사이버 인텔리 전스 공유 및 보호법 ( CISPA는 ) HR 3523 4 월 (26) 2012 년 미국 하원을 통과 제안 된 사이버 보안 법안이지만, 그해 말에 상원에서 정체. 2013 년 의회 명단에 HR 624로 돌아 왔습니다. CISPA는 "사이버 위협 인텔리전스 및 정보 공유, Sec. 1104"라는 새로운 섹션을 끝에 추가하여 1947 년 국가 보안법의 타이틀 XI를 개정 할 것입니다.
새로운 섹션의 목표는 연방 정부 , 민간 부문 기업 및 유틸리티 기관이 사이버 위협 인텔리전스를 적시에 공유하여 컴퓨터 공격으로 인한 중요한 인프라의 중단 또는 피해를 방지 하도록 허용하고 권장하는 것입니다. 이러한 엔티티의 시스템 및 네트워크. 그러나 법안의 범위와 언어는 상당히 논란의 여지가 있습니다.
지지자들에게 제안 된 법안은 정보 공유가 중요한 서비스를 방해하거나 경제 또는 국가 안보를 훼손하기 전에 사이버 공격에 신속하게 대응하고 기업이 소송에 대한 소송 위험없이 정보를 공유하고 방어 조치를 취할 수 있도록하는 수단입니다. . 반대자들에게 이는 사 법적 감독없이 개인 정보를 공유 할 수 있도록 허용하고 기존의 개인 정보 보호법을 우회하여 개인의 개인 정보 권리를 침해하며 정부의 인터넷 활동 감시와 같은 남용을 유발할 수있는 지나치게 광범위하고 모호한 법률입니다.
모든 사람들은 우리가 잠재적으로 외국 세력, 테러리스트 , 범죄자 또는 악의를 가진 다른 사람들의 사이버 공격에 취약하며 이러한 공격이 필수 서비스를 중단시킬 가능성이 있다는 데 동의 합니다. 의견 차이는이 법안이 문제를 진정으로 해결하는지, 그리고 그것이 득보다 더 많은 해를 끼칠 수 있는지에 있습니다.
CISPA가 해결하려는 위협의 종류와 법안 자체에 대해 자세히 알아 보려면 계속 읽으십시오.
- CISPA는 어떤 종류의 위협으로부터 보호해야합니까?
- 법안의 역사
- CISPA의 주요 조항
- CISPA가 그토록 논란이되는 이유는 무엇입니까?
- 더 문제가되는 언어
- CISPA를지지하고 반대하는 노력
- CISPA의 대안
- 현 상황
CISPA는 어떤 종류의 위협으로부터 보호해야합니까?
CISPA가 보호하려는 핵심 인프라에는 전력, 상하수도, 교통, 통신, 금융 네트워크 및 정부 기관과 같은 서비스가 포함됩니다. 정부 자체뿐만 아니라 거의 모든 회사와 모든 유틸리티는 적어도 부분적으로는 온라인 상태이며, 단일 컴퓨터에서 거대한 네트워크에 이르기까지 인터넷에 연결된 모든 것은 약화 공격에 취약합니다.
이 법안은 공격 유형에 대해 자세히 설명하지 않지만 몇 가지 일반적인 공격이 있습니다. DDOS (분산 서비스 거부) 공격, 회사 서버로 많은 요청이 전송되어 합법적 인 사용자에게 서비스 중단이 발생합니다. ; 중간자 (man-in-the-middle) 공격 : 한 서버에서 다른 서버로의 통신이 가로 채서 공격자의 서버를 통해 실행되어 스파이하거나 유해한 변경을 수행합니다. 특정 회사 또는 기타 기관에 대한 장기적인 표적 공격 인 지능형 지속적 위협 (APT). 공격자는 대상 컴퓨터에 바이러스, 웜, 스파이웨어, 트로이 목마 및 기타 멀웨어 (악성 소프트웨어)를 설치하여 혼란을 일으키거나 무단 액세스를 얻을 수 있습니다.
주인공이 회사와 정부 컴퓨터 시스템에 바로 접속 한 영화 "전쟁 게임"과 같은 해커의 명백한 침입 시도가 있습니다. 사용자와 시스템 관리자는 소프트웨어 또는 하드웨어 방화벽과 같은 직접적인 공격으로부터 보호 할 수있는 방법을 가지고 있습니다.], 안티 바이러스, 안티 스파이웨어 소프트웨어, 복잡한 암호 나 다단계 인증과 같은 것을 포함하는 향상된 로그인 방법.
안타깝게도 많은 시스템이 무의식적으로 개인을 속여 로그인 정보를 제공하거나 자신의 컴퓨터에 맬웨어를 설치하는 사회 공학 방법을 사용하는 공격자에 의해 침해됩니다. 피싱 은 악성 코드가 포함 된 첨부 파일, 합법적 인 것처럼 보이지만 그렇지 않은 웹 사이트 링크 또는 개인 정보 요청과 함께 전자 메일이 전송되는 일반적인 사회 공학 방법입니다. 스피어 피싱 (spearphishing ) 이라고하는이 사기의보다 표적화 된 버전이 있습니다 . 공격자는 의도 한 피해자에 대해 알고 있으며이를 사용하여 전자 메일을 합법적으로 보이도록 만들 수 있습니다.
