Risk

12/2/2011
12:42 PM
50%
50%

Bill Would Open Channels On Cyber Threats

Proposed legislation encourages the feds and private companies to share cyberintelligence information to stop threats to networks and critical infrastructure.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
House members have introduced new legislation that would promote information sharing between the government and private companies on matters of cybersecurity.

The Cyber Intelligence Sharing and Protection Act, introduced Wednesday by Reps. Mike Rogers and Dutch Ruppersberger of the House Permanent Select Committee on Intelligence--chairman and a ranking member of the committee, respectively--allows the feds to share intelligence information with companies to help them prevent cyber attacks before they happen.

The bill also allows for "approved businesses" to share cyber threat information among themselves and also with the government, according to a statement.

The bill would go "a long way in helping American businesses better protect their networks and their intellectual property," Rogers said in the statement.

"There are two types of companies in this country, those who know they've been hacked, and those who don't know they've been hacked," he said. "Economic predators, including nation-states, are blatantly stealing business secrets and innovation from private companies."

[ The Defense Department tests its networks to protect against cyber attack. Learn more: U.S. Cyber Command Practices Defense In Mock Attack. ]

The bill is a "good start" to helping lock down U.S. intellectual property and critical infrastructure such as the power grid and banking systems, Ruppersberger added.

While the feds has been sharing cyber-threat information with the private sector through a Department of Homeland Security program, the bill would expand and formalize this type of intelligence sharing among the government and private companies.

The bill would require the Director of National Intelligence to set up procedures for sharing cyber-threat intelligence with the private sector, ensuring those that receive the information have the proper security clearance.

It also allows private sector entities to share information anonymously or restrict who they share with, including the government. Congress has been considering a number of cybersecurity bills, but so far has not passed definitive, sweeping legislation in this area.

The Obama administration has taken strides to partner with the private sector particularly on matters of cybersecurity and sharing information. DHS fusion centers around the country routinely share information with local and state authorities, as well as some companies, about cyber threats.

Thursday, President Obama proclaimed December Critical Infrastructure Protection Month, highlighting and promoting efforts the feds are taking to partner with the private sector to share cybersecurity information.

Our annual Federal Government IT Priorities Survey shows how agencies are managing the many mandates competing for their limited resources. Also in the new issue of InformationWeek Government: NASA veterans launch cloud startups, and U.S. Marshals Service completes tech revamp. Download the issue now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
12/5/2011 | 9:13:57 PM
re: Bill Would Open Channels On Cyber Threats
This is a good step. I'd be happy to see a lot more disclosure about threats and known attacks among companies but any move towards information sharing is a good one.

Jim Rapoza is an InformationWeek Contributing Editor
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/2/2011 | 10:28:32 PM
re: Bill Would Open Channels On Cyber Threats
Nothing wrong with sharing information to improve security.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7679
PUBLISHED: 2018-06-21
Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution.
CVE-2018-7680
PUBLISHED: 2018-06-21
Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values.
CVE-2018-7681
PUBLISHED: 2018-06-21
Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favorites" folder. If the user has certain administrative privileges then this vulnerability can impact other users in the system.
CVE-2018-7683
PUBLISHED: 2018-06-21
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
CVE-2018-12617
PUBLISHED: 2018-06-21
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a craf...