A ‘Light Touch’ For Non-Critical Infrastructure Cybersecurity
This week, CDT filed comments responding to the recent green paper of the Department of Commerce Internet Policy Task Force, which outlined the Administration’s proposed approach to the cybersecurity challenges faced by companies outside the critical infrastructure and key resources designation. The green paper, issued in June, focused on a cluster of functions and services that it called the “Internet and Information Innovation Sector” or “I3S.” The green paper laid out several policy recommendations intended to help this sector develop security best practices and voluntary codes of conduct as well as incentivize private sector cybersecurity efforts.
In our comments on the green paper, CDT applauded the Department’s proposed light regulatory touch for non-critical infrastructure, with its focus on voluntary standards, public-private cooperation, transparency, respect for privacy, and the protection of innovation. CDT also noted, however, that these same principles should also guide the development of cybersecurity regulations for critical infrastructure. We stressed that, for both critical and non-critical systems, the responsibility for monitoring privately-owned networks for intrusions should reside with the network owners, not the government.
CDT expressed support for the Department’s proposal that I3S members develop voluntary, enforceable codes of conduct that can afford companies an appropriate amount of freedom and flexibility in their approaches to cybersecurity.
CDT cautioned the Task Force to take an incremental approach in its efforts to improve cybersecurity information sharing, advocating that special attention be paid to the privacy issues. Specifically, CDT argued, the Department should explain how the information sharing regime it envisions for cybersecurity for the I3S sector would comply with Fair Information Practices principles and with the laws protecting the privacy of electronic communications.
CDT looks forward to working with the Task Force as it continues to develop a framework for enhancing cybersecurity of non-critical information networks and systems.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.