National Cybersecurity Protection Advancement Act of 2015

Floor Speech

Date: April 23, 2015
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. Chairman, I support this bipartisan language that will help clarify language in both the Homeland Security Act and this bill by narrowing the definition of the word ``incident'' to ensure that a cybersecurity incident is limited to actions taken against an information system or information stored on that system.

This amendment ensures that information shared with the NCCIC or other private entities is limited to threats to and actions against information systems and information stored on that system.

I also want to thank the gentleman from California (Mr. McClintock) for being a leader on this issue and for calling this loophole, if you will, to the attention of the committee to make this a stronger bill on this floor.

BREAK IN TRANSCRIPT

Mr. Chairman, I support this amendment, which would clarify that the term ``cybersecurity risk'' does not apply to actions solely involving violations of consumer terms of service or consumer licensing agreements.

This amendment will protect consumers from having information shared with the government due to a minor or unwitting violation of the terms of service, such as a violation of one's Apple iTunes agreement, which my teenage daughters would appreciate.

This amendment and this bill are meant to enhance the sharing of cybersecurity information within the government and the public. In order to promote voluntary sharing, the public needs to feel confident that the sole act of violating a terms of service or licensing agreement won't be shared with the NCCIC and that this bill is not a tool to enforce violations regarding terms of service or licensing agreements. These violations have robust legal remedies in place and should be handled through those channels.

I think this strengthens the bill, and I appreciate the gentleman's amendment to do so. I support this amendment.

BREAK IN TRANSCRIPT

Mr. Chairman, I support this amendment, which establishes the National Cybersecurity Preparedness Consortium, consisting of university partners and other stakeholders who proactively coordinate to assist State and local officials in cybersecurity preparation and the prevention of cyber attacks.

The amendment directs the Cybersecurity and Infrastructure Protection Directorate to update curriculum for first responders, provide technical assistance where possible, and conduct simulations and other training to help State and local officials be better prepared for cyber attacks.

The amendment directs the consortium to consist of academic, nonprofit, and government partners to deliver the best training possible, which will further advance the overall goal of H.R. 1731, to strengthen the resiliency of Federal and private networks and, thus, protect the data of the American people more effectively.

BREAK IN TRANSCRIPT

I support this amendment, which would authorize and codify the current EINSTEIN Program operated in the Department of Homeland Security.

The EINSTEIN Program, as deployed, makes available the capability to protect Federal agency information and information systems. The Einstein Program includes technologies to diagnose, detect, prevent, and mitigate cybersecurity risks involving Federal information systems.

I would also like to thank my colleague and fellow chairman, Mr. Chaffetz, of the Oversight and Government Reform Committee for working with the Committee on Homeland Security on this important issue.

BREAK IN TRANSCRIPT

The report required by this amendment would provide a quantifiable tool for the transparency, accountability, and oversight of Americans' civil liberties, and it will address privacy concerns.

Privacy is a hallmark of H.R. 1731, and any opportunity to highlight to the American people how well DHS is protecting their civil liberties, while strengthening the cyber resilience of our Federal and non-Federal networks, is a welcome endeavor.

The report will provide data on how well the program is working, and it will potentially identify any areas of improvement, which will further strengthen the robustness of DHS' cyber information-sharing practices.

BREAK IN TRANSCRIPT

Mr. Chairman, I support this enhancement that allows the Secretary of Homeland Security to consult with stakeholders and to submit a report on how best to align federally funded cybersecurity research and development activities with private sector efforts to protect privacy and civil liberties, while assuring the security and resilience of the Nation's critical infrastructure.

The promotion of research and development activities to design resilient critical infrastructure that includes cyber threat infrastructure and that also includes cyber threat consideration in its plan is important as we build the fences against the cascading effect of cyber attacks on critical infrastructures.

BREAK IN TRANSCRIPT

The gentleman from New York is correct regarding the nature of the threat. However, the activities he has discussed were authorized by Congress last Congress with a bill that I sponsored. In addition, the bill currently before the House strengthens those provisions.

This bipartisan bill passed out of committee unanimously. This motion is nothing more than an eleventh hour attempt to bring down the bill that we worked so hard on to get to this point where we are today.

Mr. Speaker, people always ask me what keeps me up at night. In addition to the kinetic threats posed by al Qaeda and ISIS, it is a cyber attack against our Nation that concerns me the most.

This legislation is necessary to protect Americans. Every day, America is under attack. Our offensive capabilities are strong, but our defensive capabilities are weak. The attacks on Target and Home Depot stole the personal information and credit cards of millions of Americans.

The cyber breach at Anthem compromised the healthcare accounts of 80 million individuals, impacting one out of every four Americans in the most private way. North Korea's destructive attack on Sony attempted to chill our freedom of speech. Russia and China continue to steal our intellectual property and conduct espionage against our Nation.

General Alexander described this as ``the greatest transfer of wealth in history.''

At the same time, Iran attacks our financial sector on a daily basis in response to the sanctions. We also face a growing threat from cyberterrorists, like the ISIS sympathizers who hacked into USCENTCOM's social media account.

Terrorists and state sponsors of terror, like Iran, want nothing more than to carry out a destructive cyber attack to bring things down in the United States, including our power grids.

This bill protects our Nation's networks, both public and private, by removing legal barriers to the sharing of threat information.

The bill is voluntary. It is both proprivacy and prosecurity and has widespread support from industry. It allows us to obtain the keys for information sharing, to lock the door, and to keep these nation-states and criminals out. We cannot send a signal of weakness to our adversaries.

Many, Mr. Speaker, refer to the threat of a cyber Pearl Harbor. My father, part of the Greatest Generation, was a bombardier in a B-17 during World War II. He participated in the air campaign in advance of the D-day invasion against the Nazis.

Today a new generation faces different threats to our national security, and we must protect America in this new frontier. We now live in a new threat environment where digital bombs can go undetected and cause massive devastation. This bill will defend America from these attacks.

Inaction today, Mr. Speaker, would be nothing short of reckless. It is urgent that we pass this bill today, for if Congress fails to act and the United States is attacked, then Congress will have that on its hands.

BREAK IN TRANSCRIPT


Source
arrow_upward