Cybersecurity Strategy, Law, and Policy
Cybersecurity Strategy, Law, and Policy
CMIT 420 - Current Trends and Projects in Computer Networks and Cybersecurity
Table of Contents Part 1: National Security Strategy and Cybersecurity 2 Part 2: Public/Private Partnerships 5
Part 1: National Security Strategy and Cybersecurity
National Security Strategy (NSS) is an annual report, mandated by Section 603 of the Goldwater-Nichols Department of Defense Reorganization Act of 1986, for the President of the
United States to Congress describing the security strategies and goals of the administration (Department of Defense, 2020). The document explains how the administration intends to approach the security challenges facing the country. Prepared by the National Security Council, the report examines multiple issues to include military capabilities, foreign policy, and cybersecurity. After a thorough review of the Trump administration’s 2017 NSS report, our findings show the document does not adequately address our cyberspace's security landscape. However, the report touches on critical issues faced by the United States due to our cyber adversaries' capabilities. The Bush administration's 2003 National Strategy to Secure Cyberspace (NSSC) will be compared to the Trump administrations' cybersecurity strategy, as explained in the 2017 NSS report.
After the horrific tragedies of September 11th, 2001, the Bush administration realized that all activities, ranging from business transactions to national defense, rely on the interdependent networks of cyberspace (Bush, 2003). As a result, the administration published a comprehensive report on how to combat the threat of cyber attacks. President Bush did not solely rely on his cybersecurity advisors; he included all tiers of government, the private sector, and the American citizens to develop strategies to defend our cyberspace. In contrast, the Trump administration's cyberspace plan lacks the private sector’s inclusion, which is principally affected by cyber attacks. The 2017 NSS report does not discuss or incorporate state and local government involvement in its cyber plan. In the 2003 report, President Bush noted, "Securing cyberspace is an extraordinarily difficult strategic challenge that requires a coordinated and focused effort from our entire
society—the federal government, state and local governments, the private sector, and the American people." Prioritizing this inclusive approach should be the first step in securing our cyberspace
because we are all affected by any cyber domain intrusion.
As noted by the current administration in the 2017 NSS report, "America's response to the challenges and opportunities of the cyber era will determine our future prosperity and security." With the above statement, it is indisputable that the American government and its people heavily depend on technology.
The NSS report failed to outline a response strategy for defending Americans from international hackers, as was seen during the 2016 elections. The report did discuss the administration's top priorities regarding cybersecurity, highlighting risk management, deterrence, network defense, information sharing, and the establishment of layered defenses. However, the cybersecurity section of the NSS fails to elaborate on any strategies beyond the priorities mentioned above. It also failed to outline actions or recommendations on each of the prioritized efforts to secure our cyberspace assets. Unlike the NSS, the NSSC gave a thorough explanation of government readiness and how it could swiftly respond to cyber attacks.
The NSSC report outlined the strategic objectives in dealing with threats and vulnerabilities, government and citizen roles, and critical priorities in securing America's cyberspace. The report extensively explained the weaknesses in our cyber domain and
adequately provided the necessary actions to mitigate those vulnerabilities.
The Trump administration should approach the cybersecurity issues America faces as a national effort, including all Americans in securing our cyber assets. The administration should adequately address and prioritize public-private partnerships to solve America's common enemy, the cyberattack.
Part 2: Public/Private Partnerships
There is a significant overlap between the public and private sectors in technology, particularly concerning cybersecurity. Given that these two sectors constitute the entirety of the nation’s cybersecurity capabilities and that threats are ever-evolving, significant cooperation between the two is required to realistically mitigate these threats. The private sector owns the critical information infrastructure; therefore, it is in the government’s best interest to build a strong relationship with the private sector to ensure sufficient sharing of information regarding contemporary threats. Providing the private sector with this information allows companies and organizations to strengthen their network and adequately prevent or withstand attacks. The public sector, primarily the federal government, would share cyber threat indicators and defensive measures with private sector entities to ensure a bilateral synchronization of knowledge. Private organizations that receive information on cyber threat indicators are much more likely to build a strong organizational network that can withstand attacks. According to CISA:
CISA defines “cyber threat indicator” as “information that is necessary to describe or identify— (A) malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability; (B) a method of defeating a security control or exploitation of a security vulnerability; (C) a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability; (D) a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability. (Cyber Threat Indicator, 2020)
Cyber threat indicators are very powerful and can give entities a clear and concise view of the present threats, providing these organizations the ability to adjust their security features accordingly.
The private sector is an essential part of the partnership between the public and private spheres. This sector handles much of the classified material and is also exposed to a more substantial number of users. Due to this, private organizations are often prone to a broader threat landscape. This increased attack vector is especially relevant given that the private sector often handles economically valuable assets such as trade secrets and financial data. The private sector shares cyber threat indicators and defensive measures with the public sector, helping the public sector make advancements in its infrastructure and contributing to overall knowledge shared
among all entities within the cybersecurity field.
It might not always be mandatory for the private sector to share information with the public sector. Private companies are responsible for keeping customer data secure - mandating that private organizations share customer information could constitute a significant privacy breach. Personally Identifiable Information (PII) is generally protected by constitutional law and other applicable privacy laws and regulations; it can generally only be procured by a legal warrant in response to an event under criminal investigation. However, an organization should attempt an internal investigation into any breach of data or other security policy violation first.
Many laws and regulations mandate specific legal investigation for certain kinds of adverse events, or at least the notification of individuals potentially affected by policy violations such as a data breach, so how this is approached varies by jurisdiction.
The government’s restrictions to legally collect data on citizens present an interesting challenge in the cybersecurity field; this is a particular concern that arises during incident response spurred by investigations after an event has occurred. Sensitive data is inherent to the field; as such, policymakers must be mindful of the Fourth Amendment to the U.S. Constitution and other applicable privacy laws and regulations that can be interpreted to or expressly forbid the collection of individual data without proper legal authority. Many in the cybersecurity field and the general population consider personal information protected by the Fourth Amendment in the same way that an individual’s private property is.
It is well-known that in the modern United States and indeed much of the rest of the world, the public sector’s access to personal information has been controversial. A notable provision within the U.S. PATRIOT Act is the authorization for U.S. federal agencies to seize cell phone companies’ privately-held records to combat terrorism and organized crime. This practice has been notably extended to the mass collection of personal data in the age of social networking through generous interpretations of the provisions laid forth by the PATRIOT Act and related laws, often without respect to the Fourth Amendment to the United States Constitution. A bitter debate has ensued about whether the right to privacy applies to digital information, especially digital information held by a third-party organization in the private
sector.
There have been legal rulings in favor of the right to privacy regarding the unwarranted seizure of an individual’s data. In June 2018, the United States Supreme Court ruled against the warrantless seizure of cell phone records during a trial involving a series of robberies in Detroit (Travieso & Lyon, 2019). A gray area had previously existed under the Stored Communications Act of 1986, which specifies that a court may issue a subpoena, an order to provide evidence, concerning personal data that is held by an organization (Travieso & Lyon, 2019). A subpoena differs from a warrant in that it obligates an individual or organization to surrender private data to a court as required for an investigation. It could be argued that some contradiction exists between the Supreme Court’s rulings and established law; in the context of cybersecurity, current laws and regulations might be insufficient to provide a proper guideline for which data
procurement methods are lawful and which are not.
This gray area causes security personnel concern, as the wrong step in response to a potential threat, could have adverse impacts such as organizational sanctions or the inadmissibility of digital evidence in court. The Cybersecurity Act of 2015 might require additional updates to define the public sector's ability to collect and use data adequately. There is a balance that must always exist between the right to privacy and the public sector’s ability to prevent crimes. Government entities must not be enabled to overstep their authorities and collect individual data without a valid reason or stringent authorization, and cybersecurity personnel must not be bound by excessive regulations that make detecting and responding to cyber threats nearly impossible. The Cybersecurity Act could be amended to treat the response to cybercrime and collection of individual's data reminiscent of how the Supreme Court has applied to the
Fourth Amendment. For example, the Supreme Court authorizes law enforcement personnel to warrantlessly seize evidence within their line of sight and waives the warrant requirement to
enter private property if a crime is actively being committed.
Similarly, the Cybersecurity Act could be updated to allow security personnel to collect private data within reasonable limitations if it is believed that such collection would thwart an imminent threat or when responding to a recent cybercrime. In this context, any seizure of an individual's data should not only be communicated between the private entity and the seizing government agency. Any new provision to the Cybersecurity Act should also necessitate the disclosure of this data seizure to the individual to whom the data relates. Although a private organization may technically have ownership of certain aspects of an individual's data, laws and regulations should balance this information's commercial and personal components. The Cybersecurity Act should not extend beyond the boundaries imposed by the Fourth Amendment.
