Cybersecurity bill, OK'd by House, draws cautious praise
It's a step in the right directon, analysts say
February 4, 2010 04:23 PM ETComputerworld - Security analysts today gave a cautious thumbs-up to the passage of the Cybersecurity Enhancement Act of 2009 (HR 4061) by the U.S. House of Representatives.
The bill, sponsored by Rep. Daniel Lipinski (D-Ill.), aims to bolster federal cybersecurity research and development and stimulate the growth of a cybersecurity workforce in the U.S. Approved by the House Science and Technology Committee in November, it won passage by a whopping 422-6 vote in the House.
The bill is the first major cybersecurity legislation to make it through the House this year. It now has to pass muster in Senate before it can become law, and no Senate version of the bill that has even been drafted yet.
If the bill passes the Senate and becomes law, the National Science Foundation (NSF) would get $396 million to use for research-and-development programs focused on cybersecurity. An additional $210 million or so would become available over the next four years for use by the NSF for cybersecurity scholarships and for constructing cybersecurity research facilities and offering training programs in colleges and universities.
The bill would require the National Institute of Standards and Technology (NIST) to work with other standards bodies to develop internationally accepted cybersecurity standards and for leading cybersecurity public awareness campaigns. In addition, federal agencies that participate in the Networking and Information Technology Research and Development program will have to do a detailed assessments of their cybersecurity risks and develop plans for addressing those risks.
"This bill will help improve the security of cyberspace by ensuring federal investments in cybersecurity are better focused, more effective," said Mark Bregman, CTO at Symantec Corp. in e-mailed comments. "HR 4061 represents a major step forward towards defining a clear research agenda that is necessary to stimulate investment in both the private and academic worlds."
Despite the lack of a Senate bill, there's a good chance the Senate will simply roll the House measure into an appropriations bill for NIST and NSF, according to a Symantec government relations spokesman. "The policy stuff already exists in language spread over about three different bills that are still in committee. Now that the House has passed a target for the Senate to shoot at, things should start coming together on the Senate side," he predicted.
Alan Paller, director of research at the SANS Institute in Bethesda, Md. said the bill is "absolutely vital" and needs to be passed. "The objectives and the elements of this bill are vital to making significant progress in defending and fighting in cyber space."
But care needs to be taken on how resources are used, Paller said. On the scholarships front, "too many of the people being trained using the current scholarships do not come out of the programs with the key technical skills that are needed to dominate cyberspace." So before any new money is allocated for cybersecurity scholarships, improvements to cybersecurity programs already offered by the federally funded Centers of Academic Excellence are needed, he said.
cybersecurity enhancement act
Additional Resources



White Papers & Webcasts
Mobility Management for Dummies
Download Now
Best Practices for Log Monitoring
Watch Now!
Get a $20 Amazon Gift Card - Just watch a Demo
iPrism Web Filter, the TCO leader in Web Security, provides everything you need in a single appliance with throughput speeds over 100+ Mbps....
Complying with PCI without Going Broke
Do a better job saving money and securing your data. Watch now.
Eight Criteria for Selecting a Digital File Delivery Service
Manage the new realities of business. Learn more now!
Get the Instruments You Need to Become an IT Security Hero
View an online demo that shows how you can quickly bullet-proof your internet security with the new iPrism 6.4 web filter, and you'll...
Easing the E-Mail Burden During Burdensome Times
Learn how IT professionals are combating the e-mail deluge with solutions that meet their business requirements, are cost-effective, deploy easily and are easy...
Sunny Skies Ahead- Evolving Your Security Infrastructure for the Cloud
Register for this webcast now!
Free up Email System Resources and Reduce Risk
Make your email systems easier to manage by offloading large email attachments.

