National Cybersecurity and Critical Infrastructure Protection Act

Floor Speech

Date: July 28, 2014
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. THOMPSON of Mississippi. Mr. Speaker, I am pleased to be here today as an original cosponsor of this legislation, the National Cyber Security and Critical Infrastructure Protection Act.

This bipartisan legislation gives the Department of Homeland Security Congressional Authority to more fully carry out its civilian cyber mission, and to increase protection for our national critical infrastructure.

Importantly, this legislation also gives the Committee on Homeland Security a robust oversight position to make sure the Department carries out an innovative and cooperative relationship with industry, to protect the nation's privately owned critical infrastructure.

By giving DHS specific civilian authorities, it codifies what the President has already set into motion with his Cyber Executive Order 13636, issued in February of 2013, but Executive Authority goes only so far, and the President has said that his efforts cannot take the place Congressional action.

Mr. Speaker, we have stepped up to the plate. The legislation that Mr. MCCAUL and I worked on together, directs Federal agencies and private industry to coordinate the development and implementation of voluntary risk-based security standards, and codifies the ongoing process that the National Institute of Standards and Technology (NIST) and private industry have taken on.

We are asking that business and government find an adaptable and cooperative cyber security framework, for both government and private companies, not an off-the-shelf, or check-the-box solution.

We must depend on strong private sector leadership and accountability to focus on our nation's most pressing cyber vulnerabilities, protecting critical systems that when disrupted could cause catastrophic damage to our citizens. I believe this legislation will allow that process to move forward.

The President said it best, ``It is the policy of the United States to enhance the security and resilience of the Nation's critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy and civil liberties.''

Critical infrastructure provides the essential services that underpin American society, and I suggest that the owners and operators of America's critical infrastructure are in a unique position to manage their own business risks with the help of civilian government agencies, to develop operational approaches that can make our critical infrastructure protected and durable.

Mr. Speaker, I have worked long and hard with the chairman to hammer out privacy and liability concerns held by myself, and many others, on both sides of the aisle.

There are no broad exceptions to the current privacy laws in this legislation, and it focuses on information sharing using existing structures. In fact, the ACLU commended the construction of this legislation by saying, ``..... it is both pro-security and pro-privacy .....''

We still have much work to do to achieve a higher level of cyber security in this country, and internationally.

We must approach the cyber threat arena in a way that is consistent with traditional American values, and by leading on the issue of respecting personal privacy in the efforts to achieve cyber security, we must continue to respect the safeguards for our constitutional right of freedom of speech.

The wrong way is to assume that we must cede all of our personal privacy and freedoms to remain safe.

BREAK IN TRANSCRIPT


Source
arrow_upward