Cybersecurity Enhancement Act of 2012

Floor Speech

Date: April 27, 2012
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. McCAUL of Texas. Mr. Speaker, I yield myself such time as I may consume.

Mr. Speaker, today Congress has a historic opportunity to lay the groundwork to defend our Nation against cyberattacks. We're not just talking about mischievous online activity, but actions that could bring America to its knees.

Unfortunately, this is not science fiction. America is under attack, not by armies advancing on our beaches or planes overhead, but in the virtual world, where those who intend to do us harm have already penetrated our Federal and private computer networks and continue to plot relentlessly to bring down our critical infrastructure. Our water supply, nuclear facilities, air traffic control systems, electrical grid, and defense and banking systems are all vulnerable to a crippling attack.

General Keith Alexander, Director of the National Security Agency, said it is not a matter of if, but when a cyber Pearl Harbor occurs. We are just simply fortunate that a computer-based attack has not brought physical harm to Americans, but that is not for a lack of trying.

China has already successfully stolen some of our biggest military secrets, such as information about the F 35 Joint Strike Fighter, the Department of Defense's biggest weapons program ever. Now they know the program well enough not only to copy it, but to guard against it. Similar attacks continue unabated on our military's computer systems. Hackers trick soldiers into downloading viruses onto their computers, after which every keystroke is recorded. Mr. Speaker, our military secrets are being stolen every day.

Imagine if agents of a foreign government were breaking into the Pentagon and stealing top secret documents, paper files. It would not be tolerated. It would be all over the front page of The Washington Post. And yet in the virtual world, that is occurring. In fact, the October 2011 Report to Congress on Foreign Economic Collection and Industrial Espionage states it is part of China and Russia's national policy to try to identify and take sensitive technology which they need for their own development. In fact, they train and have a cyberwarfare college.

The degradation of our national security and intellectual property from cybertheft threatens to weaken us where we have historically been strong. The NSA calculates that Russia and China have stolen $1 trillion in American intellectual property, the biggest transfer of wealth in history. Their philosophy is: Why invent when you can steal it?

Besides nation-states, there are groups such as Anonymous, LulzSec, and AntiSec who indulge in nonstate ``hacktivism.'' Their agenda is to bully, embarrass, and steal from those that they disagree with philosophically or politically. They think nothing of closing down Web sites, hacking into email and voice mail, and taking sensitive information from those who don't do their bidding.

There has been a lot of hard work going into this Cyberweek and a lot of thought to find solutions. As cochair of the Center for Strategic and International Studies Commission on Cybersecurity for the 44th President, I helped draft recommendations for securing the country's government networks and critical infrastructures.

As a member of the Speaker's Cyber Task Force and chairman of the House Cybersecurity Caucus, I helped present those recommendations to Congress in the legislation we have seen this week. The historic legislation the House votes on this week incorporates many of these recommendations.

This bill, the Cybersecurity Enhancement Act, gives the National Institute of Standards and Technology the authority to set security standards for Federal computer systems and develop checklists for agencies to follow.

Why is that important?

It hardens our Federal networks. Every Federal agency has been hacked into by agents of a foreign power, by activists. Every Federal agency, including the Pentagon, has been hacked into. This bill will harden those Federal networks and make them less vulnerable to such an attack.

It also creates a Federal/university/private sector task force to coordinate research and development. It establishes cybersecurity research and development grant programs and improves the quality of our cyber workforce by creating a scholarship program.

Importantly, it creates an education and awareness program for computer hygiene. When you talk to the NSA, they tell you that computer hygiene accounts for the majority of cyberattacks. This would remedy the majority of vulnerabilities that we face.

And finally, it sets forth procurement standards for hardware and software that will minimize security risks. This will also have a ripple effect in the private sector so that they will also adopt such procurement standards.

Other legislation we saw that passed yesterday facilitates the sharing of threat information between the public and private sector, which controls most of our critical infrastructure. While it's not part of this bill, I think it's important to make the analogy that what we did yesterday was simply allow the Federal Government to share signature threat information with the private sector, similar to a police officer sharing with a homeowner a threat that they see of someone breaking into their house and then telling them how they can better protect their house and lock the door without the door being opened.

These commonsense reforms are a baseline of what we need to secure our infrastructure. We must take action before life is lost and our economy and defenses have been weakened to the point of damaging our country.

One of the biggest failures after 9/11 was the knowledge that the attacks could have possibly been prevented with better intelligence information-sharing and protective measures. There was also a lack of imagination.

And while we can't change the past, we can use it as a lesson, as we go forward in our modern cyberworld, a world in which our water supply, defense systems, nuclear power plants, electrical grid, banking systems, FAA, and other critical infrastructures are vulnerable to cyberthieves, -attacks, and -terrorists.

We know what has to be done. Mr. Speaker, the time to act is now.

With that, I reserve the balance of my time.

BREAK IN TRANSCRIPT

Mr. McCAUL. Let me just as a point of personal privilege say and give my thanks to the gentleman from Rhode Island (Mr. Langevin), my good friend, colleague, cochair of the Cybersecurity Caucus, for your vision, your leadership on this very, very important issue. As you know and I know, we were very into this issue of cybersecurity 6 years ago, before it was really cool to be into cybersecurity. So thank you so much for your leadership.

With that, Mr. Speaker, I yield 2 minutes to the gentleman from Texas (Mr. Thornberry), my good friend and colleague and also the chairman of the Speaker's Cybersecurity Caucus.

BREAK IN TRANSCRIPT


Source
arrow_upward