Understanding Sensitive But Unclassified Federations

From: ISE.gov | An Information Sharing Environment Bulletin – December 15, 2015

By: Donna Roy, Executive Director, DHS Information Sharing Environment Office, Alex Voultepsis, Chief, Engineering & Planning, Intelink/NSA, & Alan F. Rosenhauer, Chief Technology Officer, RISS

The ability of US federal, state, local, tribal, territorial, and private sector partners to share accurate information quickly is essential to our national security and resilience.  To meet this requirement, law enforcement information sharing has expanded significantly across all levels of government, improving the ability to detect, prevent, and respond to acts of terrorism or crime.

With increased access to law enforcement information that users have gained, comes the problem of managing the increasing number of passwords.  That’s why we established interoperability between our critical information sharing platforms.  Intelligence analysts at all levels of government need the right information at the right time.  They cannot waste precious time shuffling through dozens of passwords and managing multiple systems while they are building leads and identifying trends.  Further, at a time of limited resources, we need interoperability to use our IT development funds in the most efficient way possible.

While federations, including Single Sign-On (SSO), have the potential to increase risk they also have the significant ability to improve both information sharing and safeguarding when federation partners stand together to address cyber security concerns.  The Homeland Security Information Network (HSIN), Intelink, Law Enforcement Enterprise Portal (LEEP) and Regional Information Sharing Systems (RISS) SSO partners are already leading the way.  Fulfilling the duty to share doesn’t mean we have to compromise security – and we haven’t.  Every user of our SSO enabled platforms is heavily vetted before they can gain access to their home system.

Many of our systems reduce risk while expanding information sharing by employing strong two-factor authentication every time a user logs on.  These two-factor capabilities combine something you know (such as a password) with something you have (such as a PIV/CAC card) or something you are (such as a fingerprint).  The two-factor authentication eliminates passwords as an easy threat vector to penetrate our systems and reduces the ability for threat actors to use spear phishing and social engineering campaigns to take over accounts.  And thanks to strong governance through the Program Manager for the Information Sharing Environment (PM-ISE), we have the right management and security procedures in place to ensure that when a cyber-attack does occur, our responses are fast and coordinated.

Yet, despite all this, we know the cyber threat is persistent and growing and we all have a responsibility to continue to improve.  One way the SSO partners are improving is that they are implementing a regular cyber incident response exercise regimen to enhance response procedures and times, increase the speed and volume of cyber threat information sharing and vulnerability alerts, and empower our security managers to head off threats before they strike a weakness.

Responsible information sharing is always a balance between the duty to share and the imperative to safeguard.  Balancing these interests doesn’t mean compromising one for the other.  HSIN, Intelink, LEEP, and RISS as SSO partners have and continue to fulfill the duty to share and to safeguard their systems.

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *