Showing posts with label Executive Order. Show all posts
Showing posts with label Executive Order. Show all posts

Wednesday, April 1, 2015

Retaliation for Cyber Attacks; A new Executive Order

Today President Barack Obama signed his latest executive order on cybersecurity issues; this time outlining at least one method by which the Administration intends to respond to significant cyber attacks. This executive order (the number will be made available when the order is officially published in the Federal Register on Friday or Monday) is entitled: “Blocking the Property of Certain Persons Engaging in Significant Malicious Cyber-Enabled Activities”.

Declaration of National Emergency

This Executive Order is an exercise of presidential authority granted under 50 USC 1701. That authorizes the President to react to a declared national emergency. The preamble to this Executive Order is a declaration that “the increasing prevalence and severity of malicious cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States constitute an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States”. While not as expansive as many other declarations, this should satisfy the requirements of §1701.

Authorization for use of Economic Sanctions

In this exercise of presidential authority the president is allowed {§1702(a)} to investigate, regulate or prohibit:

∙ Any transactions in foreign exchange;
∙ Transfers of credit or payments between, by, through, or to any banking institution, to the extent that such transfers or payments involve any interest of any foreign country or a national thereof; and
∙ The importation or exportation of currency or securities.

This authorization extends to any person or property subject to the jurisdiction of the United States.

Defining the People Affected

The EO provides a fairly comprehensive description of the people and organizations that will be affected by these sanctions. Section 1 of the EO provides that the Secretary of the Treasury is responsible for identifying people that are “responsible for or complicit in, or to have engaged in, directly or indirectly, cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States”.

The activities are further described as being “reasonably likely to result in, or have materially contributed to, a significant threat to the national security, foreign policy, or economic health or financial stability of the United States”. Specifically identified are activities that {§1(a)(i)}:

∙ Harm, or otherwise significantly compromise the provision of services by, a computer or network of computers that support one or more entities in a critical infrastructure sector;
∙ Significantly compromise the provision of services by one or more entities in a critical infrastructure sector;
∙ Cause a significant disruption to the availability of a computer or network of computers; or
∙ Cause a significant misappropriation of funds or economic resources, trade secrets, personal identifiers, or financial information for commercial or competitive advantage or private financial gain.

Additionally, the President intends to take action against anyone that {§1(a)(i)}:

∙ Receives or uses for commercial or competitive advantage or private financial gain, or by a commercial entity, outside the United States of trade secrets misappropriated through cyber-enabled means;
∙ Has materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services in support of, any activity described in this order;
∙ Is owned or controlled by, or to have acted or purported to act for or on behalf of, directly or indirectly, any person whose property and interests in property are blocked pursuant to this order; or
∙ Has attempted to engage in any of the activities described in this order.

Maximizing the Sanctions

Normally 50 USC 1702 prohibits sanctions from affecting “donations, by persons subject to the jurisdiction of the United States, of articles, such as food, clothing, and medicine, intended to be used to relieve human suffering” {§1702(b)(2)}. The President, however, evoked the exception to that rule by declaring {§2} that allowing those types of donations “would seriously impair my ability to deal with the national emergency declared in this order”. Thus, strictly humanitarian may also be restricted from being provided to the persons or organizations identified by the Secretary of the Treasury.

Additionally, the President has opted to {§4} “suspend entry into the United States, as immigrants or nonimmigrants” for any of the people designated by the Secretary.

The remainder of the EO is essentially housekeeping; providing authorization for various federal agencies to undertake the necessary work to make this order effective.

Commentary

This EO is largely targeted at economically inspired cyber-attacks on the United States. This was at least partially clarified by Lisa Monaco, the chief counterterrorism advisor to the President; who said in a National Security Council blog post today:

Malicious cyber activity — whether it be stealing sensitive information, including personal identifiers, or trade secrets — is often profit-motivated. Because those responsible want to enjoy the ill-gotten proceeds of their activities, sanctions can have a significant impact. By freezing assets of those subject to sanctions and making it more difficult for them to do business with U.S. entities, we can remove a powerful economic motivation for committing these acts in the first place. With this new tool, malicious cyber actors who would target our critical infrastructure or seek to take down Internet services would be subject to these costs when designated for sanctions.

