Showing posts with label Defence Signals Directorate. Show all posts
Showing posts with label Defence Signals Directorate. Show all posts

Friday, September 29, 2017

Australian Signals-intelligence in the Pacific War

Dufty provides a boys (and girls) own adventure account of Australian signals intelligence in the WW2 Pacific War. The book makes the case for Australia's contribution to Macarthur's fight from Australia back to the Philippines, the role of academics and civilians in this effort and of women, against bureaucratic obstacles. The book is packed with anecdotes, as well as history.

With modern day concerts over cyber-security and its likely part in future wars in our region, it is useful to be reminded where the Australian Signals Directorate (ASD) came from and their difficult relationship with government, the military establishment and Australia's allies.

Monday, December 06, 2010

Cyber Defence Management System

The Australian Government has issued a Request for Information for a Cyber Event Management and Reporting System (DISG ITR 2010/18, 3 December 2010). The RFI was issued by the Defence Intelligence and Security Group of the Department of Defence, for the DSD Cyber Security Operations Centre (CSOC):

DESCRIPTION OF REQUIREMENT

  1. The Defence Signals Directorate (DSD) is seeking expressions of interest from industry relating to commercially available software applications capable of providing a Cyber Event Management and Reporting System (CEMaRS) capability. The CEMaRS application will provide support to the DSD Cyber Security Operations Centre (CSOC) and its’ role in defending Australian Government information networks.
  2. The CEMaRS application will provide the CSOC with a capability to view all reported or identified cyber events, to consolidate information relating to events, and to make informed decisions in responding to events.
  3. The system must:
    1. provide a capability to view all reported or detected cyber events including the ability to:
      1. ingest identified cyber events with the ability to handle substantial data rates;
      2. support flexible data ingest allowing for the addition of new sources of information and data in a variety of formats, including the ability to modify and customise these data sources;
      3. support manual entry of events reported;
      4. ingest event and system logs provided by other sources and customer organisations;
      5. support multi-dimensional prioritisation across all events including, but not limited to, source, target and level of success; and
      6. support analysis of cyber events including viewing of all associated data to draw analytical conclusions,
    2. provide a tasking and workflow capability to consolidate event information and enable informed decisions to be made to coordinate and assist with operational responses to cyber events. This include the ability to:
      1. create new tasks relating to cyber events, assign tasks to staff or teams, and link tasks to a workflow;
      2. manage all aspects of a workflow associated with cyber event management, including for specific policy workflows; and
      3. support user access controls restricting or providing access to tasks and workflows,
    3. support context searching across tasks, workflows, all associated event data, or any other ingested data;
    4. support correlation and association between events, tasks, and existing knowledge-bases enabling staff to draw comprehensive analytical conclusions;
    5. provide the ability to store data over a significant and customisable time period allowing for historical event and task correlation;
    6. provide seamless integration between event management and associated tasking and workflows;
    7. support flexible interfaces and system customisation to support evolving business processes, integration to other systems (such as an existing knowledgebase), and the addition of new custom analytic tools;
    8. support the creation of tailored statistical report of managed events, tasks and workflows;
    9. support a scalable and extensible architecture;
    10. support user authentication to the corporate LDAP service; and
    11. support the use of commodity hardware. ...
From: Cyber Event Management and Reporting System, RFI DISG ITR 2010/18, Defence Intelligence and Security Group, Australian Department of Defence, 3 December 2010

Friday, November 27, 2009

Cyberwar Podcast

Stilgerrian, interviewed me for a ZDNet Australia podcast on "Cyberwar: What is it good for?". This was recorded shortly before the Attorney-General released the new Australian Government Cyber Security Strategy and IBM announced a new computer security centre in Canberra.

Tuesday, November 24, 2009

Australian Government Cyber Security Strategy

The Federal Attorney-General, Robert McClelland has released an Australian Government Cyber Security Strategy. This is a high risk strategy as it proposes transferring the functions of the successful and experienced non-government AusCert to an inexperienced government body. A better strategy would be to resource AusCert so it can provide services to non-government bodies and work with DSD to look after government and military computer security.

The Australian Government Cyber Security Strategy has three objectives:
  1. Make Australians aware of cyber risks,
  2. Make businesses operate secure and resilient information and communications technologies,
  3. Secure Australian Government information and make communications technologies resilient.

The seven Strategic priorities are:

  1. Improve the detection, analysis, mitigation and response to sophisticated cyber threats,
  2. Provide Australians with information and tools to protect themselves online,
  3. Partner with business to promote security and resilience,
  4. Protection of government ICT systems,
  5. Promote a secure, resilient and trusted global electronic operating environment,
  6. Maintain an effective legal framework and enforcement against cyber crime,
  7. Promote research and development of cyber security a skills.

By early 2010 the Australian Government expects to have:

  1. CERT Australia: with Attorney-General’s Department taking over AusCert's responsibilities. This will incorporate the Australian Government Computer Emergency Readiness Team,
  2. Cyber Security Operations Centre (CSOC): The Defence Signals Directorate (DSD) will continue to provide civilian and military government agencies with cyber security assistance.