inicio mail me! sindicaci;ón

US government tackles social media security head-on

by Joe McKendrick

The US government knows social networking is the key to better collaboration between agencies and employees, but has held back because of security concerns. Recently, the government developed security guidelines to make social media more secure.

In a new post, ReadWriteWeb’s Jolie O’Dell describes how US Navy CIO Rob Carey wants to use social media is a resource for the US military to build trust and collaboration across all four branches.

However, the mainly unregulated, Wild West aspect to social media has put off a super security-conscious and disciplined operation such as the military. That’s doesn’t mean social media — with its powerful collaboration capabilities — doesn’t have a place in the military, Carey says. O’Dell cites a recent podcast in which Carey observed that “most social networking tools come with no rules of the road. As the Internet moves towards user-generated content, we thought there was a void we could fill… to mitigate some of the security risks associated with social media.”

Carey urges the military to engage social media full force:

“Social media is an inherent part of the toolbox for members of the millennial workforce, while baby boomers are just adopting it. Social media tools should become the standard by which we can share and collaborate on information inside and outside the network boundaries.”

Carey’s comments com eon the heels of last month’s release, by the federal CIO Council, of the Guidelines for Secure Use of Social Media by Federal Departments and Agencies. (PDF download)

The Guidelines address the information security risk head on:

“The decision to embrace social media technology is a risk-based decision, not a technology-based decision. It must be made based on a strong business case, supported at the appropriate level for each department or agency, considering its mission space, threats, technical capabilities, and potential benefits. The goal of the IT organization should not be to say “No” to social media websites and block them completely, but to say “Yes, following security guidance,” with effective and appropriate information assurance security and privacy controls. The decision to authorize access to social media websites is a business decision, and comes from a risk management process made by the management team with inputs from all players, including the CIO, CISO, Office of General Counsel(OGC), privacy official and the mission owner.”

The government breaks social media usage into four categories: Inward Sharing, Outward Sharing, Inbound Sharing, and Outbound Sharing:

Inward Sharing: “The sharing of internal organizational documents through internal collaboration sites such as SharePoint portals and internal wikis.”

Outward Sharing: “Also known as inter-institutional sharing, enables Federal Government information to be shared with external groups, such as state and local governments, law enforcement, large corporations, and individuals.”

Inbound Sharing: “Also known as “crowdsourcing,” is similar to conducting a large online collaborative poll.”

Outbound Sharing: “Federal engagement on public commercial social media Websites.”

The report makes the following recommendations for secure social media adoption by federal agencies:

Policy control: “The senior technology official at each federal agency should develop a social media communications strategy, with the support of their communication office, that accurately addresses the guidelines in this document in conjunction with government-wide policy.”

Acquisition controls: “Federal agencies should require enhanced security and privacy controls through contracted social media services, such as… supporting support stronger authentication mechanisms for federal employee and agency user profiles, including multi-factor authentication…. Ensuring social media websites consider basic security best practices, such as input validation, code security reviews, and strong cookie management.”

Training controls: “Often the best solution is to provide periodic awareness and training of policy, guidance, and best practices. The proper use of social media in the Federal Government should be part of annual security awareness training…  [such as providing] “specialized training to educate users about what information to share, with whom they can share it, and what not to share…. Providing guidance and training based on updated agency social media policies and guidelines, including an updated Acceptable Use Policy (AUP) specific to social media websites…. Providing guidance to employees to be mindful of blurring their personal and professional life. Don’t establish relationships with working groups or affiliations that may reveal sensitive information about their job responsibilities.”

Network controls: “The Federal Trusted Internet Connection (TIC) program provides a series of inspection, monitoring, detection, and blocking technologies that ensure additional security and visibility to defend against a wide array of attacks, including those discussed from a social media perspective…. Current technologies allow for increasingly granular control of web applications, data, and protocols, in accordance with departmental policy. Web content filtering technologies for all Internet traffic should be located in the department TIC or provided as an add-on for offices granted access to social media websites.”

Host controls: “The establishment of a hardened Common Operating Environment (COE) will ensure consistent and comprehensive host configuration and hardening policies across the Federal Government. Hosts may be configured using the Federal Desktop Core Configuration (FDCC), and validated through a Security Content Automation Protocol (SCAP) compatible scanner….  Two-factor authentication reduces the likelihood an attacker will gain unauthorized access to an information system through a username and password…. Federal agencies should ensure they have strong patching for operating system and application vulnerabilities, and that updating anti-virus signature files and system logging is enabled to report to the SOC on workstations in real time.”

Share and Enjoy:
  • E-mail this story to a friend!
  • Print this article!
  • TwitThis
  • del.icio.us
  • Facebook
  • Reddit
  • Digg
  • Google
  • StumbleUpon
  • SphereIt


51 Tweets

52 Comments »

Scott WrightOctober 25th, 2009 at 7:38 am

Nice article. Lots of good content. It’s good to see people focusing on how the Government is using and trying to control the use of Social Media, from a security point of view.

