Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Sunday, November 8, 2009

As DHS Cut Senior Nutrition Programs, Top Officials Got Raises

Top administrative staff at the Department of Human Services received almost $200,000 in pay raises in the past year before the agency cut senior nutrition programs, records show.
“These raises were given at a time when the economic situation was bad and getting worse and a budget shortfall was clearly imminent,” said state Rep. Randy Terrill, R-Moore. “In light of the raises, I find it hard to believe DHS could not find any way to save money other than cutting nutritional programs for the elderly.”
Records show 29 of the top 36 administrators at the agency received raises in the past year.

The pay raises ranged between $135 per month to an additional $1,894 per month. The pay raises totaled $16,380 per month and $196,560 per year.
Terrill noted the pay raises were not approved by the Legislature and it is not known if those receiving the raises assumed any additional job responsibilities. Terrill likened DHS officials’ actions to AIG executives who received millions in bonuses after obtaining taxpayer-funded bailout money from the federal government.

“DHS has violated the sacred trust with our seniors in the same way many greedy Wall Street robber barons violated the trust of the taxpayers who bailed them out,” Terrill said.
He said the case illustrates the need for even greater scrutiny of agency budgets as lawmakers revise appropriations due to the downturn.
“This unconscionable series of events calls into question the judgment of DHS’ senior management,” Terrill said. “With state workers facing furloughs or layoffs, the Legislature should scrub every agency budget to determine whether the DHS abuses are an isolated case or just the tip of the iceberg. Somehow, I suspect the latter.”
Even Demo State Sentor
Debbe Leftwich think this is
WRONG!


Oklahoma State Senate Communications Division
State Capitol

Oklahoma City, OK 73105

405-521-5774

FOR IMMEDIATE RELEASE –


State Sen. Debbe Leftwich said it was unconscionable for the Department of Human Services (DHS) to pass out nearly $200,000 in pay hikes at a time when the agency has cut $7.4 million from senior nutrition programs. Leftwich said while many employees at DHS and other state agencies are underpaid, raising salaries while cutting senior nutrition is the wrong thing to do. She applauded House member Randy Terrill, R-Moore, for bringing attention to the situation on Wednesday.

“This is outrageous, but it proves what I’ve said many times—DHS has deep pockets when it comes to something they want, like these raises. We have seniors who are literally going to suffer because of the cuts to the nutrition program, but the bureaucrats claim they couldn’t make cuts elsewhere,” said Leftwich, D-Oklahoma City. “This is indefensible.”

DHS has argued the raises were a necessary market-rate adjustment. Twenty-nine of the top 36 administrators at DHS have been given raises ranging from $135 to $1,894 per month.

“We have agencies that are being forced to leave empty posts unfilled, furlough remaining workers and cut programs, yet DHS proceeded with these raises. It’s just unbelievable,” Leftwich said. “For years I’ve tried to move state services for seniors out of DHS and other agencies to a stand-alone entity that will make taking care our older Oklahomans the priority it should be. As far as I am concerned, this action by DHS just underscores why they should not be entrusted with programs older Oklahomans need to survive.”

Friday, April 17, 2009

HOO-AH to Steve Russell (Lt. Col., U.S. Army Ret.)

HOO-AH to Oklahoma State Senator
Steve Russell (Lt. Col., U.S. Army Ret.)
for taking a stand for us Vets !!


SENATOR PROPOSES RESOLUTION OPPOSING OBAMA ADMINISTRATION’S POSITION ON ‘RIGHT WING’ EXTREMISTS AS POSSIBLE NATIONAL SECURITY THREATS

Senators Take Exception to Characterization of Veterans, Pro-Lifers, etc. as ‘Right-Wing Extremists’

Responding to a report of the Obama administration’s Department of Homeland Security (DHS) characterizing returning veterans and others who uphold traditional American values as “right wing extremists” and a threat to American security.

The nine-page document from the DHS titled "Rightwing Extremism: Current Economic and Political Climate Fueling Resurgence in Radicalization and Recruitment," has caused an outcry from veterans groups, Republican lawmakers and conservative activists.

"It may include groups and individuals that are dedicated to a single issue, such as opposition to abortion or immigration," said the report, which also listed as suspect gun owners and veterans of the Iraq and Afghanistan wars.

The outcry resulted in a demand from the head of the American Legion to meet with Ms. Napolitano, a request the DHS chief said she would honor next week when she returns to Washington from her current tour of the U.S.-Mexican border.

Sponsored by Senator Steve Russell, a retired Army Colonel and veteran of both Iraq and Afghanistan, Senate Resolution 42 demands that President Obama’s Administration ‘retract this report and apologize to America’s returning war veterans.’ “To suggest that we would terrorize the very nation we risked our lives for should give all Americans pause,” said Russell.

“Yesterday afternoon I participated in a rally with thousands of good, law-abiding, God-fearing Oklahomans who voiced their concerns about the Federal government’s expenditures of our hard-earned dollars,” said Russell, referring to the Tea Party rally that was held on the steps of the State Capitol. “According to the Department of Homeland Security report, these people would also be considered threats to the national security.

“It is vital that we take a stand and express, in our constitutional right to peaceful assembly and our extreme displeasure and disagreement with the Administration on this important matter,” Russell continued.

