[113176] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Wow, just when you though big government was someone else's

daemon@ATHENA.MIT.EDU (Michael Barker)
Sun Apr 5 13:01:06 2009

From: Michael Barker <mbarker@cyrusnetworks.com>
To: "Valdis.Kletnieks@vt.edu" <Valdis.Kletnieks@vt.edu>, "Suresh
	Ramasubramanian" <ops.lists@gmail.com>
Date: Sun, 5 Apr 2009 12:58:50 -0400
In-Reply-To: <125734.1238919185@turing-police.cc.vt.edu>
Cc: "nanog@nanog.org" <nanog@nanog.org>, Jeff Young <young@jsyoung.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

Seems like they're following up on Department of Defense Directive 8570.01,=
 whereas all Information Assurance personnel (that being defined as anyone =
with privileged access) are required to be certified.

Fully policy manual is here.
http://www.dtic.mil/whs/directives/corres/pdf/857001m.pdf


-----Original Message-----
From: Valdis.Kletnieks@vt.edu [mailto:Valdis.Kletnieks@vt.edu]=20
Sent: Sunday, April 05, 2009 4:13 AM
To: Suresh Ramasubramanian
Cc: nanog@nanog.org; Jeff Young
Subject: Re: Wow, just when you though big government was someone else's pr=
oblem

On Sat, 04 Apr 2009 16:16:24 +0530, Suresh Ramasubramanian said:

> Do you by any chance get to go work on sensitive government networks=20
> without, say, a security clearance?

What the draft actually says:

SEC. 7. LICENSING AND CERTIFICATION OF CYBERSECURITY PROFESSIONALS.

(a) IN GENERAL. - Within 1 year after the date of enactment of this Act, th=
e Secretary of Commerce shall develop or coordinate and integrate a nationa=
l licensing, certification, and periodic recertification program for cybers=
ecurity professionals.

(b) MANDATORY LICENSING. - Beginning 3 years after the date of enactment of=
 this Act, it shall be unlawful for any individual to engage in business in=
 the United States, or to be employed in the United States, as a provider o=
f cybersecurity services to any Federal agency or an information system or =
network designated by the President, or the President's designee, as a crit=
ical infrastructure information system or network, who is not licensed and =
certified under the program.

A few thoughts:

1) Somebody's going to make a mint of money doing certification testing.

2) Somebody's network is going to be left flapping in the breeze because th=
eir provider didn't get certified in time.

3) It's interesting that "providers of cybersecurity services" have to be l=
icensed, although others who do security-relevant work on the system/net do=
n't have to be - nor do they define what a "provider of cybersecurity servi=
ces" is.

So - quick show of hands: If you have a net that this applies to, do you kn=
ow which of your engineers do/don't need a cert? ;)


home help back first fref pref prev next nref lref last post