New Bill Would Put DHS In Charge of 'Critical' Private Networks
GovTechGuy writes "A new bill unveiled Wednesday by House Homeland Security chairman Bennie Thompson (D-Miss.) would give the Department of Homeland Security the authority to enforce federal cybersecurity standards on private sector companies deemed critical to national security. The Homeland Security Cyber and Physical Infrastructure Protection Act of 2010 authorizes DHS to establish and enforce risk and performance-based cybersecurity standards on federal agencies and private sector companies considered part of the country's critical infrastructure. Such firms include utilities, communications providers and financial institutions."
Considering how much a lot of those companies rely on their network infrastructure, if there isn't a provision for this then perhaps the alternative is to be prepared to take over the whole organization if/when they are crippled by an attack. I am not one for heavy handed government but someone needs to light the fire under these guys.
Why do I have a sneaking suspicion that this law will be applied WAY more often to fight torrent sites than it will ever be used to fight actual terrorists?
SJW: Someone who has run out of real oppression, and has to fake it.
If anyone is going to do this, it should be the NSA, not DHS. Why, you ask, would I trust a military agency over DHS?
1) The NSA is regulated by DoD regulations which prevent it from working as a domestic law enforcement agency.
2) The NSA can very rarely share information with law enforcement because its methods are not legally admissible in most court cases (and they're not supposed to be, since the NSA's purpose is to support the military and operations abroad where civilian courts don't even have jurisdiction in many scenarios).
3) The NSA actually knows what it's doing with its own infosec, unlike DHS.