Top Banner
BCLT Open Data Symposium April 17, 2015 Public Cybersecurity: Is there a role for open government data? Deirdre Mulligan | Elaine Sedenberg UC Berkeley School of Information
21

Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Mar 27, 2018

Download

Documents

lephuc
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

BCLT Open Data Symposium April 17, 2015

Public Cybersecurity: Is there a role for open government data?Deirdre Mulligan | Elaine Sedenberg UC Berkeley School of Information

Page 2: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Cybersecurity = Public Good

2

Page 3: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Individual vs. Collective

3

Page 4: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Goals of Public Cybersecurity

✤ Prompt the production of cybersecurity!✤ Focused on socio-technical system as a whole!

✤ Manage the remaining insecurity!✤ Reach political agreement !

✤ Definition of cybersecurity!✤ Framework to balance individual rights and

public welfare

4

Page 5: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Information as a Means

✤ Prevention Orientation (Reducing Vulnerabilities):!✤ Improving artifacts; education; community

empowerment; policy development!✤ Important to understand how things work in the

wild (machines, networks, people)!✤ Response Orientation (Managing Insecurity):!

✤ Detection; identification; containment; treatment!✤ Monitoring and analyses enable response

5

Page 6: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Public Health Functions Steering Committee, July 1995

Essential Public Health Services

6

Page 7: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Public Health: Role of information in achieving goals

Education, prevention, surveillance, and containment fueled by Information, and ongoing research that depends on data!

Information used by diverse and distributed players, essential to sustain and coordinate action!

Lots of variations in form of information collection and sharing!

Ongoing tensions between risks of broad accessibility, and need for accurate and complete data on population!

Delicate balances throughout complicated information ecosystem!7

Page 8: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Public Cybersecurity: Role of information in achieving goals

✤ What role can information sharing and data availability play in advancing public cybersecurity goals?!

✤ Underscores importance of clarifying goals!

✤ Specifically interested in the unique role open data may play

8

Page 9: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Views on Cyber Info Sharing

✤ White House: Sharing risks and incidents in order to foster real-time response collaboration; voluntary organization and encourages partnership with Federal Gov’t. (EO 2/13/15 “Promoting Private Sector Cybersecurity Information Sharing”)

Mechanisms for sharing classified information for critical infrastructure (EO 12829) !

✤ Congress: Sharing of information by Federal Gov’t; sharing of cyber threat indicators and defense measures with Federal Gov’t; oversight; assessment of current Federal capabilities and threats (CISA 2015)!

✤ Civil Liberties Advocates: Concerns about users’ privacy and broad data sharing provisions outside of cybersecurity purposes!

✤ Private Sector: Concerns over discoverability; liability; competitiveness 9

Page 10: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Historic Example of Public Health Information Sharing!

1854 Cholera Outbreak in London

10

Page 11: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

11

Page 12: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

12

Page 13: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

13

Page 14: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Relevance to current data sharing in cybersecurity

✤ Security research sometimes resembles “shoe-leather” epidemiology!

✤ Ad-hoc, independent gathering of data in response to incidents!

✤ Burden on independent actors to convince public officials!

✤ Public data limited and episodic; private entities often hold the data

14

Page 15: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Problems in current cyber info sharing

✤ Permissions and access dictated by data owners!

✤ Inconsistent data sources; often stale; fits narrow research needs!

✤ Incompatible data formats and timescales!

✤ Unclear privacy implications15

Page 16: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Present Examples of Public Health Information Sharing!

PulseNet & multidrug resistant Shigella | HIV Indicators & Data Systems

16

Page 17: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

17

Page 18: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

18

Page 19: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

✤ Systems address different goals: detection of known and unknown threats; tracking chronic conditions; understanding broader context!

✤ CDC and community role in coordinating information sharing and data stewardship!

✤ Not all data held by government; different levels of openness!

✤ Further responsibilities to inform public, educate, and formulate responses & interventions

Public Health Data Practices

19

Page 20: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Potential Benefits of Open Data for Cybersecurity

✤ Shapes communities of practice and engages “non-experts”!

✤ Government data consistent/accessible/balances risks and benefits/existing platforms!

✤ Opportunity for transparency in data surveillance systems!

✤ Level playing field for small organizations

20

Page 21: Public Cybersecurity: Is there a role for open government ... · PDF filePublic Cybersecurity: Is there a role ... (EO 2/13/15 “Promoting Private Sector Cybersecurity Information

Research Contributions

✤ 1) Information Sharing within the context of public cybersecurity is a means to an end, so goals need to be clearly defined!

✤ 2) Options for sharing data: different parties, different data, & degrees of openness!

✤ 3) Within public health, open data has advanced specific goals and outcomes in addition to fueling research that has indirectly benefited public health 21