This week, House Majority Leader Harry Reid hopes to finally bring
the long awaited Cybersecurity Act of 2012 to the floor for debate.
Senator Joe Lieberman and the four co-sponsors of the Cybersecurity Act introduced a revised version last week,
which they indicate incorporates extensive negotiations with the bill’s
opponents. The Hill’s Technology Blog reports that Senators
Rockefeller and Feinstein are reaching out to key technology CEOs to help lend their support to the bill.
This is great, because if the bill doesn’t get voted on soon, it
won’t happen this year. President Obama has weighed in as well. The President wrote a rare op-ed piece in the Wall Street Journal
to boost support. He writes, “The American people deserve to know that
companies running our critical infrastructure meet basic, commonsense
cybersecurity standards, just as they already meet other security
requirements.”
This is in response to the bill’s critics who have stated that they
would be concerned about the costs to businesses that would be imposed
by the new law. John McCain’s bill, in contrast, focuses on
strengthening the government’s Cybersecurity, but stops short of
mandating that businesses do the same.
All this should be read in light of the larger Cyber conflict that is currently going on. New York Times writer David Sanger wrote last month
that an inside source had confirmed what many had suspected, that the
Obama administration had ordered a cyber attack against Iranian
enrichment facilities.
Maybe this was a good thing. There was no loss of life that we know
of, compared to a conventional military strike against Iranian
facilities. A Cyber retaliation from the Iranians or their allies would
have also been limited to computer infrastructure.
But the new Cybersecurity bill needs to be read in light of the fact
that the US government dropped the most sophisticated Cyberweapon on the
world that we have ever seen. It’s been analyzed and perhaps
reproduced by other countries. And unlike a physical war where
proximity to a conflict means greater risk, businesses are on the front
lines of a Cyber conflict. At a psychological level, most businesses
don’t have the same outlook that a business in a war torn country might
perceive their situation.
The reality of Cybersecurity in America is that it’s not just stolen
identity that businesses need to worry about. in November of 2011, for
the first time, Robert Bryant, U.S. National Counterintelligence
Executive released a report naming China as the world’s leading source of economic espionage,
with Russia coming in a close second. The reality is that by attacking
an economy is the equivalent of holding a government hostage, as the Russians did against Georgian banks in 2008.
Cybersecurity laws need to play catch up to the current state of the
world where a rogue nation like Iran or North Korea with nothing to lose
economically could lanuch a terrorist like attack against small or
medium sized businesses with very weak defenses and wreak havoc.
Unfortunately, the news today indicates that the bill is being fought on
mostly partisan lines despite months of compromise that went into the
new bill. Senator McCain wants to delay the bill and Heritage
Action, a conservative advocacy group related to the Heritage
Foundation indicated it will track lawmakers votes on their key vote
scorecard.
HackLaw is a blog dedicated to discussing the legal issues in information security and developments that may have an impack on information security law.
Showing posts with label Cybersecurity Act of 2012. Show all posts
Showing posts with label Cybersecurity Act of 2012. Show all posts
Thursday, July 26, 2012
Monday, March 19, 2012
McCain vs. Lieberman - SecureIT vs. Cybersecurity Act of 2012
Senator John McCain along with 5 other Republican senators released their counterproposal to the Lieberman-Collins Cybersecurity Act of 2012 released last month. The bill is called the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information and Technology (Secure IT) Act. Let me start by saying that when I see a bill that cleverly named so as to have an acronym that is readable, I immediately wonder how serious the authors of a bill are about its passage. I can't think of any bills off the top of my head that have actually passed that have been so named. HIPAA? Sarbanes Oxley? Digital Millenium Copyright Act?
I'm not sure how long it took McCain and the other Senators to write their counterproposal bill. It isn't clear whether the bill was already in progress or whether they started last month after hearing about the competing legislation. In any event, McCain’s bill was introduced only a week after the Lieberman bill. The Lieberman purports to have been the result of 3 years of negotiation and research. Mostly, the McCain bill appears to be a hodgepodge of the Cybersecurty Act of 2012 and other preexisting bills, with a ton of deletions and insertions of partisan elements.
Let’s look at the similarities and differences between the two bills:
Both bills have some provision for a Federal Cyber Scholarship-for-service program. The McCain bill copies word for word the first paragraph of the Lieberman bill. Where the Lieberman bill has provisions for how many scholarships are to be given (1,000) and provides for full tuition, the McCain bill provides no guidance on how many scholarships will be given, and only provides for tuition for 2 years of study. The Lieberman bill requires students to enter into a commitment for the same amount of time they spent in school, while the McCain bill requires one and a half times.
If I were a student, I’m not sure I’d be interested in the McCain offer. Less money for longer indentured servitude? Unfortunately, not many students would be able to sign up for the McCain proposal, since the McCain bill specifies that no additional funding will be allocated for Cybersecurity. This means that any money for scholarships would have to be carved out of departments individual budgets…presumably why the McCain bill doesn’t specify a specific number of scholarships. Presumably that number would be close to 0.
No new funding is problematic where issues of national security and defense come into play. If the national air traffic control network, for example, needs to be completely scrapped and a new secure network needs to be deployed, how could that be accomplished under the McCain bill? The FAA would have to carve that out of its budget, and small upgrades would have to happen over a long period of time. This is perhaps why Lieberman and Rockefeller have been so outspoken in their criticism of the McCain bill since the counterproposal.
The Lieberman bill has several sections that the McCain bill is missing entirely:
The McCain bill has several sections that the Lieberman bill is missing:
The Lieberman bill only mentions High Performance Computing once to make one small amendment while the McCain bill focuses on it for several pages. My only thought here is why? McCain’s changes to the High Performance Computing act of 1991 don’t even really have anything to do with security. The changes mostly read as funding modifications, which make me think this whole bill is about pork, and not security.
