October 2010

Executive Branch Is Making Progress Implementing 2009 Cyberspace Policy Review Recommendations

To address pervasive computer-based (cyber) attacks against the United States that posed potentially devastating impacts to systems and operations, the federal government has developed policies and strategies intended to combat these threats. A recent key development was in February 2009, when President Obama initiated a review of the government's overall strategy and supporting activities with the aim of assessing U.S. policies and structures for cybersecurity. The resulting policy review report--issued by the President in May 2009--provided 24 near- and mid-term recommendations to address these threats. GAO was asked to assess the implementation status of the 24 recommendations. In doing so, GAO, among other things, analyzed the policy review report and assessed agency documentation and interviewed agency officials.

Of the 24 recommendations in the President's May 2009 cyber policy review report, 2 have been fully implemented, and 22 have been partially implemented. The two fully implemented recommendations involve appointing within the National Security Council a cybersecurity policy official (Special Assistant to the President and Cybersecurity Coordinator) responsible for coordinating the nation's cybersecurity policies and activities, and a privacy and civil liberties official. Examples of partially implemented recommendations include:

1) Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties, leveraging privacy-enhancing technologies for the nation: In June 2010, the administration released a draft strategy (entitled National Strategy for Trusted Identities in Cyberspace) that seeks to increase trust associated with the identities of individuals, organizations, services, and devices involved in financial and other types of online transactions, as well as address privacy and civil liberty issues associated with identity management. It plans to finalize the strategy in October 2010.
2) Develop a framework for research and development strategies: The administration's Office of Science and Technology Policy (which is within the Executive Office of the President) has efforts under way to develop a framework for research and development strategies, which as currently envisioned includes three key cybersecurity research and development themes, but is not expected to be finalized until 2011.

Officials from key agencies involved in these cybersecurity efforts, (e.g., the Departments of Defense and Homeland Security and the Office of Management and Budget) attribute the partial implementation status of the 22 recommendations in part to the fact that agencies are moving slowly because they have not been assigned roles and responsibilities with regard to recommendation implementation. Specifically, although the policy review report calls for the cybersecurity policy official to assign roles and responsibilities, agency officials stated they have yet to receive this tasking and attribute this to the fact that the cybersecurity policy official position was vacant for 7 months. In addition, officials stated that several mid-term recommendations are broad in nature, and agencies state they will require action over multiple years before they are fully implemented. This notwithstanding, federal agencies reported they have efforts planned or under way that are aimed toward implementing the 22 partially implemented recommendations. While these efforts appear to be steps forward, agencies were largely not able to provide milestones and plans that showed when and how implementation of the recommendations was to occur. Specifically, 16 of the 22 near- and mid-term recommendations did not have milestones and plans for implementation. Consequently, until roles and responsibilities are made clear and the schedule and planning shortfalls identified above are adequately addressed, there is increased risk the recommendations will not be successfully completed, which would unnecessarily place the country's cyber infrastructure at risk. GAO recommends that the national Cybersecurity Coordinator designates roles and responsibilities and develops milestones and plans for the recommendations that lacked these key planning elements.

(GAO-11-24)

Opportunities Exist to Improve Management of DOD's Electronic Health Record Initiative

The Department of Defense (DOD) provides medical care to 9.6 million active duty service members, their families, and other eligible beneficiaries worldwide. DOD's Military Health System has long been engaged in efforts to acquire and deploy an electronic health record system. The latest version of this initiative--the Armed Forces Health Longitudinal Technology Application (AHLTA)--was expected to give health care providers real-time access to individual and military population health information and facilitate clinical support. However, the system's early performance was problematic, and DOD recently stated that it intended to acquire a new electronic health record system. GAO was asked to 1) determine the status of AHLTA, 2) determine DOD's plans for acquiring its new system, and 3) evaluate DOD's acquisition management of the initiative. To do this, GAO reviewed program plans, reports, and other documentation and interviewed DOD officials.

