Statements on Introduced Bills and Joint Resolutions

Floor Speech

Date: June 10, 2010
Location: Washington, DC

BREAK IN TRANSCRIPT

Ms. COLLINS. Mr. President, I rise to join Senators LIEBERMAN and CARPER in introducing the Protecting Cyberspace as a National Asset Act of 2010. This vital legislation would fortify the government's efforts to safeguard America's cyber networks from attack. It would build a public/private partnership to promote national cyber security priorities. It would strengthen the government's ability to set, monitor compliance with, and enforce standards and policies for securing Federal civilian systems and the sensitive information they contain.

The marriage of increasingly robust computer technology to expanding and nearly instantaneous global telecommunications networks is a truly seismic event in human history. This information revolution touches everything, from personal relationships and entertainment to commerce, scientific research, and the most sensitive national security information. Cyberspace is a place of great, even unparalleled, power.

But, to tweak the familiar saying, with great power comes great vulnerability. Cyberspace is under increasing assault on all fronts: cyber vandalism, cyber crime, cyber sabotage, and cyber espionage. Across the world at this moment, computer networks are being hacked, probed, and infiltrated relentlessly. The purpose of these cyber exploits ranges from simple mischief and massive theft to societal mayhem and geopolitical advantage.

In February, Dennis Blair, the former Director of National Intelligence, gave this chilling assessment before the Senate Select Committee on Intelligence:

``Malicious cyber activity is occurring on an unprecedented scale with extraordinary sophistication. While both the threats and technologies associated with cyberspace are dynamic, the existing balance in network technology favors malicious actors, and is likely to continue to do so for the foreseeable future.''

Consider these sobering facts:

Cyber crime costs our national economy nearly $8 billion annually.

Hackers can operate in relative safety and anonymity from a laptop or desktop anywhere in the world. The expanding capabilities of wireless hand-held devices strengthen this cloak of cyber invisibility.

As our national and global economies become ever more intertwined, cyber terrorists have greater potential to attack high-value targets. From anywhere in the world, they could disrupt telecommunications systems, shut down electric power grids, or freeze financial markets. With sufficient know-how and a few keystrokes, they could cause billions of dollars in damage and put thousands of lives in jeopardy.

As the hackers' techniques advance, the number of hacking attempts is exploding. Just this March, the Senate's Sergeant at Arms reported that the computer systems of Congress and Executive Branch agencies now are under cyber attack an average of 1.8 billion times per month.

Recent examples of cyber attacks are myriad and disturbing:

Press reports a year ago stated that China and Russia had penetrated the computer systems of America's electrical grid. The hackers allegedly left behind malicious hidden software that could be activated later to disrupt the grid during a war or other national crisis.

At about the same time, we learned that, beginning in 2007 and continuing well into 2008, hackers repeatedly broke into the computer systems of the Pentagon's $300-billion Joint Strike Fighter project. They stole crucial information about the Defense Department's costliest weapons program ever.

In 2007, the country of Estonia was attacked in cyberspace. A 3-week onslaught of botnets overwhelmed the computer systems of the nation's parliament, government ministries, banks, telecommunications networks, and news organizations. This attack on Estonia is a wake-up call that has yet to be sufficiently heeded.

The private sector is also under attack. In January, Google announced that attacks originating in China had targeted its systems as well as the networks of more than 30 other companies. The attacks on Google sought to access the email accounts of Chinese human rights activists. For the other companies, lucrative information, such as critical corporate data and software source codes, were targeted.

Last year, cyber thieves secretly implanted circuitry into keypads sold to British supermarkets, which were then used to steal account information and PIN numbers. This same tactic was used against a large supermarket chain in Maine, compromising more than 4 million credit cards.

Nor are small businesses immune. Last summer, a small Maine construction firm found that cyber crooks had stolen nearly $600,000 through an elaborate scheme involving dozens of coconspirators throughout the United States.

These attacks, and the hundreds like them that are occurring at any given time whether on our government or private sector systems, have ushered us into a new age of cyber crime and, indeed, cyber warfare. They underscore the high priority we must give to the security of our information technology systems.

The terrorist attacks of September 11, 2001, exposed the vulnerability of our nation to catastrophic attacks. Since that terrible day, we have done much to protect potential targets such as ports, chemical facilities, transportation systems, water supplies, government buildings, and other vital assets. We cannot afford to wait for a ``cyber 9/11'' before our government finally realizes the importance of protecting our digital resources, limiting our vulnerabilities, and mitigating the consequences of penetrations of our networks.

