Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts
19 December 2016
Cybersecurity: Understanding DNS Attacks
source: Understanding the DNS Attacks: Convenience v Security | K2 Intelligence - Investigations · Compliance Solutions · Cyber Defense - JDSupra
#Cybersecurity #Cyberattack #Security #DNS
14 November 2016
6 Proposals to Stop IoT-Based DDoS Attacks
6 Proposals to Stop IoT-Based DDoS Attacks:
source: Six Proposals to Stop IoT-Based DDoS Attacks | BakerHostetler - JDSupra
source: Six Proposals to Stop IoT-Based DDoS Attacks | BakerHostetler - JDSupra
04 March 2016
21 January 2016
NIST IoT Framework, Cybersecurity, Data Privacy
re: NIST, IoT, Framework, Cybersecurity, Data Privacy, Internet of Things
NIST IoT Framework Raises Interesting Cybersecurity and Data Privacy Challenges | Carlton Fields - JDSupra
31 December 2015
IoT, Internet of Things, Inevitable Collision with Product Liability
IoT, Internet of Things, Inevitable Collision with Product Liability, security, Industrial Internet Consortium, cybersecurity,
source: The Internet of Things and the Inevitable Collision with Product Liability PART 5: Security and the Industrial Internet Consortium | Wilson Elser - JDSupra
14 December 2015
IRS Taxpayer Campaign to Protect Personal Information
Re: IRS, Taxpayer, Protect, Personal Information, Data, Cybersecurity, Security.
Source: IRS Begins Campaign to Encourage Taxpayers to Protect Personal Information | McGuireWoods LLP - JDSupra
10 December 2015
Cyber-Insurance Does Not Ensure Protection From Data Breach
... a recent lawsuit filed in California underscores that while obtaining cyber-insurance may be prudent, it cannot replace conducting a thorough risk assessment and adopting best practices when it comes to information security management. Failure to implement critical information security policies may render a cyber-insurance policy invalid...
cybersecurity, insurance, data, breach, cyberattack, security,
Source: Cyber-Insurance Does Not Ensure Protection From Data Breach | Wiggin and Dana LLP - JDSupra
cybersecurity, insurance, data, breach, cyberattack, security,
Source: Cyber-Insurance Does Not Ensure Protection From Data Breach | Wiggin and Dana LLP - JDSupra
17 November 2015
UN Internet Governance Forum, IGF2015, ICTs, Sustainable Development
14 November 2015 – Consensus at the closing 10th Internet Governance Forum (IGF) in Brazil today underscored the contribution of Information Communications Technologies (ICTs) and the Internet to the achievement of the recently adopted 2030 Agenda for Sustainable Development, the United Nations announced. Goal 9 of the agenda sets an ambitious target to “significantly increase access to information and communications technology and strive to provide universal and affordable access to the Internet in least developed countries by 2020.”
“In keeping with the IGF inclusiveness, this gathering in Joao Pessoa addressed both opportunities and challenges under the following sub-themes: Cybersecurity and Trust; Internet Economy; Inclusiveness and Diversity; Openness; Enhancing Multi-stakeholder Cooperation; Internet and Human Rights; Critical Internet Resources and Emerging Issues,” said UN Assistant Secretary-General Lenni Montiel in a press release.
According to the UN, the three-day Forum “became the Mecca center for vibrant discussions about internet governance in the context of sustainable development.” Annually convened by the Organization, the 2015 event reportedly succeeded in giving some 4,000 online participants, from 116 developed and developing countries, the opportunity to engage directly with 2,400 on-site attendees in debates that addressed the challenges, as well as opportunities for the future of the internet.
In addition, over 150 thematic workshops at the 10th IGF focused on a diverse range of topics spanning from zero rating and network neutrality to freedom of expression online, cybersecurity and internet economy. Many workshops also stressed the interrelation of human rights and fundamental freedom, both online and offline and how this related to the promotion of development.
Meanwhile, the Under-Secretary-General for the Environment, Energy, Science and Technology of the Ministry of Foreign Affairs of Brazil, Ambassador José Antônio Marcondes de Carvalho, said the Forum could develop and produce “tangible contributions” and, thus, have more substantial impact on the evolution of the Internet, especially in terms of public policy.
“This Forum gives an unambiguous message of the importance of the IGF and the legitimacy and relevance of its continuity,” he stated.
source: United Nations News Centre - UN Internet Governance Forum closes, highlights linkages with sustainable development
“In keeping with the IGF inclusiveness, this gathering in Joao Pessoa addressed both opportunities and challenges under the following sub-themes: Cybersecurity and Trust; Internet Economy; Inclusiveness and Diversity; Openness; Enhancing Multi-stakeholder Cooperation; Internet and Human Rights; Critical Internet Resources and Emerging Issues,” said UN Assistant Secretary-General Lenni Montiel in a press release.
According to the UN, the three-day Forum “became the Mecca center for vibrant discussions about internet governance in the context of sustainable development.” Annually convened by the Organization, the 2015 event reportedly succeeded in giving some 4,000 online participants, from 116 developed and developing countries, the opportunity to engage directly with 2,400 on-site attendees in debates that addressed the challenges, as well as opportunities for the future of the internet.
In addition, over 150 thematic workshops at the 10th IGF focused on a diverse range of topics spanning from zero rating and network neutrality to freedom of expression online, cybersecurity and internet economy. Many workshops also stressed the interrelation of human rights and fundamental freedom, both online and offline and how this related to the promotion of development.
Meanwhile, the Under-Secretary-General for the Environment, Energy, Science and Technology of the Ministry of Foreign Affairs of Brazil, Ambassador José Antônio Marcondes de Carvalho, said the Forum could develop and produce “tangible contributions” and, thus, have more substantial impact on the evolution of the Internet, especially in terms of public policy.
“This Forum gives an unambiguous message of the importance of the IGF and the legitimacy and relevance of its continuity,” he stated.
source: United Nations News Centre - UN Internet Governance Forum closes, highlights linkages with sustainable development
16 November 2015
NTIA's Larry Strickling at Internet Governance Forum, João Pessoa, Brazil
Remarks of Lawrence E. Strickling, U.S. Assistant Secretary of Commerce for Communications and Information, at IGF2015, the Internet Governance Forum 2015, at João Pessoa, Brazil, on November 10, 2015–as prepared for delivery–(emphasis added):
Thank you. At the outset, let me congratulate our host nation, Brazil, as the first country to have hosted two meetings of the Internet Governance Forum (IGF). It is fitting that Brazil, with its strong tradition of supporting multistakeholder Internet governance, be the first country to earn this honor.
Over the past 10 years, the IGF has proven itself to be an indispensable platform for addressing Internet issues. I look forward each year to attending the IGF and meeting with this diverse collection of stakeholders to tackle the challenges facing the Internet. This year I am pleased to see important innovations in the IGF’s intersessional work on items such as the best practices forums and the IGF policy options document on connecting the next billion. These and other innovations will enrich the conversations this week in Brazil.
As we mark the 10-year anniversaries of the World Summit on the Information Society (WSIS) and the IGF, it is important to take stock of where we have come and the challenges ahead. There is much to celebrate in how the Internet has evolved into a platform for global economic growth, innovation and free speech. The open Internet is helping the economies and societies of both developed and developing nations. Not only has it created a dynamic and growing digital economy, it has transformed just about every facet of our day-to-day lives. Every one of us has a stake in ensuring the continued growth, job formation and wealth creation that an open Internet brings.
In the United States, we attribute that success in large part to the bottom-up, multistakeholder approach to resolving technical and policy challenges facing the Internet. This is why we are such strong supporters of the IGF – one of the preeminent international examples of this approach – and have called for an extension of the IGF that is consistent with its original mandate. We are pleased that so many countries have echoed this call. If collectively, we continue to support multistakeholder Internet governance, if we make it more inclusive of developing countries and more responsive to all stakeholders, then we can truly achieve the Information Society we envisioned 10 years ago.
In the United States, we are committed to multistakeholder Internet governance, as convincingly demonstrated by our announcement in March 2014 that the U.S. government would transition its historical stewardship role over the Internet Domain Name System to the multistakeholder community. Since that time, the response from the community of technical experts, academics, civil society and industry has been inspiring. Over the past year and a half, stakeholders have worked hundreds of hours to complete a transition proposal that meets the criteria we have outlined. We are hopeful the working groups will complete their work in the coming weeks.
This work is tiring; sometimes contentious; perhaps exasperating. No doubt, this is not an easy task. But it is an important one. All of us should appreciate the effort and level of commitment demonstrated by all the participants in this process. Most importantly, the process is working and I am confident it will be successful. It will be a testament to the strength of the multistakeholder process when the transition is completed.
But even with the growth of international support for multistakeholder governance, there is continued cause for concern. Freedom House’s 2015 report on Internet freedom finds that Internet freedom around the world is in decline for a fifth consecutive year. More governments are censoring information from their citizens and attempting to put up barriers to the open Internet within their borders.
The growth of sophisticated malware and other cyber security threats, the need to protect the privacy of Internet users and the mounting online theft of intellectual property online have challenged governments’ ability to balance these important interests with the equally important need for openness. Governments increasingly feel compelled to do something they see as meaningful – if not outright drastic – to protect their citizens and their businesses from these threats.
Regrettably, in their attempts to do something to protect their citizens and businesses, governments sometimes rush to put up digital walls between their countries and the rest of the world, between their citizens and people abroad. In recent years, we have seen governments institute data localization laws, as well as impose limitations on data storage and data transfer.
Historically, these kinds of restrictive policies have tended to be pursued by authoritarian governments that want to try to control information and monitor the activities of their citizens. In recent years, however, even democratic countries have considered restrictions on data flows.