I’ve been writing a lot on my website The Streetwise Security Zone (a place for non-technical users and IT managers to learn about security awareness and get training on it), as well as hosting a new podcast with Tom Eston and Kevin Johnson, called The Social Media Security Podcast. We just published Episode 3, with some technical and some non-technical explanations and tips.

Please drop by and check us out. We’d love to receive some public comments and reviews on what we are doing. Perhaps a Government-focused episode would be of interest. Let us know.

Thanks

Scott Wright
The Streetwise Security Coach

SEOSpyOctober 23rd, 2009 at 8:08 pm

RT @ffblog: US government tackles social media security head-on http://bit.ly/48t5O7

This comment was originally posted on Twitter

mytweetfollowerOctober 23rd, 2009 at 8:53 pm

http://bit.ly/twi55 US government tackles social media security head-on http://bit.ly/243kuu

This comment was originally posted on Twitter

mostashOctober 23rd, 2009 at 9:46 pm

US government tackles social media security head-on http://bit.ly/VJG2q

This comment was originally posted on Twitter

social_medioOctober 23rd, 2009 at 10:01 pm

US government tackles social media security head-on http://bit.ly/tB5wW

This comment was originally posted on Twitter

megsnotebookOctober 23rd, 2009 at 10:03 pm

vernment tackles social media security head-on http://icio.us/rfggbe

This comment was originally posted on Twitter

koach84October 23rd, 2009 at 10:04 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/gVcvB

This comment was originally posted on Twitter

RSSirteubalOctober 23rd, 2009 at 10:05 pm

US government tackles social media security head-on http://bit.ly/gVcvB

This comment was originally posted on Twitter

gbatuyongOctober 23rd, 2009 at 10:07 pm

US government tackles social media security head-on http://bit.ly/4w6tyK (via @marketingmoron) #Gov20 #socialmedia #sdsms

This comment was originally posted on Twitter

kritikas56October 23rd, 2009 at 10:27 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/4Ej0XU

This comment was originally posted on Twitter

Jenn822October 23rd, 2009 at 10:33 pm

RT @socialmediainfo: US government tackles social media security head-on http://bit.ly/1c1krH

This comment was originally posted on Twitter

MissSocialite7October 23rd, 2009 at 10:39 pm

US government tackles social media security head-on http://bit.ly/XgPEe

This comment was originally posted on Twitter

diana6801October 23rd, 2009 at 10:41 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://tinyurl.com/yf5qfo2

This comment was originally posted on Twitter

AFPADudeOctober 23rd, 2009 at 10:41 pm

RT @Jenn822 @socialmediainfo US government tackles social media security head-on http://bit.ly/1c1krH

This comment was originally posted on Twitter

2helppeopleOctober 23rd, 2009 at 10:52 pm

US government tackles social media security head-on http://bit.ly/gVcvB

This comment was originally posted on Twitter

ZimmermitchOctober 23rd, 2009 at 10:54 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/3yTsa1

This comment was originally posted on Twitter

ZimmermitchOctober 23rd, 2009 at 10:54 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/3jBTFC

This comment was originally posted on Twitter

HayrobleyOctober 23rd, 2009 at 10:54 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/3jBTFC

This comment was originally posted on Twitter

Emma_WattsonOctober 23rd, 2009 at 10:54 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/W9bfV

This comment was originally posted on Twitter

Katrina_adamsOctober 23rd, 2009 at 10:55 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/3jBTFC

This comment was originally posted on Twitter

Arvil_LavigneOctober 23rd, 2009 at 10:56 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/ILN2a

This comment was originally posted on Twitter

emcconne_readsOctober 23rd, 2009 at 10:57 pm

US government tackles social media security head-on: The US government knows social networking is the key to be.. http://tinyurl.com/yh4ak8s

This comment was originally posted on Twitter

Megan_FoxGirlsOctober 23rd, 2009 at 11:01 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/W9bfV

This comment was originally posted on Twitter

Position1MediaOctober 23rd, 2009 at 11:01 pm

The FASTForward Blog » US government tackles social media security … http://bit.ly/3t5i0R

This comment was originally posted on Twitter

CarolynShueOctober 23rd, 2009 at 11:09 pm

US government tackles social media security head-on: by Joe McKendrick The US government knows social networkin.. http://bit.ly/qtGi9

This comment was originally posted on Twitter

glennsnewsOctober 24th, 2009 at 1:15 am

The FASTForward Blog » US government tackles social media security … http://bit.ly/2ygnUZ

This comment was originally posted on Twitter

JpdenisonOctober 24th, 2009 at 2:29 am

Must read : US government tackles social media security head-on #yam http://ff.im/-apKTz

This comment was originally posted on Twitter

FSWOctober 24th, 2009 at 4:02 am

Reading: “US government tackles social media security head-on” http://bit.ly/16P04C

