Cybersecurity: Next Steps to Protect Our Critical Infrastructure
Total Page:16
File Type:pdf, Size:1020Kb
S. HRG. 111–667 CYBERSECURITY: NEXT STEPS TO PROTECT OUR CRITICAL INFRASTRUCTURE HEARING BEFORE THE COMMITTEE ON COMMERCE, SCIENCE, AND TRANSPORTATION UNITED STATES SENATE ONE HUNDRED ELEVENTH CONGRESS SECOND SESSION FEBRUARY 23, 2010 Printed for the use of the Committee on Commerce, Science, and Transportation ( U.S. GOVERNMENT PRINTING OFFICE 57–888 PDF WASHINGTON : 2010 For sale by the Superintendent of Documents, U.S. Government Printing Office Internet: bookstore.gpo.gov Phone: toll free (866) 512–1800; DC area (202) 512–1800 Fax: (202) 512–2104 Mail: Stop IDCC, Washington, DC 20402–0001 VerDate Nov 24 2008 14:15 Nov 04, 2010 Jkt 057888 PO 00000 Frm 00001 Fmt 5011 Sfmt 5011 S:\WPSHR\GPO\DOCS\57888.TXT SCOM1 PsN: JACKIE SENATE COMMITTEE ON COMMERCE, SCIENCE, AND TRANSPORTATION ONE HUNDRED ELEVENTH CONGRESS SECOND SESSION JOHN D. ROCKEFELLER IV, West Virginia, Chairman DANIEL K. INOUYE, Hawaii KAY BAILEY HUTCHISON, Texas, Ranking JOHN F. KERRY, Massachusetts OLYMPIA J. SNOWE, Maine BYRON L. DORGAN, North Dakota JOHN ENSIGN, Nevada BARBARA BOXER, California JIM DEMINT, South Carolina BILL NELSON, Florida JOHN THUNE, South Dakota MARIA CANTWELL, Washington ROGER F. WICKER, Mississippi FRANK R. LAUTENBERG, New Jersey GEORGE S. LEMIEUX, Florida MARK PRYOR, Arkansas JOHNNY ISAKSON, Georgia CLAIRE MCCASKILL, Missouri DAVID VITTER, Louisiana AMY KLOBUCHAR, Minnesota SAM BROWNBACK, Kansas TOM UDALL, New Mexico MIKE JOHANNS, Nebraska MARK WARNER, Virginia MARK BEGICH, Alaska ELLEN L. DONESKI, Staff Director JAMES REID, Deputy Staff Director BRUCE H. ANDREWS, General Counsel ANN BEGEMAN, Acting Republican Staff Director BRIAN M. HENDRICKS, Republican General Counsel NICK ROSSI, Republican Chief Counsel (II) VerDate Nov 24 2008 14:15 Nov 04, 2010 Jkt 057888 PO 00000 Frm 00002 Fmt 5904 Sfmt 5904 S:\WPSHR\GPO\DOCS\57888.TXT SCOM1 PsN: JACKIE C O N T E N T S Page Hearing held on February 23, 2010 ....................................................................... 1 Statement of Senator Rockefeller ........................................................................... 1 Statement of Senator Snowe ................................................................................... 3 Prepared statement .......................................................................................... 5 Statement of Senator Ensign .................................................................................. 36 Statement of Senator Pryor .................................................................................... 38 Statement of Senator Begich .................................................................................. 41 Statement of Senator Klobuchar ............................................................................ 43 Statement of Senator Thune ................................................................................... 47 WITNESSES Vice Admiral Michael McConnell, USN (Retired), Executive Vice President, National Security Business, Booz Allen Hamilton ............................................ 7 Prepared statement .......................................................................................... 10 James A. Lewis, Director and Senior Fellow, Technology and Public Policy Program, Center for Strategic and International Studies ................................ 12 Prepared statement .......................................................................................... 14 Scott Borg, Director and Chief Economist, U.S. Cyber Consequences Unit ....... 17 Prepared statement .......................................................................................... 19 Mary Ann Davidson, Chief Security Officer, Oracle Corporation ........................ 21 Prepared statement .......................................................................................... 23 James Arden ‘‘Jamie’’ Barnett, Jr., Rear Admiral, USN (Retired), Chief, Pub- lic Safety and Homeland Security Bureau, FCC ............................................... 27 Prepared statement .......................................................................................... 29 APPENDIX Hon. Tom Udall, U.S. Senator from New Mexico, prepared statement .............. 55 Written questions submitted by Vice Admiral Michael McConnell to: Hon. John D. Rockefeller IV ............................................................................ 55 Hon. Tom Udall ................................................................................................ 55 Response to written questions submitted by Dr. James A. Lewis to: Hon. John D. Rockefeller IV ............................................................................ 