# National Cyber security:  Is regulatory legislation the answer (or not) ?

**URL:** <https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768>\
**Category:** Great Debates\
**Created:** [March 7, 2011, 10:17am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768 "2011-03-07T10:17:56Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 7, 2011, 10:17am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/1 "2011-03-07T10:17:56Z")

</div>

I have been reading **‘Cyber War: The next threat to National Security and what to do about it’** by Richard A. Clarke. There are some interesting and compelling points made on the vulnerability of existing computer systems and the ease with which they could be attacked or controlled from external sources, unless the issue of security penetration is seriously readdressed at a joined-up national level. The more advanced a nation, the more fragile it is to this form of attack; the more reliance it has on technology and connectivity, the more it has to lose.

Whilst this may be an ideological issue in terms of approach to public policy, it seems not to be a particularly partisan issue in the politics of reality. The author of the book mentioned above worked as special advisor to Bush 1, Clinton, Bush 2 and advised on the Obama campaign. The current president recently stated that: _“The vast majority of our critical information infrastructure in the United States is owned and operated by the private sector… let me be very clear: My administration will not dictate security standards for private companies”_, so is treading the same anti-regulatory path followed by previous incumbents. Is this the correct approach?

I would assume that anti-regulatory conservatives would prefer the market was left to its own devices and allow private companies the freedom to ascertain for themselves the correct or necessary levels of security required. I would suggest an analogy with this approach is (biological) evolution. Sure, the market may find the most efficient way to exist and perform, but without the foresight of forward planning, it can’t in any way predict or stop the extraordinary, catastrophic event.

I would also speculate that if a cyber attack was launched and the private businesses that own the Nation’s ‘critical infrastructure’ were hit – electricity generation and distribution companies, aircraft flight control, oil and gas lines, water supplies, trains and traffic, financial institutions, and all the other essential public interest utilities and services that are in private company holdings – then it would be government organisations and tax payers’ money that ultimately steps in to clean up the mess. Is, as the cliché goes, prevention not better than cure?

_So, I would frame the debate as thus:_

Should it be the responsibility of government to enact legislation to firmly tighten up regulatory procedures (over private businesses) and enforce the enactment of adequate (and no doubt expensive) cyber security, to ultimately ensure the safety of the general public at large; or…

Should private businesses be left free from such governmental constraints to conduct themselves in the matter they deem appropriate and most realistic to the perceived threats, and let the market ultimately decide what, if anything, is required in this regard (even if the public are left potentially vulnerable)?

Thanks.

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 7, 2011, 11:06am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/2 "2011-03-07T11:06:59Z")

</div>

> [@Aro](#):
>
> Should it be the responsibility of government to enact legislation to firmly tighten up regulatory procedures (over private businesses) and enforce the enactment of adequate (and no doubt expensive) cyber security, to ultimately ensure the safety of the general public at large; or..

No. This is the classic problem with big government getting invoved in things they cannot possibly scope, understand and/or control based on nebulous fear of some bogeyman that’s going to bring an end to life as we know it.

> [@Aro](#):
>
> Should private businesses be left free from such governmental constraints to conduct themselves in the matter they deem appropriate and most realistic to the perceived threats, and let the market ultimately decide what, if anything, is required in this regard (even if the public are left potentially vulnerable)?

Well, they’re not, so that is basically a false premise to the argument that private business is left to themselves in this area. All sorts of legal regulatory information security requirements already exist in various industries. I don’t know if I get what you’re at with the what “if anything” part as far as the public is concerned. You are suggesting concerns about private industry controlling the communications infrastructure. Every company and individual that uses it has a stake. I haven’t been anywhere in the past 10 years (and I’ve been alot of places, BTW) where increased focus on all aspects of computer, systems and communications security was not readily apparent.

The whole cyber scare coming into the public consciousness thing vis-a-vis governmental intervention manifested last year with the infamous Internet kill switch hubbub. I suspect your book was either an offshoot of that or some precursor to it. Either way, I wouldn’t be too worried, at least not until the government tries to get more involved.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 7, 2011, 12:03pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/3 "2011-03-07T12:03:24Z")

</div>

> [@Nadir](#):
>
> _All sorts of legal regulatory information security requirements already exist in various industries_.

Sure, all companies will definitely have some form of security in place, and I’m sure the majority feel they are currently well protected, given the esoteric (or improbable) nature of the threat. But the inherent structure and connectivity of the internet allows the possibility of intrusion to grow as we develop, not diminish. The more technology connects devices, the more we allow remote access for overview and maintenance, for running diagnostics, for convenience sake, the more vulnerable each system becomes to external attack.

> [@Nadir](#):
>
> \*You are suggesting concerns about private industry controlling the communications infrastructure. \*

No, I’ve no inherent issue with private companies being responsible for running and providing essential services. But I would suggest that if experts on cyber security are looking at the existing systems security measures and find there are vulnerabilities that could potentially be exploited by those with malicious intent, and when they point out these facts to the private companies in question but they don’t act or take the concerns seriously, what other path would there be other than to turn to central government to take up the mantle and _impress_ upon the private companies the necessity of plugging the gaps? I may not be the preferred approach, but it may just be a necessary one.

Don’t get me wrong; I’m not remotely an expert on any of this, and haven’t quite made up my mind on what I would personally deem the proper approach, so am open to all arguments and evidence. I’m presenting the case from the author’s perspective, but of course I can’t relay the entirety of the evidence and concerns (of which there are many) listed in the book here. But the issue as presented seems to be more than just a scare-story or a bogeyman fear; there are genuine concerns that need to be addressed, the question is how best to do that?

---

<div class="post-metadata">

**Author:** ![Acid\_Lamp](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@Acid\_Lamp](https://boards.straightdope.com/u/Acid_Lamp)\
**Post date:** [March 7, 2011, 12:15pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/4 "2011-03-07T12:15:39Z")

</div>

Strangely enough, I agree with **Nadir** on this point, though for a differing reason. The Internet is simply too nebulous, quickly evolving, and inconsistent in nature for government to address it in anything but the most general and ultimately ineffective terms. A cutting edge hacker can get what he or she wants if there is a connection. The only solution in this game is continued vigilance and upgrading of hardware and software alike to keep pace. This will be done with reasonable regularity in the private sector anyway simply to keep up.

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 7, 2011, 12:18pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/5 "2011-03-07T12:18:14Z")

</div>

There have always been vulnerabilities. Those vulnerabilities, the n’er-do-wells who try to exploit them and the security people responsible for protecting the resources have all been evolving right along with the systems everything rides on for the past 30-odd years. It’s a never-ending game of cat and mouse.

The real problem these days is the players are becoming extremely sophisticated just as the systems themselves are. State-sponsored groups target the enemy’s military. Illegitimate organizations of all kinds, organized crime, terrorists, what-have-you make money with phishing and spam schemes. Political operatives deface web sites to get their online graffiti exposed. It never ends. But this stuff all relies on the lines staying up and operable. No worries.

The biggest problem I see is disruption in space during a large scale conflict. But that’s another thread.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 7, 2011, 12:45pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/6 "2011-03-07T12:45:51Z")

</div>

> [@Nadir](#):
>
> _Why Take Down the System When EVERYBODY’s Using It?_

No one wants to take down the internet; they recognise it as too good a tool for taking down other potential targets. There is concern that nation states are or have already begun such tactics - such as [Russia’s cyber attack on Georgia.](http://www.zdnet.com/blog/security/coordinated-russia-vs-georgia-cyber-attack-in-progress/1670)

One other example would be when Microsoft, under pressure for sales, gave the Chinese government full access to Windows source code, that no one else has. The Chinese government then tweaked the code to suit their own needs for computers released in the Chinese market (including those used by US companies in China) and potentially within other markets too if they buy computers made in China (and who doesn’t?) This allowed the Chinese government to implement their own backdoor access into others’ systems and to monitor usage, content etc.. leaving any systems using this operating system staggeringly vulnerable and easily manipulated.

Even the integrated and international supply chain and construction of computer components (hardware) and of written code (software) can have many nations and many hundreds of individuals involved in its creation, implementation, manufacture and production. This leaves plenty of opportunities for trapdoors and logic bombs etc.. to be hidden in operating code for future use should they be necessary. Many nations ( well, China & Russia and no doubt the US ) are positioning themselves to leave such access in others’ systems, like sleeper cells. All in the name of hedging bets.

One other issue is that, with the growing sophistication of attacks, many systems won’t even recognise when, of if, they have been hit. It’s not like breaking into a museum and taking a Picasso - files and code can be copied and all trace of the theft covered up and hidden, so no one is even aware of the intrustion.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 7, 2011, 2:05pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/7 "2011-03-07T14:05:25Z")

</div>

For a little bit of background, I had a look at Wikipedia and they have a page - [Cyberwarfare](http://en.wikipedia.org/wiki/Cyber_war) - giving a reasonable overview of the issue under discussion, for anyone interested.

---

<div class="post-metadata">

**Author:** ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)\
**Post date:** [March 7, 2011, 3:42pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/8 "2011-03-07T15:42:33Z")

</div>

> [@Aro](#):
>
> One other example would be when Microsoft, under pressure for sales, gave the Chinese government full access to Windows source code, that no one else has. The Chinese government then tweaked the code…
> 
> …leaving any systems using this operating system staggeringly vulnerable and easily manipulated.

Sounds like Windows, alright. 😃

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 7, 2011, 10:10pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/9 "2011-03-07T22:10:00Z")

</div>

That’ll be the day - when M$ gives anyone full access to anything. :rolleyes:

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 8, 2011, 9:26am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/10 "2011-03-08T09:26:37Z")

</div>

What exactly is it you are rolling your eyes at? That Microsoft wouldn’t give access to their usually protected and proprietary source code, that they certainly wouldn’t give it to the Russians or the Chinese, or just the fact that Microsoft products are so poor that they don’t work well enough to give access to anything?

[China Gets A Peek At Microsoft Source Code](http://www.informationweek.com/news/software/operating_systems/showArticle.jhtml?articleID=225400063)

[Microsoft Gave Windows Source Code to TOPSEC, Which Trains and Employs Chinese Cyberspies](http://techrights.org/2010/12/06/microsoft-topsec-in-china/)

[Leaked US embassy cables: Diplomats fear that China used Microsoft source code for cyber warfare](http://packetstormsecurity.org/news/view/18265/Diplomats-Fear-China-Used-Microsoft-Source-Code-For-Cyber-Warfare.html)

[China uses access to Microsoft source code to help plot cyber warfare, US fears](http://www.guardian.co.uk/world/us-embassy-cables-documents/214462)

> [@](#):
>
> _56. (S//NF) CTAD comment: Additionally, CNITSEC enterprises has recruited Chinese hackers in support of nationally-funded “network attack scientific research projects.” From June 2002 to March 2003, TOPSEC employed a known Chinese hacker, Lin Yong (a.k.a. Lion and owner of the Honker Union of China), as senior security service engineer to manage security service and training. Venus Tech, another CNITSEC enterprise privy to the GSP, is also known to affiliate with XFocus, one of the few Chinese hacker groups known to develop exploits to new vulnerabilities in a short period of time, as evidenced in the 2003 release of Blaster Worm (See CTAD Daily Read File (DRF) April 4, 2008). 57. (S//NF) CTAD comment: While links between top Chinese companies and the PRC are not uncommon, it illustrates the PRC’s use of its “private sector” in support of governmental information warfare objectives, especially in its ability to gather, process, and exploit information. As evidenced with TOPSEC, there is a strong possibility the PRC is harvesting the talents of its private sector in order to bolster offensive and defensive computer network operations capabilities. (Appendix sources 51-52)_

[Does Microsoft’s sharing of source code with China and Russia pose a security risk?](http://www.zdnet.com/blog/security/does-microsofts-sharing-of-source-code-with-china-and-russia-pose-a-security-risk/6789)

> [@](#):
>
> _Moreover, in the context of the Linus’s Law - “Given enough eyeballs, all bugs are shallow“, taking all the geopolitical factors on an international scale into consideration, if Russia or China manage to find a security flaw by having access to the source code offered to them by Microsoft for national security reasons, there’s little to zero possibility that they will go public with it, as the competitive advantage from a cyber warfare/cyber espionage perspective is indisputable._

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 9, 2011, 3:56pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/11 "2011-03-09T15:56:12Z")

</div>

You do of course realize, that our info ops troops have been fighting a cyber war with China for over ten years now, right?

I’m not going to add a rolleyes smiley, except to wonder in print why the cyber world as we know it has not yet ceased to exist.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 10, 2011, 9:20am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/12 "2011-03-10T09:20:55Z")

</div>

> [@Nadir](#):
>
> _You do of course realize, that our info ops troops have been fighting a cyber war with China for over ten years now, right?_

Do you think? I wouldn’t call it a war, regardless of how it might be considered by others. It’s really far short of such a scenario. It’s the usual diplomatic posturing, sword-fencing, _realpolitik_ capers that happens in all fields of endeavour when two nations face-off. Maybe some aspects could be considered battlefield placing of assets in anticipation of their future use, if required, but nothing particularly major has been deployed in attack for or defence of either nation - yet.

There has certainly been industrial espionage, intellectual property theft, spying and strategic positioning of backdoor assets and access points to either enable more of the same or to provide the potential for a vastly ramped up attack should the situation arise that requires it. But no one wants to show their full hand unless the conflict is serious enough to warrant it, as attacks of this nature will generally only work the first time. (Once flaws in systems have been exploited, the gaps will be plugged by defensive teams, so you don’t waste the opportunities you have on the small stuff)

The US has great _offensive_ capabilities in this regard, they could strike back easily, but being able to turn off Chinese Air Defence would really be of limited comfort to US citizens if the PLA have turned off the power in many US cities for weeks, shut down all financial markets and created massive shortages in goods and food by scrambling the routing systems in US railroads. It’s got to be ‘defense first’.

So until the real and obvious vulnerabilities in US _defensive_ systems are fully addressed and considered, the US can never be fully confidence in even holding their own in any cyber exchange again, even with nations with much less conventional capabilities. And this defensive vulnerability can, I would suggest, only be addressed by strict federal regulation, as the private companies in charge of ‘critical infrastructure’ are not willing to pay the money to _properly_ secure them, many believing protection from any external attacks is the responsibility of the DoD to provide.

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 10, 2011, 3:15pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/13 "2011-03-10T15:15:52Z")

</div>

> [@Aro](#):
>
> Do you think? I wouldn’t call it a war…

The Chinese have been actively targeting and exploiting U.S. DoD and corporate information systems for over 10 years. You can call it whatever you want. You don’t seem to have a very good grasp on the various aspects of modern war. It’s not just about killing people people and blowing things up. Our military, industrial and indeed very fabric of life today is heavily dependent on communications and information processing systems of all kinds. If you are just now getting around to worrying about that you must have been asleep for a couple of decades.

The Air Force has a Numbered Air Force (24th) dedicated to offensive and defensive cyber ops. Private enterprise may be more or less focused on information operations and data security functions depending on their reliance on such technology. It’s an ongoing aspect of life on the Internet and the cyber world we live in today. It’s nothing new and nothing to get all worked up about. Certainly nothing calling for legislation, as you naively suggest in this uninformed, alarmist plea to debate.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 10, 2011, 4:31pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/14 "2011-03-10T16:31:25Z")

</div>

> [@Nadir](#):
>
> _The Chinese have been actively targeting and exploiting U.S. DoD and corporate information systems for over 10 years. You can call it whatever you want._

And I will, thanks.

> [@Nadir](#):
>
> _You don’t seem to have a very good grasp on the various aspects of modern war. It’s not just about killing people and blowing things up._

Really? Who knew! My point above, as I’m sure you fully realise, is that the extent of the damage that _could_ be done by exploiting weak system defences is hardly being fully explored (by either side) at the present. It may be difficult to map out a scenario where this could occur, but if there was a full out war situation with Russia or China in the future, then when the gloves are off the damage that could be dealt out would be magnitudes greater than the spying and hacking capers that are currently being undertaken in the low-grade cyber conflict of today. You can call it a war now if you like, but it’s hardly there yet.

> [@Nadir](#):
>
> _Our military, industrial and indeed very fabric of life today is heavily dependent on communications and information processing systems of all kinds. If you are just now getting around to worrying about that you must have been asleep for a couple of decades._

I’m not worried about it at all, as I’m neither involved in cyber security, information processing, secure communications, nor indeed am I American, for that matter. What I am doing is I’m trying to have a civil discussion on this general topic, on a message board. Whereas I get the impression you feel the subject is either too mundane to be worthy of discussion, or too well known that rehashing aspects and approaches to it is a waste of time, which begs the question as to why you are responding at all?

But again, the very heart of my point is that, yes, the entire countries’ infrastructure is heavily reliant on communications, and regardless of what you say, the current systems in place are not secure. Obama’s ideas for upgrading the entire US electricity network to a ‘Smart Grid’ is one example; a great policy idea and could bring better value to consumers, save many billions of dollars, but leaves the entire network extremely vulnerable to attack, without the correct security considerations.

> [@Nadir](#):
>
> _The Air Force has a Numbered Air Force (24th) dedicated to offensive and defensive cyber ops._

They do, and you can read about them in the links I’ve posted earlier. As do the Navy (Fleet Cyber Command), as do the Army (Army Cyber command), but admittedly to a lesser extent. The Air Force, of course, no longer have the lead on the cyber front that they wanted to maintain, as overall command was removed from them and given to [US Cyber Command](http://en.wikipedia.org/wiki/United_States_Cyber_Command) based in Fort Meade, Maryland. Please note they are all military and only charged with protecting military or DoD computer networks, not with any civilian networks (such as the power networks mentioned above) which is predominantly the point of the entire thread.

> [@Nadir](#):
>
> _Private enterprise may be more or less focused on information operations and data security functions depending on their reliance on such technology._

And you seem to think that what private businesses are already doing in this regard is completely enough to secure the critical infrastructure they own and control, whereas you have not in any way shown why you should assume this to be the case.

> [@Nadir](#):
>
> _It’s an ongoing aspect of life on the Internet and the cyber world we live in today. It’s nothing new and nothing to get all worked up about._

I’m not worked up in the slightest, but thanks for your concern regardless. It is the nature of the world we live in, sure, but that doesn’t suggest that we can’t carry on discussing ways to improve things in that world either. If you want to have things secure and remove vulnerabilities that could potentially be exploited, why not discuss it? It’s an important question and merely saying ”_it’s in hand, we have it under control, it’ll all work out”_ is frankly a much more naive approach than what I have been posting here to date. It’s about securing the vital systems, then it’s about gaming out the possible responses to attacks, creating contingency plans, having operations and procedures in place to deal with eventualities etc.. There are plenty of things to discuss without resorting to minor digs and petty '_you don’t know what you’re talking about’_ type insults.

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 10, 2011, 6:05pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/15 "2011-03-10T18:05:22Z")

</div>

> [@Aro](#):
>
> …by exploiting weak system defences …

What is your basis or cite for assuming we have weak system defenses? The book you read?

> [@Aro](#):
>
> …I’m not worried about it at all, as I’m neither involved in cyber security, information processing, secure communications, nor indeed am I American, for that matter.

No kidding? Then why are you insisting there is some theoretical problem calling for legislation?

> [@Aro](#):
>
> … the current systems in place are not secure.

Cite?

> [@Aro](#):
>
> Obama’s ideas for upgrading the entire US electricity network to a ‘Smart Grid’ is one example..

Maybe you should introduce this idea to the leaders of your country. People running the SCADA system in this country have been implementing enhanced security information infrastructure upgrades for years. Obama’s “idea” is nothing new, except possibly to you and him.

> [@Aro](#):
>
> …without the correct security considerations.

Again you assume this must be the case. Cite.

> [@Aro](#):
>
> And you seem to think that what private businesses are already doing in this regard is completely enough to secure the critical infrastructure they own and control, whereas you have not in any way shown why you should assume this to be the case.

You have not shown it not to be the case. Were is the problem?

> [@Aro](#):
>
> It’s about securing the vital systems, then it’s about gaming out the possible responses to attacks, creating contingency plans, having operations and procedures in place to deal with eventualities…

And you believe this is not already being done because of the book you read?

Meh. I work in information security. Sorry, not buying it. Maybe the European Union needs some legislation in this area? No idea what they are doing over there. You seem to have a lot to say about things like the U.S. military, Obama, et al, not being an American, that is. DARPA and U.S. DoD started the Internet back when you probably still wet behind the ears, and we’re doing just fine with it right now, thank you very much.

The book you cite in your opening is just another alarmist left-wing scare-mongering load of rubbish from Clark. Really, it is. Let it go. I’m done here.

---

<div class="post-metadata">

**Author:** ![Aro](https://avatars.discourse-cdn.com/v4/letter/a/b3f665/32.png) [@Aro](https://boards.straightdope.com/u/Aro)\
**Post date:** [March 11, 2011, 10:00am UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/16 "2011-03-11T10:00:19Z")

</div>

> [@Nadir](#):
>
> What is your basis or cite for assuming we have weak system defenses? The book you read?

The book was a starting point, and all the cites contained within the book were also sources of additional information, sure. But it’s not just me, or this one book I mentioned, that is suggesting the defences are not what they should be. See below…

> [@Nadir](#):
>
> Cite?

Okay, here’s a few for you:

[GSA falls short in four critical areas](http://www.infosecurity-us.com/view/14956/gsa-falls-short-in-four-critical-cybersecurity-areas/)

> [@](#):
>
> - The audit noted that “numerous” cybersecurity weaknesses were identified in five GSA systems reviewed by the inspector general. These weaknesses result from “security misconfigurations of database or operating system software”.  
> According to the audit, “these weaknesses included database and operating system software that was not patched or securely configured and lax password management practices for database administrator accounts. As a result, these systems and their sensitive data were placed at an increased risk of inappropriate access, modification, or destruction.”\*

[Lawmakers: US, DoD still not taking Cyber Security seriously](http://www.stripes.com/news/lawmakers-u-s-dod-still-not-taking-cybersecurity-seriously-1.134503)

> [@](#):
>
> \*On Friday, the panel asked more specifically if anyone made progress in determining how the DOD should respond to attacks to the national civilian power grid that could cripple military bases, a top concern for authorities including Vice Adm. Barry McCullough, commander of the Navy’s 10th Fleet, who warned Congress in September.
> 
> “I have to say, I’m afraid many in industry and in government still fail to appreciate the urgency of this threat,” said ranking Democrat James Langevin, of Rhode Island. “Since I began working on this issue, I’ve been disappointed by the overall lack of serious response and commitment to this issue.”
> 
> Many bases have one source of power, Langevin said, with few backup systems, and so would be out of commission weeks or months if a grid attack were successful.
> 
> “I don’t think there’s any question but that [a power grid attack] is a real national security threat that we have to pay attention to,” said CIA Director Leon Panetta, one day earlier, under questioning from the House Permanent Select Committee on Intelligence.\*