Such proposals do far more harm than good. Restricting data flows and competition between firms increase costs for Internet users and businesses, retard technological innovation, and may curb freedom of expression.
This assessment may seem like common sense to many of us in this room. But it is not accepted by everyone. And that is why it is imperative that we continue multistakeholder venues like the IGF. They allow us – as representatives of diverse stakeholder communities – to come together, to offer our unique perspectives, to work through our most difficult problems, and to make a case for policies and practices that encourage the development of an open and innovative Internet.
In closing, I urge all nations to step up in support of the free and open Internet and the multistakeholder process that has led to its success. If we want to maintain a vibrant and growing Internet, we must all take action to ensure that the multistakeholder approach continues to define the future of Internet governance. Thank you for listening.
Source: US Government - NTIA
Thank you. At the outset, let me congratulate our host nation, Brazil, as the first country to have hosted two meetings of the Internet Governance Forum (IGF). It is fitting that Brazil, with its strong tradition of supporting multistakeholder Internet governance, be the first country to earn this honor.
Over the past 10 years, the IGF has proven itself to be an indispensable platform for addressing Internet issues. I look forward each year to attending the IGF and meeting with this diverse collection of stakeholders to tackle the challenges facing the Internet. This year I am pleased to see important innovations in the IGF’s intersessional work on items such as the best practices forums and the IGF policy options document on connecting the next billion. These and other innovations will enrich the conversations this week in Brazil.
As we mark the 10-year anniversaries of the World Summit on the Information Society (WSIS) and the IGF, it is important to take stock of where we have come and the challenges ahead. There is much to celebrate in how the Internet has evolved into a platform for global economic growth, innovation and free speech. The open Internet is helping the economies and societies of both developed and developing nations. Not only has it created a dynamic and growing digital economy, it has transformed just about every facet of our day-to-day lives. Every one of us has a stake in ensuring the continued growth, job formation and wealth creation that an open Internet brings.
In the United States, we attribute that success in large part to the bottom-up, multistakeholder approach to resolving technical and policy challenges facing the Internet. This is why we are such strong supporters of the IGF – one of the preeminent international examples of this approach – and have called for an extension of the IGF that is consistent with its original mandate. We are pleased that so many countries have echoed this call. If collectively, we continue to support multistakeholder Internet governance, if we make it more inclusive of developing countries and more responsive to all stakeholders, then we can truly achieve the Information Society we envisioned 10 years ago.
In the United States, we are committed to multistakeholder Internet governance, as convincingly demonstrated by our announcement in March 2014 that the U.S. government would transition its historical stewardship role over the Internet Domain Name System to the multistakeholder community. Since that time, the response from the community of technical experts, academics, civil society and industry has been inspiring. Over the past year and a half, stakeholders have worked hundreds of hours to complete a transition proposal that meets the criteria we have outlined. We are hopeful the working groups will complete their work in the coming weeks.
This work is tiring; sometimes contentious; perhaps exasperating. No doubt, this is not an easy task. But it is an important one. All of us should appreciate the effort and level of commitment demonstrated by all the participants in this process. Most importantly, the process is working and I am confident it will be successful. It will be a testament to the strength of the multistakeholder process when the transition is completed.
But even with the growth of international support for multistakeholder governance, there is continued cause for concern. Freedom House’s 2015 report on Internet freedom finds that Internet freedom around the world is in decline for a fifth consecutive year. More governments are censoring information from their citizens and attempting to put up barriers to the open Internet within their borders.
The growth of sophisticated malware and other cyber security threats, the need to protect the privacy of Internet users and the mounting online theft of intellectual property online have challenged governments’ ability to balance these important interests with the equally important need for openness. Governments increasingly feel compelled to do something they see as meaningful – if not outright drastic – to protect their citizens and their businesses from these threats.
Regrettably, in their attempts to do something to protect their citizens and businesses, governments sometimes rush to put up digital walls between their countries and the rest of the world, between their citizens and people abroad. In recent years, we have seen governments institute data localization laws, as well as impose limitations on data storage and data transfer.
Historically, these kinds of restrictive policies have tended to be pursued by authoritarian governments that want to try to control information and monitor the activities of their citizens. In recent years, however, even democratic countries have considered restrictions on data flows.
Such proposals do far more harm than good. Restricting data flows and competition between firms increase costs for Internet users and businesses, retard technological innovation, and may curb freedom of expression.
This assessment may seem like common sense to many of us in this room. But it is not accepted by everyone. And that is why it is imperative that we continue multistakeholder venues like the IGF. They allow us – as representatives of diverse stakeholder communities – to come together, to offer our unique perspectives, to work through our most difficult problems, and to make a case for policies and practices that encourage the development of an open and innovative Internet.
In closing, I urge all nations to step up in support of the free and open Internet and the multistakeholder process that has led to its success. If we want to maintain a vibrant and growing Internet, we must all take action to ensure that the multistakeholder approach continues to define the future of Internet governance. Thank you for listening.
