e-Resolution 2007: Top Priorities for Government IT Security
Sun, 2007-01-07 17:15

  So what are the top IT security priorities for government, whether federal, state, or local, in 2007?  

    First, a few quick caveats are needed. There are plenty of personalized priorities for each of us. We all have our own strategies and local plans. While everyone seems to be talking about common items like patching systems, mobile workers, identity management, and a protecting sensitive information accessed from mobile devices, we’re all at different places with our architectures and infrastructures. In Michigan, we’ll be releasing our new Strategic IT Security Plan for 2007-2010 later this month. I’ll provide a link to the executive summary of our plan when it comes out, so you can see more details and compare and contrast with your own approaches.

     Second, as I talk with colleagues around the country, it’s very clear that we have the full spectrum from laggards to bleeding edge security groups, when in comes to adoption of the “new security stuff.” The RSA conference is coming around again, with a host of new promising black boxes. Which ones will make a difference? That’s another blog, but there’s always a few surprises out there.  

    Third (and finally), all emergencies are local, and we can never predict when the next cyber-Katrina will hit. Veteran CSOs know that all priorities and predictions can go by the wayside if something really bad happens (either locally or nationally). None of us want to be a bad headline, either.

    So after all the formalities ….. What’s the answer? What’s the top (new) thing we should all be working on after we’ve answered all the above questions?

     I vote for implementing the National Infrastructure Protection Plan (NIPP) - Sector Specific Plans, and especially the IT-Sector Specific Plan. I know that’s a mouth full and you may not even know what I’m talking about.  For detailed information on what the NIPP is and downloading copies of the overall plan, you should go to the DHS website.

     Reliable sources have told me that all of the NIPP sector plans will be released together as one package later this month or early next month at the latest. It should be a big deal, with plenty of press and a few senior level execs making appearances on the news-talk circuits. Without going into specifics, there will be actions items and direction for new security initiatives, and private sector and government entities should take note by sector. This will become our major roadmap for either the next three years or until a new administration changes direction - whichever comes first.  

     I know that some readers view these types of documents as largely unrelated to their “real” job. While progress has been made on the National Strategy to Secure Cyberspace, some articles were written saying that that plan was too watered down when it was published.

    I’m aware of those criticisms. Still, I’ve spent a good chunk of time in 2006 working with public and private sector colleagues to help write the soon to be released IT Sector Plan for the NIPP. The private sector, via the IT Sector Coordinating Council or IT-SCC, has been very involved in this writing process, working in close collaboration with the IT- Government Coordinating Council (IT-GCC). Federal, State and local representation is also involved in the IT-GCC. My involvement has been as the National Association of CIOs (NASCIO's) primary rep to the IT-GCC.

   I know I’m biased, but I do think this IT-sector plan will be important  and “different.” I can’t go into details until it’s released, but at that time, I plan to provide (hopefully helpful) “NIPP-notes” on each important chapter. They’ll be kind of like “Cliff Notes” for those who relied on those handy booklets to get through high school and college.  

   There were many articles written on the NIPP in 2006, and you can even take a course from FEMA on the plan called IS-860. I mention all of this now, since I believe this will (and should) become a major focus and priority for 2007 and beyond. I recommend getting familiar with the overall NIPP now and be ready when the IT plan comes out soon.

 

       

Ads by TechWords
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Maximizing Site Visitor Trust Using Extended Validation SSL

VeriSignNow with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in the free VeriSign white paper.

» Read the Paper

Sponsored Links

Manage your IT more effectively

Efficient - Flexible - Compliant

Secure your virtual and physical environments with the same software

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Digital Identity Protection and Data Security Get Personal

Welcome to the age of Service-Oriented Security (SOS)

When Customer Relationship is Everything, Businesses Bank on SSL Solutions

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

The Case for Business Software Assurance ~ Securing Your Applications

Maximizing Site Visitor Trust Using Extended Validation SSL

Solving Online Credit Fraud Using Device Reputation

Understanding Data Location is Imperative for Data Loss Prevention

5 Steps to Secure Outsourced Application Development

CA's IT Security centralizes your identity management to turn security into a proactive, business-building tool

Simplify your data center with Juniper Networks. View the webcast

Any company can promise identity protection. Only Debix can prove it

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

IDC Defines an Identity and Access Management Submarket

Using Likewise to Comply with PCI Data Security Standard

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Enabling Compliance with Converged Mainframe Security and Storage

Managing SSL Security in Multi-Server Environments

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Get in Compliance With Government Data Regulations

Taking the Botnet Threat Seriously