Risk
12/2/2011
12:42 PM
Connect Directly
RSS
E-Mail
50%
50%

Bill Would Open Channels On Cyber Threats

Proposed legislation encourages the feds and private companies to share cyberintelligence information to stop threats to networks and critical infrastructure.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
House members have introduced new legislation that would promote information sharing between the government and private companies on matters of cybersecurity.

The Cyber Intelligence Sharing and Protection Act, introduced Wednesday by Reps. Mike Rogers and Dutch Ruppersberger of the House Permanent Select Committee on Intelligence--chairman and a ranking member of the committee, respectively--allows the feds to share intelligence information with companies to help them prevent cyber attacks before they happen.

The bill also allows for "approved businesses" to share cyber threat information among themselves and also with the government, according to a statement.

The bill would go "a long way in helping American businesses better protect their networks and their intellectual property," Rogers said in the statement.

"There are two types of companies in this country, those who know they've been hacked, and those who don't know they've been hacked," he said. "Economic predators, including nation-states, are blatantly stealing business secrets and innovation from private companies."

[ The Defense Department tests its networks to protect against cyber attack. Learn more: U.S. Cyber Command Practices Defense In Mock Attack. ]

The bill is a "good start" to helping lock down U.S. intellectual property and critical infrastructure such as the power grid and banking systems, Ruppersberger added.

While the feds has been sharing cyber-threat information with the private sector through a Department of Homeland Security program, the bill would expand and formalize this type of intelligence sharing among the government and private companies.

The bill would require the Director of National Intelligence to set up procedures for sharing cyber-threat intelligence with the private sector, ensuring those that receive the information have the proper security clearance.

It also allows private sector entities to share information anonymously or restrict who they share with, including the government. Congress has been considering a number of cybersecurity bills, but so far has not passed definitive, sweeping legislation in this area.

The Obama administration has taken strides to partner with the private sector particularly on matters of cybersecurity and sharing information. DHS fusion centers around the country routinely share information with local and state authorities, as well as some companies, about cyber threats.

Thursday, President Obama proclaimed December Critical Infrastructure Protection Month, highlighting and promoting efforts the feds are taking to partner with the private sector to share cybersecurity information.

Our annual Federal Government IT Priorities Survey shows how agencies are managing the many mandates competing for their limited resources. Also in the new issue of InformationWeek Government: NASA veterans launch cloud startups, and U.S. Marshals Service completes tech revamp. Download the issue now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
12/5/2011 | 9:13:57 PM
re: Bill Would Open Channels On Cyber Threats
This is a good step. I'd be happy to see a lot more disclosure about threats and known attacks among companies but any move towards information sharing is a good one.

Jim Rapoza is an InformationWeek Contributing Editor
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/2/2011 | 10:28:32 PM
re: Bill Would Open Channels On Cyber Threats
Nothing wrong with sharing information to improve security.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1032
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf...

CVE-2012-1417
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

CVE-2012-1506
Published: 2014-09-17
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from th...

CVE-2012-1507
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index...

CVE-2012-2583
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

Best of the Web
Dark Reading Radio