Risk
12/2/2011
12:42 PM
50%
50%

Bill Would Open Channels On Cyber Threats

Proposed legislation encourages the feds and private companies to share cyberintelligence information to stop threats to networks and critical infrastructure.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
House members have introduced new legislation that would promote information sharing between the government and private companies on matters of cybersecurity.

The Cyber Intelligence Sharing and Protection Act, introduced Wednesday by Reps. Mike Rogers and Dutch Ruppersberger of the House Permanent Select Committee on Intelligence--chairman and a ranking member of the committee, respectively--allows the feds to share intelligence information with companies to help them prevent cyber attacks before they happen.

The bill also allows for "approved businesses" to share cyber threat information among themselves and also with the government, according to a statement.

The bill would go "a long way in helping American businesses better protect their networks and their intellectual property," Rogers said in the statement.

"There are two types of companies in this country, those who know they've been hacked, and those who don't know they've been hacked," he said. "Economic predators, including nation-states, are blatantly stealing business secrets and innovation from private companies."

[ The Defense Department tests its networks to protect against cyber attack. Learn more: U.S. Cyber Command Practices Defense In Mock Attack. ]

The bill is a "good start" to helping lock down U.S. intellectual property and critical infrastructure such as the power grid and banking systems, Ruppersberger added.

While the feds has been sharing cyber-threat information with the private sector through a Department of Homeland Security program, the bill would expand and formalize this type of intelligence sharing among the government and private companies.

The bill would require the Director of National Intelligence to set up procedures for sharing cyber-threat intelligence with the private sector, ensuring those that receive the information have the proper security clearance.

It also allows private sector entities to share information anonymously or restrict who they share with, including the government. Congress has been considering a number of cybersecurity bills, but so far has not passed definitive, sweeping legislation in this area.

The Obama administration has taken strides to partner with the private sector particularly on matters of cybersecurity and sharing information. DHS fusion centers around the country routinely share information with local and state authorities, as well as some companies, about cyber threats.

Thursday, President Obama proclaimed December Critical Infrastructure Protection Month, highlighting and promoting efforts the feds are taking to partner with the private sector to share cybersecurity information.

Our annual Federal Government IT Priorities Survey shows how agencies are managing the many mandates competing for their limited resources. Also in the new issue of InformationWeek Government: NASA veterans launch cloud startups, and U.S. Marshals Service completes tech revamp. Download the issue now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
12/5/2011 | 9:13:57 PM
re: Bill Would Open Channels On Cyber Threats
This is a good step. I'd be happy to see a lot more disclosure about threats and known attacks among companies but any move towards information sharing is a good one.

Jim Rapoza is an InformationWeek Contributing Editor
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/2/2011 | 10:28:32 PM
re: Bill Would Open Channels On Cyber Threats
Nothing wrong with sharing information to improve security.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5208
Published: 2014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbit...

CVE-2014-7286
Published: 2014-12-22
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.

CVE-2014-8896
Published: 2014-12-22
The Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 allows remote authenticated users to modify ...

CVE-2014-8897
Published: 2014-12-22
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 ...

CVE-2014-8898
Published: 2014-12-22
Cross-site scripting (XSS) vulnerability in the Collaboration Server in IBM InfoSphere Master Data Management Server for Product Information Management 9.x through 9.1 and InfoSphere Master Data Management - Collaborative Edition 10.x through 10.1, 11.0 before FP7, and 11.3 and 11.4 before 11.4 FP1 ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.