Cybersecurity Bill Tweaks Raise Concerns Over Government Standard-Setting Powers

A recent revision to a comprehensive cybersecurity bill has sparked worries from tech industry groups and a prominent high-tech watchdog, who argue that the proposed government standard-setting powers could hinder innovation. The Business Software Alliance and TechAmerica have joined the Center for Democracy and Technology in urging Senate Commerce Chairman John Rockefeller's staff to alter language that would give the National Institute of Standards and Technology a major role in how IT systems are designed.

Key Takeaways:

  • The revised draft of the bill requires the National Institute of Standards and Technology to formulate "measurable and auditable" risk metrics and best practices for IT systems.
  • Critics argue that this language could allow NIST to impose software and network standards on companies, stifling innovation.
  • Business Software Alliance executives warn that software firms doing global business cannot operate under country-specific rules, pointing to China's threat to impose software requirements.
  • A more attractive alternative is to encourage global standards developed by the IT industry, which would stimulate innovation and improve US security.
  • Senate Commerce Chairman John Rockefeller's staff has received extensive comment from industry and civil liberties groups, and the final bill will benefit from these comments.

Statistics:

  • The Business Software Alliance represents over 1,000 technology firms.
  • China's threat to impose software requirements could effectively close off that market for some US products.
  • High-tech criminals are frequently a step ahead of their targets, highlighting the need for innovative security measures.
  • The final bill is expected to be influenced by comments from industry and civil liberties groups.

Sources:

  • Business Software Alliance
  • TechAmerica
  • Center for Democracy and Technology
  • Senate Commerce Committee
  • Senate Homeland Security and Governmental Affairs Committee
  • Cisco Systems
  • IBM
  • Intel
  • Hewlett-Packard
  • Microsoft
  • Greg Nojeim, CDT senior counsel
  • Katherine McGuire, BSA lobbyist
  • Franck Journoud, BSA Manager of Information Security Policy
  • John Rockefeller, Senate Commerce Chairman
  • Olympia Snowe, R-Maine, Senator
  • Joseph Lieberman, Senate Homeland Security and Governmental Affairs Chairman