Albuquerque Journal

Obama seeks $3.1 billion for cybersecur­ity

Government systems are archaic, president says

- BY TAMI ABDOLLAH

WASHINGTON — President Barack Obama said Tuesday he is asking Congress for $3.1 billion to update the government’s archaic computer systems to protect them from cyberattac­ks as part of a new, centralize­d effort to boost cybersecur­ity.

Obama said he will hire a new chief informatio­n security officer — but whose salary would be paltry compared to those paid by big businesses — and expand the government’s troubled “Einstein” intrusion-prevention technology. Obama said some infrastruc­ture is downright ancient, with the Social Security Administra­tion relying on systems from the 1960s that are vulnerable.

“That’s going to have to change,” Obama said, flanked by top national security advisers in the Roosevelt Room. “We’re going to have to play some catch-up.”

Across town, the director of national intelligen­ce, James Clapper, warned Congress that Russia, China, Iran and North Korea are the most serious threats to U.S. informatio­n systems. Clapper also said increasing­ly connected devices and appliances make the country vulnerable in new ways.

Obama’s comments came after the release of his 2017 budget proposal. Obama is asking Congress for $19 billion more in cybersecur­ity funding across all government agencies — an increase of more than from 35 percent from last year.

Dubbed the “Cybersecur­ity National Action Plan,” the White House touted the plan as the “capstone” of seven years of work to build a cohesive federal cybersecur­ity response — an effort that has often faltered in the past.

Obama said some problems could be fixed relatively quickly, but added he was directing his advisers to focus also on anticipati­ng future threats so that cyberse- curity protection­s can adapt.

“I’m going to be holding their feet to the fire to make sure they execute on this in a timely fashion,” Obama said.

Other plans would make it less convenient — but ostensibly more secure — for citizens to access their personal records by increasing use of passwords and PIN authentica­tion. The budget also proposes that the government reduce the use of Social Security numbers for identifica­tion. None of the suggestion­s appeared groundbrea­king or entirely novel. Many were previously suggested in government and industry reports, and some appeared to replicate previous efforts.

“A lot of this stuff is not new,” said Randy Sabett, a former National Security Agency crypto-engineer. Sabett worked on a cybersecur­ity commission report that advised Obama on the subject in 2008. Success would depend on administra­tion leadership, he said, adding: “The window dressing is there; now what’s behind the curtains.”

The hiring of a single high-level official to deal with cyber intruders in federal government networks establishe­s a position long in place at companies in the private sector. The job posting Tuesday indicated it will pay between $123,000 and $185,000 — although the largest companies pay far more for the same job.

The lack of such a government role has been especially notable after hackers stole the personal files of 21 million Americans from the Office of Personnel Management. The new security job is expected to be filled in 60 to 90 days, said Tony Scott, the U.S. chief informatio­n officer. The White House said that person will report to Scott and set and monitor performanc­e goals for agencies. Scott said the person would make sure strategies are consistent­ly applied across agencies.

It remains to be seen whether the person will have enough authority, said Jacob Olcott, a congressio­nal cybersecur­ity adviser.

Newspapers in English

Newspapers from United States