애플, 페이스 북, 마이크로 소프트 (그리고 아마도 다른 회사)의 직원들이 해킹 된 인기있는 개발자 사이트에서 감염된 소프트웨어를 다운로드 할 때 희생양이 된 최근 사례에서와 같이 사용자가 직접 찾는 소프트웨어에도 맬웨어가 포함될 수 있습니다.
악성 소프트웨어는 컴퓨터 또는 전체 컴퓨터 네트워크를 감염시킬 수 있으며 스파이, 중단 또는 기타 사악한 허위 행위를 허용 할 수 있습니다. 특정 작업을 자동으로 실행하고 소유자가 모르는 사이에 외부 사용자가 컴퓨터를 제어 할 수 있도록 허용하는 소프트웨어 인 봇 (bot)이라는 것을 설치하여 컴퓨터를 하이재킹 할 수 있습니다. 이를 좀비 컴퓨터 라고도 합니다 . 다른 사람에 대한 공격을 시작하는 데 사용할 수있는 봇넷이라는 이러한 하이재킹 된 시스템의 네트워크가 있습니다.
최근 뉴스에서 다른 주목할만한 공격이있었습니다. Mandiant라는 사이버 보안 회사의 조사에 따르면 중국의 해커가 뉴욕 타임스 네트워크에 침입하여 고위 중국 관리에 대해 글을 쓰는 특정 기자의 이메일을 감시 한 것으로 보입니다. Bloomberg News에 대해서도 유사한 시도가있었습니다. Mandiant [출처 : Bodeen ] 에 따르면 다른 회사에 대한 공격도 중국으로 추적되었습니다 .
세계 최대 석유 생산 업체 인 Saudi Aramco는 회사 내 약 3 만 대의 컴퓨터에있는 데이터를 불타는 미국 국기 사진으로 대체하는 바이러스로 공격을 받아 기계를 쓸모 없게 만들었습니다. 이러한 공격은 인터넷에 연결되지 않은 것으로 보이는 컴퓨터로 추적되어 내부 작업이라고 추측했습니다.
사이버 공격은 자신의 기술을 과시하려는 개인, 지적 재산 또는 금융 정보를 훔치려는 범죄자, 혼란을 일으키려는 테러리스트 그룹, 심지어는 간첩 또는 군사 활동을 목적으로 정부까지도 공격 할 수 있습니다. 잠재적 인 보안 문제를 지적하고자하는 활동 가나 사람들에 의한 침해도있을 수 있습니다.보다 악의적 인 사이버 공격의 비용은 엄청날 수 있으며 영업 비밀 및 기타 데이터 손실, 재정적 절도 및 정리 비용이 포함될 수 있습니다. 감염된 시스템의 복구 등이 있습니다. 또한 위험에는 우리 모두가 의존하는 서비스 중단도 포함됩니다.
법안의 역사
원래 CISPA는 2011 년 11 월 30 일 미시간 공화당의 마이크 로저스 하원 정보위원회 위원장에 의해 HR 3523으로 소개되었으며, 같은위원회의 위원 인 메릴랜드의 민주당 네덜란드 루퍼스 버거가 공동 후원했습니다. 20 명의 다른 대표, 민주당과 공화당 모두. 대형 통신 및 기술 회사를 포함한 많은 기업의 지원을 받았지만 시민 자유 단체의 많은 반대에 직면했습니다. 2012 년 4 월 25 일 오바마 대통령 행정부는 사이버 위협으로부터 핵심 인프라를 충분히 보호하지 못하고 개인의 프라이버시, 데이터 기밀성 및 시민의 자유를 보호하지 못한 것에 대해 법안을 거부하겠다고 위협하기도했습니다.
40 개 이상의 수정안이 제안되었습니다. 4 월 25 일 하원 규칙위원회에서 여러 가지 개인 정보 보호 수정안을 거부했습니다. 국가 안보국 (NSA) 또는 국토 안보부 (DHS)의 추가 감시 권한을 허용하기위한 수정안 1 개가 4 월 26 일 철회되었습니다. 몇 가지 수정안이 통과되었습니다. , 원본 청구서를 11 페이지에서 27 페이지로 늘 렸습니다. 여기에는 다음이 포함됩니다.
- 최소화 보존 및 알림 개정 데이터의 사용 제한 개인 정보 보호와 시민의 자유에 미치는 영향에 최대한의 노력을 언급 한 성명에서 정부가 cyberthreat 관련이없는 결정하는 데이터를 전송 한 기관, 한계를 통지하는 조항을 추가.
- 정의 개정 삽입 또는 용어 "가용성", "비밀", "사이버 위협 정보", "사이버 위협 정보", "사이버 보안의 목적", "사이버 보안 시스템"과 "무결성에 대한 정의를 수정."
- 책임 개정 식별 또는 cyberthreat 정보를 획득하는 단계를 포함 할 정보를 공유하기위한 민간 단체의 섹션 포기 책임의 표현을 변경.
- 제한 개정 권한을 추가 제공 또는 민간 부문의 시스템 또는 네트워크에 연방 정부가 소유 한 사이버 보안 시스템을 사용하는 기업의 기존 권한을 수정합니다 법안에 그 아무것도 언급하지 않는 부분을 삽입.
- 정부와 공유 된 사이버 위협 정보의 허용 된 사용을 설명하는 언어를 추가 하는 사용 수정안 .
- 이 법안이 채택 된 지 5 년 후에 만료되도록하는 일몰 조항도 추가되었습니다.
