Exit Interview: DHS’s Bruce McConnell
From: BankInfoSecurity.com
A Top Cybersecurity Leader Assesses Tenure at DHS
By Eric Chabrow
Though others deemed Bruce McConnell as one of the government’s most innovative security thought-leaders, he says his vision of how best to secure IT evolved during his just-ended 4-year tenure at DHS as a senior cybersecurity policymaker.
Allan Friedman of the Brookings Institution says McConnell’s thinking on cybersecurity was ahead of its time when he became the Department of Homeland Security’s senior counselor and director, strategy and policy for cybersecurity, in July 2009, and “remained largely unchanged, while the world around him slowly converged on it.”
McConnell, who for the past four months had been serving as acting deputy undersecretary for cybersecurity in DHS’s National Protection and Programs Directorate, says in the first of a two-part interview with Information Security Media Group that he began the job in 2009 knowing that cybersecurity required resilience and cooperation among many stakeholders, important attributes that remain vital.
What has changed is his realization of the importance of technologies offered by the private sector. As an example, he points out that the government has turned to the private sector to acquire technology to build the Einstein intrusion detection and prevention systems to protect civilian agencies’ information networks.
Privacy-Security Synergy
Another area where his thinking evolved was recognizing the synergy between privacy and security. McConnell points out that DHS regularly publishes unclassified assessments on each of its systems describing how it handles personal information. Those assessments are available to the public for review. “It is possible to link privacy and security by the use of transparency,” he says. “My thinking has become more nuanced on that point that it’s really important to keep those two things together.”
In the interview conducted days before his departure from DHS, McConnell discusses the:
- Impact of a politically dysfunctional Congress, which hasn’t enacted significant cybersecurity legislation in more than a decade;
- Cybersecurity framework being developed by a government-industry partnership that will create IT security best practices that the owners of the nation’s critical infrastructure can adopt voluntarily; and
- Need to create global institutions to improve Internet security governance.
In the second part of the interview, which will be posted in the coming days, McConnell discusses the challenges the government faces in establishing programs for sharing cyberthreat information.
McConnell says he plans to join The EastWest Institute, a global think tank focused on security. Before working at DHS, he served on the Obama-Biden presidential transition team, working on a variety of information policy and technology issues. During the first eight years of the millennium, McConnell worked as a consultant. In 1999 and 2000, he coordinated year 2000 computer mediation programs for 120 nations.
As chief of information policy and technology in the White House Office of Management and Budget from 1993-1999, McConnell led the government-industry team that reformed U.S. encryption export policy, created an information security strategy for government agencies, redirected government technology procurement and management along commercial lines and extended the presumption of open government information onto the Internet.
| Print article |