Posts

Showing posts with the label cdm

Hearing Witness Doesn't Understand CDM

Image
This post is a follow up to this post on CDM . Since that post I have been watching hearings on the OPM breach. On Wednesday 24 June a Subcommittee of the House Committee on Homeland Security held a hearing titled  DHS’ Efforts to Secure .Gov . A second panel (starts in the Webcast around 2 hours 20 minutes) featured Dr. Daniel M. Gerstein, a former DHS official now with RAND, as its sole witness. During his opening statement, and in his written testimony , he made the following comments: "The two foundational programs of DHS’s cybersecurity program are EINSTEIN (also called  EINSTEIN 3A) and CDM. These two systems are designed to work in tandem, with EINSTEIN  focusing on keeping threats out of federal networks and CDM identifying them when they are  inside government networks. EINSTEIN provides a perimeter around federal (or .gov) users, as well as select users in the .com  space that have responsibility for critical infrastructure. EINSTEIN ...

My Federal Government Security Crash Program

Image
In the wake of recent intrusions into government systems, multiple parties have been asking for my recommended courses of action. In 2007, following public reporting on the 2006 State Department breach, I blogged When FISMA Bites ,  Initial Thoughts on Digital Security Hearing . and What Should the Feds Do . These posts captured my thoughts on the government's response to the State Department intrusion. The situation then mirrors the current one well: outrage over an intrusion affecting government systems, China suspected as the culprit, and questions regarding why the government's approach to security does not seem to be working. Following that breach, the State Department hired a new CISO who pioneered the "continuous monitoring" program, now called "Continuous Diagnostic Monitoring" (CDM). That CISO eventually left State for DHS, and brought CDM to the rest of the Federal government. He is now retired from Federal service, but CDM remains. Years l...

Continuous Diagnostic Monitoring Does Not Detect Hackers

Image
There is a dangerous misconception coloring the digital security debate in the Federal government. During the last week, in the wake of the breach at the Office of Personnel Management (OPM), I have been discussing countermeasures with many parties. Concerned officials, staffers, and media have asked me about the Einstein and  Continuous Diagnostic Monitoring  (CDM) programs. It has become abundantly clear to me that there is a fundamental misunderstanding about the nature of CDM. This post seeks to remedy that problem. The story  Federal cyber protection knocked as outdated, behind schedule by Cory Bennett unfortunately encapsulates the misunderstanding about Einstein and CDM: The main system used by the federal government to protect sensitive data from hacks has been plagued by delays and criticism that it is already outdated — months before it is even fully implemented. The Einstein system is intended to repel cyberattacks like the one revealed last week ...

Why DIARMF, "Continuous Monitoring," and other FISMA-isms Fail

Image
I've posted about twenty FISMA stories over the years on this blog, but I haven't said anything for the last year and a half. After reading Goodbye DIACAP, Hello DIARMF by Len Marzigliano, however, I thought it time to reiterate why the newly "improved" FISMA is still a colossal failure. First, a disclaimer: it's easy to be a cynic and a curmudgeon when the government and security are involved. However, I think it is important for me to discuss this subject because it represents an incredible divergence between security people. On one side of the divide we have "input-centric," " control-compliant ," "we-can-prevent-the-threat" folks, and on the other side we have "output-centric," "field-assessed," "prevention eventually fails" folks. FISMA fans are the former and I am the latter. So what's the problem with FISMA? In his article Len expertly discusses the new DoD Information Assurance Risk...