Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Bill Would Open Channels On Cyber Threats

Proposed legislation encourages the feds and private companies to share cyberintelligence information to stop threats to networks and critical infrastructure.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
House members have introduced new legislation that would promote information sharing between the government and private companies on matters of cybersecurity.

The Cyber Intelligence Sharing and Protection Act, introduced Wednesday by Reps. Mike Rogers and Dutch Ruppersberger of the House Permanent Select Committee on Intelligence--chairman and a ranking member of the committee, respectively--allows the feds to share intelligence information with companies to help them prevent cyber attacks before they happen.

The bill also allows for "approved businesses" to share cyber threat information among themselves and also with the government, according to a statement.

The bill would go "a long way in helping American businesses better protect their networks and their intellectual property," Rogers said in the statement.

"There are two types of companies in this country, those who know they've been hacked, and those who don't know they've been hacked," he said. "Economic predators, including nation-states, are blatantly stealing business secrets and innovation from private companies."

[ The Defense Department tests its networks to protect against cyber attack. Learn more: U.S. Cyber Command Practices Defense In Mock Attack. ]

The bill is a "good start" to helping lock down U.S. intellectual property and critical infrastructure such as the power grid and banking systems, Ruppersberger added.

While the feds has been sharing cyber-threat information with the private sector through a Department of Homeland Security program, the bill would expand and formalize this type of intelligence sharing among the government and private companies.

The bill would require the Director of National Intelligence to set up procedures for sharing cyber-threat intelligence with the private sector, ensuring those that receive the information have the proper security clearance.

It also allows private sector entities to share information anonymously or restrict who they share with, including the government. Congress has been considering a number of cybersecurity bills, but so far has not passed definitive, sweeping legislation in this area.

The Obama administration has taken strides to partner with the private sector particularly on matters of cybersecurity and sharing information. DHS fusion centers around the country routinely share information with local and state authorities, as well as some companies, about cyber threats.

Thursday, President Obama proclaimed December Critical Infrastructure Protection Month, highlighting and promoting efforts the feds are taking to partner with the private sector to share cybersecurity information.

Our annual Federal Government IT Priorities Survey shows how agencies are managing the many mandates competing for their limited resources. Also in the new issue of InformationWeek Government: NASA veterans launch cloud startups, and U.S. Marshals Service completes tech revamp. Download the issue now. (Free registration required.)

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
12/5/2011 | 9:13:57 PM
re: Bill Would Open Channels On Cyber Threats
This is a good step. I'd be happy to see a lot more disclosure about threats and known attacks among companies but any move towards information sharing is a good one.

Jim Rapoza is an InformationWeek Contributing Editor
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/2/2011 | 10:28:32 PM
re: Bill Would Open Channels On Cyber Threats
Nothing wrong with sharing information to improve security.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Another COVID-19 Side Effect: Rising Nation-State Cyber Activity
Stephen Ward, VP, ThreatConnect,  7/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15600
PUBLISHED: 2020-07-07
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-15599
PUBLISHED: 2020-07-07
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
CVE-2020-8916
PUBLISHED: 2020-07-07
A memory leak in Openthread's wpantund versions up to commit 0e5d1601febb869f583e944785e5685c6c747be7, when used in an environment where wpanctl is directly interfacing with the control driver (eg: debug environments) can allow an attacker to crash the service (DoS). We recommend updating, or to res...
CVE-2020-12821
PUBLISHED: 2020-07-07
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CVE-2020-15008
PUBLISHED: 2020-07-07
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user su...