These types of tools have not been enormously successful in countering drug cartels, for instance. And their utility against foreign governments has been almost completely inconsequential (except for the residents of those nations). It is hard to understand how anyone expects this to have any serious consequence in reducing, much less stopping foreign based cyber-attacks against this country.


It does provide the government with the ability to ‘take action’ short of direct counter-attacks by cyber, cyber-physical or conventional military forces. The fact that this action can be corrected in kind if the attribution about the source of the original attack turns out to be mistaken will allow actions to be taken with less thought of consequences of mis-attribution. To that extent this is probably a good (if ineffective) tool to have available; it will allow for political cover while further investigation takes place.

Wednesday, February 13, 2013

Cybersecurity Executive Order


Well, President Obama finally signed the long promised Cybersecurity Executive Order. We don’t have an EO number yet, that will come in the next day or two when the EO is published in the Federal Register. In any case, what is posted on the White House web site is certainly good enough for us to start seeing what practical effect this EO will have on cybersecurity.

The Policy

We couldn’t even get started on this without looking at the basic policy statement included in §1:

“It is the policy of the United States to enhance the security and resilience of the Nation's critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties.”

While this policy is supposed to be focused on ‘critical infrastructure’ it is clear that the focus of the cybersecurity effort is on information security. Control systems are addressed in passing (a single mention, safety, is specifically targeted at physical systems), but it is clear that this is mainly an IT policy.

Critical Infrastructure

Since this EO is targeted on protecting the cybersecurity of critical infrastructure it is important to understand what that term means. First in §2 we see a basic definition of the term:

“As used in this order, the term critical infrastructure means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

The way this definition is constructed it is difficult to see any single facility or company that would qualify as ‘critical infrastructure’. This definition would only seem to apply to networks or organizations. For example, only the incapacity or destruction of the electric transmission network, the gasoline pipeline network or the financial network would have a truly debilitating impact on the ‘national economic security’ or ‘national public health’. It is hard to see how the destruction or incapacity of any single entity would meet the definition.

This definition is expanded somewhat in §9(a) where the Secretary of DHS is required to identify “critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional [emphasis added] or national effects on public health or safety, economic security, or national security”. The addition of a lower ‘regional’ impact standard will increase slightly the number of affected facilities. It would probably stretch to include major oil refineries for instance or regional power companies.

Now all of this certainly depends on how you define ‘debilitating impact’; a term carefully left undefined in this EO. The more broadly you define ‘debilitating’ the more inclusive the term ‘critical infrastructure’ becomes. Water it down enough and everything is critical infrastructure.

Information Sharing

The one thing that should be relatively easy to implement in this EO would be the information sharing provisions of §4. It shouldn’t take an EO, however, for the President to direct the intelligence agencies to produce unclassified reports on cybersecurity threats as is outlined in §4(a). The expansion of the sharing of classified intelligence as outline in §4(c) will be slow as the private sector will be slow to adopt the necessary security mechanisms required to handle classified documents.

The Cybersecurity Framework

Since there is no Congressional mandate or authority for the regulation of cybersecurity, the President has studiously avoided the use of the word ‘regulation’. Instead he has required the Director of the National Institute of Standards (NIST) to lead the development of “a framework to reduce cyber risks to critical infrastructure”. To ensure that everyone understands that these non-regulation are intended to behave like regulations, §7(a) goes on to explain that the framework “shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks”.

The semi-regulatory nature of the framework is further reinforced by the requirement in §7(d) that the Director shall “engage in an open public review and comment process”; the same type review process that is used for writing or revising regulations.

The one area where this EO has certainly taken an extreme leap of faith has been in the time frame set forth for the development of the Cybersecurity Framework. Section 7(e) of the order provides the Director 240 day to publish a preliminary version of the framework. Depending on how much of the work of developing the framework has already been done by NIST (and I would bet that they have been hard at work on this while the EO was being developed) this might actually be doable.

It will be nearly impossible, however, to have the final version of the framework published 125 days later (within one year of the official publication of this EO). This is because of the need to complete the comment and review process promised in §7(d). Anything less than a 90 day comment period will certainly end up in court and it will take a minimum of at least another 90 days for NIST to process and formulate responses to the huge number of comments that will inevitably result.

Since these are supposed to be consensus standards formulated in consultation with rest of the federal government, I will be very surprised if the draft version of the framework can be published within the one year time frame and it could be 2016 before the OMB approves the final version. And the OMB will be intimately involved in the publication of this document; see §12(b).

