
TIA cautions against cybersecurity mandates
The Telecommunications Industry Association released a white paper on
Tuesday that urges Congress to avoid enacting new cybersecurity mandates and
focus its attention towards improving information sharing about
cyberattacks instead.
The release of the white paper comes as the Senate is teed up to move to
Sen. Joe Lieberman's (I-Conn.) cybersecurity bill later this week. TIA
argues in the white paper that regulations would turn companies'
focus from securing their computer systems to complying with new rules, and would also become quickly outdated with the increasing
sophistication of malicious viruses and other cyberthreats. It encouraged Congress to support voluntary cybersecurity frameworks.
"The primary concern is that imposing rigid regulatory requirements that
by their nature will be unable to keep up with rapidly evolving
technologies will require industry to focus on meeting obsolete security
requirements rather than the actual threat at hand, which will in
effect make critical infrastructures and the customers that they serve
less secure," the white paper says.
"The success of critical infrastructure owners and operators in
repelling increasingly sophisticated attacks has resulted from the
voluntary, public-private model – a model capable of evolving along with
changes to the critical infrastructure and the risk environment," the
paper continues.
That argument against new security mandates has also been voiced by the U.S.
Chamber of Commerce and could provide fodder for those looking to fight
against sections of Lieberman's bill that are viewed as too regulatory.
Lieberman and four other co-sponsors introduced a
revised version of his bill last week that softened provisions dealing with critical
infrastructure. It proposed to establish a program where companies operating
critical infrastructure could certify that their computer systems meet
certain cybersecurity standards in exchange for incentives. The changes
were made to mollify concerns voiced by Republicans and business groups
about the bill being too regulatory.
The five co-sponsors are hosting a press conference on Tuesday afternoon
to describe the changes made to the latest version of the cybersecurity
bill.
Danielle Coffey, TIA's vice president for government affairs, said the
trade group is still reviewing the latest version of Lieberman's bill
but noted it made "real progress" from the original one introduced
earlier this year. However, she added TIA is still weighing whether the
critical infrastructure provisions are "truly voluntary measures."
"If it's benchmarks and goal posts they want us to reach, and [also
create] a structure where regulations may or may not be imposed, that
leaves a lot open for the government to come up with regulations and
mandates in the future, even if it's not the intention of this Congress
to impose them right now," said Coffey.
In the white paper, TIA argues that improving information sharing about
cyberthreats between the government and industry would help critical
infrastructure operators immediately address bad code or other malicious
threats spotted on their computer systems. The white paper noted that
information sharing needs to happen in real-time and also voiced support
for the House's Cyber Intelligence Sharing and Protection Act.
Lieberman, Sen. Susan Collins (R-Maine) and the other sponsors of the
cybersecurity bill have argued over the past year that information
sharing isn't enough to combat the growing cyberthreat the nation faces
and standards for critical infrastructure also need to be a part of the legislative
solution. The senators have pointed to statements made by Gen. Keith
Alexander, head of U.S. Cyber Command, and former National Security
Agency Director Michael Hayden about how legislation should include some sort
of cybersecurity standards for critical infrastructure in addition to
information sharing measures.
Among the six policy recommendations listed in the report, TIA argues
for increased funding for cybersecurity research and development and
support of industry-developed cybersecurity best practices. It also
warns against the introduction of supply chain rules that would restrict
telecommunications equipment from being imported into the United
States, noting that the nation's "global economic competitiveness could
be severely affected by other export markets adopting similar
restrictive policies."
TIA's member companies include Qualcomm, Raytheon, Apple and Cisco.







Most Viewed RSS Feed »