“Taken at face value, this report from our Department of Homeland Security would qualify the vast majority of Oklahomans as threats to our national security,” Russell added. “If upholding traditional American values such as the sanctity of life, the right to bear arms and defending your country is extremist, then I stand so accused,” Russell concluded.

Senate Resolution 42 further states that the Oklahoma State Senate supports America’s military veterans, who have risked their lives preserving the nation instead of attacking it, and believes that the traditional American values under attack by the Obama Administration should be respected and revered by the federal government.

The Resolution will likely be heard in the Senate on Wednesday.

Wednesday, March 11, 2009

Legislation Implementing DHS Audit Recommendations Passes House

Legislation aimed at reducing the number of children removed from their home with the help of social workers and in-home services for parents passed the House today.

House Bill 1734 seeks to implement several recommendations of an audit of the Department of Human Services, including a requirement that law enforcement consult with DHS before removing a child; the creation of a passport program to allow information about a child’s physical and behavioral health and educational needs to be available electronically; implementation of a phase-out of public shelters; establishment of a centralized statewide hotline for all reports of abuse and neglect of children; and a reorganization of the department offices in Tulsa and Oklahoma Counties.

“The title is off this bill and we will continue to work with all interested parties to make sure this legislation keeps children in our state safe,” said Rep. Ron Peters, author of the bill and chairman of the House Appropriations Subcommittee on Human Services. “We will make it safer for children to stay in their homes with improved risk and safety assessments and increased home services for parents who genuinely want to take care of their children. These changes will allow DHS workers to focus more of their time on the true cases of abuse.”

The audit came after five months of extensive study by the independent auditing firm Hornby Zeller Associates.

House Speaker Chris Benge formed a bipartisan working group last year to study the issue made up of Reps. Peters, Kris Steele and Pam Peterson, Jeannie McDaniel, Wade Rousselot and Richard Morrissette. The group called for the performance audit as a way to determine what changes are needed to the system.

The legislation also calls for improved and expanded training for DHS workers to better assess the risk to and safety of a child. The change, coupled with the recommendation for DHS workers to be directly involved in child removals, would help to prevent children from being removed from the home needlessly, which puts undue burdens on the child and the system itself, said Peters, R-Tulsa.

In Oklahoma, the audit shows that 20 percent of children removed from their home are returned within one week of removal. In the Tulsa area, 40 percent of children removed are returned home in that same timeframe.

“The safety of our children is the utmost goal here, and I am hopeful we will be able to bring real change to the system with this legislation,” said Benge, R-Tulsa.

The legislation passed the House today with a vote of 87-8 and will move to the Senate for consideration.

Friday, January 23, 2009

REAL ID Act: Maryland may have to delay federal Real ID program


State may have to delay federal
Real ID program

High costs and requiring legal residency may delay Maryland's progress with the Real ID program, even though the state has met fewer than half the requirements for the federal driver's license mandate.

"I think it's unlikely we'll do anything this year, and it's going to be a tremendous burden on this state," Sen. Brian Frosh, D-Montgomery, said at a hearing Wednesday. He serves as chairman of the Senate Judicial Proceedings Committee.

The federal law has tougher requirements for getting driving licenses, including being a legal resident.

The U.S. Department of Homeland Security issued 18 benchmarks that states must meet to get a second extension, to May 2011, for Real ID implementation.

The Motor Vehicle Administration has met eight of those requirements. Most were already in place and therefore cost nothing to implement.

Four remain unfulfilled because the state doesn't check applicants' residency status, according to MVA administrator John Kuo.

MVA has the technology to check legal status, so it wouldn't cost more money if legal status were added as a requirement, Kuo said.

Between 35 percent to 50 percent of the out-of-country applicants are rejected for driver's licenses because they don't have enough proof they are Maryland residents or don't have proper documentation, the administrator said.

The General Assembly must grant approval to the residency requirement.

Some lawmakers say Real ID is a way to thwart terrorism and reduce illegal immigration. Others view the program as an invasion of privacy and fear it could lead to undocumented people driving without licenses.

In the 47 states that require drivers to have legal status, "I bet there are a lot of people driving without licenses," said Sen. Jennie Forehand, D-Montgomery.

The state can reject the Real ID requirements, but that would mean Maryland licenses couldn't be used to enter federal buildings or board planes.

Kuo said a two-tier system, in which those without legal status could obtain a driver's license but not be federally compliant, is an alternative. But he said that would put an administrative and fiscal burden on MVA.

Real ID is expected to cost Maryland $30 million to implement. The federal government has given the state $1.1 million, with another $700,000 coming this fiscal year.

Delegate Ron George, R-Anne Arundel, again plans to submit a bill requiring legal status for driving licenses, pointing to the large number of foreign applicants at the MVA.

Friday, January 9, 2009

Democrats weigh IT money for DHS in stimulus bill

The economic stimulus package under consideration by key Democrats could include funding for the Homeland Security Department -- possibly as much as $2 billion, congressional and industry sources said today.

