What Were Congress's Cybersecurity Priorities?

134 views
β€’
February 26, 2020
by
RSAC Cybersecurity
YouTube video player
What Were Congress's Cybersecurity Priorities?

TL;DR

Congress prioritized election security, the federal cyber workforce, stronger CISA operations, clearer national leadership, and better protection for federal networks and critical infrastructure. Committee staff also emphasized cloud security, assistance for state, local, tribal, and territorial governments, small-business support, supply-chain concerns, and closer coordination between government and the private sector.

Transcript

All right. Hey, good morning everybody. Uh, my name is Sean Jamison, I work for RSA, and we are here this morning to talk to the congressional view of cybersecurity priorities in the 116th Congress. The panel discussion will be facilitated by Norma Krayem, the vice president chair of Cybersecurity and Data Privacy Practices Group at Van Scoyoc Asso... Read More

Key Insights

  • Cybersecurity is one of the policy areas where bipartisan congressional support remained strong, according to the moderator. The relevant House and Senate committees had been active in advancing bills and addressing operational, workforce, election, infrastructure, and federal-network security issues.
  • Election security was a sustained priority for the House Homeland Security Committee across the 115th and 116th Congresses. The Senate minority also emphasized protecting election systems, addressing foreign influence through social media, and ensuring state and local governments had adequate resources.
  • CISA administrative subpoena authority was a leading Senate majority proposal. The legislation would enable CISA to contact critical-infrastructure owners and operators when it identified potential vulnerabilities, giving those organizations an opportunity to investigate and address weaknesses in their systems.
  • Federal cyber workforce policy focused on identifying barriers that prevent people from entering government service. Committee staff also considered ways to make movement between government and industry easier, because experience on both sides could improve institutional understanding and future communication.
  • National cybersecurity leadership was viewed as insufficiently clear. Chairman Johnson's concern was that responsibilities were distributed across agencies with different legal authorities, leaving uncertainty about who would provide strategic leadership at the White House level during a significant cyber incident.
  • Federal cybersecurity oversight included the Continuous Diagnostics and Mitigation program and FedRAMP. The Senate committee examined how agencies secure federal networks and the .gov domain, as well as how the government's transition to cloud services could proceed with appropriate security.
  • State, local, tribal, and territorial governments needed both cybersecurity resources and useful information. Congressional work also examined how the federal government could assist small businesses that might lack the full set of resources required to defend themselves from cyberattacks.
  • Public-private coordination was presented as a strategic cybersecurity priority. Committee staff acknowledged that information-sharing initiatives had produced mixed results and sought additional ways to combine government authorities with the private sector's insights and capabilities more effectively.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What cybersecurity issues did the 116th Congress prioritize?

The priorities described by congressional committee staff included election security, the federal cyber workforce, CISA's operational effectiveness, federal network protection, cloud security, and strategic leadership during major incidents. They also discussed cybersecurity resources for state, local, tribal, and territorial governments, assistance for small businesses, critical-infrastructure vulnerabilities, foreign influence campaigns, and stronger cooperation between government and the private sector.

Q: How would administrative subpoena authority help CISA?

Administrative subpoena authority would allow CISA to contact critical-infrastructure owners and operators after identifying potential vulnerabilities in their systems. Those organizations could then take action to examine and address the identified weaknesses. Senate majority staff characterized this activity as part of CISA's responsibility as the nation's risk advisor and said the related legislation was expected to advance through a committee markup.

Q: Why was election security a congressional cybersecurity priority?

Election security received sustained attention because the 2020 election was approaching and state and local governments needed resources to protect election systems. Committee staff distinguished between foreign influence conducted through social media and direct cybersecurity threats to election infrastructure. Their work included supporting state and local authorities and coordinating with CISA as it worked with communities responsible for election administration.

Q: What cybersecurity workforce problems was Congress examining?

Congress was examining barriers that made it difficult for cybersecurity professionals to enter the federal workforce. Committee staff planned to review existing federal policies, initiatives, and executive orders to identify the most important obstacles. They also explored making movement between government and industry easier, reasoning that experience in both environments could improve mutual understanding, communication, and the government's overall cybersecurity capability.

Q: Who should lead the federal response to a major cyber incident?

The panel did not name a specific official who should lead every major cyber incident. Instead, Senate staff identified unclear strategic leadership as a problem requiring attention. Different agencies properly controlled separate cybersecurity responsibilities because of their laws and authorities, but the committee wanted clarity about who at the White House level or above could coordinate those participants during a significant incident.

Q: How was Congress overseeing federal cybersecurity programs?

The Senate Homeland Security and Governmental Affairs Committee was examining programs that protect federal networks and the .gov domain. Its oversight included Continuous Diagnostics and Mitigation and FedRAMP, along with the government's move to cloud services and the security of that transition. This work reflected the committee's broad jurisdiction over federal cybersecurity operations as well as non-federal critical-infrastructure partnerships.

Q: How could the federal government support smaller governments and businesses?

Congressional staff considered how to provide state, local, tribal, and territorial governments with the resources and information needed to improve cybersecurity. They also examined federal policy tools that could assist small businesses, which might not possess the complete resources needed to defend themselves against cyberattacks. CISA's work in communities was presented as an important part of this broader support structure.

Q: How could government and industry improve cybersecurity cooperation?

Government and industry could improve cooperation by moving beyond existing information-sharing efforts and finding additional ways to use their respective authorities, insights, and capabilities together. Senate staff acknowledged that previous information-sharing initiatives had both strengths and weaknesses in practice. Their strategic objective was a closer public-private relationship that could strengthen cybersecurity across critical infrastructure and other non-federal systems.

Summary & Key Takeaways

  • Cybersecurity remained an area of bipartisan congressional activity during the 116th Congress. The House Homeland Security Committee focused on election security, workforce needs, and recommendations from the Cyber Solarium Commission, while the Senate committee pursued legislation and oversight intended to improve federal capabilities, clarify responsibilities, and strengthen national cybersecurity coordination.

  • The Senate majority highlighted proposed administrative subpoena authority for CISA. The authority would allow CISA to contact critical-infrastructure owners and operators after identifying potential system vulnerabilities, enabling those organizations to address the issues. The committee viewed this capability as consistent with CISA's role as the nation's risk advisor and operational partner.

  • Federal priorities included oversight of Continuous Diagnostics and Mitigation, FedRAMP, cloud migration security, and workforce mobility between government and industry. Non-federal priorities included election systems, state and local resources, small-business assistance, foreign influence campaigns, and cooperation with critical infrastructure. Panelists also sought clearer strategic leadership during significant cyber incidents.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š