{"id":1063,"date":"2013-03-06T15:57:59","date_gmt":"2013-03-06T15:57:59","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=1063"},"modified":"2019-03-08T19:52:36","modified_gmt":"2019-03-09T00:52:36","slug":"the-new-cybersecurity-executive-order","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2013\/03\/06\/the-new-cybersecurity-executive-order\/","title":{"rendered":"Blog: The New Cybersecurity Executive Order"},"content":{"rendered":"<p><span style=\"color: #000000\">By Airen Adamonis, Copy Editor\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><\/p>\n<p><span style=\"color: #000000\">The United States is currently at war with China.\u00a0 However, this war is not taking place on any battlefields.\u00a0 It\u2019s taking place in cyberspace. \u00a0According to a <\/span><a href=\"http:\/\/www.washingtonpost.com\/business\/technology\/chinese-cyberspies-have-hacked-most-washington-institutions-experts-say\/2013\/02\/20\/ae4d5120-7615-11e2-95e4-6148e45d7adb_story.html\"><span style=\"color: #0000ff\">recent article published by the Washington Post<\/span><\/a>, the United States has been the target of an immense \u201ccyber-espionage campaign\u201d that is threatening the country\u2019s economic competitiveness.<\/p>\n<p><span style=\"color: #000000\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Just days after a private security firm released a <\/span><a href=\"http:\/\/intelreport.mandiant.com\/\"><span style=\"color: #0000ff\">study<\/span><\/a> accusing the Chinese military of carrying out numerous cyber-attacks against U.S. businesses, <span style=\"color: #000000\">the Obama Administration released a long-awaited Executive Order on cybersecurity measures. <span style=\"font-size: medium\">\u00a0<\/span><\/span><a href=\"http:\/\/www.whitehouse.gov\/the-press-office\/2013\/02\/12\/executive-order-improving-critical-infrastructure-cybersecurity\"><span style=\"color: #0000ff\">The Executive Order on Improving Critical Infrastructure Cybersecurity<\/span><\/a><span style=\"color: #000000\"> (the \u201cOrder\u201d), released on February 12, 2013, has a goal to address cyber threats through a strengthened partnership between the U.S. Government and critical infrastructure owners.\u00a0 To accomplish this goal, the Order:<\/span><\/p>\n<ul>\n<li><span style=\"color: #000000\">\u00a0 Requires the development of new information sharing programs to provide both classified and unclassified threat and attack information to U.S. companies; <\/span><\/li>\n<li><span style=\"color: #000000\">\u00a0 Requires the NIST\u2019s creation of a Framework of cybersecurity practices (\u201cCybersecurity Framework\u201d) to reduce cyber risks to critical infrastructure;<\/span><\/li>\n<li><span style=\"color: #000000\">\u00a0\u00a0Compels agencies to conduct regular assessments of privacy and civil liberties impacts of their activities and to make such assessments available to the public;<\/span><\/li>\n<li><span style=\"color: #000000\">\u00a0 Establishes a voluntary program to promote the adoption of the Cybersecurity Framework, which will provide incentives for companies to comply; and <\/span><\/li>\n<li><span style=\"color: #000000\">\u00a0 Calls for a review of existing cybersecurity regulation. <\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: Times New Roman;color: #000000;font-size: medium\">\u00a0<\/span><\/p>\n<p><span style=\"color: #000000\">What does all of this mean for businesses?\u00a0 For now, it does not mean much since none of the industries covered by the order will actually have to meet the completely voluntary standards.\u00a0 According to <\/span><a href=\"http:\/\/www.huntonprivacyblog.com\/2013\/02\/articles\/obama-administration-releases-long-awaited-cybersecurity-executive-order\/\"><span style=\"color: #0000ff\">Hunton &amp; Williams\u2019 Privacy Blog<\/span><\/a><span style=\"color: #000000\">, the Order could potentially impact businesses in the following ways:<\/span><\/p>\n<p>(1)\u00a0\u00a0 Businesses in the private sector will receive a surge of notifications from the government concerning cyber threats and recommended ways to respond to threats based on a process developed by the Department of Homeland Security (\u201cDHS\u201d).\u00a0 The current DHS process mainly shares classified cyber threats only with defense companies, but under the new Order, information will be shared with other critical infrastructure companies, such as energy companies.<\/p>\n<p>(2)\u00a0\u00a0 Critical infrastructure companies and secondary actors (i.e. insurance companies) will be able to <i>voluntarily<\/i> use the new Cybersecurity Framework to address potential risks.\u00a0 Since participation is completely voluntary, it is likely that DHS will create incentives for companies to comply.\u00a0 An example included in the Order is the call for a review of the federal procurement process to create a preference for vendors who meet the Cybersecurity Framework standards.<\/p>\n<p>(3)\u00a0\u00a0 Certain private sector companies, who if targeted would have a devastating effect, will be named on a list of \u201cCritical Infrastructure at Greater Risk.\u201d \u00a0If added onto the list, companies can request reconsideration of their inclusion on the list.\u00a0 However, this list does not change the fact that compliance with the Framework remains completely voluntary.<\/p>\n<p>Although the new Order appears to be a positive step in the right direction by encouraging information sharing between the public and private sectors, it is unlikely that it is enough to prevent what seems like an inevitable national cybersecurity catastrophe.\u00a0 Congress needs to make the next move fast.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline\">Additional Sources:<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/www.huntonprivacyblog.com\/2013\/02\/articles\/obama-signs-presidential-policy-directive-on-critical-infrastructure-security-and-resilience\/\"><span style=\"color: #0000ff\">http:\/\/www.huntonprivacyblog.com\/2013\/02\/articles\/obama-signs-presidential-policy-directive-on-critical-infrastructure-security-and-resilience\/<\/span><\/a><\/p>\n<p><a href=\"http:\/\/www.huntonprivacyblog.com\/2013\/02\/articles\/observations-on-the-cybersecurity-executive-order-and-presidential-policy-directive\/\"><span style=\"color: #0000ff\">http:\/\/www.huntonprivacyblog.com\/2013\/02\/articles\/observations-on-the-cybersecurity-executive-order-and-presidential-policy-directive\/<\/span><\/a><\/p>\n<p><a href=\"http:\/\/www.bna.com\/president-obama-signs-n17179872423\/\"><span style=\"color: #0000ff\">http:\/\/www.bna.com\/president-obama-signs-n17179872423\/<\/span><\/a><\/p>\n<p><a href=\"http:\/\/www.whitehouse.gov\/sites\/default\/files\/uploads\/07_eo_quotes_02132013.pdf\"><span style=\"color: #0000ff\">http:\/\/www.whitehouse.gov\/sites\/default\/files\/uploads\/07_eo_quotes_02132013.pdf<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Airen Adamonis, Copy Editor\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The United States is currently at war with China.\u00a0 However, this war is not taking place on any battlefields.\u00a0 It\u2019s taking place in cyberspace. \u00a0According to a recent article published by the Washington Post, the United States has been the target of an immense \u201ccyber-espionage campaign\u201d that is threatening the [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[61849],"class_list":["post-1063","post","type-post","status-publish","format-standard","hentry","category-blog-post","tag-blog-post-2"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-h9","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=1063"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/1063\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=1063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=1063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=1063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}