Talk has surfaced about the inclusion of hundreds of millions of dollars for Customs and Border Protection, the Transportation Security Administration and the Coast Guard, sources said.
Funding could be sought to help states comply with the so-called Real ID law, which requires them to issue secure driver's licenses to their citizens.
The push for the funding appeared to be coming from both lawmakers and the homeland security industry. "Everything's in play," one source said. But aides for the Senate and House Appropriations committees could not confirm specific homeland security efforts that might be included in the stimulus and sources cautioned that nothing has been decided.

Sources pointed to an economic stimulus bill proposed by former Senate Appropriations Chairman Robert Byrd in November as a blueprint, which sought to provide more than $2 billion for Homeland Security agencies. Funding in the bill included $500 million for TSA to buy and install explosives detection equipment, about $300 million for the Coast Guard and another $300 million for border security, especially to expedite the deployment of technology to the southwest border.

The bill called for another $100 million to improve infrastructure at the nation's ports of entry and about $350 million to consolidate the Homeland Security Department headquarters in Washington. An industry source said it is likely that the stimulus bill will include funding to improve ports of entry and for TSA baggage-screening operations.

Another source added that other infrastructure improvements in the bill, such as for bridges, could include security measures, such as video cameras or perimeter protections.

"It's a great opportunity now. Security was an afterthought before. Now you have the opportunity to do those things up front," the source said.

Friday, October 24, 2008

U.S. to miss deadline on Mexico border fence...

WHY ????

The United States will miss its deadline to complete a security fence along the Mexican border this year, Homeland Security Secretary Michael Chertoff said on Thursday.


"I don't think we're going to hit the nail on the head and be done by the end of the year," Chertoff told Reuters, adding that about 370 miles (595 km) of the planned 670-mile (1,070-km) fence had been completed.

Chertoff said he hoped when the Bush administration leaves office in January about 90 to 95 percent of the fence.

"We've gotten most of the way there. We will be very substantially close," he said in an interview.

Congress has mandated that the fence, which will eventually stretch from California to Texas to help stem the tide of illegal immigration, be finished this year but law suits have slowed its progress.

"We've had some delay because the court proceedings in Texas have gone more slowly than I thought ... Although every time there's actually been a legal challenge, we've won," Chertoff said.

The nearly 2,000-mile 3,200-km border with Mexico is the main entry route for illegal immigrants into the United States, which is already home to 11 million to 12 million undocumented aliens.

Better enforcement have slowed the influx however. Border patrol agents arrested 880,000 people crossing illegally in 2007, down from 1.1 million a year earlier.


Chertoff said progress was being made on other measures aimed at boosting border security, including moves to double the number of border patrol personnel on the job to more than 18,000 by the end of 2008.

"We will hit the 18,000 target," he said.

He said that plans for a $21 million expansion of a high-tech "virtual fence" along parts of the border were being implemented and the first test section was yielding results.

"We've used it to catch thousands of illegal migrants we've also seized several tons of marijuana," he said.

The government announced this year that it was awarding Boeing Co contracts to build two sections of the fence that would include fixed towers, radar and ground sensors, remote control cameras and software linking border agents.

Friday, October 3, 2008

New manager takes on troubled border security program

In less than four months, the Homeland Security Department will hand off border security programs to a new administration that are over cost, behind schedule and downsized from original plans, according to lawmakers, congressional investigators and industry officials.

Despite three years of work and nearly $1 billion in taxpayer's money, the department's so-called SBInet program has not met goals and expectations, the critics said. The program -- aimed at using technology and traditional fencing to control the nation's borders -- faces even more upheaval and overhaul as a new program manager takes over the reins.

In one of the biggest changes so far, the department had to forgo planned technology investments for the remainder of this year in order to have enough money and time to erect more physical fencing and vehicle barriers by December.

Facing a surge in fencing costs, the department notified Congress that it needs to reprogram nearly $400 million to meet its obligations, of which more than $200 million was originally intended for surveillance systems, cameras and computer software. And, most recently, the department notified its SBInet contractor, Boeing Integrated Defense Systems, it does not intend to give Border Patrol agents a mobile common operating picture during the next phase of the program, CongressDaily has learned.


In what sources on and off the Hill described as an abrupt but necessary move, Customs and Border Protection announced Sept. 19 it was replacing its manager for the overall Secure Border Initiative with retired Air Force Col. Mark Borkowski. "There is nothing sacrosanct," Borkowski said, referring to his approach to SBInet. "It's clear to me that it looks like [SBInet] lacks focus," he added. "I'm going to presume that what it looks like is accurate and I'm going to act accordingly."

Borkowski said he needs to determine if the SBInet program has the right management structure, authorities and personnel. He said he will review whether Boeing is the right contractor for the program.

Homeland Security and industry officials admit SBInet has had setbacks, but contend the program is not as troubled as it appears. They say the system is operating around the clock in one spot south of Tucson, Ariz., and recently contributed to the seizure of 4,000 pounds of marijuana. And now that the department has made construction of physical fencing a top priority, they say, the program can focus on systems integration and testing before deploying technology for follow-on phases.


But at this point, CBP has informed Boeing it does not intend to give Border Patrol agents a mobile computer in their vehicles that connects them to a common operating picture -- essentially identical displays of visual information, congressional and industry sources said. A congressional aide said lawmakers will have no patience for more problems in follow-on phases, given that the department and Boeing now have more time to test and integrate technology.

