News / Science & Technology

Obama Administration Offers Companies Broad Standards to Improve Cybersecurity

Reuters
The U.S. government on Wednesday released the final version of standards meant to help companies in nationally critical industries better defend against cyber attacks, and officials now face the challenge of getting the private sector to adopt the voluntary measures.

Criticized for being too vague and toothless, the so-called cybersecurity framework turned a vast amount of industry input into guidelines designed for 16 different sectors whose disruption could be devastating to the country.

The release from the National Institute of Standards and Technology comes exactly one year after President Barack Obama issued an executive order directing the agency to compile voluntary minimum cybersecurity standards as one step to counter the lack of progress on cybersecurity law in Congress.

“While I believe today's Framework marks a turning point, it's clear that much more work needs to be done to enhance our cybersecurity,” Obama said in a statement.

“I again urge Congress to move forward on cybersecurity legislation that both protects our nation and our privacy and civil liberties,” he said. “Meanwhile, my Administration will continue to take action, under existing authorities, to protect our nation from this threat.”

The framework, drafted by the nonregulatory government agency in consultation with thousands of industry experts, offers broad benchmarks for companies to measure the effectiveness of their cyber defenses.

The Obama administration had faced intense pushback from the private sector on its earlier effort to mandate cyber defense standards, which contributed to stalled legislation. Now, the White House hopes companies voluntarily adopt the framework they have helped draft.

“This voluntary Framework is a great example of how the private sector and government can, and should, work together to meet this shared challenge,” Obama said, and a senior administration official called the framework the beginning of a “continuing common-sense conversation” about protecting the nation's critical assets from cyber attacks.

“I think that the NIST standards will become over the next year or two, while we are waiting for legislation, the de facto best practices, just because they are accessible and current,” said Jonathan Fairtlough, managing director at Kroll Advisory Solutions' cyber investigations practice.

Will private sector adapt standards?

Cybersecurity experts warn that relentless efforts to hack into U.S. banks and financial institutions, the power grid and other critical infrastructure, paired with instances of disruptive attacks abroad, pose a national security threat.

The issue recently became a household topic after hackers stole about 40 million credit and debit card records and 70 million other records with personal customer data from the third-largest U.S. retailer, Target Corp.

Many experts have expressed alarm about the lack of awareness or reluctance among some companies' leadership to spend more money on cyber defenses. The framework could force the issue into more executive suites, analysts say.

“At a minimum, it's going to force this conversation up the food chain, out of the CEO office into the boardroom,” said Tom Kellermann, a former member of Obama's Commission on Cyber Security and software company executive now with professional services firm Alvarez & Marsal.

But it is unclear whether the private sector, always concerned about liabilities attached to any standards, would widely adopt the voluntary framework.

The departments of Homeland Security, Commerce and Treasury are reviewing potential incentives for adoption, though some companies worry that incentives will come with strings attached and prompt more regulatory oversight or threat of lawsuits.

The White House has emphasized the voluntary nature of the framework and the need for companies to view cybersecurity as a business decision, part of its risk-management strategy.

“We may not ever know how widely the framework has been adopted, because obviously there's not a requirement,” a second senior Obama administration official said on Wednesday. “There's an enlightened sense here that we're counting on.”

Department of Homeland Security on Wednesday also launched a program called Critical Infrastructure Cyber Community that would help companies reach out to the government for assistance in adopting the framework, and that participation may help gage the popularity of the standards, the official said.

Questions about effectiveness

But it is also unclear how effective the framework will prove in practice.

“At that high level, they got it right. ... Further down, it gets murky really fast,” said Andrew Ginter, vice president of industrial security at Waterfall Security Solutions, whose clients include power plants and water-treatment facilities.

“The NIST framework never uses the word 'firewall.' It's that abstract,” he said, referring to a common standard component of network security.

The framework offers sweeping categories such as “access control” or “data security” to evaluate how effectively a company identifies and protects network assets, and detects, responds to and recovers from breaches, on a one-to-four-tier scale for implementation.

The categories then break into subcategories, such as keeping inventories of used software platforms and applications, ensuring that top executives know roles and responsibilities, and setting information security policies.

The document also incorporates how the companies could do that while protecting privacy and civil liberties.

The framework builds on and references existing regulations, many of which were developed for specific sectors, such as energy and financial services.

“It can get really quite hard” studying and balancing various existing standards, said Dave Burg, who advises corporations on cybersecurity strategies at consultancy PricewaterhouseCoopers. “This framework will provide a very nice baseline against which companies can test themselves.”

You May Like

Video Iran Nuclear Deal Becomes US Campaign Issue

Voters in three crucial battleground states - Florida, Ohio and Pennsylvania - overwhelmingly oppose nuclear deal with Iran More

Al-Qaida's Syria Affiliate Reemerges

Jabhat al-Nusra has rebounded, increasingly casting itself as a critical player in battle for Syria’s future More

Lessons Learned From Katrina, 10 Years Later

FEMA chief Craig Fugate says key changes include better preparation, improved coordination among state, federal assistance agencies More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Colombians Flee Venezuela as Border Crisis Escalatesi
X
August 27, 2015 2:08 AM
Hundreds of Colombians have fled Venezuela since last week, amid an escalating border crisis between the two countries. Last week, Venezuelan President Nicolas Maduro ordered the closure of a key border crossing after smugglers injured three Venezuelan soldiers and a civilian. The president also ordered the deportation of Colombians who are in Venezuela illegally. Zlatica Hoke reports.
Video

Video Colombians Flee Venezuela as Border Crisis Escalates

Hundreds of Colombians have fled Venezuela since last week, amid an escalating border crisis between the two countries. Last week, Venezuelan President Nicolas Maduro ordered the closure of a key border crossing after smugglers injured three Venezuelan soldiers and a civilian. The president also ordered the deportation of Colombians who are in Venezuela illegally. Zlatica Hoke reports.
Video

Video Is China's Economic Data Accurate?

Some investors say China's wild stock market gyrations have been made worse by worries about the reliability of that nation's economic data. And some critics say the reports can mislead investors by painting an unrealistically-strong picture of the economy. A key China scholar says Beijing is not fudging ((manipulating)) the numbers, but that the economy is evolving quickly from smoke-stack industries to services, and the ways of tracking new economic activity are falling behind the change. V
Video

Video Next to Iran, Climate at Forefront of Obama Agenda

President Barack Obama this week announced new initiatives aimed at making it easier for Americans to access renewable energy sources such as solar and wind. Obama is not slowing down when it comes to pushing through climate change measures, an issue he says is the greatest threat to the country’s national security. VOA correspondent Aru Pande has more from the White House.
Video

Video Shipping Containers Provide Experimental Housing

Housing prices around the San Francisco Bay area are out of reach for many people, so some young entrepreneurs, artists and tech industry workers are creating their own houses using converted shipping containers. But as VOA's Mike O’Sullivan reports from Oakland, the effort requires ingenuity and dealing with restrictive local laws.
Video

Video Arctic Draws International Competition for Oil

A new geopolitical “Great Game” is underway in earth’s northernmost region, the Arctic, where Russia has claimed a large area for resource development and President Barack Obama recently approved Shell Oil Company’s test-drilling project in an area under U.S. control. Greg Flakus reports.
Video

Video Philippine Maritime Police: Chinese Fishermen a Threat to Country’s Security

China and the Philippines both claim maritime rights in the South China Sea.  That includes the right to fish in those waters. Jason Strother reports on how the Philippines is catching Chinese nationals it says are illegal poachers. He has the story from Palawan province.
Video

Video Technique May Eliminate Drill-and-Fill Dental Care

Many people dread visiting dentists because they're afraid of drills. Now, however, a technology developed by a British firm promises to eliminate the need for mechanical cleaning of dental cavities by speeding a natural process of tooth repair. VOA’s George Putic reports.
Video

Video China's Spratly Island Building Said to Light Up the Night 'Like A City'

Southeast Asian countries claim China has illegally seized territory in the Spratly islands. It is especially a concern for a Philippine mayor who says Beijing is occupying parts of his municipality. Jason Strother reports from the capital of Palawan province, Puerto Princesa.
Video

Video Ages-old Ice Reveals Secrets of Climate Change

Ice caps don't just exist at the world's poles. There are also tropical ice caps, and the largest sits atop the Peruvian Andes - but it is melting, quickly, and may be gone within the next 20 years. George Putic reports scientists are now rushing to take samples to get at the valuable information about climate change locked in the ice.
Video

Video French Experiment in Integrating Roma Under Threat

Plans to destroy France’s oldest slum have sparked an outcry on the part of its Roma residents. As Lisa Bryant reports from the Paris suburb of La Courneuve, rights groups argue the community is a fledgling experiment on integrating Roma who are often outcasts in many parts of Europe.
Video

Video Kenyans Turn to Agriculture for Business

Each year Kenyan universities continue to churn out graduates for the job market despite the already existing high rate of unemployment among youth in the country. Some of these young men and women have realized that agriculture can be as rewarding as any other business or job, and they are resorting to agribusiness in large numbers as a way of tackling unemployment. Rael Ombuor reports for VOA.
Video

Video First Women Graduate Elite Army Ranger School

Two women are making history for the U.S. Army by proving they are among the toughest of the tough. VOA's Carla Babb reports from Fort Benning, Georgia as 94 men and those two women rise as graduates of the difficult Ranger school.

VOA Blogs