Monday, June 04, 2018

Canadian Centre for Cyber Security to absorb CSE IT Security program?

It looks like the new Canadian Centre for Cyber Security (CCCS) announced in the 2018 budget (see p. 205) will be absorbing most, probably all, of the IT Security program at CSE.

[Update 12 June 2018: Confirmed. "From CSE, the entire IT Security branch will be transformed to become part of the Cyber Centre."]

Defence Minister Sajjan recently told The Hill Times (Jolson Lim, "Sajjan to unveil 20-year defence spending plan this spring; says active cybersecurity powers from Bill C-59 will be checked," Hill Times, 28 May 2018; subscribers only) that the CCCS will have a staff of about 750: "The cyber centre will unite approximately 750 employees from existing cybersecurity operations units at Public Safety Canada, Shared Services Canada, and the Communications Security Establishment into one organization, as part of CSE."

That's about one and half times the size of the entire IT Security staff at CSE. The Deputy Chief in charge of IT Security, Scott Jones, recently stated that CSE's ITSEC program has "around 500" employees, although that total would not include ITSEC's share of CSE's policy, administration, and support staff. Add in the (undisclosed number of) employees at Shared Services' Security Operations Centre and Public Safety's Canadian Cyber Incident Response Centre, who are being transferred to CSE to become part of CCCS, and you presumably get somewhat closer to the 750 figure, but substantial new hiring is also likely to be required. The $44.5-million on-going budget boost promised for the CCCS as part of Budget 2018 suggests that as many as 150-200 new employees might be brought on staff.

The U.K.'s National Cyber Security Centre (NCSC) already operates on this model. Created in 2016, the NCSC absorbed GCHQ's existing Communications-Electronics Security Group and merged it with a number of other cyber security organizations from across the U.K. government. Although it has a separate public identity, the NCSC remains an arm of GCHQ.

According to the Defence Minister, the Canadian Centre for Cyber Security will be fully operational by the fall of 2019. Sajjan also stated that the government expects to name the first head of the Centre "this spring", so presumably that announcement is imminent. ITSEC head Scott Jones is the obvious candidate for the job unless he has plans for some other role in the agency or elsewhere.

CSE is currently in the market for a new Chief for the entire agency, but the government hasn't hired from within CSE for that job since Stew Woolner got the position in 1989 so it would be a bit of a surprise if they went that route. Also, although Jones would undoubtedly be well qualified for the job of Chief, Acting Chief Shelly Bruce would likely be the first choice if agency employees were actually in the running.

All in all, I'd be surprised if Jones is not chosen to head the CCCS. Presumably we'll hear soon.

And maybe we'll learn more about plans for the CCCS when the government finally unveils its promised National Cyber Security Strategy.

Update 12 June 2018: Yup, Jones will be the head of the new centre.


Post a Comment

<< Home