InfraGard
Motto | Partnership For Protection |
---|---|
Formation | 1996 |
Type | Non-profit organization |
Membership | 54,677 |
Website | www.infragard.org |
InfraGard is a non-profit organization serving as a public-private partnership between U.S. businesses and the Federal Bureau of Investigation. The organization is an information sharing and analysis effort serving the interests, and combining the knowledge base of, a wide range of private sector and government members.[1] InfraGard is an association of individuals that facilitates information sharing and intelligence between businesses, academic institutions, state and local law enforcement agencies, and other participants dedicated to prevent hostile acts against the United States.[2] InfraGard's mutual nondisclosure agreements among its members (individuals) and the FBI promotes trusted discussions of vulnerabilities and solutions that companies and individuals may be hesitant to place in the public domain and provide access to additional threat information from the FBI.
History
InfraGard began in the Cleveland, Ohio, Field Office in 1996,[3][4] and has since expanded to become a national-level program, with InfraGard coordinators in every FBI field office. Originally, it was a local effort to gain support from the information technology industry and academia for the FBI's investigative efforts in the cyber arena, but it has since expanded to a much wider range of activities surrounding the nation's critical infrastructure.[1]
The program expanded to other FBI Field Offices, and in 1998 the FBI assigned national program responsibility for InfraGard to the former National Infrastructure Protection Center (NIPC) directed by RADM James B. Plehal USNR and to the FBI's Cyber Division in 2003.[3] Since 2003, InfraGard Alliances and the FBI said that they have developed a TRUST-based public-private sector partnership to ensure reliability and integrity of information exchanged about various terrorism, intelligence, criminal, and security matters. It supports FBI priorities in the areas of counterterrorism, foreign counterintelligence, and cybercrime.[3][5]
Purpose
InfraGard is focused on protecting the 16 critical infrastructures outlined by Presidential Directive 21: Critical Infrastructure Security & Resilience by sharing threat information, assisting the FBI in finding and prosecuting those who attack critical infrastructure through physical or cyber means, provide training for active shooter scenarios, cyber defense, and any other threats against the nation. The organization is committed to providing the tools and resources needed by those who own and operate the nation's critical infrastructure to protect their enterprises and maintain the services necessary for a safe and prosperous nation.
Information sharing
InfraGard chapters also participate to assure that the critical infrastructure owners and operators -- estimated at 85% private sector -- are engaged and represented in local and regional planning efforts.[6] Working on all 16 critical infrastructure sectors, the organization provides resources and information not only on prevention, but also on building resilience and response capabilities.[7]
Training
InfraGard chapters around the nation also provide cyber and physical security training sessions that focus on the latest threats as identified by the FBI. Sessions include threat briefings, technical sessions on cyber and physical attack vectors, response training, and other resources to help CISOs and CSOs protect their enterprise. InfraGard approaches threats to critical infrastructure from both a tactical and strategic level, addressing the needs of those on the front lines of security as well as those decision makers tasked with assessing their enterprise's vulnerabilities and allocating resources to protect it. [8]
The information sharing between the organization and government has been criticized by those protecting civil liberties, concerned the membership would be surrogate eyes and ears for the FBI.[9] The group has also been the subject of hacking attacks intended to embarrass the FBI.[10] Local chapters regularly meet to discuss the latest threats or listen to talks from subject matter experts on security issues,[11] with membership open to U.S. citizens at no cost.[12] As of July, 2012, the organization reported membership at over 54,677 (including FBI).[3]
Critical infrastructure
InfraGard focuses on the development, management and protection of critical infrastructure. InfraGard has a nationwide focus group that reviews threats that could disrupt critical infrastructure nationwide for a month or more named the electromagnetic pulse special interest group (EMP SIG). This is an all-hazards approach that looks at manmade and natural electromagnetic pulse (EMP), cyber attack, coordinated physical attack, pandemics or insider threats and mitigating actions that could minimize such threats. Mitigation strategies include hardening and prevention strategies in addition to the development of local infrastructure that could make local communities more robust and sustainable. (See EMP SIG press release and guidance document. See also the website of the association of universities involved in public policy, the Policy Studies Organization, who produces the technology policy conference called the Dupont Summit in which the InfraGard National EMP SIG brought public and private sector leaders to discuss these emerging threat issues: http://www.ipsonet.org/conferences/the-dupont-summit/dupont-summit-2012/infragard-emp-sig )
Civil liberties
Partnerships between government agencies and private organizations has its critics.[9][13][14] Concerned about civil liberties, the American Civil Liberties Union (ACLU) warned that there "is evidence that InfraGard may be closer to a corporate TIPS program, turning private-sector corporations — some of which may be in a position to observe the activities of millions of individual customers — into surrogate eyes and ears for the FBI". Concluding that “any program that institutionalizes close, secretive ties between such organizations raises serious questions about the scope of its activities, now and in the future.”[9][11] While others describing Infragard state "the architecture of the Internet—and the many possible methods of attack— requires governments, corporations, and private parties to work together to protect network security and head off threats before they occur."[15] Responding to the ACLU criticism, Chairwoman Kathleen Kiernan of the InfraGard National Members Alliance (INMA) denies that InfraGard is anything but beneficial to all Americans stating “It's not an elitist group in any way, shape or form,” she says. “We're out there trying to protect everybody. Any U.S. citizen on the planet is eligible to apply to InfraGard.”[11]
LulzSec attacks
In 2011, LulzSec claimed responsibility for attacking chapter websites managed by local members in Connecticut and Atlanta, in order to embarrass the FBI with "simple hacks".[10] The group leaked some of InfraGard member e-mails and a database of local users.[16] The group defaced the website posting the following message, "LET IT FLOW YOU STUPID FBI BATTLESHIPS", accompanied with a video. LulzSec has posted the following message regarding the attack:
"It has not come to our unfortunate attention that NATO and our good friend Barrack Osama-Llama 24th-century Obama [sic] have recently upped the stakes with regard to hacking. They now treat hacking as an act of war. So, we just hacked an FBI affiliated website (Infragard, specifically the Atlanta chapter) and leaked its user base. We also took complete control over the site and defaced it [...]."[17]
See also
- MATRIX – Information sharing partnership between various local, state and federal law enforcement agencies
- Operation TIPS – Program to have citizens provide information to law enforcement and intelligence agencies
- Terrorism Liaison Officer
References
- 1 2 "Robert S. Mueller, III -- InfraGard Interview at the 2005 InfraGard Conference" (mov). Infragard (Official Site) -- "Media Room". Retrieved 2009-12-09.