Source: US Government - NTIA
30 September 2015
Wyndham Decision: FTC Can Sue Businesses For Getting Hacked
re: federal trade commission, cybersecurity, liability
source: Burning Down The House – The Wyndham Decision Allows The FTC To Sue Businesses For Getting Hacked | Fowler White Burnett, P.A. - JDSupra
29 September 2015
02 September 2015
US Ambassador at 7th Annual Summit on Cyber and Network Security
U.S. Ambassador Richard R. Verma’s Remarks at ASSOCHAM’s 7th Annual Summit on Cyber and Network Security - Ashok Hotel, New Delhi | August 26, 2015 (As Prepared for Delivery):
Good morning and thanks for the generous introduction. I’m delighted to be here and thank ASSOCHAM for the chance to speak to you on this important topic. Of course, the Internet today is part of just about everything we do. This digital age has opened countless windows of opportunity, to the great benefit of the U.S. and India. Both our societies and our economies have been enriched by the many advantages of greater connectivity; and I know this first hand, since I continue to marvel and how instantly connected I have felt to Indians of all ages since I have started my Twitter account. In fact just two weeks ago I visited Twitter’s India headquarters and took part in an online chat with a number of tech savvy Indians.
When we talk about digital technology, it is natural to think about potential risks, but it is the possibilities that should motivate us. From the campuses of Silicon Valley to the tech parks of Bangalore, our countries have emerged as leaders in the field of IT development. The Indian diaspora has played a particularly large role. Just two weeks ago Sundar Pichai, a native of Chennai, was named CEO of Google, one of America’s tech giants. He is one of countless similar examples. Indeed, when Prime Minister Modi visits California next month, he will be welcomed by a vibrant Indian-American community which, over the last two decades, has helped to transform the high-technology sector.
Similarly, here in India, technology has been integral in powering economic growth, whether it be through e-commerce, IT services, or product development. The Prime Minister’s “Digital India” initiative highlights India’s commitment to enhancing digital capacity, across a variety of sectors, bridging the divide between urban and rural communities. Secretary John Kerry also recently launched a new initiative to increase internet connectivity, in partnership with government, development banks, engineers, and industry leaders. I applaud these efforts, as broadening the reach of the Internet is a powerful way to promote global development. Every time a country increases its internet penetration by ten percent, its total economic growth can expand by up to two percent.
The Internet is part of the critical infrastructure that we have come to depend on. We use it in so many ways – as a communication tool, a marketplace, a forum for expressing new ideas. Digital technology promotes transparency and helps to hold governments accountable. It is a means to fight against repression, and protect human dignity. Yet we must ensure that cybersecurity tools are not inappropriately used to undermine these important benefits.
But, as transformative as the Internet is, there are risks. And the more reliant we become on the Internet, the greater those risks become. This means we need sound policies to protect this essential resource, as it is vital to advancing human progress in the 21st century. Therefore, promoting an open, secure, and reliable Internet is a key component of our economic policy.
Protecting the Internet cannot be the task of just one country, however, and requires cooperation between government, industry, academia, and every user. It is a shared resource, and thus its stewardship is a shared responsibility. The Internet has flourished because of the bottom-up, consensus-based process that allows multiple stakeholders to participate in its governance. Likewise, all stakeholders have a critical role in cybersecurity and cybercrime as well. The multistakeholder approach reaches beyond government and includes the private sector, civil society, academic institutions, and all internet users. Multistakeholder Internet governance has served us well thus far, and it is critical to broaden this approach to other areas of cyber policy because all institutions and users share a responsibility to keep the internet operating in a safe, secure, and reliable manner.
To that end, India’s recent decision to support the multistakeholder approach to internet governance is not only a win for India’s people, but an example of India’s ever-expanding role as a democratic world leader. We look forward to working closely with India and other partners to preserve the multistakeholder model, wherever it is challenged.
Of course, there are other, serious threats to the internet. As recent headlines have shown, cyber-attacks are a real and persistent concern. Internet misconduct has resulted in billions of dollars in economic damage. Criminal networks misuse the Internet to steal information and profit at the expense of private citizens, businesses, and governments. Extremist groups see it as a means to disseminate violent extremist propaganda and mislead youth into joining their causes. It is in our shared interest to seek collaborative solutions to these challenges.
We believe that the best defense is to promote what we call “international cyber stability.” This means we are seeking broad consensus on what constitutes responsible behavior in cyberspace. Our goal is to create a climate in which people everywhere are able to enjoy the benefits of the digital world. There is general consensus that the basic rules of international law apply in cyberspace, but there are a number of additional principles that should underpin countries’ behavior in cyberspace.
First, we posit that no country should support or conduct online activity that intentionally damages or impedes another country’s use.
Second, no country should seek to prevent emergency teams from responding to a security breach, or allow its own teams to cause harm.