56 Hon. Tom Udall ................................................................................................ 57 Hon. John Ensign ............................................................................................. 57 Response to written questions submitted by Hon. John D. Rockefeller IV to Scott Borg ......................................................................................................... 58 Response to written questions submitted by Mary Ann Davidson to: Hon. John D. Rockefeller IV ............................................................................ 60 Hon. Tom Udall ................................................................................................ 62 Hon. John Ensign ............................................................................................. 72 Response to written questions submitted by Rear Admiral James Barnett, Jr. to: Hon. John D. Rockefeller IV ............................................................................ 75 Hon. John Ensign ............................................................................................. 77 (III) VerDate Nov 24 2008 14:15 Nov 04, 2010 Jkt 057888 PO 00000 Frm 00003 Fmt 5904 Sfmt 5904 S:\WPSHR\GPO\DOCS\57888.TXT SCOM1 PsN: JACKIE VerDate Nov 24 2008 14:15 Nov 04, 2010 Jkt 057888 PO 00000 Frm 00004 Fmt 5904 Sfmt 5904 S:\WPSHR\GPO\DOCS\57888.TXT SCOM1 PsN: JACKIE CYBERSECURITY: NEXT STEPS TO PROTECT OUR CRITICAL INFRASTRUCTURE TUESDAY, FEBRUARY 23, 2010 U.S. SENATE, COMMITTEE ON COMMERCE, SCIENCE, AND TRANSPORTATION, Washington, DC. The Committee met, pursuant to notice, at 2:40 p.m. in room SR–253, Russell Senate Office Building, Hon. John D. Rockefeller IV, Chairman of the Committee, presiding. OPENING STATEMENT OF HON. JOHN D. ROCKEFELLER IV, U.S. SENATOR FROM WEST VIRGINIA The CHAIRMAN. Welcome, all. And this hearing will come to order. And members will be coming in. Before I give my opening statement, I just want to make sure that everybody knows who is testifying. And Vice Admiral Michael McConnell, U.S. Navy, Retired, Executive Vice President of Na- tional Security Business, Booz Allen Hamilton. He and I have done a lot of work together, including on FISA, other matters. Dr. James Lewis, Director and Senior Fellow, Technology and Public Policy Program Center for Strategic and International Studies. And Dr. Lewis is there, working on his computer, I think. Mr. Scott Borg, Director and Chief Economist, U.S. Cyber Consequences Unit. And Rear Admiral James Arden Barnett, Jr., Chief, Public Safety and Homeland Security Bureau, Federal Communications Commission. I’m really glad about that. And Ms. Mary Ann Davidson, Chief Se- curity Officer, Oracle Corporation. So, you’re going to have some at- tention focused on you today. This Nation—is it OK if I proceed? OK. This Nation and its citi- zens depend enormously on communication technologies in so in- credibly many ways every single day. Vast network expansions have transformed virtually every aspect of our lives: education, healthcare, how businesses grow, don’t grow, function, and the de- velopment of an interconnected, more democratic conversation. Our government, our economy, our very lives rely on technology that connects millions of people around the world in real time and all the time. And yet, these powerful networks also carry great risks which people, for the most part, don’t understand—understandably don’t understand—but are going to have to come to understand. In recent years, hackers have attacked numerous Federal agen- cies, key media outlets, large companies across the private sector, targeting intellectual property, stealing valuable information vital to our national and economic security. (1) VerDate Nov 24 2008 14:15 Nov 04, 2010 Jkt 057888 PO 00000 Frm 00005 Fmt 6633 Sfmt 6633 S:\WPSHR\GPO\DOCS\57888.TXT SCOM1 PsN: JACKIE 2 What was it? An article I read in the paper, somebody from DOD says, ‘‘We’re getting attacked every day, all day, 7 days a week.’’ And that’s what they do. And these attacks are coming with in- creasing regularity and increasing sophistication. A major cyber at- tack could shut down our Nation’s most critical infrastructure: our power grid, telecommunications, financial services; you just think of it, and they can do it—the basic foundations on which our com- munities and families have been built, in terms of all of their lives and who are trying to have a future. So, this hearing is a next step in examining the important action we should be taking right now, as a government and as a national economy, to harden our defenses and safeguard critical infrastruc- ture against a major cyber attack. Having said that they’re hap- pening all the time, that would seem to be out of order, but, you know, it needs—both need to be said. Now, I understand it’s no secret that cybersecurity is one of my top securities;