Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Cisco all but kills Cius tablet computer
Windows 8 Update: Steve Ballmer's 80-inch Windows 8 tablet
Gartner: Don't trust cloud provider to protect your corporate assets
Take me out to the ballgame, with 4G
Most OpenOffice users run Windows
Smartphones with quad-core chips and 4G LTE coming soon
Government alarm over cyberattacks validated by terrorists
Lawmakers call on DOJ to reopen investigation into Google Wi-Fi spying
Researchers propose TLS extension to detect rogue SSL certificates
IaaS: Renting on-demand technology
Yahoo Axis may be game changer for search and the troubled company
Android, Apple Own 80% of Global Smartphone Market; Microsoft's Share, 2.2%
Managing Mobile Mania
Proposed New York Legislation Would Ban Anonymous Online Comments
Supercomputer to connect to 400PB of storage via Ethernet



Send to a friend

Feedback
Breaking news
Today's top news.

Cybersecurity law: What's at stake?

Techno-literate lawyers tell us what we need to know about pending cybersecurity legislation.

Related linksToday's breaking news
Send to a friendFeedback


The events of Sept. 11, 2001, spawned an assortment of cybersecurity bills, the majority of which are either innocuous or only marginally beneficial, calling for increased federal funding for long-term, high-risk cybersecurity research; grants to fund cybersecurity research and education at universities; or antitrust liability exemptions for information sharing related to cybersecurity vulnerabilities and breaches. However, two of the bills warrant close scrutiny as they might affect enterprise network security.

The 'standards' bill

The first is the Cyber Security Research and Development Act, introduced by Sen. Ron Wyden (D-Ore.). An amended version directs the National Institute of Standards and Technology (NIST) to set benchmark cybersecurity standards for federal agencies. While the Wyden bill does not impose government-developed security standards on the private sector, industry members are concerned that NIST standards could hamstring innovation.

Despite such concerns, the Senate Commerce Committee approved the Wyden bill on May 17, in effect guaranteeing that debate over the bill's amended provisions will intensify.

The 'best practices' bill

The second bill to watch is S. 1900, supported by Sen. John Edwards (D-N.C.). Known as the Cyberterrorism Preparedness Act of 2002, the bill authorizes NIST to establish a nonprofit, nongovernmental consortium of academic and private sector experts to promulgate cybersecurity "best practices." Although the bill calls for initial implementation of these best practices only in government systems, some supporters hope that the practices will serve as a model for private sector cybersecurity. In fact, the bill requires study on how to achieve broad adoption of these best practices in the private sector and hints at the possibility of requiring companies that do business with the federal government to comply with these practices.

Some industry leaders are concerned that the federal "best practices" are designed to be used in litigation against large companies. For example, federal best practices could become the baseline against which the adequacy of a company's security practices would be measured in a class action suit in which plaintiffs seek to recover losses arising out of a security breach.

Nonetheless, Edwards' bill, which has cleared the Senate Commerce Committee, might be more appealing than the Wyden bill to those who believe the key to improved federal cybersecurity is not the development of technological standards, but the adoption of performance guidelines and best practices.

While the industry should monitor these bills, legislative imposition of cybersecurity standards on the private sector does not appear imminent. That said, legislators and federal regulators easily could be spurred to action by a catastrophic cybersecurity-related event, such as a breach at a major online bank leading to significant losses, disclosure of sensitive information or identity theft.

Accordingly, if the industry is to stave off burdensome federal cybersecurity regulation in the long run, it must not only monitor legislative efforts to prevent the de facto imposition of government cybersecurity standards on the private sector, but also consider industry self-regulatory initiatives.

Baker is a partner and Schneck an associate with Steptoe & Johnson in Washington, D.C.

Related Links

Cyber Security Research and Development Act

Cyberterrorism Preparedness Act of 2002

National system security finds common ground
Beginning this month, all new national security systems must pass Common Criteria testing.
Network World, 07/08/02

Congress: Tighten IT security
Prompted by last year's terrorist attacks, momentum is building on Capitol Hill to expand the role of the National Institute of Standards and Technology in establishing IT security standards and best practices. But the prospect is raising concerns in some circles. Network World, 04/22/02.

Error 404--Not Found

Error 404--Not Found

From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:

10.4.5 404 Not Found

The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.

If the server does not wish to make this information available to the client, the status code 403 (Forbidden) can be used instead. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address.

Topics: Security
Get all your security news, alerts, reviews, how-tos and more in one place.

Network World's Security and Bug Patch Alert newsletter
Get the latest information on security and bug alert announcements and fixes from major vendors.

Network World on Security newsletter
Stay current on security challenges and solutions, and get strategic insight into the future of information security.

Security research page
Get up to speed on security issues, including intrusion detection, hackers and other subjects.

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.