Risk
3/24/2010
12:46 PM
50%
50%

Cybersecurity Bill Passes Senate Committee

Senators supporting the legislation, aimed at protecting the U.S. from cyberattacks, stress the need to enact it as soon as possible.

A crucial piece of cybersecurity legislation is one step closer to becoming law after being approved during a Commerce, Science & Transportation Committee hearing Wednesday.

The Cybersecurity Act, S. 773, aimed at protecting critical U.S. network infrastructure against cybersecurity threats by fostering collaboration between the federal government and the private sector firms that maintain that infrastructure, is now on its way to the Senate floor.

The bill, co-sponsored by committee Chairman Sen. Jay Rockefeller (D-W.Va.) and Sen. Olympia Snowe (R-Maine), was introduced last April and then re-introduced last week with some key changes. Notably, it no longer gives the president unilateral power to disconnect networks from the Internet in the event of a major cyberattack.

The bill also includes amendments for how the president and private sector can work together to help secure critical infrastructure.

During the hearing, senators expressed how important it is that the Senate passes the legislation quickly, as it's long overdue.

Sen. Rockefeller called the fact that the bill still hasn't been passed like "starting in kindergarten," as both President Obama and former President George W. Bush both called for comprehensive cybersecurity legislation.

"The government hasn't gotten its act together; the private sector has had problems getting its act together," he said. "It's extraordinary and very discouraging."

Co-sponsor Sen. Snowe weighed in as well, noting the "gravity" of the threat and stressing how much effort went in to developing a bill that "goes to great lengths" to bring the public and private sectors together to mitigate the threat.

"I hope we get broad support for this legislation," she said.

Noting that the bill gives various government departments a year to implement cybersecurity policy, Sen. Bill Nelson (D-Florida) said that might even be too much time in light of potential cyber threats.

"We'd better get it done before a year because our enemies are out there," he said.

The Cybersecurity Act calls for a revision of cybersecurity processes and oversight in government, the facilitation of public-private partnerships on keeping computer systems safe, the funding of cybersecurity research, and the hiring of more cybersecurity specialists.

Companion legislation that would create the national cybersecurity adviser position -- the National Cybersecurity Advisor Act, S.778 -- is still pending before the Senate Committee on Homeland Security and Government Affairs.

The House last month passed its own cybersecurity bill, the Cybersecurity Enhancement Act of 2009 (HR 4061), first introduced by Rep. Daniel Lipinski (D-IL) last year. That bill funds research and development for a comprehensive cybersecurity plan that would involve the cooperation of several federal agencies.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.