Cybersecurity Framework: Making It Work

From: BankInfoSecurity

Coordinator Discusses Role of Insurers in Setting Incentives

By Eric Chabrow

he Obama administration is floating the idea that the nation’s critical infrastructure operators would more likely adopt voluntary IT security best practices if the government engages the insurance industry to help develop the standards and procedures in its cybersecurity framework.

“The goal of this collaboration would be to build underwriting practices that promote the adoption of cyber-risk reducing measures and risk-based pricing and foster a competitive cyber-insurance market,” says Michael Daniel, the White House cybersecurity coordinator.

he departments of Homeland Security, Commerce and Treasury have identified eight incentives the federal government could use to encourage the nation’s critical infrastructure owners to adopt voluntarily the cybersecurity framework being developed under the auspices of the National Institute of Standards and Technology [see NIST Unveils Draft of Cybersecurity Framework].

Besides cybersecurity insurance, the seven other incentives are grants, process preferences, liability limitation, streamlined regulations, public recognition, rate recovery for price-regulated industries and cybersecurity research.

In February, President Obama issued an executive order that focused on sharing cyberthreat information, promoting online privacy protection and establishing IT security best practices, known as the cybersecurity framework, that the owners of the nation’s critical infrastructure could adopt voluntarily [see Obama Issues Cybersecurity Executive Order].

NIST has been holding a series of public sessions where government and industry are developing the cybersecurity framework. NIST will hold its fourth session on the framework from Sept. 11 to 13 at the University of Texas at Dallas, where it will present a draft of the cybersecurity framework. The final version is due in February.

Promoting Risk-Reducing Measures

The Commerce Department’s analysis of the cybersecurity insurance incentive says insurance carriers would bring extensive knowledge of the effectiveness of specific cybersecurity practices and could help evaluate specific proposed elements from this perspective. “This collaboration between insurance companies, NIST and other stakeholders could serve as a basis for creating underwriting practices that promote the adoption of cyber risk-reducing measures and risk-based pricing,” the Commerce analysis says. “This collaboration could also foster a competitive cyber-insurance market.”

Writing in the White House blog, Daniel says NIST, part of the Commerce Department, is taking steps to engage the insurance industry in further discussions on the framework.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *