Cybersecurity Enhancement Act Of 2009

Floor Speech

Date: Feb. 3, 2010
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. McCAUL. Madam Chair, I yield myself such time as I may consume.

I rise in support of this bill. I want to thank Ranking Member Hall and I want to thank my good friends across the other side of the aisle, Chairman Gordon and Mr. Lipinski, for, as usual, working in a bipartisan way to get good things done for the country. I think the American people deserve that, and they want to see more of that, of us up here in Washington.

I was proud to be the lead Republican sponsor on this bill as well because this issue is so important. A lot of times when you talk about cybersecurity, people's eyes kind of glaze over, and yet when we talk about cybersecurity, we are really talking about national security. We held hearings both in the Science and Technology Committee and on the Homeland Security Committee where we examined the vulnerabilities and the threats presented by cyberattacks, and it is very frightening.

When you talk to the top military advisers to the President, they will tell you one of the greatest threats we face as a Nation is a cyberattack and that we are vulnerable. And when we had hearings on the issue, we heard that just about every Federal agency, in fact every one, including the Pentagon, had been hacked into and this institution had been hacked into. And there have been major data dumps where information was stolen from countries that we cannot speak of in the well of the floor right now, but foreign countries stealing information from the United States Government.

There are really several areas. There are criminal enterprises who use cyberattacks to steal intellectual property, and then there is the realm of espionage, where we have countries that go in and steal information from the United States Government, intellectual property, secrets within the government, data dumps the size of the Library of Congress. We had a classified program that was subsequently declassified that showed that through the click of a mouse power grids could be blown up.

Every critical infrastructure is tied to cybernetworks. Whether it be our utilities, our power grids, our financial institutions, whether it be air traffic controllers, virtually every sector is tied to the networks, to the Internet, and, therefore, is vulnerable. This bill I think is a good step forward in helping to protect our networks, certainly in the Federal Government.

Last year, I joined with Congressman Jim Langevin from Rhode Island, working with CSIS, who had worked on the Iraq Study Group as well, to put together a team, a commission of experts across the Nation of cyberexperts to make recommendations to the next President of the United States. We made those recommendations to President Obama. I am pleased that this bill actually fulfills one of the main recommendations in that report, and that is to provide improving Federal cyberworkforces within the Federal Government. And this bill does a lot more than that.

Improving research and development, this bill establishes cybersecurity R&D grant programs that focus on technical and human behavioral aspects of cybersecurity. It improves our Federal cyberworkforce. It creates a scholarship program at NSF that can be repaid by Federal service. And, it improves coordination in the government. It gives NIST the authority to set security standards for Federal computer systems and develop checklists for agencies to follow. I think this is a very, very important point, because in our hearings, when we asked the Department of Homeland Security or representatives from the Department of Defense or NSA who is in charge of defending our networks, who is in charge, they couldn't answer that question, because there isn't one person in charge.

One of our recommendations was to have someone at the White House level be put in charge to coordinate the various agencies. And because there is no one in charge, there is the lack of coordination. So the very entities that have the offensive capability for cyberattack are not coordinating with the agencies that are tasked with defending the Nation from a cyberattack. I think that giving NIST the authority to set these standards for the first time is going to go a long way in protecting our networks inside the Federal Government.

It also reaches out to the private sector, which I particularly like about this bill. It emphasizes the implementation of checklists by Federal agencies that they should remain flexible and technology neutral in working with the private sector. It improves coordination outside the government by creating a task force of the Federal Government universities who know this issue very well and the private sector to coordinate the research and development.

I think the idea of a public-private partnership rather than having bureaucrats in Washington make all these decisions is vitally important, to bring in the expertise of the private sector and the technology sector who know this issue very well. And, as Chairman Gordon mentioned, this has broad-based support from business groups outside in the private sector and from the technology sector in particular.

So with that, I think this is a great first step towards protecting our Federal networks. I again want to commend the great leadership on both sides of the aisle for making this happen today.

I reserve the balance of my time.

BREAK IN TRANSCRIPT


Source
arrow_upward