Voluntary Adoption of Framework

Section 8 of the EO clearly makes adoption of the framework by the private sector voluntary and there will be incentives developed {§8(d)} even before the draft framework is completed to encourage that voluntary participation in the program. The most important incentive is outlined in §8(e) where an attempt will be made (almost certainly successfully) to require adoption of the standards as part of the federal acquisition process. That is a fairly big carrot/stick that could be wielded far beyond the broadest possible definition of ‘critical infrastructure’.

The portion of the EO that will cause the most problems for the private sector is to be found in §10 where it spells out how agencies “with responsibility for regulating the security of critical infrastructure” will try to find existing authorities to require the implementation of the framework within the regulated community. Those agencies have 90 days from the publication of the preliminary framework to identify:

• If agency has clear authority to establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure;
• The existing authorities identified, and
• Any additional authority required.

It is likely that some agencies will be able to begin implementation of the framework requirements before the final framework is approved in the comment and response process. Even where clear authority exists, though, it will take regulatory changes (with the required comment and review process) to fully implement the final framework provisions.

The Legislative Process

 The one thing that this EO will certainly do is to aggravate the legislative process for the adoption of cybersecurity measures by Congress. The Republican controlled House is certain to start work on bills to limit the authority of the President to implement the framework even before the initial version is published. Those challenges will focus on the provisions of §8(e) and §10. That legislative work will certainly take away from efforts to produce a Republican consensus cybersecurity bill.

In the Senate, the amendment process on any cybersecurity legislation will be tied up in the processing of amendments to limit the implementation of this EO. The impossibility of getting the votes necessary to move past those amendments will kill any floor action on even the most agreeable cybersecurity legislation.

Implementation

Finally, I am going to have to announce that this EO is stillborn. The Obama Administration has demonstrated a complete inability to implement any of the executive orders published to date. I find it hardly likely for them to be able to implement something as complex and controversial as this.

Tuesday, December 4, 2012

The Latest Cybersecurity Draft EO


There is another reported draft of a cybersecurity executive order floating around the internet; this one dated 11-21-12. The version that I have comes from Paul Rosenzweig’s  Lawfare Blog site. Since there is no way of telling for sure if this is really from the White House, or what changes might be made to it if it is, I’m not going to do a real detailed look at its provisions. There are, however, some things of interest that bear discussion.

Definitions


The key to the extent that a cybersecurity executive order will affect any particular facility is the definition that is used for ‘critical infrastructure’. There are a number of official definitions from various pieces of legislation adopted over the years and this draft {§2} uses one of the more expansive definitions taken from 42 USC 5195c(e). That definition reads:

“In this section, the term ‘‘critical infrastructure’’ means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.” (pg 5507)

Since the terms ‘incapacity’ and ‘debilitating impact’ are undefined this definition allows a great deal of leeway for the DHS Secretary to use in determining which facilities or systems are to be considered critical infrastructure.

The other interesting definition is the one that is quite obviously absent. There is no definition of cyber anything. Again, if the covered cyber-systems are not restrictively defined, and no definition is the least restrictive definition, then it is completely up to the Secretary what should be covered. Furthermore, there is no inherent reason for internal consistency in that decision.

Selection of ‘at Greatest Risk’ Facilities or Systems


Section 9 of the draft EO requires the Secretary to “identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. This identification is supposed to take place within 150 days of the publication of the EO. Fortunately a classified list of presumptive candidates for this list is already being maintained by DHS under provisions of 6 USC 124l.

That section requires that the Secretary maintain “maintain a single classified prioritized list of systems and assets… that the Secretary determines would, if destroyed or disrupted, cause national or regional catastrophic effects [emphasis added]” {6 USC 124l(a)(2)}. All the Secretary has to determine is which ones would remain on that list because of a cybersecurity incident. Again, since ‘cybersecurity incident’ is not defined in the EO this determination can be somewhat arbitrary.

It appears that the sole reason for establishing this list of ‘at greatest risk’ facilities is to allow the Secretary to prioritize the issuance of security clearances to “appropriate personnel employed by critical infrastructure owners and operators” {§4(d)}. This would, of course, allow for the sharing of classified intelligence information with those personnel. What this ignores is that there is a lot more to sharing classified information than just having a security clearance.

