Cybersecurity will be a focal point of President Barack Obama’s State of the Union address Tuesday, including a proposal to standardize how private companies share and report information on cyber crime.
Many states already have legislation on the books requiring companies to report breaches in which sensitive customer information is leaked. Legislation being proposed by the administration would create a single federal statute governing how and when information on cyber attacks must be released, intended to ease confusion in the private sector.
The administration is also planning to create private-sector Information Sharing and Analysis Organizations (ISAOs) to manage threat reporting and disseminate important information and offer limited liability protection to companies that participate.
“It’s very important that this legislative proposal moves forward,” said Mike Brown, vice president and general manager of global public sector for RSA. “A legislative proposal is necessary to bring clarity,” particularly to information sharing and breach notifications.
Brown noted several cybersecurity bills passed the House and Senate during the lame duck session, providing some hope for bipartisan movement this year.
“I’m more optimistic because a lot of the leadership, both Democrats and Republicans understand cybersecurity is important,” he said, confident that legislation will make it out of committee. “We have to work through all the details but with the risk the private sector has seen, these things resonate. For the majority, it’s something that is a need, something industry has called for.”
Some 70 percent of private sector cybersecurity professionals agree or strongly agree with the president’s proposal, according to a survey by the Information Systems Audit and Control Association (ISACA).
Corporate reputation was the biggest concern among those polled (40 percent), though a few also cited cost (17 percent) and infrastructure (17 percent) as potential roadblocks.
“Federal leaders must quickly agree on clear, simple and straightforward cybersecurity legislation and regulations, as threats and attacks are the new modern-day conflicts,” ISACA said. “To that end, we must have a business and IT workforce that is trained to prevent and respond to such attacks.”
Along with breach reporting, the administration has asked for grants to bolster cybersecurity education, particularly at America’s historically black colleges.
Vice President Joe Biden announced Thursday plans to provide $25 million in grants over the next five years, spread across 13 colleges and universities and two national laboratories.