This provision must be carefully laid out to respect the right to privacy. It should never be interpreted as an authorization for the public sector to gather private data in mass without any prior warrant or notification to the owners of said information. The changing nature of crime and the ever-evolving threat landscape does not necessitate the erosion of individual rights. A balance must be struck between the right to personal privacy and the need to defend public and
private assets from cyber attacks.
References
ATTOG Technologies. (n.d.). Your PII Chart [Digital image]. Retrieved July 11, 2020, from
https://www.attogtech.com/wp-content/uploads/2016/02/attog-technologies-pii-chart.png
Baker, E. W. (2014, April). Model of CI for SED [Digital image]. Retrieved July 11, 2020, from
https://www.researchgate.net/profile/Elizabeth_White_Baker/publication/262882721/figu re/fig1/AS:613882573881349@1523372419971/Model-of-CI-for-SED.png
Cyber Threat Indicator. (4 July 2020). Retrieved from
https://www.pillsburylaw.com/images/content/5/0/v2/5066/Definitions.pdf
Department of Homeland Security. (2003, February 1). The National Strategy to Secure Cyberspace. Retrieved from https://www.us-cert.gov/sites/default/files/publications/ cyberspace_strategy.pdf
G2 Crowd. (n.d.). How Does Blockchain Work? [Digital image]. Retrieved July 11, 2020, from
https://devpolicy.org/wp-content/uploads/2019/03/Credit-G2-Crowd.jpg
GDRP.eu (8 July, 2020). Do consumers know their GDPR data privacy rights? General Data
Protection Regulation, EU. Retrieved from: https://gdpr.eu/consumers-gdpr-data-privacy-rights/
Hay, S. (2020, April 24). What is Blockchain Technology? Retrieved July 12, 2020, from https://99bitcoins.com/what-is-blockchain/
Institute for Defense Analysis. (n.d.). Cyberspace - The Embedded Domain [Digital image].
Retrieved July 11, 2020, from https://live.mrf.io/statics/i/p/assets.realclear.com/images/44/445276_5_.png
Mearian, L. (2019, January 29). What is blockchain? The complete guide. Retrieved from
ComputerWorld: https://www.computerworld.com/article/3191077/what-is-blockchainthe-complete-guide.html
NetApp HCI. (2018, January 9). Service Provider HCI Deployment Opportunities [Digital
image]. Retrieved July 11, 2020, from https://blog.netapp.com/wp-content/uploads/2018/01/Screen-Shot-2018-01-05-at-10.25.2
2-AM.png
OrangeHRM. (n.d.). GDPR [Digital image]. Retrieved July 11, 2020, from
https://www.orangehrm.com/assets/Uploads/gdpr.jpg
Secure Reading. (n.d.). CIA Triad [Digital image]. Retrieved July 11, 2020, from
https://securereading.com/wp-content/uploads/2016/10/Information-security_1_2017.png
Support Center, M. (4 July 2020). Cyber Threat and Vulnerability Analysis of the U.S. Electric Sector. Retrieved from https://www.energy.gov/sites/prod/files/2017/01/f34/Cyber Threat and Vulnerability Analysis of the U.S. Electric Sector.pdf
Teitler, K. (4 July 2020). Fostering Public-Private Collaboration on Cybersecurity. Retrieved
from https://www.edgewise.net/blog/fostering-public-private-collaboration-on-cybersecurity
Travieso, F. & Lyon, E. (15 January 2019). The Legal Implications of Digital Privacy.
Government Technology. Retrieved from: https://www.govtech.com/public-safety/The-Legal-Implications-of-Digital-Privacy.html
United States, Executive Office of the President. (2017, December 18). National Security Strategy of the United States of America. Retrieved from https://www.whitehouse.gov/ wp-content/uploads/2017/12/NSS-Final-12-18-2017-0905.pdf
US Army. (2020). Multi-Domain Operations Investment Plan [Digital image]. Retrieved July 11,
2020, from https://upload.wikimedia.org/wikipedia/en/8/8c/Multi-domain_operations%2Cinvestment
Plan2020.png
Upcounsel (8 July, 2020). EULA and Privacy Policy: Everything You Need to Know.
Wright, A., & Filippi, P. D. (2015). Decentralized Blockchain Technology and the Rise of Lex
Cryptographia. SSRN Electronic Journal. doi:10.2139/ssrn.2580664
2
2