Information Sharing


This version of the draft EO has the most comprehensive requirements for the federal government to share information with the private sector that I have seen to date. Section 4 of the EO separately requires the Director of National Intelligence, the Attorney General and the Secretary of DHS to prepare within 120 days instructions to their subordinate agencies to “ensure the timely production of unclassified versions of all reports of cyber threats to the U.S. homeland that identify a specific targeted entity [emphasis added]” {§4(a)}. It then directs the Secretary to establish a coordinated process that “rapidly disseminates” such reports to the “U.S. targeted entity” {§4(b)}. Of course, this does not address cyber-intelligence that does not identify a specific targeted entity.

There is nothing in this draft EO that requires, suggests or even hints that the private sector should share cybersecurity information with the Federal government. There are a couple of mentions of 6 USC 133 which deals with the government sharing of voluntarily shared critical infrastructure information, but they are just reminders of what information provided by the private sector can be shared outside of the government without specific permission.

Security Guidelines


Section 7 deals with the development of a ‘baseline framework to reduce cyber risk to critical infrastructure’ (NOTE to EO drafters: you’ve got to come up with a better name that has a memorable acronym; it’s a requirement of the OMB style manual.) The Director of NIST is required to develop a ‘Cybersecurity Framework’ that includes “a set of standards, methodologies, procedures and processes that align policy, business, and technological approaches to address cyber risks” {§7(a)}.

A preliminary version of the Cybersecurity Framework will be ready within 240 days. There are, of course no penalties assigned for missing this time frame. That is a good thing as any number of standards organizations have been working for years to come up with their particular piece of just this type of framework. Then, one year after the EO is signed the Director, after engaging in an “open public review and comment process” {§7(e)} will publish a final version of the Framework.

To make things a tad bit more confusing, while the Framework was being developed in a consultive (okay the word was made up, but it sounds appropriately bureaucratic) environment, the Sector-Specific [Federal] Agencies in further consultation with their [Private] Sector Coordinating Councils are encouraged to “develop implementing guidance or supplemental materials to address sector-specific risks and operating environments” {§8(b)}.

Voluntary Program


Section 8 requires the DHS Secretary to “establish a voluntary program to support the adoption of the Cybersecurity Framework by owners and operators of critical infrastructure and any other interested parties” {§8(a)}. The Secretaries of Commerce and Treasury will identify incentives that can be given to encourage participation under current law and to suggest new legislation to further enhance those incentives.

In addition to those carrots there are at least two sticks included in this draft EO that will be used to encourage participation. The gentlest is the provision requiring Sector Specific Agencies to report annually “on the extent to which owners and operators notified under section 9 [the ‘at greatest risk’ list, see above] of this order are participating in the Program” {§8(c)}. Presumably there could be some Presidential arm twisting as a result.

The potentially more serious stick is regulatory action. Section 10 requires Federal agencies (but not independent regulatory agencies, they are not under the direction of the President) responsible for regulating the security of critical infrastructure to review the Cybersecurity Framework and determine if they have “clear regulatory authority to establish requirements based upon the Cybersecurity Framework” {§10(a)} and identify any additional authority needed. Agencies would then have 60-days to “propose prioritized, risk-based, efficient, and coordinated actions” {§10(b)} to mitigate cyber-risk consistent with the Cybersecurity Framework.

The CFATS program, for instance, should have no legal problem adding the Cybersecurity Framework to its regulatory scheme as long as the requirements were risk-based performance standards and not specific security requirements.

Moving Forward


Now all of the above is predicated on the ‘fact’ that this ‘draft EO’ is legitimately a working draft. Even if it is, we have no idea of what changes might be made to it before it is published in its final form. Realistically, we’ll just have to wait and see what comes out of the Oval Office.

Wednesday, November 14, 2012

Reid Kills Cybersecurity Bill


This afternoon Sen. Reid (D,NV) effectively killed the Senate’s cybersecurity bill, S 3414, daring the Republicans to vote down a take it or leave it option on a cloture vote. Allowing no attempt for the Republicans to offer any amendments to the bill, Reid insured that he would not get the necessary votes to stop debate, ending with a nearly party-line vote of 51-47 (four Republicans voting Aye and four Democrats voting No). This was a purely political move since Reid knew that the bill would never pass in the House.

