サイバーインテリジェンス共有および保護法(CISPA)は、2012年4月26日に米国下院でHR 3523として可決されたが、その年の後半に上院で停滞したサイバーセキュリティ法案です。2013年にHR624として議会の名簿に戻りました。CISPAは、「サイバー脅威インテリジェンスと情報共有、セクション1104」という新しいセクションを最後に追加することにより、1947年の国家安全保障法のタイトルXIを修正します。
新しいセクションの目的は、連邦政府の機関、民間企業、公益事業者がサイバー脅威インテリジェンスをタイムリーに共有して、コンピューターへの攻撃による重要なインフラストラクチャの中断や危害を防ぐことを可能にし、奨励することです。これらのエンティティのシステムとネットワーク。しかし、法案の範囲と文言は非常に物議を醸していることが証明されています。
支持者にとって、提案された法律は、情報共有が重要なサービスを混乱させたり、経済や国家安全保障を損なう前にサイバー攻撃に迅速に対抗できるようにし、企業が情報を共有し、訴訟のリスクなしに防御策を講じることを可能にする手段です。 。反対派にとっては、司法の監視なしに個人情報を共有することを許可し、既存のプライバシー法を回避することによって個人のプライバシー権を害し、インターネット活動の政府による監視などの悪用を招く可能性がある、広範で曖昧な法律です。
誰もが、私たちが潜在的に外国勢力、テロリスト、犯罪者、または悪意のある他者からのサイバー攻撃に対して脆弱であり、これらの攻撃が重要なサービスを混乱させる可能性があることに同意します。意見の相違は、この法案が本当に問題を解決するかどうか、そしてそれが善よりも害を及ぼす可能性があるかどうかにあります。
CISPAが対処することを意図している脅威の種類、および法案自体について詳しく知るために読んでください。
- CISPAはどのような脅威から保護することを意図していますか?
- 法案の歴史
- CISPAの主な規定
- なぜCISPAはそれほど物議を醸しているのですか?
- より問題のある言語
- CISPAを支持し反対するために行われた努力
- CISPAの代替案
- 現状
CISPAはどのような脅威から保護することを意図していますか?
CISPAが保護することを目的とする重要なインフラストラクチャには、電力、上下水道、輸送、通信、金融ネットワーク、政府機関などのサービスが含まれます。最近では、ほとんどすべての企業とすべての公益事業者、および政府自体が少なくとも部分的にオンラインになっており、1台のコンピューターから巨大なネットワークまで、インターネットに接続されているものはすべて衰弱させる攻撃に対して脆弱です。
この法案では攻撃の種類について詳しくは説明していませんが、一般的なものがいくつかあります。分散型サービス拒否(DDOS)攻撃では、多数の要求が企業のサーバーに送信され、正当なユーザーへのサービスが中断されます。 ; 中間者攻撃。あるサーバーから別のサーバーへの通信が傍受され、攻撃者のサーバーを介して実行され、スパイしたり、有害な変更を加えたりします。高度な持続的脅威(APT)は、特定の企業または他のエンティティに対する長期的な標的型攻撃です。攻撃者は、ウイルス、ワーム、スパイウェア、トロイの木馬、およびその他のマルウェア(悪意のあるソフトウェア)を標的のコンピューターにインストールして、大混乱を引き起こしたり、不正アクセスを取得したりすることを目的とする場合があります。
映画「ウォーゲーム」のように、ハッカーからの明白な侵入の試みがあります。そこでは、主人公が会社や政府のコンピューターシステムに直接ダイヤルしました。ユーザーとシステム管理者は、ソフトウェアやハードウェアファイアウォールなどの直接攻撃から保護する方法、ウイルス対策およびスパイウェア対策ソフトウェア、複雑なパスワードや多要素認証などの改善されたログイン方法を利用できます。
残念ながら、多くのシステムは、無意識のうちにログイン情報を提供したり、自分のマシンにマルウェアをインストールしたりするソーシャルエンジニアリング手法を使用する攻撃者によって侵害されています。フィッシングは、マルウェアを含むファイルの添付ファイル、正当に見えるが正当ではないが個人情報の要求ではないWebサイトへのリンクを含む電子メールが送信される一般的なソーシャルエンジニアリング手法です。スピアフィッシングと呼ばれるこの詐欺のより標的を絞ったバージョンがあり、攻撃者は意図された被害者について何かを知っており、それを使用して電子メールを正当なものにすることができます。
ハッキングされた人気のある開発者サイトから感染したソフトウェアをダウンロードしたときに、Apple、Facebook、Microsoft(およびおそらく他の企業)の従業員が餌食になった最近の事例で起こったように、ユーザーが自分で探しているソフトウェアでさえマルウェアが含まれている可能性があります。
悪意のあるソフトウェアは、コンピューターまたはコンピューターのネットワーク全体に感染し、スパイ、混乱、またはその他の悪意のある悪意のある攻撃を可能にする可能性があります。ボットと呼ばれるものをインストールすることにより、コンピューターが乗っ取られる可能性があります。これは、特定のタスクを自動的に実行し、外部ユーザーが所有者に知られていないコンピューターを制御できるようにするソフトウェアです。これらはゾンビコンピュータと呼ばれることもあります。ボットネットと呼ばれるこれらのハイジャックされたマシンのネットワークがあり、他の人に対して攻撃を仕掛けるために使用できます。
最近のニュースでは、他にも注目すべき攻撃がありました。Mandiantと呼ばれるサイバーセキュリティ会社の調査によると、中国のハッカーがニューヨークタイムズのネットワークに侵入し、中国の高官について書いている特定の記者の電子メールをスパイしているようです。BloombergNewsに対しても同様の試みが行われました。Mandiant [出典: Bodeen ]によると、他の企業に対する攻撃も中国にまでさかのぼります。
世界最大の石油生産者であるサウジアラムコがウイルスに襲われ、社内の約3万台のコンピューターのデータが、燃えている米国旗の写真に置き換えられ、コンピューターが使用できなくなりました。これらの攻撃は、明らかにインターネットに接続されていないコンピューターに追跡され、内部の仕事であるとの推測につながりました。
サイバー攻撃は、自分のスキルを誇示しようとしている個人、知的財産や財務情報を盗もうとしている犯罪者、大混乱をもたらすことを目的としたテロリストグループ、さらにはスパイや軍事活動の目的で政府によっても実行される可能性があります。また、潜在的なセキュリティ問題を指摘したい活動家や人々による違反もあります。より悪意のあるサイバー攻撃のコストは莫大なものになる可能性があり、企業秘密やその他のデータの損失、金銭の盗難、クリーンアップのコストが含まれる可能性があります。とりわけ、感染したシステムの修復。また、リスクには、私たち全員が依存しているサービスの中断も含まれます。
法案の歴史
