Editor’s Note:  For more about cost effective regulatin of private sector critical infrastructure, see here.

From: Government Security News

By: Mark Rockwell

While thanking the private security industry for their important contributions to the overall security of the U.S., Department of Homeland Security secretary Janet Napolitano called for more work to protect critical infrastructure under increasing electronic assault.

In a luncheon speech the first day of the ASIS 2012 conference in Philadelphia, Napolitano backed a reported White House draft executive order that calls for private infrastructure companies to develop voluntary “private sector baseline” protections for “core infrastructure.”

A draft executive order is currently being circulated among relevant federal agencies for feedback, according to reports.

The draft order, according to a report in The Hill newspaper the week of Sept. 3, would establish a voluntary program for critical infrastructure companies, like power and chemical companies, to establish cyber security best-practices and craft cyber standards along with government. Similar proposals had been included in cyber security bills that died in Congress earlier this summer in the face of mostly Republican opposition to what they call excessive regulation.

The White House order shows President Obama and his administration are to determined to move ahead in spite of Congressional deadlock. In her remarks to ASIS, Napolitano echoed that determination. She urged attendees to continue in “fostering an environment of shared responsibility to make cyber space safe.”

She noted mounting attacks on critical infrastructure facilities, including water and power plants. The ICS CERT (Industrial Control System Computer Emergency Readiness Team) has sent damage assessment teams to infrastructure company sites in response to cyber attacks 78 times in the last year, she said. The danger continues to mount, she said, and private industry needs clearer guidelines for sharing information with federal authorities.

“We need to make it easier to report and provide assistance,” she said.

“We have an amalgam of different statutes that need to be reworked. The plain fact is we need to address it now, not in the years to come,” she said.

“Cyber is the active, the most dynamic, and the most threatening risk we have,” she said.