Technology Sectors

Market Sectors

Executive Order on cyber security coming, might include information sharing

White House meeting

As Congress recesses for the national election, the White House is close to issuing an Executive Order on Cyber security in the coming days that could include information-sharing measures for infrastructure providers, according to reports.

Before Congress adjourned for what is expected to be a seven-week long break for the November election, it failed to approve cyber security legislation amid partisan squabbling. Some congressmen who had backed cyber legislation urged President Obama to develop protections including information-sharing procedures with private industry to blunt the threat.

Reports said the president is about to issue an Executive Order directing federal agencies to develop voluntary Cyber security guidelines for critical infrastructure owners, such as power and water companies.

A Sept. 24 report by Reuters quoted former government Cyber security sources saying the pending order would give government agencies 90 days to propose new regulations and create a new Cyber security council at the Department of Homeland Security with representatives from the Defense Department, Justice Department, Director of National Intelligence and the Department of Commerce.

One congressman who had pushed unsuccessfully for Cyber security legislation, Senate Homeland Security and Governmental Affairs Committee chairman Joe Lieberman. (ID-CT), urged the president in a Sept. 24 letter “to use the full extent of his executive powers” to secure the nation’s cyber networks, by conducting risk assessments of the most critical cyber infrastructure and establishing security standards.

In his letter, Lieberman called the Cyber threat to the U.S. “real and imminent.”

“Now that Congress has recessed until after the elections, I am writing to you about the continuing failure of the Senate to pass comprehensive Cyber security legislation.  Countless national security leaders from your administration and the previous administration have made clear that the threat from cyber attack is similar to the threat we faced from terrorism on September 10, 2001 – the danger is real and imminent, yet we have not acted to defend against it.”

Lieberman said Obama should use his executive authority to the maximum extent possible to defend the nation from cyber attack.  “For example, under current law, as set forth in Title II of the Homeland Security Act of 2002, the Department of Homeland Security has clear authority, if directed by you, to conduct risk assessments of critical infrastructure, identify those systems or assets that are most vulnerable to cyber attack, and issue voluntary standards for those critical systems or assets to maintain adequate Cyber security,” he said. 

“Though executive action cannot offer private sector entities liability protections for compliance with these guidelines, I urge you to consider other incentives that you can offer by executive action to companies that own critical cyber infrastructure and decide to comply with the cyber defense standards that result from your Executive Order,” he said.

 I urge you to explore any means at your disposal that would encourage regulators to make mandatory the standards developed by the Department of Homeland Security pursuant to your Executive Order so we can guarantee that our most critical infrastructure will be defended against attacks from our adversaries.  

Additionally, Lieberman asked Obama to consider using his authority to strengthen information sharing mechanisms to the fullest extent possible under current law.

 Lieberman noted, however that the executive action can’t make all the changes necessary to facilitate the type of information sharing that he said is urgently needed – but only new statutory authorization will be sufficient. 

 

Upcoming Events

Event Details Dates of Event
Critical Security Controls International Summit 2013 Apr 26 - May 2
Secure India @Bangalore 2013 Apr 29 - May 4
Cloud Security Alliance CCSK Certification Training May 6 - 7
SANS Security West 2013 May 9 - 19
SANS Brisbane 2013 May 13 - 18
GovSec Conference & Expo May 14 - 15
CPM East Conference & Expo May 14 - 15
TREXPO - The Law Enforcement Expo May 14 - 15
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
ISSA-LA Fifth Annual Information Security Summit May 21 - 21
Southwest Microwave Seminar May 21 - 21
Southwest Microwave Seminar May 21 - 21
Southwest Microwave Perimeter Defense Seminar May 21 - 21
Southwest Microwave Seminar May 22 - 22
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18