"Good morning and welcome. We are here today to examine the private sector's experience working with the National Institute of Standards and Technology (NIST) to develop and utilize the "Framework for Improving Critical Infrastructure Cybersecurity," and also to look forward to additional steps that can be taken to help improve our nation's cybersecurity.
"No country, company, or consumer is immune to cybersecurity threats. The United States faces a growing array of threats from hackers, criminals, terrorists, and nation-states who seek to gain access to sensitive or classified information. This also includes efforts to steal intellectual property or consumers' personal information, deny the availability of normally accessible online services, or potentially sabotage the networks and control systems of critical infrastructure.
"While cyber threats are not new, we saw a number of notable cyber events last year. In 2014, security flaws such as Sandworm, Shellshock, POODLE, and Heartbleed compromised millions of servers and systems. Attacks on point of sale systems sent ripples through the retail industry, not to mention the significant cyber hack on Sony Pictures.
"In 2014, after a decade without passage of major cybersecurity legislation, Congress passed five cybersecurity bills that were signed into law. I am especially pleased that our Committee's work on the Cybersecurity Enhancement Act of 2014, which I worked on with former Chairman Rockefeller was one of those bills the President signed into law.
"Our Committee's bill ensures the continuation of a voluntary and industry-led process for identifying cybersecurity standards and best practices for critical infrastructure -- codifying elements of the successful process that NIST undertook to create its Cybersecurity Framework, and ensuring NIST's continued involvement in this public-private collaboration.
"The law also included important provisions for research and development, workforce development, and increased public awareness. It will help to protect the public and private sectors against the growing number of cyber threats from around the world by, among other things, strengthening and directing better cooperation across Federal agencies in research and development, improving our test beds and cloud computing security, and authorizing the National Science Foundation's successful Cybercorps scholarships.
"I am proud to note that Dakota State University in my home state is a leading institution of higher education in the area of cybersecurity. I appreciate that Dr. Josh Pauli, an Associate Professor of Cyber Security at DSU, has provided written remarks discussing that work, and I will submit that as part of the record.
"I called today's hearing primarily to hear from stakeholders about their experience with the NIST Framework. Released almost one year ago, the Framework provides a common language regarding security issues to facilitate discussions within a company between the technical IT security managers and senior management. While the Framework targets organizations that own or operate critical infrastructure, businesses across all sectors may find use of the Framework beneficial.
"The success of the Framework thus far is due in large part to NIST's collaborative relationship and engagement with the private sector. As a non-regulatory agency dedicated to promoting U.S. innovation and industrial competiveness in ways that enhance economic security, NIST has been a genuine partner and has successfully combined its technical expertise in standards with the know-how of the private sector to help advance the nation's technology infrastructure.
"Congress is now tasked with important questions about what actions the federal government should take next, including:
o How do we assess the effectiveness of the Framework going forward?
o What incentives do businesses and consumers need to improve their cyber defenses?
o What type of cyber threat information sharing legislation is needed to help industry defend against more sophisticated cyber attacks?
o What should we do to better secure our supply chain?
o And what more can be done in related areas?
"These questions are relevant to both the private and public sectors. According to the U.S. Government Accountability Office, "Federal agencies have significant weaknesses in information security controls " Last year, I along with Senator Rockefeller sent letters to every agency under our committee's jurisdiction asking targeted questions about the measures being taken to protect systems using unsupported operating systems, as well as compliance with the Federal Information Security Management Act. As Chairman, I will be continuing to conduct such oversight of agencies' information security management.
"While I am pleased that Congress took a positive step to improving our cybersecurity posture by passing a number of bills in December, I believe an absolutely necessary missing piece for this Congress is finally passing legislation to spur greater cyber threat information sharing. It is my hope that the Senate can find a path forward in this area soon. The hearing being held today underscores the seriousness of the threat and our commitment to passing information sharing legislation that did not get done last Congress."