Congress was slow to pass legislation on cybersecurity information sharing. The Cybersecurity Information Sharing Act (CISA) of 2015 followed at least ten years of discussion. Consider the electric power grid and the threats it faces, what are the limitations of the CISA and provide two changes/additions would you recommend?
Answer:-
what are the limitations of the CISA
There are two basic problems with the so-called Cybersecurity Information Sharing Act, which is scheduled for possible amendment in the Senate on Tuesday. The first is everything the bill, generally approved by the Senate last week, does. The second is everything it doesn’t do.
The bill is so obviously badly written—with overly broad, ill-defined language—that the privacy and consumer groups that long have opposed it increasingly are finding allies in tech companies like Apple, Twitter, and Google, which have gone public with their own opposition. (Disclosure: My employer, R Street Institute, is on record as opposing CISA. So are many of my previous employers and colleagues, including the Electronic Frontier Foundation and the Wikimedia Foundation.)
In effect, the bill aims to sidestep search warrants and other pesky due-process limitations on government by giving technology companies a motive to “share” what it calls “cyber threat indicators” to the Department of Homeland Security. S. 754gives tech companies—which receive troves of data from Internet users—huge incentives (like protection from legal liability) for “voluntarily” sharing these potential “cyber threat indicators” with government agencies.
What’s a “cyber threat indicator”? Section 2 of the bill (full text here) offers a definition so broad that it’s hard to be certain, even after multiple rereadings, what this term doesn’t include. It appears to cover any “information” that would “describe or identify” any “method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability.”
This language could apply to anything. Example: I already have lawful access to my own computers. But what if someone writes up a cautionary note about how to delude me, perhaps through a phone call, into voluntarily giving over my passwords to these systems. She then sends it to me by private email so I can check whether she’s right. But if she does so, isn’t she describing or identifying a method to cause me, with my legitimate access, to defeat my own security-control tools? The law would allow Google (my email provider) to voluntarily share that private email with DHS. That seems like a bad, unintended outcome.
And as Robyn Greene of New America’s Open Technology Institute explains in detail, other provisions extend the scope of this new kind of surveillance well beyond “cybersecurity”
CISA and provide two changes/additions would you recommend?
Congress was slow to pass legislation on cybersecurity information sharing. The Cybersecurity Information Sharing Act (CISA)...
everything explain in the last pic i need a summer for the
pags thank u
workforce. [3] Health Care in a Global Context HANDS OFF MY HEALTH CARET The United States is one of the world's only developed nations that does not guarantee universal health coverage for its citizens. (31) In 2005 the United States and the other member states of the World Health Organization signed the World Health Assembly resolution 58.33, [16] which stated that nations should "transition to...
FISCAL POLICY IN THEORY: March, 2020: we are on the verge of Congress and the President passing legislation that will empower the federal government to spend an unprecedented amount of EXTRA money not seen since World War 2 ---- in order to address the pandemic but also to help cushion the blow financially of perhaps ten or twenty million Americans --- or more --- losing their jobs, and thus suffering a drop in income. The scale of the 2020 recession...
Read the case: Netflix Inc.: The Second Act - Moving into Streaming and complete your case analysis. Discuss the following: 1) briefly summarize the key marketing strategy issues in the case that are still relevant TODAY in addition to contemporary issues you find via research; 2) make thorough recommendations on how the issues should be handled; 3) provide a justification for the recommendations. Case write-ups should be 3-5 pages, double spaced, 12 font size in Times New Roman. The case...
Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...
QUESTION 10
Consider the monthly data, including the estimates for March
2020, and the information in the articles. Which of the following
is the best analysis of and prediction for the money market in the
U.S. economy for the next few months?
a.
Shortages are causing panic buying by households, which has
increased money demand. Lenders are increasing their lending to
keep up with the needs of households and businesses. Money demand
is increasing more than money supply.
b.
Shortages...
please answer question 3. Please do take some updated
information about Sears regarding their possible Bankruptcy and
could the data be a tangible asset used for liquidation. Answr
should be at least 2 paragraph.
The shrinkage data, combined with sale and purchase data, has expanded the organization 2009, Sears decided to begin an initiativ closer to its customers. They wanted to achieve objective by implementing Big Data technol However, their IT capabilities were not up to the It is clear...
Below is the information:
It is important to understand the different leadership styles employed by nursing leaders in healthcare organizations and to understand their significance on nursing practice and patient outcomes, for better or for worse. Objective: Read the articles from Nursing Standard (PDF) and Bradley University (PDF). In -250 words, formulate an opinion on the following: 1. Reflect on an occasion where you experienced ineffective leadership (doesn't have to be in the hospital). What behaviors did they display? What...
Case Study 12: Hong Kong Police’s Project Management B Chuah Background In the 1990’s, Hong Kong Police (HKP) was responsible for the public safety and internal security of Hong Kong. She came under the umbrella of the Security Bureau of the Government of Hong Kong. It had more than 34,000 employees, of these, over 26,000 were disciplinary staff. This was the largest department within the hierarchy of the Government of Hong Kong. The organization structure of HKP was rather complicated....
I need help with my very last assignment of this term
PLEASE!!, and here are the instructions: After reading Chapter Two,
“Keys to Successful IT Governance,” from Roger Kroft and Guy
Scalzi’s book entitled, IT Governance in Hospitals and Health
Systems, please refer to the following assignment instructions
below.
This chapter consists of interviews with executives
identifying mistakes that are made when governing healthcare
information technology (IT). The chapter is broken down into
subheadings listing areas of importance to understand...
CASE 8 Unlocking the Secrets of the Apple iPhone in the Name of access the male San Bernardino suspect's iPhone 5c. Cook stated: Antiterrorism We are challenging the FBI's demands with the deepes respect for American democracy and a love of our country. We believe it would be in the best interest of everyone to step back and consider the implications While we believe the FBI's intentions are good, if would be wrong for the w e nt to force...