Chairman Lieberman and I have held a number of hearings on cyber security in the Senate Homeland Security and Governmental Affairs Committee. Senator Carper has been similarly active, particularly on exploring modifications to the Federal Information Security Management Act that are designed to enhance protections of Federal networks and information.

From our examinations of this issue, we know that there are threats to and vulnerabilities in our cyber networks. We also know that the tactics used to exploit these vulnerabilities are constantly evolving and growing increasingly dangerous. Now, it is time to take action. A strong and sustained Federal effort to promote cyber security is a key component of effective deterrence.

For too long, our approach to cyber security has been disjointed and uncoordinated. This cannot continue. The United States requires a comprehensive cyber security strategy backed by aggressive implementation of effective security measures. There must be strong coordination among law enforcement, intelligence agencies, the military, and the private owners and operators of critical infrastructure.

This bill would establish the essential point of coordination. The Office of Cyberspace Policy in the Executive Office of the President would be run by a Senate-confirmed Director who would advise the President on all cyber security matters. The Director would lead and harmonize Federal efforts to secure cyberspace and would develop a national strategy that incorporates all elements of cyber security policy, including military, law enforcement, intelligence, and diplomacy. The Director would oversee all Federal activities related to the national strategy to ensure efficiency and coordination. The Director would report regularly to Congress to ensure transparency and oversight.

To be clear, the White House official would not be another unaccountable czar. The Cyber Director would be a Senate-confirmed position and thus would testify before Congress. The important responsibilities given to the Director of the Office of Cyberspace Policy related to cybersecurity are similar to the responsibilities of the current Director of the Office of Science and Technology Policy.

The Cyber Director would advise the President and coordinate efforts across the Executive Branch to protect and improve our cybersecurity posture and communications networks. By working with a strong operational and tactical partner at the Department of Homeland Security, the Director would help improve the security of Federal and private sector networks.

This strong DHS partner would be the National Center for Cybersecurity and Communications, or Cyber Center. It would be located within the Department of Homeland Security to elevate and strengthen the Department's cyber security capabilities and authorities. This Center also would be led by a Senate-confirmed Director.

The Cyber Center, anchored at DHS, with a strong and empowered leader, will close the coordination gaps that currently exist in our disjointed federal cyber security efforts. For day-to-day operations, the Center would use the resources of DHS, and the Center Director would report directly to the Secretary of Homeland Security. On interagency matters related to the security of federal networks, the Director would regularly advise the President--a relationship similar to the Director of the NCTC on counterterrorism matters or the Chairman of the Joint Chiefs of Staff on military issues. These dual relationships would give the Center Director sufficient rank and stature to interact effectively with the heads of other departments and agencies, and with the private sector.

Congress has dealt with complex challenges involving the need for interagency coordination in the past with a similar construct. We have established strong leaders with supporting organizational structures to coordinate and implement action across agencies, while recognizing and respecting disparate agency missions.

The establishment of the National Counterterrorism Center within the Office of the Director of National Intelligence is a prime example of a successful reorganization that fused the missions of multiple agencies. The Director of NCTC is responsible for the strategic planning of joint counterterrorism operations, and in this role reports to the President. When implementing the information analysis, integration, and sharing mission of the Center, the Director reports to the Director of National Intelligence. These dual roles provide access to the President on strategic, interagency matters, yet provide NCTC with the structural support and resources of the office of the DNI to complete the day-to-day work of the NCTC. The DHS Cyber Center would replicate this successful model for cyber security.

As we have seen repeatedly, from the financial crisis to the environmental catastrophe in the Gulf of Mexico, what happens in the private sector does not always affect just the private sector. The ramifications for government and for the taxpayers often are enormous.

This bill would establish a public/private partnership to improve cyber security. Working collaboratively with the private sector, the Center would produce and share useful warning, analysis, and threat information with the private sector, other Federal agencies, international partners, and state and local governments. By developing and promoting best practices and providing voluntary technical assistance to the private sector, the Center would improve cyber security across the nation. Best practices developed by the Center would be based on collaboration and information sharing with the private sector. Information shared with the Center by the private sector would be protected.

With respect to the owners and operators of our most critical systems and assets, the bill would mandate compliance with certain risk-based performance requirements to close security gaps. These requirements would apply to vital components of the electric grid, telecommunications networks, financial systems, or other critical infrastructure systems that could cause a national or regional catastrophe if disrupted.

This approach would be similar to the current model that DHS employs with the chemical industry. Rather than setting specific standards, DHS would employ a risk-based approach to evaluating cyber vulnerabilities, and the owners and operators of covered critical infrastructure would develop a plan for protecting those vulnerabilities and mitigating the consequences of an attack.

