The Macrosite for News, Analysis and Opinion about the Future of the Internet
Kim Davis

McCain's 'Do Little' Cybersecurity Bill

Written by Kim Davis
3/2/2012 11 comments
no ratings
DISCUSS     Email This

When Senate Majority Leader Harry Reid introduced a cybersecurity bill designed, essentially, to implement the White House's framework for protecting the nation's critical infrastructure, John McCain was quick to throw himself in front of the train, saying the bill would "stymie job creation" by imposing new costs on private industry. He told a meeting of the Homeland Security Committee:

If the legislation before us today were enacted into law, unelected bureaucrats at the DHS could promulgate prescriptive regulations on American businesses, which own roughly 90% of critical cyber infrastructure.

Meanwhile, the private sector enterprises potentially affected by the bill long ago set up a chorus of lamentation -- via the US Chamber of Commerce -- about burdensome regulations. Unsurprisingly, the companies which own key parts of the critical infrastructure would prefer incentives to new rules.

Yesterday, we were able to see what McCain's alternative looks like. The "Strengthening and Enhancing Cybersecurity by Using Research, Education, Information, and Technology Act" resolves into a neat acronym -- SECURE IT -- but otherwise is little more than an attempt to preserve the profoundly insecure status quo.

Introduced by McCain and seven fellow Senators, the bill seeks to improve cybersecurity without regulating existing systems. It's an application, in other words, of the principle that "more government is seldom a solution to any problem," as co-sponsor Saxy Chambliss put it.

Maybe the McCain proposal represents an alternative, and even streamlined route to the same goals? Let's take a look. The Cybersecurity Act of 2012 -- Harry Reid's preferred measure, which enjoys bipartisan support -- would make the Department of Homeland Security responsible for designating the elements of the infrastructure which need to meet a defined set of security standards.

The private sector would determine how best to meet the standards, but compliance would be verified, either by a third-party or through self-certification. Hardly draconian.

The SECURE IT Act takes the DHS out of the picture completely, and doesn't replace it with any other regulatory body. Rather, it emphasizes "partnership" and voluntary information sharing between the private sector and government. It does require federal contractors providing cybersecurity services to government to report threats to such services, conferring legal protections in return.

It does increase penalties for some cybercrimes, but proudly imposes no new regulations on industry.

There really are people who are prepared to say that cybersecurity can be left in private hands. Tom Ridge, former head of the DHS, is one of them. He told the Homeland Security Committee:

The private sector routinely thwarts cyber attacks against its networks because it is fast and nimble in its response and recovery efforts. A new regulatory regime would box in our critical infrastructures, hampering the freedom, agility, and innovation needed to deflect or defeat adversaries who are often quite amply resourced.

It's not that Ridge is crazy. It's just that he's now employed by the US Chamber of Commerce.

Of course the private sector thwarts cyberattacks. Doubtless it thwarts them every day and every hour. But it's equally evident that cybercrime is often spectacularly successful. Bringing down the Sony PlayStation network for weeks on end is one thing. Crashing the power grid for half that time would be a disaster. The NSA believes hackers could do it.

But let's trust industry not to let it happen.

— Kim Davis Follow me on TwitterVisit my LinkedIn pageFriend me on Facebook, Community Editor, Internet Evolution

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
slfisher
Thinkernetter
Sunday March 11, 2012 12:06:09 PM
no ratings

before I could make a decision one way or another. For example, I would have a real issue with a "national Internet ID card."

Kim Davis
Thinkernetter
Thursday March 8, 2012 9:59:18 AM
no ratings

Not the FBI Director adds his voice to NSA, telling Congress that protecting against terrorist cyberwar is urgent.

Story.

 

Kim Davis
Thinkernetter
Friday March 2, 2012 3:57:45 PM
no ratings

This might push a few buttons, but if there's genuine concern about government intruding on private enterprise, then you know what?  Nationalise those parts of the grid which are really critical.  I mean, we don't have private armed forces, and the grid seems to me to be as critical to national security.

Kim Davis
Thinkernetter
Friday March 2, 2012 3:55:58 PM
no ratings

I'm sufficiently persuaded that something needs to be.  After all, that the NSA found is necessary to say it was concerned about Anonymous attacking the grid is quite worrying.  But it doesn't follow, of course, that just anything needs to be done.

But I don't think it's draconian to hold the authentically key parts of the grid to security standards which can be set and reviewed at federal level.

Joe Stanganelli
Thinkernetter
Friday March 2, 2012 3:30:25 PM
no ratings

Yes, don't get me wrong; I've little doubt that your observation is correct, Kim.  It's just a matter of which bill -- if either -- should be passed.

FWiW, because no company *wants* to be hacked or have its systems or data compromised, and because IT professionals probably understand these issues better than many legislators (as the SOPA hearings showed us), I'm not convinced that a bill like McCain's that imposes less direct regulation but nonetheless facilitates business working together is necessarily bad.

At the same time, utiltiies and similar entities must be secure.

Perhaps, one might hope, an effective yet not overly intrusive compromise will be reached.

