Senators Unveil Major Cybersecurity Bill

Measure Would Update FISMA, Encourage Sharing of Cyberthreats

By , February 14, 2012.
Senators Unveil Major Cybersecurity Bill

The long-awaited, wide-ranging cybersecurity legislation that would update the laws that govern how the federal government secures its information systems as well as help safeguard the vital private networks in which American society depends on was introduced in the Senate Feb. 14.

See Also: POS Security Essentials: How to Prevent Payment Card Breaches

The Cybersecurity Act of 2012 has been a half decade in the making as threats against government and private IT systems intensify.

"Our nation's vulnerabilities have already been demonstrated by the daily attempts by nation-states, cybercriminals and hackers to penetrate our systems," Sen. Susan Collins, R-Maine, one of the bill's sponsors, said in a Senate speech. "The threat is not just to our national security, but also to our economic well-being."

Collins, ranking member of the Senate Homeland Security and Governmental Affairs Committee was joined by Committee Chairman Joseph Lieberman, ID-Conn.; Senate Commerce Committee Chairman Jay Rockefeller, D-W.Va.; and Intelligence Committee Chairwoman Diane Feinstein, D-Calif., as chief sponsors of the bill.

The legislation would codify some of the authority the Obama administration has granted the Department of Homeland Security over federal civilian agency IT security and create the National Center for Cybersecurity and Communications within DHS, headed by a Senate-confirmed director, to coordinate federal efforts to battle cybersecurity threats facing the government and the nation's critical information infrastructure, the mostly privately owned networks that control the flow of money, energy, food, transportation and other vital resources that the economy needs to function.

Strengthening FISMA

The bill would amend the Federal Information Security Management Act to require the government to develop a comprehensive acquisition risk management strategy, moving away from a culture of compliance to one of security by giving DHS the authority to streamline agency reporting requirements and reduce paperwork through continuous monitoring and risk assessment.

Penetration testing through so-called red-team exercises would be emphasized under the bill's provisions as well as operational testing of systems to ensure agencies are aware of network vulnerabilities. The bill's sponsors say the legislation would also ensure agencies make informed decisions when purchasing IT products and services by directing the Office of Management and Budget to develop security requirements and best practices for federal IT contracts.

One of the more contentious parts of the bill is one that would establish a mechanism in which the owners of the national information infrastructure would help develop cybersecurity standards that they would need to follow.

'Regulation' Without Bite

DHS would assess the risk and vulnerabilities of critical infrastructure systems that threaten the nation's well-being to determine which networks should be required to meet a set of risk-based security standards. Operators of these systems who believe their systems are wrongly designated could appeal DHS's determination.

The bill calls for developing risk-based performance requirements, looking first to existing standards or industry practices. If a sector is sufficiently secured, no new performance requirements would be developed or required to be met. Under the bill, the owners of a covered system would determine how best to meet the performance requirements and then verify that it was meeting them. A third-party assessor could also be used to verify compliance, or an owner could choose to self-certify compliance. Current industry regulators such as the Securities and Exchange Commission for the banking industry would continue their oversight.

One group representing a segment of critical infrastructure owners, the Telecommunications Industry Association, liked the lack of stringent requirements in the bill: "Primary responsibility for the security of critical infrastructure should lie with the owners and operators of that infrastructure."

Follow Eric Chabrow on Twitter: @GovInfoSecurity

  • Print
  • Tweet Like LinkedIn share
Get permission to license our content for reuse in a myriad of ways.
ARTICLE Breach Delays USPS Financial Report

Breaches continue to plague the regular operations of victimized organizations. Take, for instance,...

Latest Tweets and Mentions

ARTICLE Breach Delays USPS Financial Report

Breaches continue to plague the regular operations of victimized organizations. Take, for instance,...

The ISMG Network