After obligating approximately $2 billion over the 13-year life of its initiative to acquire an electronic health record system, as of September 2010, DOD had delivered various capabilities for outpatient care and dental care documentation. DOD had scaled back other capabilities it had originally planned to deliver, such as replacement of legacy systems and inpatient care management. In addition, users continued to experience significant problems with the performance (speed, usability, and availability) of the portions of the system that have been deployed. DOD has initiated efforts to improve system performance and enhance functionality and plans to continue its efforts to stabilize the AHLTA system through 2015, as a "bridge" to the new electronic health record system it intends to acquire. According to DOD, the planned new electronic health record system--known as the EHR Way Ahead--is to be a comprehensive, real-time health record for service members and their families and beneficiaries. The system is expected to address performance problems, provide unaddressed capabilities such as comprehensive medical documentation, capture and share medical data electronically within DOD, and improve existing information sharing with the Department of Veterans Affairs. As of September 2010, the department had established a planning office, and this office had begun an analysis of alternatives for meeting the new system requirements. Completion of this analysis is currently scheduled for December 2010. Following its completion, DOD expects to select a technical solution for the system and release a delivery schedule. DOD's fiscal year 2011 budget request included $302 million for the EHR Way Ahead initiative. Weaknesses in key acquisition management and planning processes contributed to AHLTA having fewer capabilities than originally expected, experiencing persistent performance problems, and not fully meeting the needs of users.

1) A comprehensive project management plan was not established to guide the department's execution of the system acquisition. (2) A tailored systems engineering plan did not exist to guide the technical development of the system, an effort that was characterized by significant complexity. (3) Requirements were incomplete and did not sufficiently reflect user and operational needs. (4) An effective plan was not used to improve users' satisfaction with the system.

DOD has initiated efforts to bring its processes into alignment with industry best practices. However, it has not carried out a planned independent evaluation to ensure it has made these improvements. Until it ensures that these weaknesses are addressed, DOD risks undermining the success of further efforts to acquire electronic health record system capabilities. GAO is recommending that DOD take six actions to help ensure that it has disciplined and effective processes in place to manage the acquisition of further electronic health record system capabilities. In written comments on a draft of this report, DOD concurred with GAO's recommendations and described actions planned to address them.

(GAO-11-50)

Tech CEOs go to the White House

The leaders of six technology companies are heading to the White House to send a message about how the government can reduce the deficit.

They will meet with Federal Reserve Chairman Ben Bernanke, Council of Economic Advisers Director Austan Goolsbee, National Economic Council Director Larry Summers and other economic officials. The tech leaders include the heads of IBM, Dell, Applied Materials, EMC, Intel, Motorola and Micron. IBM's chairman, Sam Palmisano, and Dell's chief executive, Michael Dell, will be in tow.

They will deliver their plan on reducing the deficit by $1 trillion over the next 10 years without new legislation. Their idea is to foster greater innovation in areas ranging from healthcare to education and energy to spur economic growth and create jobs. The Technology CEO Council believes the government can cut 30 percent of its IT overhead from the $76 billion it spends annually in this area, can cut money from its procurement processes by reducing duplication, and should reduce fraud and go digital rather than using paper.

Half of critical private-sector networks hit by politically motivated cyber attacks

Half of the companies that provide critical infrastructure such as utilities or communication services have experienced politically motivated cyber attacks, according to a new report from Symantec. A survey of critical infrastructure providers found 53 percent suspected they had experienced an attack with a specific political goal in mind. The companies affected reported being attacked an average of 10 times over the past five years. Half said they expect another attack in the next year and 80 percent believe the attacks are becoming more frequent. The respondents said the majority of the attacks were somewhat to extremely effective and cost firms an average of $850,000 each.

Could BITAG have stopped Comcast's network neutrality breach?

A group for Internet service providers could reduce litigation by building consensus between technical experts on whether certain network management practices are acceptable, according to Dale Hatfield, executive director of the Broadband Internet Technical Advisory Group (BITAG).

Companies such as Comcast, Verizon and AT&T formed BITAG in June along with Google, Microsoft, Intel, and a few others. The effort came as the Federal Communications Commission (FCC) considered making rules about how phone and cable companies manage Internet traffic. The techniques Internet service providers use to manage their networks can become controversial. Comcast launched years of litigation when it was caught interrupting service to people who use the high-bandwidth application BitTorrent, a file-sharing program. The company has since renounced the tactic, but the consequences of the litigation still have lawyers reeling. Hatfield said some details still need to be worked out, but took a question on how BITAG would approach an Internet service provider that wants feedback on a new network management practice. "An ISP contemplating a new or revised network management practice would submit a request to the BITAG asking for a review of the practice," he said. If a special committee of a working group accepts the request, he said, it would be assigned to a subcommittee. That might sound very bureaucratic, but at that point the engineers would start making technical headway. The first step is to understand how the practice works from a technical perspective.

NAB, CEA Backing TV-on-Net Technology

The National Association of Broadcasters and the Consumer Electronics Association are backing a technology designed to facilitate the distribution of TV stations over the Internet by insuring that only viewers within the stations' over-the-air market can receive them.