We will now see if Reid has any interest in actually allowing the consideration of cybersecurity legislation, no matter how meaningless. As I mentioned in an earlier post, there are three house bills (okay, just three cybersecurity bills) that are waiting for Senate action. If Reid wants to pass a symbolic cybersecurity vote two of those bills (probably not CISPA) would fill the bill. But, I would bet that none of these three bills will see the light of day.

Now we just have to wait for the President’s executive order; the justification has been established.

Sunday, October 14, 2012

S 3414 May Still Be Alive - Cybersecurity


Two different news organizations (TheHill.com and RollCall.com) are reporting that Sen. Reid (D,NV) is planning on bringing cybersecurity legislation back to the floor of the Senate when the body returns for their lame-duck session after the election. As I noted in August, Reid can call for reconsideration of the cloture vote on the bill at any time that he feels that he has the votes.

Legislation vs Executive Order


Both articles tie the Reed statement to the recent speech by the Secretary of Defense warning of a cyber Pearl Harbor attack. That statement follows recent news reports that the Administration was consulting with Congress and the business community on possible provisions for an executive order on cybersecurity for critical infrastructure. It seems likely that all of these events are tied together in a plan to provide the government the authority to regulate cybersecurity.

The politics of cybersecurity legislation are complicated. First, the regulatory authority that the Administration claims is necessary to protect this country against cyber-attacks by nation-states, terrorists, or even criminal organizations can only be provided by legislation. An executive order would provide only limited authority to expand regulations in only a few industrial sectors; other sector regulations would have to be based upon voluntary compliance.

Election Calculus


Cybersecurity legislation is clearly not a presidential election issue; neither side has made any attempt to make significant political capital taking a stand on the issue. President Obama is hardly likely to publish an executive order before the election for fear of offending some of his ‘civil liberties’ supporters who object to information sharing provisions supported by the Administration.

The Administration has a slim majority of support in the Senate for S 3414, but not enough as currently crafted to be able to get past a cloture vote. An agreement on allowing votes on some key amendments may change enough votes may provide a 60 vote margin to bring the bill to a vote; a vote that would probably lead to passage of the bill in the Senate. Passage of the bill in the House, as currently written, is almost impossible; the House cybersecurity legislation religiously avoids regulating industry beyond enabling some limited information sharing provisions that require nothing of industry.

The election next month may change the calculus in both bodies of Congress. If Democrats get closer to a supermajority (a clear supermajority does not currently seem to be a possibility) in the Senate, current opposition to S 3414 may be reduced by some departing members wishing to have at least some influence on cybersecurity legislation. If the Republicans, on the other hand gain seats (especially if they break the 50 vote barrier) in the election, the Democrats will have to surrender a lot of their desires to get S 3414 passed. The agreement would have to be for more than just votes on amendments; some of the mandatory provisions would have to be changed to voluntary. Which provisions would have to be changed would depend on the number of new Republicans reporting in January and which Democrats won’t return.

The House is much more complicated. Just about the only thing that will cause a wholesale change in the approach of the Republican leadership is if they lose control of the House in the election. Any other election outcome ensures that the current leadership will at the very least have a veto power over any cybersecurity legislation that heads towards the President. Any lame-duck Senate bill will have to take this into account.

Executive Order


Any effective executive order by President Obama will have to be proceeded by an election win. A President Romney would simply sign an executive order vacating one issued by Obama long before any effective action could be taken under such an order.

An Obama win would still not ensure that an executive order would have much of an effect on cybersecurity. To be effective the administration has to write regulations that have to go through the publish and comment process. This Administration has a poor record of writing regulations, particularly in the homeland security realm. A two-year old executive order harmonizing controlled unclassified information (CUI;  Executive Order 13556) has yet to produce any regulations changing the handling of such information. That regulation would only really affect executive branch politics, not business operations; that should make it an easier sell politically.

The Administration would also have to take into consideration that any regulations that have a substantial effect on business operations would certainly face litigation on the grounds of overstepping federal authority. Even just increasing cybersecurity controls over already regulated industries would certainly face such law suits. Extending such regulations to currently unregulated industries would be a non-starter just because of the threat of law suits. It has been made clear that even information sharing rules are likely to be opposed on privacy and free speech grounds.