The original CISPA was introduced as H.R. 3523 on Nov. 30, 2011 by Republican Mike Rogers of Michigan, chairman of the House Intelligence Committee, and co-sponsored by Democrat Dutch Ruppersberger of Maryland, ranking member of the same committee, as well as more than 20 other representatives, Democrat and Republican alike. It had the support of a lot of companies, including large telecommunications and tech companies, but faced a lot of opposition from civil liberties groups. On April 25, 2012, President Obama's administration even threatened that he would veto the bill for not doing enough to protect core infrastructure from cyberthreats and failing to protect the privacy, data confidentiality and civil liberties of individuals.
More than 40 amendments were proposed. Several pro-privacy amendments were rejected by the House Rules Committee on April 25. One amendment to allow the National Security Agency (NSA) or the Department of Homeland Security (DHS) additional surveillance authority was withdrawn on April 26. A few amendments were passed, increasing the original bill from 11 pages to 27 pages. These included the following:
- The Minimization Retention and Notification Amendment, which added provisions for notifying entities that have sent data that the government determines is not cyberthreat related, limitations on the use of the data and a statement that mentioned possible efforts to limit privacy and civil liberty impacts.
- The Definitions Amendment, which inserted or modified definitions for the terms "availability," "confidentiality," "cyber threat information," "cyber threat intelligence," "cybersecurity purpose," "cybersecurity system" and "integrity."
- The Liability Amendment, which changed the wording of a section waiving liability of private entities for sharing information to include identifying or obtaining cyberthreat information.
- The Limitation Amendment, which inserted a section that states that nothing in the bill will provide additional authority or modify existing authority of an entity to use a cybersecurity system owned by the federal government on a private-sector system or network.
- The Use Amendment, which adds language outlining the allowed uses of cyberthreat information shared with the government.
- A sunset clause was also added that makes the bill expire five years after its adoption.
The amended version of H.R. 3523 passed in the U.S. House of Representatives on April 26, 2012 by 248 to 168 votes, but never reached a vote in the U.S. Senate.
CISPA was reintroduced in the house by Senators Rogers and Ruppersberger in February 2013 under a different bill number, H.R. 624. It is virtually identical to the version of H.R. 3523 that passed the House in 2012.
Key Provisions of CISPA
CISPA concentrates entirely on sharing cyberthreat-related information between the government and private entities, and between private entities and other private entities. It makes provisions for government agencies to share both unclassified and classified information with private companies and utilities. For classified information, it specifies that the entities or individuals receiving information must be certified or have security clearance, and makes provisions for granting temporary or permanent security clearance to individuals within these entities.
また、民間企業と他の民間企業との間で情報を共有することもできます。これには、それらの企業を保護するために雇用されているサイバーセキュリティ会社も含まれます。また、民間団体がサイバー脅威に関する情報を連邦政府と共有するための規定を設けており、そのような情報を受け取った機関は、それをDHSの国立サイバーセキュリティおよび通信統合センターに送信することを指定しています。
CISPAは、情報公開法および州政府、地方政府、部族政府によって制定された同様の法律に基づく共有情報の開示を免除します。この法案は、企業(およびシステムを保護するために雇用されたサイバーセキュリティ会社)を、情報共有、サイバーセキュリティシステムの使用に関する訴訟から免除します。サイバー脅威情報を特定または取得するか、サイバー脅威情報に基づいて行う決定について、「誠実に」行動していることを条件とします。ただし、政府機関は、法案に記載されている情報開示および使用規則に「故意または故意に違反」した場合、違反日から2年の時効で訴えられる可能性があります。
この法案には、連邦政府が共有する情報をどのように使用できるかについての制限が含まれています。与えられた5つの正当な用途は次のとおりです。サイバーセキュリティの目的。サイバーセキュリティ犯罪の調査と起訴。死亡または重大な身体的危害からの個人の保護。児童ポルノ、性的搾取およびその他の関連する犯罪からの未成年者の保護。と国家安全保障の保護。政府は、サイバーセキュリティ犯罪の捜査および起訴以外の目的で情報を積極的に検索すること、および前文に記載されている目的以外の目的で情報を保持または使用することを制限されています。CISPAはまた、政府による図書館の使用を明確に制限しています流通記録、図書館利用者リスト、本の販売記録、本の顧客リスト、銃器の販売記録、納税申告記録、教育記録、医療記録。
この法案は、情報がサイバー脅威に関連していないと連邦政府が判断した場合、政府は情報を提供したエンティティに通知する必要があると述べています。
CISPAはまた、特定の政府機関によって作成および公開されなければならない手順とレポートを規定し、民間企業からのすべての情報共有を自主的に行い、参加しないことを選択した場合の罰則はなく、法案はインテリジェンスコミュニティの要素であり、民間または政府機関のサイバーセキュリティへの取り組みを指示する権利。
法案で定義されているサイバーセキュリティの目的には、次のものが含まれます。脆弱性から保護するための取り組み。完全性、機密性、または可用性に対する脅威。アクセスを拒否、劣化、混乱、または破壊するための努力。システムやネットワークへの不正アクセス、およびそれらに保存、処理、または移動する情報を取得するための取り組み。これには、情報を盗み出す(または削除する)不正アクセスが明示的に含まれますが、消費者の利用規約またはライセンス契約の違反のみを伴う不正アクセスは除外されます。サイバーセキュリティシステムとサイバー脅威インテリジェンスの定義には、同様の言葉が含まれています。
なぜCISPAはそれほど物議を醸しているのですか?
CISPAは、プライバシー、透明性、司法監視の欠如、サイバーセキュリティ、国家安全保障、その他の漠然と定義された用語を装って市民のインターネット活動の監視に使用される可能性など、さまざまな理由で多くの問題を抱えています。
1つの問題は、共有できるデータの種類を厳密に定義するのではなく、「サイバー脅威インテリジェンス」などの包括的な用語を使用していることです。これにより、企業は個人識別情報(PII)を含む、あらゆる種類の情報を取得して共有できる可能性があります。通信など。CISPAは、政府が共有するデータを匿名化、最小化、またはその他の方法で制限することを民間企業が主張することを許可していますが、企業がそのような制限を行う必要はありません。
連邦政府による共有情報の使用に関するサブセクションには、プライバシーと市民の自由に対処する段落がありますが、「連邦政府は、連邦システムと重要な情報インフラストラクチャをサイバーセキュリティの脅威から保護する必要性と一致して、このような脅威を軽減するために、このサブセクションに従って連邦政府とサイバー脅威情報を共有することによるプライバシーと市民の自由への影響を制限するための合理的な努力を行ってください。」「かもしれない」という言葉の使用はそれを自発的に聞こえさせ、これらの努力が何を伴うかについてのさらなる定義はありません。政府による情報の使用に関する年次報告書の作成に関するセクションでは、法案は「影響を判断するための測定基準、
The bill provides legal immunity to companies sharing information, even if it turns out they did it improperly, provided they acted in "good faith." It also allows immunity "for decisions made based on cyber threat information," but doesn't define "decisions made." From the companies' point of view, this allows them to freely share cyberthreat information and to act on that information without worrying about costly lawsuits , but it could completely curtail right of an individual or entity to sue for any harm done, since it is difficult to prove that someone didn't act in good faith. It has been argued that this immunity could also allow companies to do things like retaliation hacking of a suspected intruder to gain information or disrupt their systems.
Another controversial aspect of CISPA's wording is the potential it has to supersede a number of privacy laws.
More Problematic Language
CISPA potentially sidesteps judicial oversight through the term "notwithstanding any other provision of law," which overrides a lot of existing privacy laws, including the Wiretap Act, Cable Communications Act, Video Privacy Protection Act, Stored Communications Act and Electronic Communications Privacy Act -- acts that do provide rules and oversight regarding the sharing of personal information. In the case of CISPA, no warrant is required for the government to obtain personal information.
Even though individuals can sue the government if it willfully misuses their information, it could be very difficult to find out such a thing ever happened. Even if non-cyberthreat information is sent to the government, the government is only required to notify the sending entity, and no one is require to inform the person whose data was shared. And information shared is exempt from disclosure under Freedom of Information Act and other similar disclosure laws. There would have to be some obvious harm that pointed to the sharing, and it would have to be evident within two years of the time the federal government misused the data because of the statute of limitations.
CISPA is also under attack for not defining or limiting what government entities the information can be handed over to, aside from the stipulation that receiving agencies give it to the National Cybersecurity and Communications Integration Center of the DHS, which can share it with other agencies. The information could legally be given to any agency of the federal government, including intelligence agencies. How the government can use the information is defined broadly, as well, including "for cybersecurity purposes," which is somewhat vaguely defined in the bill, and "to protect the national security of the United States," which is fairly broadly defined in the National Security Act.
There is a notable dearth of terms related to technology in the bill. The word "computer" is only used within the definition of "cybersecurity crime" to include computer crimes in the list of possible violations. Otherwise, H.R. 624 refers to the things being protected as "systems and networks," which is somewhat ambiguous. The words and phrases "online," "Internet ," "Web," "digital," "information technology" and even "technology" are never used.
The original version of the bill included theft of intellectual property as one of the cybersecurity purposes. This has been removed from the latest version of CISPA, and language was inserted to specify that cyberthreat information does not include efforts to gain access involving violations of consumer terms of service or licensing agreements. However, some groups still fear that it can be used to pursue things like copyright infringement.
CISPA doesn't provide the legal means for the government to directly monitor people's online activities and digital data, but it does allow companies to voluntarily give undefined types and amounts of information that they deem cyberthreat information to the federal government, and the government can keep and use this data for reasons of cybersecurity, national security and investigation of a few other crimes. This and the fact that it can be given to any agency are causing consternation since this could allow intelligence agencies a sort of sideways access to personal information.
No one is arguing that sharing information on emerging threats isn't important in the fight to secure computer systems and networks from the ever-growing threat of attack, but arguments are being made to place limitations on the types of information shared and with what entities it can be shared. The supporters of CISPA counter that the bill is not intended for surveillance, and that the immunities are necessary to encourage companies to share information without fear of lawsuit. The opponents argue that the risks to privacy and civil liberties are too great in the bill as currently written.
Efforts Made in Support of and Opposition to CISPA
A number of private companies and trade associations have expressed support for CISPA. Many of them sent letters of support to the U.S. House of Representatives for either H.R. 3423, H.R. 624 or both, including AT&T, Verizon, US Telecom, Comcast, Time Warner Cable, the National Cable & Telecommunications Association, Edison Electric Institute, Financial Joint Trades, Financial Services Roundtable, Boeing, Lockheed Martin, IBM, Intel, Oracle, Symantec, Microsoft, Facebook, TechAmerica, the Internet Security Alliance, Juniper Networks, the National Cable & Telecommunications Association and the Chamber of Commerce. Facebook and Microsoft both backed away a little after protests and stated or implied that they would support changes to the final legislation that addressed privacy concerns.
The letters of support include praise for breaking down existing barriers to the timely sharing of cyberthreat intelligence with private entities, not placing regulatory burdens on private companies and protecting them from frivolous lawsuits and legal uncertainty with regards to sharing information, among other things.
But some companies and organizations concerned with privacy and civil liberties have vigorously spoken out against CISPA, including the Electronic Frontier Foundation, the American Civil Liberties Union, Access Now, the American Library Association, the Society of American Archivists, the Cato Institute, the Center for Democracy and Technology, the Entertainment Consumers Association, the Sunlight Foundation, Reporters Without Borders, the Society of Professional Journalists, the Rutherford Institute, the Republican Liberty Caucus, Mozilla and Tech Freedom, among others. Notable individuals who have expressed concerns include former Representative and Presidential candidate Ron Paul, who called the bill "Big Brother writ large," and Tim Berners-Lee, the inventor of the World Wide Web . And of course, there was the President's veto threat.
The EFF and some other opposing groups organized a "Week of Action" in mid-April 2012 to protest CISPA, during which they waged a grassroots campaign asking people to sign petitions, write, call and tweet Congressmen and otherwise express opposition to the bill. Nearly a million people did so the first go round, but despite this activity, CISPA did pass in the House -- albeit with a few changes.
As of early spring of 2013, similar pushes are being made to protest the bill anew. Within a day or so of CISPA being reintroduced in the House, hundreds of thousands of online signatures were reportedly collected and delivered to the U.S. House Intelligence Committee. We likely haven't heard the end of vigorous arguments on both sides of the issue.
Alternatives to CISPA
Some notable alternatives to CISPA have been put forth, including two bills introduced in the Senate and an Executive Order issued by President Obama.
One of the Senate bills is the Cybersecurity Act (S. 3414) introduced by Senators Joe Lieberman (I-CT), Susan Collins (R-ME) and three other senators. It is a much longer (in excess of 200 pages) and more detailed bill than CISPA that opens up ways for private entities and the federal government to share information related to cyberthreats, puts oversight of sharing in the purview of the DHS and also allows for setting up cybersecurity guidelines to be followed on a voluntary basis, but with incentives for compliance by private entities. It creates the National Cybersecurity Council (NCC) to be made up of representatives from multiple agencies (both civilian and military) to coordinate with the private sector to assess computer system vulnerabilities and come up with the guidelines.
The Cybersecurity Act was amended to include more protections to privacy and civil liberties, including a guarantee that only civilian (non-military) organizations have access to shared cyberthreat information and an exemption of first-amendment protected activities from being identified as categories of critical cyber infrastructure . It also doesn't include national security as one of the possible uses of shared cybersecurity information, but it does let the federal government use the information for the other three reasons allowed under CISPA.
A rival bill introduced by Senator John McCain (R-AZ) and several co-sponsoring senators is called the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information, and Technology Act (SECURE IT Act, S. 3342). It is also a heftier bill than CISPA, coming in at more than 100 pages. It would facilitate information sharing between multiple government agencies and private entities on cyberthreats, strengthen criminal penalties related to cybercrimes, foster networking and information technology research and development and sharing of research, and would allow the Department of Commerce, Department of Homeland Security, and the National Security Agency (NSA) to coordinate on policies regarding cybersecurity efforts. It has faced many of the same criticisms as CISPA, including that it has an overbroad definition of cyberthreat information, places few limits on the types of information that can be shared and how it can be used (including cybersecurity purposes, national security purposes and a whole host of criminal prevention, investigation and prosecution purposes), similar "notwithstanding any other provision of law" language and oversight issues, such as the removal of lawsuit liability from companies and the shared information being exempt from the Freedom of Information Act. It is also criticized for putting a non-civilian entity (the NSA) in charge of information sharing.
The Current State of Affairs
As of early 2013, neither Senate bill passed, but in the wake of CISPA's resurrection in the House, President Obama issued an Executive Order (EO) that covers some of the ground of the proposed cybersecurity bills, including timely sharing of information on cyberthreats from the federal government to critical infrastructure entities and companies that provide cybersecurity services. It does not enable any new sharing of information in the other direction (from private companies to public entities). It takes an existing Defense Industrial Base (DIB) information sharing program called the Enhanced Cybersecurity Services program, which was put in place to allow the Department of Defense (DoD) and the DHS to share non-classified cybersecurity information with defense contractors and the like, and expands it by allowing it to cover the other government agencies and critical infrastructure sectors. Like CISPA, the EO addresses creating an avenue for critical infrastructure personnel to gain security clearance for the sharing of classified information. It charges the National Institute of Standards and Technology (NIST) and others to work collaboratively with industry experts to create a cybersecurity practices framework to help reduce cyberthreat risks to infrastructure, and calls on the DHS to develop incentives to promote adoption of the framework.
The EO also calls for the Chief Privacy Officer and Officer for Civil Rights and Civil Liberties of the DHS to assess privacy and civil liberties risks and make recommendations on how to minimize and mitigate those risks. They are to use the Fair Information Practice Principles (FIPP) and other related policies to evaluate cybersecurity activities to this end, and their assessments are to be made available to the public.
Since CISPA is under consideration once more, no rival cybersecurity bills have passed yet and cyberthreats appear to be on the rise, the debate on how best to handle cybersecurity, especially sharing of information from private industry to government, is far from over. But perhaps all the rousing debates and calls to action will help whatever laws are ultimately passed to best straddle the line between too much and too little sharing while providing real protections.
Lots More Information
Author's Note: How CISPA Works
Being an IT worker, a writer and a heavy Internet user, I'm concerned about the security of our computers and networks. Lord knows I don't want my data stolen, or a cyberattack to take down the Internet or cut the power. How would I watch an entire season of "Downton Abbey" on Netflix while simultaneously writing an essay, checking e-mail and surfing the net for Grumpy Cat pictures?
