Obama cybersecurity order lacks bite, security experts say
Scaled back order a good start, but comprehensive bipartisan legislation is essential to prevent cyberattacks
Computerworld - President Barack Obama's cybersecurity executive order, announced during his State of the Union address Tuesday night, elicited guarded praise from several quarters even as it revived calls for more comprehensive bipartisan legislation to address long-term security threats.
As expected, Obama last night signed a Presidential Policy Directive requiring federal agencies and critical infrastructure owners and operators to work cooperatively to minimize cyber risks and strengthen resilience to attacks.
The order stems from what the White House has long said is the need for immediate action to protect critical assets against cyber threats because of Congress' continued failure to pass legislation.
Republicans, however, have assailed the plan to issue the order as unnecessary presidential overreach and have long maintained that the best way to address security issues is through bipartisan legislation.
BITS, the technology policy division of the influential Financial Services Roundtable, last night called the directive a constructive step forward but added that legislation is still necessary.
"While the Executive Order moves our nation forward, Congressional action is needed to effect additional fundamental improvement," the group said in a statement. "We urge Congress to build upon these actions, while not duplicating them."
"The Administration's new cyber policy is a mixed bag," said Larry Clinton, president of the Internet Security Alliance. "Its ultimate success rests on how several ambiguous policies are implemented."
The increased information sharing, and the emphasis on voluntary standards are positive steps, Clinton said in a statement. "But if the talk of partnership and incentives is just a rhetorical facade for the same approach that has failed in the Senate for the past three years, then this so-called 'new policy' will leave us where we are now: without a coherent policy in the face of ever more sophisticated cyber threats to our nation."
President Barack Obama's cybersecurity executive order elicited guarded praise from several quarters even as it revived calls for more comprehensive bipartisan legislation to address long-term security threats.
Obama's order requires that federal government agencies share cyberthreat and vulnerability information with each other and with private companies. It calls for the enablement of a national situational awareness capability for cybersecurity through better information sharing.
The executive order establishes two national critical infrastructure centers to be operated by the U.S. Department of Homeland Security (DHS). One will focus on physical infrastructure and the other on cyber infrastructure.
The centers will serve as a central point for collecting and disseminating threat information gathered by various sector specific government agencies and departments and by owners of critical infrastructure.
The centers will also be responsible for integrating, analyzing and prioritizing vulnerability and threat information from various sources including the Department of Defense, the Department of Justice and the intelligence community.
As part of this function, the DHS centers will recommend prevention and mitigation measures for critical infrastructure prior to and during a cyberattack, and will help with incident response and restoration efforts.
The executive order puts DHS in charge of planning, coordinating and implementing changes. It requires the DHS and sector-specific federal agencies to work with critical infrastructure owners and regulatory entities to develop security guidelines and metrics for measuring progress.
- DOJ's charges against China reframe security, surveillance debate
- Hacker indictments against China's military unlikely to change anything
- U.S. to formally accuse Chinese military of hacking
- Cyberattacks could paralyze U.S., former defense chief warns
- The NSA blame game: Singling out RSA diverts attention from others
- Jury still out on FISA court
- Suspected China-based hackers 'Comment Crew' rises again
- Chinese hackers master the art of lying in wait
- Spy court OK'd all U.S. wiretap requests it received in 2012
- Groups denounce FBI plan to require Internet backdoors for wiretaps
- Top 10 Reasons to Strengthen Information Security with Desktop Virtualization Regain control and reduce risk without sacrificing business productivity and growth
- Preventing Sophisticated Attacks: Anti-Evasion & Advanced Evasion Techniques McAfee Next Generation Firewall applies sophisticated analysis techniques specifically to detect advanced evasion techniques (AET).
- The Security Industry's Dirty Little Secret The debate over advanced evasion techniques (AETs) This report summarizes the findings of a McAfee commissioned research group to determine the level of understanding IT security professionals have about AETs...
- Demand More, Get the Most from the Move to a Next-Generation Firewall Beyond the basics in a next generation firewall, to protect your investment you should demand other valuable features: intrusion prevention, contextual rules, advanced...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!