Obama signs executive order to boost critical infrastructure security

President Obama signed an executive order on Feb. 12 that seeks to better protect the nation's critical infrastructure from cyber intrusions through increased information sharing and the joint development and implementation of a framework of shared cybersecurity practices between government and industry.

The executive order, "Improving Critical Infrastructure Cyber Security, which coincided with Obama's State of the Union address, follows on the heels of failed efforts by Congress in 2012 to pass comprehensive cybersecurity legislation. President Obama's executive order was widely anticipated and seeks to provide intermediate measures to protect critical infrastructure against cyberattacks from hostile actors that are increasing in number and frequency.

Obama acknowledged in his State of the Union address the growing threat that the United States faces from cyberattacks, citing how hackers steal people's identities and infiltrate private e-mail. He also mentioned that foreign countries hostile to the United States are systematically stealing corporate secrets through hacking.

"Now our enemies are also seeking the ability to sabotage our power grid, our financial institutions, and our air traffic control systems," Obama said. "We cannot look back years from now and wonder why we did nothing in the face of real threats to our security and our economy."

He said that the new executive order "will strengthen our cyber defenses by increasing information sharing, and developing standards to protect our national security, our jobs, and our privacy."

In concluding his remarks on cybersecurity, the president called on Congress to act on the matter "by passing legislation to give our government a greater capacity to secure our networks and deter attacks."

Congressional action on cybersecurity is required for many reasons, including liability protections that require statutory authority and are not covered by an executive order.

The executive order instructs the National Institute of Standards and Technology to develop a baseline framework to reduce cyber risk to critical infrastructure. The framework will include voluntary security standards for critical infrastructure companies.

The Homeland Security Department will coordinate participation by the Energy Department and solicit industry input to develop a program to assist companies in implementing the cybersecurity framework and in identifying incentives for its adoption.

The executive order also calls for expanding the Defense Industrial Base Information Sharing Program to include additional critical infrastructure companies. The order expands the voluntary Enhanced Cybersecurity Services program, thereby enabling near real-time sharing of cyber threat information to assist participating critical infrastructure companies in their cyber protection efforts.

The order also requires federal agencies to share unclassified reports of threats with U.S. companies in a timely manner.

Reader Comments

Thu, Feb 14, 2013 ThaiLawForum Bangkok

What’s worse – the President’s blatant disregard for the First Amendment and a free press, his violation of the separation of powers in bypassing Congress and signing the decree into law, or the privacy-attacking cyber security policy itself? Here's what we thought about the general lack of constitutionality in all of this: http://www.thailawforum.com/blog/obama-signs-unconstitutional-exec-order-on-cyber-security

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

Webcast

  • Improving Performance Management and Project Control to Meet Cost/Schedule Milestones in DoD Procurement

    It can be nearly impossible to build annual budgets that consider forecasted project and program work plans along with detailed cost data, particularly when attempting to reconcile actual and projected program costs with actual schedule performance. In this webcast, a defense IT program manager will share best practices and hard-won lessons aligning critical data on project performance, cost systems and schedules for truly big picture program management insight. Read more