeholders in addressing these issues.

Internet of things: the influence of M2M data on the
energy industry

GigaOm Research

March 4, 2014

21

This report examines the drivers of machine-2machine (M2M)-data exploitation in the smart-grid
sector and the oil and gas sector, as well as the risks
and opportunities for buyers and suppliers of the
related core technologies and services.

CRS-12
c11173008

Date

.

Title

Date

Pages

Notes

Software Defined Perimeter

Cloud Security Alliance

December 1,
2013

13

The Software Defined Perimeter (SDP) initiative by
the Cloud Security Alliance aims to make “invisible
networks” accessible to a wider range of government
agencies and corporations. The initiative will foster
development of an architecture for securing the
“Internet of Things” by using the cloud to create
highly secure end-to-end networks between any IPaddressable entities.

Delivering on the Promise of Big Data and the Cloud

Booz Allen Hamilton

January 9, 2013

7

From the report: “Reference architecture does away
with conventional data and analytics silos,
consolidating all information into a single medium
designed to foster connections called a ‘data lake,’
which reduces complexity and creates efficiencies
that improve data visualization to allow for easier
insights by analysts.”

Cloud Computing: An Overview of the Technology and
the Issues facing American Innovators

House Judiciary
Committee, Subcommittee
on Intellectual Property,
Competition, and the
Internet

July 25, 2012

156

Overview and discussion of cloud computing issues.

Information Technology Reform: Progress Made but
Future Cloud Computing Efforts Should be Better
Planned

Government
Accountability Office
(GAO)

July 11, 2012

43

GAO recommends that the Secretaries of
Agriculture, Health and Human Services, Homeland
Security, State, and the Treasury, and the
Administrators of the General Services
Administration (GSA) and Small Business
Administration should direct their respective chief
information officers to establish estimated costs,
performance goals, and plans to retire associated
legacy systems for each cloud-based service discussed
in this report, as applicable.

Cloud Computing Strategy

DOD Chief Information
Officer

July 2012

44

The DOD Cloud Computing Strategy introduces an
approach to move the department from the current
state of a duplicative, cumbersome, and costly set of
application silos to an end state that is agile, secure,
and cost-effective and to a service environment that
can rapidly respond to changing mission needs.

A Global Reality: Governmental Access to Data in the
Cloud—A Comparative Analysis of Ten International
Jurisdictions

Hogan Lovells

May 23, 2012

13

This white paper compares the nature and extent of
governmental access to data in the cloud in many
jurisdictions around the world.

CRS-13
c11173008

Source

.

Title

Date

Pages

Notes

Policy Challenges of Cross-Border Cloud Computing

U.S. International Trade
Commission

May 2012

38

This report examines the main policy challenges
associated with cross-border cloud computing—data
privacy, security, and ensuring the free flow of
information—and the ways countries are addressing
them through domestic policymaking, international
agreements, and other cooperative arrangements.

Cloud Computing Synopsis and Recommendations (SP
800-146)

National Institute of
Standards and Technology
(NIST)

May 2012

81

NIST’s guide explains cloud technologies in plain
terms to federal agencies and provides
recommendations for IT decision makers.

Global Cloud Computing Scorecard a Blueprint for
Economic Opportunity

Business Software Alliance

February 2,
2012

24

This report notes that although many developed
countries have adjusted their laws and regulations to
address cloud computing, the wide differences in
those rules make it difficult for companies to invest in
the technology.

Concept of Operations: FedRAMP

GSA

February 7,
2012

47

Implementation of FedRAMP will be in phases. This
document describes all the services that will be
available at initial operating capability, targeted for
June 2012. The concept of operations will be updated
as the program evolves toward sustained operations.

Federal Risk and Authorization Management Program
(FedRAMP)

Federal Chief Information
Officers Council

January 4, 2012

N/A

FedRAMP has been established to provide a standard
approach to assessing and authorizing (A&A) cloud
computing services and products.

Security Authorization of Information Systems in Cloud
Computing Environments (FedRAMP)

White House/Office of
Management and Budget
(OMB)

December 8,
2011

7

FedRAMP will now be required for all agencies
purchasing storage, applications, and other remote
services from vendors. The Administration promotes
cloud computing as a means to save money and
accelerate the government’s adoption of new
technologies.

U.S. Government Cloud Computing Technology
Roadmap, Volume I, Release 1.0 (Draft). High-Priority
Requirements to Further USG Agency Cloud Computing
Adoption (SP 500-293)

NIST

December 1,
2011

32

Volume I is aimed at interested parties that wish to
gain a general understanding and overview of the
background, purpose, context, work, results, and
next steps of the U.S. Government Cloud Computing
Technology Roadmap initiative.

CRS-14
c11173008

Source

.

Title

Source

Date

Pages

Notes

U.S. Government Cloud Computing Technology
Roadmap, Volume II, Release 1.0 (Draft), Useful
Information for Cloud Adopters (SP 500-293)

NIST

December 1,
2011

85

Volume II is designed as a technical reference for
those actively working on strategic and tactical cloud
computing initiatives including, but not limited to,
U.S. government cloud adopters. This volume
integrates and summarizes the work completed to
date and explains how these findings support the
roadmap introduced in Volume I.

Information Security: Additional Guidance Needed to
Address Cloud Computing Concerns

GAO

October 6,
2011

17

Twenty-two of 24 major federal agencies reported
that they were either concerned or very concerned
about the potential information security risks
associated with cloud computing. GAO
recommended that the NIST issue guidance specific
to cloud computing security.

Cloud Computing Reference Architecture (SP 500-292)

NIST

September 1,
2011

35

This special publication, which is not an official U.S.
government standard, is designed to provide guidance
to specific communities of practitioners and
researchers.

Guide to Cloud Computing for Policy Makers

Software and Information
Industry Association (SAII)

July 26, 2011

27

The SAII concludes that “there is no need for cloudspecific legislation or regulations to provide for the
safe and rapid growth of cloud computing, and in fact,
such actions could impede the great potential of
cloud computing.”

Federal Cloud Computing Strategy

White House

February 13,
2011

43

The strategy outlines how the federal government
can accelerate the safe, secure adoption of cloud
computing and provides agencies with a framework
for migrating to the cloud. It also examines how
agencies can address challenges related to the
adoption of cloud computing, such as privacy,
procurement, standards, and governance.

25 Point Implementation Plan to Reform Federal
Information Technology Management

White House

December 9,
2010

40

The plan’s goals are to reduce the number of
federally run data centers from 2,100 to
approximately 1,300; rectify or cancel one-third of
troubled IT projects, and require federal agencies to
adopt a “cloud first” strategy in which they will move
at least one system to a hosted environment within a
year.

Source: Highlights compiled by CRS from the reports.
Note: These reports analyze cybersecurity issues related to the federal government’s adoption of cloud computing storage options.
CRS-15
c11173008

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Critical Infrastructure: CRS Reports
•
•
•
•
•
•
•

•
•

c11173008

CRS Report R42683, Critical Infrastructure Resilience: The Evolution of Policy and
Programs and Issues for Congress, by John D. Moteff
CRS Report RL30153, Critical Infrastructures: Background, Policy, and Implementation,
by John D. Moteff
CRS Report R42660, Pipeline Cybersecurity: Federal Policy, by Paul W. Parfomak
CRS Report R41536, Keeping America’s Pipelines Safe and Secure: Key Issues for
Congress, by Paul W. Parfomak
CRS Report R41886, The Smart Grid and Cybersecurity—Regulatory Policy and Issues,
by Richard J. Campbell
CRS Report R42338, Smart Meter Data: Privacy and Cybersecurity, by Brandon J.
Murrill, Edward C. Liu, and Richard M. Thompson II
CRS Report RL33586, The Federal Networking and Information Technology Research
and Development Program: Background, Funding, and Activities, by Patricia Moloney
Figliola
CRS Report 97-868, Internet Domain Names: Background and Policy Issues, by Lennard
G. Kruger
CRS Report IN10027, Open-Source Software and Cybersecurity: The Heartbleed Bug, by
Eric A. Fischer, Catherine A. Theohary, and John W. Rollins

Congressional Research Service

16

.

Table 4. Critical Infrastructure
Title

Date

Pages

Notes

HHS Breach Portal: Breaches Affecting 500 or More
Individuals

Health and Human
Services (HHS)

Ongoing

Cybersecurity for Energy Delivery Systems Program
(CEDS)

Department of
Energy (DOE),
Office of Electricity
Delivery and
Energy Reliability

Ongoing

N/A

The program assists the energy sector asset owners (electric,
oil, and gas) by developing cybersecurity solutions for energy
delivery systems through integrated planning and a focused
research and development effort. CEDS co-funds projects with
industry partners to make advances in cybersecurity capabilities
for energy delivery systems.

Cybersecurity Capability Maturity Model (C2M2)

DOE Office of
Electricity Delivery
and Energy
Reliability

Ongoing

N/A

The model was developed by the DOE and industry as a
cybersecurity control evaluation and improvement management
tool for energy sector firms. It tells adherents how to assess and
grade adoption of cybersecurity practices.

GridEx

North American
Electric Reliability
Corporation
(NERC)

Ongoing

N/A

The objectives of the NERC Grid Security Exercise (GridEx)
series are to use simulated scenarios (with no real-world effects)
to exercise the current readiness of participating electricity
subsector entities to respond to cyber- or physical security
incidents and provide input for security program improvements
to the bulk power system. GridEx is a biennial international grid
security exercise that uses best practices and other
contributions from the Department of Homeland Security, the
Federal Emergency Management Agency, and the National
Institute of Standards and Technology.

CRS-17
c11173008

Source

As required by Section 13402(e)(4) of the HITECH Act, the
Secretary must post a list of breaches of unsecured protected
health information affecting 500 or more individuals. These
breaches are now posted in a new, more accessible format that
allows users to search and sort the posted breaches.
Additionally, this new format includes brief summaries of the
breach cases that OCR has investigated and closed, as well as
the names of private practice providers who have reported
breaches of unsecured protected health information to the
Secretary.

.

Title

Date

Pages

Notes

ICBA Data Breach Toolkit

Independent
Community
Bankers of America

Ongoing

N/A

ICBA and Visa have teamed up to bring a special
communications toolkit to community banks. This
comprehensive communications guide gives community banks
the means of communicating with card customers and the media
within 24 hours of a data compromise. Having this contingency
plan in place can make all the difference in a data breach
episode. The toolkit Includes a brochure on communications
best practices following a data breach and customizable template
materials, such as cardholder letters, statement inserts, FAQs,
and media statements.

Appendix J: Strengthening the Resilience of Outsourced
Technology Services

Federal Financial
Institutions
Examination
Council (FFIEC)

Ongoing

N/A

The increasing sophistication and volume of cyber threats and
their ability to disrupt operations or corrupt data can affect the
business resilience of financial institutions and technology service
providers (TSPs). Financial institutions and their TSPs need to
incorporate the potential impact of a cyber event into their
business continuity planning (BCP) process and ensure
appropriate resilience capabilities are in place. The changing
cyber threat landscape may include risks that must be managed
to achieve resilience.

Cybersecurity Risk Management and Best Practices
(WG4): Cybersecurity Framework for the
Communications Sector

Federal
Communications
Commission,
Communications
Security, Reliability
and Interoperability
Council (CSRIC)

March 18,
2015

415

The CSRIC is a federal advisory committee that provides
recommendations to the FCC regarding best practices and
actions the commission can take to help ensure security,
reliability, and interoperability of communications systems and
infrastructure. The CSRIC approved a report that identifies best
practices, provides a variety of important tools and resources
for communications companies of different sizes and types to
manage cybersecurity risks, and recommends a path forward.

Tracking & Hacking: Security & Privacy Gaps Put
American Drivers at Risk

Senator Edward
Markey

February 11,
2015

14

Nearly all modern vehicles have some sort of wireless
connection that hackers could potentially use to gain access to
their critical systems. The company’s protections on those
connections are “inconsistent and haphazard” across the
industry. In addition to security weaknesses, the report also
found that many auto companies are collecting detailed location
data from cars and often transmitting it insecurely.

CRS-18
c11173008

Source

.

Title

Date

Pages

Notes

Senators Alexander, Murray Announce Oversight
Initiative on Security of Health IT

Senate Committee
on Labor, Health,
Education and
Pensions

February 6,
2015

N/A

U.S. Senate health committee Chairman Lamar Alexander (RTenn.) and Ranking Member Patty Murray (D-Wash.) today
announced a bipartisan initiative focused on examining the
security of health information technology and the health
industry’s preparedness for cyber threats. The goal of the
Alexander-Murray initiative is to examine whether Congress can
help ensure the safety of health information technology,
including electronic health records, hospital networks, insurance
records, and network-connected medical devices, like
pacemakers and continuous glucose monitors. Begun last month,
the ongoing staff meetings will include participants from relevant
government oversight agencies, independent cybersecurity
experts, health industry leaders, and others.

Report on Cybersecurity Practices

Financial Industry
Regulatory
Authority

February 2015

46

The report presents an approach to cybersecurity grounded in
risk management to address these threats. It identifies principles
and effective practices for firms to consider, while recognizing
that there is no one-size-fits-all approach to cybersecurity.

Incident Response/Vulnerability Coordination in 2014

ICS/CERT Monitor

September
2014-February
2015

15

In FY2014, the Industrial Control Systems Cyber Emergency
Response Team (ICS-CERT) received and responded to 245
incidents reported by asset owners and industry partners. The
Energy Sector led all others again in 2014 with the most
reported incidents. ICS-CERT’s continuing partnership with the
Energy Sector provides many opportunities to share information
and collaborate on incident response efforts. In addition, in 2014
the Critical Manufacturing Sector reported incidents, some of
which were from control systems equipment manufacturers.

Guidance on Maritime Cybersecurity Standards (Federal
Register Notice of Public Meeting and Request for
Comments)

U.S. Coast Guard

December 12,
2014

2

From the summary: “The U.S. Coast Guard announces a public
meeting to be held in Washington, DC, to receive comments on
the development of cybersecurity assessment methods for
vessels and facilities regulated by the Coast Guard. This meeting
will provide an opportunity for the public to comment on
development of security assessment methods that assist vessel
and facility owners and operators identify and address
cybersecurity vulnerabilities that could cause or contribute to a
Transportation Security Incident. The Coast Guard will consider
these public comments in developing relevant guidance, which
may include standards, guidelines, and best practices to protect
maritime critical infrastructure.”

CRS-19
c11173008

Source

.

Title

Date

Pages

Notes

Federal Financial Institutions Examination Council (FFIEC)
Cybersecurity Assessment: General Observations

FFIEC

November 3,
2014

Inquiry into Cyber Intrusions Affecting U.S.
Transportation Command Contractors

Senate Armed
Services
Committee

September 17,
2014

Critical Infrastructure Protection: DHS [Department of
Homeland Security] Action Needed to Enhance
Integration and Coordination of Vulnerability Assessment
Efforts

Government
Accountability
Office (GAO)

September 15,
2014

82

DHS used 10 different assessment tools and methods from
FY2011 through FY2013 to assess critical infrastructure
vulnerabilities. Four of the 10 assessments did not include
cybersecurity. The differences in the assessment tools and
methods mean DHS is not positioned to integrate its findings in
identifying priorities.

Energy Sector Cybersecurity Framework Implementation
Guidance: Draft For Public Comment and Comment
Submission Form

DOE Office of
Electricity Delivery
and Energy
Reliability

September 12,
2014

N/A

Energy companies need not make a choice between the National
Institute of Standards and Technology (NIST) cybersecurity
framework and the DOE’s C2M2. The NIST framework tells
organizations to grade themselves on a four-tier scale based on
their overall cybersecurity program sophistication. C2M2 tells
users to assess cybersecurity control implementation across 10
domains of cybersecurity practices, such as situational
awareness, according to their specific “maturity indicator level.”

CRS-20
c11173008

Source

Companies are critically dependent on IT. Financial companies
should routinely scan IT networks for vulnerabilities and
anomalous activity and test systems for their potential exposure
to cyberattacks. The study recommends sharing threat data
through such avenues as the Financial Services Information
Sharing and Analysis Center.
52

Hackers associated with the Chinese government successfully
penetrated the computer systems of Transportation Command
(TRANSCOM) contractors 20 times in the course of a single
year. Chinese hackers tried to get into the systems 50 times.
The congressional committee found that only two of the
intrusions were detected. It also found that officials were
unaware due in large part to unclear requirements and methods
for contractors to report breaches and for government agencies
to share information.

.

Title

Date

Pages

Notes

Guidelines for Smart Grid Cybersecurity, Smart Grid
Cybersecurity Strategy, Architecture, and High-Level
Requirements (3 volumes)

NIST

September
2014

668

This three-volume report, Guidelines for Smart Grid
Cybersecurity, presents an analytical framework that
organizations can use to develop effective cybersecurity
strategies tailored to their particular combinations of smart gridrelated characteristics, risks, and vulnerabilities. Organizations in
the diverse community of smart grid stakeholders—from
utilities to providers of energy management services to
manufacturers of electric vehicles and charging stations—can use
the methods and supporting information presented in this
report as guidance for assessing risk and identifying and applying
appropriate security requirements. This approach recognizes
that the electric grid is changing from a relatively closed system
to a complex, highly interconnected environment. Each
organization’s cybersecurity requirements should evolve as
technology advances and as threats to grid security inevitably
multiply and diversify.

A Criticism of the Current Security, Privacy and
Accountability Issues in Electronic Health Records

International
Journal of Applied
Information
Systems

September
2014

8

Unless a different approach is used, the reliant on cryptography
and password or escrow based system for key management will
impede trust of the electronic health records (EHR) system and
hence its acceptability. In addition, users with right access should
also be monitored without affecting the clinician workflow. This
paper presents a detailed review of some selected recent
approaches to ensuring security, privacy, and accountability in
EHR and identifies gaps for future research.

Security in the New Mobile Ecosystem (Free registration
required.)

Ponemon Institute
and Raytheon

August 2014

30

Mobile devices are quickly becoming an integral tool for the
workforce, but the security practices and budgets in most
organizations are not keeping pace with the growing number of
devices that must be managed and kept secure.

Critical Infrastructure: Security Preparedness and
Maturity

Unisys and the
Ponemon Institute

July 2014

34

Unisys and the Ponemon Institute surveyed nearly 600 IT
security executives of utility, energy, and manufacturing
organizations. Overall, the report finds organizations are simply
not prepared to deal with advanced cyber threats. Only half of
companies have actually deployed IT security programs and,
according to the survey, the top threat actually stems from
negligent insiders.

CRS-21
c11173008

Source

.

Title

Source

Date

Pages

Notes

Securing the U.S. Electrical Grid: Understanding the
Threats to the Most Critical of Critical Infrastructure,
While Securing a Changing Grid

Center for the
Study of the
Presidency and
Congress

July 2014

180

From the report: “While [electrical grid] modernization entails
significant challenges in its own right, it also provides an
opportunity to ‘bake security in’—both in the hardware and
software controlling these systems and in the business models,
regulatory systems, financial incentives, and insurance structures
that govern the generation, transmission, and distribution of
electric power.… In this report and the aforementioned dozen
recommendations, we have sought to identify the immediate
action that can be taken by the White House, the Congress, and
the private sector to mitigate current threats to the electrical
grid.”

