Welcome to DU!
The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards.
Join the community:
Create a free account
Support DU (and get rid of ads!):
Become a Star Member
Latest Breaking News
General Discussion
The DU Lounge
All Forums
Issue Forums
Culture Forums
Alliance Forums
Region Forums
Support Forums
Help & Search
General Discussion
Related: Editorials & Other Articles, Issue Forums, Alliance Forums, Region ForumsPresident Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure
President Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure
By Michelle Richardson
Last night the President signed an executive order (EO) aimed at ramping up the cybersecurity of critical infrastructure. Overwhelmingly, the EO focuses on privacy-neutral coordination between the government and the owners and operators of critical infrastructure (CI)such as the banking, communication, power, and transportation sectorswhich have long been regulated because of their fundamental role in the smooth operation of society. Now that these important entities are all connected to the internet, the administration insists that their cybersecurity be on par with their physical security.
There are two important information sharing advancements in the EO, and this time they are good for privacy. They do not include the many problems of legislation like the Cyber Intelligence and Sharing Protection Act (CISPA) because an executive order by definition cannot take away the privacy protections granted by current statutes. In other words, the EO cannot exempt companies from privacy statutes, or let the government collect new information. It can only act within its existing power to change policies and practices.
Two cheers for cybersecurity programs that can do something besides spy on Americans.
The first information sharing advancement greases the wheels of information from the government to the private sector. Section 4 lights a fire under agencies and directs them to share more information with companiesinformation they already have and can legally collect under current law. Information flowing in this direction is nowhere as near as problematic as the opposite direction. To the extent that corporate and congressional advocates claim that CISPA is needed for this purpose, the administration beat them to the punch. The EO directs the attorney general, the director of national intelligence and the secretary of homeland security to set up a system to get threat information to critical infrastructure owners and operators. They have four months to pull it together.
The second information sharing provision is a net positive for civil liberties. Section 5 directs the Department of Homeland Security, the Privacy and Civil Liberties Oversight Board (PCLOB) and the Office of Management and Budget to evaluate current interagency information sharing. There is plenty of cyber information floating around the executive branch and across different agencies. There doesn't appear to be any publicly available regulation of how that information is protected for privacy purposes, and it may very well be that it is protected by a mish-mash of originating statutes that treat different types of information with varying protections. By holding the agencies accountable to the Fair Information Practice Principles (FIPPs)transparency, choice, minimization and morewe may see a government-wide cybersecurity privacy regime evolve. To get it done right, PCLOB will need to be funded and staffed up, and advocacy will be needed to keep the agencies true to the FIPPs, but the President has now declared them the bellwether for cybersecurity information.
Overall, the EO is a win for privacy and civil liberties. It's a good reminder that while some are focused like a laser on turning our internet records over to the National Security Agency, there are a lot of other things that government can do to advance cybersecurity instead. Now it's up to all of us to make sure Congress follows the President's lead.
http://www.aclu.org/blog/national-security-technology-and-liberty/president-obama-shows-no-cispa-invasion-privacy-needed
By Michelle Richardson
Last night the President signed an executive order (EO) aimed at ramping up the cybersecurity of critical infrastructure. Overwhelmingly, the EO focuses on privacy-neutral coordination between the government and the owners and operators of critical infrastructure (CI)such as the banking, communication, power, and transportation sectorswhich have long been regulated because of their fundamental role in the smooth operation of society. Now that these important entities are all connected to the internet, the administration insists that their cybersecurity be on par with their physical security.
There are two important information sharing advancements in the EO, and this time they are good for privacy. They do not include the many problems of legislation like the Cyber Intelligence and Sharing Protection Act (CISPA) because an executive order by definition cannot take away the privacy protections granted by current statutes. In other words, the EO cannot exempt companies from privacy statutes, or let the government collect new information. It can only act within its existing power to change policies and practices.
Two cheers for cybersecurity programs that can do something besides spy on Americans.
The first information sharing advancement greases the wheels of information from the government to the private sector. Section 4 lights a fire under agencies and directs them to share more information with companiesinformation they already have and can legally collect under current law. Information flowing in this direction is nowhere as near as problematic as the opposite direction. To the extent that corporate and congressional advocates claim that CISPA is needed for this purpose, the administration beat them to the punch. The EO directs the attorney general, the director of national intelligence and the secretary of homeland security to set up a system to get threat information to critical infrastructure owners and operators. They have four months to pull it together.
The second information sharing provision is a net positive for civil liberties. Section 5 directs the Department of Homeland Security, the Privacy and Civil Liberties Oversight Board (PCLOB) and the Office of Management and Budget to evaluate current interagency information sharing. There is plenty of cyber information floating around the executive branch and across different agencies. There doesn't appear to be any publicly available regulation of how that information is protected for privacy purposes, and it may very well be that it is protected by a mish-mash of originating statutes that treat different types of information with varying protections. By holding the agencies accountable to the Fair Information Practice Principles (FIPPs)transparency, choice, minimization and morewe may see a government-wide cybersecurity privacy regime evolve. To get it done right, PCLOB will need to be funded and staffed up, and advocacy will be needed to keep the agencies true to the FIPPs, but the President has now declared them the bellwether for cybersecurity information.
Overall, the EO is a win for privacy and civil liberties. It's a good reminder that while some are focused like a laser on turning our internet records over to the National Security Agency, there are a lot of other things that government can do to advance cybersecurity instead. Now it's up to all of us to make sure Congress follows the President's lead.
http://www.aclu.org/blog/national-security-technology-and-liberty/president-obama-shows-no-cispa-invasion-privacy-needed
InfoView thread info, including edit history
TrashPut this thread in your Trash Can (My DU » Trash Can)
BookmarkAdd this thread to your Bookmarks (My DU » Bookmarks)
1 replies, 756 views
ShareGet links to this post and/or share on social media
AlertAlert this post for a rule violation
PowersThere are no powers you can use on this post
EditCannot edit other people's posts
ReplyReply to this post
EditCannot edit other people's posts
Rec (2)
ReplyReply to this post
1 replies
= new reply since forum marked as read
Highlight:
NoneDon't highlight anything
5 newestHighlight 5 most recent replies
President Obama Shows No CISPA-like Invasion of Privacy Needed to Defend Critical Infrastructure (Original Post)
ProSense
Feb 2013
OP
ProSense
(116,464 posts)1. Kick! n/t