The Cybersecurity Act of 2009, S. 773, introduced by Senators Rockefeller (D-WV) and Snowe (R-ME), has kicked off what promises to be an intense debate over the federal government’s cybersecurity policy. There’s broad consensus about the goal – better security for both governmental and private sector critical infrastructure information systems – but not much agreement about how to achieve it.
The Rockefeller/Snowe bill includes some especially troubling provisions. For starters, it would give the President the authority to limit or shut down Internet traffic to federal government and private critical infrastructure systems. It would give the Secretary of Commerce the power to override any law, regulation, or policy – including privacy laws and laws protecting trade secrets – to obtain access to information held by private parties that might be relevant to cybersecurity threats and vulnerabilities. Broadly read, the provision would authorize the Secretary of Commerce to override the Wiretap Act and the Electronic Communications Privacy Act to gain access to communications content. Finally, it includes provisions that would allow the government to dictate software design standards for the private sector.
CDT has prepared a detailed analysis of the Rockefeller-Snowe bill here.
Fortunately, the Rockefeller/Snowe bill isn’t the only game in town.
Senator Carper’s (D-DE) U.S. Information and Communications Enhancement (ICE) Act (S. 921) takes an entirely different, and much more appropriate, approach. It focuses primarily on strengthening the security of governmental information systems by amending the Federal Information Security Management Act. In contrast, many provisions of the Rockefeller-Snowe bill would apply the same measures and authorities without distinction to both private and public systems.
Also taking a more cautious approach is Senator Lieberman’s (I-CT) S. 946, which focuses on securing the electric power grid against cyber attack. While it is true that "bits are bits," the sectoral approach to cybersecurity recognizes that measures appropriate for securing systems that are used to control the electric power grid might be inappropriate for securing elements of the communications infrastructure. This sectoral approach says, basically, "Let’s identify the ways in which the electric power grid is vulnerable and develop solutions for those vulnerabilities."
To the credit of Senators Rockefeller and Snowe, they have actively solicited comments and suggestions for improving their legislation. CDT has met with staff for both Senators and has shared its views and concerns as well as ideas for alternative approaches.
Soon, the report of the team President Obama appointed to review cybersecurity policy government-wide will be made public. Melissa Hathaway and her team gave the report to the President on April 17. This report will sketch out at a high level the Administration’s views about how cybersecurity should be addressed. It will no doubt spur additional legislation and further advance the debate.
Almost every week, a new major cybersecurity breach is reported in the media. The test for Congress and the Administration will be to address the security issues that permit these incidents to occur without doing unnecessary damage to the openness and innovation that has made the Internet so successful.
For more information, see my May 1 testimony before a House subcommittee here.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.