Maritime Critical Infrastructure Protection: DHS Needs
to Better Address Port Cybersecurity

GAO

June 5, 2014

54

GAO’s objective was to identify the extent to which DHS and
other stakeholders have taken steps to address cybersecurity in
the maritime port environment. GAO examined relevant laws
and regulations, analyzed federal cybersecurity-related policies
and plans, observed operations at three U.S. ports selected for
being high-risk ports and leaders in calls by vessel type (e.g.,
container), and interviewed federal and nonfederal officials.

Executive Leadership of Cybersecurity: What Today’s
CEO Needs To Know About the Threats They Don’t See

FFIEC

May 7, 2014

30

The FFIEC highlighted key focus areas for senior management
and boards of directors of community institutions as they assess
their institutions’ abilities to identify and mitigate cybersecurity
risks.

Sector Risks Snapshots

DHS

May 2014

52

DHS’s snapshots provide an introduction to the diverse array of
critical infrastructure sectors, touching on some of the key
threats and hazards concerning these sectors and highlighting
the common, first-order dependencies and interdependencies
between sectors.

Critical Infrastructure Protection Issues Identified in
Order No. 791

Federal Energy
Regulatory
Commission
(FERC)

April 24, 2014

N/A

FERC will hold a technical meeting on cybersecurity and
communications security standards for power generators.
Among other issues, the meeting will consider possible
disjunctures between FERC’s regulatory standards for grid
reliability and the new voluntary cybersecurity framework for
critical infrastructure that NIST rolled earlier this year.

CRS-22
c11173008

.

Title

Date

Pages

Notes

Notice of Completion of Notification of CyberDependent Infrastructure and Process for Requesting
Reconsideration of Determinations of Cyber Criticality

DHS Programs
Directorate

April 17, 2014

3

The Secretary of DHS has been directed to identify critical
infrastructure in which a cybersecurity incident could reasonably
result in catastrophic regional or national effects on public health
or safety, economic security, or national security. In addition to
identifying such infrastructure, the Secretary has also been
directed to confidentially notify owners and operators of critical
infrastructure identified and establish a mechanism through
which entities can request reconsideration of that identification,
whether inclusion or exclusion from this list. This notice informs
owners and operators of critical infrastructure that the
confidential notification process is complete and describes the
process for requesting reconsideration.

Cybersecurity Procurement Language for Energy Delivery
Systems

DOE Energy
Sector Control
Systems Working
Group

April 2014

46

This guidance suggests procurement strategies and contract
language to help U.S. energy companies and technology suppliers
build in cybersecurity protections during product design and
manufacturing. It was “developed through a public-private
working group including federal agencies and private industry
leaders.”

Benchmarking Trends: Interest in Cyber Insurance
Continues to Climb (Requires free registration to access.)

Marsh USA

March 31,
2014

4

As cyber incidents increased in frequency and severity in 2013,
the percentage of companies that purchased cyber insurance
rose by double digits (see figure 1 in the report). Early signs in
2014 indicate that the trend is not just continuing but
accelerating. Recent high-profile data breaches, growing boardlevel concern, and the increasing vulnerability of operations to
technology failure appear to be influencing purchasing decisions.

Wireless Emergency Alerts (WEA) Cybersecurity Risk
Management Strategy for Alert Originators

Carnegie
Mellon/Pittsburgh
Software Institute

March 2014

183

From the report: “The Wireless Emergency Alerts (WEA)
service depends on computer systems and networks to convey
potentially life-saving information to the public in a timely
manner. However, like other cyber-enabled services, it is
susceptible to risks that may enable attackers to disseminate
unauthorized alerts or to delay, modify, or destroy valid alerts.
Successful attacks may result in property destruction, financial
loss, injury, or death and may damage WEA credibility to the
extent that users ignore future alerts or disable alerting. This
report describes a four-stage cybersecurity risk management
(CSRM) strategy that alert originators can use throughout WEA
adoption, operations, and sustainment, as well as a set of
governance activities for developing a plan to execute the
CSRM.”

CRS-23
c11173008

Source

.

Title

Date

Pages

Notes

Cybersecurity and the North American Electric Grid:
New Policy Approaches to Address an Evolving Threat

Bipartisan Policy
Center

February 28,
2014

Framework for Improving Critical Infrastructure
Cybersecurity

NIST

February 12,
2014

41

The voluntary framework consists of cybersecurity standards
that can be customized to various sectors and adapted by both
large and small organizations. Additionally, so that the private
sector may fully adopt this framework, DHS announced the
Critical Infrastructure Cyber Community (C3)—or “C-cubed”—
Voluntary Program. The C3 program gives companies that
provide critical services such as cell phones, email, banking, and
energy and state and local governments direct access to
cybersecurity experts within DHS who have knowledge about
specific threats, ways to counter those threats, and how, over
the long term, to design and build systems that are less
vulnerable to cyber threats.

ITI Recommendations to the Department of Homeland
Security Regarding its Work Developing a Voluntary
Program Under Executive Order 163636, “Improving
Critical Infrastructure Cybersecurity.”

Information
Technology
Industry Council
(ITI)

February 11,
2014

3

ITI released a set of recommendations eying further
improvement of the framework, changes that call for DHS to
“de-emphasize the current focus on incentives.” Partly, ITI
recognizes the cyber order can produce change even in an
environment in which fiscal constraints and congressional
inaction stall carrots for adoption—but a bigger biz argument,
made in its report yesterday, is that ITI and others do not want
incentives if they come at the cost of “compliance-based
programs.”

CRS-24
c11173008

Source

The Bipartisan Policy Center’s initiative identifies urgent
priorities, including strengthening existing protections, enhancing
coordination at all levels, and accelerating the development of
robust protocols for response and recovery in the event of a
successful attack. The initiative developed recommendations in
four policy areas: standards and best practices, information
sharing, response to a cyberattack, and paying for cybersecurity.
The recommendations are targeted to Congress, federal
government agencies, state public utility commissions (PUCs),
and industry.

.

Title

Date

Pages

Notes

The Federal Government’s Track Record on
Cybersecurity and Critical Infrastructure

Senate Homeland
Security and
Governmental
Affairs Committee
(Minority Staff)

February 4,
2014

19

Since 2006, the federal government has spent at least $65 billion
on securing its computers and networks, according to an
estimate by the Congressional Research Service (CRS). NIST,
the government’s official body for setting cybersecurity
standards, has produced thousands of pages of precise guidance
on every significant aspect of IT security. And yet agencies—
even agencies with responsibilities for critical infrastructure or
vast repositories of sensitive data—continue to leave themselves
vulnerable, often by failing to take the most basic steps toward
securing their systems and information.

Electricity Subsector Cybersecurity Capability Maturity
Model (ES-C2M2) (Case Study)

Carnegie Mellon
University Software
Engineering
Institute

January 23,
2014

39

ES-C2M2 is a White House initiative, led by DOE in partnership
with the Department of Homeland Security and representatives
of electricity subsector asset owners and operators, to manage
dynamic threats to the electric grid. Its objectives are to
strengthen cybersecurity capabilities, enable consistent
evaluation and benchmarking of cybersecurity capabilities, and
share knowledge and best practices.

NIPP 2013: Partnering for Critical Infrastructure Security
and Resilience

DHS

2013

57

The National Infrastructure Protection Plan (NIPP) 2013 meets
the requirements of Presidential Policy Directive-21, “Critical
Infrastructure Security and Resilience,” signed in February 2013.
The plan was developed through a collaborative process
involving stakeholders from all 16 critical infrastructure sectors,
all 50 states, and all levels of government and industry. It
provides a clear call to action to leverage partnerships, innovate
for risk management, and focus on outcomes.

World Federation of Exchanges (WFE) Launches Global
Cyber Security Committee

WFE

December 12,
2013

N/A

The WFE announced the launch of the exchange industry’s first
cybersecurity committee with a mission to aid in the protection
of the global capital markets. The working group will bring
together representation from a number of exchanges and
clearinghouses across the globe to collaborate on best practices
in global security.

The Critical Infrastructure Gap: U.S. Port Facilities and
Cyber Vulnerabilities

Brookings
Institution/ Center
for 21st Century
Security and
Intelligence

July 2013

50

The study argues that the level of cybersecurity awareness and
culture in U.S. port facilities is relatively low and that a
cyberattack at a major U.S. port would quickly cause significant
damage to the economy.

FFIEC Forms Cybersecurity and Critical Infrastructure
Working Group

FFIEC

June 6, 2013

2

FFIEC formed a working group to further promote coordination
across federal and state banking regulatory agencies on critical
infrastructure and cybersecurity issues.

CRS-25
c11173008

Source

.

Title

Source

Date

Pages

Notes

Electric Grid Vulnerability: Industry Responses Reveal
Security Gaps

Representative
Edward Markey
and Representative
Henry Waxman

May 21, 2013

35

The report found that less than one-quarter of investor-owned
utilities and less than one-half of municipally and cooperatively
owned utilities followed through with voluntary standards issued
by the Federal Energy Regulatory Commission after the Stuxnet
worm struck in 2010.

Initial Analysis of Cybersecurity Framework RFI [Request
for Information] Responses

NIST

May 20, 2013

33

Comments on the challenges of protecting the nation’s critical
infrastructure have identified a handful of issues for the more
than 200 people and organizations that responded to a formal
RFI. NIST has released an initial analysis of 243 responses to the
Feb. 26 RFI. The analysis will form the basis for an upcoming
workshop at Carnegie Mellon University in Pittsburgh as NIST
moves forward on creating a cybersecurity framework for
essential energy, utility, and communications systems.

