Risk
3/24/2010
12:46 PM
50%
50%

Cybersecurity Bill Passes Senate Committee

Senators supporting the legislation, aimed at protecting the U.S. from cyberattacks, stress the need to enact it as soon as possible.

A crucial piece of cybersecurity legislation is one step closer to becoming law after being approved during a Commerce, Science & Transportation Committee hearing Wednesday.

The Cybersecurity Act, S. 773, aimed at protecting critical U.S. network infrastructure against cybersecurity threats by fostering collaboration between the federal government and the private sector firms that maintain that infrastructure, is now on its way to the Senate floor.

The bill, co-sponsored by committee Chairman Sen. Jay Rockefeller (D-W.Va.) and Sen. Olympia Snowe (R-Maine), was introduced last April and then re-introduced last week with some key changes. Notably, it no longer gives the president unilateral power to disconnect networks from the Internet in the event of a major cyberattack.

The bill also includes amendments for how the president and private sector can work together to help secure critical infrastructure.

During the hearing, senators expressed how important it is that the Senate passes the legislation quickly, as it's long overdue.

Sen. Rockefeller called the fact that the bill still hasn't been passed like "starting in kindergarten," as both President Obama and former President George W. Bush both called for comprehensive cybersecurity legislation.

"The government hasn't gotten its act together; the private sector has had problems getting its act together," he said. "It's extraordinary and very discouraging."

Co-sponsor Sen. Snowe weighed in as well, noting the "gravity" of the threat and stressing how much effort went in to developing a bill that "goes to great lengths" to bring the public and private sectors together to mitigate the threat.

"I hope we get broad support for this legislation," she said.

Noting that the bill gives various government departments a year to implement cybersecurity policy, Sen. Bill Nelson (D-Florida) said that might even be too much time in light of potential cyber threats.

"We'd better get it done before a year because our enemies are out there," he said.

The Cybersecurity Act calls for a revision of cybersecurity processes and oversight in government, the facilitation of public-private partnerships on keeping computer systems safe, the funding of cybersecurity research, and the hiring of more cybersecurity specialists.

Companion legislation that would create the national cybersecurity adviser position -- the National Cybersecurity Advisor Act, S.778 -- is still pending before the Senate Committee on Homeland Security and Government Affairs.

The House last month passed its own cybersecurity bill, the Cybersecurity Enhancement Act of 2009 (HR 4061), first introduced by Rep. Daniel Lipinski (D-IL) last year. That bill funds research and development for a comprehensive cybersecurity plan that would involve the cooperation of several federal agencies.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.