From: Hillicon Valley/The Hill’s Technology Blog
By Jennifer Martinez
Commerce Department officials on Monday stressed that Congress needs to pass cybersecurity legislation that incentivizes companies to boost the security of their computer systems and networks, adding that the executive branch cannot grant that power.
“Tax incentives, liability protections— those are things that the president can’t wave a magic wand and make happen,” said Ari Schwartz, senior policy advisor to the Secretary of Commerce, at a briefing about the executive order hosted by law firm Venable. “Congress needs to pass those things.”
The executive order issued by President Obama last month directs the Commerce Department’s National Institute of Standards and Technology (NIST) to take up the task of crafting a framework of cybersecurity best practices for critical infrastructure firms to follow. While it spends the next year working with industry to draft that framework, NIST has four months to compose a list of incentives that the executive branch can offer companies in exchange for them taking steps to bolster the security of their networks and systems from hacker attacks.
However, officials will be limited with the type of incentives it can offer industry as an executive order cannot grant new powers or authorities like congressional legislation can. These incentives are intended to entice critical infrastructure firms to join a voluntary program led by the Department of Homeland Security, which was established in the president’s cyber order. The companies that participate in this program will follow the cybersecurity best practices and standards crafted by NIST.
At a Senate hearing last week, Homeland Security Secretary Janet Napolitano said the administration is considering offering a “seal of approval” to companies who join the Homeland Security-led program and a “procurement preferences acquisition” process as possible incentives.
The officials also acknowledged that it will be “a challenge” to put together a cybersecurity framework over the next eight months that can apply across various sectors of U.S. critical infrastructure—such as water systems, electric companies and banking systems—and businesses that vary in size. They also repeated the administration’s call for industry to help with the implementation of the order.
“The NIST process will not work if we don’t have help from industry,” said Adam Sedgewick, senior Internet policy advisor at NIST. “It will not be a successful framework if we don’t get that kind of participation.”
Leave a Reply