The Criminal Penalties section amends the Computer Fraud and Abuse Act, but mostly focuses on stiffening penalties and forfeiture of property directly or indirectly gained by said fraud and abuse. While these are okay goals of the act and could potentially be added to the Lieberman bill, the miss the point of the reality of hacking today. The most successful hackers operate internationally and are very difficult to capture. The McCain bill does nothing to address this new reality.
I'm not sure how long it took McCain and the other Senators to write their counterproposal bill. It isn't clear whether the bill was already in progress or whether they started last month after hearing about the competing legislation. In any event, McCain’s bill was introduced only a week after the Lieberman bill. The Lieberman purports to have been the result of 3 years of negotiation and research. Mostly, the McCain bill appears to be a hodgepodge of the Cybersecurty Act of 2012 and other preexisting bills, with a ton of deletions and insertions of partisan elements.
Let’s look at the similarities and differences between the two bills:
Both bills have some provision for a Federal Cyber Scholarship-for-service program. The McCain bill copies word for word the first paragraph of the Lieberman bill. Where the Lieberman bill has provisions for how many scholarships are to be given (1,000) and provides for full tuition, the McCain bill provides no guidance on how many scholarships will be given, and only provides for tuition for 2 years of study. The Lieberman bill requires students to enter into a commitment for the same amount of time they spent in school, while the McCain bill requires one and a half times.
If I were a student, I’m not sure I’d be interested in the McCain offer. Less money for longer indentured servitude? Unfortunately, not many students would be able to sign up for the McCain proposal, since the McCain bill specifies that no additional funding will be allocated for Cybersecurity. This means that any money for scholarships would have to be carved out of departments individual budgets…presumably why the McCain bill doesn’t specify a specific number of scholarships. Presumably that number would be close to 0.
No new funding is problematic where issues of national security and defense come into play. If the national air traffic control network, for example, needs to be completely scrapped and a new secure network needs to be deployed, how could that be accomplished under the McCain bill? The FAA would have to carve that out of its budget, and small upgrades would have to happen over a long period of time. This is perhaps why Lieberman and Rockefeller have been so outspoken in their criticism of the McCain bill since the counterproposal.
The Lieberman bill has several sections that the McCain bill is missing entirely:
- Information Sharing
- Public Awareness Reports
- International Cooperation
The McCain bill has several sections that the Lieberman bill is missing:
- High Performance Computing
- Criminal Penalties
The Lieberman bill only mentions High Performance Computing once to make one small amendment while the McCain bill focuses on it for several pages. My only thought here is why? McCain’s changes to the High Performance Computing act of 1991 don’t even really have anything to do with security. The changes mostly read as funding modifications, which make me think this whole bill is about pork, and not security.
The Criminal Penalties section amends the Computer Fraud and Abuse Act, but mostly focuses on stiffening penalties and forfeiture of property directly or indirectly gained by said fraud and abuse. While these are okay goals of the act and could potentially be added to the Lieberman bill, the miss the point of the reality of hacking today. The most successful hackers operate internationally and are very difficult to capture. The McCain bill does nothing to address this new reality.
Wednesday, February 22, 2012
McCain Disses the Department of Homeland Security, Dashes Hopes for Security Bill in 2012
Senator John McCain last week dissed the Department of Homeland Security, stating that the NSA is better suited to preventing cyberattacks. Wait, what? The NSA has tremendous cyber capabilities, don't get me wrong. But wasn't DHS formed to prevent the kinds of bureaucratic nightmares of sharing information between agencies. The DHS has a National Cybersecurity Center charged with protecting US Government communications networks.
This comes after a bipartisan committee of Senators including Joe Lieberman, Jay Rockafeller, and Susanne Collins brought a new bill last week that, at least on paper, had a good chance of passing this year. McCain and 8 other Senators rushed to criticize the bill, potentially dashing any hopes of passing a Cybersecurity bill this year. This bill is purported to have incorporated many of the proposals on Cybersecurity over the past several years, so potentially it was on the fast track to passage...and maybe it still does.
The Senator could have just as easily said that the FBI should be in charge of preventing cyberattacks. The issue of CyberSecurity is like a hot potato. Should the Department of Defense and the NSA have the ball? Or DHS and the NCS? Or the Department of Justice and the FBI? How do you determine whether an attack is coming from a government or an individual? A crime syndicate or a hacktivist group? Ultimately prevention and education, like this bill supports, are the best ways of keeping us all out of trouble...aside from unplugging our computers. Hopefully that doesn't get lost.
This comes after a bipartisan committee of Senators including Joe Lieberman, Jay Rockafeller, and Susanne Collins brought a new bill last week that, at least on paper, had a good chance of passing this year. McCain and 8 other Senators rushed to criticize the bill, potentially dashing any hopes of passing a Cybersecurity bill this year. This bill is purported to have incorporated many of the proposals on Cybersecurity over the past several years, so potentially it was on the fast track to passage...and maybe it still does.
The Senator could have just as easily said that the FBI should be in charge of preventing cyberattacks. The issue of CyberSecurity is like a hot potato. Should the Department of Defense and the NSA have the ball? Or DHS and the NCS? Or the Department of Justice and the FBI? How do you determine whether an attack is coming from a government or an individual? A crime syndicate or a hacktivist group? Ultimately prevention and education, like this bill supports, are the best ways of keeping us all out of trouble...aside from unplugging our computers. Hopefully that doesn't get lost.
Subscribe to:
Posts (Atom)