• TREND MICRO
  • ABOUT
Search:
  • Latest Posts
  • Categories
    • Android
    • AWS
    • Azure
    • Cloud
    • Compliance
    • Critical Infrastructure
    • Cybercrime
    • Encryption
    • Financial Services
    • Government
    • Hacks
    • Healthcare
    • Internet of Everything
    • Malware
    • Microsoft
    • Mobile Security
    • Network
    • Privacy
    • Ransomware
    • Security
    • Social Media
    • Small Business
    • Targeted Attacks
    • Trend Spotlight
    • Virtualization
    • Vulnerabilities
    • Web Security
    • Zero Day Initiative
    • Industry News
  • Our Experts
    • Ed Cabrera
    • Rik Ferguson
    • Greg Young
    • Mark Nunnikhoven
    • Jon Clay
    • William “Bill” Malik
  • Research
Home   »   Industry News   »   Spotlight   »   Data sharing proposal is nice start, but more work needed, legislators say

Data sharing proposal is nice start, but more work needed, legislators say

  • Posted on:December 13, 2011
  • Posted in:Spotlight
  • Posted by:
    Trend Micro
0

Proposed legislation currently making it's way through the House of Representatives could be a good first step in the right direction for the government and private companies looking to collaborate on cybersecurity measures, but the bill requires further tweaking before it can gain the necessary votes, lawmakers said recently.

A main provision of the proposed bill, which some have said is long overdue in promoting a data security partnership between the public and private sectors, is the creation of the semi-independent National Information Sharing Organization. Through the NISO, firms in the private sector and public agencies can collaborate on the cybersecurity threats they face, as well as means for protecting critical infrastructure.

Numerous changes have already been made to the proposed legislation, but some House democrats are calling for further amendments, according to a recent Bloomberg report. Specifically, the legislators are calling on the bill's authors to define how consumer data privacy will be upheld when such information is shared through the NISO.

Prior to having any chance of being passed, according to Bloomberg, New York Democrat Yvette Clarke said lawmakers must "explore the real-life implications of such a body and its actions, and how it would affect the department’s ability to enhance cybersecurity for our government agencies.” Clarke is the senior Democrat on the cybersecurity subcommittee that held a hearing on the proposed legislation on December 6.

Industry experts and data privacy advocates have echoed such calls by House democrats. Gregory Nojeim, the senior counsel at the San Francisco-based Center for Democracy and Technology, told Bloomberg that consumers have a right to know what information is being shared by companies and the government.

He added that only information that will help fight cybersecurity should be passed on to the NISO, and none of it should be used for law enforcement purposes, according to Bloomberg.

And while collaboration between the government and the private sector has been promoted as key to enhancing Internet security in the United States, some are questioning whether more regulation is the answer. A recent ZDNet commentary by data security expert Torsten George argued that more compliance requirements may only add to the problem.
Companies, George said, are more concerned about compliance than actual security.

"Unfortunately, being compliant does not equate to being secure, as compliance lacks the correlation to risk and is conducted periodically, rather than continuously," he wrote. "Thus, only regulations that mandate prioritizing security in the overall picture will really move the needle."

Still, cooperation between privately held companies and the government remains necessary if the U.S. is to fend off continued and escalating cyberattacks on both enterprise and federal networks, some experts say. Cheri McGuire, the vice president of global government affairs and cybersecurity policy for a security firm, testified before the House subcommittee that it's in everyone's best interest to create a so-called data security clearinghouse like the NISO, Bloomberg reported.

She said the move to “share information is a strong step in the right direction,” according to Bloomberg.

This legislation is another sign that organizations in the U.S. are acutely aware of the cyber threats they face and are determined to do something about the cybersecurity issue. That notion was also reflected in the recently released 2011 Lloyd’s Risk Index from insurance market Lloyd's of London.

The report revealed that organizations in North America – where cybercrime costs about $96 billion annually, Lloyd's revealed – have taken the lead on data security measures and routinely outpace the rest of the world in terms of security measures and research.

Data Security News from SimplySecurity.com by Trend Micro

Related posts:

  1. Obama: Better cybersecurity needed to stay ahead of hackers (Op/Ed)
  2. DHS needs better sharing plan, experts say
  3. UK agency new EU data protection proposal
  4. White House attempts improvement of security data sharing

Security Intelligence Blog

  • Our New Blog
  • How Unsecure gRPC Implementations Can Compromise APIs, Applications
  • XCSSET Mac Malware: Infects Xcode Projects, Performs UXSS Attack on Safari, Other Browsers, Leverages Zero-day Exploits

Featured Authors

Ed Cabrera (Chief Cybersecurity Officer)
Ed Cabrera (Chief Cybersecurity Officer)
  • Ransomware is Still a Blight on Business
Greg Young (Vice President for Cybersecurity)
Greg Young (Vice President for Cybersecurity)
  • Not Just Good Security Products, But a Good Partner
Jon Clay (Global Threat Communications)
Jon Clay (Global Threat Communications)
  • This Week in Security News: Ransomware Gang is Raking in Tens of Millions of Dollars and Microsoft Patch Tuesday Update Fixes 17 Critical Bugs
Mark Nunnikhoven (Vice President, Cloud Research)
Mark Nunnikhoven (Vice President, Cloud Research)
  • Twitter Hacked in Bitcoin Scam
Rik Ferguson (VP, Security Research)
Rik Ferguson (VP, Security Research)
  • The Sky Has Already Fallen (you just haven’t seen the alert yet)
William
William "Bill" Malik (CISA VP Infrastructure Strategies)
  • Black Hat Trip Report – Trend Micro

Follow Us

Trend Micro In The News

  • Cloud-based Email Threats Capitalized on Chaos of COVID-19
  • Detected Cyber Threats Rose 20% to Exceed 62.6 Billion in 2020
  • Trend Micro Recognized on CRN Security 100 List
  • Trend Micro Reports Solid Results for Q4 and Fiscal Year 2020
  • Connected Cars Technology Vulnerable to Cyber Attacks
  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © 2017 Trend Micro Incorporated. All rights reserved.