Does anyone want to volunteer their private security information?

Analysis
Sep 26, 20125 mins

Some members of Congress are pushing for an Executive Order to implement "voluntary sharing" of security data from the private sector to the government…but will private industry bite?

It has been almost 10 years since FISMA was enacted, the last major federal law to focus primarily on information security. Even then, the scope of FISMA was limited to federal government agencies and selected contractors. Federal information security mandates affecting private industry have always been addressed as an appendage or inferred requirement to major federal legislation: HIPAA, GLBA and SOX were all focused either on specific categories of data or business types, and none of them took a framework-based approach to security (instead, they relied on individual security controls). We do not yet have a comprehensive federal law addressing information security – or “cybersecurity,” the preferred nomenclature of the federal government – in a manner that applies to protecting data regardless of its context, applicable to private industry.

RELATED: The NSA’s acceptance of hackers at Defcon marks progress for information security

The Legacy of Howard Schmidt: Take Care of the Basics and Information Security Will Take Care of Itself

This summer, we came very close (for good or bad, we’ll never know). Both the Cybersecurity Act of 2012, sponsored by Sen. Joseph Lieberman (I-CT), and the Cyber Intelligence Sharing and Protection Act (CISPA), sponsored by Rep. Mike Rogers (R-MI), cleared their respective chambers but died in the other chamber. So much for a bicameral legislature, eh? While there were many differences between these two bills, one shared component was the idea of “voluntary sharing” of private industry security data with the federal government, specifically by those corporations and other entities that manage “critical infrastructure” – a vaguely-defined, catch-all phrase that could include energy production and distribution, transportation and logistics, agriculture, financial services, and a host of other industries. With the demise of both bills, several Democratic senators are now urging the Obama administration to issue an executive order to support voluntary standards and data sharing between private industry and federal agencies, such as the DHS and NSA.

There are two major issues with this approach. The first is simply one of authority: suggesting that the Executive branch has the Constitutional authority to mandate information security practices to the private sector is a tenuous argument; but that’s a discussion for a different blog. In a perfect world, the way to address this problem – assuming, of course, that you subscribe to the notion that it needs to be addressed – is through, as the saying goes, an Act of Congress. Unfortunately, amendments, provisions and waivers within the more than forty bills currently making their way through both chambers are likely to result in legislation that is so watered-down it doesn’t actually help to solve the problem of cybersecurity, has no enforcement teeth, or – in the worst case – is so encumbered with unrelated detritus (which currently ranges from gun control measures to wholesale repeal of the healthcare act) that it simply fails to be passed.

The second problem is more obvious: any program that includes the words “voluntary” in it will be ignored wholesale by private industry, especially if it has any type of a price tag associated with it…unless, of course, the participants are getting something in return. A program based on the idea of voluntarily sharing data with a government agency that will simply take the data provided, put it into a black box, and say, “thank you for making America safer” is going to fail. But if the participants get something in return – especially something of substantial value – their likelihood of participation goes way up. So what would it take for a private company to consider sharing security data? Here are a few parameters for thought:

  • Access to “Big Picture” Security Threat Data. The federal government has visibility into real-time cybersecurity threats that most private corporations do not. Providing a way for participants in the voluntary program to gain visibility to these macro-level threats would be a huge enticement.
  • Industry Comparison Metrics. The most common question I’ve been asked by my customers and clients over the years is, “how does our security program compare to our competitors?” Providing detailed, industry-specific (but name-sanitized) security metrics as a benefit for participating in the program is a great way to encourage participation.
  • Privacy of Provided Data at the Point of Collection. The other side of the coin is that organizations will not share their data if it’s going to be provided to competitors with their name attached to it. Organizations will want to implement sanitization of their data at the point of collection (not after the government gets a hold of it).
  • Public Relations Opportunity. The government should provide – and generously fund – an awareness campaign for the program. Private industry organizations might be more willing to participate if they can get “good security citizen” PR mileage out of their participation.
  • Guarantees of No Liability or Government Interference. If there are any teeth added to a “voluntary sharing” program – for example, the federal government sending in a Tiger Team to “help” a volunteering organization in the event that the government determines its security controls are below industry average – this program will be dead on arrival.

I have no doubt that these U.S. Senators, as well the Obama administration – who responded positively to the Senators’ request – are sincere in their desire to ensure the security of information and systems that are critical to Americans’ daily lives. However, an Executive Order based on voluntary participation is going to be as ineffective as the legislation that Congress has failed to pass to date, unless it provides something of value for those who are “volunteering” to take part in the program.