When it comes to cybersecurity, the criticality of cyber in the functionality of systems creates difficulties in a traditional sense of security. The Defense Department’s chief information officer, Terry Halvorsen, is approaching this issue from a risk standpoint as opposed to security.
“Security by itself doesn’t mean anything. I’m trying to change this discussion now from talking about cybersecurity to appropriate cyber risk. This is a risk decision, it is not a security decision,” he said at the AFCEA NOVA Joint Warfighter IT Day on Thursday. “You’ve got to get the risk right and that means there’s risk.”
This notion has been broached many times in the past using risk management frameworks to address cybersecurity concerns, both within and outside the government. For example, Halvorsen noted that he can have a fully secure system in 10 minutes, however, no one would be able to communicate or perform key mission functions. Rather, security must be a risk assessment in context of the mission, he said.
“Here’s the hard part … security isn’t a constant. Security is going to be more like a rheostat — it’s got to go up in some missions, down in others. Sometimes it goes up because of the threat, sometimes it goes down because of the mission,” he said.
The DoD, Halvorsen added, is designed to go to the highest risk regions of the world. “We don’t generally to places that are low risk. We tend to go to places that are high risk, that’s pretty much where you want me to be too,” he said. “We’ve got to get cyber in that frame. How do we balance security and the mission?”
Systems in security should be resilient and good enough. The resiliency model of security is best summed up from the standpoint that everyone will be hacked; the issue is figuring out how to fight through it.
Paraphrasing Cyber Command’s commander, Adm. Michael Rogers, Halvorsen said it’s not about preventing an attack, but figuring out how to operate in the event of an attack, and fight through it. “You’re not going to just be able to stop [operations],” he noted.
In some of the early cyber exercises, some of the answers folks came up with was to turn the systems off, he said, adding: “If you do that the bad guys have won. … You’re now slower.”
Halvorsen said security has costs, and organizations — DoD included — have to worry about how much security costs. One can price themselves out, Halvorsen said, trying to make systems 100 percent secure.
He also mentioned some items he’s hoping for going forward, one being the frequency hopping radios equivalent in networks. “That effect can be: How do you change networks on a dime? … How do we get that concept of being able to move agily and do that in an environment that includes all the partners I talked about?”
Also at the top of his wish list: a communications device that can operate in every communication range and mode. “Maybe I have this small, really cheap drone flying over a Stryker unit pumping down very accurately tuned wireless. Could I use that in lieu of standard radio?” he posited. “And maybe it has in it, just for fun, something that might help me detect IEDs. And could do precision navigation and timing that I could target with. That’s the first thing on my Christmas list.”
Halvorsen: Cybersecurity must be a risk assessment in context of mission