But I'm equally concerned about privacy. The less of my data flowing out to people I never intended to look at it, the better. There is no telling how the NSA would interpret one of my short stories.
Reading through these bills and thinking about what could possibly go wrong due to wording issues was pretty fascinating. I'm sure that the drafters of all such legislation are by and large well-meaning people trying to proactively snuff out security threats. But "well-meaning" means about as much as "good faith" in legal terms. Not everyone on the planet has good intentions, as we are reminded daily by the news, and anything that can be used for ill or even just misguided purposes probably will be at some point. So I hope that whatever bill passes is extremely well-thought-out and vetted by industry, civil liberty and legal experts alike. Keep the Internet safe for Grumpy Cat.
Related Articles
Sources
- Albanesius, Chloe. "Obama's Cybersecurity Executive Order vs. CISPA: Which Approach Is Best?" PC Magazine. February 13, 2013. (March 11, 2013) http://www.pcmag.com/article2/0,2817,2415380,00.asp
- Biddle, Sam. "What is CISPA?" Gizmodo. April 26, 2012. (March 3, 2013)http://gizmodo.com/5905360/what-is-cispa
- Bodeen, Christopher. "Yang Jiechi, China's Foreign Minister, Dismisses Hacking Claims by U.S." Huffington Post. March 09, 2013. (March 09, 2013) http://www.huffingtonpost.com/2013/03/09/yang-jiechi-chinas-foreig_n_2844984.html
- Bradbury, Danny. "With cyber attacks on the rise, is your company's data secure?" Guardian. February 11, 2013. (March 9, 2013)http://www.guardian.co.uk/media-network/media-network-blog/2013/feb/11/cyber-attack-security-data
- Bucci, Steven P. "Securing U.S. Computer Networks with SECURE IT." The Heritage Foundation. July 16, 2012. (March 10, 2013) http://www.heritage.org/research/reports/2012/07/securing-us-computer-networks-with-secure-it
- Bumiller, Elisabeth and Thom Shanker. "Panetta Warns of Dire Threat of Cyberattack on U.S." New York Times. October 11, 2012. (March 6, 2013)http://www.nytimes.com/2012/10/12/world/panetta-warns-of-dire-threat-of-cyberattack.html
- CNBC. "Code Wars: America's Cyber Threat." (March 9, 2013)http://www.cnbc.com/id/42210831/Code_Wars_America039s_Cyber_Threat
- Couts, Andrew. "Not CISPA: Revised Senate Cybersecurity Bill Praised by Civil Liberty Advocates." Digital Trends. July 20, 2012. (March 9, 2013)http://www.digitaltrends.com/web/not-cispa-revised-senate-cybersecurity-bill-praised-by-civil-liberty-advocates/
- FBI. "Computer Intrusions." (March 9, 2013)http://www.fbi.gov/about-us/investigate/cyber/computer-intrusions
- FBI. "Spear Phishers - Angling to Steal Your Financial Info." April 1, 2009. (March 9, 2013)http://www.fbi.gov/news/stories/2009/april/spearphishing_040109
- Fitzpatrick, Alex. "CISPA Cybersecurity Bill Passes House, With Some Amendments." Mashable. April 26, 2012. (March 8, 2013)http://mashable.com/2012/04/26/cispa-passes-house/
- Fitzpatrick, Alex. "Internet Activists Deliver 300,000 Anti-CISPA Signatures to Congress." Mashable. February 15, 2013. (March 11, 2013) http://mashable.com/2013/02/15/cispa-petitions/
- Glass, Nick. "Cloud threats and firewalls: Internet guru demystifies cyber security." CNN. March 5, 2013. (March 9, 2013)http://www.cnn.com/2013/03/05/tech/threat-cloud-cyber-security/index.html
- Greenberg, Andy. "President Obama's Cybersecurity Executive Order Scores Much Better Than CISPA on Privacy." Forbes. February 12, 2013. (March 11, 2013) http://www.forbes.com/sites/andygreenberg/2013/02/12/president-obamas-cybersecurity-executive-order-scores-much-better-than-cispa-on-privacy/
- Gross, Doug. "Report: Eastern European gang hacked Apple, Facebook, Twitter." CNN. February 20, 2013. (March 9, 2013)http://www.cnn.com/2013/02/20/tech/web/hacked-apple-facebook-twitter
- Harris, Leslie. "CISPA: Progress, But Flaws Remain." Center for Democracy and Technology. April 24, 2012. (March 11, 2013) https://www.cdt.org/blogs/leslie-harris/2404cispa-progress-flaws-remain
- Hartman, Rachel Rose. "CISPA: The controversy surrounding it and how it might affect you." ABC News. April 27, 2012. (March 11, 2013) http://abcnews.go.com/Politics/OTUS/cispa-controversy-surrounding-affect/story?id=16229426
