Critical analysis and replies needed

profileJohn_matt
replies_1_needed.docx

Reply 1 needed

John,

Seems you developed a vast understanding of how real cyber attacks are. In saying that, I would venture to say that you will agree administrations must take the necessary measure to combat cyber attacks. Based on the high level targets that have been successfully infiltrated, clearly no one is exempt from being attacked. The proper handling of government data is very important. Government employees must be aware of how information should be cared for based on it's sensitivity. All agencies should be manned with a cyber security team who are responsible for training all data custodians as well maintained security features.

R,

E.W.

Reply 2 needed

I thought we were supposed to answer the question of our administration would ensure that Digital Government services are secure? 

· What is meant by "Digital Government services?" (previously called "e-Government" services)

· Where have past administrations fallen short in protecting Digital Government / e-Government services?

· What is meant by "Threats" (i.e. individual hackers, politically motivated hacktivists, criminal enterprises, and unfriendly "nation state" actors)

I feel like the questions for the debate were not answered.  Growth has been observed in the Information Technology field since the 1940s.  Now, in more modern times, the role of E-government, or virtual government has been on the rise.  This is providing the American people an open platform allowing for the use and re-use of government data while preserving privacy in the process. (Office of Management and Budget, 2016)  Privacy is paramount in this process; the people won't trust the government with data, if they feel the data is not protected.  That being said, the government is taking stride to anonymize data, especially when we are discussing health data, PII, or tax data.  We have seen that between "January 1, 2009 and May 31, 2012, there have been 268 breach incidents in government agencies with more than 94 million records containing personally identifiable information exposed." (Data Breaches, 2012)  Threats come in many forms: malicious software, nation state actors (people who are working for adversaral governments), hacktivists (hackers with a cause), etc.  Threats are what we can expect to exploit vulnerabilities in computer systems.

You did mention some of this, but I feel you touched the tip of the iceberg.

Digital government services are built three "layers": the information, or data, such as weather and census data plus other supporting data, the platform by which data is delivered and managed for access by people, and the presentation layer, which determines the way in which people see the and receive the data through the Internet, mobile applications, and other delivery methods (Office of Management and Budget, 2016)  These layers are functional in that they are designed to facilitate the development of open government through the use Internet -based media functionality.  The problem lies with the number of breaches that occur constantly.   Hopefully, the Data Security and Breach Notification Act of 2015, will help enforce disclosure of breaches when they happen. (Nelson, 2015)   Because there have been 268 breaches recorded between the beginning of 2009 and 2012 where we have seen the breach of personal information, we need to be vigilant in mitigating them.  Even a breach by Russian hackers exfiltrating information from the Democratic national Convention just was reported; information regarding presidential candidates was stolen.

Can you tell us how past administrations failed at securing services?

P.S. I am not trying to be rude by any means; I simply did not feel the questions were answered here.  If you feel I misunderstood your viewpoint, then help me to better understand.

Reply 3 needed

Incident response is a piece of the cyber security puzzle, but it is worthless unless you do it in a timely fashion.  Creating a culture of security awareness is imperative to creating a defense in depth strategy for enterprise networks.  Users are the weakest link in this, and attackers will frequently exploit them.  Many breaches stem internally from people's ignorance or being careless with opening email or sharing passwords. (Abawajy, 2014).  This can easily result in a breach of any network, whether intentional or not.  I have personally seen this in action; mostly because people do not understand what they are doing when they are clicking things while browsing the Internet.  Likewise, one user can bypass all the security mechanism present on a network.  Check out "( http://www.theregister.co.uk/2010/01/14/google_china_attack_analysis/ )." (Grauer, 2016)  Failing to deliver the cyber risk information that board members want, in a way they understand, will not go unnoticed,” said Ryan Stolte, Chief Technology Officer and Co-Founder of Bay Dynamics. And there will be repercussions. 59 percent of board members surveyed said that there is a good chance that one or more IT and security executives who fail to provide useful and actionable information in their reports would lose their jobs.

So if that wasn't enough motivation, there are guides that can be obtain from NIST to guide you on create secure configurations for computer systems and servers.  You can also access iase.disa.mil to get information on Secure Technical Information Guides (STIGs) to assist in endeavors like this as well.

Abawajy, J. (2014). User preference of cyber security awareness delivery methods. Behaviour & Information Technology, 33(3), 236-247.

Grauer, Y. (2016). Forbes Welcome. Forbes.com. Retrieved 14 June 2016, from http://www.forbes.com/sites/ygrauer/2016/06/14/cyber-security-executives-need-to-step-up-their-game-heres-why/#d8c3ea43be1a