Instead, what's happening is that policy people in the Administration believe we need extensive further legislation and rulemaking to ensure that computer systems which are in any way "vital to the national interest" are kept "secure", where a final definition of "security" is sure to rest on "XXX hours of $400/person/hour time from a Raytheon or Lockheed subcontractor".
Restated†:
The GOP:
* Wants Government to keep its hands off private networks
* Does not currently see "cybersecurity" as a subject worth increasing Executive power over (possibly a side effect of who controls the Executive)
* Is, true to form, pursuing a policy of finding minimalistic ways of allowing private industry to self-regulate the problem away
* Is marginally more likely than the Democratic Administration to want to concede privacy concerns to private industry and away from end-users in the service of this goal
The Democratic Administration:
* Generally believes itself to be at (undeclared, cold) war with China over information systems
* Believes Government intervention is going to be required to protect utilities, communications, military, and trading exchange networks
* Is marginally more likely than the GOP to want to enact rules regarding information privacy that protect end-users from private industry --- but not from the Government.
The animating concern regarding CISPA to HN readers is privacy. You should be aware that privacy is a third- or fourth- tier concern of both factions in this policy debate. The real concern is: does private industry tackle the "China hacker problem" itself, or does the Government step in?
Excepting that the only mechanism the government has to add security to any network (private, public, or military) is to purchase blocks of Raytheon hours, I don't even disagree with Obama: the security of many networks that are prima facie vital to the public interest are not only a shambles, but continue to degrade in quality as rounds of purchasing and infrastructure upgrades continue to execute without any serious attention given to software security quality. Look at the "Smart Grid" for the most obvious example, but there are more, such as SCADA networks that are "modernizing" into web-based systems with circa-2005 levels of application security. The Administration is not wrong that CISPA doesn't go far enough --- and again: that is the central conflict here, that CISPA does.not.go.far.enough --- but they have no effective mechanisms to bring to bear to improve the situation either. Their vantage point implies a bonanza for giant government contractors like Lockheed and SAIC.
Be careful what you wish for, especially if all your opinions about CISPA came from EFF. For the first time, my perception is that the EFF is running with this CISPA issue not out of genuine concern over policy, but because it's a vehicle for fundraising off Internet rage. And look at the result: stories where the Democratic Administration looks like a white knight. Wow, is that ever the opposite of what's actually happening.
† (and please note I'm a dollars-donating supporter of the Democratic party; I support public schools and believe in single-payer health care --- but party identification is unavoidable here and vital to understanding what is happening)