In a letter to Senator John McCain, originally obtained by the Washington Post for a report published last Friday, General Keith Alexander, the director of the NSA and current commander of the U.S. Cyber Command, says that the U.S. should implement policy that would require hardened network defenses.
In Senator McCain’s letter, he asked General Alexander to explain what additional authorities he believed were necessary in order to defend the U.S. from a cyber attack initiated by a peer-competitor like China or Russia.
In his response, the head of the U.S. Cyber Command told the one-time presidential hopeful that legislation is needed for “information sharing and core critical infrastructure hardening,” adding that if the Department of Defense is to defend the nation against cyber attack, it must be able to see those attacks in real time.
“This requires legislation that, at a minimum, removes existing barriers and disincentives that inhibit the owners of the critical infrastructure from sharing cyber threat indicators with the Government,” General Alexander wrote.
“Additionally, given DoD reliance on certain core critical infrastructure to execute its mission, as well as the importance of the Nation’s critical infrastructure to our national and economic security overall, legislation is also needed to ensure that infrastructure is efficiently hardened and resilient. Recent events have shown that a purely voluntary and market driven system is not sufficient.”
He believes that some minimum-security requirements are necessary in order to ensure critical infrastructure is taking “appropriate measures to harden its networks…” At the same time, he added, it is important that legislative requirements not be too burdensome.
When asked which agency within the federal government has the most cybersecurity expertise and is most capable of protecting critical infrastructure, General Alexander said that none of them are.
“No single public or private entity has all of the required authorities, resources, and capabilities; cybersecurity requires a team… protecting our national interest in the cyber realm requires a team effort consisting of DHS, FBI, NSA/CSS and USCYBERCOM.”
The entire letter is worth a read. It was recently published in full by PublicIntelligence.net.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Critical Vulnerability Impacts Over 120 Lexmark Printers
- BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws
- Industry Reactions to Hive Ransomware Takedown: Feedback Friday
- Microsoft Urges Customers to Patch Exchange Servers
- Iranian APT Leaks Data From Saudi Arabia Government Under New Persona
- US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware
- Cyberattacks Target Websites of German Airports, Admin
- US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’