HR 3523의 수정 된 버전은 2012 년 4 월 26 일 미국 하원에서 248에서 168 표로 통과되었지만 미국 상원에서는 투표에 도달하지 못했습니다.
CISPA는 2013 년 2 월 Rogers 상원과 Ruppersberger 상원 의원에 의해 다른 법안 번호 HR 624로 재 도입되었습니다. 이는 2012 년 하원을 통과 한 HR 3523 버전과 거의 동일합니다.
CISPA의 주요 조항
CISPA는 정부와 민간 기관 사이, 민간 기관과 기타 민간 기관간에 사이버 위협 관련 정보를 공유하는 데 전적으로 집중합니다. 이는 정부 기관이 비공개 및 기밀 정보를 민간 기업 및 유틸리티와 공유하도록 규정합니다. 기밀 정보의 경우 정보를받는 주체 또는 개인이 인증을 받거나 보안 허가를 받아야 함을 명시하고 이러한 주체 내의 개인에게 임시 또는 영구 보안 허가를 부여하는 조항을 만듭니다.
또한 개인을 보호하기 위해 해당 회사에서 고용 한 사이버 보안 회사를 포함하여 민간 기업과 기타 민간 기업 간의 정보 공유를 허용합니다. 또한 민간 단체가 사이버 위협에 대한 정보를 연방 정부와 공유 할 수 있도록 규정하고, 그러한 정보를 수신하는 모든 기관이 DHS의 국가 사이버 보안 및 통신 통합 센터로이를 전송하도록 지정합니다.
CISPA는 정보 공개법 및 주, 지방 및 부족 정부가 제정 한 유사한 법률에 따라 공유 정보의 공개를 면제합니다.이 법안은 기업 (및 시스템 보호를 위해 고용 된 사이버 보안 회사)의 정보 공유 소송에서 사이버 보안 시스템을 사용하여 사이버 위협 정보 또는 사이버 위협 정보를 기반으로 내린 결정에 대해 "선의로"행동하는 경우 식별하거나 획득합니다. 정부 기관은 이 법안에 밖으로 철자 정보 공개 및 사용 규칙을 "의도적으로 또는 고의적으로 위반하는"경우, 그러나, 위반 일로부터 2 년 제한의 법령으로 소송을 제기 할 수있다.
이 법안에는 연방 정부가 공유 한 정보를 사용하는 방법에 대한 제한이 포함되어 있습니다. 주어진 5 가지 합법적 인 용도는 다음과 같습니다. 사이버 보안 목적; 사이버 보안 범죄의 수사 및 기소 사망 또는 심각한 신체적 상해로부터 개인 보호; 아동 포르노, 성적 착취 및 기타 관련 범죄로부터 미성년자를 보호합니다. 국가 안보 보호. 정부는 사이버 보안 범죄에 대한 수사 및 기소 이외의 목적으로 정보를 적극적으로 검색하는 것이 제한되며, 앞 문장에 기재된 목적 이외의 목적으로 정보를 보유 또는 사용하는 것이 제한됩니다. CISPA는 또한 정부가 도서관 을 사용하지 못하도록 특별히 제한합니다. 유통 기록, 도서관 후원자 목록, 도서 판매 기록, 도서 고객 목록, 총기 판매 기록, 세금 환급 기록, 교육 기록 및 의료 기록.
이 법안에는 사이버 위협과 관련이 없다고 판단한 정보가 연방 정부와 공유되는 경우 정부는 정보를 제공 한 주체에이를 알려야한다고 명시하고 있습니다.
CISPA는 또한 특정 정부 기관이 개발하고 공개해야하는 절차 및 보고서를 지시합니다. 민간 기관의 모든 정보 공유를 자발적으로 만들고 참여하지 않기로 선택한 것에 대한 불이익없이 법안이 어떤 것도 제공하려는 시도가 아님을 밝힙니다. 정보 커뮤니티의 요소는 개인 또는 정부 기관의 사이버 보안 노력을 지시 할 수있는 권리입니다.
법안에 정의 된 사이버 보안 목적 은 다음과 같습니다. 취약성으로부터 보호하기위한 노력; 무결성, 기밀성 또는 가용성에 대한 위협; 액세스를 거부, 저하, 방해 또는 파괴하려는 노력 그리고 시스템과 네트워크에 대한 무단 액세스뿐만 아니라 저장, 처리 또는 이동하는 모든 정보를 얻으려는 노력. 여기에는 정보 유출 (또는 제거)에 대한 무단 액세스가 명시 적으로 포함되지만 소비자 서비스 약관 또는 라이선스 계약 위반만을 포함하는 무단 액세스는 제외됩니다. 사이버 보안 시스템 과 사이버 위협 인텔리전스 의 정의 에는 유사한 언어가 포함되어 있습니다.
CISPA가 그토록 논란이되는 이유는 무엇입니까?
CISPA는 프라이버시 , 투명성, 사 법적 감독 부족, 사이버 보안, 국가 안보 및 기타 모호하게 정의 된 용어로 위장하여 시민의 인터넷 활동을 감시하는 데 사용될 가능성 등 다양한 이유로 많은 결함을 가지고 있습니다.
한 가지 문제는 공유 할 수있는 데이터 유형을 엄격하게 정의하는 대신 "사이버 위협 인텔리전스"와 같은 포괄적 인 용어를 사용한다는 것입니다. 따라서 잠재적으로 기업이 개인 식별 정보 (PII), 개인 정보를 포함한 모든 종류의 정보를 획득하고 공유 할 수 있습니다. 통신 등. CISPA는 민간 단체가 정부가 공유하는 데이터를 익명화, 최소화 또는 제한 할 것을 주장 할 수 있도록 허용하지만 회사가 그러한 제한을 할 필요는 없습니다.