Way Forward


There is a possibility that the Obama Administration could craft, with the help of the Republican leadership in the House a minimalist cybersecurity bill modeled on the House passed HR 2096. The House might acquiesce to limited cybersecurity regulations on the electric industry; the one industry that almost everyone has been mentioning as being at risk (shows how ‘everyone’s’ imagination is so limited). If they can get the House Republicans onboard, then they can probably convince the Senate.

One thing that all of the politicians have just about missed in their discussions is that there is a significant difference between IT and ICS cybersecurity. Any bill that really tries to address critical infrastructure cybersecurity must clearly differentiate between the two and write specific requirements for both types of security programs.

Tuesday, September 18, 2012

And Another Thing About OIP


Joel Langill made an important point last week in a TWEET about my original OIP personnel problem post. He said that these problems were “not good in light of potential exec order!” Since NPPD would presumably be the DHS agency that would be responsible for any program set forth in a cybersecurity executive order, these problems might be expected to crop up in the responsible agency. We certainly don’t want the cybersecurity jobs to be “given to those in favor with senior IP leadership without regard to process or to qualifications”.

So, Secretary Napolitano, please tell us that the DHS agency given responsibility for carrying out the President’s CSEO will be staffed by professionals that will be chosen based upon their experience and ability not on who they know. And don’t say ‘of course’, your agency does not have a real good track record.

Tuesday, August 7, 2012

Cybersecurity Moving Forward at the Pace of Politics


As everyone in the cybersecurity industry surely knows, the Senate last week failed to limit debate on S 3414, the Cybersecurity Act of 2012. While most pundits have commented that this kills the bill for this year (and this Congress), that is not technically correct. Sen. Reid (D,NV), after having voted against cloture was able to offer a motion to reconsider the cloture vote. That means that after the Senate reconvenes on September 10th, the cloture vote could be called again.

Consideration of the Bill Still Possible


There are numerous reports that negotiation are still underway on which amendments would be considered on the bill if a subsequent cloture vote were to succeed. There is a remote possibility that some sort of agreement could be reached that would allow for consideration of the bill either before the election or in the lame duck session after the election.

The compromise version of the bill would have to severely reduce the already limited regulatory provisions of the bill before it could stand any chance of coming to the floor of the House for subsequent approval. It would seem that there are little prospects of the bill passing.

The Possibility of an Executive Order


An interesting development occurred over the weekend with the suggestion that President Obama might issue, before the election, an executive order on cybersecurity. Such an order could put into place many of the provisions of S 3414 without Congressional action. One of the more interesting pieces on this possibility can be found over on the Volokh Conspiracy blog. Stewart Baker does a good job at looking at what could be done in cybersecurity with such an executive order.

More importantly he makes an interesting political point:

“An executive order would also advance a story line that has the President robustly protecting national security while a do-nothing Congress dithers.”

If an executive order were broadly and non-specifically crafted it might sway some of the non-committed, moderate voters who are fed up with the grid lock in Congress. In some swing states this could be enough to change the outcome of the election. It would still be a fine balancing act, however, as any information sharing provisions of such an order would be seen by many members of the President’s base as an attack on civil liberties. While this wouldn’t convince any of them to vote for Romney, it could cause a significant number to sit out the election; potentially throwing swing states into the Romney column.

I would suspect that there are White House staffers hard at work on carefully crafting an executive order directing DHS to take some cybersecurity actions. At the same time the Obama campaign would be hard at work trying to figure out the political consequences of such an order. If one were to be published I would expect it to be done in early October. In the meantime political surrogates on both sides will be discussing the issue; prepping the ground for an October surprise and its response.

Implementing an Executive Order


An executive order takes time to craft; it is after all is said and done a political document as much as it is a legal document. In this case, not only would it have to withstand the scrutiny of a political campaign, but President Obama would be writing it with a President Romney in mind. An executive order can be vacated as easily as it is written, so it would be written to withstand the review of the next administration.

More importantly, the regulations that would implement that executive order would have to go through the standard publish, public-comment, and revise processes that regulations based upon legislation would have to go through. Given the time that it takes to write and internally review regulations, there is no way that the first NPRM based upon an executive order published next month would be ready for OMB review before January 1st. Given the slow pace that we have seen over the last decade in crafting controversial regulations it would be likely sometime in 2016 before we saw any effective regulations coming out of a cybersecurity executive order.
 
/* Use this with templates/template-twocol.html */