THE HILL
 
comment
Print

TIA cautions against cybersecurity mandates

By Jennifer Martinez - 07/24/12 12:01 AM ET

The Telecommunications Industry Association released a white paper on Tuesday that urges Congress to avoid enacting new cybersecurity mandates and focus its attention towards improving information sharing about cyberattacks instead.

The release of the white paper comes as the Senate is teed up to move to Sen. Joe Lieberman's (I-Conn.) cybersecurity bill later this week. TIA argues in the white paper that regulations would turn companies' focus from securing their computer systems to complying with new rules, and would also become quickly outdated with the increasing sophistication of malicious viruses and other cyberthreats. It encouraged Congress to support voluntary cybersecurity frameworks.

"The primary concern is that imposing rigid regulatory requirements that by their nature will be unable to keep up with rapidly evolving technologies will require industry to focus on meeting obsolete security requirements rather than the actual threat at hand, which will in effect make critical infrastructures and the customers that they serve less secure," the white paper says.

"The success of critical infrastructure owners and operators in repelling increasingly sophisticated attacks has resulted from the voluntary, public-private model – a model capable of evolving along with changes to the critical infrastructure and the risk environment," the paper continues.

That argument against new security mandates has also been voiced by the U.S. Chamber of Commerce and could provide fodder for those looking to fight against sections of Lieberman's bill that are viewed as too regulatory. 

Lieberman and four other co-sponsors introduced a revised version of his bill last week that softened provisions dealing with critical infrastructure. It proposed to establish a program where companies operating critical infrastructure could certify that their computer systems meet certain cybersecurity standards in exchange for incentives. The changes were made to mollify concerns voiced by Republicans and business groups about the bill being too regulatory.

The five co-sponsors are hosting a press conference on Tuesday afternoon to describe the changes made to the latest version of the cybersecurity bill.

Danielle Coffey, TIA's vice president for government affairs, said the trade group is still reviewing the latest version of Lieberman's bill but noted it made "real progress" from the original one introduced earlier this year. However, she added TIA is still weighing whether the critical infrastructure provisions are "truly voluntary measures."

"If it's benchmarks and goal posts they want us to reach, and [also create] a structure where regulations may or may not be imposed, that leaves a lot open for the government to come up with regulations and mandates in the future, even if it's not the intention of this Congress to impose them right now," said Coffey.

In the white paper, TIA argues that improving information sharing about cyberthreats between the government and industry would help critical infrastructure operators immediately address bad code or other malicious threats spotted on their computer systems. The white paper noted that information sharing needs to happen in real-time and also voiced support for the House's Cyber Intelligence Sharing and Protection Act.

Lieberman, Sen. Susan Collins (R-Maine) and the other sponsors of the cybersecurity bill have argued over the past year that information sharing isn't enough to combat the growing cyberthreat the nation faces and standards for critical infrastructure also need to be a part of the legislative solution. The senators have pointed to statements made by Gen. Keith Alexander, head of U.S. Cyber Command, and former National Security Agency Director Michael Hayden about how legislation should include some sort of cybersecurity standards for critical infrastructure in addition to information sharing measures.

Among the six policy recommendations listed in the report, TIA argues for increased funding for cybersecurity research and development and support of industry-developed cybersecurity best practices. It also warns against the introduction of supply chain rules that would restrict telecommunications equipment from being imported into the United States, noting that the nation's "global economic competitiveness could be severely affected by other export markets adopting similar restrictive policies."

TIA's member companies include Qualcomm, Raytheon, Apple and Cisco.



Source:
http://thehill.com/blogs/hillicon-valley/technology/239653-tia-cautions-against-cybersecurity-mandates
Phillip J. Bond’s ‘Tech Execs’ appears here on The Hill's Hillicon Valley Blog occasionally.

More Videos »

Hillicon Valley Twitter - Click to follow
More From The Web
bloglogo

More Briefing Room »

More Congress Blog »

More Pundits Blog »

More Twitter Room »

More Hillicon Valley »

More E2-Wire (Energy) »

More Ballot Box »

More On The Money »

More Healthwatch »

More Floor Action »

More Transportation »

More DEFCON Hill »

More Global Affairs »

More In The Know »

More RegWatch »

Get latest news from The Hill direct to your inbox, RSS reader and mobile devices.