- Jackson, William. "McCain's retooled Secure IT act still a privacy threat, critics say." GCN. July 2, 2012. (March 10, 2013) http://gcn.com/Articles/2012/07/02/Secure-IT-Act-amended-critics-say-still-threat-to-privacy.aspx?Page=1
- Jaycox, Mark M. and Kurt Opsahl. "CISPA is Back: FAQ on What it is and Why it's Still Dangerous." Electronic Frontier Foundation. February 25, 2013. (March 3, 2013)https://www.eff.org/cybersecurity-bill-faq
- Jaycox, Mark M. "CISPA, the Privacy-Invading Cybersecurity Spying Bill, Is Back in Congress." February 13, 2013. (March 6, 2013)https://www.eff.org/deeplinks/2013/02/cispa-privacy-invading-cybersecurity-spying-bill-back-congress
- Kelly, Heather. "Cyber-criminals are targeting phones and bank info." CNN. February 21, 2013. (March 9, 2013)http://www.cnn.com/2013/02/21/tech/mobile/mcafee-threats-report
- Koebler, Jason. "Civil Liberties Organizations Launch Protests Against CISPA." US News & World Report. April 16, 2012. (March 11, 2013) http://www.usnews.com/news/articles/2012/04/16/civil-liberties-organizations-launch-protests-against-cispa
- Library of Congress - Thomas. "Bill Text Versions 112th Congress (2011-2012) H.R. 3523." (March 8, 2013)http://thomas.loc.gov/cgi-bin/query/z?c112:H.R.3523:
- Magid, Larry. "Privacy Advocates Prefer Obama's Cybersecurity Plan Over CISPA." Forbes. February 21, 2013. (March 8, 2013)http://www.forbes.com/sites/larrymagid/2013/02/21/privacy-advocates-prefer-obamas-cybersecurity-plan-over-cispa/
- Magid, Larry. "What is CISPA and Why Would the President Veto It?" Forbes. April 25, 2012. (March 9, 2013)http://www.forbes.com/sites/larrymagid/2012/04/25/what-is-cispa-and-why-would-the-president-veto-it/
- McCullagh, Declan. "How CISPA would affect you (faq)." CNET. April 27, 2012. (March 3, 2013)http://news.cnet.com/8301-31921_3-57422693-281/how-cispa-would-affect-you-faq/
- McCullagh, Declan. "Microsoft backs away from CISPA support, citing privacy." CNET. April 27, 2012. (March 11, 2013) http://news.cnet.com/8301-33062_3-57423580/microsoft-backs-away-from-cispa-support-citing-privacy/
- O'Grady, Jason D. "Apple, Facebook employees hacked via website malware, Java vulnerability." ZDNet. February 21, 2013. (March 09, 2013)http://www.zdnet.com/apple-facebook-employees-hacked-via-website-malware-java-vulnerability-7000011601/
- Opsahl, Kurt. "The CISPA Government Access Loophole." EFF. March 1, 2013. (March 8, 2013)https://www.eff.org/deeplinks/2013/02/cispa-government-access-loophole
- Perlroth, Nicole. "Connecting the Dots After Cyberattack on Saudi Aramco." New York Times. August 27, 2012. (March 6, 2013)http://bits.blogs.nytimes.com/2012/08/27/connecting-the-dots-after-cyberattack-on-saudi-aramco/
- Perlroth, Nicole. "Hackers in China Attacked The Times for Last 4 Months." New York Times. January 30, 2013. (March 6, 2013)http://www.nytimes.com/2013/01/31/technology/chinese-hackers-infiltrate-new-york-times-computers.html?_r=0
- Peterson, Andrea. "Cybersecurity Bill Supporters Regroup As Executive Order Looms." Think Progress. February 6, 2013. (March 6, 2013)http://thinkprogress.org/security/2013/02/06/1548761/cispa-executive-order/
- Reitman, Rainey. "Even with Rogers' Amendments, CISPA is Still a Surveillance Bill." EFF. April 26, 2012. (March 8, 2013)https://www.eff.org/deeplinks/2012/04/even-rogers-amendments-cispa-still-surveillance-bill
- Reitman, Rainey. "Industry Experts to Congress: We Can Remove Personally Identifiable Information Before Reporting Cybersecurity Threats." EFF. February 16, 2013. (March 9, 2013)https://www.eff.org/deeplinks/2013/02/industry-experts-congress-we-can-remove-personally-identifiable-information
- Reitman, Rainey. "Victory Over Cyber Spying." EFF. August 2, 2012. (March 11, 2013) https://www.eff.org/deeplinks/2012/08/victory-over-cyber-spying
- Richardson, Michelle. "CISPA Claws Back to Life." ACLU. February 10, 2013. (March 9, 2013)http://www.aclu.org/blog/technology-and-liberty-national-security/cispa-claws-back-life
- Richardson, Michelle. "New Cybersecurity Amendments Unveiled to Address Privacy Concerns." ACLU. July 19, 2012. (March 9, 2013)http://www.aclu.org/blog/national-security-technology-and-liberty/new-cybersecurity-amendments-unveiled-address-privacy