Joint Working Group on Improving Cybersecurity and
Resilience Through Acquisition, Notice of Request for
Information

General Services
Administration

May 13, 2013

3

Among other things, Presidential Policy Directive-21requires the
General Services Administration, in consultation with the
Department of Defense and DHS, to jointly provide and support
government-wide contracts for critical infrastructure systems
and ensure that such contracts include audit rights for the
security and resilience of critical infrastructure.

2013 Annual Report

Financial Stability
Oversight Council
(FSOC)

April 25, 2013

195

Under the Dodd-Frank Act, FSOC must report annually to
Congress on a range of issues, including significant financial
market and regulatory developments and potential emerging
threats to the financial stability of the United States. FSOC’s
recommendations address heightened risk management and
supervisory attention to operational risks, including
cybersecurity and infrastructure.

Version 5 Critical Infrastructure Protection Reliability
Standards (Notice of Proposed Rulemaking)

FERC

April 24, 2013

18

FERC proposes to approve the Version 5 Critical Infrastructure
Protection (CIP) Reliability Standards, CIP-002-5 through CIP011-1, submitted by the North American Electric Reliability
Corporation, the commission-certified Electric Reliability
Organization. The proposed reliability standards, which pertain
to the cybersecurity of the bulk electric system, represent an
improvement over the current commission-approved CIP
Reliability Standards as they adopt new cybersecurity controls
and extend the scope of the systems that are protected by the
existing standards.

CRS-26
c11173008

.

Title

Date

Pages

Notes

Wireless Cybersecurity

Syracuse University
New York,
Department of
Electrical
Engineering and
Computer Science

April 2013

167

This project dealt with various threats in wireless networks,
including eavesdropping in a broadcast channel, noncooperative
eavesdropping in a single-source, single-sink planar network, and
primary user emulation attack in a cognitive radio network. The
major contributions were detailed analysis of performance
trade-off in the presence of the eavesdropping threat, a
combined encoding and routing approach that provides provable
security against noncooperating eavesdropping, and a physical
layer approach to counter the primary emulation attack. The
research results under this effort significantly advanced our
understanding on some of the fundamental trade-offs among
various performance metrics in a wireless system. Practically
feasible wireless security measures were also obtained that
could lead to more assured operations in which secured
wireless networks play an indispensable role. This project led to
one PhD dissertation, one pending patent application, two
archival journal papers, and a number of peer-reviewed
conference papers.

Incentives to Adopt Improved Cybersecurity Practices

NIST and the
National
Telecommunication
s and Information
Administration

March 28,
2013

N/A

The Department of Commerce (DOC) is investigating ways to
incentivize companies and organizations to improve their
cybersecurity. To better understand what stakeholders—such as
companies, trade associations, academics, and others—believe
would best serve as incentives, the department has released a
series of questions to gather public comments in a notice of
inquiry.

Cybersecurity: The Nation’s Greatest Threat to Critical
Infrastructure

U.S. Army War
College

March 2013

38

This paper provides a background on what constitutes national
critical infrastructure and critical infrastructure protection;
discusses the immense vulnerabilities, threats, and risks
associated in the protection of critical infrastructure; and
outlines governance and responsibilities of protecting vulnerable
infrastructure. The paper makes recommendations for federal
responsibilities and legislation to direct nation critical
infrastructure efforts to ensure national security, public safety,
and economic stability.

SCADA [Supervisory Control and Data Acquisition] and
Process Control Security Survey

SANS Institute

February 1,
2013

19

SANS Institute surveyed professionals who work with SCADA
and process control systems. Of the nearly 700 respondents,
70% said they consider their SCADA systems to be at high or
severe risk; one-third of them suspected that these systems had
been already been infiltrated.

CRS-27
c11173008

Source

.

Title

Date

Pages

Notes

Follow-up Audit of the Department’s Cyber Security
Incident Management Program

DOE Inspector
General’s Office

December
2012

25

In 2008, the DOE’s Cyber Security Incident Management
Program (DOE/IG-0787, January 2008) reported the department
and National Nuclear Security Administration (NNSA)
established and maintained a number of independent, at least
partially duplicative, cybersecurity incident management
capabilities. Several issues were identified that limited the
efficiency and effectiveness of the department’s cybersecurity
program and adversely affected the ability of law enforcement to
investigate incidents. In response to the findings, management
concurred with the recommendations and indicated that it had
initiated actions to address the issues identified.

Terrorism and the Electric Power Delivery System

National
Academies of
Science

November
2012

146

Focuses on measures that could make the electric power
delivery system less vulnerable to attacks, restore power faster
after an attack, and make critical services less vulnerable when
delivery of conventional electric power has been disrupted.

New FERC Office to Focus on Cyber Security

DOE

September 20,
2012

N/A

FERC announced the creation of the agency’s new Office of
Energy Infrastructure Security, which will work to reduce
threats to the electric grid and other energy facilities. The goal is
for the office to help FERC, and other agencies and private
companies, better identify potential dangers and solutions.

Canvassing the Targeting of Energy Infrastructure: The
Energy Infrastructure Attack Database

Journal of Energy
Security

August 7,
2012

8

The Energy Infrastructure Attack Database (EIAD) is a
noncommercial dataset that structures information on reported
(criminal and political) attacks to energy infrastructure
worldwide by nonstate actors since 1980. In building this
resource, the objective was to develop a product that could be
broadly accessible and connect to existing available resources.

Smart-Grid Security

Center for
Infrastructure
Protection and
Homeland Security,
George Mason
School of Law

August 2012

26

Highlights the significance of and the challenges with securing the
Smart Grid.

Cybersecurity: Challenges in Securing the Electricity Grid

GAO

July 17, 2012

25

In a prior report, GAO made recommendations related to
electricity grid modernization efforts, including developing an
approach to monitor compliance with voluntary standards.
These recommendations have not yet been implemented.

CRS-28
c11173008

Source

.

Title

Date

Pages

Notes

Energy Department Develops Tool with Industry to Help
Utilities Strengthen Their Cybersecurity Capabilities

DOE

June 28, 2012

N/A

The Cybersecurity Self-Evaluation Tool uses best practices
developed for the Electricity Subsector Cybersecurity Capability
Maturity Model Initiative, which involved a series of workshops
with the private sector to draft a maturity model that can be
used throughout the electric sector to better protect the grid.

ICS-CERT Incident Response Summary Report, 20092011

U.S. Industrial
Control System
Cyber Emergency
Response Team
(ICS-CERT)

May 9, 2012

17

The number of reported cyberattacks on U.S. critical
infrastructure increased sharply—from 9 incidents in 2009 to
198 in 2011. Water sector-specific incidents, when added to the
incidents that affected several sectors, accounted for more than
half of all incidents. In more than half of the most serious cases,
implementing best practices such as log-in limitation or a
properly configured firewall would have deterred the attack,
reduced the time it would have taken to detect an attack, and
minimized its impact.

Cybersecurity Risk Management Process (Electricity
Subsector)

DOE Office of
Electricity Delivery
and Energy
Reliability

May 2012

96

The guideline describes a risk-management process that is
targeted to the specific needs of electricity sector organizations.
Its objective is to build upon existing guidance and requirements
to develop a flexible risk-management process tuned to the
diverse missions, equipment, and business needs of the electric
power industry.

ICT Applications for the Smart Grid: Opportunities and
Policy Implications

Organization for
Economic Cooperation and
Development
(OECD)

January 10,
2012

44

This report discusses “smart” applications of information and
communication technologies (ICTs) for more sustainable energy
production, management, and consumption. The report outlines
policy implications for government ministries dealing with
telecommunications regulation, ICT sector and innovation
promotion, and consumer and competition issues.

The Department’s Management of the Smart Grid
Investment Grant Program

DOE Inspector
General

January 20,
2012

21

According to the DOE inspector general, the department’s rush
to award stimulus grants for projects under the next generation
of the power grid, known as the Smart Grid, resulted in some
firms receiving funds without submitting complete plans for how
to safeguard the grid from cyberattacks.

Critical Infrastructure Protection: Cybersecurity
Guidance Is Available, but More Can Be Done to
Promote Its Use

GAO

December 9,
2011

77

According to GAO, given the plethora of guidance available,
individual entities within the sectors may be challenged in
identifying the guidance that is most applicable and effective in
improving their security posture. Improved knowledge of the
available guidance could help both federal and private-sector
decision makers better coordinate their efforts to protect
critical cyber-reliant assets.

CRS-29
c11173008

Source

.

Title

Source

Date

Pages

Notes

The Future of the Electric Grid

Massachusetts
Institute of
Technology (MIT)

December 5,
2011

39

Chapter 1 provides an overview of the status of the electric
grid, the challenges and opportunities it will face, and major
recommendations. To facilitate selective reading, detailed
descriptions of the contents of each section in Chapters 2–9 are
provided in each chapter’s introduction, and recommendations
are collected and briefly discussed in each chapter’s final section.
(See Chapter 9, “Data Communications, Cybersecurity, and
Information Privacy,” pages 208-234).

FCC’s Plan for Ensuring the Security of
Telecommunications Networks

Federal
Communications
Commission (FCC)

June 3, 2011

1

FCC Chairman Genachowski’s response to letter from
Representative Anna Eshoo dated November 2, 2010, regarding
concerns about the implications of foreign-controlled
telecommunications infrastructure companies providing
equipment to the U.S. market.