Kim Davis
Thinkernetter
Friday March 2, 2012 3:12:52 PM
no ratings

Joe, I admit I didn't wade through the bills for this piece, but relied on reporting.  I can see that there might be some concerns about the first bill,  but McCain's alternative strikes me as an entirely lobby-driven attempt to run the first bill into the ground.  Annoyingly cynical.

Joe Stanganelli
Thinkernetter
Friday March 2, 2012 3:10:46 PM
no ratings

Aha.  Thanks for highlighting this, Kim.

I took a peek at the actual bill (just a peek; it's a long one, it is); to be fair, it seems that it nonetheless may be a bit overly broad (particularly in terms of what may be designated as "critical infrastructure").

I am also concerned about this bill being implemented in conjunction with a national Internet ID card and the potential for abuse; indeed, the bill provides that the DHS will collaborate with NIST and the Department of Commerce -- agencies that have oversight over NSTIC (the Internet security card program).

In any case, I only read some of the bill, and have not read McCain's competing SECURE IT at all, so I might not really know what I'm talking about here.

Kim Davis
Thinkernetter
Friday March 2, 2012 2:58:12 PM
no ratings

Nice one, Bolingbroke.  I'd forgotten that.  The Senate, of course, has been the target of seveal breaches.

Bolingbroke
IQ Crew
Friday March 2, 2012 2:26:22 PM
no ratings

Ironic that the US Chamber of Commerce is involved in trying to squelch the security bill in light of the fact they were hacked not long ago by perhaps China.

Kim Davis
Thinkernetter
Friday March 2, 2012 2:25:29 PM
no ratings

I think you are mistaken, Joe (although it's always possible that I am).

The DHS is charged with determinng which private companies run a sufficiently important part of the infrastructure that they should be covered by these regulations, and "owners/operators who think their systems were wrongly designated would have the right to appeal".  So the intention of the legislation, at least, is not to do what you describe.

 

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Editor's Blog
Alison Diana
Alison Diana   5/24/2013   7 comments
The Memorial Day weekend begins with Geek Pride Day on Saturday. Kick off your holiday with nine news tidbits that are perfect for sharing at backyard BBQs and poolside get-togethers.
Kim Davis
Kim Davis   5/23/2013   13 comments
At the IBM Smarter Commerce Global Summit here in Nashville, I'm hearing many stories about how businesses have adapted their IT strategies in response to this rapidly changing, pressurized, data-driven commercial world.
Mitch Wagner
Mitch Wagner   5/21/2013   18 comments
Neal Stephenson is best known as the author of science fiction novels such as SnowCrash and Anathem. But he does other things as well. Among them: He's assembled a team of scientists and engineers to figure out how to build a 20-kilometer-tall tower to use as a platform for launching rockets into space.
Mitch Wagner
Mitch Wagner   5/21/2013   12 comments
While interstellar travel presents huge challenges, it's "almost inevitable," according to a speaker at the Starship Century symposium here in San Diego.
Mitch Wagner
Mitch Wagner   5/20/2013   6 comments
Tumblr founder and CEO David Karp reassured users on Monday that the service's freewheeling culture isn't changing.
5
of
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
what.the.ferraro
CMAS Alert! Something's Wrong! Or Not!

11|2|11   |   03:18   |   27 comments


If you have a CMAS-enabled handset, be prepared to receive scary alerts from the government.
Wisdom of the Big Chair
Facial Recognition Looms on the Horizon

7|27|11   |     |   4 comments


Law enforcement agencies are poised to use iPhones as facial recognition systems in the coming months. The technical advance promises efficiency but has created a backlash among civil liberties proponents.
Full Nelson
The New Cyber War

10|8|09   |   3:06   |   4 comments


Cyber Warfare may be the next frontier for tactical hacking. It has already reared its head in Estonia, Russia, and Georgia, and some say it has been used by North Korea, China, and other world powers. The implications and the potential are both fascinating and scary.
Second Shooter
Europe Considers One Network to Cover them All

1|17|13   |   1:45   |   12 comments


EU operators are considering joining up to create a pan-European network to reduce competitive overbuild and cost. This might lower costs and focus operators on higher-level, more interesting services.
Kim Davis
Aaron Swartz, RIP

1|14|13   |   2:36   |   6 comments


The Internet freedom activist, threatened with jail time, seems to have taken his own life last week.
Second Shooter
Moratorium on Internet Regulation Could Be Dangerous

12|6|12   |   2:15   |   No comments


Congress is considering a bill to extend a moratorium on Internet regulation changes for two years. But with issues like service quality, cloud performance, and privacy looming, we risk contaminating the Internet with fraud.
Kim Davis
British Hacking Report Is 'Bonkers'

12|5|12   |   2:20   |   3 comments


Prime Minister David Cameron pledged to accept the hacking report’s recommendations unless they were “bonkers.” He’s rejecting the main one.
Second Shooter
Don't Be Scared of the ITU

12|4|12   |   2:04   |   8 comments


The risk of the ITU taking over the Internet is overblown. First, it's almost certain its goals are simply to create orderly interconnect and settlement. Second, how good a job has ICANN done anyway? If we don't like international control we should clean up our own processes in both governance and interconnect!
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   4 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE