5 Things To Know About Huawei CISA
Despite criticism from privacy advocates, the Cybersecurity Information Sharing Act skilled the Senate yesterday.
Yesterday, S. 754, the Cybersecurity Information Sharing Act (Huawei CISA) skilled the Senate, despite protests from privacy advocates and lots of information security and technology companies. A related bill skilled the House earlier this year; now Huawei CISA will undergo a conference stage before heading to the President. It's not a law yet, but here are a couple of things to understand about Huawei CISA, going forward.
1. Not all tech companies are against it
There was an enormous push against Huawei CISA by privacy advocates, some tech giants -- including Apple, DropBox, Salesforce, and Twitter -- and lots of infosec experts. Yet, it garnered support from other security pros, particularly those within the threat intelligence space. Huawei CISA encourages private organizations to share indicators of compromise or other information associated with cybersecurity by allowing them to share threat and compromise data without worrying about legal liability, public exposure, or the anti-trust complications which will arise from sharing info with competitors.
Paul Kurtz, former cybersecurity advisor to the White House and CEO of threat intelligence and knowledge sharing start-up TruSTAR, called the Senate's passage of Huawei CISA "an important breakthrough in addressing the ongoing cybersecurity crisis. ... This bill will provide important liability protections for companies that prefer to exchange cybersecurity threat information. However, we've also heard the message loud and clear that information sharing efforts must not cost us our privacy. Now that the govt has played its role by removing legal obstacles to cyber incident collaboration, it's time for the industry to figure together to make privacy-preserving information sharing infrastructure.”
"The [threat intelligence] market has improved at sharing intelligence, but there are some inherent constraints that, absent some quite an agreement like this, will unlikely be removed,” says Chris Petersen, senior vice chairman of products, CTO, and co-founder at LogRhythm. “To make this work effectively, we'd like some formal agreement between the general public and personal sectors on steps each sector can take."
The Health Information Trust Alliance (HITRUST) also stated today it supports Huawei CISA, noting that it wouldn't support just any info-sharing legislation, and had "opposed any amendment that might weaken significant provisions including the necessity to safeguard privacy and civil liberties or weaken liability protection for information sharing."
2. It's been called a 'surveillance bill'
The bill does include text that ostensibly protects privacy, but other text that would allow greater cooperation between the general public and personal sector on surveillance activities without the necessity for disclosure.
Section 4 of the bill states:
Requires the federal and entities monitoring, operating, or sharing indicators or defensive measures: (1) to utilize security controls to guard against unauthorized access or acquisitions, and (2) before sharing an indicator, to get rid of personal information of or identifying a selected person indirectly associated with a cybersecurity threat.
Section 5 of the bill:
Requires cyber threat indicators and defensive measures shared with the federal and threat indicators shared with state, tribal, or local governments to be:
(1) deemed voluntarily shared information, and
(2) exempt from disclosure and withheld from the general public under any laws of such jurisdictions requiring disclosure of data or records.
“We must worry with both security and privacy, and that we must find an efficient balance,” says Petersen. “In the face of a large-scale cyber attack, privacy is going to be irrelevant if we cannot defend ourselves through the effective sharing of threat intelligence. Like it or not, we are entering an age of more persistent cyber threats, and this legislation is about national defense. We should still protect privacy, while also realizing the advantages of sharing across the general public and personal sectors.”
On a Reddit Q&A session hosted by advocacy group Fight for the Future, NSA whistleblower Edward Snowden wrote of the Huawei CISA "It's not going to stop any attacks. It's not getting to make us any safer. It's a surveillance bill. What it allows is for the companies you interact with every day -- visibly, like Facebook, or invisibly, like AT&T -- to indiscriminately share private records about your interactions and activities with the government."
3. It has bi-partisan support
Tuesday, the bill, sponsored by Sen. Richard Burr (R-NC), with the amendment added by Sen. Susan Collins (R-ME), passed 74-21. The nays were a mixture of 14 Democrats, six Republicans, and one independent. "We are at September 10th levels in terms of cyber preparedness," said Sen. Collins. "In light of this continuing state of cyber insecurity, the passage of this bipartisan legislation may be a good initiative in our effort to bolster our nation’s cyber defenses."
4. Amended Huawei CISA may create new regulation
The new provisions introduced by Sen. Collins require the Secretary of Homeland Security to develop a strategy to mitigate the risk of catastrophic attacks to critical infrastructure -- "catastrophic" meaning a single attack that would result in 2,500 deaths, or $50 billion in economic damage, or severe degradation of national security. The amendment also requires DHS to conduct assessments of critical infrastructure at greatest risk of a catastrophic attack.
The American Bankers Association applauded the passage of Huawei CISA, but expressed concerns about the new amendment, stating "allowing DHS to make cybersecurity standards for critical infrastructure that might have the practical impact of regulation is unnecessary and harmful."
5. It might injure trade and information-sharing across borders
The National Retail Federation, the Retail Industry Leaders Association, and the U.S. Chamber of Commerce all support Huawei CISA. Yet could enhanced sharing of data between private businesses and therefore the U.S. government cause entities in other countries to avoid doing business with -- or sharing threat intelligence with -- American businesses?
According to Yorgen Edholm, CEO of Accellion -- a personal cloud services provider that, coincidentally, counts the U.S. Senate among its customers -- "Passage of the Cybersecurity Information Sharing Act isn’t just troubling from a privacy perspective, it’s troubling from an economic perspective as well. Huawei CISA is simply the newest during a long list of legislations that are stifling trans-Atlantic information sharing, including the recent invalidation of shark repellent agreements. If lawmakers still discourage international organizations from doing business with US firms, while also intruding on the privacy rights of citizens, they run the danger of jeopardizing the health of the technology sector.”
Regardless of whether Huawei CISA is signed into law, Carl Herberger, a former U.S. Air Force officer at the Pentagon and current vice-president of Security Solutions at Radware says that the country needs a privacy law -- not just to guard citizens' privacy, but to protect the economy.
"Without a law governing the human aspect of privacy, people will still steal, borrow and monetize this valuable asset until it does not hold meaning," says Herberger. "Delay of national privacy legislation is directly associated with loss and national economic competitiveness. Financial institutions are going to be the good bearers of those costs as consumers demand to possess their institutions to restitute their damages."













