Showing posts with label IdeaScale. Show all posts
Showing posts with label IdeaScale. Show all posts

Sunday, November 3, 2013

DHS ITF IdeaScale Cybersecurity Project – Lack of Support

This may be the last of the blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier posts in this series were:


It has been quite a while since I last wrote about the DHS ITF IdeaScale Cybersecurity Project mainly because there has been little of interest posted to the site. It has been a number of weeks now since the last activity of any sort has taken place. With the recent publication of the Preliminary Cybersecurity Framework, it would seem that there is no longer any need for input via this site.

I have mixed feelings about the limited success seen in this commendable attempt to get detailed input from the public about the complex topic of cybersecurity and the development of the cybersecurity framework. First off it is heartening to see the publication of 23 ‘ideas’ from a wide variety of people, particularly since most of the submitters were not well known commenters on matters of cybersecurity. The broadening of the source of public ideas is always a good thing.

Likewise, I was pleased to see the number and quality of the comments that were offered about these ideas. I don’t recall a single personal attack and the negative comments were all apparently offered in the spirit of constructive criticism. It is nice to see this sort of discussion when the flame war is the more common mode of discourse on internet forums.

I was severely disappointed, however, in the complete lack of feedback from DHS on the ideas discussed on this site. Beyond an occasional ‘nice comment’ posting from anonymous moderators, there is no indication that anyone at DHS looked at, much less considered any of these ideas. Nor have I seen any effort by DHS to publicize this effort.


I have been a strong supporter of the IdeaScale efforts by DHS. I have contributed ideas, comments and votes. I have written about the ideas (both mine and others) posted to the sites and I have strongly recommended that people participate in the various efforts. I will continue to monitor and participate in the ongoing and future IdeaScale, but I can no longer suggest that others do the same. I’ll participate for the same reason that I blog, I have an innate need to put in my two cents worth. It allows me the chance to say ‘I told you so’ when my ideas are ignored. Unless you have a similar need, don’t waste your time participating in the DHS IdeaScale projects.

Saturday, May 4, 2013

DHS ITF Establishes Collaboration Community


DHS has once again partnered with IdeaScale to establish a ‘collaboration community’ to help the DHS Integrated Task Force in the implementation and the coordination of interagency, and public and private sector efforts to support the President’s Executive Order on Improving Critical Infrastructure Cybersecurity (EO 13636). Patterned on previous IdeaScale campaigns on the National Dialogue on Preparedness and the Quadrennial Homeland Security Review, the Integrated Task Force Collaboration Community (ITFCC) allows for public input and discussion of proposals associated with EO 13636 implementation.

DHS is not being real proactive in publicizing this ITFCC. I have seen a single TWEET® on the topic and nothing else. That might explain why there are only four ideas currently on the page after being up for at least a week (that’s the date on the initial suggestion).

Topics

There are three different topic about which the site is soliciting public ideas. They are:


Only the third topic has an extensive explanation of what is being sought. It is also the only topic page that specifically mentions one of the working groups from the ITFCC; Evaluation and Planning Workgroup. They explain that they have already conducted focus group analysis and have come up with a four part purpose of the development of a public-private partnership for the implementation of the EO. Those parts are:

• Evaluate and address critical infrastructure risk through public-private collaboration and collective action across the national preparedness spectrum to prevent, protect against, mitigate, respond to, and recover from all hazards.
• Define and address national priorities for all-hazards critical infrastructure security and resilience through the bidirectional sharing of relevant and actionable information and the identification and exchange of best practices, tools, capabilities, and resources.
• Build and sustain trust, leverage existing, and develop new relationships to ensure the continued maintenance and growth of the partnership.
• Work collaboratively to identify and mitigate organizational and structural barriers to entry to facilitate increased participation by State, local, and private sector stakeholders in regions across the Nation.

Participation

This is a public participation discussion site, open to all comers. To publish new suggestions, make comments, or vote upon on existing suggestions you have to be registered with IdeaScale. People who registered on the two earlier DHS discussions can still use that registration ID and password.

I don’t see a ‘registration’ tool or button, but if you try to vote, make a suggestion, or comment on an existing suggestion you will be prompted to either sign in or register. It has been  a couple of years since I registered on IdeaScale, but I seem to recall that you have a wide latitude in the information that you provide or fail to provide to the site. I can’t vouch for the whole site security thing, but it does provide some fair level of anonymity on the public side if you so desire.

Current Comments

As I mentioned earlier there are only four comments currently posted on the board. They are (in order of current vote totals; highest to lowest):


The first three are glittering generalities that fall into the general ‘motherhood and apple pie’ category. The last is a little more specific but not really directed at cybersecurity concerns. This is one of the problems with these public comment/suggestion exercises; there are very few concrete proposals and more than a few that trend off-topic. Oh well, searching for gems is like that.

Currently there are no comments that directly apply to industrial control system security efforts. I will, however, continue to monitor and report upon this site.

Monday, August 13, 2012

More on New DHS Web Site


Last week I noted that DHS had done an across the board upgrade of their web site. Most of the pages just had their content copied into a new format, so there was no real change in information. The concept of landing pages appears to have been done away with; two that I tracked in particular on chemical security and cybersecurity have disappeared.

Change Notification


As I noted earlier, DHS has done away with the update dates on the bottom of pages that allowed viewers to quickly determine if changes had been made to a page since it was last visited. DHS has continued to make email notification of page changes available on a limited number of pages. In the chemical security arena those pages include:

Critical Infrastructure – Chemical Security - http://www.dhs.gov/critical-infrastructure-chemical-security 

2012 Chemical Sector Security Summit - http://www.dhs.gov/2012-chemical-sector-security-summit

If you have an interest in either of these pages you should certainly sign up for this free service. The only problem that I have seen in the past is that it only provides notification for changes on the specific pages listed. It does not provide notice of changes made on linked pages.

Chemical Security Assessment Tool


The one page that I am extremely disappointed about the lack of email notification for changes is the page dealing with the Chemical Security Assessment Tool (CSAT). This is the single most important part of the CFATS web site for the regulated community and there appears to be no method of communicating changes to this portion of the site.

I am providing the listing of the CSAT web pages below. It includes the links to the latest versions of the various supporting documents (and those links are now active).

Chemical Security Assessment Tool - http://www.dhs.gov/chemical-security-assessment-tool  -

Register to Access CSAT - http://www.dhs.gov/register-access-csat

CSAT User Registration .PDF [10-11 V 5.1] - http://www.dhs.gov/xlibrary/assets/chemsec_csatuserregismanual.pdf


CSAT Account Management .PDF [04-11 V 2.1] - http://www.dhs.gov/xlibrary/assets/chemsec_csatuseraccountmanage.pdf






Top Screen Users Manual .PDF [09-10 V 1.99] - http://www.dhs.gov/xlibrary/assets/chemsec_csattopscreenusersmanual.pdf

CSAT Security Vulnerability Assessment - http://www.dhs.gov/csat-security-vulnerability-assessment









SSP Edit Process User Guide .PDF [10-10 V 0.7] - http://www.dhs.gov/xlibrary/assets/chemsec_csatsspedit_userguide.pdf

Public Comments


DHS is using their successful public feedback program on IdeaScale.com. Comments can be submitted by joining the DHS Redesign community. The same site allows you to look at all of the comments on the design, report issues, and to suggest improvements (I just submitted asuggestion [NOTE: Link added 12:50 EDT 8-13-12] to add the review dates to each page).

These IdeaScale discussions have been very interesting in the past and I expect to see a lot of interesting ideas brought up. I just hope that DHS does a better job in responding to the ideas and suggestions about their web site than they have done in their previous projects on this site.
 
/* Use this with templates/template-twocol.html */