Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Revised Cybersecurity Act of 2012 Again Goes Before U.S. Senate

    Written by

    Todd R. Weiss
    Published July 31, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A reworked version of a proposed and controversial federal cyber-security law is again going before the U.S. Senate, but this time, the so-called Cybersecurity Act of 2012 might have enough changes and comprises to make it more palatable for all sides.

      Senate debate on the revised legislation will begin July 31, several months after an earlier version was withdrawn due to criticism of some of its language and policy related to digital privacy and personal freedoms.

      “This revised legislation would establish a robust public‐private partnership to improve the cybersecurity of our nation€™s most critical infrastructure, which is mostly owned by the private sector,” according to a summary of the bill. “Industry would develop voluntary cybersecurity practices and a multi‐agency government council would ensure these practices are adequate to secure systems from attacks.”

      The bill “was developed in response to what defense and intelligence leaders have called an €˜existential threat€™ to our country,” according to the legislation. “Our critical infrastructure is increasingly vulnerable to cyber threats, and can be manipulated or attacked by faceless individuals using computers halfway around the globe. The destruction or exploitation of critical infrastructure through a cyber attack, whether a nuclear power plant, a region€™s water supply, or a major financial market, could cripple our economy, our national security, and the American way of life. We must act now.”

      Several critics of the earlier version of the legislation say they are more comfortable with the new version of the bill, though they still question whether such a law is ultimately needed.

      “The bill is a step in the right direction of protecting online rights, but still has major flaws that allow for nearly unlimited monitoring of user data or countermeasures (like blocking or dropping packets),” wrote Mark Jaycox and Rainey Reitman of the Electronic Frontier Foundation privacy group in a blog post. That “overly broad” language is contained in Section 701 of the bill, they wrote, and is being addressed by an amendment that would remove this specific language.

      “We remain unconvinced that a cybersecurity bill is necessary at this time, and we’re committed to fighting to ensure user privacy isn’t sacrificed in the rush to pass a bill,” they wrote. “While the most recent version of the bill has strong privacy protections, Section 701 continues to pose a real threat to the rights of users to communicate privately.”

      The American Civil Liberties Union said the new version of the bill better addresses key privacy concerns that the group had with the previous version.

      “Senators have unveiled significant privacy amendments” in the new legislation, wrote Michelle Richardson, legislative counsel for the ACLU in Washington, in a blog post, including that “companies who share cybersecurity information with the government give it directly to civilian agencies, and not to military agencies like the National Security Agency.”

      “The single most important limitation on domestic cybersecurity programs is that they are civilian-run and do not turn the military loose on Americans and the Internet,” Richardson added.

      The revised bill would also “restrict the government€™s use of information it receives under the cyber info sharing authority so that it can be used only for actual cybersecurity purposes and to prosecute cyber crimes, protect people from imminent threat of death or physical harm, or protect children from serious threats,” Richardson wrote.

      The bill would also “require annual reports from the Justice Department, Homeland Security, Defense and Intelligence Community Inspectors General that describe what information is received, who gets it, and what is done with it,” Richardson wrote, as well as “allow individuals to sue the government if it intentionally or willfully violates the law.”

      In a statement, Fred Humphries, vice president of U.S. government affairs for Microsoft, called the new bill “an encouraging step in the legislative process.”

      “Microsoft supports Congress€™ efforts to advance risk management practices, strengthen protection of critical infrastructure, and enhance appropriate information sharing about cyber-threats,” Humphries said. €œThe framework is flexible enough to permit future improvements to security−an important point since cyber-threats evolve over time. The current bill as it stands seeks to advance these priorities and we continue to work to help ensure that any legislation is optimized to meet cyber-security challenges while protecting civil liberties and privacy.”

      The highlights of the new bill include the following:

      • It would establish the National Cybersecurity Council made up of members from the departments of Defense, Justice, Commerce, the intelligence community and other federal agencies, to conduct risk assessments to find the greatest and most immediate cyber-risks to Americans. The Council would also identify the nation’s most critical infrastructure to help improve national security against attacks.
      • It would improve information sharing between private sector companies and the federal government while protecting individual and civil liberties.
      • It would improve the security of federal government networks by amending the Federal Information Security Management Act (FISMA) and would require the federal government to develop a comprehensive acquisition risk management strategy. The amendments to FISMA would move agencies away from a culture of compliance to a culture of security by giving the Department of Homeland Security the authority to streamline agency reporting requirements and reduce paperwork through continuous monitoring and risk assessment.

      A national cyber-security bill has been in serious discussions for the last several years. In 2010, Senate Bill 3480, the Protecting Cyber Space as a National Asset Act, failed to be taken up by the full Senate, according to The Homeland Security and Governmental Affairs Committee. Then in February 2011, Senate Bill 413, the Cybersecurity and Internet Freedom Act, was introduced. It was later merged with similar legislation from other congressional committees, resulting in The Cybersecurity Act of 2012, Senate Bill 2105, the original cyber-security law was introduced this past February.

      Todd R. Weiss
      Todd R. Weiss
      Todd R. Weiss is a seasoned technology journalist with over 15 years of experience covering enterprise IT. Since 2014, he has been a senior writer at eWEEK.com, specializing in mobile technology, smartphones, tablets, laptops, cloud computing, and enterprise software. Previously, he was a staff writer for Computerworld.com from 2000 to 2008, reporting on a wide range of IT topics. Throughout his career, Weiss has written extensively about innovations in mobile tech, cloud platforms, security, and enterprise software, providing insightful analysis to help IT professionals and businesses navigate the evolving technology landscape. His work has appeared in numerous leading publications, offering expert commentary and in-depth analysis on emerging trends and best practices in IT.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.