U.S. should immunize big data transfers during disasters, attacks
Full article732 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Companies that share customers' personal data with federal agencies during a natural disaster or major cyber or terror attack would get legal immunity under a "good Samaritan framework," called for in a draft report to the Obama administration.
Companies that share customers’ personal data with federal agencies during a natural disaster or major cyber or terror attack would get legal immunity under a ‘good Samaritan framework,’ called for in a draft report to the Obama administration.
The National Security Telecommunications Advisory Committee, a telecom industry body, said, ‘The framework should afford standard agreed upon protections to entities sharing data in good faith’ during such a major incident.
‘The framework should pre-establish general rules between the Government and the participating private sector organizations to define the appropriate use of [such shared] data’ states the report, titled NSTAC Report to the President on Big Data Analytics.
Specifically, the framework ought to ‘clarify rules regarding the protection of privacy, data use, ownership, storage, retention, accidental disclosure, and deletion.’
NSTAC’s 21 members are meeting Wednesday in Palo Alto, California, to approve the draft, which will then be formally submitted to the White House. The committee, meeting in Silicon Valley for the first time, will be briefed by Cabinet-level officials including Commerce Secretary Penny Pritzker, Homeland Security Secretary Jeh Johnson and Defense Secretary Ash Carter — all part of the administration’s effort to cross-fertilize some of the valley’s legendary innovation into the sometimes creaky edifice of the federal government.
Addressing the huge volumes of data now available through online devices, the report notes that many newer smartphones and tablets feature ‘advanced sensors such as high definition microphones, text, cameras, accelerometers, barometers, and more.
‘In the future — depending on data agreements between the State government, local law enforcement, and mobile phone carriers — some jurisdictions may have the ability to enable callers to share situational data with [911] operators when a user places an emergency call.’
This ‘data exhaust’ could be crucial to authorities seeking to assess a major incident. ‘To have the full potential of these technological advancements, it is critical to develop the needed frameworks for data sharing,’ the report states.
Big data analysis, or BDA, might also be able to thwart terrorist planning and preparation for an attack in the homeland, the report states, echoing the intent of the controversial Pentagon project in the aftermath of Sept. 11 dubbed Total Information Awareness.
In their hypothetical ‘use case,’ the reports authors envisage that the terrorist planners sometimes use oblique or coded, though unencrypted, messaging — including through social media.
By the time the planners are ready to launch their attack, ‘there is a significant amount of disjointed information contained in a variety of data sources that point to an eminent [sic] threat … This is the first pivotal point for BDA to play a substantial role in preventing the event.’
By the time the day of the attack arrives, ‘BDA processes have identified a potential threat and collection of meaningful data intensifies. Correlation of travel itineraries, car rentals and credit card purchases can possibly pinpoint the targeted locations and the individuals that have been dispatched to each location.’
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/u-s-should-immunize-big-data-transfers-during-disasters-attacks-report/