[Obama administration falls short on cybersecurity, CSIS report says](http://www.infosecurity-us.com/view/15770/obama-administration-falls-short-on-cybersecurity-csis-report-says/)

> [@](#):
>
> _The United States still lacks an integrated national cybersecurity strategy….The goal for 2011 should be to issue a comprehensive national strategy based on new ideas rather than recycling” the 2003 National Strategy to Secure Cyberspace put out by the Bush administration_…\<snip\>\*
> 
> ..In addition, while the Department of Homeland Security is responsible for defending the civilian government’s cyberspace and the Department of Defense is responsible for the military networks, nobody is responsible for defending the privately owned critical infrastructure networks\*…\<snip\>\*
> 
> …Identifying progress in 2011 will be simple. If the nation passes laws and the administration issues effective regulations for critical infrastructure, there has been progress. These should include mandatory improvements in authentication of identity for critical infrastructure. No regulations mean inadequate progress…\*

[Cyber Security CSIS report](http://csis.org/publication/cybersecurity-two-years-later)

> [@](#):
>
> _2010 should have been the year of cybersecurity. It began with a major exfiltration of data from Google and other Fortune 500 companies, saw the Department of Defense describe how its classified networks had been compromised, watched the Stuxnet worm cut through industrial control systems, and ended with annoying denial of service attacks over Wikileaks. These public incidents were accompanied by many other exploits against government agencies, companies, and consumers. They show how the United States is reliant on, but cannot secure, the networks of digital devices that make up cyberspace. As a nation, we must do more to reduce risk, and we must do it soon._

[White House Scores Low on Cybersecurity Report Card](https://www.infosecisland.com/blogview/11350-White-House-Scores-Low-on-Cybersecurity-Report-Card.html)

> [@](#):
>
> \*The National Security Cyberspace Institute has released a report that examines the White House record on cybersecurity policy over the last two years.
> 
> The grades earned by the Obama administration are mediocre at best, and certainly do not live up to the current challenges facing national cybersecurity in the wake of Aurora, Stuxnet, and WikiLeaks..\*

> [@Nadir](#):
>
> People running the SCADA system in this country have been implementing enhanced security information infrastructure upgrades for years. Obama’s “idea” is nothing new, except possibly to you and him.

The idea of making it more and more interactive is being driven by the current administration. But as you know, this opens up all sorts of new avenues into the control systems: more access points = less secure. It’s not a difficult concept to grasp.

> [@Nadir](#):
>
> You have not shown it not to be the case. Were is the problem?

W_h_ere the problem is, firstly, is assuming everything is just fine and dandy. See some of the concerns above.

> [@Nadir](#):
>
> Meh. I work in information security. Sorry, not buying it.

You’ve very sure you’re that good, eh? Nothing gets past you? You have it all in hand and everyone else is simply crying wolf, being wishy-washy liberal Cassandras? Is it your position that _everything_ that can be done is being done, or simply that what is in place now is _probably_ good enough? No room for improvement?

> [@Nadir](#):
>
> You seem to have a lot to say about things like the U.S. military, Obama, et al, not being an American, that is.

You think I’m not allowed to have an opinion on things American because I’m not American? Please. This is a US-based board, generally things discussed here are related to the US in some way. I happily discuss other things related to other places in the world when on other message boards. Again, if you are uninterested in the topic, feel free to pass the thread by. If you are interested, please feel free to cease the petty insults and snide remarks and address the content instead. As a self-appointed expert, you could always try to _inform_ rather than _insult_, you know?

> [@Nadir](#):
>
> DARPA and U.S. DoD started the Internet back when you probably still wet behind the ears, and we’re doing just fine with it right now, thank you very much.

