Once again, lawmakers are using a year-end spending bill to pass the year’s most significant technology legislation.
Whereas last year the Federal IT Acquisition Reform Act (FITARA) was included in the National Defense Authorization Act, this year the Cybersecurity Act of 2015 — also known as the Cybersecurity Information Sharing Act (CISA) — is part of the 2016 omnibus spending package.
MORE: Full text of 2016 spending package
The final cybersecurity bill merges parts of the Senate-passed CISA and two bills that passed the House earlier this year, relying mostly on language from the National Cybersecurity Protection Advancement Act crafted by the House Committee on Homeland Security.
Legislators had been conferencing on a merged bill since late October and proponents in both chambers wanted to see the final version pass before the end of the year. With time running out and Congress facing a potential government shutdown, including the final version in the yearly spending bill was the only option.
The bill codifies an information-sharing framework by which the government and private industry can share data about known cyber threats in real time (or near real time, depending on who you ask), bolstering the security posture for both sectors.
The Department of Homeland Security will take the lead collecting and disseminating the information, as appropriate, as well as managing the creation of Information Sharing and Analysis Organizations (ISAOs). DHS has already awarded a grant to set up the standards by which the ISAOs will operate.
The measure is hardly a cure-all for the cybersecurity threat but can help organizations stay on top of emerging attack vectors, shining light on new zero-days as they pop up.
The legislation also includes mandates to strengthen government cybersecurity — both around information-sharing efforts and detection and response across all federal agencies — and bolster the cyber workforce.




