Obama executive order redefines critical infrastructure
More companies could get designated as part of the sector under this week's presidential cybersecurity order
Computerworld - President Barack Obama's cybersecurity executive order, signed on Tuesday, could significantly expand the list of companies categorized as part of U.S. critical infrastructure sector, security experts said Wednesday.
The executive order requires federal agencies and critical infrastructure owners and operators to work cooperatively to minimize cyber risks and strengthen resilience to attacks. It also calls for the creation of new consensus security standards and best practices that critical infrastructure companies will be urged, but not mandated, to follow.
The order stems from what the White House has long said is the need for immediate action to protect critical assets against cyber threats.
Administration officials contended that the order was necessary because Congress has so far failed to adequately update cybersecurity legislation.
A key piece of the executive order is requires federal agencies overseeing critical infrastructure areas to identify organizations "where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security."
Such entities will then be designated as part of the U.S. critical infrastructure.
The order gives the Department of Homeland Security (DHS) and sector-specific federal agencies 150 days to use a risk-based assessment approach to identify such organizations. Owners and operators of those businesses will then be notified by the DHS.
The order allows businesses to challenge a classification and ask to for reconsideration.
A separate Presidential Policy Directive (PPD-21) released on Tuesday scraps the previous national policy for federal agencies and departments to identify and prioritize critical infrastructure. That policy had been established under Homeland Security Presidential Directive-7 (HSPD-7) of 2003.
"This PPD updates our policy from a primary focus on protecting critical infrastructure against terrorism to protecting, securing, and making the nation's critical infrastructure more resilient to all hazards - including natural disasters, manmade threats, pandemics, and cyber attacks," a spokeswoman from the White House's National Security Council told Computerworld via email Wednesday.
"The PPD is focused on clarifying Federal roles and responsibilities; integrating physical security and cybersecurity analysis and situational awareness; improving information sharing; and having the Federal government function more effectively to be a better partner to the critical infrastructure owners and operators," she added.
The Presidential directive identifies 16 critical infrastructure sectors, including the Chemical, Commercial Facilities, Critical Manufacturing, Dams, Defense Industrial Base, Energy, Financial Services, Information Technology, Nuclear Reactors and Water and Wastewater systems.
The DHS is the designated federal agency for 10 of these sectors, including IT, Critical Manufacturing and Communication. The Treasury Department will oversee the identifying of critical infrastructure entities within the financial services sector while the Department of Defense will oversee the Defense Industrial Base sector.
The language in the executive order significantly broadens the number of entities that can be classified as being part of the country's critical infrastructure, said Andrew Serwin, chair of the privacy, security and information management practice at law firm Foley & Lardner LLP.
The order defines critical infrastructure as any organization and associated systems where a cyberattack could pose a threat to U.S. national security, public safety and health or economic interests.
- Cyberattacks could paralyze U.S., former defense chief warns
- The NSA blame game: Singling out RSA diverts attention from others
- Jury still out on FISA court
- Suspected China-based hackers 'Comment Crew' rises again
- Chinese hackers master the art of lying in wait
- Spy court OK'd all U.S. wiretap requests it received in 2012
- Groups denounce FBI plan to require Internet backdoors for wiretaps
- South Korea cyberattacks hold lessons for U.S.
- U.S. military networks not prepared for cyberthreats, report warns
- Return of CISPA: Cybersecurity boon or privacy threat?
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts