Industry wary of House-passed cyber bills

WASHINGTON, DC – APRIL 9: Committee chairman U.S. Rep. Michael McCaul (R-TX) delivers his opening remarks during a House Homeland Security Committee hearing entitled ‘The Boston Marathon Bombings, One Year On: A Look Back to Look Forward,’ on Capitol Hill, April 9, 2014 in Washington, DC. The first anniversary will be of the Boston Marathon bombings is April 15, whicj killed three people were and injured hundreds. (Photo by Drew Angerer/Getty Images)

More: Obama announces threat info-sharing executive order

First, the House passed the Protecting Cyber Networks Act on Wednesday, which sets up a framework for sharing threat information, including strict guidelines on how that information can be used and restrictions on surveillance activities.

The bill — crafted by the Permanent Select Committee on Intelligence — passed by a wide margin, 301-116.

Then, on Thursday, they passed the House Committee on Homeland Security’s National Cybersecurity Protection Advancement (NCPA) Act by a vote of 355-63.

“Removing the legal barriers for the voluntary sharing of cyber threats will help keep malicious nation states and cyber criminals out of our vital digital networks,” said Rep. Michael McCaul, R-Texas, chairman of the Homeland Security Committee. “I look forward to moving this landmark bill over to the Senate and getting it to the president’s desk as quickly as possible.”

More: Obama offers new legislative agenda on cybersecurity

Both bills were forwarded on to the Senate for consideration, though the upper chamber is expected to vote on one of its own proposals — most likely the Cybersecurity Information Sharing Act (CISA) sponsored by Sen. Richard Burr, R-N.C. When that vote will take place is very much up in the air.

Despite provisions included in all three bills, privacy advocates remain staunchly against the idea, claiming it will be used as another tool for government surveillance.

More: New cyber center to coordinate threat intelligence

The bills’ proponents say they have taken these concerns into account.

“I am pleased that this bill includes key provisions to protect consumer’s privacy and personal identifiable information,” Rep. Cedric Richmond, D-La., ranking member of the Homeland Security Cybersecurity, Infrastructure Protection and Security Technologies Subcommittee, said of NCPA. “It requires corporations — and the Department of Homeland Security — to scrub irrelevant personal information from the data they share.”

Similarly, clauses in the Protecting Cyber Networks Act also restrict federal agencies and companies from using the information they collect or disseminating it for purposes other than cybersecurity.

While simply having these issues spelled out in the legislation might not be enough to quell privacy fears, the bills might have a tougher barrier to overcome: getting industry to participate.

More: NIST weighs pros and cons of cyberattack data-sharing

A survey of cybersecurity professionals conducted by Bromium showed some 78 percent believed their company would benefit from sharing information about cyber threats but only 48 percent said their company would actually participate.

“There is clearly a disconnect in these results,” Bromium analysts said of the findings, “which suggest that information security professionals are concerned about how information sharing initiatives will aggregate and anonymize their organization’s data.”

It’s possible a Senate or conference bill could assuage these concerns but none of the current proposals have been able to garner support from all sectors.

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.