Cybersecurity Governance - Congressional Oral Statement Project
Good morning ladies and gentlemen of Congress, I am Brandon Johnson, Chief Information
Security Officer of the My Cybersecurity organization and I thank you for your time today and
for this opportunity to appear before you to discuss the Computer Fraud and Abuse Act of 1986.
Specifically, I will be speaking on how overly broad the Computer Fraud and Abuse Act is in its
verbiage and interpretation, and I will offer my assessment and recommendation as to what
should be amended.
The Computer Fraud and Abuse Act, as you know, is a United States cybersecurity bill
that was enacted in 1986 to combat cybercrime as it relates to civil and criminal conduct. It was
created as an amendment to existing computer fraud law that did not adequately address the
growing issues around prosecuting offenses involving computer systems. To this day, the CFAA
has seen numerous iterations in an attempt to maintain current and relative in today’s ever
changing cyber environment. To put this growing environment into perspective, according to the
United States Census Bureau, 87% of households in America have a computer, compared to 8%
in 1984, and there is an estimated 50 million devices that will be connected to the Internet of
Things (IOT) before the end of the year (CRS, 2020).
Due to the gravity of consequences and scope of this cyber environment, it is imperative
that Congress gets the CFAA right and establishes clear and concise law for the court systems to
accurately carry out their duties justly and honorably under their given judicial power. What
worries me, and many other’s in my industry, is that the broadened scope of this law opens the
door for misuse of power and allows creative prosecutors the ability to take advantage of this
vague verbiage to bring criminal charges that do not satisfy the crime of hacking a computer, but
instead target behavior prosecutors dislike. For example, “in cases like United States v. Drew and
United States v. Nosal the government claimed that violating a private agreement or corporate
policy amounts to a CFAA violation” (EFF, n.d.). This is due to the highly contested grey area
surrounding the true meaning of “without authorization” and “exceeds authorized access”, as
many court systems have interpreted these terms in many different ways. The law doesn’t
actually define these terms and they have been subject to considerable dispute. Which is why it is
critical that Congress amends the CFAA to clearly articulate what these terms mean and what
they encompass so that court systems and government prosecutors can apply the law
appropriately. There should not be federal offenses that amount to prison time just for violating
terms of service agreements, but this can happen under the current law as it is written.
To reiterate, this should not be the case, and these types of violations should be met with
proportionate punishment, such as misdemeanor charges, fines, or community service, which
would be commensurate punishments for low-level offenses. These offenses should also be
handled by local state government and, or through civil suits because the CFAA
disproportionately hands out harsh penalties under its current scheme. Some first-time offenses
can be punishable to up to five years in prison each, plus fines. Where other violations can push
ten years, 20 years, or even life in prison. Harsh penalties and highly interpretable language
essentially endanger anyone with a computer, as it can be so easy to be convicted under the
“without authorization” or “exceeds authorized access” standards as they broadly apply to any
device that is connected to the internet.
With that being said, other than the changes already proposed, I believe the following
changes to the CFAA will serve to benefit the government in its right and responsibility to
prosecute crimes, while protecting the rights of citizens. To start, the felony threshold for many
of the crimes under the CFAA is far too low and will turn minor violations into major felonies,
just simply because the value of the information obtained or the monetary loss to the computer or
its owner exceeds a set amount, which under the law is set at $5,000. What this means is any
minor infraction that would otherwise not be a felony, or not warrant long prison stents or high
fines is immediately escalated if the violation cost something or someone more than $5,000. In
todays modern technological environment, this $5,000 threshold is extremely easy to exceed as
technological assets are increasingly more and more expensive.
Another huge issue currently on the minds of many in the industry is the protection of
security researchers, innovators, and privacy seekers in relation to the fine and often blurred line
between circumventing technical measures and identifying security flaws in the name of
innovation and being federally charged with crimes under the CFAA. Congress is currently
discussing Aaron’s Law, which debates how the law should treat users who work their way
around these mentioned technical measures with the intent of identifying, tracking, or
preventing, interoperability with other programs and services. The current law treats these
individuals the same as an intentional criminal that bypasses access barriers on purpose to
commit fraud or act with malicious intent. This can have damaging effects on the cybersecurity
industry as it may deter the good guys from conducting this type of intrusive research as they
may fear of being accused of committing federal crimes. The main focus is that these
punishments, if necessary, can more often be held in a civil manner between the organization or
state and the perpetrator and not be automatically backed up with harsh criminal penalties under
the CFAA.
