Big Data. Big Decisions
InformationWeek
Special Coverage Series


CEOs Voice Support For Cyber Legislation, With Caveats

Senate report indicates many Fortune 500 CEOs support comprehensive cybersecurity legislation that increases information sharing, but only if sharing is voluntary.

Fortune 500 CEOs widely support cybersecurity legislation that increases voluntary information sharing between the private sector and the federal government, according to a survey by Sen. Jay Rockefeller, D-W.Va.

Sen. Rockefeller had written a letter to Fortune 500 CEOs in September asking for their views on federal cybersecurity policy. In a memo released Wednesday, the majority staff for the Senate Committee on Commerce, Science and Transportation summarized the more than 300 responses to Rockefeller's letter in a memo.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"Nearly every company that provided a thorough response expressed support for more robust, two-way cyber threat information sharing, with greater access to security clearances to ease the process," the memo said. However, while "many" companies supported a voluntary information sharing regime, many also expressed concerns about mandatory, inflexible or duplicative cybersecurity standards.

[ Which tech initiatives should Obama prioritize in his next term? Read 5 Items Should Top Obama's Technology Agenda. ]

Despite broad language expressing support for comprehensive cyber legislation that focuses on elements like information sharing, lack of detailed statistics in the Senate memo means it remains unclear exactly how much support and concern exists among respondents to Rockefeller's letter.

Rockefeller was among a group of senators pushing to pass comprehensive cybersecurity legislation in 2012. That bill, which was amended to strip out mandatory information-sharing programs, was nonetheless blocked by Republicans in the Senate in August after vocal opposition to the bill from lobbying groups like the Chamber of Commerce.

A debate over whether comprehensive cybersecurity legislation should include mandatory standards for private sector companies had been one of the sticking points for passage of the legislation through part of 2012.

On January 23, Rockefeller and six fellow Democratic senators introduced the 2013 version of the legislation: the Cybersecurity and American Cyber Competitiveness Act of 2013. In introducing the legislation, Rockefeller said that he saw an "opportunity to reach needed consensus" on cyber legislation during this Congress. The current version of Rockefeller's legislation includes no mandate.

According to the memo, " very few companies" surveyed expressed "outright opposition" to the 2012 bill, and "only a subset" of those companies' views aligned with the Chamber of Commerce's opposition, which expressed concern even about voluntary information sharing. Rather, "many" companies favored voluntary information sharing, including use of the program to develop best practices, conduct risk assessments and identify critical infrastructure.

There was less support, however, for the prescription of a single set of inflexible best practices, especially if those practices would be disruptive to current regulatory compliance. A number of companies worried that mandatory standards would lead to additional costly "check the box" compliance, negatively impact innovation and fail to keep up with the rapid pace of change in the cyber world.

Among the choice -- though anonymous -- quotes from Fortune 500 CEOs:

-- "We agree that collaborative efforts between government and business are essential in undertaking the significant challenges related to cybersecurity, much like partnerships we currently have for disaster response and recovery," said one national retail chain CEO.

-- "Congress [should] continue working to pass cybersecurity legislation that will advance risk management practices, strengthen the protection of critical cyber infrastructure and enhance appropriate information sharing of actionable information concerning cyber threats," said a Fortune 100 tech CEO.

-- "[My company] is concerned that 'voluntary' will lead to 'regulated,' resulting in precious resources being diverted away from active threat management to compliance-based activities," said one Fortune 100 energy CEO.

In a statement accompanying the staff memo, Rockefeller said that the CEOs' responses "will be a great resource as we refine much-needed cybersecurity legislation to improve and deepen the collaboration between our government and private sector."

While Rockefeller might express optimism about his bill this year, the Chamber of Commerce retains its opposition, which could again gum up the legislative process and potentially scuttle this year's bill. However, even if Congress fails or is unable to react, the White House has been preparing an executive order that could put in place a number of cybersecurity and information-sharing policies even without new legislation.

Offensive cybersecurity is a tempting prospect. It's also way too early to go there. Here's what to do instead. Also in the new, all-digital Nuclear Option issue of InformationWeek: Military agencies worldwide are figuring out the tactics and capabilities that will be critical in any future cyber war. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.