Third, no country should engage in cyber-enabled theft of intellectual property, trade secrets, or other confidential information for commercial gain.
Fourth, every country should confront malicious cyber activity emanating from its soil. This includes the activities of extremist groups who seek to engage in criminal and terrorist behavior.
And finally, every country should do what it can to help states that are the victims of a cyber-attack.
Agreeing to and abiding by these principles would move us a long way towards ensuring a more secure cyberspace. In order to get there, however, we must work to improve our own and our partners’ capacity to protect against cyber threats. This includes a preventative component – through strong legal frameworks and improved training. It also means enhancing our capability to respond to threats, by improving the resiliency of our networks, and strengthening the relationships between our law enforcement communities.
Perhaps the greatest protection against such threats is the regular and substantive sharing of information on cyber threats, and stronger coordination in response to cyber-attacks and cybercrime. This is an area in which the United States and India continue to partner. We recently provided information on a high-profile hacking group operating from India, enabling our two countries to take concerted action against its threat. We are also engaged in efforts to improve the process through which other countries can obtain bank records and other forms of electronic evidence from the United States, for use in legal proceedings against illicit actors.
We should continue to build information-sharing mechanisms through law enforcement and intelligence channels, as well as within our private sector, as the bulk of our networks lie outside of public and government control. We must also continue to work through differences in our legal systems that can sometimes slow the sharing of information used during criminal investigations. Given the risks involved, these are worthwhile efforts.
Just two weeks ago, our governments participated in the U.S.-India Cyber dialogue. The United States and India held open and constructive conversations about substantive measures to increase cyber cooperation, ranging from coordinating on internet governance issues, deepening our existing cyber security collaboration, streamlining the exchange of information related to cybercrime, and U.S. support for India’s ambitious but essential cybersecurity skills development initiative. These, and other common objectives, highlight the criticality of the U.S.-India relationship, leverage the inseparable ties of our IT communities, and emphasize yet another example of our joint efforts to safeguard critical infrastructure and national security.
Our populations are among the most interconnected on the planet, which is in part a reflection of our shared values. The Internet is an unparalleled platform where voices from every corner of the globe can contribute to political, economic, and social discourse. Discussions on how to manage cyberspace can be difficult, because they touch on the core of our democratic values, including ethics, the role of government in society, and economic liberty. But if we commit ourselves to protecting internet freedom, the digital revolution will continue to power the opportunities our societies cherish most – by helping to strengthen governments, make us safer, boost economic growth, and promote free expression. And those are goals worth fighting for.
Thank you.
source: Speeches & Remarks | New Delhi, India - Embassy of the United States
Good morning and thanks for the generous introduction. I’m delighted to be here and thank ASSOCHAM for the chance to speak to you on this important topic. Of course, the Internet today is part of just about everything we do. This digital age has opened countless windows of opportunity, to the great benefit of the U.S. and India. Both our societies and our economies have been enriched by the many advantages of greater connectivity; and I know this first hand, since I continue to marvel and how instantly connected I have felt to Indians of all ages since I have started my Twitter account. In fact just two weeks ago I visited Twitter’s India headquarters and took part in an online chat with a number of tech savvy Indians.
When we talk about digital technology, it is natural to think about potential risks, but it is the possibilities that should motivate us. From the campuses of Silicon Valley to the tech parks of Bangalore, our countries have emerged as leaders in the field of IT development. The Indian diaspora has played a particularly large role. Just two weeks ago Sundar Pichai, a native of Chennai, was named CEO of Google, one of America’s tech giants. He is one of countless similar examples. Indeed, when Prime Minister Modi visits California next month, he will be welcomed by a vibrant Indian-American community which, over the last two decades, has helped to transform the high-technology sector.
Similarly, here in India, technology has been integral in powering economic growth, whether it be through e-commerce, IT services, or product development. The Prime Minister’s “Digital India” initiative highlights India’s commitment to enhancing digital capacity, across a variety of sectors, bridging the divide between urban and rural communities. Secretary John Kerry also recently launched a new initiative to increase internet connectivity, in partnership with government, development banks, engineers, and industry leaders. I applaud these efforts, as broadening the reach of the Internet is a powerful way to promote global development. Every time a country increases its internet penetration by ten percent, its total economic growth can expand by up to two percent.
The Internet is part of the critical infrastructure that we have come to depend on. We use it in so many ways – as a communication tool, a marketplace, a forum for expressing new ideas. Digital technology promotes transparency and helps to hold governments accountable. It is a means to fight against repression, and protect human dignity. Yet we must ensure that cybersecurity tools are not inappropriately used to undermine these important benefits.
But, as transformative as the Internet is, there are risks. And the more reliant we become on the Internet, the greater those risks become. This means we need sound policies to protect this essential resource, as it is vital to advancing human progress in the 21st century. Therefore, promoting an open, secure, and reliable Internet is a key component of our economic policy.