The internet, albeit funded by DARPA and ARPANET, was really an invention of the left-wing hippy sect based on the campuses of MIT, Stanford and Berkeley, back in the day. And since you know all about the internet, you’ll of course understand that when it was created it was solely for use by well-meaning academics and researchers to exchange ideas, so security was never a consideration, and this basic premise has never been changed. Guys like Larry Roberts who wrote the first transmission codes realised the protocols created an unsecure system, but did not want to slow down the development of the technology. In those days it didn’t matter as it was a small network so it was far easier to simply secure the transmission lines by encrypting links between each computer on the network. With the exponential growth experienced in connections, this is clearly no longer possible, but the same insecurities in the transmission protocols remains. How would you secure that, if at all? I would suggest that for critical systems, such as the power network, there should be NO connectivity to the internet at all.

> [@Nadir](#):
>
> The book you cite in your opening is just another alarmist left-wing scare-mongering load of rubbish from Clark. Really, it is.

So you’ve read it? That’s good to know at least. Because you wouldn’t be so rash as to judge the content based on hearsay or your personal opinion of the author’s credentials now, would you? Clarke, who worked for the State department under Reagan, appointed by Bush I to the counter-terrorism security group, and became Special Advisor to Bush II on cyber-security, a recognised expert in his field who is suddenly berated in the right-wing press for his outspoken remarks against Bush’s bungled handling of the 9/11 attacks and subsequent Iraq war. And his experience has led to holding a position that the only way to safely secure American lives from future cyber attacks is to enforce private companies in charge of critical infrastructure to tighen up their security, and the very use of the word ‘regulation’ makes him a target for right-wing hatred.

But I didn’t want to debate the writing style of the book nor the personal qualities of the author, or I would have posted this in Café Society. So let’s move on and deal with the actual content instead, eh? ( unless of course, you really are ‘done’, then I’ll say goodbye )

---

<div class="post-metadata">

**Author:** ![Nadir](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nadir/32/7302_2.png) [@Nadir](https://boards.straightdope.com/u/Nadir)\
**Post date:** [March 11, 2011, 2:13pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/17 "2011-03-11T14:13:33Z")

</div>

Bye!

---

<div class="post-metadata">

**Author:** ![spazattak](https://avatars.discourse-cdn.com/v4/letter/s/8e8cbc/32.png) [@spazattak](https://boards.straightdope.com/u/spazattak)\
**Post date:** [March 11, 2011, 5:52pm UTC](https://boards.straightdope.com/t/national-cyber-security-is-regulatory-legislation-the-answer-or-not/573768/18 "2011-03-11T17:52:09Z")

</div>

> [@Acid\_Lamp](#):
>
> Strangely enough, I agree with **Nadir** on this point, though for a differing reason. The Internet is simply too nebulous, quickly evolving, and inconsistent in nature for government to address it in anything but the most general and ultimately ineffective terms. A cutting edge hacker can get what he or she wants if there is a connection. The only solution in this game is continued vigilance and upgrading of hardware and software alike to keep pace. This will be done with reasonable regularity in the private sector anyway simply to keep up.

Have you worked in IT in the private sector? Or information security in the private sector? Security and profits are generally two competing ideas. The people in the profession are very dedicated and generally pretty good at what they do - with an amazing ability to get things done on shoe-string budgets (mostly because of the culture of information sharing and open-source products that are available) but that doesn’t change the fact that more often than not, they’re viewed as the janitorial staff.

Now I’m not saying national legislation is the right idea - there are some pretty great public/private partnerships and fantastic security information sharing organizations - but it requires dedicated, knowledgeable staff to take advantage of those opportunities. There’s nothing short of reputation keeping infrastructure companies even close to honest right now.

This isn’t a simple throw-away ‘no’. It’s a complicated topic - and legislation might be a good way to force the hands of some cheap and/or unwilling infrastructure companies - the question becomes - what kind of legislation would be effective if that were pursued?