- Richardson, Michelle. "President Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure." ACLU. February 13, 2013. (March 6, 2013)http://www.aclu.org/blog/national-security-technology-and-liberty/president-obama-shows-no-cispa-invasion-privacy-needed
- Sasso, Brendan. "Longtime friends Lieberman, McCain divided over cybersecurity legislation." The Hill. March 14, 2012. (March 10, 2013) http://thehill.com/blogs/hillicon-valley/technology/215907-senators-mccain-lieberman-disagree-its-a-real-doozy
- Staff writer. "How a 'denial of service' attack works." CNET. February 9, 2000. (March 9, 2013)http://news.cnet.com/2100-1017-236728.html
- Steele, Patrick. "Voices of Opposition Against CISPA." EFF. April 19, 2012. (March 9, 2013)https://www.eff.org/deeplinks/2012/04/voices-against-cispa
- Symantec. "Advanced Persistent Threat (APT): The Uninvited Guest." (March 9, 2013)http://www.symantec.com/theme.jsp?themeid=apt-infographic-1
- Symantec. "Denial of service (DoS) attack." (March 9, 2013)http://www.symantec.com/security_response/glossary/define.jsp?letter=d&word=denial-of-service-dos-attack
- Symantec. "Man-in-the-middle attack." (March 9, 2013)http://www.symantec.com/security_response/glossary/define.jsp?letter=m&word=man-in-the-middle-attack
- Thrasher, Brown. "BREAKING: Senate CISPA Failes Cloture Vote." Daily Kos. August 2, 2012. (March 9, 2013)http://www.dailykos.com/story/2012/08/02/1116107/-BREAKING-Senate-CISPA-Fails-Cloture-Vote
- U.S. Government Printing Office. "S. 3342." June 27, 2012. (March 10, 2013) http://www.gpo.gov/fdsys/pkg/BILLS-112s3342pcs/pdf/BILLS-112s3342pcs.pdf
- U.S. Government Printing Office. "S. 3414." July 19, 2012. (March 10, 2013) http://www.gpo.gov/fdsys/pkg/BILLS-112s3414pcs/pdf/BILLS-112s3414pcs.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Backgrounder on the Rogers-Ruppersberger Cybersecurity Bill." (March 5, 2013)http://intelligence.house.gov/backgrounder-rogers-ruppersberger-cybersecurity-bill
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 3523 - Letters of Support." (March 11, 2013) http://intelligence.house.gov/hr-3523-letters-support
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 3523 - The Bill and Amendments." (March 8, 2013)http://intelligence.house.gov/hr-3523-bill-and-amendments
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 624." (March 6, 2013)http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/HR624.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 624 - Letters of Support." (March 3, 2013)https://intelligence.house.gov/hr-624-letters-support
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Myth v. Fact: Cyber Intelligence Sharing and Protection Act of 2013 (CISPA)." (March 6, 2013)http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/cispamythvactFeb122013v2.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Rogers & Ruppersberger Reintroduce Cybersecurity Bill to Protect the American Economy." February 13, 2013. (March 6, 2013)http://intelligence.house.gov/press-release/rogers-ruppersberger-reintroduce-cybersecurity-bill-protect-american-economy
- Vamosi, Robert. "Internet-scale 'man in the middle' attack disclosed." CNET. October 17, 2008. (March 9, 2013)http://news.cnet.com/8301-1009_3-10068327-83.html
- Vijayan, Jaikumar. "Privacy groups protest CISPA bill." Computer World. February 14, 2013. (March 11, 2013) http://www.computerworld.com/s/article/9236800/Privacy_groups_protest_CISPA_bill_
- Vijayan, Jaikumar. "Return of CISPA: Cybersecurity boon or privacy threat?" Computer World. March 1, 2013. (March 11, 2013) http://www.computerworld.com/s/article/9237262/Return_of_CISPA_Cybersecurity_boon_or_privacy_threat_
- White House. "Executive Order -- Improving Critical Infrastructure Cybersecurity." February 12, 2013. (March 6, 2013)http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity
- White House. "Executive Order on Improving Critical Infrastructure Cybersecurity." February 12, 2013. (March 11, 2013) http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity-0
- Whittaker, Zack. "'Privacy killer' CISPA is coming back, whether you like it or not." ZDNet. February 8, 2013. (March 11, 2013) http://www.zdnet.com/privacy-killer-cispa-is-coming-back-whether-you-like-it-or-not-7000011056/