Protecting the Internet cannot be the task of just one country, however, and requires cooperation between government, industry, academia, and every user. It is a shared resource, and thus its stewardship is a shared responsibility. The Internet has flourished because of the bottom-up, consensus-based process that allows multiple stakeholders to participate in its governance. Likewise, all stakeholders have a critical role in cybersecurity and cybercrime as well. The multistakeholder approach reaches beyond government and includes the private sector, civil society, academic institutions, and all internet users. Multistakeholder Internet governance has served us well thus far, and it is critical to broaden this approach to other areas of cyber policy because all institutions and users share a responsibility to keep the internet operating in a safe, secure, and reliable manner.
To that end, India’s recent decision to support the multistakeholder approach to internet governance is not only a win for India’s people, but an example of India’s ever-expanding role as a democratic world leader. We look forward to working closely with India and other partners to preserve the multistakeholder model, wherever it is challenged.
Of course, there are other, serious threats to the internet. As recent headlines have shown, cyber-attacks are a real and persistent concern. Internet misconduct has resulted in billions of dollars in economic damage. Criminal networks misuse the Internet to steal information and profit at the expense of private citizens, businesses, and governments. Extremist groups see it as a means to disseminate violent extremist propaganda and mislead youth into joining their causes. It is in our shared interest to seek collaborative solutions to these challenges.
We believe that the best defense is to promote what we call “international cyber stability.” This means we are seeking broad consensus on what constitutes responsible behavior in cyberspace. Our goal is to create a climate in which people everywhere are able to enjoy the benefits of the digital world. There is general consensus that the basic rules of international law apply in cyberspace, but there are a number of additional principles that should underpin countries’ behavior in cyberspace.
First, we posit that no country should support or conduct online activity that intentionally damages or impedes another country’s use.
Second, no country should seek to prevent emergency teams from responding to a security breach, or allow its own teams to cause harm.
Third, no country should engage in cyber-enabled theft of intellectual property, trade secrets, or other confidential information for commercial gain.
Fourth, every country should confront malicious cyber activity emanating from its soil. This includes the activities of extremist groups who seek to engage in criminal and terrorist behavior.
And finally, every country should do what it can to help states that are the victims of a cyber-attack.
Agreeing to and abiding by these principles would move us a long way towards ensuring a more secure cyberspace. In order to get there, however, we must work to improve our own and our partners’ capacity to protect against cyber threats. This includes a preventative component – through strong legal frameworks and improved training. It also means enhancing our capability to respond to threats, by improving the resiliency of our networks, and strengthening the relationships between our law enforcement communities.
Perhaps the greatest protection against such threats is the regular and substantive sharing of information on cyber threats, and stronger coordination in response to cyber-attacks and cybercrime. This is an area in which the United States and India continue to partner. We recently provided information on a high-profile hacking group operating from India, enabling our two countries to take concerted action against its threat. We are also engaged in efforts to improve the process through which other countries can obtain bank records and other forms of electronic evidence from the United States, for use in legal proceedings against illicit actors.
We should continue to build information-sharing mechanisms through law enforcement and intelligence channels, as well as within our private sector, as the bulk of our networks lie outside of public and government control. We must also continue to work through differences in our legal systems that can sometimes slow the sharing of information used during criminal investigations. Given the risks involved, these are worthwhile efforts.
Just two weeks ago, our governments participated in the U.S.-India Cyber dialogue. The United States and India held open and constructive conversations about substantive measures to increase cyber cooperation, ranging from coordinating on internet governance issues, deepening our existing cyber security collaboration, streamlining the exchange of information related to cybercrime, and U.S. support for India’s ambitious but essential cybersecurity skills development initiative. These, and other common objectives, highlight the criticality of the U.S.-India relationship, leverage the inseparable ties of our IT communities, and emphasize yet another example of our joint efforts to safeguard critical infrastructure and national security.
Our populations are among the most interconnected on the planet, which is in part a reflection of our shared values. The Internet is an unparalleled platform where voices from every corner of the globe can contribute to political, economic, and social discourse. Discussions on how to manage cyberspace can be difficult, because they touch on the core of our democratic values, including ethics, the role of government in society, and economic liberty. But if we commit ourselves to protecting internet freedom, the digital revolution will continue to power the opportunities our societies cherish most – by helping to strengthen governments, make us safer, boost economic growth, and promote free expression. And those are goals worth fighting for.
Thank you.
source: Speeches & Remarks | New Delhi, India - Embassy of the United States
01 September 2015
Joint Statement: 2015 United States-India Cyber Dialogue
Joint Statement: 2015 United States-India Cyber Dialogue:
To increase global cybersecurity and promote the digital economy, the United States and India have committed to robust cooperation on cyber issues. To that end, the United States and India met at the U.S. Department of State in Washington, DC on August 11 and 12 for the 2015 U.S.-India Cyber Dialogue.
The whole-of-government Cyber Dialogue, fourth in the series, was led by the U.S. Cybersecurity Coordinator and Special Assistant to the President Michael Daniel and by India’s Deputy National Security Advisor Arvind Gupta. The Department of State Coordinator for Cyber Issues Christopher Painter and the Ministry of External Affairs Joint Secretary for Policy Planning, Counterterrorism, and Global Cyber Issues Santosh Jha co-hosted the Dialogue. U.S. whole-of-government participation included the Departments of State, Justice, Homeland Security, Treasury, and Commerce. The Indian government was represented by the National Cyber Security Coordinator at the National Security Council Secretariat, the Ministry of External Affairs, the Ministry of Home Affairs, and the Ministry of Communication and Information Technology.
The delegations discussed a range of cyber issues including cyber threats, enhanced cybersecurity information sharing, cyber incident management, cybersecurity cooperation in the context of “Make in India,” efforts to combat cybercrime, Internet governance issues, and norms of state behavior in cyberspace.
The two delegations identified a variety of opportunities for increased collaboration on cybersecurity capacity-building, cybersecurity research and development, combating cybercrime, international security, and Internet governance, and intend to pursue an array of follow-on activities to bolster their cybersecurity partnership and achieve concrete outcomes.
In addition to the formal Dialogue, the delegations met with representatives from the private sector to discuss issues related to cybersecurity and the digital economy. The Indian delegation also met with Deputy Secretary of State Antony Blinken and Assistant to the President for Homeland Security and Counterterrorism Lisa Monaco.
The two countries decided to hold the next round of the Cyber Dialogue in Delhi in 2016.
source: whitehouse.gov
To increase global cybersecurity and promote the digital economy, the United States and India have committed to robust cooperation on cyber issues. To that end, the United States and India met at the U.S. Department of State in Washington, DC on August 11 and 12 for the 2015 U.S.-India Cyber Dialogue.
The whole-of-government Cyber Dialogue, fourth in the series, was led by the U.S. Cybersecurity Coordinator and Special Assistant to the President Michael Daniel and by India’s Deputy National Security Advisor Arvind Gupta. The Department of State Coordinator for Cyber Issues Christopher Painter and the Ministry of External Affairs Joint Secretary for Policy Planning, Counterterrorism, and Global Cyber Issues Santosh Jha co-hosted the Dialogue. U.S. whole-of-government participation included the Departments of State, Justice, Homeland Security, Treasury, and Commerce. The Indian government was represented by the National Cyber Security Coordinator at the National Security Council Secretariat, the Ministry of External Affairs, the Ministry of Home Affairs, and the Ministry of Communication and Information Technology.
The delegations discussed a range of cyber issues including cyber threats, enhanced cybersecurity information sharing, cyber incident management, cybersecurity cooperation in the context of “Make in India,” efforts to combat cybercrime, Internet governance issues, and norms of state behavior in cyberspace.
The two delegations identified a variety of opportunities for increased collaboration on cybersecurity capacity-building, cybersecurity research and development, combating cybercrime, international security, and Internet governance, and intend to pursue an array of follow-on activities to bolster their cybersecurity partnership and achieve concrete outcomes.
In addition to the formal Dialogue, the delegations met with representatives from the private sector to discuss issues related to cybersecurity and the digital economy. The Indian delegation also met with Deputy Secretary of State Antony Blinken and Assistant to the President for Homeland Security and Counterterrorism Lisa Monaco.
The two countries decided to hold the next round of the Cyber Dialogue in Delhi in 2016.
source: whitehouse.gov
29 July 2015
China, New National Security Law, Effort to Control Cybersecurity
China Adopts the New National Security Law - a Top Legislative Effort to Control Cybersecurity | DLA Piper - JDSupra:
more news links below (on mobile go to web version link below)
Follow @expvccom
more news links below (on mobile go to web version link below)
Follow @expvccom
09 June 2015
Privacy, Cybersecurity, Updates
Privacy & Cybersecurity Update - May 2015 | Skadden, Arps, Slate, Meagher & Flom LLP - JDSupra:
more news links below (on mobile go to web version link below)
Follow @expvccom
more news links below (on mobile go to web version link below)
Follow @expvccom
02 June 2015
Information Sharing, Cybersecurity Strategy
Information Sharing Can Help Fortify Your Cybersecurity Strategy | Polsinelli - JDSupra:
more news links below (on mobile go to web version link below)
Follow @expvccom
more news links below (on mobile go to web version link below)
Follow @expvccom
25 March 2015
Internet Governance Forum 2015, João Pessoa, Brazil, 10-13 Nov 2015
Internet Governance Forum: "IGF 2015 The Tenth Annual IGF Meeting is scheduled to take place in João Pessoa, Brazil, on 10-13 November 2015. [NEW] Overarching Theme and Sub-Themes After consulting the wider Internet community and discussing the overarching theme of the 2015 IGF meeting, the Multistakeholder Advisory Group decided to retain the title “Evolution of Internet Governance: Empowering Sustainable Development”. This theme will be supported by eight sub-themes that will frame the discussions at the João Pessoa meeting: Cybersecurity and Trust; Internet Economy; Inclusiveness and Diversity; Openness; Enhancing Multistakeholder Cooperation; Internet and Human Rights; Critical Internet Resources; Emerging Issues. Refer to the MAG Chair's Blog for further information."
