Modern field guide to security and privacy

New US cybersecurity standards: Will they do enough?

The Obama administration has unveiled the nation's first cybersecurity standards to protect critical infrastructure. The voluntary standards – which met with some criticism – are an attempt to address US vulnerabilities to cyberattack.

|
AP Photo/Kathy Kmonicek, File
In this file photo, utility workers repair power lines damaged by Superstorm Sandy. Criticism greeted the White House's release of new cybersecurity standards Wenesday. The voluntary guidelines are intended to protect critical infrastructure.

The Obama administration on Wednesday unveiled America’s first-ever cybersecurity standards aimed at helping businesses protect the critical infrastructure they own – to a huge chorus of complaints.

Not enough privacy protections built into the standards, privacy groups complained. Not enough incentives to actually induce companies to use these voluntary standards, security wonks moaned. Not enough backbone to ensure that critical infrastructure – like the power grid – is really safe, others said.

“Inevitably you’re going to have people unhappy with the process because it was a voluntary system with so many factors being considered from a high level,” says Jessica Herrera-Flanigan, a cyberpolicy expert at the Monument Policy Group consultancy. “Is it helpful, yes.... Will it solve all of our cybersecurity problems, probably not. We now need companies to go through and figure out how to implement the concepts in it. This is just the beginning.”

The unveiling of the cyber framework, developed by the National Institute of Standards, comes after the White House tried, and failed, to get tough cybersecurity legislation through Congress last year. Though the executive order issued Feb. 12 cannot compel private companies that own the power grid, for instance, to comply – only legislation can do that – the voluntary standards are an attempt at least to do what is possible to address US vulnerabilities to cyberattack.

At its core, the framework is a set of best practices, standards, and guidelines intended to help organize the way firms think about cyberrisks, benchmark their progress, and improve their overall preparedness, administration officials said.

The framework also aims to increase timely sharing of threat information, digital signatures, and reports between the Department of Homeland Security (DHS) and willing companies, including the issuance of security clearances to critical infrastructure operators.

It also will expand a Department of Defense Enhanced Cybersecurity Initiative that shares threat and protection information with defense contractors to include key infrastructure companies.

Moreover, it adds a new Critical Infrastructure Partnership Advisory Council in which DHS would help orchestrate cybersecurity upgrades for critical infrastructure. DHS would work with specific federal agencies to persuade companies to become involved and upgrade their systems.

Despite acknowledging it as a first step, the administration touted the standards, saying that it had acted where Congress had not for two years – and that the standards at least get the ball rolling on securing the cybersystems that undergird US systems for food, water, transportation, finance, and energy production, to name a few.

“While I believe today’s Framework marks a turning point, it’s clear that much more work needs to be done to enhance our cybersecurity,” President Obama said in a statement Wednesday. “Our critical infrastructure continues to be at risk from threats in cyberspace, and our economy is harmed by the theft of our intellectual property.... I again urge Congress to move forward on cybersecurity legislation that both protects our nation and our privacy and civil liberties.”

But the order largely fell short of many experts’ expectations for what could be done, even voluntarily.

Greg Nojeim, a privacy advocate at the Center for Democracy and Technology, in a statement called the voluntary cybersecurity framework “useful guideposts for companies who want to better secure their data." But privacy measures in the standards were “watered down,” and it’s unlikely that violations could be measured under the new yardstick, he noted.

Still, some companies were positive about the voluntary measures.

“We believe the NIST cyber security framework provides a workable approach to protecting our bulk transmission system and are pleased to have been part of the development effort,” said Bennett Gaines, senior vice president of corporate services and chief information officer at FirstEnergy, an Ohio-based electric utility with about 6 million customers across Ohio, Pennsylvania, and New Jersey.

Administration officials were upbeat, saying the measures could go a long way even using mild incentives such as publicly recognizing companies that had met the standards. Lower insurance costs could result, they said.

“We face an adversary that is faster than we are,” Phyllis Schneck, deputy undersecretary for cybersecurity for the National Protection and Programs Directorate (NPPD) at DHS, told an audience of policy experts at a cybersecurity conference hosted by the Center for National Policy and the Monitor on Wednesday.

“The way we counter an adversary like that is to make their profit model harder. And the way we do that is to make our infrastructure more secure,” she said. "This framework is a huge vehicle to enable companies, to give them a formula almost that they can adopt to their own use.”

True, but spreading the gospel of cybersecurity to all corners of private industry – which owns about 85 percent of it – will require that they see useful results that start in the federal government itself, some at the cybersecurity conference said.

“On the positive side, they did adopt a model that includes detection, response, and resolution,” says Richard Bejtlich, chief security strategist for FireEye, a Silicon Valley computer security firm. “On the bad side, I would prefer to see more action by the federal government in securing their own networks to set an example for how it should be done. That hasn’t happened yet.”

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
What is the Monitor difference? Tackling the tough headlines – with humanity. Listening to sources – with respect. Seeing the story that others are missing by reporting what so often gets overlooked: the values that connect us. That’s Monitor reporting – news that changes how you see the world.

Dear Reader,

About a year ago, I happened upon this statement about the Monitor in the Harvard Business Review – under the charming heading of “do things that don’t interest you”:

“Many things that end up” being meaningful, writes social scientist Joseph Grenny, “have come from conference workshops, articles, or online videos that began as a chore and ended with an insight. My work in Kenya, for example, was heavily influenced by a Christian Science Monitor article I had forced myself to read 10 years earlier. Sometimes, we call things ‘boring’ simply because they lie outside the box we are currently in.”

If you were to come up with a punchline to a joke about the Monitor, that would probably be it. We’re seen as being global, fair, insightful, and perhaps a bit too earnest. We’re the bran muffin of journalism.

But you know what? We change lives. And I’m going to argue that we change lives precisely because we force open that too-small box that most human beings think they live in.

The Monitor is a peculiar little publication that’s hard for the world to figure out. We’re run by a church, but we’re not only for church members and we’re not about converting people. We’re known as being fair even as the world becomes as polarized as at any time since the newspaper’s founding in 1908.

We have a mission beyond circulation, we want to bridge divides. We’re about kicking down the door of thought everywhere and saying, “You are bigger and more capable than you realize. And we can prove it.”

If you’re looking for bran muffin journalism, you can subscribe to the Monitor for $15. You’ll get the Monitor Weekly magazine, the Monitor Daily email, and unlimited access to CSMonitor.com.

QR Code to New US cybersecurity standards: Will they do enough?
Read this article in
https://www.csmonitor.com/World/Passcode/2014/0212/New-US-cybersecurity-standards-Will-they-do-enough
QR Code to Subscription page
Start your subscription today
https://www.csmonitor.com/subscribe