Cybersecurity: What About U.S. Policy?

Cybersecurity: What About U.S. Policy?
复制标题

网络安全:美国政策怎么样?

DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
L. Trautman
L. Trautman
中科院分区:
--
文献类型:
--
作者:
L. Trautman

文献摘要

被引文献

相似文献

2014年12月,就在假期休会前几个小时,美国国会通过了五项旨在加强美国网络安全的主要立法提案。在总统签署后,这些法律成为自2002年联邦信息安全管理法案通过以来十多年来颁布的第一部网络安全法律。我的目标是以高度可读性的方式探讨网络安全政策这个异常复杂的主题。与最近致命的全球埃博拉疫情的类比被用来说明政策挑战,希望这将有助于将网络安全的技术语言转变为更容易理解的故事。就像埃博拉病毒一样,网络威胁有能力让我们的城市陷入停滞。许多网络安全政策的影响与埃博拉病毒造成的影响惊人地相似。首先,简要叙述了网络攻击的严重危险和潜在后果。其次,我评论了技术复杂性的快速变化以及许多高级商业和政府领导人相对不熟悉计算机所造成的政策影响。第三,讨论了选定的相互竞争的网络安全选民群体的特点:消费者;投资者;执法部门;企业;联邦、州和地方政府;以及国家安全利益。通过探索这些不同群体的感知需求以及有时相互冲突的行动,我希望为有关网络政策的全国对话做出有价值的贡献,并在应对新的科技病毒大流行方面取得有意义的进展。接下来,是对过去十年左右取得的最新政策发展里程碑的审查,包括在2014年底通过了几项旨在加强美国网络安全的主要立法提案:2014年的《国家网络安全保护法》;2014年的《联邦信息安全现代化法》;《网络安全劳动力评估法》;《国土安全劳动力评估法》;以及《2014年网络安全增强法案》。最后,鉴于迫切需要对网络安全采取立即和有效的协调办法,本文提出了一些关于制定政策目标和战略的想法。希望这篇文章将有助于政策制定者今天就这一重要话题进行的对话。
During December 2014, just hours before the holiday recess, the U.S. Congress passed five major legislative proposals designed to enhance U.S. cybersecurity. Following signature by the President, these became the first cybersecurity laws to be enacted in over a decade, since passage of the Federal Information Security Management Act of 2002. My goal is to explore the unusually complex subject of cybersecurity policy in a highly readable manner. An analogy with the recent deadly and global Ebola epidemic is used to illustrate policy challenges, and hopefully will assist in transforming the technological language of cybersecurity into a more easily understandable story. Much like Ebola, cyberthreat has the ability to bring our cities to a standstill. Many cybersecurity policy implications are strikingly similar to those occasioned by Ebola.First, a brief recital of the grave danger and potential consequences of cyberattack is provided. Second, I comment on the policy impact resulting from rapid changes in technological complexity and the relative lack of computer familiarity on the part of many senior business and governmental leaders. Third, the characteristics of selected competing cybersecurity constituency groups are discussed: consumers; investors; law enforcement; business; federal, state and local government; and national security interests. By exploring the perceived needs and sometimes conflicting actions of these various constituencies, I hope to make a worthwhile contribution to the national conversation about cyber policy and make meaningful progress toward dealing with the new pandemic of technological virus. Next, is an examination of recent policy development milestones achieved during the past decade or so, including passage of several major legislative proposals designed to enhance U.S. cybersecurity during the waning hours of 2014: The National Cybersecurity Protection Act of 2014; The Federal Information Security Modernization Act of 2014; The Cybersecurity Workforce Assessment Act; The Homeland Security Workforce Assessment Act; and The Cybersecurity Enhancement Act of 2014. Finally, given the critical need for an immediate and effective coordinated approach to cybersecurity, a few thoughts about crafting policy goals and strategies are offered. Hopefully this essay will assist in the conversation being had today by policy makers on this important topic.