4 ms·
Of course you could argue that those aren't necessarily separate missions. http://articles.latimes.com/2009/jul/14/opinion/oe-radack14 http://articles.latimes.
by subsystem 13y ago
Of course you could argue that those aren't necessarily separate missions.
http://articles.latimes.com/2009/jul/14/opinion/oe-radack14 http://articles.latimes.com/2009/jul/14/opinion/oe-radack14
- rdl 13y agoMost of the COMSEC mission is getting secure software/algorithms/protocols/standards speced, written, and deployed, not secure IDSes and stuff operational (that's generally been done at the service level or below). And generally the NSA's contribution to commercial security has been via their advisory role to NIST in the process to develop or select things like AES, SHA, etc. (and various FIPS, like 140-2, required to sell to government, but also used by private industry). The "NSA run CERT/IDS/etc." is obviously problematic, but I'm pretty happy to have NSA/NIST advising on algorithm selection, as long as the algorithms also are liked by the open community (giving NSA a veto, even a secret veto, seems fine as long as there are enough options.)