THE HILL
 
comment
Print

Senate cybersecurity bill would let firms appeal Homeland Security regulations

By Gautham Nagesh - 02/13/12 04:48 PM ET

Critics say allowing DHS to determine requirements in consultation with the private sector could water down security provisions. 

The leadership of the Senate Homeland Security Committee will introduce a comprehensive cybersecurity bill on Tuesday that would allow firms to appeal whether new security regulations should apply to their sector.

The legislation would task the Department of Homeland Security with determining which sectors of the economy would be covered by new cybersecurity regulations, after risk assessments in consultation with the private sector, the intelligence community and others.

But designated sectors would have the right to appeal whether the regulations apply to them. Several groups representing portions of the private sector considered part of the critical infrastructure have expressed concern about the impact of the regulations on both security and the bottom line.

"Passing the bill is crucial for national security, but not if the provisions on critical infrastructure regulation are watered down. This will be a real test for this Congress," said James Lewis, senior fellow and director at the Center for Strategic and International Studies.

Examples of sectors considered likely to fall under the new regulations are utilities, water treatment plants and transportation providers. Some sectors, such as major financial institutions and telecom providers, may ask for exemptions based on a demonstrated ability to secure their systems.

After determining which firms are critical infrastructure, DHS would then, in consultation with the private sector, determine cybersecurity performance requirements for firms in the covered sectors.

"The performance requirements would cover only those systems and assets whose disruption could result in severe degradation of national security, catastrophic economic damage, or the interruption of life-sustaining services sufficient to cause mass casualties or mass evacuations," said a committee spokesman.

"The bill would only cover the most critical systems and assets in a given sector, and only if they are not already being appropriately secured. The focus is on the systems that are insecure not the ones that are doing well."

The question of enforcement has also been crucial to the debate, with firms fearing the impact of financial penalties or criminal liability for failing to secure their systems. The committee spokesman said the final penalties for firms that don't comply have yet to be determined.

"There would be a huge market incentive for designated sectors to meet the security standards. But if they don’t DHS and the AG would decide on penalties," said the spokesman.

Industry groups have argued the problem of cybersecurity is one of cost, so increasing incentives for firms to adopt better protections would be a more effective route. They have championed concurrent efforts in the House, which focus on encouraging information sharing more than new regulations.


Source:
http://thehill.com/blogs/hillicon-valley/technology/210349-senate-cybersecurity-bill-would-let-firms-appeal-regulations
Phillip J. Bond’s ‘Tech Execs’ appears here on The Hill's Hillicon Valley Blog occasionally.

More Videos »

Hillicon Valley Twitter - Click to follow
More From The Web
bloglogo

More Briefing Room »

More Congress Blog »

More Pundits Blog »

More Twitter Room »

More Hillicon Valley »

More E2-Wire (Energy) »

More Ballot Box »

More On The Money »

More Healthwatch »

More Floor Action »

More Transportation »

More DEFCON Hill »

More Global Affairs »

More In The Know »

More RegWatch »

Get latest news from The Hill direct to your inbox, RSS reader and mobile devices.