Category Archives: Security

The Eight Roles of DCID 6/3

Only five short of a baker’s dozen, there are eight roles provided in Director of Central Intelligence Directive (DCID) 6/3 “Protecting Sensitive Compartmented Information Within Information Systems”.

(pdf) (doc)

  1. Principal Accrediting Authority — responsibility for all intelligence systems within their respective purviews, are the DCI, EXDIR/CIA, AS/DOS (Intelligence & Research), DIRNSA, DIRDIA, ADIC/FBI (National Security Div), D/Office of Intelligence/DOE, SAS/Treasury (National Security), D/NIMA, and the D/NRO
  2. Data Owner — final statutory and operational authority for specified information
  3. Designated Accrediting Authority — authority to assume formal responsibility for operating a system at an acceptable level of risk based on the implementation of an approved set of technical, managerial, and procedural safeguards
  4. Designated Accrediting Authority Representative (DAA Rep) — technical expert responsible to the DAA for ensuring that security is integrated into and implemented throughout the life cycle of a system
  5. Information System Security Manager (ISSM) — responsible for an organization’s IS security program
  6. Information System Security Officer (ISSO) — responsible to the ISSM for ensuring that operational security is maintained for a specific IS
  7. Privileged Users — access to system control, monitoring, or administration functions
  8. General Users — can receive information from, input information to, or modify information on, a system without a reliable human review

They provide a good exercise in defining relationships with compartmentalised information; it’s fun to try and make a diagram that shows the connections and overlap.

DCID 6/3 in 1999 superseded DCID 1/16, which had the much more fun title of “Security Policy for Uniform Protection of Intelligence Processed in Automated Information Systems and Networks“.

DCID 1/16 was from 1988 and superseded DCID 1/16 of 1983 — a time of great US government concern about outsider attacks and NSA’s first attempt to wrestle control of the Internet away from NIST.

Phoenix Law Enforcement Arrest Moles

Twelve officers from the Maricopa County Sheriff’s Office have been arrested. Three are named:

…Deputy Sheriff Alfredo Navarrette, Detention Officer Silvia Rios-Najera, and Detention Officer Marcella Hernandez, all ICE-trained officers.

They are accused of tipping off drug traffickers and human smugglers about ongoing investigations.

Hernandez allegedly had an ongoing personal relationship with a major drug kingpin and was 8-months pregnant with his child. According to court documents, she arranged the transfer of multiple heroin loads and allowed her boyfriend’s drug trafficking organization to use her two houses as stash houses.

Perhaps the most shocking revelation is that Navarrette used to work in the anti-human smuggling unit for a short time, and when officers raided his house, they found two illegal immigrants being housed inside.

Two of the three were charged with use of electronic communication in drug related transactions.

“Quit Coal” Painted on Fisk Smokestack

I often talk about the need for quick response to threats to critical infrastructure but here’s a video of Greenpeace climbers who took a long time to scale a 455 ft smokestack at a power plant in Chicago and paint it with giant letters: “QUIT COAL”

FOX News reports that the sign is related to a protest movement to regulate urban emissions.

Studies indicate that Chicago has the highest concentration of people in the country living near coal-fired power plants.

The Chicago City Council for the past year has been discussing an ordinance for clean energy generation sponsored by Alderman Daniel Solis.

The ordinance would obligate Fisk and Crawford to substitute natural gas for coal.

In addition, it would subject other polluting plants around Pilsen and Little Village to strict emission controls.

The proposed ordinance establishes that if a facility has a quarterly emissions average exceeding federal and state limits, it must suspend its operations until pollution controls are installed to bring it into compliance with those standards.

Will the Fisk plant just paint over the QUIT at the top?

Easy to turn the protest sign right back into a COAL message — no QUIT — although the publicity of climbers getting arrested is still a factor.

Had they painted SUSPEND OPERATIONS UNTIL POLLUTION CONTROLS ARE INSTALLED it would have left behind a sign much harder to convert or paint over (and even better publicity from a more sophisticated and impressive attack). Painting over SUSPEND OPERATIONS UNTIL would leave the smokestack with POLLUTION CONTROLS ARE INSTALLED…

The Pissalyzer

A beer company in Italy has created a heat-activated coaster-sized sticker that fits in urinals for men. If they pass more than a pint’s worth of liquid the sticker reveals a message that says they should call a cab.

…after 25 seconds of pee – a length of time at the urinal that would only occur if the person relieving themself had drunk more than one pint of beer (the Italian drink-drive limit).

I am sure bars also like it because it reduces the cost of cleaning the men’s toilets.