This comment was originally posted on Twitter

proactivedefendOctober 24th, 2009 at 5:20 am

News Update: The FASTForward Blog » US government tackles social media security head-on: Enterprise 2.0 Blog: News,… http://ow.ly/15X1vj

This comment was originally posted on Twitter

NLoverheid20October 24th, 2009 at 6:02 am

The FASTForward Blog » US government tackles social media security head-on: Enterprise 2.0 Blog: News, Coverage.. http://bit.ly/4Bx6Jf

This comment was originally posted on Twitter

JohnFMooreOctober 24th, 2009 at 7:07 am

The govt makes good steps around use of #social: http://bit.ly/5UFAo #gov20 #security

This comment was originally posted on Twitter

govwikiOctober 24th, 2009 at 7:20 am

RT The govt makes good steps around use of #social: http://bit.ly/5UFAo #gov20 #security http://bit.ly/2aaaXC

This comment was originally posted on Twitter

mfauscetteOctober 24th, 2009 at 7:30 am

US government tackles social media security head-on http://bit.ly/3BEvZJ

This comment was originally posted on Twitter

socialmediatipOctober 24th, 2009 at 7:43 am

The FASTForward Blog » US government tackles social media security … http://bit.ly/gVcvB

This comment was originally posted on Twitter

JameelMosesPAOctober 24th, 2009 at 10:02 am

RT @AFPADude: RT @Jenn822 @socialmediainfo US government tackles social media security head-on http://bit.ly/1c1krH

This comment was originally posted on Twitter

ryan_zoomboTVOctober 24th, 2009 at 10:38 am

http://bit.ly/Rt9MV The FASTForward Blog » US government tackles social media security … http://bit.ly/4eVbSF

This comment was originally posted on Twitter

ryan_zoomboTVOctober 24th, 2009 at 10:39 am

http://bit.ly/u4pad The FASTForward Blog » US government tackles social media security … http://bit.ly/4eVbSF

This comment was originally posted on Twitter

videoturfOctober 24th, 2009 at 1:16 pm

The FASTForward Blog » US government tackles social media security … http://bit.ly/3yTsa1

This comment was originally posted on Twitter

rob21fbOctober 24th, 2009 at 10:13 pm

The FASTForward Blog » US government tackles social media security …: The US government knows social networki.. http://bit.ly/4vl9Yw

This comment was originally posted on Twitter

hebsgaardOctober 25th, 2009 at 11:31 am

US government tackles social media security head-on http://tinyurl.com/yh4ak8s

This comment was originally posted on Twitter

rharbridgeOctober 25th, 2009 at 8:31 pm

Interesting: http://is.gd/4BADO US Government Tackles Social Media Head On

This comment was originally posted on Twitter

christammillerOctober 25th, 2009 at 9:24 pm

US gov’t tackles social media security head-on: http://is.gd/4BDpo

This comment was originally posted on Twitter

jabolinsOctober 25th, 2009 at 9:27 pm

RT @christammiller US govt tackles social media security head-on: http://is.gd/4BDpo

This comment was originally posted on Twitter

BillIvesOctober 26th, 2009 at 12:35 pm

US government tackles social media security head-on from@joemckendrick http://bit.ly/5UFAo

This comment was originally posted on Twitter

gbrettmillerOctober 26th, 2009 at 1:11 pm

US government tackles social media security head-on from @joemckendrick http://bit.ly/5UFAo (via @BillIves)

This comment was originally posted on Twitter

CindyKimPROctober 26th, 2009 at 1:33 pm

The US govt. tackles the Wild West of social media http://bit.ly/43XjLs

This comment was originally posted on Twitter

EdNadrotowiczOctober 26th, 2009 at 7:36 pm

RT @BillIves: US government tackles social media security head-on from@joemckendrick http://bit.ly/5UFAo

This comment was originally posted on Twitter

EdNadrotowiczOctober 26th, 2009 at 7:59 pm

@nahumg It seems to work fine for me – try this http://bit.ly/1bb1xk

This comment was originally posted on Twitter

nahumgOctober 26th, 2009 at 8:17 pm

RT @EdNadrotowicz: RT @BillIves: US government tackles social media security head-on from@joemckendrick http://bit.ly/5UFAo

This comment was originally posted on Twitter

webtechmanOctober 26th, 2009 at 8:21 pm

RT @nahumg @EdNadrotowicz @BillIves: US government tackles social media security head-on from@joemckendrick http://bit.ly/5UFAo #gov20

This comment was originally posted on Twitter

danavanOctober 27th, 2009 at 7:37 pm

US government tackles social media security head-on: Enterprise 2.0 Blog: News, Coverage, and Commentary http://ff.im/-aCtrJ

This comment was originally posted on Twitter

dsarathyOctober 28th, 2009 at 5:51 am

US government tackles social media security head-on – http://bit.ly/SRSwg

This comment was originally posted on Twitter

» Subscribe to the RSS feed for these comments

Your comment

Want an image to appear near your comment? Go to gravatar.com

HTML-Tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Additional comments powered by BackType