Hot on the heels of the latest Sony hack, the seemingly-dormant National Cybersecurity and Critical Infrastructure Protection Act passed by the House is expecting movement within the Senate.
If passed, the bill would allow private companies to share cybersecurity data with the Department of Homeland Security. The bill also outlines Homeland Security’s role in American cybersecurity and would reauthorize the department’s authorities.
The bill would also give legal protection to private companies that share information with the federal government. All government agencies would also be required to tell Homeland Security about any cyberattack.
What would constitute a "cyberattack" from a corporation's perspective? To paraphrase Rahm Emanuel, "Never let a serious crisis go to waste."
(Score: 1) by SecurityGuy on Friday December 05 2014, @03:02PM
Be careful to define "cyberattack", though, or you'll have legions of people spending hours filling out paperwork about every script kiddie port scan.
(Score: 2) by Leebert on Saturday December 06 2014, @12:10AM
If you think that's funny and not sad, you clearly don't work in government infosec. Because I've seen exactly that.
(Score: 1) by SecurityGuy on Tuesday December 09 2014, @05:39PM
You might note that nowhere did I say it was funny. I wasn't kidding.