Is there a digestible explanation of what this CISA entails?
Is there a digestible explanation of what this CISA entails?
The full text is only about 30 pages, and can be found here: https://www.govtrack.us/congress/bills/114/hr2029/text/eah#l...
This is embedded in the "H.R. 2029: Military Construction and Veterans Affairs and Related Agencies Appropriations Act, 2016", which is the vehicle for the Omnibus bill as passed by the Senate yesterday: https://www.govtrack.us/congress/bills/114/hr2029
CISA defines "cybersecurity threats" and "threat indicators", which are now legalese versions of the stuff Intrusion Detection Systems track: exploit code, vulnerability information, and wire traces of attacks.
Everyone already collects this stuff; that's most of what network security teams are paid to do. The government has several huge network security teams (they operate the largest IT system in the world), and, of course, the whole Fortune 500 does as well. All these organizations are collecting information about attacks and siloing it.
CISA requires the government to establish a process to share indicators with private companies. So when analysts or IPS systems or anomaly detection schemes running inside FedGov networks generate a signature for an attack, there will now be federal rules requiring them to submit that data to a process that will disseminate it to the private sector.
CISA allows the private sector to do the same thing in reverse, sharing their data with the government, which will in turn share a facsimile of that data back out to the rest of the private sector. The bill requires companies to have a process to ensure they aren't knowingly sharing any personally identifying information, and they are only allowed to share information that pertains to the types of attacks defined as "cybersecurity threats". Those attacks specifically exclude terms of service violations.
Unlike CISPA, which was a more benign bill, CISA explicitly allows local, state, and federal law enforcement to use threat indicators to prosecute crimes. CISA has a very short list of crimes whose prosecution can be assisted with shared indicators --- identity theft, espionage, and trade secret theft. PCNA, the (now dead) House version of CISA, had a broader list.
Unlike the law of the land before CISPA/CISA/PCNA was proposed, there is now a path for private companies to share data with the USG regardless of the other regulatory regimes they're under. This is good if you think sharing attack information is very important and bad if you think companies that work with regulated information (driving records, credit scores, medical data, student records, &c) should operate under different, stricter rules than other companies. Much of the impetus for these bills was to overcome objections from legal at BigCos that would never allow any information sharing out of fear that such sharing could get them sued. They are now immunized from those suits, so long as they're in good faith sharing only information about actual cybersecurity threats.
That's pretty much it, at a high level. It's a very short bill, just 30 pages, and most of the interesting stuff is in the definitions at the top of the bill. It's worth skimming.
Here's what the bill says you can share, lightly edited:
Data about malicious reconnaissance and recon anomalies, vulnerabilities and exploit code, anomaly events that describe exploit attempts, privilege escalation attempts that bypass security features for post-auth users, malware C&C, documentation of the data exfiltrated by attackers in breaches, and, finally, anything at all related to cyber attacks iff you were already lawfully allowed to share it.
That's it.
The deeper problem is that any piece or amount of information can, in the right circumstances, become personally-identifiable, and so the only guaranteed-safe system would be to forbid collecting or sharing anything. Which would necessarily result in literally turning off the internet.
At the very least, this allows one to quantify the tradeoff of security and specificity in what is released.