Wednesday, September 24, 2008

Homeland Security replaces head of troubled border program

After coming under heavy congressional fire for technical problems and cost overruns surrounding efforts to build virtual fencing along the nation's borders, the Homeland Security Department has replaced the official in charge of the multibillion-dollar program, CongressDaily has learned.

Sources on and off the Hill said they hope the removal of Gregory Giddens as chief of the Secure Border Initiative will breathe new life into the troubled program.

The most problem-plagued program that Giddens managed was SBInet, which is focused on using both technology and traditional fencing to secure the nation's borders.

For congressional aides, the likelihood Giddens would be removed became clearer when the department stopped sending him to Capitol Hill to testify about SBInet and instead sent top Customs and Border Protection officials.

"Given the problems with the program and the spotlight on it I don't think you'll find a lot of people surprised about them pulling Greg," a congressional aide said. "The program has suffered public blows and they want a fresh start, particularly as they transition it to the next president."

Sources said they were not aware of anything improper that Giddens did. He has been named executive director for facilities management and engineering in CBP's finance office.

The department has named Mark Borkowski as the new executive director for the Secure Border Initiative.

Borkowski has been serving as a program manager for the U.S. Border Patrol and has 25 years of experience in large systems acquisitions and program management for NASA and the Air Force, according to CBP.

"I've heard through the grapevine that's he's a good fixer," an industry source said of Borkowski.

Sources said the decision to give Borkowski the job likely means that Border Patrol Chief David Aguilar is taking more control of the program to ensure it meets the needs of agents in the field.

"On balance, I want to think that it will be very good for the program simply because whoever now comes in can have an opportunity to address the issues that have seemed to make GAO and Congress so disgruntled," another industry source said.

"Sometimes it's good to get a new coach on the team even though there might not be anything wrong with the old coach."

CBP Deputy Commissioner Jayson Ahern praised Giddens in a statement, saying he developed a comprehensive border security strategic plan and built up the SBI program office "to design and deploy the technological systems, tactical infrastructure, and transportation services required to gain control of our borders."

Congressional oversight committees will likely give Borkowski little time to settle into his new post before they pepper him with questions and outline their expectations. Lawmakers will let him know that patience is running thin to correct deficiencies.

"SBInet has encountered numerous setbacks ... I plan to hold the department accountable for getting SBInet back on track and securing our borders," said House Homeland Security Border Subcommittee Chairwoman Loretta Sanchez, D-Calif.

GAO released a report Monday with blistering criticism of SBInet, along with summaries of several reviews it has made of the program.

"Important aspects of SBInet remain ambiguous and in a continued state of flux, making it unclear and uncertain what technology capabilities will be delivered, when and where they will be delivered, and how they will be delivered," GAO said.

"The absence of clarity and stability in these key aspects of SBInet impairs the ability of the Congress to oversee the program and hold DHS accountable for program results, and it hampers DHS's ability to measure program progress," GAO added.

Wednesday, August 20, 2008

Implications of Russian Cyber Battles






Implications of
Russian Cyber Battles

By Colin Clark

When the history of the Russian invasion of Georgia is written, one of the most revealing discussions may center on the role of cyber warfare.

Some questions that will need answering: Just when did Russian hackers begin their attacks on the Georgian websites. Just what role did NATO — especially Estonian and American — cyber warriors have in guiding the Georgian response. Was the enormous three-week attack on Estonia last April from Russia a practice run for the Georgian attack?

When the Russians crippled Estonia’s cyber infrastructure, NATO dispatched top cyber war experts to investigate and to improve the Estonians’ electronic defenses.

It seems reasonable that, in the event of a true combined operation against the Georgians, NATO dispatched cyber experts to help though I haven’t confirmed that yet. There are numerous reports that Estonia has sent cyber warriors to help the Georgians combat both countries historic nemesis.

Official and unofficial Pentagon spokesmen refused to comment on whether the US might or might not be assisting the Georgians in their efforts to protect their Internet infrastructure.

However, one source said that if any US agency would be helping the Georgians it would be the Department of Homeland Security. The reason: if the Russians were to learn the Pentagon was assisting the Georgians they could claim the US was waging cyber war against them.

And US policy is that attacks on our computer systems can be considered an act of war, a logic the Russians would be sure to follow.
If DHS is assisting the Georgians then we can make it very clear that US efforts are purely defensive. Also, DHS is home to the Computer Emergency Response Team.

All this raises questions about the US approach to cyber warfare — not defensive and security measures, but the willingness to use the web to attack an enemy to blunt or cripple their offensive capabilities.

As one of my wittier sources put it earlier today: Are the Georgians really more afraid of a cyber attack than of all those missiles raining down on their heads. The global World Wide Web may be incredibly resilient, but local web connections can be seriously disrupted by those old timey capabilities known as kinetics. Destroy phone or cable connections –easily done with artillery or bombs — and you’ve made it a lot harder to rebuild and reconnect than would a denial of service attack. On top of the destruction, an enemy can send a much clearer and simpler signal than can be done through cyber attacks. On the other hand, it is the very ambiguity of a cyber attack that can make it such a powerful tool in the times before a conflict erupts. Ask the Russians and the Estonians.