- ↑ "Infragard, Official Site". Infragard. Retrieved 2012-07-10.
- 1 2 3 4 "About Infragard". Infragard (Official site). Retrieved 2009-12-09.
- ↑ "InfraGard History". InfraGard National Members Alliance.
- ↑ "InfraGard - A Partnership That Works". FBI. 2010-03-08. Retrieved 2012-07-15.
- ↑ Christopher, Ryan. "MWCOG and InfraGardNCR Key to Government Engagement with Private Sector Critical Infrastructure Stakeholders". CIP Report. George Mason University. Retrieved August 16, 2016.
- ↑ Stone, Andrea. "Four Key Imperatives to Building Effective Transportation Infrastructure Resilience". CIP Report. George Mason University. Retrieved August 16, 2016.
- ↑ NCR, InfraGard. "TAC-STRAT: A Tactical and Strategic Look at Cyber Security". eventbrite. eventbrite. Retrieved August 16, 2016.
- 1 2 3 Stanley, J. (2004). The Surveillance-Industrial Complex: How the American Government is Enlisting Private Parties in the Construction of a Surveillance Society (PDF) (Report). ACLU. p. 12. Retrieved 2011-06-05.
- 1 2 "Hackers Claim Strike On FBI Partner--Again". Huffington Post. June 21, 2011.
- 1 2 3 Kaplan, D. (2009-01-01). "On guard: InfraGard makes strides under new leadership". SCMagazine. Retrieved 2012-07-15.
- ↑ "InfraGard Membership". InfraGard. Retrieved 2012-07-15.
- ↑ Madsen, W. (1999). "Details emerge of NSA and FBI involvement in domestic US computer security". Computer Fraud & Security. 1999 (1): 10–11. doi:10.1016/S1361-3723(00)86979-1.
- ↑ Joh, E. E. (2006). "The Forgotten Threat: Private Policing and the State". Indiana Journal of Global Legal Studies. 13 (2): 357–389. doi:10.2979/GLS.2006.13.2.357.
- ↑ Balkin, J. M. (2008). "The Constitution in the National Surveillance State" (pdf). Minnesota Law Review. 93 (1)."Abstract".
- ↑ "LulzSec claims to have hacked FBI-affiliated website". LA Times. 2011-06-03. Retrieved 2011-06-04.
- ↑ Read, M. (2011-06-04). "LulzSec Hackers Go After FBI Affiliates". Gawker. Retrieved 2011-06-04.
Further reading
- John P. Mello Jr., "Taking a Byte out of Crime - FBI's new computer network about cyber crime", CFO magazine, March 2001
- Andrew F. Hamm, "FBI to valley: Tell us about attacks", San Jose Business Journal, June 28, 2002
- "Critical Infrastructure Protection: Significant Challenges in Developing National Capabilities" (pdf). General Accounting Office (now Government Accountability Office). April 2001. GAO-01-323.
- Richard Thieme, "Center of Attention: An Interview with Ron Dick of NIPC", "Thiemeworks Interviews", 2001
- "InfraGard: Ten Years and Going Strong", FBI press release, October 4, 2006
- Dan Verton "FBI Teams with Business to Fight Cybercrime", Computerworld, January 9, 2001
- ARRL News "FBI's 'InfraGard' Program Courts Amateur Radio as Ally", ARRL News Jul 21, 2006
- Bob Evans, "Business Technology: Security Tips That Will Scare--And Help--You", InformationWeek, August 29, 2005
- D. Ian Hopper, "Rather than breaking down doors, authorities take down walls in overture to IT professionals", CNN.com, April 28, 2000
- Bernstein James, "LI business focusing on cyber security, fraud", newsday.com, December 7, 2010