Federal government, state, and private regulatory bodies are hard at work to continue to
address and research these issue and advance policy proposals to react to emerging threats
associated with technology. These efforts are appreciated and well-noticed, but as you sit at the
highest levels of government in the United States Congress, I urge you to take these matters
seriously as they affect the national security of the nation as well as the protection of its citizens.
Thank you for your time and consideration.
Appendix A: Cybercrime Awareness Summary
1. What is the relationship between criminal and civil court systems as they apply to cybersecurity policy?
Within a criminal court system, the prosecution of a person accused of breaking a law is the standard. There needs to be a law already in place that forbids the behavior of the perpetrator. Guilty outcomes result in consequences such as fines, probation, incarceration, or death. Civil law basically covers everything else. For example, breaches in contracts or lawsuits between different parties are discussed in civil court proceedings. Consequences of losing a civil suit do not include imprisonment and usually involve the payment of compensation either financially or through repaid services. As a result of this
difference in consequence, the standard of evidence in civil cases is not as high as in criminal cases. These rules apply in the same manner no matter if the crime is considered a cyber/computer crime or not. However, because of the nature of digital crimes, a higher proof of standard is usually required in terms of preserving the integrity and origin of digital information as it can be easily corrupted or modified. Therefore, cybersecurity policy needs to be explicitly clear in its directives involving the collection of evidence for a civil or criminal case, because prosecutors will need to prove without a doubt that the data has not been modified in any way (Burgess, 2017). What this means, is cybersecurity policy needs to as clearly as possible articulate the expected behaviors and authorized actions of individuals, and the consequences associated with not following the policy.
2. What is compliance?
Generally speaking, compliance is defined as following rules and meeting requirements. In regard to cybersecurity, this means creating a program that establishes risk-based controls in order to protect CIA of information under the purview of the organization and in line with applicable standards, regulations, and laws.
3. What can US organizations do to comply with regulatory issues?
There are regulations that apply to certain industries, so an organization can ensure compliance by first identifying what industry their business operates within. Once this is understood, the organization can begin to determine what regulations apply to their business based on their presence within the industry, and then implement those requirements into daily business operations through effective policy. Organizations can hire legal teams that are responsible for making this determination and discovering the applicable regulations that apply to the business. This team would be responsible for identifying the right regulations and then assessing where and how they apply within the organization.
4. What policies and technologies can be used to address regulations? 5. How can US organization monitor compliance with cybersecurity policies and relevant regulatory
requirements?
Taking a proactive approach can help organizations address regulatory issues. This means actively seeking help and healthy relationships with regulators and policy makers to ensure the organization is developing its business operations within compliance from the beginning. Basically fusing relationships with government, regulators, and industry to achieve better outcomes collectively. There are compliance monitoring systems that will automatically track and alert if compliance has been updated that is necessary for the organization to address. These systems typically have data stores and metrics that are used to test compliance and report to leadership on the current status of compliance within the organization.
6. List the laws and regulations mentioned in the module.
Laws and policies relating to National Security
a. The Computer Fraud and Abuse Act b. The National Strategy to Secure Cyberspace c. The PATRIOT Act d. National Security Letters e. The Foreign Intelligence Surveillance Act f. The Cybersecurity Act of 2015 g. The Cybersecurity Workforce Assessment Act of 2014
7. List information security strategies, plans, policies, and procedures mentioned in the module that can be used to reduce regulatory risk.
a. The Sarbanes-Oxley Act b. The Gramm-Leach-Bliley Act c. The Payment Card Industry Data Security Standards d. The Health Insurance Portability and Accountability Act e. The Health Information Technology for Economic and Clinical Health Act
General compliance policies and standards can be used within an organization to shape the security culture as well as set acceptable behavior requirements. Things like acceptable use policies and non-disclosure agreements are a few examples of policies that help protect the organization and the individual.
