From: The Global Legal Post
The US Government declared war against cyber-attacks, issuing an Executive Order to address the issue. A year later, Dawn Livingston assesses progress.
In recent years the United States has witnessed a significant rise in the number of data breaches and cyber-attacks on government agencies, private citizens and critical infrastructure industries. Incidents such as “Stuxnet” and “Red October”, the network breach of The Wall Street Journal, and news of website breaches of American banks seem to occur with greater frequency. These attacks have led to heightened consideration by U.S. Government officials as well as members of Congress regarding the federal government’s role in addressing cybersecurity risks directed at the country’s critical infrastructure.
In February 2013, President Obama issued a preliminary response to these growing concerns in his State of the Union address by announcing the White House Executive Order for “Improving Critical Infrastructure Cybersecurity” (the “EO”). President Obama further urged Congress to follow his lead and pass comprehensive cybersecurity legislation to “give our government a greater capacity to secure our networks and deter attacks.” The EO tasked federal agencies to take immediate action to address cyber-threats on the country’s critical infrastructure.
With the EO’s anniversary approaching, it is a good time to evaluate the progress made toward meeting the President’s goals and to set expectations for 2014.
The Cybersecurity Executive Order
The intended purpose of the EO was to improve the security and resiliency of critical infrastructure industries (“CII”) by mobilizing federal agencies to increase information sharing and collaboration between the government and private owners and operators of CII. CII within this context is broadly defined as:
“systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”
To achieve the goals increase information sharing and collaboration, these components required participation from a broad range of government agencies, including the Department of Homeland Security (“DHS”), Department of Commerce (“Commerce”), the National Institute of Science and Technology (“NIST”), Department of Treasury (“Treasury”) as well as other national security and sector-specific agencies.
Information sharing
Among the key EO components, DHS, the U.S. Attorney General, and the Director of National Intelligence together were tasked with disseminating unclassified reports on timely cyber-threat information to U.S. companies. Further, DHS is responsible for expanding the agency’s voluntary Enhanced Cybersecurity Service program, which will facilitate nearly real time sharing of cyber-threat information to assist participating CII. Finally, DHS is responsible for identifying CII that, in the event of a successful cybersecurity incident, would severely impact national security, economic security or public health and safety, and create a process to confidentially notify the owners and operators of the companies.
The National Protection and Programs Directorate (NPPD) within DHS is the leader in protecting the nation’s physical and cyber networks. In June 2013, NPPD reported to Congress that the agency has implemented “sharelines” to increase the volume, timeliness and quality of cyber-threat information shared with private sector companies. It was also reported DHS provided the list of CII to the White House as directed. This process has been confidential and little has been released publicly.
NIST Cybersecurity Framework
Perhaps the most important component of the EO, or at least the most widely reported component, is the National Institute of Standards and Technology’s (“NIST”) development of a voluntary Cybersecurity Framework. The Framework is a set of standards and procedures, based on existing industry guidelines and practices, to reduce cybersecurity risks to CII.
Leave a Reply