Cyber Infrastructure Protection

U.S. Army War
College

May 9, 2011

324

Part 1 deals with strategic and policy cybersecurity-related
issues and discusses the theory of cyberpower, Internet
survivability, large-scale data breaches, and the role of
cyberpower in humanitarian assistance. Part 2 covers social and
legal aspects of cyber infrastructure protection and discusses the
attack dynamics of political and religiously motivated hackers.
Part 3 discusses the technical aspects of cyber infrastructure
protection, including the resilience of data centers, intrusion
detection, and a strong emphasis on Internet protocol (IP)
networks.

In the Dark: Crucial Industries Confront Cyberattacks

McAfee and Center
for Strategic and
International
Studies (CSIS)

April 21, 2011

28

The study reveals an increase in cyberattacks on critical
infrastructure such as power grids, oil, gas, and water; it also
shows that many of the world’s critical infrastructures lacked
protection of their computer networks and reveals the cost and
impact of cyberattacks.

Cybersecurity: Continued Attention Needed to Protect
Our Nation’s Critical Infrastructure and Federal
Information Systems

GAO

March 16,
2011

17

According to GAO, executive branch agencies have made
progress instituting several government-wide initiatives aimed at
bolstering aspects of federal cybersecurity, such as reducing the
number of federal access points to the Internet, establishing
security configurations for desktop computers, and enhancing
situational awareness of cyber events. Despite these efforts, the
federal government continues to face significant challenges in
protecting the nation’s cyber-reliant critical infrastructure and
federal information systems.

CRS-30
c11173008

.

Title

Source

Federal Energy Regulatory Commission’s Monitoring of
Power Grid Cyber Security

DOE Office of
Inspector General

Electricity Grid Modernization: Progress Being Made on
Cybersecurity Guidelines, but Key Challenges Remain to
be Addressed

Pages

Notes

January 26,
2011

30

NERC developed Critical Infrastructure Protection (CIP)
cybersecurity reliability standards, which were approved by the
FERC in January 2008. Although the commission had taken steps
to ensure CIP cybersecurity standards were developed and
approved, NERC’s testing revealed that such standards did not
always include controls commonly recommended for protecting
critical information systems. In addition, the CIP standards
implementation approach and schedule approved by the
commission were not adequate to ensure that systems-related
risks to the nation’s power grid were mitigated or addressed in
a timely manner.

GAO

January 12,
2011

50

From the report: “To reduce the risk that NIST’s smart grid
cybersecurity guidelines will not be as effective as intended, the
Secretary of Commerce should direct the Director of NIST to
finalize the agency’s plan for updating and maintaining the
cybersecurity guidelines, including ensuring it incorporates (1)
missing key elements identified in this report, and (2) specific
milestones for when efforts are to be completed. Also, as a part
of finalizing the plan, the Secretary of Commerce should direct
the Director of NIST to assess whether any cybersecurity
challenges identified in this report should be addressed in the
guidelines.”

Partnership for Cybersecurity Innovation

White House
Office of Science
and Technology
Policy

December 6,
2010

4

The Obama Administration released a memorandum of
understanding signed by DOC’s NIST, DHS’s Science and
Technology Directorate (DHS/S&T), and the Financial Services
Sector Coordinating Council (FSSCC). The goal of the
agreement is to speed up the commercialization of cybersecurity
research innovations that support the nation’s critical
infrastructures.

WIB Security Standard Released

International
Instrument Users
Association (WIB)

November 10,
2010

CRS-31
c11173008

Date

The Netherlands-based WIB, an international organization that
represents global manufacturers in the industrial automation
industry, announced the second version of the Process Control
Domain Security Requirements for Vendors document—the first
international standard that outlines a set of specific
requirements focusing on cybersecurity best practices for
suppliers of industrial automation and control systems.

.

Title

Date

Pages

Notes

Information Security Management System for Microsoft
Cloud Infrastructure

Microsoft

November
2010

15

This study describes the standards Microsoft follows to address
current and evolving cloud security threats. It also depicts the
internal structures within Microsoft that handle cloud security
and risk management issues.

NIST Finalizes Initial Set of Smart Grid Cyber Security
Guidelines

NIST

September 2,
2010

N/A

NIST released a three-volume set of recommendations relevant
to securing the Smart Grid. The guidelines address a variety of
topics, including high-level security requirements, a risk
assessment framework, an evaluation of privacy issues in
residences and recommendations for protecting the evolving
grid from attacks, malicious code, cascading errors, and other
threats.

Critical Infrastructure Protection: Key Private and Public
Cyber Expectations Need to Be Consistently Addressed

GAO

July 15, 2010

38

Private-sector stakeholders reported that they expect their
federal partners to provide usable, timely, and actionable cyber
threat information and alerts; access to sensitive or classified
information; a secure mechanism for sharing information;
security clearances; and a single centralized government
cybersecurity organization to coordinate government efforts.
However, according to private-sector stakeholders, federal
partners are not consistently meeting these expectations.

The Future of Cloud Computing

Pew Research
Center’s Internet
and American Life
Project

June 11, 2010

26

Technology experts and stakeholders expect they will “live
mostly in the cloud” in 2020 and not on the desktop, working
mostly through cyberspace-based applications accessed through
networked devices.

The Reliability of Global Undersea Communications Cable
Infrastructure (The ROGUCCI Report)

Institute of
Electrical and
Electronics
Engineers and the
EastWest Institute

May 26, 2010

186

This study submits 12 major recommendations to privatesector, government, and other stakeholders—especially the
financial sector—for the purpose of improving the reliability,
robustness, resilience, and security of the world’s undersea
communications cable infrastructure.

NSTB Assessments Summary Report: Common Industrial
Control System Cyber Security Weaknesses

DOE, Idaho
National
Laboratory

May 2010

123

This report by the National SCADA Test Bed (NSTB) program
notes that computer networks controlling the electric grid are
plagued with security holes that could allow intruders to
redirect power delivery and steal data. Many of the security
vulnerabilities are strikingly basic and fixable problems.

Explore the reliability and resiliency of commercial
broadband communications networks

FCC

April 21, 2010

N/A

The FCC launched an inquiry into the ability of existing
broadband networks to withstand significant damage or severe
overloads as a result of natural disasters, terrorist attacks,
pandemics, or other major public emergencies, as recommended
in the National Broadband Plan.

CRS-32
c11173008

Source

.

Title

Source

Date

Security Guidance for Critical Areas of Focus in Cloud
Computing V2.1

Cloud Security
Alliance

21 Steps to Improve Cyber Security of SCADA Networks

DOE,
Infrastructure
Security and Energy
Restoration

Source: Highlights compiled by CRS from the reports.

CRS-33
c11173008

Pages

Notes

December
2009

76

From the report, “Through our focus on the central issues of
cloud computing security, we have attempted to bring greater
clarity to an otherwise complicated landscape, which is often
filled with incomplete and oversimplified information. Our focus
... serves to bring context and specificity to the cloud computing
security discussion: enabling us to go beyond gross
generalizations to deliver more insightful and targeted
recommendations.”

January 1,
2007

10

The President’s Critical Infrastructure Protection Board and
DOE have developed steps to help any organization improve the
security of its SCADA networks. The steps are divided into two
categories: specific actions to improve implementation and
actions to establish essential underlying management processes
and policies.

Cybersecurity: Authoritative Reports and Resources, by Topic

.

Cybercrime and Data Security: CRS Reports and Other CRS
Products
•
•
•
•
•
•
•
•
•
•
•

•
•
•
•

•
•
•
•

c11173008

CRS Report 97-1025, Cybercrime: An Overview of the Federal Computer Fraud
and Abuse Statute and Related Federal Criminal Laws, by Charles Doyle
CRS Report 94-166, Extraterritorial Application of American Criminal Law, by
Charles Doyle
CRS Report R43955, Cyberwarfare and Cyberterrorism: In Brief, by Catherine
A. Theohary and John W. Rollins
CRS Report R42403, Cybersecurity: Cyber Crime Protection Security Act (S.
2111, 112th Congress)—A Legal Analysis, by Charles Doyle
CRS Report 98-326, Privacy: An Overview of Federal Statutes Governing
Wiretapping and Electronic Eavesdropping, by Gina Stevens and Charles Doyle
CRS Report RL32706, Spyware: Background and Policy Issues for Congress, by
Patricia Moloney Figliola
CRS Report CRS Report R41975, Illegal Internet Streaming of Copyrighted
Content: Legislation in the 112th Congress, by Brian T. Yeh
CRS Report R42112, Online Copyright Infringement and Counterfeiting:
Legislation in the 112th Congress, by Brian T. Yeh
CRS Report R40599, Identity Theft: Trends and Issues, by Kristin Finklea
CRS Report R41927, The Interplay of Borders, Turf, Cyberspace, and
Jurisdiction: Issues Confronting U.S. Law Enforcement, by Kristin Finklea
CRS Report RL34651, Protection of Children Online: Federal and State Laws
Addressing Cyberstalking, Cyberharassment, and Cyberbullying, by Alison M.
Smith
CRS Report R42547, Cybercrime: Conceptual Issues for Congress and U.S. Law
Enforcement, by Kristin Finklea and Catherine A. Theohary
CRS Report R43382, Data Security and Credit Card Thefts: CRS Experts, by
Eric A. Fischer
CRS Legal Sidebar WSLG483, Obstacles to Private Sector Cyber Threat
Information Sharing, by Edward C. Liu and Edward C. Liu
CRS Legal Sidebar WSLG672, Online Banking Fraud: Liability for
Unauthorized Payment from Business Checking Account, by M. Maureen
Murphy
CRS Legal Sidebar WSLG831, Federal Securities Laws and Recent Data
Breaches, by Michael V. Seitzinger
CRS Legal Sidebar WSLG 906, Hackers Cannot Always Be Tried Where ThirdParty Victims Reside, by Charles Doyle
CRS Legal Sidebar WSLG 959, In the Matter of LabMD: The FTC Must Publicly
Disclose Its Data Security Standards, by Gina Stevens
CRS Report IN10218, Information Warfare: Cyberattacks on Sony, by Catherine
A. Theohary

Congressional Research Service

34

.