more news links below (on mobile go to web version link below)
Follow @expvccom
more news links below (on mobile go to web version link below)
Follow @expvccom
18 January 2015
Top Cybersecurity Reads in 2014
JD Supra's Top Cybersecurity Reads in 2014 | JD Supra Perspectives - JDSupra:
more news links below (on mobile go to web version link below)
Follow @expvccom
more news links below (on mobile go to web version link below)
Follow @expvccom
13 November 2014
US State Department on ITU Plenipotentiary 2014: "We Won!"
Morning Tech - POLITICO.com: (11 Nov 2014) "U.S. ITU DELEGATION CROWS ABOUT INTERNET GOVERNANCE SUCCESS. The U.S. delegation is claiming credit for keeping major cybersecurity and Internet governance issues off the table at the ITU's recently-closed plenipotentiary in South Korea...."
"The International Telecommunication Union (ITU) Plenipotentiary Conference, which concluded on November 7, is a three week, high-level policy conference held every four years. Ambassador Daniel Sepulveda, U.S. Coordinator for International Communications and Information Policy, led the U.S. delegation to a successful outcome that will greatly support the development of global telecommunications infrastructure and networks. The Plenipotentiary Conference sets the ITU general policies, adopts four-year strategic and financial plans, and elects the ITU senior management team, members of Council, and members of the Radio Regulations Board for the next four years.
"The U.S. delegation achieved its four primary objectives, and all outcomes were agreed by consensus with other member states. The U.S. delegation was elected to another four year term on the ITU Council with more votes than we received four years ago, and Ms. Joanne Wilson was elected to the Radio Regulations Board (RRB). Member states improved the ITU’s fiscal and strategic management and transparency policies and improved the ability of all stakeholders to view and participate in the work of the Union. The member states agreed to no changes to the ITU’s legal instruments (the Constitution and Convention of the Union). Finally, member states decided not to expand the ITU’s role in Internet governance or cybersecurity issues, accepting that many of those issues are outside of the mandate of the ITU. The leadership of the U.S. delegation was instrumental to each of these efforts.
....
Internet and Cybersecurity Issues
"The United States built a broad consensus that led to success on Internet and cybersecurity issues keeping the ITU’s work focused on its current mandate. The United States worked with other members to mitigate and remove proposed language from resolutions that would have improperly expanded the scope of ITU work and curtail the robust, innovative, multi-stakeholder Internet we enjoy today, while providing clear guidance to the ITU on the efforts it can and should work on.
"The U.S. also worked successfully with partners to eliminate proposed language that could have provided a mandate for the ITU in surveillance or privacy issues; inhibited the free flow of data; regulated Internet content and service companies; undermined the multi-stakeholder process; or called on the ITU to develop international regulations on these issues.
"Finally, a compromise was reached on the Council Working Group on International Internet-related Public Policy (CWG-Internet), which will provide for physical consultation meetings, open to all stakeholders, to be held prior to each of the CWG-Internet meetings. These meetings will allow all Internet stakeholders to directly contribute to the work of the CWG-Internet....." (emphasis added, read more at the link above)
More information and public statements on the ITU Plenipotentiary Conference can be found here:
"The United States built a broad consensus that led to success on Internet and cybersecurity issues keeping the ITU’s work focused on its current mandate. The United States worked with other members to mitigate and remove proposed language from resolutions that would have improperly expanded the scope of ITU work and curtail the robust, innovative, multi-stakeholder Internet we enjoy today, while providing clear guidance to the ITU on the efforts it can and should work on.
"The U.S. also worked successfully with partners to eliminate proposed language that could have provided a mandate for the ITU in surveillance or privacy issues; inhibited the free flow of data; regulated Internet content and service companies; undermined the multi-stakeholder process; or called on the ITU to develop international regulations on these issues.
"Finally, a compromise was reached on the Council Working Group on International Internet-related Public Policy (CWG-Internet), which will provide for physical consultation meetings, open to all stakeholders, to be held prior to each of the CWG-Internet meetings. These meetings will allow all Internet stakeholders to directly contribute to the work of the CWG-Internet....." (emphasis added, read more at the link above)
More information and public statements on the ITU Plenipotentiary Conference can be found here:
- Secretary Kerry’s Statement on the U.S. Delegation to the International Telecommunication Union Plenipotentiary Conference
- Media Note: U.S. Delegation to the International Telecommunication Union Plenipotentiary Conference in Busan, Republic of Korea
- U.S. Government Policy Statement at the International Telecommunications Union Plenipotentiary Conference
Subscribe to:
Posts (Atom)