Lawmakers reintroduce cyberthreat information-sharing bill
Some privacy and civil liberties groups say that CISPA still allows companies to share too much privacy information
IDG News Service - Two U.S. lawmakers have reintroduced a controversial cyberthreat information-sharing bill over the objections of some privacy advocates and digital rights groups.
As promised, Representatives Mike Rogers, a Michigan Republican, and C.A. "Dutch" Ruppersberger, a Maryland Democrat, have reintroduced the Cyber Intelligence Sharing and Protection Act (CISPA), a bill that would allow private companies to share a wide range of cyberthreat information with U.S. government agencies.
New legislation is needed to protect the U.S. from cyberattacks coming from Iran and other countries, said Rogers, chairman of the House of Representatives Intelligence Committee. Cyberattacks have "exploded into what is an epidemic," he said during a briefing on the bill. "We are in a cyberwar -- most Americans don't know it, most folks in the world probably don't know it -- and at this point, we're losing."
The bill can help U.S. agencies and businesses address their toughest cybersecurity problems, Rogers said. "It's not a surveillance program, it's in real time, at the speed of light, exchanging zeros and ones when it comes to malicious software to catch it and stop it," he said.
Several privacy and digital rights groups have said the bill allows companies to share too much private information with government agencies, without sufficient oversight. The U.S. House of Representatives passed CISPA last April, but the legislation failed to advance in the Senate after the White House threatened a veto over privacy concerns.
The privacy protections in the new bill are "woefully inadequate," Sharon Bradford Franklin, senior policy counsel at civil liberties group the Constitution Project, said in an email. "If passed in its current form, it would allow companies that hold sensitive personal information to share it with the federal government, including with agencies that have a history of domestic spying, which could then potentially use the information for purposes totally unrelated to cybersecurity," she added..
Rogers and Ruppersberger said they've addressed privacy concerns in the new bill, although several privacy groups still voiced opposition to CISPA. The lawmakers have worked with privacy groups and will work with the White House as the bill moves forward, Ruppersberger said.
The two sponsors engaged in "lengthy negotiations" on privacy concerns, Ruppersberger said. The new bill has narrowed the definition of information that can be shared and sets strict restrictions on the government's use and searching of the data, the sponsors said.
The two lawmakers introduced CISPA a day after President Barack Obama signed an executive order focused on allowing federal agencies to share cyberthreat information with U.S. businesses and on creating voluntary cybersecurity standards for operators of critical infrastructure.
The bill is needed in addition to the executive order to enable wider sharing of cyberthreat information than the order allows, Rogers said. While Obama's order allows federal agencies to share cyberthreat information with companies, the bill would allow agencies to share classified information and would allow U.S. businesses to share cyberthreat information with each other and with government agencies.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...