Showing posts with label Cybersecurity Intelligence. Show all posts
Showing posts with label Cybersecurity Intelligence. Show all posts

Monday, December 5, 2011

HR 3523 Amendments

The results of last week’s markup of HR 3523, the Cyber Intelligence Sharing and Protection Act of 2011 [NOTE: the GPO print is now available] were finally posted on the Intelligence Committee web site this weekend. I suppose since most of their hearings are classified they don’t get a lot of practice putting up ridiculously small amounts of information on their web page.

There were two amendments, neither of which made any substantive changes in the information shared by the government. To keep the industry happy about providing information to the government about security issues, they further restricted the use that the intelligence community can make of the information provided. And the second amendment requires yet another report to Congress about the success of this program.

Reporting Protections


The amendment from the Chairman and Ranking Member prohibits the federal government from using the information provided unless “at least one significant purpose of the use of the information is” cybersecurity or protection of the national security of the United States {§1104(c)(1)(B)}. Furthermore, the government is prohibited from even searching the information for a purpose other than those two; can’t have the government searching for how many bogus reports came from a single source now.

Such attention to paranoia is amazing. The bill already prohibited the government from using the material for regulatory purposes, releasing it under the Freedom of Information Act, sharing it with other entities without permission and prohibits courts from using it in liability cases based upon the reporting, or failing to report, cybersecurity information in ‘good faith’. This is much better treatment (from the point of view of the black-helicopter league) than the average citizen gets under the ‘See Something Say Something’ program.

Of course, since neither ‘cybersecurity’ nor ‘protection of the national security of the United States’ is defined in the bill, these provisions are practically speaking unenforceable. Oh well, at least the Congressmen can point to the words in the bill; as if any government words will make the black-helicopter crowd happy.

IG Report


The second amendment by Rep. Thompson, (R, CA) requires the Inspector General of the Intelligence Community (that would be an interesting job), to prepare a report to Congress on the use made of intelligence provided by the private sector. The wording of the amendment makes it clear that, once again, the main concern of the Committee is that the information provided by the private sector will not be misused by the Government.

While I certainly don’t want any God-Fearing American Citizen’s privacy or civil liberties being abused by the intelligence community, I am much more concerned about ensuring that the government intelligence community proactively shares threat information with the private sector. How about a report on the number of intelligence reports that get down to the potential targets so that they can properly protect themselves against cyber-attacks? That is what I would like to see tracked by the IG.

Bipartisan Support


The press release announcing the results of the mark-up of this bill notes that it was passed on a “decisive vote of 17-1”; though there is no word on how the two amendments were adopted. A 17 to 1 vote (even with two committee members not voting) can be assumed to be a show of bipartisan support for the bill and there is no reason that this bill couldn’t achieve the same sort of support on the floor.

I would not be surprised, however, if this bill gets rolled into whatever general cyber-security bill makes it to the floor of the House in January.

Thursday, December 1, 2011

HR 3523 Introduced – Cybersecurity Intelligence Sharing

Yesterday Rep. Rogers (R,MI) introduced HR 3523, the Cyber Intelligence Sharing and Protection Act of 2011 (Note: the text of the bill is not yet available on the GPO site, but it is available on Thomos.LOC.gov but there are no permanent links on that site) [Here is the link to the bill text - http://t.co/EodFJriz; Thanks to Chris Jager for info on how to get permanent link on Thomas.loc.com; Updated 07:57 CST]. The bill would require the Director of National Intelligence (DNI) to “establish procedures to allow elements of the intelligence community to share cyber threat intelligence with private-sector entities and to encourage the sharing of such intelligence” {§1104(a)(1)}.

New Class of Disclosure


Current law already allows sharing of intelligence information, at the discretion of the intel community, with people in the private sector with the appropriate Need-To-Know and the proper security clearance. This bill would expand that discretion and allow for sharing with ‘certified entities’ even if they currently have no security clearances. It still would require the protection of the shared “cyber threat intelligence from unauthorized disclosure” {§1104(a)(2)(C)}



A ‘certified entity’ is a cybersecurity provider, protected entity (someone who has hired a cybersecurity provider to provide protect their system), or a self-protected entity (someone who has cybersecurity providers in-house). There are two important caveats to this definition; the certified entity {§1104(f)(1)}:

“[P]ossesses or is eligible to obtain a security clearance, as determined by the Director of National Intelligence; and

“[I]s able to demonstrate to the Director of National Intelligence that such provider or such entity can appropriately protect classified cyber threat intelligence.”

The difference between ‘possesses’ and ‘is eligible to obtain’ is an important quibble. There are long delays in getting security clearances approved and they are not handed out to the private sector unless there is a need for them. This would allow an intel agency to disclose actionable intelligence to a cyber-target with a minimal security check.

Would Cover ICS


The definition of cybersecurity system included in this bill is very broad and contains none of the code words that would restrict it to information systems. Theft or misappropriation of information is included as one of things to be protected against, but only after “efforts to degrade, disrupt or destroy” {§1104(f)(5)(A)} the system is listed.

Sharing is a Two-Way Street


This bill recognizes that sharing information would also include cybersecurity intelligence information flowing back to the intelligence community. It specifically includes three very important protections for covered entities that provide that intelligence; the information shall {§1104(b)(2)(C)}:

“[B]e exempt from disclosure under section 552 of title 5, United States Code [Freedom of Information Act];

“[B]e considered proprietary information and shall not be disclosed to an entity outside of the Federal Government except as authorized by the entity sharing such information; and

“[N]ot be used by the Federal Government for regulatory purposes.”

It does not, however, include such disclosures in any of the recognized categories of protected information. Specifically, it does not protect the information under classified information rules or any one of a number of Sensitive But Unclassified categories that are currently undergoing review. This would potentially leave the shared information open to disclosure in court cases, for instance.

The bill was referred to the House Select Committee on Intelligence for consideration and review; that likely means that at least some Committee hearings on this bill would take place behind closed doors.
 
/* Use this with templates/template-twocol.html */