Saturday, March 22, 2008

Chertoff: ID must comply to fly


Chertoff: ID must comply to fly
By DEVLIN BARRETT

Homeland security officials on Friday hinted at a possible face-saving deal to end their standoff with a handful of states over new driver's license rules — a dispute that, left unresolved, could cause big air travel headaches.

For weeks, the Homeland Security Department has been headed toward a showdown with some states over a law called Real ID, which would require new security measures for state-issued driver's licenses. Yet a late Good Friday letter from a top DHS official suggested Washington may be backing away from a messy fight.

South Carolina, Maine and Montana are the only states that have not sought extensions to comply, or already started toward compliance with Real ID, which was passed after the 2001 terror attacks on New York and Washington.

On Friday, the federal agency granted Montana an extension, even though state officials didn't ask for one and insist they will not adhere to the Real ID law.

Montana Gov. Brian Schweitzer told The Associated Press that DHS "painted themselves in a corner."

A fourth state, New Hampshire, has asked to be exempted, but Homeland Security officials have not found that letter legally acceptable, so the Granite State has not received an extension.

Homeland Security Secretary Michael Chertoff had warned that if holdout states do not send a letter by the end of March seeking an extension, come May, residents of such states will no longer be able to use their driver's licenses as valid ID to board airplanes or enter federal buildings.

Such travelers would instead have to present a passport or be subjected to secondary screening.

Five senators — Susan Collins and Olympia Snowe of Maine, Jon Tester and Max Baucus of Montana, and John Sununu of New Hampshire — appealed to Chertoff last week to exempt all 50 states from the looming deadline.

Chertoff responded that it was not he but Congress that picked the date when the law went into effect in 2005.

"You may disagree with the foregoing law, but I cannot ignore it," Chertoff said in the letter.

The law, he said, is necessary for national security according to recommendations from the commission that studied the Sept. 11, 2001, attacks.

Yet hours after Chertoff sent those letters Friday, DHS Assistant Secretary Stewart Baker wrote to the attorney general of Montana, saying that even though the state was explicitly not seeking an extension, it would be granted one anyway. Baker reasoned the state's new license security measures already met many of the Real ID requirements anyway.

"I can only provide the relief you are seeking by treating your letter as a request for an extension," Baker wrote.

Schweitzer, Montana's Democratic governor, said his state had not backed down.

"We sent them a horse. If they choose to call it a zebra, that is their business," said Schweitzer.

The agency's approach to Montana could provide an easy way out for the remaining states resistant to Real ID — and suggests the federal government doesn't want to go ahead with its plan to conduct extra screening on residents of certain states.

If the two sides can't cut a face-saving deal, Chertoff has offered a blunt warning to those critics who claim the government is bluffing. "Showing up at the airport with only a driver's license from such a state will be no better than showing up without identification," he wrote to the senators. "No doubt this will impel many to choose the inconvenience of traveling with a passport."

The end of the standoff with Montana does not necessarily mean the entire fight is over.

South Carolina Gov. Mark Sanford was considering legal action, and the state's attorney general was preparing an opinion on whether the governor would have a case if he decided to sue the federal government. A spokesman for Attorney General Henry McMaster said the opinion will be released Monday.

Chertoff has offered a plan to gradually implement Real ID requirements over a period of 10 years, so that eventually all driver's licenses would have several layers of security features to prevent forgery. They would also be issued only after a number of identity checks, including immigration status and verification of birth certificates.

Critics of the plan say it is too expensive, an invasion of privacy, and won't actually make the country safer.


___

Associated Press writer Matt Gouras in Helena, Mont., contributed to this report.

Tuesday, March 11, 2008

DHS stages cyberwar exercise

DHS stages cyberwar exercise
by Shaun Waterman
Washington


Officials from 18 federal agencies, nine states, four foreign governments and more than three dozen private companies will take part in a cyberwar exercise staged by the U.S. Department of Homeland Security this week.

The war game, codenamed Cyber Storm II, will run Monday to Thursday, based at U.S. Secret Service headquarters in Washington. It is the second DHS biannual cyber-exercise, designed to test the ability of federal agencies and their partners in state, local and foreign governments and the private sector to respond to and recover from cyberattacks on their computer networks.

"The goal of Cyber Storm II is to examine the processes, procedures, tools, and organizational response to a multi-sector coordinated attack through, and on, the global cyber infrastructure," says a fact sheet from the department.

Details of the planning for the event are closely held, in part to avoid tipping off participants. The fact sheet says only that the exercise -- the culmination of more than 18 months of planning led by DHS' National Cyber Security Division -- will simulate a series of coordinated physical and cyberattacks on IT and communications systems and chemical, rail and pipeline infrastructure.

The attacker is not identified, but has "a specific political and economic agenda," says the fact sheet. In the last Cyber Storm exercise in 2006, the enemy was an anarchistic coalition of "hacktivists" -- politically motivated hackers -- called the Worldwide Anti-Globalization Alliance, joined by a number of "independent actors."

In the scenario, the attackers penetrated state health records' databases, attacked Federal Aviation Administration systems and defaced newspaper sites.

"Key elements of the hacker attack plan were to strike at trusted cyber systems that were used to control both physical infrastructures and digital commerce and services," says the DHS' after-action report, released in September 2006. "The attackers focused on maximizing economic harm and fomenting general distrust of big business and government by disrupting services and misleading news media and other information outlets."

