Countermeasures

Senate NDAA helps CISA warn critical infrastructure computer systems of cyberattacks

The U.S. Senate’s 2021 National Defense Authorization Act (NDAA) includes legislation that
would help the Cybersecurity and Infrastructure Security Agency (CISA) warn the owners and operators of critical infrastructure computer systems that it is vulnerable to cyberattacks.

The bill gives CISA a limited authority to detect, identify, and receive information only related to critical infrastructure systems for a cybersecurity purpose. It is designed to give CISA the legal means necessary to notify the owner of the critical infrastructure system who was the subject of the subpoena. Subpoenas must be authenticated by electronic signature so that the internet service provider (ISP) knows it is coming from CISA and has not been fraudulently generated.

CISA must notify the party within 7 days of receiving their information. Further, CISA must destroy personally identifiable information after 6 months.

“When CISA identifies a potential cyber vulnerability in an electrical grid or other critical infrastructure, it cannot always identify the owner of the company in order to alert the company about the vulnerability,” U.S. Sen. Maggie Hassan (D-NH), one of the billʻs sponsors, said. “This commonsense proposal gives CISA the ability to get the information it needs from an Internet Service Provider in order to reach out to critical infrastructure companies to help prevent damaging cyberattacks.”

U.S. Sen. Ron Johnson (R-WI) also introduced the bill, which was cosponsored by U.S. Sens. Angus King (I-ME) and Ron Wyden (D-OR).

The legislation requires CISA to make an annual report to both Congress and the public. The report must detail the number of cybersecurity vulnerabilities that have been mitigated and number of entities that have been warned.

“We ask Americans: if you see something, say something. With this legislation, we are empowering CISA to do the same,” Johnson said.

Dave Kovaleski

Recent Posts

FEMA launches new hurricane season campaign with multicultural messaging on flood risks

The 2024 Hurricane Season Campaign began for the Federal Emergency Management Agency (FEMA) this week,…

7 hours ago

SERVICE Act of 2024 seeks DOJ pilot program, grants for local veteran response teams

As a way to support veterans, U.S. Reps. Maria Elvira Salazar (R-FL), Dale Strong (R-AL),…

7 hours ago

DHS publishes guidelines for securing critical infrastructure and weapons against AI threats

Mere days after the Department of Homeland Security formed a new Artificial Intelligence (AI) Safety…

1 day ago

U.S. Army and European Command awards KBR $771M contract

KBR will continue to provide life support, equipment readiness, training and supply chain solutions for…

1 day ago

Spectrum and National Security Act introduced to modernize spectrum policy, revamp FCC authority

In a bid to update federal spectrum and communications network policy, restore the auction authority…

2 days ago

Department of Homeland Security forms AI Safety and Security Board

As a new means to advise the Secretary of Homeland Security and stakeholders, and promote…

2 days ago

This website uses cookies.