A set of export controls, intended to promote transparency and greater responsibility in the exports of weapons systems and other technologies, poses a risk of compromising cybersecurity, according to a Department of Homeland Security official in testimony before a joint House subcommittee hearing.
A 41-member group called the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies developed and agreed to the controls in 2013. In January, a joint hearing of the House Oversight and Government Reform Committee’s IT Subcommittee and the Homeland Security Committee’s Cybersecurity, Infrastructure Protection and Security Technologies Subcommittee examined the impact of the measures.
Phyllis Schneck, deputy under secretary for cybersecurity and communications at DHS, told the panel that the rapid evolution of technology could conflict with the export controls in ways that hamper U.S. cyber protection efforts.
“Technology is evolving at a faster pace than ever before,” reads her written testimony. “Our adversaries are also changing rapidly, and are constantly developing new tools and attacks to compromise critical networks, steal data and potentially damage our physical infrastructure. In this environment, it is essential for cybersecurity researchers and developers to share information rapidly across borders in the interest of creating the next security solution of combating an emerging risk.”
Schneck acknowledged that some of the risks the controls are intended to reduce, such as surveillance tools and intrusion software, are also cybersecurity concerns. “But such examples also exemplify why we must support improved cybersecurity,” she said.
The risk posed by the export controls is a slowdown in cross-border development efforts, she said. “[I]n implementing that control, we need to avoid unintended consequences to cybersecurity. In a threat environment where our adversaries continue to gain in sophistication, we cannot afford to unduly constrain development of the next generation of cybersecurity solutions.”