연방 정부의 공유 정보 사용에 관한 하위 섹션에는 개인 정보 보호 및 시민의 자유를 다루는 단락이 있지만, "연방 정부는 사이버 보안 위협으로부터 연방 시스템 및 중요 정보 인프라를 보호해야 할 필요성과 일치 할 수 있습니다. 이러한 위협을 완화하기 위해이 하위 섹션에 따라 연방 정부와 사이버 위협 정보를 공유하는 것이 개인 정보 보호 및 시민의 자유에 미치는 영향을 제한하기위한 합리적인 노력을 기울여야합니다. " "할 수있다"라는 단어의 사용은 자발적인 것처럼 들리며 이러한 노력이 수반 할 수있는 것에 대한 더 이상의 정의는 없습니다. 정보의 정부 사용에 대한 연례 보고서 작성에 관한 섹션에서 법안은 "영향을 결정하는 메트릭,개인 정보 보호 및 시민의 자유에 관한 것 "이지만이 정보가 어떻게 사용되는지에 대한 언급은 없습니다.
이 법안은 정보를 공유하는 회사가 "선의"로 행동 한 경우 부적절하게 한 것으로 판명 되더라도 법적 면제를 제공합니다. 또한 "사이버 위협 정보를 기반으로 내린 결정"에 대한 면제를 허용하지만 "내린 결정"을 정의하지는 않습니다. 기업 입장에서는 사이버 위협 정보를 자유롭게 공유 할 수 있고 비용이 많이 드는 소송 에 대한 걱정없이 해당 정보에 대해 조치를 취할 수 있지만, 피해를 입었을 때 개인이나 단체가 소송을 제기 할 수있는 권리는 완전히 축소 될 수 있습니다. 누군가가 선의로 행동하지 않았 음을 증명하기 위해. 이러한 면책은 기업이 정보를 획득하거나 시스템을 방해하기 위해 의심되는 침입자에 대한 보복 해킹과 같은 일을하도록 허용 할 수도 있다는 주장이 있습니다.
CISPA 문구의 또 다른 논란의 여지가있는 측면은 여러 개인 정보 보호법을 대체 할 가능성이 있다는 것입니다.
더 문제가되는 언어
CISPA는 도청 법, 케이블 통신법, 비디오 개인 정보 보호법, 저장 통신법 및 전자 통신 개인 정보 보호법을 포함하여 기존의 많은 개인 정보 보호법을 무시하는 "다른 법률 조항에도 불구하고"라는 용어를 통해 사법 감독을 회피 할 가능성이 있습니다. 개인 정보 공유에 관한 규칙과 감독을 제공하는 행위. CISPA의 경우 정부가 개인 정보를 획득하기 위해 영장이 필요하지 않습니다.
개인이 고의로 자신의 정보를 오용하면 정부를 고소 할 수 있지만 그런 일이 일어났다는 사실을 알아내는 것은 매우 어려울 수 있습니다. 암호화되지 않은 정보가 정부에 전송 되더라도 정부는 전송 주체에게만 알릴 필요가 있으며, 누구도 데이터를 공유 한 사람에게 알릴 필요가 없습니다. 그리고 공유 된 정보는 정보 자유 법 및 기타 유사한 공개법에 따라 공개되지 않습니다. 공유를 지적하는 명백한 피해가 있어야하며, 공소 시효로 인해 연방 정부가 데이터를 오용 한 후 2 년 이내에 분명해야합니다.
CISPA는 또한 정보를 수신하는 기관이 다른 기관과 공유 할 수있는 DHS의 국가 사이버 보안 및 통신 통합 센터에 정보를 제공한다는 규정을 제외하고는 정보를 전달할 수있는 정부 기관을 정의하거나 제한하지 않는다는 이유로 공격을 받고 있습니다. 정보는 정보 기관을 포함하여 연방 정부의 모든 기관에 합법적으로 제공 될 수 있습니다. 정부가 정보를 사용할 수있는 방법은 법안에서 다소 모호하게 정의 된 "사이버 보안 목적"과 "미국의 국가 안보 보호"를 포함하여 광범위하게 정의됩니다. 국가 안보 법.
법안에는 기술과 관련된 용어가 눈에 띄게 부족합니다. "컴퓨터"라는 단어는 가능한 위반 목록에 컴퓨터 범죄를 포함하기 위해 "사이버 보안 범죄"의 정의 내에서만 사용됩니다. 그렇지 않으면 HR 624는 보호되는 사물을 "시스템 및 네트워크"라고 부르며 다소 모호합니다. "온라인", " 인터넷 ", "웹", "디지털", "정보 기술"및 "기술" 이라는 단어와 구문 은 사용되지 않습니다.
The original version of the bill included theft of intellectual property as one of the cybersecurity purposes. This has been removed from the latest version of CISPA, and language was inserted to specify that cyberthreat information does not include efforts to gain access involving violations of consumer terms of service or licensing agreements. However, some groups still fear that it can be used to pursue things like copyright infringement.
CISPA doesn't provide the legal means for the government to directly monitor people's online activities and digital data, but it does allow companies to voluntarily give undefined types and amounts of information that they deem cyberthreat information to the federal government, and the government can keep and use this data for reasons of cybersecurity, national security and investigation of a few other crimes. This and the fact that it can be given to any agency are causing consternation since this could allow intelligence agencies a sort of sideways access to personal information.