The technology is the latest from serial entrepreneur Jack Perry and the first from his new company, Syncbak. NAB made an investment in Syncbak in "the low six figures" earlier this year through its Fastroad program that seeds technology that may be of value to broadcasting, said EVP Dennis Wharton. "The investment recognizes that broadcast television service needs to evolve to reach viewers wherever they are and deliver programs to whatever device they may have," Wharton said. "Local broadcasting and signal distribution via the Internet have not been compatible concepts to date due to the global reach of the Internet. The local TV business model depends on program access based on geographic exclusivity. "The technology underpinning Syncbak allows viewers to be authorized so they will be able to receive the local station signals only in the area in which they reside, thus allowing Internet distribution of local television signals without violating the spirit of the geographic exclusivity business model," Wharton added. Jason Oxman, the CEA spokesman, said moving TV stations onto the Internet makes sense for all involved. "Our member companies are deploying television with Internet connectivity built in and content providers are making broadband-enabled content available at a rapid pace," he said. "The addition of broadcast content to those broadband pipelines would be beneficial to the manufacturers and consumers who buy them." And it is a "good business opportunity" for broadcasters, he said. "We think Syncbak has come up with a promising technology that allows for the seamless migration of broadcast content to the Internet."

Brainstorming: the FCC Mobile App

The Federal Communications Commission is working to develop more powerful and innovative mobile applications to put in consumers' hands and wants to hear your ideas for new FCC Mobile Applications. What kinds of functionality could we deliver? Guidelines and precautions for emergency situations? Tools that illuminate the sometimes fuzzy world of consumer electronics and billing? Maps that mash up FCC data with private sector data?

Research Shows Broadband Adoption Related to Clear Need for Its Use

The final day of the Telecommunications Policy Research Conference looked at broadband adoption and universality. The problems addressed are key in helping the government determine how broadband is being adopted and where intervention is necessary.

The panel on adoption included a presentation by John Horrigan from the Federal Communications Commission, who showed that non-adopters claim price is a major factor in their lack of access. When controlling for price, however, the paper found that one of the most powerful factors to get non-adopters to subscribe is the support of a social network that includes adopters. This theory is key to the FCC's digital literacy corps program. That initiative aims to train young people in technology in the hopes that they in turn will teach their families and communities. The lack of a social network that finds the Internet useful may be key in why the final non-adopters do not use the Internet. If these individuals do not have any adopters in their social network then they are not exposed to the benefits of broadband.

Janice Hauge from the University of North Texas discussed her paper on demand side policies that reinforced Horrigan's findings by showing that when individuals find technology relevant they are more likely to adopt it. "A program should motivate non-users to adopt, make broadband affordable, employ content in the training that relates to everyday life or the use of public services, and focus on the accessibility and usability of broadband and online services."

Nocil Tuner-Lee from the Joint Center observed that among African Americans, younger people are actively helping their community learn about the value of the Internet. This research mimics findings that the Rural Electrification Administration found in the 1930s when trying to expand electricity. The final panel of the day looked at the issues surrounding universal access. While it is clear to both the FCC and researchers that the Universal Service Fund is broken, there are numerous possible solutions.

Battle Over Music Royalties May Erupt In November

The MusicFIRST coalition urged Congress to pass a measure that would require AM and FM radio stations to pay performers a fee for playing their music on air, saying the music industry groups will use all of their power to advance the bill during a lame-duck session to be held in mid-November. Performance rights legislation has been approved by the House and Senate Judiciary committees, but has stalled with resistance from a host of lawmakers and the National Association of Broadcasters.

Internet Traffic up 62% in 2010

Data from research firm Telegeography shows that Internet traffic has grown 62 percent in 2010, after logging a handsome 74 percent growth in 2009.

The growth in traffic is coming from non-mature markets likes Eastern Europe and India, where traffic growth between mid-2009 and mid-2010 was in excess of 100 percent. This means the carriers, who added about 13.2 Tbps of new Internet capacity in 2010, will have to keep beefing up their networks. In comparison, carriers added 9.4 Tbps of capacity in 2009 and 6 Tbps in 2008. That said, the networks are not evenly divided. The capacity is still in abundance in larger, more mature markets, but less so in newer markets such as Africa. This will be changing soon, especially as we see deployment of new cables in those regions.

This new capacity in non-mature markets, when married to growth in wireless networks and easy availability of cheap smartphones, is going to turn the Internet on its head.