From: Government Security News

By: Mark Rockwell

DHS pressed its case on Capitol Hill on March 13 that legislation that further facilitates information sharing between public and private entities is urgently needed to supplement the White House’s executive order on public/private Cyber security.

In testimony before the House Homeland Security Committee, DHS deputy secretary Jane Holl Lute told lawmakers the U.S. confronts a dangerous one-two punch of known and unknown vulnerabilities in Cyber space, along with strong and quickly expanding adversary capabilities. Cyber crime has also increased significantly over the last decade, she noted.

Holl Lute said her department has responded to more than half a million reports of Cyber security incidents since 2009 and issued almost 30,000 alerts to private industry and public agencies on Cyber security problems.

Holl Lute was only one of a group of Obama administration Cyber warriors testifying on Capitol Hill on March 13. For instance, Gen. Keith Alexander, commander of the U.S. Cyber Command at the National Security Agency, testified before the House Armed Services Committee the same day, telling the panel the U.S. military is creating offensive Cyber teams that would defend the country against electronic attack. “This is an offensive team that the Defense Department would use to defend the nation if it were attacked in cyberspace,” he said. “Thirteen of the teams that we’re creating are for that mission alone.”Alexander told the committee that  DoD is developing 40 of the Cyber support teams that should be ready for action by 2015.

Holl Lute said private industry, as well as non-military government agencies, have their hands full with Cyber defenses. She said in 2012, DHS identified a campaign of tightly-focused, well-crafted Cyber intrusions that targeted natural gas and pipeline companies. She said information stolen from those entities might provide an attacker with sensitive knowledge about industrial control systems, including information that could allow for unauthorized operation of the systems. “As the President has said, we know that our adversaries are seeking to sabotage our power grid, our financial institutions, and our air traffic control systems. These intrusions and attacks are coming all the time and they are coming from different sources and take different forms, all the while increasing in seriousness and sophistication,” she said.

DHS and the Department of Defense are pushing for more Congressional actions to protect against electronic assault. Although president Obama issued an executive order that began establishing voluntary critical infrastructure standards for Cyber protections, Holl Lute and other DHS officials want Congress to bolster those efforts with laws that provide hiring and pay flexibilities to secure federal civilian networks, protect critical infrastructure, respond to cyber threats, and combat cybercrime.

She also said the executive order didn’t grant new regulatory authority or establish additional incentives for participation in the voluntary program. Hall Lute said DHS believes that “a suite of legislation is necessary to implement the full range of steps needed to build a strong public-private partnership, and we will continue to work with Congress to achieve this.”

Holl Lute also provided a glimpse of how DHS has worked to counter the threat to private industry and government agencies. Since 2009, the National Cybersecurity & Communications Integration Center (NCCIC), DHS’ 24 x 7 cyber situational awareness, incident response, and management center has responded to nearly half a million incident reports and released more than 26,000 actionable Cyber security alerts to our public and private sector partners, she said. Since 2009, the NCCIC has also responded to nearly half a million incident reports.

In 2012, she said the US-Computer Emergency Response Team (US-CERT) processed approximately 190,000 cyber incidents involving federal agencies, critical infrastructure, and industry partners. The total, she added, represented a 68 percent increase from 2011. US-CERT also issued over 7,455 actionable cyber-alerts in 2012 used by private sector and government agencies to protect their systems. It has also had over 6,400 partners subscribe to the US-CERT portal to engage in information sharing and receive cyber threat warning information

The Department’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) responded to 177 incidents in 2012, completed 89 site assistance visits and deployed 15 teams with US-CERT to respond to significant private sector cyber incidents. She added that over 1,000 companies had used DHS’ cyber self-evaluation tool.