No one is arguing that sharing information on emerging threats isn't important in the fight to secure computer systems and networks from the ever-growing threat of attack, but arguments are being made to place limitations on the types of information shared and with what entities it can be shared. The supporters of CISPA counter that the bill is not intended for surveillance, and that the immunities are necessary to encourage companies to share information without fear of lawsuit. The opponents argue that the risks to privacy and civil liberties are too great in the bill as currently written.
Efforts Made in Support of and Opposition to CISPA
A number of private companies and trade associations have expressed support for CISPA. Many of them sent letters of support to the U.S. House of Representatives for either H.R. 3423, H.R. 624 or both, including AT&T, Verizon, US Telecom, Comcast, Time Warner Cable, the National Cable & Telecommunications Association, Edison Electric Institute, Financial Joint Trades, Financial Services Roundtable, Boeing, Lockheed Martin, IBM, Intel, Oracle, Symantec, Microsoft, Facebook, TechAmerica, the Internet Security Alliance, Juniper Networks, the National Cable & Telecommunications Association and the Chamber of Commerce. Facebook and Microsoft both backed away a little after protests and stated or implied that they would support changes to the final legislation that addressed privacy concerns.
The letters of support include praise for breaking down existing barriers to the timely sharing of cyberthreat intelligence with private entities, not placing regulatory burdens on private companies and protecting them from frivolous lawsuits and legal uncertainty with regards to sharing information, among other things.
But some companies and organizations concerned with privacy and civil liberties have vigorously spoken out against CISPA, including the Electronic Frontier Foundation, the American Civil Liberties Union, Access Now, the American Library Association, the Society of American Archivists, the Cato Institute, the Center for Democracy and Technology, the Entertainment Consumers Association, the Sunlight Foundation, Reporters Without Borders, the Society of Professional Journalists, the Rutherford Institute, the Republican Liberty Caucus, Mozilla and Tech Freedom, among others. Notable individuals who have expressed concerns include former Representative and Presidential candidate Ron Paul, who called the bill "Big Brother writ large," and Tim Berners-Lee, the inventor of the World Wide Web . And of course, there was the President's veto threat.
The EFF and some other opposing groups organized a "Week of Action" in mid-April 2012 to protest CISPA, during which they waged a grassroots campaign asking people to sign petitions, write, call and tweet Congressmen and otherwise express opposition to the bill. Nearly a million people did so the first go round, but despite this activity, CISPA did pass in the House -- albeit with a few changes.
As of early spring of 2013, similar pushes are being made to protest the bill anew. Within a day or so of CISPA being reintroduced in the House, hundreds of thousands of online signatures were reportedly collected and delivered to the U.S. House Intelligence Committee. We likely haven't heard the end of vigorous arguments on both sides of the issue.
Alternatives to CISPA
Some notable alternatives to CISPA have been put forth, including two bills introduced in the Senate and an Executive Order issued by President Obama.
One of the Senate bills is the Cybersecurity Act (S. 3414) introduced by Senators Joe Lieberman (I-CT), Susan Collins (R-ME) and three other senators. It is a much longer (in excess of 200 pages) and more detailed bill than CISPA that opens up ways for private entities and the federal government to share information related to cyberthreats, puts oversight of sharing in the purview of the DHS and also allows for setting up cybersecurity guidelines to be followed on a voluntary basis, but with incentives for compliance by private entities. It creates the National Cybersecurity Council (NCC) to be made up of representatives from multiple agencies (both civilian and military) to coordinate with the private sector to assess computer system vulnerabilities and come up with the guidelines.
The Cybersecurity Act was amended to include more protections to privacy and civil liberties, including a guarantee that only civilian (non-military) organizations have access to shared cyberthreat information and an exemption of first-amendment protected activities from being identified as categories of critical cyber infrastructure . It also doesn't include national security as one of the possible uses of shared cybersecurity information, but it does let the federal government use the information for the other three reasons allowed under CISPA.
A rival bill introduced by Senator John McCain (R-AZ) and several co-sponsoring senators is called the Strengthening and Enhancing Cybersecurity by Using Research, Education, Information, and Technology Act (SECURE IT Act, S. 3342). It is also a heftier bill than CISPA, coming in at more than 100 pages. It would facilitate information sharing between multiple government agencies and private entities on cyberthreats, strengthen criminal penalties related to cybercrimes, foster networking and information technology research and development and sharing of research, and would allow the Department of Commerce, Department of Homeland Security, and the National Security Agency (NSA) to coordinate on policies regarding cybersecurity efforts. It has faced many of the same criticisms as CISPA, including that it has an overbroad definition of cyberthreat information, places few limits on the types of information that can be shared and how it can be used (including cybersecurity purposes, national security purposes and a whole host of criminal prevention, investigation and prosecution purposes), similar "notwithstanding any other provision of law" language and oversight issues, such as the removal of lawsuit liability from companies and the shared information being exempt from the Freedom of Information Act. It is also criticized for putting a non-civilian entity (the NSA) in charge of information sharing.