The choice of adversary -- which the report stressed "was neither a forecast of any particular threats currently existing nor an expression of any specific concerns" -- raised some eyebrows. Among U.S. military planners, nation states, and in particular China, are considered the actually existing adversaries with the most significant capabilities to launch attacks on, or through, the Internet.

One report, by Washington Post blogger Brian Krebs, said Cyber Storm II will feature a nation-state attacker, but a DHS official familiar with the planning said only that this was "a possibility."

The official added that the adversary was "more sophisticated" than in 2006. The scenario was "designed to examine the response to some of the threats that are out there in the real world," he said.

Having a nation-state adversary would make sense, former DHS preparedness chief George Foresman told UPI.

"The top candidates for adversaries would be states, terrorist groups and criminal enterprises" as they were in the real world, said Foresman, who was only involved in the very early stages of planning the event.

As in 2006, the attacks this week will be simulated on special systems set up for the exercise "and will not impact any live networks," says the fact sheet.

Participants in the exercise, which consists of a series of detailed scenarios unfolding according to a strict timetable, will learn of developments via more than 1,700 pre-scripted "injects" in the form of phone calls or e-mails from exercise managers, or through a mock TV news channel set up for the event.

But some of what players will learn from the channel will be bogus, former DHS official Jerry Dixon told Krebs' Security Fix blog.

"They'll inject some red herring attacks and information to throw intelligence analysts and companies off the trail of the real attackers," said Dixon, who helped plan the exercise.

The $6 million event will involve thousands of participants across the world, including from departments of the Australian, British, Canadian and New Zealand governments, and from U.S. agencies including the Department of Defense, CIA, National Security Agency and FBI.

Foresman said the foreign countries participating, all signatories to the 1947 UKUSA intelligence-sharing accords with the United States, were chosen because "there is a shared basis by which you can deal with classified information."

In Australia, which has ramped up its level of participation since the last exercise in 2006, officials from the federal police, Attorney General's Department and AUSCERT -- the Australian national Computer Emergency Response Team -- will all take part, Attorney General Robert McClelland told a news conference Friday.

In New Zealand, participating agencies include the Ministry of Foreign Affairs and Trade, the Ministry of Health, the Customs Service and the New Zealand Defense Forces, according to ComputerWorld.co.nz.

Companies taking part include ANZ National Bank, Cisco Systems Inc., which owns much U.S. Internet infrastructure, Dow Chemical, IBM, computer security firm McAfee, software giant Microsoft and Verizon.

International and private-sector participation is essential, said Foresman. "A cyberattack against the United States with real-world effects inside our borders can be launched from anywhere in the world," he said, adding that the attacks would target or utilize infrastructure owned by the private sector.

Cyber-warfare is "inherently international and inherently private (sector)," he said.

The 2006 after-action report said Cyber Storm I was designed to test basic elements of communication and decision-making in a complex environment of interdependent systems and multiple stakeholders.

"Effective response to the scenario was designed to require rapid communications and de-confliction of critical information between players in all sectors and organizations, as well as strategic integration of information to gain accurate situational awareness," it said.

"It's all about the information," Foresman said, adding that "the ability to communicate highly technical information in real-time" between government officials without a common vocabulary had been a major challenge identified by Cyber Storm I.

"Collaboration between the government and the private sector" was something planners continued to wrestle with. "We haven't mastered that piece yet," he said.

Wednesday, March 5, 2008

DHS gives itself a 'C' for cybersecurity





And DHS

now want our DL info too...

DHS gives itself a 'C' for cybersecurity
By Jill R. Aitoro

The top ranking official in the Homeland Security Department's national protection division called the agency's efforts in cybersecurity satisfactory, assigning a grade of 'C' during congressional testimony Thursday. But members of Congress called the grade inadequate, emphasizing the need for better collaboration with agency technology leaders, real-time response to system attacks, and metrics that measure the ability to protect networks from specific threats rather than system compliance.

DHS officials didn't reveal too many specifics regarding the much anticipated but highly classified initiative during a hearing before the House Homeland Security Committee. Robert Jamison, undersecretary for national protection and programs directorate at DHS, described plans to enhance federal cyber-situational awareness, intrusion detection, information sharing and response capabilities.

The primary means of accomplishing these goals will be the trusted Internet connections initiative, which aims to reduce the number of federal connections to networks outside the firewall, and Einstein, a system that monitors agency networks using an automated process for collecting, correlating, analyzing and sharing computer security information with the U.S. Computer Emergency Readiness Team, or US-CERT. So far, 15 agencies have deployed Einstein.

"The threat is real," Jamison said. "Our adversaries are adept at hiding attacks in normal everyday traffic that comes across the network. The only true way to protect networks is intrusion detection."

The total budget for the comprehensive initiative has not been confirmed, but reports estimate related funds to be in the billions. DHS requested $294 million in its fiscal year 2009 budget for cybersecurity, most of which will go to continued deployment of Einstein. While DHS will lead much of the initiative, individual agencies will be responsible for aspects of cybersecurity efforts, and the Office of Management and Budget will help enforce system compliance across the federal government.