Table 5. Cybercrime, Data Breaches, and Data Security
Title

c11173008

Source

Date

Pages

Notes

ThreatExchange

Facebook

Ongoing

ThreatExchange is a set of application programming interfaces, or
APIs, that let disparate companies trade information about the
latest online attacks. Built atop the Facebook Platform—the
standard set of tools for coding applications atop the company’s
worldwide social network—ThreatExchange is used by Facebook
and a handful of other companies, including Tumblr, Pinterest,
Twitter, and Yahoo. Access to the service is strictly controlled,
but [Facebook] hopes to include other companies as time goes
on.

HHS Breach Portal: Breaches Affecting 500 or
More Individuals

Health and Human
Services (HHS)

Ongoing

As required by Section 13402(e)(4) of the HITECH Act, the
Secretary must post a list of breaches of unsecured protected
health information affecting 500 or more individuals. These
breaches are now posted in a new, more accessible format that
allows users to search and sort the posted breaches. Additionally,
this new format includes brief summaries of the breach cases that
OCR has investigated and closed, as well as the names of private
practice providers who have reported breaches of unsecured
protected health information to the Secretary.

ThreatWatch

NextGov

Ongoing

N/A

ThreatWatch is a snapshot of the data breaches hitting
organizations and individuals, globally, on a daily basis. It is not an
authoritative list because many compromises are never reported
or even discovered. The information is based on accounts
published by outside news organizations and researchers.

Criminal Underground Economy Series

Trend Micro

Ongoing

N/A

A review of various cybercrime markets around the world.

Digital Attack Map

Arbor Networks

Ongoing

N/A

The map is powered by data fed from 270+ ISP customers
worldwide who have agreed to share network traffic and attack
statistics. The map displays global activity levels in observed attack
traffic, which it collected anonymously, and does not include any
identifying information about the attackers or victims involved in
any particular attack.

Global Botnet Map

Trend Micro

Ongoing

N/A

Trend Micro continuously monitors malicious network activities
to identify command-and-control (C&C) servers and help increase
protection against botnet attacks. The real-time map indicates the
locations of C&C servers and victimized computers they control
that have been discovered in the previous six hours.

CRS-35

.

Title

c11173008

Source

Date

Pages

Notes

HoneyMap

Honeynet Project

Ongoing

N/A

The HoneyMap displays malicious attacks as they happen. Each red
dot represents an attack on a computer. Yellow dots represent
honeypots or systems set up to record incoming attacks. The
black box on the bottom gives the location of each attack. The
Honeynet Project is an international 501c3 nonprofit security
research organization, dedicated to investigating the latest attacks
and developing open source security tools to improve Internet
security.

The Cyberfeed

Anubis Networks

Ongoing

N/A

This site provides real-time threat intelligence data worldwide.

Regional Threat Assessment: Infection Rates and
Threat Trends by Location Regional Threat
Assessment: Infection Rates and Threat Trends by
Location (Note: Select “All Regions” or a specific
country or region to view threat assessment
reports)

Microsoft Security
Intelligence Report (SIR)

Ongoing

N/A

This report provides data on infection rates, malicious websites,
and threat trends by regional location, worldwide.

Meet ‘Tox': Ransomware for the Rest of Us

McAfee Labs

May 23, 2015

N/A

The packaging of malware and malware-construction kits for
cybercrime “consumers” has been a long-running trend. Various
turnkey kits that cover remote access plus botnet plus stealth
functions are available just about anywhere. Ransomware, though
very prevalent, has not yet appeared in force in easy-to-deploy
kits. However, Tox is now available–and it’s free.

2014 Internet Crime Report

Internet Crime
Complaint Center (IC3)

May 19, 2015

48

IC3, a joint project of the National White Collar Crime Center
and the FBI, received 269,422 complaints last year consisting of a
wide array of scams affecting victims across all demographic
groups. In 2014, victims of Internet crimes in the United States
lost more than $800 million. On average, approximately 22,000
complaints were received each month.

Fifth Annual Benchmark Study on Privacy and
Security of Healthcare Data

Ponemon Institute

May 2015

7

A rise in cyberattacks against doctors and hospitals is costing the
U.S. health-care system $6 billion a year as organized criminals
who once targeted retailers and financial firms increasingly go
after medical records. Criminal attacks are up 125% compared
with five years ago replacing lost laptops as the leading threat.
The study also found most organizations are unprepared to
address new threats and lack adequate resources to protect
patient data.

CRS-36

.

c11173008

Title

Source

Best Practices for Victim Response and Reporting
of Cyber Incidents

Department of Justice

2015 Data Breach Investigations Report (DBIR)

Pages

Notes

April 29,
2015

15

DOJ issued new guidance for businesses on best practices for
handling cyber incidents. The guidance is broken down into what
companies should do— and should not do— before, during and
after an incident. The recommendations include developing an
incident response plan, testing it, identifying highly sensitive data
and risk management priorities, and connecting with law
enforcement and response firms in advance.

Verizon

April 14,
2015

70

A full three-quarters of attacks spread from the first victim to the
second in 24 hours or less, and more than 40% spread from the
first victim to the second in under an hour. On top of the speed
with which attackers compromise multiple victims, the useful
lifespan of shared information can sometimes be measured in
hours. Researchers also found that of the IP addresses observed in
current information sharing feeds, only 2.7% were valid for more
than a day, and the number dwindles from there. Data show that
information sharing has to be good to be effective.

2014 Global Threat Intel Report

CrowdStrike

February 6,
2015

N/A

This report summarizes CrowdStrike’s year-long daily scrutiny of
more than 50 groups of cyber threat actors, including 29 different
state-sponsored and nationalist adversaries. Key findings explain
how financial malware changed the threat landscape and point of
sale malware became increasingly prevalent. The report also
profiles a number of new and sophisticated adversaries from
China and Russia, including Hurricane Panda, Fancy Bear, and
Berserk Bear.

Unique in the shopping mall: On the
reidentifiability of credit card metadata

Science Magazine

January 30,
2015

5

MIT scientists showed they can identify an individual with more
than 90% accuracy by looking at just four purchases, three if the
price is included—and this is after companies “anonymized" the
transaction records, saying they wiped away names and other
personal details.

Ransomware on the Rise: FBI and Partners
Working to Combat This Cyber Threat

FBI

January 20,
2015

N/A

Ransomware scams involve a type of malware that infects
computers and restricts users’ access to their files or threatens
the permanent destruction of their information unless a ransom—
anywhere from hundreds to thousands of dollars—is paid. The
site offers information on the FBI’s and federal, international, and
private-sector partners’ proactive steps to neutralize some of the
more significant ransomware scams through law enforcement
actions against major botnets.

CRS-37

Date

.

Title

c11173008

Source

Date

Pages

Notes

26

Sophos Labs Hungary evaluated the malware and APT campaigns
of several groups that all leveraged a particular exploit—a
sophisticated attack against a specific version of Microsoft Office.
The report found that none of the groups were able to modify the
attack enough to infect other versions of Office, even though
several versions were theoretically vulnerable to the same type of
attack. Despite the aura of skill and complexity that seems to
surround APTs, they are much less sophisticated than they are
given credit for. The APT groups are lacking in quality assurance.
Many attacks are not thoroughly tested and attackers fail to
recognize when some functionality of the attack is not working
properly.

Exploit This: Evaluating the Exploit Skills of
Malware Groups

Sophos Labs Hungary

January 2015

The Cost of Malware Containment
(free registration required)

Ponemon Institute

January 2015

Addressing the cybersecurity Malicious Insider
threat

Schluderberg, Larry
(Utica College Master's
Thesis)

January 2015

80

The purpose of this research was to investigate who constitutes
MI threats, why and how they initiate attacks, the extent to which
MI activity can be modeled or predicted, and to suggest some risk
mitigation strategies. The results reveal that addressing the
Malicious Insider threat is much more than just a technical issue.
Dealing effectively with the threat involves managing the dynamic
interaction between employees, their work environment and
work associates, the systems with which they interact, and
organizational policies and procedures.

The Underground Hacker Markets are Booming
with Counterfeit Documents, Premiere Credit
Cards, Hacker Tutorials, and 1000% Satisfaction
Guarantees

Dell Secure Works

December
2014

16

Researchers examined dozens of underground hacker markets for
this second annual survey and found that business is booming.
Prices have gone down for many items, and the offerings have
expanded. As the report puts it: “Underground hackers are
monetizing every piece of data they can steal or buy and are
continually adding services so other scammers can successfully
carry out online and in-person fraud."

CRS-38

A survey of more than 600 U.S. IT and IT security practitioners
found that in a typical week, organizations receive an average of
nearly 17,000 malware alerts; only 19% are deemed reliable, or
worthy of action. Compounding the problem, respondents believe
their prevention tools miss 40% of malware infections in a typical
week.

.

Title

c11173008

Source

Date

Pages

Notes

What Happens When You Swipe Your Card?

60 Minutes

November
30, 2014

N/A

From the script for the segment “Swiping Your Card”:
“Sophisticated cyberthieves steal your credit card information.
Common criminals buy it and go on shopping sprees—racking up
billions of dollars in fraudulent purchases. The cost of the fraud is
calculated into the price of every item you buy. When computer
crooks swipe your card number, we all end up paying the price.
2014 is becoming known as the ‘year of the data breach.’"

Continuing Federal Cyber Breaches Warn Against
Cybersecurity Regulation

Heritage Foundation

October 27,
2014

N/A

This is a list of federal government cybersecurity breaches and
failures, most of which occurred during 2013 and 2014. The list is
part of a continuing series published by Heritage that serves as a
long-term compilation of open-source data about federal
cybersecurity breaches dating back to 2004.

2014 Cost of Cybercrime Global Report (Email
registration required.)

Hewlett-Packard
Enterprise Security and
the Ponemon Institute

October 8,
2014

30

This 2014 global study of U.S.-based companies, which spanned
seven nations, found that over the course of a year the average
cost of cybercrime climbed by more than 9% to $12.7 million for
companies in the United States, up from $11.6 million in the 2013
study. The average time to resolve a cyberattack is also rising,
climbing to 45 days from 32 days in 2013.

How Consumers Foot the Bill for Data Breaches
(infographic)

NextGov.com

August 7,
2014

Is Ransomware Poised for Growth?

Symantec

July 14, 2014

N/A

Ransomware usually masquerades as a virtual “wheel clamp” for
the victim’s computer. For example, pretending to be from the
local law enforcement, it might suggest the victim had been using
the computer for illicit purposes and claim that to unlock his or
her computer the victim would have to pay a fine—often between
$100 and $500. The use of Ransomware escalated in 2013, with a
500% (sixfold) increase in attack numbers between the start and
end of the year.

iDATA: Improving Defences Against Targeted
Attack

Centre for the
Protection of National
Infrastructure (UK)

July 2014

8

The iDATA program consists of a number of projects aimed at
addressing threats posed by nation-states and state-sponsored
actors. iDATA has resulted in several outputs for the
cybersecurity community. This document provides a description
of the iDATA program and a summary of the reports.

CRS-39

More than 600 data breaches occurred in 2013 alone, with an
average organizational cost of more than $5 million. But in the
end, it is the customers who are picking up the tab, from higher
retail costs to credit card reissue fees.

.

Title

c11173008

Source

Date

Pages

Notes

Cyber Risks: The Growing Threat

Insurance Information
Institute

June 27,
2014

27

Although cyber risks and cybersecurity are widely acknowledged
to be serious threats, many companies today still do not purchase
cyber risk insurance. Insurers have developed specialist cyber
insurance policies to help businesses and individuals protect
themselves from the cyber threat. Market intelligence suggests
that the types of specialized cyber coverage being offered by
insurers are expanding in response to this fast-growing market
need.

Hackers Wanted: An Examination of the
Cybersecurity Labor Market

RAND Corporation

June 24,
2014

110

RAND examined the current status of the labor market for
cybersecurity professionals—with an emphasis on their being
employed to defend the United States. This effort was in three
parts: first, a review of the literature; second, interviews with
managers and educators of cybersecurity professionals,
supplemented by reportage; and third, an examination of the
economic literature about labor markets. RAND also
disaggregated the broad definition of “cybersecurity professionals”
to unearth skills differentiation as relevant to this study.

Global Cybercrime: The Interplay of Politics and
Law

Centre for International
Governance Innovation

June 20,
2014

23

This paper explores the recent unsealing of a 31-count indictment
against 5 Chinese government officials and a significant cyber
breach perpetrated by Chinese actors against Western oil, energy,
and petrochemical companies. The paper concludes by noting that
increased cooperation between governments is necessary but
unlikely to occur as long as the discourse surrounding cybercrime
remains so heavily politicized and securitized. If governments
coalesced around the notion of trying to prevent the long-term
degradation of trust in the online economy, then they might
profitably advance the dialogue away from mutual suspicion and
toward mutual cooperation.

Net Losses: Estimating the Global Cost of
Cybercrime

Center for Strategic and
International Studies and
McAfee

June 2014

24

This report explores the economic impact of cybercrime,
including estimation, regional variances, IP theft, opportunity and
recovery costs, and the future of cybercrime.

2014 U.S. State of Cybercrime Survey

PricewaterhouseCooper
s, CSO Magazine, the
CERT Division of the
Software Engineering
Institute at Carnegie
Mellon University, and
the U.S. Secret Service

May 29, 2014

21

The cybersecurity programs of U.S. organizations do not rival the
persistence, tactical skills, and technological prowess of their
potential cyber adversaries. This year, three out of four (77%)
respondents to the survey had detected a security event in the
past 12 months, and more than one-third (34%) said the number
of security incidents detected had increased over the previous
year.

CRS-40

.

Title

c11173008

Source

Date

Pages

Notes

Privileged User Abuse and The Insider Threat
(Requires free registration to access.)

Ponemon Institute and
Raytheon

May 21, 2014

32

The report looks at what companies are doing right and the
vulnerabilities that need to be addressed with policies and
technologies. One problematic area is the difficulty in actually
knowing if an action taken by an insider is truly a threat. Sixty-nine
percent of respondents say they do not have enough contextual
information from security tools to make this assessment, and 56%
say security tools yield too many false positives.

Online Advertising and Hidden Hazards to
Consumer Security and Data Privacy

Senate Permanent
Subcommittee on
Investigations

May 15, 2014

47

The report found consumers could expose themselves to malware
just by visiting a popular website. It noted that the complexity of
the industry made it possible for both advertisers and host
websites to defer responsibility and that consumer safeguards
failed to protect against online abuses. The report also warned
that current practices do not create enough incentives for “online
advertising participants” to take preventive measures.

Sharing Cyberthreat Information Under 18 USC §
2702(a)(3)

Department of Justice

May 9, 2014

7

The Department of Justice issued guidance for Internet service
providers to assuage legal concerns about information sharing.
The white paper interprets the Stored Communications Act,
which prohibits providers from voluntarily disclosing customer
information to governmental entities. The white paper says the
law does not prohibit companies from divulging data in the
aggregate, without any specific details about identifiable
customers.

The Rising Strategic Risks of Cyberattacks

McKinsey and Company

May 2014

N/A

Companies are struggling with their capabilities in cyber risk
management. As highly visible breaches occur with increasing
regularity, most technology executives believe they are losing
ground to attackers. Organizations large and small lack the facts to
make effective decisions, and traditional “protect the perimeter”
technology strategies are proving insufficient.

Big Data: Seizing Opportunities, Preserving Values

White House

May 2014

85

Findings include a set of consumer protection recommendations,
such as national data-breach legislation, and a fresh call for
baseline consumer-privacy legislation first recommended in 2012.

The Target Breach, by the Numbers

Krebs on Security

May 6, 2014

N/A

A synthesis of numbers associated with the Target data breach of
December 19, 2013 (e.g., number of records stolen, estimated
dollar cost to credit unions and community banks, amount of
money Target estimates it will spend upgrading payment terminals
to support Chip-and-PIN enabled cards).

CRS-41

.

Title

c11173008

Source

Date

Pages

Notes

Heartbleed’s Impact

Pew Research Center

April 30,
2014

13

The Heartbleed security flaw on one of the most widely used
“secure socket” encryption programs on the Internet had an
impact on a notable share of Internet users. Some 60% of adults
(and 64% of Internet users) said they had heard about the bug.
Some 19% of adults said they had heard a lot about it, and 41%
said they had heard a little about it. However, the Heartbleed
story drew much less intensity and scope of attention than other
big news stories.

Russian Underground Revisited

Trend Micro

April 28,
2014

25

The price of malicious software—designed to enable online bank
fraud, identity theft, and other cybercrimes—is falling dramatically
in some of the Russian-language criminal markets in which it is
sold. Falling prices are a result not of declining demand but rather
of an increasingly sophisticated marketplace. This report outlines
the products and services being sold and what their prices are.

A “Kill Chain” Analysis of the 2013 Target Data
Breach

Senate Commerce
Committee

March 26,
2014

18

This report analyzes what has been reported to date about the
Target data breach, using the intrusion kill chain framework, an
analytical tool introduced by Lockheed Martin security
researchers in 2011 and today widely used by information security
professionals in both the public and private sectors. This analysis
suggests that Target missed a number of opportunities along the
kill chain to stop the attackers and prevent the massive data
breach.

Markets for Cybercrime Tools and Stolen Data

RAND Corporation
National Security
Research Division and
Juniper Networks

March 25,
2014

83

This report, part of a multiphase study on the future security
environment, describes the fundamental characteristics of the
criminal activities in cyberspace markets and how they have grown
into their current state to explain how their existence can harm
the information security environment.

CRS-42

.

Title

c11173008

Source

Date

Pages

Notes

Merchant and Financial Trade Associations
Announce Cybersecurity Partnership

Retail Industry Leaders
Association

February 13,
2014

N/A

Trade associations representing the merchant and financial
services industries announced a new cybersecurity partnership.
The partnership will focus on exploring paths to increased
information sharing, better card security technology, and
maintaining the trust of customers. Discussion regarding the
partnership was initiated by the Retail Industry Leaders
Association and the Financial Services Roundtable, joined by the
American Bankers Association, the American Hotel and Lodging
Association, the Clearing House, the Consumer Bankers
Association, the Food Marketing Institute, the Electronic
Transactions Association, the Independent Community Bankers of
America, the International Council of Shopping Centers, the
National Associations of Convenience Stores, the National
Grocers Association, the National Restaurant Association, and the
National Retail Federation.

FTC Statement Marking the FTC’s 50th Data
Security Settlement

Federal Trade
Commission (FTC)

January 31,
2014

2

The FTC announces its 50th data security settlement. What
started in 2002 with a single case applying established FTC Act
precedent to the area of data security has grown into an
enforcement program that has helped to increase protections for
consumers and encouraged companies to make safeguarding
consumer data a priority.