The Current State of Affairs
As of early 2013, neither Senate bill passed, but in the wake of CISPA's resurrection in the House, President Obama issued an Executive Order (EO) that covers some of the ground of the proposed cybersecurity bills, including timely sharing of information on cyberthreats from the federal government to critical infrastructure entities and companies that provide cybersecurity services. It does not enable any new sharing of information in the other direction (from private companies to public entities). It takes an existing Defense Industrial Base (DIB) information sharing program called the Enhanced Cybersecurity Services program, which was put in place to allow the Department of Defense (DoD) and the DHS to share non-classified cybersecurity information with defense contractors and the like, and expands it by allowing it to cover the other government agencies and critical infrastructure sectors. Like CISPA, the EO addresses creating an avenue for critical infrastructure personnel to gain security clearance for the sharing of classified information. It charges the National Institute of Standards and Technology (NIST) and others to work collaboratively with industry experts to create a cybersecurity practices framework to help reduce cyberthreat risks to infrastructure, and calls on the DHS to develop incentives to promote adoption of the framework.
The EO also calls for the Chief Privacy Officer and Officer for Civil Rights and Civil Liberties of the DHS to assess privacy and civil liberties risks and make recommendations on how to minimize and mitigate those risks. They are to use the Fair Information Practice Principles (FIPP) and other related policies to evaluate cybersecurity activities to this end, and their assessments are to be made available to the public.
Since CISPA is under consideration once more, no rival cybersecurity bills have passed yet and cyberthreats appear to be on the rise, the debate on how best to handle cybersecurity, especially sharing of information from private industry to government, is far from over. But perhaps all the rousing debates and calls to action will help whatever laws are ultimately passed to best straddle the line between too much and too little sharing while providing real protections.
Lots More Information
Author's Note: How CISPA Works
Being an IT worker, a writer and a heavy Internet user, I'm concerned about the security of our computers and networks. Lord knows I don't want my data stolen, or a cyberattack to take down the Internet or cut the power. How would I watch an entire season of "Downton Abbey" on Netflix while simultaneously writing an essay, checking e-mail and surfing the net for Grumpy Cat pictures?
But I'm equally concerned about privacy. The less of my data flowing out to people I never intended to look at it, the better. There is no telling how the NSA would interpret one of my short stories.
Reading through these bills and thinking about what could possibly go wrong due to wording issues was pretty fascinating. I'm sure that the drafters of all such legislation are by and large well-meaning people trying to proactively snuff out security threats. But "well-meaning" means about as much as "good faith" in legal terms. Not everyone on the planet has good intentions, as we are reminded daily by the news, and anything that can be used for ill or even just misguided purposes probably will be at some point. So I hope that whatever bill passes is extremely well-thought-out and vetted by industry, civil liberty and legal experts alike. Keep the Internet safe for Grumpy Cat.
Related Articles
Sources
- Albanesius, Chloe. "Obama's Cybersecurity Executive Order vs. CISPA: Which Approach Is Best?" PC Magazine. February 13, 2013. (March 11, 2013) http://www.pcmag.com/article2/0,2817,2415380,00.asp
- Biddle, Sam. "What is CISPA?" Gizmodo. April 26, 2012. (March 3, 2013)http://gizmodo.com/5905360/what-is-cispa
- Bodeen, Christopher. "Yang Jiechi, China's Foreign Minister, Dismisses Hacking Claims by U.S." Huffington Post. March 09, 2013. (March 09, 2013) http://www.huffingtonpost.com/2013/03/09/yang-jiechi-chinas-foreig_n_2844984.html
- Bradbury, Danny. "With cyber attacks on the rise, is your company's data secure?" Guardian. February 11, 2013. (March 9, 2013)http://www.guardian.co.uk/media-network/media-network-blog/2013/feb/11/cyber-attack-security-data
- Bucci, Steven P. "Securing U.S. Computer Networks with SECURE IT." The Heritage Foundation. July 16, 2012. (March 10, 2013) http://www.heritage.org/research/reports/2012/07/securing-us-computer-networks-with-secure-it
- Bumiller, Elisabeth and Thom Shanker. "Panetta Warns of Dire Threat of Cyberattack on U.S." New York Times. October 11, 2012. (March 6, 2013)http://www.nytimes.com/2012/10/12/world/panetta-warns-of-dire-threat-of-cyberattack.html
- CNBC. "Code Wars: America's Cyber Threat." (March 9, 2013)http://www.cnbc.com/id/42210831/Code_Wars_America039s_Cyber_Threat
- Couts, Andrew. "Not CISPA: Revised Senate Cybersecurity Bill Praised by Civil Liberty Advocates." Digital Trends. July 20, 2012. (March 9, 2013)http://www.digitaltrends.com/web/not-cispa-revised-senate-cybersecurity-bill-praised-by-civil-liberty-advocates/
