Showing posts with label Regulation. Show all posts
Showing posts with label Regulation. Show all posts

Wednesday, February 22, 2012

Soviet-Style Cybersecurity Regulation


Posted by Jim Harper

Reading over the cybersecurity legislative package recently introduced in the Senate is like reading a Soviet planning document. One of its fundamental flaws, if passed, would be its centralizing and deadening effect on society’s responses to the many and varied problems that are poorly captured by the word “cybersecurity.”
But I’m most struck by how, at every turn, this bill strains to release cybersecurity regulators—and their regulated entities—from the bonds of law. The Department of Homeland Security could commandeer private infrastructure into its regulatory regime simply by naming it “covered critical infrastructure.” DHS and a panel of courtesan institutes and councils would develop the regulatory regime outside of ordinary administrative processes. And—worst, perhaps—regulated entities would be insulated from ordinary legal liability if they were in compliance with government dictates. Regulatory compliance could start to usurp protection of the public as a corporate priority.
The bill retains privacy-threatening information-sharing language that I critiqued in no uncertain terms last week (Title VII), though the language has changed. (I have yet to analyze what effect those changes have.)
The news for Kremlin Beltway-watchers, of course, is that the Department of Homeland Security has won the upper-hand in the turf battle. (That’s the upshot of Title III of the bill.) It’s been a clever gambit of Washington’s to make the debate which agency should handle cybersecurity, rather than asking what the government’s role is and what it can actually contribute. Is it a small consolation that it’s a civilian security agency that gets to oversee Internet security for us, and not the military? None-of-the-above would have been the best choice of all.

Tuesday, February 21, 2012

On cybersecurity bill, battle lines forming


Posted at 10:00 AM ET, 02/17/2012

On cybersecurity bill, battle lines forming

Battle lines over new Senate legislation to defend the country against cyberattacks are forming on the issue of regulation, with some experts testifying on Thursday that the bill goes too easy on industry and others saying it is too tough.
The 207-page bill introduced this week would cover only those critical systems that the department secretary determines could lead to “mass” casualties, catastrophic economic damage or “severe degradation” of national security.
Software companies, for instance, would not be covered. Those that are would have to meet security requirements set by the secretary and the companies. The bill also allows for the two-way sharing of technical threat data between the government and the private sector.
“This bill includes significant loopholes that would keep our nation at risk,” said James A. Lewis, a cyber-expert with the Center for Strategic and International Studies, referring to software and other companies not covered.
...

Cyberweapons Treaties Might Help Prevent Cyberwar


26 October 2011 | 09:55 AM ET | Paul Wagenseil, SecurityNewsDaily Managing Editor

MIAMI — At the Hacker Halted cybersecurity conference here yesterday (Oct. 25), BT chief security technology officer Bruce Schneier suggested that international cyberweapons treaties might lessen the chance of a real cyberwar.
"We're in the early years of a cyberwar arms race," said Schneier in his keynote address. "This is dangerous. The cyberweapons could go off accidentally, and right now they're controlled at a rather low level in the military hierarchy. You don't want some colonel starting a war."
...