Worst Practices Guide to Insider Threats: Lessons
from Past Mistakes

American Academy of
Arts and Sciences

January 2014

32

From the report: “Here, we are presenting a kind of ‘worst
practices’ guide of serious mistakes made in the past regarding
insider threats. While each situation is unique, and serious insider
problems are relatively rare, the incidents we describe reflect
issues that exist in many contexts and that every nuclear security
manager should consider. Common organizational practices—such
as prioritizing production over security, failure to share
information across subunits, inadequate rules or inappropriate
waiving of rules, exaggerated faith in group loyalty, and excessive
focus on external threats—can be seen in many past failures to
protect against insider threats.”

ENISA Threat Landscape 2013—Overview of
Current and Emerging Cyber-Threats

European Union Agency
for Network and
Information Security
(ENISA)

December
11, 2013

70

The report is a collection of top cyber threats that have been
assessed in the reporting period (i.e., within 2013). ENISA has
collected more than 250 reports regarding cyber threats, risks,
and threat agents. This report is a comprehensive compilation of
the top 15 cyber threats assessed.

CRS-43

.

Title

c11173008

Source

Date

Pages

Notes

Cyber-enabled Competitive Data Theft: A
Framework for Modeling Long-Run Cybersecurity
Consequences

Brookings Institution

December
2013

18

Economic espionage has existed at least since the industrial
revolution, but the scope of modern cyber-enabled competitive
data theft may be unprecedented. In this paper, the authors
present what they believe is the first economic framework and
model to understand the long-run impact of competitive data theft
on an economy by taking into account the actual mechanisms and
pathways by which theft harms the victims.

Trends in Incident Response in 2013

U.S. Industrial Control
System Cyber
Emergency Response
Team (ICS-CERT)
Monitor

OctoberDecember
2013

14

In 2013, ICS-CERT responded to 256 incidents reported either
directly from asset owners or through other trusted partners.
Most of these incidents were initially detected in business
networks of critical infrastructure organizations that operate
industrial control systems. Of the 256 reported incidents, 59%, or
151 incidents, occurred in the energy sector, which exceeded all
incidents reported in other sectors combined.

Illicit Cyber Activity Involving Fraud

Carnegie Mellon
University Software
Engineering Institute

August 8,
2013

28

Technical and behavioral patterns were extracted from 80 fraud
cases—67 insider and 13 external—that occurred between 2005
and the present. These cases were used to develop insights and
risk indicators to help private industry, government, and law
enforcement more effectively prevent, deter, detect, investigate,
and manage malicious insider activity within the banking and
finance sectors.

The Economic Impact of Cybercrime and Cyber
Espionage

Center for Strategic and
International Studies

July 22, 2013

20

Losses to the United States (the country in which data is most
accessible) may reach $100 billion annually. The cost of
cybercrime and cyber espionage to the global economy is some
multiple of this, likely measured in hundreds of billions of dollars.

Cyber-Crime, Securities Markets, and Systemic
Risk

World Federation of
Exchanges and the
International
Organization of
Securities Commissions

July 16, 2013

59

This report explores the nature and extent of cybercrime in
securities markets so far and the potential systemic risk aspects of
this threat. It presents the results of a survey to the world’s
exchanges on their experiences with cybercrime, cybersecurity
practices, and perceptions of the risk.

Towards Trustworthy Social Media and
Crowdsourcing

Wilson Center

May 2013

12

Individuals and organizations interested in using social media and
crowdsourcing currently lack two key sets of information: a
systematic assessment of the vulnerabilities in these technologies
and a comprehensive set of best practices describing how to
address those vulnerabilities. Identifying those vulnerabilities and
developing those best practices are necessary to address a
growing number of cybersecurity incidents ranging from innocent
mistakes to targeted attacks that have claimed lives and cost
millions of dollars.

CRS-44

.

c11173008

Title

Source

Date

Pages

Notes

Remaking American Security: Supply Chain
Vulnerabilities and National Security Risks Across
the U.S. Defense Industrial Base

Alliance for American
Manufacturing

May 2013

355

Because the supply chain is global, it makes sense for U.S. officials
to cooperate with other nations to ward off cyberattacks.
Increased international cooperation to secure the integrity of the
global IT system is a valuable long-term objective.

Comprehensive Study on Cybercrime

United Nations Office
on Drugs and Crime

February
2013

320

The study examined the problem of cybercrime from the
perspective of governments, the private sector, academia, and
international organizations. It presents its results in eight chapters,
covering Internet connectivity and cybercrime; the global
cybercrime picture; cybercrime legislation and frameworks;
criminalization of cybercrime; law enforcement and cybercrime
investigations; electronic evidence and criminal justice;
international cooperation in criminal matters involving cybercrime;
and cybercrime prevention.

HoneyMap - Visualizing Worldwide Attacks in
Real-Time and Honeynet Map

The Honeynet Project

October 1,
2012

N/A

The HoneyMap shows a real-time visualization of attacks against
the Honeynet Project’s sensors deployed around the world.

Does Cybercrime Really Cost $1 Trillion?

ProPublica

August 1,
2012

N/A

In a news release to announce its 2009 report, Unsecured
Economies: Protecting Vital Information, computer security firm
McAfee estimated a $1 trillion global cost for cybercrime. The
number does not appear in the report itself. This estimate is
questioned even by the three independent researchers from
Purdue University whom McAfee credits with analyzing the raw
data from which the estimate was derived. An examination by
ProPublica has found new grounds to question the data and
methods used to generate these numbers, which McAfee and
Symantec say they stand behind.

Information Security: Cyber Threats Facilitate
Ability to Commit Economic Espionage

Government
Accountability Office
(GAO)

June 28,
2012

20

This statement discusses (1) cyber threats facing the nation’s
systems, (2) reported cyber incidents and their impacts, (3)
security controls and other techniques available for reducing risk,
and (4) the responsibilities of key federal entities in support of
protecting Internet protocol.

Measuring the Cost of Cybercrime

11th Annual Workshop
on the Economics of
Information Security

June 25,
2012

N/A

From the report: “For each of the main categories of cybercrime
we set out what is and is not known of the direct costs, indirect
costs and defence costs—both to the UK and to the world as a
whole.”

The Impact of Cybercrime on Businesses

Ponemon Institute

May 2012

21

The study found that targeted attacks on businesses cost
enterprises an average of $214,000. The expenses are associated
with forensic investigations, investments in technology, and brand
recovery costs.

CRS-45

.

Title

Source

Date

Pages

Notes

Proactive Policy Measures by Internet Service
Providers against Botnets

Organization for
Economic Co-operation
and Development
(OECD)

May 7, 2012

25

This report analyzes initiatives in a number of countries through
which end-users are notified by Internet service providers (ISPs)
when their computers are identified as being compromised by
malicious software and encouraged to take action to mitigate the
problem.

Developing State Solutions to Business Identity
Theft: Assistance, Prevention and Detection Efforts
by Secretary of State Offices

National Association of
Secretaries of State
(NASS)

January 2012

23

This white paper is the result of efforts by the 19-member NASS
Business Identity Theft Task Force to develop policy guidelines
and recommendations for state leaders dealing with identity fraud
cases involving public business records.

Twenty Critical Security Controls for Effective
Cyber Defense: Consensus Audit Guidelines

SANS Institute

October 3,
2011

77

The 20 security measures are intended to focus agencies’ limited
resources on plugging the most common attack vectors.

Revealed: Operation Shady RAT: an Investigation
Of Targeted Intrusions Into 70+ Global
Companies, Governments, and Non-Profit
Organizations During the Last 5 Years

McAfee

August 2,
2011

14

A cyber-espionage operation lasting many years penetrated 72
government and other organizations, most of them in the United
States, and has copied everything from military secrets to
industrial designs, according to technology security company
McAfee. (See page 4 for the types of compromised parties, page 5
for the geographic distribution of victim’s country of origin, pages
7-9 for the types of victims, and pages 10-13 for the number of
intrusions for 2007-2010).

The Role of Internet Service Providers in Botnet
Mitigation: an Empirical Analysis Based on Spam
Data

OECD

November
12, 2010

31

This working paper considers whether ISPs can be critical control
points for botnet mitigation, how the number of infected machines
varies across ISPs, and why.

Untangling Attribution: Moving to Accountability in
Cyberspace (Testimony)

Council on Foreign
Relations

July 15, 2010

14

Robert K. Knake’s testimony before the House Committee on
Science and Technology on the role of attack attribution in
preventing cyberattacks and how attribution technologies can
affect the anonymity and privacy of Internet users.

Technology, Policy, Law, and Ethics Regarding U.S.
Acquisition and Use of Cyberattack Capabilities

National Research
Council

2009

368

This report explores important characteristics of cyberattacks. It
describes the current international and domestic legal structure as
it might apply to cyberattacks and considers analogies to other
domains of conflict to develop relevant insights.

Source: Highlights compiled by CRS from the reports.

c11173008

CRS-46

.

Table 6. National Security, Cyber Espionage, and Cyberwar
Title

c11173008

Source

Date

Pages

Notes

Cyberthreat: Real-Time Map

Kaspersky Labs

Ongoing

N/A

Kaspersky Labs has launched an interactive cyber threat map that
lets viewers see cybersecurity incidents as they occur around the
world in real time. The interactive map includes malicious objects
detected during on-access and on-demand scans, email and web
antivirus detections, and objects identified by vulnerability and
intrusion detection subsystems.

Cybersecurity: Jihadism and the internet

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/crs%3AR42507. Public record. Not legal advice.