- FBI. "Computer Intrusions." (March 9, 2013)http://www.fbi.gov/about-us/investigate/cyber/computer-intrusions
- FBI. "Spear Phishers - Angling to Steal Your Financial Info." April 1, 2009. (March 9, 2013)http://www.fbi.gov/news/stories/2009/april/spearphishing_040109
- Fitzpatrick, Alex. "CISPA Cybersecurity Bill Passes House, With Some Amendments." Mashable. April 26, 2012. (March 8, 2013)http://mashable.com/2012/04/26/cispa-passes-house/
- Fitzpatrick, Alex. "Internet Activists Deliver 300,000 Anti-CISPA Signatures to Congress." Mashable. February 15, 2013. (March 11, 2013) http://mashable.com/2013/02/15/cispa-petitions/
- Glass, Nick. "Cloud threats and firewalls: Internet guru demystifies cyber security." CNN. March 5, 2013. (March 9, 2013)http://www.cnn.com/2013/03/05/tech/threat-cloud-cyber-security/index.html
- Greenberg, Andy. "President Obama's Cybersecurity Executive Order Scores Much Better Than CISPA on Privacy." Forbes. February 12, 2013. (March 11, 2013) http://www.forbes.com/sites/andygreenberg/2013/02/12/president-obamas-cybersecurity-executive-order-scores-much-better-than-cispa-on-privacy/
- Gross, Doug. "Report: Eastern European gang hacked Apple, Facebook, Twitter." CNN. February 20, 2013. (March 9, 2013)http://www.cnn.com/2013/02/20/tech/web/hacked-apple-facebook-twitter
- Harris, Leslie. "CISPA: Progress, But Flaws Remain." Center for Democracy and Technology. April 24, 2012. (March 11, 2013) https://www.cdt.org/blogs/leslie-harris/2404cispa-progress-flaws-remain
- Hartman, Rachel Rose. "CISPA: The controversy surrounding it and how it might affect you." ABC News. April 27, 2012. (March 11, 2013) http://abcnews.go.com/Politics/OTUS/cispa-controversy-surrounding-affect/story?id=16229426
- Jackson, William. "McCain's retooled Secure IT act still a privacy threat, critics say." GCN. July 2, 2012. (March 10, 2013) http://gcn.com/Articles/2012/07/02/Secure-IT-Act-amended-critics-say-still-threat-to-privacy.aspx?Page=1
- Jaycox, Mark M. and Kurt Opsahl. "CISPA is Back: FAQ on What it is and Why it's Still Dangerous." Electronic Frontier Foundation. February 25, 2013. (March 3, 2013)https://www.eff.org/cybersecurity-bill-faq
- Jaycox, Mark M. "CISPA, the Privacy-Invading Cybersecurity Spying Bill, Is Back in Congress." February 13, 2013. (March 6, 2013)https://www.eff.org/deeplinks/2013/02/cispa-privacy-invading-cybersecurity-spying-bill-back-congress
- Kelly, Heather. "Cyber-criminals are targeting phones and bank info." CNN. February 21, 2013. (March 9, 2013)http://www.cnn.com/2013/02/21/tech/mobile/mcafee-threats-report
- Koebler, Jason. "Civil Liberties Organizations Launch Protests Against CISPA." US News & World Report. April 16, 2012. (March 11, 2013) http://www.usnews.com/news/articles/2012/04/16/civil-liberties-organizations-launch-protests-against-cispa
- Library of Congress - Thomas. "Bill Text Versions 112th Congress (2011-2012) H.R. 3523." (March 8, 2013)http://thomas.loc.gov/cgi-bin/query/z?c112:H.R.3523:
- Magid, Larry. "Privacy Advocates Prefer Obama's Cybersecurity Plan Over CISPA." Forbes. February 21, 2013. (March 8, 2013)http://www.forbes.com/sites/larrymagid/2013/02/21/privacy-advocates-prefer-obamas-cybersecurity-plan-over-cispa/
- Magid, Larry. "What is CISPA and Why Would the President Veto It?" Forbes. April 25, 2012. (March 9, 2013)http://www.forbes.com/sites/larrymagid/2012/04/25/what-is-cispa-and-why-would-the-president-veto-it/
- McCullagh, Declan. "How CISPA would affect you (faq)." CNET. April 27, 2012. (March 3, 2013)http://news.cnet.com/8301-31921_3-57422693-281/how-cispa-would-affect-you-faq/
- McCullagh, Declan. "Microsoft backs away from CISPA support, citing privacy." CNET. April 27, 2012. (March 11, 2013) http://news.cnet.com/8301-33062_3-57423580/microsoft-backs-away-from-cispa-support-citing-privacy/
- O'Grady, Jason D. "Apple, Facebook employees hacked via website malware, Java vulnerability." ZDNet. February 21, 2013. (March 09, 2013)http://www.zdnet.com/apple-facebook-employees-hacked-via-website-malware-java-vulnerability-7000011601/
- Opsahl, Kurt. "The CISPA Government Access Loophole." EFF. March 1, 2013. (March 8, 2013)https://www.eff.org/deeplinks/2013/02/cispa-government-access-loophole
- Perlroth, Nicole. "Connecting the Dots After Cyberattack on Saudi Aramco." New York Times. August 27, 2012. (March 6, 2013)http://bits.blogs.nytimes.com/2012/08/27/connecting-the-dots-after-cyberattack-on-saudi-aramco/
- Perlroth, Nicole. "Hackers in China Attacked The Times for Last 4 Months." New York Times. January 30, 2013. (March 6, 2013)http://www.nytimes.com/2013/01/31/technology/chinese-hackers-infiltrate-new-york-times-computers.html?_r=0
- Peterson, Andrea. "Cybersecurity Bill Supporters Regroup As Executive Order Looms." Think Progress. February 6, 2013. (March 6, 2013)http://thinkprogress.org/security/2013/02/06/1548761/cispa-executive-order/
- Reitman, Rainey. "Even with Rogers' Amendments, CISPA is Still a Surveillance Bill." EFF. April 26, 2012. (March 8, 2013)https://www.eff.org/deeplinks/2012/04/even-rogers-amendments-cispa-still-surveillance-bill