These owners and operators would be able to choose which security measures to implement to meet applicable risk-based performance requirements. The bill does not authorize any new surveillance authorities or permit the government to ``take over'' private networks. This model would allow for continued innovation and dynamism that are fundamental to the success of the IT sector.

The bill would provide limited liability protections to the owners and operators of covered critical infrastructure that comply with the new risk-based performance requirements. Covered critical infrastructure also would be required to report certain significant breaches affecting vital system functions to the center. These reports would help ensure that the Federal Government has comprehensive awareness of the security risks facing these critical networks.

If a cyber attack is imminent or occurring, the bill would provide a responsible framework, developed in coordination with the private sector, for the President to authorize emergency measures to protect the Nation's most critical infrastructure. The President would be required to notify Congress in advance of the declaration of a national cyber emergency, or as soon thereafter as possible. This notice would include the nature of the threat, the reason existing protective measures are insufficient to respond to the threat, and the emergency actions necessary to mitigate the threat. The emergency measures would be limited in duration and scope.

Any emergency actions directed by the President during the 30-day period covered by the declaration must be the least disruptive means feasible to respond to the threat. Liability protections would apply to owners and operators required to implement these measures, and if other mitigation options were available, owners and operators could propose those alternative measures to the Director and, once approved, implement those in lieu of the mandatory emergency measures.

The center also would share information, including threat analysis, with owners and operators of critical infrastructure regarding risks affecting the security of their sectors. The center would work with sector-specific agencies and other Federal agencies with existing regulatory authority to avoid duplication of requirements, to use existing expertise, and to ensure government resources are employed in the most efficient and effective manner.

With regard to Federal networks, the Federal Information Security Management Act--known as FISMA--gives the Office of Management and Budget broad authority to oversee agency information security measures. In practice, however, FISMA is frequently criticized as a ``paperwork exercise'' that offers little real security and leads to a disjointed cyber security regime in which each Federal agency haphazardly implements its own security measures.

The bill we introduce today would transform FISMA from paper-based to real-time responses. It would codify and strengthen DHS authorities to establish complete situational awareness for Federal networks and develop tools to improve resilience of Federal Government systems and networks.

The legislation also would take advantage of the Federal Government's massive purchasing power to help bring heightened cyber security standards to the marketplace. Specifically, the Director of the Center would be charged with developing a supply chain risk management strategy applicable to Federal procurements. This strategy would emphasize the security of information systems from development to acquisition and throughout their operational life cycle.

While the Director should not be responsible for micromanaging individual procurements or directing investments, we have seen far too often that security is not a primary concern when agencies procure their IT systems. Recommending security investments to OMB and providing strategic guidance on security enhancements early in the development and acquisition process will help ``bake in'' security. Cyber security can no longer be an afterthought in our government agencies.

These improvements in Federal acquisition policy should have beneficial ripple effects in the larger commercial market. As a large customer, the Federal Government can contract with companies to innovate and improve the security of their IT services and products. With the Government's vast purchasing power, these innovations can establish new security baselines for services and products offered to the private sector and the general public.

Finally, the legislation would direct the Office of Personnel Management to reform the way cyber security personnel are recruited, hired, and trained to ensure that the Federal Government and the private sector have the talent necessary to lead this national effort and protect its own networks. The bill would also provide DHS with temporary hiring and pay flexibilities to assist in the establishment of the center.

Some have suggested that this effort can be led from the White House alone--why create a new center at DHS and two Senate-confirmed Director positions? One of the great lessons of 9/11 is that true security demands aggressive oversight, expert evaluation, and thorough testing of systems. There must be constant, real-time monitoring of security and analysis of threats. This task requires much more than a cyber czar. It requires strong civilian counterparts to the Secretary of Defense and the Director of National Intelligence. These Directors, at the White House and at DHS, would serve as those counterparts.

The National Security Agency and other intelligence agencies possess enormous skills and resources, but privacy and civil liberties demands preclude these agencies from shouldering a leadership role in the security of our civilian information technology systems. The intelligence community must play a critical part in providing threat information, but it cannot lead the cyber security effort.

We are all acutely aware that there are those who seek to do harm to this country and to our people. If hackers can nearly bring Estonia to its knees through cyber attacks, infiltrate our military's most closely-guarded project, and, in the case of Google, hack the computers owned and operated by some of the world's most successful computer experts, we must assume even more spectacular and potentially devastating attacks lie ahead.

We must be ready. It is vitally important that we build a strong public-private partnership to protect cyberspace. It is a vital engine of our economy, our government, our country and our future. I urge my colleagues to support this crucial legislation.

BREAK IN TRANSCRIPT


Source
arrow_upward