Home Invites Blogs Careers Chat Events Forums Groups Members News Photos Polls Singles Videos
Home > > Post Content

Exec Order Could Ease Cybersecurity Bill Passage (162 hits)

Ridding Gov's Role in Setting Standards from Legislative Equation

By Eric Chabrow, December 7, 2012

A presidential executive order on cybersecurity, under review by the Obama administration, if issued might help ease passage of information security legislation in the 113th Congress, despite Republican objection to such a decree.

At the heart of the proposed executive order is a process in which the federal government, through the Department of Homeland Security, would collaborate with industry to establish IT security best practices that the mostly-private owners of the nation's critical infrastructure - banks, energy distribution companies, transportation networks, to name a few - could adopt voluntarily [see Administration Seeks Private Sector Counsel on Order].

Should President Obama issue the executive order, the need to include language on developing government-backed critical infrastructure protections wouldn't be necessary in any new legislation.

"Until we see the EO - assuming there is one - we won't know what they need to do in the law, but if it looks like the alleged drafts people say are floating around, they won't need to do much on critical infrastructure," says James Lewis, director of the Technology and Public Policy Program at the Center for Strategic and International Studies, a Washington think tank.

Provisions calling for just such a process helped torpedo the Cybersecurity Act of 2012, which twice failed to surmount a Republican-led filibuster [see Senate, Again, Fails to Halt Filibuster]. GOP lawmakers - with backers in business, notably the U.S. Chamber of Commerce - contend that businesses themselves know best on how to defend their networks. Also, some fear voluntary standards could turn into regulations.

"The proposal is not just for government to work with industry, which everyone knows they already do - but that government (would) have the final say as to what comes out," says Larry Clinton, chief executive of the Internet Security Association, a trade group.

When it became clear that the Cybersecurity Act would not pass the Senate, several of its Democratic sponsors called on Obama to issue an executive order to implement some of its provisions, such as establishing IT security best practices. Republicans, even one of the bill's sponsors - Sen. Susan Collins of Maine - cautioned the president against bypassing Congress with an executive order [see 'We Can't Wait' for Cybersecurity].

The Information Sharing Predicament

Another contentious provision of the Cybersecurity Act, information sharing between the government and industry, could only be addressed partially in an executive order because providing liability protection from information sharing can only be granted by an act of Congress. Many companies would be reluctant to share information about threats and vulnerabilities without being assured they won't be sued for liability.

Allan Friedman, research director of the Center for Technology Innovation at Brookings, a Washington think tank, says there are many different types of information sharing, many of which would not involve the dicey liability issue, a point often lost on members of Congress. "Lawmakers tend to treat all info sharing the same," Friedman says. "Engineers know that there's a huge difference between an attack signature from an intrusion-detection system and a profile of a new type of attacker."

Friedman says the executive order could encourage more collaboration between business and government, modeling new efforts after existing initiatives such as those between military contractors and the Defense Department, the DoD-Defense Industrial Base Collaborative Information Sharing Environment, and InfraGard, an FBI-business information sharing program aimed at safeguarding critical infrastructure.

The more contentious matters dealing with information sharing, which also includes protecting the privacy and civil liberties of citizens whose personal information could be exposed during exchanges of data between business and government, must be addressed by legislation.

http://www.govinfosecurity.com/exec-order-...
Posted By: Steve Williams
Friday, December 7th 2012 at 11:21AM
You can also click here to view all posts by this author...

Report obscenity | post comment
Share |
Please Login To Post Comments...
Email:
Password:

 
"The more contentious matters dealing with information sharing, which also includes protecting the privacy and civil liberties of citizens whose personal information could be exposed during exchanges of data between business and government, must be addressed by legislation."
Friday, December 7th 2012 at 11:23AM
Steve Williams
More From This Author
LETTERS TO TRUMP
Why was the public not told when they were discovered in November?
McCarthy thanks Trump after House speaker vote: 'He was with me from the beginning'
Donald Trump's 'Digital Trading Cards' Sold Out In One Day — Netting $4.4 Million
AFPAC II (2021) Nick Fuentes Full Speech
Ousted Twitter counsel Jim Baker vetted 'Twitter Files' without Elon Musk's knowledge, Matt Taibbi reveals
Herschel Walker Interview at First Baptist Atlanta
Nick Fuentes is not a White Supremacist
Forward This Blog Entry!
Home

(Advertise Here)
Who's Online
>> more | invite 
Black America Resources
100 Black Men of America
www.100blackmen.org

Black America's Political Action Committee (BAMPAC)
www.bampac.org

Black America Study
www.blackamericastudy.com

Black America Web
www.blackamericaweb.com

CNN Black In America Special
www.cnn.com/blackinamerica

NUL State of Black America Report
www.nul.org

Most Popular Bloggers
reginald culpepper has logged 14896 blog subscribers!
agnes levine has logged 13172 blog subscribers!
rickey johnson has logged 12258 blog subscribers!
tanisha grant has logged 9118 blog subscribers!
miisrael bride has logged 3962 blog subscribers!
>> more | add 
Latest Jobs
Human Resources Intern with Meals on Wheels America in Arlington, VA.
Staff Attorney or Senior Attorney for Oil, Gas, and Petrochemicals Program with Environmental Integrity Project in Austin, TX.
Environmental Protection Maintainer 1 - 260303-3487PS-001 - Apply by 3/23/26! with State of Connecticut, Executive Branch in Burlington, CT.
Processing Technician - 260305-6435CL-001 - Apply by 3/19/26! with State of Connecticut, Executive Branch in Middletown, CT.
USBP Recruitment Event in Sioux Falls, SD - April 7-9 with U.S. Customs and Border Protection in Sioux Falls, SD.
>> more | add