- Reitman, Rainey. "Industry Experts to Congress: We Can Remove Personally Identifiable Information Before Reporting Cybersecurity Threats." EFF. February 16, 2013. (March 9, 2013)https://www.eff.org/deeplinks/2013/02/industry-experts-congress-we-can-remove-personally-identifiable-information
- Reitman, Rainey. "Victory Over Cyber Spying." EFF. August 2, 2012. (March 11, 2013) https://www.eff.org/deeplinks/2012/08/victory-over-cyber-spying
- Richardson, Michelle. "CISPA Claws Back to Life." ACLU. February 10, 2013. (March 9, 2013)http://www.aclu.org/blog/technology-and-liberty-national-security/cispa-claws-back-life
- Richardson, Michelle. "New Cybersecurity Amendments Unveiled to Address Privacy Concerns." ACLU. July 19, 2012. (March 9, 2013)http://www.aclu.org/blog/national-security-technology-and-liberty/new-cybersecurity-amendments-unveiled-address-privacy
- Richardson, Michelle. "President Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure." ACLU. February 13, 2013. (March 6, 2013)http://www.aclu.org/blog/national-security-technology-and-liberty/president-obama-shows-no-cispa-invasion-privacy-needed
- Sasso, Brendan. "Longtime friends Lieberman, McCain divided over cybersecurity legislation." The Hill. March 14, 2012. (March 10, 2013) http://thehill.com/blogs/hillicon-valley/technology/215907-senators-mccain-lieberman-disagree-its-a-real-doozy
- Staff writer. "How a 'denial of service' attack works." CNET. February 9, 2000. (March 9, 2013)http://news.cnet.com/2100-1017-236728.html
- Steele, Patrick. "Voices of Opposition Against CISPA." EFF. April 19, 2012. (March 9, 2013)https://www.eff.org/deeplinks/2012/04/voices-against-cispa
- Symantec. "Advanced Persistent Threat (APT): The Uninvited Guest." (March 9, 2013)http://www.symantec.com/theme.jsp?themeid=apt-infographic-1
- Symantec. "Denial of service (DoS) attack." (March 9, 2013)http://www.symantec.com/security_response/glossary/define.jsp?letter=d&word=denial-of-service-dos-attack
- Symantec. "Man-in-the-middle attack." (March 9, 2013)http://www.symantec.com/security_response/glossary/define.jsp?letter=m&word=man-in-the-middle-attack
- Thrasher, Brown. "BREAKING: Senate CISPA Failes Cloture Vote." Daily Kos. August 2, 2012. (March 9, 2013)http://www.dailykos.com/story/2012/08/02/1116107/-BREAKING-Senate-CISPA-Fails-Cloture-Vote
- U.S. Government Printing Office. "S. 3342." June 27, 2012. (March 10, 2013) http://www.gpo.gov/fdsys/pkg/BILLS-112s3342pcs/pdf/BILLS-112s3342pcs.pdf
- U.S. Government Printing Office. "S. 3414." July 19, 2012. (March 10, 2013) http://www.gpo.gov/fdsys/pkg/BILLS-112s3414pcs/pdf/BILLS-112s3414pcs.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Backgrounder on the Rogers-Ruppersberger Cybersecurity Bill." (March 5, 2013)http://intelligence.house.gov/backgrounder-rogers-ruppersberger-cybersecurity-bill
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 3523 - Letters of Support." (March 11, 2013) http://intelligence.house.gov/hr-3523-letters-support
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 3523 - The Bill and Amendments." (March 8, 2013)http://intelligence.house.gov/hr-3523-bill-and-amendments
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 624." (March 6, 2013)http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/HR624.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "H.R. 624 - Letters of Support." (March 3, 2013)https://intelligence.house.gov/hr-624-letters-support
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Myth v. Fact: Cyber Intelligence Sharing and Protection Act of 2013 (CISPA)." (March 6, 2013)http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/cispamythvactFeb122013v2.pdf
- U.S. House of Representatives Permanent Select Committee on Intelligence. "Rogers & Ruppersberger Reintroduce Cybersecurity Bill to Protect the American Economy." February 13, 2013. (March 6, 2013)http://intelligence.house.gov/press-release/rogers-ruppersberger-reintroduce-cybersecurity-bill-protect-american-economy
- Vamosi, Robert. "Internet-scale 'man in the middle' attack disclosed." CNET. October 17, 2008. (March 9, 2013)http://news.cnet.com/8301-1009_3-10068327-83.html
- Vijayan, Jaikumar. "Privacy groups protest CISPA bill." Computer World. February 14, 2013. (March 11, 2013) http://www.computerworld.com/s/article/9236800/Privacy_groups_protest_CISPA_bill_
- Vijayan, Jaikumar. "Return of CISPA: Cybersecurity boon or privacy threat?" Computer World. March 1, 2013. (March 11, 2013) http://www.computerworld.com/s/article/9237262/Return_of_CISPA_Cybersecurity_boon_or_privacy_threat_
- White House. "Executive Order -- Improving Critical Infrastructure Cybersecurity." February 12, 2013. (March 6, 2013)http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity
- White House. "Executive Order on Improving Critical Infrastructure Cybersecurity." February 12, 2013. (March 11, 2013) http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity-0
- Whittaker, Zack. "'Privacy killer' CISPA is coming back, whether you like it or not." ZDNet. February 8, 2013. (March 11, 2013) http://www.zdnet.com/privacy-killer-cispa-is-coming-back-whether-you-like-it-or-not-7000011056/