Lawmakers, business execs defend privacy in CISPA
Critics say the cyberthreat information-sharing bill still has privacy problems
IDG News Service - Privacy and digital rights groups are overstating the privacy concerns in a controversial cyberthreat information bill introduced this week in the U.S. Congress, the bill's sponsors and leaders of some business groups said.
Groups opposed to the Cyber Intelligence Sharing and Protection Act (CISPA), introduced Wednesday, have "unfounded fears" about the privacy implications of the bill, said Representative Mike Rogers, a CISPA sponsor, Michigan Republican and chairman of the House of Representatives Intelligence Committee.
The bill would allow private companies in the U.S. to share cyberthreat information related to national security and cybercrime with each other and with government agencies, and it gives companies that share information in "good faith" immunity from customer lawsuits. CISPA would also allow government agencies to share classified cyberthreat information with businesses.
The bill is needed, Rogers said, because companies fear lawsuits if they share cyberthreat information with each other or the government.
Several privacy and civil liberties groups have objected to the bill, saying it allows privacy companies to share a wide range of personal information with government agencies without adequate oversight. On Thursday, the same day as a House hearing on CISPA, digital rights groups Demand Progress and Fight for the Future said they delivered a petition with 300,000 signatures opposing CISPA to Congress.
"According to the bill, personal information can be shared and obtained as long as the purpose is for 'cybersecurity' purposes, which can include anything like 'safeguarding' networks," Tiffiniy Cheng, co-founder of Fight for the Future, wrote in an email. "You can already choose a list of things that would fit into that [description] that most people would find to be a horrifying reason to obtain their personal info."
But companies would share little, if any, personal information with each other or with government agencies, Paul Smocer, president of the BITS tech policy arm of the Financial Services Roundtable, said during Thursday's hearing. Companies would be sharing information about the type of attacks and the source of attacks, not personal information about customers whose data was compromised, he said.
When cybersecurity vendor Mandiant now shares attack information with its customers, "it's data that is totally anonymous," added Kevin Mandia, CEO of Mandiant.
Smocer called the current privacy provisions in CISPA adequate.
In some cases, however, companies would be sharing the IP addresses of suspected attackers, Smocer said. Witnesses in the hearing didn't talk about the privacy implications of sharing information about suspected attackers.
The Intelligence Committee had no privacy or civil liberties groups testify during the CISPA hearing.
Most members of the committee did not raise privacy concerns, but Representative Adam Schiff, a California Democrat, asked witnesses if they would decline to share cyberthreat information if the bill required them to take reasonable steps to delete personal information. None of the four business witnesses said such a requirement would stop them from sharing information.
- Step Out of the Bull's-Eye Learn about the evolution of targeted attacks, the latest in security intelligence, and strategic steps to keep your business safe.
- Using Cyber Insurance and Cybercrime Data to Limit Your Business Risk This paper examines the challenges of understanding cyber risks, the importance of having the right cyber risk intelligence, and how to use this...
- 5 Tips to Secure Small Business Backdoors in the Enterprise Supply Chain This paper examines the insecurity of the small businesses in the supply chain and offers tips to close those backdoors into the enterprise.
- Comprehensive Advanced Threat Defense The hot topic in the information security industry these days is "Advanced Threat Defense" (ATD). This paper describes a comprehensive, network-based approach to...
- Live Webcast Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- Security Vulnerabilities Associated With Having Local Administrator Privileges Viewfinity will demonstrate how removing admin rights and granularly managing privileges at the application level reduces the attack surface.
- What Does it Take to Deliver a Superior Customer Experience? The Two Top-Rated Online Retailers, B&H Photo and Crutchfield Electronics, Share Their Secrets Discuss practical CX tools and service methods such as contact center agents and the use of realtime speech analytics to help contact center... All Cybercrime and Hacking White Papers | Webcasts