News / Science & Technology

Obama Administration Offers Companies Broad Standards to Improve Cybersecurity

Reuters
The U.S. government on Wednesday released the final version of standards meant to help companies in nationally critical industries better defend against cyber attacks, and officials now face the challenge of getting the private sector to adopt the voluntary measures.

Criticized for being too vague and toothless, the so-called cybersecurity framework turned a vast amount of industry input into guidelines designed for 16 different sectors whose disruption could be devastating to the country.

The release from the National Institute of Standards and Technology comes exactly one year after President Barack Obama issued an executive order directing the agency to compile voluntary minimum cybersecurity standards as one step to counter the lack of progress on cybersecurity law in Congress.

“While I believe today's Framework marks a turning point, it's clear that much more work needs to be done to enhance our cybersecurity,” Obama said in a statement.

“I again urge Congress to move forward on cybersecurity legislation that both protects our nation and our privacy and civil liberties,” he said. “Meanwhile, my Administration will continue to take action, under existing authorities, to protect our nation from this threat.”

The framework, drafted by the nonregulatory government agency in consultation with thousands of industry experts, offers broad benchmarks for companies to measure the effectiveness of their cyber defenses.

The Obama administration had faced intense pushback from the private sector on its earlier effort to mandate cyber defense standards, which contributed to stalled legislation. Now, the White House hopes companies voluntarily adopt the framework they have helped draft.

“This voluntary Framework is a great example of how the private sector and government can, and should, work together to meet this shared challenge,” Obama said, and a senior administration official called the framework the beginning of a “continuing common-sense conversation” about protecting the nation's critical assets from cyber attacks.

“I think that the NIST standards will become over the next year or two, while we are waiting for legislation, the de facto best practices, just because they are accessible and current,” said Jonathan Fairtlough, managing director at Kroll Advisory Solutions' cyber investigations practice.

Will private sector adapt standards?

Cybersecurity experts warn that relentless efforts to hack into U.S. banks and financial institutions, the power grid and other critical infrastructure, paired with instances of disruptive attacks abroad, pose a national security threat.

The issue recently became a household topic after hackers stole about 40 million credit and debit card records and 70 million other records with personal customer data from the third-largest U.S. retailer, Target Corp.

Many experts have expressed alarm about the lack of awareness or reluctance among some companies' leadership to spend more money on cyber defenses. The framework could force the issue into more executive suites, analysts say.

“At a minimum, it's going to force this conversation up the food chain, out of the CEO office into the boardroom,” said Tom Kellermann, a former member of Obama's Commission on Cyber Security and software company executive now with professional services firm Alvarez & Marsal.

But it is unclear whether the private sector, always concerned about liabilities attached to any standards, would widely adopt the voluntary framework.

The departments of Homeland Security, Commerce and Treasury are reviewing potential incentives for adoption, though some companies worry that incentives will come with strings attached and prompt more regulatory oversight or threat of lawsuits.

The White House has emphasized the voluntary nature of the framework and the need for companies to view cybersecurity as a business decision, part of its risk-management strategy.

“We may not ever know how widely the framework has been adopted, because obviously there's not a requirement,” a second senior Obama administration official said on Wednesday. “There's an enlightened sense here that we're counting on.”

Department of Homeland Security on Wednesday also launched a program called Critical Infrastructure Cyber Community that would help companies reach out to the government for assistance in adopting the framework, and that participation may help gage the popularity of the standards, the official said.

Questions about effectiveness

But it is also unclear how effective the framework will prove in practice.

“At that high level, they got it right. ... Further down, it gets murky really fast,” said Andrew Ginter, vice president of industrial security at Waterfall Security Solutions, whose clients include power plants and water-treatment facilities.

“The NIST framework never uses the word 'firewall.' It's that abstract,” he said, referring to a common standard component of network security.

The framework offers sweeping categories such as “access control” or “data security” to evaluate how effectively a company identifies and protects network assets, and detects, responds to and recovers from breaches, on a one-to-four-tier scale for implementation.

The categories then break into subcategories, such as keeping inventories of used software platforms and applications, ensuring that top executives know roles and responsibilities, and setting information security policies.

The document also incorporates how the companies could do that while protecting privacy and civil liberties.

The framework builds on and references existing regulations, many of which were developed for specific sectors, such as energy and financial services.

“It can get really quite hard” studying and balancing various existing standards, said Dave Burg, who advises corporations on cybersecurity strategies at consultancy PricewaterhouseCoopers. “This framework will provide a very nice baseline against which companies can test themselves.”

You May Like

Photogallery Pope Condemns IS 'Persecution' of Minorities

Pope delivers annual 'Urbi et Orbi' (to the city and the world) blessing, appeals for end to conflicts in Africa, dialogue in Middle East, condemns Taliban attack in Pakistan More

China Reduces Number of Crimes Punishable by Death

Earlier this year China announced plans to remove nine crimes from the list of capital offenses, including counterfeiting, fraudulent fund-raising and forcing others into prostitution More

Analysis: For N. Koreans, Parody Has Grave Tone

Most North Koreans who might see 'The Interview' would be horribly offended, outraged, and confused More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Estimates Rising of Foreign Fighters in Iraq, Syriai
X
Jeff Seldin
December 24, 2014 11:38 PM
Foreign fighters are making more of a mark on the battles raging across Syria and Iraq than initially thought. VOA's Jeff Seldin has more.
Video

Video Estimates Rising of Foreign Fighters in Iraq, Syria

Foreign fighters are making more of a mark on the battles raging across Syria and Iraq than initially thought. VOA's Jeff Seldin has more.
Video

Video Russians Head Into Holiday Facing Economic Malaise

Russian preparations for the New Year holiday are clouded by economic recession and a tumbling currency, the ruble. Nonetheless, people in the Russian capital appear to be in a festive mood. VOA's Daniel Schearf reports from Moscow.
Video

Video Mombasa in Holiday Tourism Slump Due to Security Fears

Kenya's usually popular beachside tourist destination of Mombasa is seeing a much slower holiday season this year due to fears of insecurity as the country has suffered from a string of terror attacks linked to Somali militants. Mohammed Yusuf reports for VOA on how businessmen and tourists feel about the situation.
Video

Video For Somalis, 2014 Marked by Political Instability Within Government

While Somalia has long been torn apart by warfare and violence, this year one of the country's biggest challenges has come from within the government, as political infighting curtails the country's progress, threatens security gains and disappoints the international community. VOA's Gabe Joselow report.
Video

Video US Political Shift Could Affect Iran Nuclear Talks

Secretary of State John Kerry’s efforts to resolve Iran’s nuclear crisis are continuing into 2015 after Iran and six world powers failed to agree by a November deadline. U.S. domestic politics, however, could complicate efforts to reach a deal in the new year. VOA State Department correspondent Pam Dockins has the story.
Video

Video NYSE: The Icon of Capitalism

From its humble beginnings in 1792 to its status as an economic bellweather for the world, the New York Stock Exchange is an integral part of the story of America. VOA’s Bernard Shusman reports from Wall Street.
Video

Video Islamic State Emergence Transforms Syria and Iraq in 2014

The emergence of the Islamic State in Iraq and Syria as a potent force in early 2014 changed the dynamics of the region. Their brutal methods - including executions and forced slavery - horrified the international community, drawing Western forces into the conflict. It also splintered the war in Syria, where more than 200,000 Syrians have died in the conflict. VOA’s Henry Ridgwell looks back at a deadly year in the region -- and what 2015 may hold.
Video

Video Massive Study Provides Best Look at Greenland Ice Loss Yet

The Greenland ice sheet is melting faster than predicted, according to a new study released in the Proceedings of the National Academic of Sciences that combines NASA satellite data and aerial missions. As VOA’s Rosanne Skirble reports, the finding means coastal communities worldwide could be at greater risk, sooner, from the impact of rising seas.
Video

Video US Marines, Toys for Tots Bring Christmas Joy

Christmas is a time for giving in the United States, especially to young children who look forward to getting presents. But some families don't have money to buy gifts. For nearly 70 years, a U.S. Marines-sponsored program has donated toys and distributed them to underprivileged children during the holiday season. VOA's Deborah Block tells us about the annual Toys for Tots program.
Video

Video France Rocked by Attacks as Fear of ISIS-Inspired Terror Grows

Eleven people were injured, two seriously, when a man drove his car into crowds of pedestrians Sunday night in the French city of Dijon, shouting ‘God is Great’ in Arabic. It’s the latest in a series of apparent ‘lone-wolf’ terror attacks in the West. Henry Ridgwell looks at the growing threat of attacks, which security experts say are likely inspired by the so-called "Islamic State" terror group.

Circumventing Censorship

An Internet Primer for Healthy Web Habits

As surveillance and censoring technologies advance, so, too, do new tools for your computer or mobile device that help protect your privacy and break through Internet censorship.
More

All About America

AppleAndroid