Welcome | Sign In
CRMBuyer.com
Law

New Bill Would Give Feds Sweeping Cybersecurity Enforcement Powers

Print Version
E-Mail Article
Reprints
New Bill Would Give Feds Sweeping Cybersecurity Enforcement Powers

If passed by Congress and signed into law by the president, the Cybersecurity Act of 2009 would mark a new dawn in securing the computer networks of utilities, banks, traffic control operations, telecoms and other entities critical to homeland security. Both government and private industry cybersecurity efforts have been ineffective up to now, proponents maintain.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

A bill introduced in the U.S. Senate would give the government dramatic new powers to regulate and enforce federal standards for cybersecurity.

The government already monitors and regulates military networks, of course. This measure, however, called the "Cybersecurity Act of 2009," would extend that control to private systems that power essential activities, such as the electric grid. New regulatory powers would compel industry compliance.

All of this would be overseen by a cybersecurity "czar," appointed by the president to helm a new Office of the National Cybersecurity Adviser. The cybersecurity chief would be empowered to shut down networks -- including private ones controlling utilities, banking, transportation traffic control or telecommunications -- if a cyberattack were underway.

The legislation is cosponsored by Senate Commerce Committee Chairman John D. Rockefeller IV, D-W.Va., and Sen. Olympia J. Snowe, R-Maine. The White House reportedly contributed to the bill, although it has not officially endorsed it.

Among its provisions, the bill would create a public-private clearinghouse for sharing information on cyber-threats, as well as licensing and certification standards for cybersecurity professionals. The measure would also create state and regional cybersecurity centers and expand a scholarship program for students who wish to focus on cybersecurity as a course of study.

Very Weak

Currently the Department of Homeland Security is tasked with providing assistance to private networks. However, government efforts have been trained largely on its military and national security IT backbone -- with questionable success Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales.

For example, it's widely suspected that China has successfully hacked its way into the Pentagon's computer systems.

Cybersecurity performance in the private sector is far from stellar.

Earlier this year, IBM (NYSE: IBM) researchers reported that poorly secured corporate Web sites were becoming a top cybersecurity threat, with companies increasingly putting their own clients at risk. Both commercial and custom-built software applications riddled with bugs and vulnerabilities were among the culprits.

The researchers also cited the increasing number of hacker attacks that used legitimate business sites as a launch pad for their activities -- usually through large-scale, automated SQL injection attacks.

The 'C' Word

The cybersecurity community appears to be withholding judgment on the proposed legislation until more details are revealed.

"It may wind up being a doubled-edge sword, like a lot of government regulation," Rohyt Belani, CEO of the Intrepidus Group, told the E-Commerce Times.

"What often happens is that regulators will come up with a rule or regulation in the tech space -- but once it is implemented it is clear they didn't think it through or ask a technologist for advice," Belani said.

On the positive side, he added, the measure could be used by security and compliance staff as an effective stick to secure more funds for IT security measures that management was reluctant to fund. "We call it the 'C' word," he said.

Given the Obama Administration's push for open forums and dialogue, Belani said he would like officials to give the cybersecurity community opportunities to review and comment on the proposal.

Troubling Issues

Even if the security community were to provide input, the bill would likely have some trouble spots.

Security is not something that is easy to measure, Jack Danahy, CTO and cofounder of Ounce Labs, told the E-Commerce Times. "It can be a combination of measures that can secure a network. You could have a lot of one thing and very little of another and still have the system be secure."

Entirely different combinations of products or ratios of measures could produce equally secure systems, he noted.

Generating metrics or measurements in the cybersecurity space is very difficult, said Danahy. "We have been grappling with this issue for years, trying to figure out how to best judge if something is secure."


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network