When asked how he would grade DHS in its response to cybersecurity threats, Jamison gave the department "a solid 'C'," which members of Congress called unsatisfactory.

"I would say 'C' is an [accurate] score, but absolutely unacceptable, because they're supposed to lead by example," said Alan Paller, director of research at the SANS Institute, a nonprofit cybersecurity research organization in Bethesda, Md.

Among the problems that lawmakers noted is the tendency by agencies to leave in the dark those charged with protecting networks. Threat analysis conducted by DHS and other national security agencies is largely classified, and therefore not disclosed to chief information officers. Jamison said that efforts to improve situational awareness -- by consolidating the number of external Internet connections and improving intrusion detection -- will increase the amount of information available to agency CIOs.

Both Republicans and Democrats in Congress also stressed the need to move away from a reactionary strategy. Einstein, for example, tracks IP addresses, the size of data packets and where information is flowing network to network, but is largely passive. Information needs to be routinely downloaded and analyzed to detect patterns, malicious addresses and any suspicious activities. Planned enhancements to Einstein will allow real-time response to threats, Jamison said, by finding harmful code and alerting system administrators when intruders attempt access.

"I've been sitting here with my mouth open," said Rep. Jane Harman, D-Calif. "While all of you are well-meaning, the fact that you don't have threat information and are working on projects that will take years to complete is shocking. If we're serious about these threats, we're not being serious about response."

Karen Evans, OMB administrator of electronic government and information technology, hinted at new metrics for gauging the ability of agency networks to combat threats. Certification and accreditation of systems, currently the primary means of measuring agency compliance with cybersecurity efforts, allows agencies to do inventory of what they have in place, while future metrics will test for vulnerabilities.

"When we first started this process ... agencies didn't know what they didn't know," Evans said, loosely quoting a statement made by former Homeland Security CIO, Scott Charbo, during a June 2007 congressional hearing on the same topic. Charbo, who is now the DHS deputy undersecretary of the National Protection and Programs Directorate, also testified at Thursday's hearing.

"Certification and accreditation is a soup-to-nuts process," Evans said. "[Now] we have to move to the next level where we're actually achieving a result rather than doing a paper exercise."

New metrics need to measure how well agencies can withstand known attacks, Paller said.

"The biggest mistake of the last 10 years has been that people kept attacks secret; it caused the government to fall behind. Now that we know better, let's measure systems not on the hypothetical, but on what's real."

Monday, January 14, 2008

DHS revamps driver's license rules to cut costs to states






DHS revamps driver's license
rules to cut costs to states

By Jill R. Aitoro

The Homeland Security Department today announced revamped guidelines for its program of how states issue driver's licenses that the government hopes will curb the criticism from states that previous approaches cost too much and by extending the deadline to issue the more secure licenses by six years to 2014.

The guidelines, spurred by the recommendations of the 9/11 commission and passed into law by Congress in 2005 in the REAL ID Act, establish national standards for state-issued driver's licenses and identification cards to make it harder for illegal immigrants and terrorists to obtain a valid license.

DHS' plan to implement REAL ID was heavily criticized by states and civil liberties groups as being too onerous on citizens and costly, with states claiming REAL ID could cost more than $14 billion. More than a dozen states passed laws or resolutions indicating that they would not comply with the law.

DHS has responded with new guidelines that back away from previous requirements viewed as more onerous, such as requiring a biometric identifier, such as a fingerprint, be attached to the driver's license. The only significant difference now is a requirement that states photograph every person who comes into a department of motor vehicles office to apply for a driver's license. The photograph will be stored in a database so other DMV offices in the state would know if an individual has been denied a license because of improper identification.

"There are burdens states expressed concerning business processes and cost," said DHS Secretary Michael Chertoff, noting the department has received 21,000 comments on the REAL ID law. "[DHS] has taken steps to ... give states flexibility and extend the period of enrollment.

"Chertoff said the revamped guidelines should reduce the costs to states to comply with the law by 75 percent -- from the original estimate of $14.6 billion to $3.9 billion. In addition,

DHS will provide to states $80 million in grants and another $280 million in general funding to help offset costs more.DHS reduced the costs to comply with REAL ID by offering a phased approach, Chertoff said.

In the first phase, to be completed by Dec. 31, 2009, DHS requires states to verify whether applicants are legally eligible to obtain a driver's license by electronically verifying their Social Security numbers with the Social Security Administration. By that date, states also must check if applicants have more than one driver's license, and must conduct background checks for DMV employees and contractors to ensure that they follow proper processes when issuing licenses.

In the second phase, to be completed by May 11, 2011, DHS requires states to begin issuing the new driver's licenses. States have until Dec. 1, 2014, to issue licenses to citizens who are 50 years of age and younger. Individuals older than 50 have until Dec. 1, 2017, to obtain a DHS-compliant driver's license.

As part of the second phase, states also must verify applicants' identification documents by accessing existing databases to make sure the records are valid and be able to confirm the tamper-resistant features of the licenses. In addition, states must store in their DMV database the full name of applicants according to the identity documents that DHS accepts as valid.

Referring to terrorists, illegal immigrants and identity thieves, Chertoff said, "We're going to disappoint all three categories of people" with the guidelines.

But some argue that a 10-year plan for program implementation simply passes off responsibility to future administrations. "In its new REAL ID regulations, the Department of Homeland Security appears to have dumped the problems of the state on a future president," wrote Barry Steinhardt, director of the American Civil Liberties Union's Technology and Liberty Program, and Tim Sparapani, senior legislative counsel for ACLU's Washington legislative office. "REAL ID needs to be repealed; it is not only a threat to Americans' privacy, but it is utterly unworkable.

"States are not required to adopt REAL ID, but licenses that are issued and are not in compliance with REAL ID requirements will not be accepted for boarding commercial flights or for accessing a federal facility. In addition, Chertoff said, states that opt out might face a rush of illegal immigrants entering their borders.

Chertoff dismissed claims that REAL ID infringes on people's privacy, saying no additional information will be collected, nor will any information be needlessly shared. "You could make the argument that you should have a right to get on an airplane and not identify who you are, but if so, you're against all identification," he said. "I don't think that makes sense, and I don't think the American [people] think that makes sense. ... We have to get over [the idea] that every time DHS does something it's evil."

Saturday, January 12, 2008

(Oklahoma) State officials not sold on new DHS rules

State officials not sold on new license rules

State officials and some in Congress remain skeptical about new federal rules for driver’s licenses, even after major changes designed to cut the cost of those rules and provide more flexibility.
The U.S. Department of Homeland Security (DHS) Friday (Jan. 11) released final rules for the Real ID Act of 2005, giving states nearly five extra years to verify the identity of an estimated 245 million drivers and reissue secure licenses to them. The regulations also give states more leeway in securing the licensing process and in what fraud-prevention features are required on the actual cards.

“We initially estimated Real ID would cost states more than $11 billion. These regulations offer states some flexibility that may tame those costs,” said William T. Pound, executive director of the bi-partisan National Conference of State Legislatures. “Still, the fact remains that the administration has not asked Congress to fund state costs, and Congress has only provided states $90 million,” Pound said.

U.S. Sen. Patrick Leahy (D), chairman of the Senate Judiciary Committee and co-sponsor of a bill to repeal Real ID, blasted the finalized rules as too little too late. “It is unfortunate that instead of addressing the fundamental problems this law poses for the states, the Administration appears content merely to prolong a contentious and unproductive battle to force the states to comply,” he said in a written statement.

Homeland Security Secretary Michael Chertoff told reporters that the revised rules would cost states $3.9 billion over 10 years and said the average price of each new license would rise just $8 under Real ID — a bargain for the added protection from terrorism and fraud.

“For an added $8 per license, Real ID will give law enforcement and security officials a powerful advantage against falsified documents, and it will bring some peace of mind to citizens wanting to protect their identity from theft by a criminal or illegal alien,” Chertoff said.

The biggest reduction in costs will come from stretching out the process: Instead of requiring that states reissue all of their licenses by between this year and 2013, those over 50 years old can delay getting a Real ID until 2017.

DHS had previously given states until May to request a delay to begin issuing Real IDs by the end of 2009. California, Indiana, Kentucky, Maryland and Ohio have already been approved for that extension, said Darrell Williams, director of the Real ID program office at DHS.

Under the final rules, states that receive an extension must meet 18 benchmarks by the end of 2009, including completing background checks on motor vehicle agency employees and incorporating specific security features on the cards, such as a digital photo and an electronic watermark.

By May 2011, all states must verify the identity and legal residence of all license holders under 50 years old using the five electronic databases required by the law. Those over 50 years old at that time will not be required to get a Real ID until Dec. 1, 2017.

David Quam, chief lobbyist for the National Governors Association, said that overall it was clear that DHS had taken states’ concerns into consideration. But he said there are still major questions about whether the federal government can find a way for all 50 states to electronically verify data varying from birth records to visa status. Only one of the five databases required by the law is now available to all states.

The flexibility and extended time frames recognize that nearly half of the states already have taken such steps to improve the security of their licenses and their licensing process, Richard Barth, assistant secretary of homeland security told state officials during a Jan. 11 conference call.

One area that DHS will not be flexible on is enforcement: Beginning in May, non-compliant licenses cannot be used to board a commercial flight or enter a federal building. Chertoff said that will directly affect citizens in six states that have passed laws rejecting Real ID, regardless of the any security measures that state has applied to its licenses. Residents in those states will instead have to use military or other federal identification or passports at the airports.

Maine, Montana, New Hampshire, Oklahoma, South Carolina and Washington have passed laws refusing to comply with the act over the concerns of its cost, infringement on state practice and threats to personal privacy. Georgia has given the governor the authority to ignore the law if he deems it to expensive and the Idaho Legislature has pointedly rejected any funding for Real ID.

DHS Rolls Out New ID Program

The government announced today new security rules aimed at making it harder for terrorists and illegal immigrants to get a driver's license.

It's all part of the REAL ID Act created by the Department of Homeland Security.

The legislation requires that driver's license photos be taken at the start of the application process, rather than at the end, so if the person fails to prove identity and citizenship, their photo will be kept on file for future reference. States will also be required to check the applicant's Social Security number and immigration status.

Americans born after December 1st, 1964 will be required to get the new licenses during the next six years, and by 2014, anyone boarding a plane or entering a federal building will have to show a REAL ID-compliant license.