Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Committee approves cybersharing bill despite privacy concerns

The bill would give the NSA access to private information held by U.S. companies, a critic says

The U.S. House of Representatives Intelligence Committee has approved a recently introduced bill that would allow greater cyberthreat information sharing between U.S. intelligence agencies and private companies even though privacy advocates say it would allow those agencies to spy on U.S. residents.

The committee approved the Cyber Intelligence Sharing and Protection Act late Thursday by a 17-1 vote. The bill, introduced just Wednesday, would allow intelligence agencies to share classified cyberthreat information with approved U.S. companies, while encouraging companies to share their own information with the government or other companies.

The next step for the bill is a vote in the full House. That vote has not yet been scheduled.

The bill will protect privacy, said Representative Mike Rogers, a Michigan Republican and committee chairman. "The decisiveness of the vote shows the tremendous bipartisan support for this bill," he said in a statement. "Through hard work and compromise we have struck a delicate balance that provides strong protections for privacy and civil liberties, while still enabling effective cyber threat sharing and providing clear authority for the private sector to defend its own networks."

The bill would help protect U.S. businesses from cyberespionage, Rogers said.

Information sharing is a good goal, but the bill goes too far, said Jim Dempsey, vice president of public policy for the Center for Democracy and Technology. The bill could give the U.S. National Security Agency new access to personal information held by U.S. companies, given the legislation's broad definition of the kind of information that companies can share with the NSA and other government agencies, he said.

The bill allows companies to share any information pertaining to the protection of information systems, Dempsey said. That "potentially could be all traffic," he said.

The bill, although it says information sharing with the government is voluntary, could also allow the NSA to demand that private companies share their information in exchange for the cyber-threat information the agency has, Dempsey said. "It creates an incentive structure as to who gets the NSA's secret sauce," he said. "We're afraid that the NSA would use that, basically, as a trading card. They would say, 'We'll give you our good stuff, if you give us a lot of your good stuff.'"

The bill would also shift responsibility for cybersecurity from private industry to the government, and from civilian agencies within the government to intelligence and military agencies, Dempsey said. "We think the government should not be involved in monitoring the private-sector networks," he said.

Bill sponsors Rogers and Representative C.A. "Dutch" Ruppersberger, a Maryland Democrat, introduced an amendment, approved by the committee, designed to limit government agencies' use of information they get from private companies.

The amendment prohibits the government from using cyberthreat information unless at least one significant purpose is cybersecurity or national security. It also prohibits the government from searching through any cyberthreat information it receives from the private sector for any purposes not authorized by the bill.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Bill, IDG, National Security Agency, NSA, Technology
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: C.A. Ruppersberger, Center for Democracy and Technology, data protection, government, Government use of IT, Jim Dempsey, legislation, Mike Rogers, privacy, security, U.S. House of Representatives Intelligence Committee, U.S. National Security Agency
Latest Blog Posts
Whitepapers
  • Why performance management? A guide for the midsize organisation
    Midsize organisations are uniquely positioned to take advantage of a performance management approach to business. Compared with larger companies, they have more agility to bring information and people together and respond faster to changing market conditions. With one performance management solution, midsize companies can turn disconnected data into information, turn information into valuable insight and turn insight into action.
    Learn more »
  • Top Reasons to Implement an SOA Governance Strategy: A List for IT Executives
    Service-oriented architecture (SOA) has moved beyond hype to widespread acceptance as an IT strategy for delivering business value. SOA promotes the notion of modularity, providing overwhelming flexibility and superior economics for addressing business demands. However, undertaking the transformation to SOA is not without its challenges. If left unchecked, your inventory of SOA assets will become unmanageable; the reuse of services will diminish in favor of custom development; or even worse, modifications will be made to your existing services that break other business processes. The purpose of SOA governance is to help you ensure that this does not happen. This paper outlines the most compelling reasons for you to establish SOA governance within your organization.
    Learn more »
  • Cloud printing in the enterprise: liberating the mobile print experience from cables, operating systems and physical boundaries
    In recent years mobile technology has proliferated throughout the enterprise. Today, virtually no one in the workforce is bound to a desk to work, check e-mail or communicate with co-workers and customers. At the same time, we’re seeing the rise of cloud technologies, loosely defined as online resources, often provided as a service, that manage the data and software that used to run solely on PCs. This merger of mobile and cloud technologies is on its way to becoming one of most significant enablers of business productivity and innovation seen in the past decade. Read more.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.