Appendix B: Computer Fraud and Abuse Summary
The Computer Fraud and Abuse Act (CFAA) was developed in the 1980s to address the lack of criminal laws available to fight emerging computer crimes (OLE, 2015). It is a civil and criminal cybercrime law prohibiting a variety of computer-related conduct. Since its creation, Congress has significantly amended the CFAA to address the unauthorized access and use of computers and computer networks in effort to strike an “appropriate balance between the Federal Government’s interest in computer crime and the interests and abilities of the States to proscribe and punish such offenses.” Additionally, technology and the human relationship to it have evolved substantially and therefore laws like the CFAA need to be continuously revisited and updated to meet current trends. As of September 21, 2020, the CFAA prohibits seven categories of conduct and they are:
1. Obtaining national security information through unauthorized computer access and sharing or retaining it;
2. Obtaining certain types of information through unauthorized computer access; 3. Trespassing in a government computer;
4. Engaging in computer-based frauds through unauthorized computer access; 5. Knowingly causing damage to certain computers by transmission of a program, information,
code, or command; 6. Trafficking in passwords or other means of unauthorized access to a computer; 7. Making extortionate threats to harm a computer or based on information obtained through
unauthorized access to a computer.
This list was provided by the Congressional Research Service at the annual review of the CFAA by the 116th Congress. The above list of penalties generally refers to criminal acts and penalties but, in some circumstances, the CFAA allows victims who suffer specific types of loss or damage as a result of CFAA violations to bring civil actions against the violators.
Generally speaking, laws are enacted to deter individuals from carrying out criminal acts. The thought process here is that if there are substantial consequences as a result of performing an illegal action, then individuals may avoid those illegal actions. As we all know, deterrence in and of itself is not effective enough to stop crime, as there are plenty of individuals that still carry out illegal acts no matter how many laws are in place. What this law is good at, is protecting companies and individuals from computer crimes after they have occurred by giving them the right to seek criminal or civil suits against the perpetrator. This is important, because this can give organizations power to show other would-be attackers that they will not tolerate the behavior and will prosecute offenders to the fullest extent of the law. I believe this is where the CFAA is most beneficial to the “good guys” or “victims”.
However, there is a lot of grey area in regard to verbiage within the CFAA and how the law is interpreted, which can cause many issues in the legal process, as well as allow for government to overreach in their powers. For example, the CFAA hands out criminal punishments in a tiered approach starting with 5 years of imprisonment minimums all the way up to 20-year imprisonment minimums for given crimes that meet certain criteria. This can cause disproportionate penalties in relation to the offense. As currently written, first time offenses can easily be charged as felonies, instead of misdemeanors that would otherwise act as a very strict warning to the offender (EFF, 2020). Additionally, the basis for enforcing any violation of the CFAA is backed by terms that are extremely broad and have been disputed and interpreted very differently amongst congress and lower federal courts. Congress didn’t actually define the terms “without authorization” or “exceeds his/her authorized access”, which are the criteria given by the CFAA to forbid someone from accessing information in a protected computer. Paul Larkin Jr., a senior legal researcher at the Institute for Constitutional Government says that the CFAA and how it is currently written would “make it a crime for an employee to use his work computer to access the internet in order to check his standing in a fantasy football league or for any of the myriad of other harmless reasons why a person would surf the net” because of how loosely the law is written (2013).
On the other hand, the United States Courts of Appeals for the Ninth and Fourth Circuits have addressed similar issues and have favored on the defendants’ behalf under the interpretation that as long as the offender had authorized access to the information, they could not be held liable in the future for use of the information however it may be used. Further explained: “The Ninth Circuit case involved David Nosal, a former senior official at Korn/Ferry International, an executive search firm. Nosal enticed company employees to supply him with valuable information that he used at his own rival firm. The federal government charged him with violating the CFAA, but the en banc Ninth Circuit rejected the government’s reading of the statute. In United States v. Nosal, the court held that Nosal did not violate the CFAA because his confederates had permission to access Korn/Ferry’s data base, even though they did not have permission to give that information to him” (Heritage, 2013). The judge in this case
recommended the issue be brought up in either civil court or state criminal court instead of being tried in federal criminal court.
As seen in these examples, the CFAA provides the government the ability to hand down extensive sentencing and interpret the law very loosely to fit the prosecution’s needs, even though it may not apply or is better suited at the state level.
As said before, the CFAA does a poor job of protecting organizations from cyberattacks, it simply allows for a broad interpretation and application of federal law that can often times be far too strict for the given offense. The CFAA could improve in this respect by adding criteria that differentiates the need to try an individual at the state or federal level, as nearly every offense can be argued applicable for federal prosecution under the loosely given verbiage. This clear delineation would help protect individuals from wrongful or unfair charges.
