IT Security & Network Security News & Reviews - eWeek



NSA: Assume Attackers Will Compromise Networks




In comments at a cyber-security forum, an NSA official said the agency's systems must be built with the assumption adversaries will get in.

The National Security Agency appears to be taking some old advice to heart—assume your organization will be compromised.

Debora Plunkett, head of the NSA's Information Assurance Directorate, said as much Dec. 16 at a cyber-security forum sponsored by the Atlantic and Government Executive media organization.

"We have to build our systems on the assumption that adversaries will get in," she reportedly told attendees.

"The most sophisticated adversaries are going to go unnoticed on our networks," she said.

The comments follow the fallout from the WikiLeaks situation, where some 250,000 U.S. diplomatic cables were posted online. Plunkett declined comment on the incident, but did state during her comments that "there's no such thing as secure anymore."

In July, the NSA revealed some details for a project called "Perfect Citizen" after information leaked out to the press. The agency described the program as a "vulnerabilities-assessment and capabilities-development" effort meant to help the NSA "better understand the threats to national security networks."

In her comments, Plunkett said the United States cannot put its trust "in different components of the system that might have already been violated."

"We have to, again, assume that all the components of our system are not safe, and make sure we're adjusting accordingly," she said.

Gartner analyst John Pescatore said Plunkett's comments actually reflect an old position at the NSA.

"Basically, unless the hardware and software was built by NSA and has NSA-approved tamper protection, it can't be trusted," he wrote in an e-mail. "Since even NSA has to use commercial hardware and software, their own environments can't be trusted! That's why they have the High Assurance Computing effort, defining what would have to be implemented in all IT in order for them to trust it.

"This sounds drastic, but not so much different than what good enterprise security practice is—assume you will be compromised, so do vulnerability scanning, network forensics, etc., to see if you are," he added.








 
 
>>> More IT Security & Network Security News & Reviews Articles          >>> More By Brian Prince
 

FEATURED SPONSOR MESSAGE

Is your IT environment efficient and flexible?

Are your systems integrated to share data, make better-informed decisions, and respond to events in real-time? The key to maximizing agility and creating and retaining happy customers is to create an "intelligent, integrated enterprise."

Learn more.

Brought to you by





Advertisement
eWEEK Quick LInks