Langevin amendment to boost cyber defenses for critical infrastructure wins House approval
Full article821 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The designated entities will be required to report how they manage cyber risk for critical assets.
An amendment that includes cyber protections to defend “systemically important” critical infrastructure — such as large energy utilities, telecom providers and major financial institutions — won adoption in the U.S. House of Representatives Thursday.
The legislation is an outgrowth of the wo rk of the Cyberspace Solarium Commission, which originally recommended a model similar to that envisioned in the bill. It mandates that the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) designate infrastructure needed for “national critical functions,” with operators at designated entities required to report to CISA the national cyber director on their management of cyber risk.
Designation will require organizations to disclose risk management strategies for critical assets and supply chain; share and receive threat intelligence with the government; and allow federal agencies to examine operations and assess performance-based security goals.
Rhode Island Democrat Jim Langevin — a longtime congressional leader on cyber issues who will retire later this year — proposed the language as an amendment to the National Defense Authorization Act. The House approved it by voice vote.
The amendment’s passage “will improve our ability to protect Americans against malicious hackers, and give the private sector the support they need to defend their networks,” Langevin said in a prepared statement.
The amendment’s passage “will improve our ability to protect Americans against malicious hackers, and give the private sector the support they need to defend their networks.”
Rep. Jim Langevin
The legislation limits the number of designations to a total of 200 but allows the Department of Homeland Security to raise that number by 150% after four years. Designated entities will have the ability to appeal for removal from the list.
The U.S. Chamber of Commerce criticized the amendment as written and sent a letter to all House members Wednesday, noting that many businesses’ “core policy goals” are not acknowledged, including legal liability protections and national preemption of state cybersecurity and protection laws.
he legislation’s passage will better protect Americans from devastating cyberattacks, according to Mark Montgomery, the former head of the Solarium Commission, which Congress established in 2019 to develop a plan to defend the U.S. in cyberspace. Montgomery said the commission’s recommendations for ensuring the government and businesses collaborate on cybersecurity have not been as successful as he would like. He called the legislation passed Thursday an important first step.
“Because of their importance to national security, economic viability, public health and safety, [these entities] are most vulnerable to malicious action or adversary cyber attack,” said Montgomery, who now runs the Center on Cyber and Technology Innovation at the think tank the Foundation for Defense of Democracies. “We need to build the ligature of public-private collaboration and we have not achieved some of our major goals there.”
More Scoops
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
Acting director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners.
Time to restore America’s cyberspace security system
National cyber director says U.S. needs to counter Chinese surveillance, push American tech
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/langevin-amendment-cyber-defense/