Appendix C: Computer Crime Comparison Table
State Statute Attributes Compared to CFAA Attributes Contrasted to CFAA
Report on Effectiveness in Its State
Illinois - Computer tampering
- Commission of a computer offense without approval of the
computer owner
- Destroying or altering data
- Falsifying or forging email transmission
- Inserting a program with intent to do damage.
- The same offenses under the CFAA will
warrant felony offenses and the CFAA does not
get into as much detail as the Illinois law (such as
the verbiage for usernames, passwords,
etc.)
- Clearly delineates first time offenses and allows first time unauthorized access offenses to be
classified as misdemeanor offenses
rather than felony offenses. However,
second time offenses will carry felony charges and specifies that aggravated tampering and fraud are
mandated/automatic felonies under Illinois
law.
California Regarding hacking, this California statute states that individuals can be subject to
penalties if they create computer instructions with the goal of
modifying, damaging, destroying, recording, or transmitting information on a computer
system or network without the owner's permission. The statute
also prohibits hacking, defining it as the intent is to defraud,
blackmail, or wrongly use data without permission.
- Knowingly cause transmission of a
program, information, code, or command.
- Intentionally cause damage to protected
computer without authorization
Does not directly define the development of
malicious software and the category of
punishment for such.
Violating the CCDAFA could result in a
maximum $10,000 fine and a three-year prison term. Minor violations
are considered misdemeanors as
opposed to felonies. Of note, any computer equipment used to
commit a crime under this law is subject to
forfeiture and "...the law specifies that anyone who is a victim of a
violation of this law is entitled to bring a civil suit against the violator
in order to get compensation for their
damages
New York Computer trespassing addresses unauthorized access to a
computer with the intent to commit a crime or access
materials. There are four degrees of offense in this law for
computer tampering. Finally, unlawful duplication and criminal
possession of computer-related material are offenses under New York's computer crime statutes.
Trespassing in a government computer is punishable by up to one
year in prison and 10 years for a second
offense.
Again, very vague and does not get into nearly
as much detail as the state law.
The maximum sentence for computer trespassing is four years under New York's statute. Computer
tampering carries the potential for up to 15
years in prison
Name of Case Statute Reference Judicial Opinion Statute Success
Facebook, Inc. v. Power Ventures, Inc.
The computer fraud and abuse act of 1986 and the California Penal Code section 502. 844 F.3d 1058 (9th Cir. 2016)
828 F.3d 1068
The court ruled in favor of Facebook, citing that Power Ventures did not have authorization to access users’ data from Facebook in order to promote its own website. Especially after Facebook issued a cease-and-desist order, which is what really cemented the charges.
California Penal Code section 502 imposes liability on a person who "[k]nowingly accesses and without permission takes, copies, or makes use of any data from a computer, computer system, or computer network, or takes or copies any supporting documentation, whether existing or residing internal or external to a computer, computer system, or computer network."
People v. Puesan 111 A.D.3d 222 (N.Y. App. Div. 2013)
111 A.D.3d 222
2013 N.Y. Slip Op. 6530
Defendant was charged with almost every offense defined in article 156, and was convicted after trial of every count: three counts of computer trespass (Penal Law 156.10), three counts of computer tampering in the third degree Penal Law 156.25)[1] ), one count of unlawful duplication of computer related material in the first degree (Penal Law § 156.3[2] ), and one count of criminal possession of
Defendant was convicted on all counts. Sentenced to 5 years’ probation as sufficient evidence was gathered proving the offense were carried out knowingly.
computer related material (Penal Law § 156.35). .
The People of the State of Illinois v. Barbara Janisch
Charged with computer tampering under the Computer Crime Prevention Law (720 ILCS 5/16D-3(a)(2).
Defendant was charged with computer tampering. The charge alleged that “defendant, knowingly and without authorization of Michael Brumitt, accessed computer data from his MSN Hotmail email account and therby obtained data from the MSN Hotmail account.”
Defendant was ordered to pay a fine and perform community service. Which seems appropriate for the offense. The Jury concluded that the offense met 4 propositions, that the defendant knowingly access data, obtained data, acted without the consent of the computer’s owner, and the defendant knew she was acting without the computer owner’s authorization.
Which could have been argued in the opposite direction as the computer was public to the household and the email account password was shared with the defendant. However, the sticking point is that she was not explicitly authorized to use the account even though she knew the password.