The pressure is on at the White House to quickly appoint a cybersecurity coordinator, following Melissa Hathaway's resignation from her role as acting senior director for cyberspace.
The new coordinator's position was created by President Obama in May to oversee the development and implementation of a government-wide cyber-security strategy. Although eight weeks have passed since Obama's announcement, the White House has yet to name anyone for the job.
"Melissa Hathaway leaving raises the priority for the President," said Alan Paller, director of research at the SANS Institute in Bethesda, Md. So long as Hathaway was around, the need to find someone more permanent was less urgent, he said. That situation has now changed.
The Wall Street Journal yesterday reported that Hathaway had resigned from her role as the Obama administration's top cybersecurity official for personal reasons. Hathaway had also said she did not to be considered for the White House cybersecurity post for the same personal reasons, the Journal reported.
Hathaway, a former Bush administration aide, was working as cybercoordination executive for the Office of the Director of National Intelligence (ODNI) when she was appointed to her new role by President Obama in February.
She was directed to conduct a 60-day review of government-wide cybersecurity preparedness, which she completed in April. Hathaway's much-anticipated report formed the basis of Obama's announcement of a new cybersecurity strategy in May and his plans to create a White House cybersecurity office.
The fact that he has yet to name anyone to the post -- despite the administration's self-professed focus on information security matters -- illustrates the challenge of finding someone willing to take on the job.
One of the biggest problems is the way the role is defined. When Hathaway and others in the security industry called for the creation of a White House cybersecurity post, the idea had been to establish an office that would have the clout needed to influence and enforce security changes in the government. What emerged, however, is largely seen as more symbolic than hands-on.
"The position as set up is designed more for bureaucracy and empire building, not driving change for the better of cybersecurity," said John Pescatore, an analyst at Gartner. "It really does need someone who is more interested in the political and visibility aspects, not the heavy lifting" required for better security.
The problem, according to Pescatore and others, lies with the fact that the new office reports both to the National Security Council and the National Economic Council. "It is really set up to be a liaison kind of position, put inside the National Security Council," he said, with no real power other than to coordinate between federal agencies.
Even so, agencies such as the US Department of Homeland Security and the National Institutes of Science and Technology will continue to shoulder much of the cybersecurity burdens, he said. "...I'm sure part of the problem is finding someone to take the position as defined."
Hathaway's resignation, though, could be a sign that a White House announcement could come soon, added Paller. "I think Melissa left because the announcement of a different person is imminent," he said.