If There's A National Cybersecurity Policy, What Should It Cover?
from the if-anything... dept
A bunch of folks have been sending in the various news stories about a new report recommending to the incoming presidential administration a set up a national cybersecurity policy, which is the sort of broad pronouncement that many people would instinctively agree with. However, it's not really clear what this covers. The report covers both government and private companies' computer networks, as if the issues and challenges facing each should be covered under a single plan. There's also talk of some new kind of warrant called "data warrants" rather than search warrants. Obviously, protecting internet infrastructure from foreign attacks is a good thing, but there's a lot here that seems like a grab for power -- and the ability to more closely gather and monitor data.The fact that government networks and security of government computers is a mess is one issue, but it shouldn't be mixed in with private companies protecting their own data. The two issues should be tackled separately. If the government needs to fix its own computer network and security policies, that seems like a reasonable job for the national CIO that Obama has indicated is a part of his plan, rather than a separate cybersecurity policy.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: cybersecurity, national policy
Reader Comments
Subscribe: RSS
View by: Time | Thread
Too many of our rights are being taken with anyone standing up.
[ link to this | view in chronology ]
Natl Cybersecurity Policy
[ link to this | view in chronology ]
National Unity with respect to Cyber Operations is a good thing
[ link to this | view in chronology ]
The Fed govt is already into the IT racket
The panopticon economy
The NSA’s new data-mining facility is one component of a growing local surveillance industry
by Greg M. Schwartz
http://sacurrent.com/news/story.asp?id=69607
[ link to this | view in chronology ]
Definitions don't hurt
I consistently notice that many people have problems adapting old concepts of property and space to the new information-based world - reference the continued (and correct) postings about using free to drive market demand.
Isn't this just a way for the gov't to recognize that, when it is seizing hard drives, it is not the actual hard drive that is being targeted, but the data it contains? I think it is better for the government to get warrants for the things they actually want, rather than something that contains it?
[ link to this | view in chronology ]
What it should cover
1) National security - there are already standards in place to protect classified government information and these clearly apply to electronic data as well. Persons or organisations with access to the classified information must have the necessary clearance and a need to know. It is then their responsibility to safeguard the information. This isn't so much a technology issue -- though technology such as data encryption should obviously be used -- as much as it's a social issue. Because the existing system is based on trust (and background checks), the answer, it would seem, is harsher punishment for breaking these laws. Granted, it doesn't do much in the way of prevention, but some things (particularly social things) cannot be solved with technology.
2) Personal security - the only other area of concern, as far as I can tell, is safeguarding personal information. This includes credit card information, social security numbers, etc. While any and all services that require this kind of information should take every measure possible to protect it, the protection provided is not always sufficient. If the government is going to impose IT laws, it should be the information security aspect that is the central theme. Personal information of any kind should be treated like classified information with suggestions and guidelines to follow to secure the information and harsh penalties for not following the regulations.
Imposing legislation on any matter other than national or personal security is wrong and a violation of the greatest right in America: choice. Persons and organisations should maintain the right of choice in all matters, so long as their choices do not negatively impact the security of others.
[ link to this | view in chronology ]