Cybersecurity Governance - Congressional Oral Statement Project
ORAL STATEMENT DRAFT 1
Benjamin Oduro-Danso
University of Maryland Global Campus
CMP 610: Foundations in Cybersecurity Management
Prof. Karla Perri
April 25, 2021
Madam Chairwoman, Ranking Member and other Members of the Committee--Members of the Congress committee, good morning. It is a great honor to stand in front of you today to discuss and provides information on how to mechanisms of improveing the Computer Fraud and Abuse Act( CFAA) of 1986. I am a member of the spell out the acronym, and then use it, CISO group, working as the senior communication security officer. After closely watching numerous lawmakers' efforts to reform the "Federal Computer Fraud and Abuse Act," I have developed solutions that I believe will make the law more effective and fair. to the law's Flaws.(You would not tell M of Congress that a law they have enacted has flaws) I've decided to speak about this subject since it received a lot of attention a few decades ago due to Aaron Swartz's actions, as an internet advocate and early user of the technology. With the aid of my many years of work experience in the fields of cybersecurity and information systems, I'll walk you through my suggestionsfinal reviews f. or revising CFAA regulations point by point.
It is crucial to start at the beginning by explaining what the by examining the CFAA policiesintended so that I can provide context for my proposals. The CFAA is intended to is the statute that regulates the prevention of criminal cyber-attacks. The law includes governs seven criminal acts and unauthorized access to a computer or other digital gadget to obtain confidential national security information (Snell, 2012). It also prohibits public officials from accessing individual user machines without their authorization by tracking enforcement. More significantly, it protects against computer system failures, particularly when a malicious script is used to alter control codes and data and export data via approved electronic devices. So I started saying that you would review the Act, which by the way you “capitalize” but it refers to a named thing. Combine what I have with your paragraph below to eliminate redundancies.
Examining the Computer Fraud and Abuse Act
Before coming up with working solutions, a thorough review of the act is needed. I'll start by emphasizing that theThe CFAA tackles fundamental computer system abuse and centers on cyber warfare by promoting workplace understanding of these laws. This sentence repeats what you said above. I would go into the 7 areas and then discuss penalties. Create a logical flow.
As a result, staff and the general public ought to be aware of the gravity of the situation and the repercussions of breaching the statute's regulations. As a result, awareness is perhaps the most successful way of solving any cyber-crime problem or obstacle (Stoner, 2019). The state should possibly concentrate on reducing intervention from malign but influential government officials whose job it is to undermine the act's regulations and rules. However, the CFAA rules aren't entirely ineffective in protecting different organizations' computer systems. This entire paragraph is a bit disorganized. You talk about needing to be aware, how it solves cyber-crime and then intervention. Focus on each point you want to make in its entirety and then move to the next point. This is point A –so state it, This is the effect of point A and this is why it is not an ideal solution. Explain what issue it was supposed to fix and then tell me why it didn’t fix it.
F
urthermore, studies indicate that 50 percent of the total cyber-attacks are usually identified and responded to. As a result, describing the Aact's degree of efficacy is challenging. What's clear is that businesses have seen what arises whenever cyber-attack events are identified, and they don't want to be in a similar predicament.
Analyzing other directives, regulations, and standards
Numerous reports from around the world have documented successful hacking attacks from both big and small companies. The effect of these activities has had a significant impact on the dangerous or hazardous environments that have also been observed around the world. As a result, nations are acquiring massive investments, based on the location, to develop appropriate quality assurance programs to address such threats. According to (Herberger 2018), there are quite a variety of issues that nations can do to reduce threats on electric power plants, which endanger the dignity and credibility of numerous manufacturing departments. This will entail not just updating CFAA regulations but also those in the following measures. This seems out of context. If you want to discuss threats, then recite the types of threats the Act is intended to stop and then say why the CFAA is not a comprehensive fix for them. Then you say because of that, I recommend the following.
Cybersecurity Information Sharing Act
This law was is a statutory law enacted in the U. S. presented in the Senate in July 2014 and adopted in October of the same year ( 2015). Congress enacts laws and the President signs them, he doesn’t pass a bill.On December 18, 2015, President Barack Obama passed the bill. Via the exchange of cybersecurity threats in internet issues, the legislation now allows for the advancement of cybersecurity in the nation. The legislation also provides for the sharing of web traffic data across manufacturing and engineering companies and the US administration. I think you need more of an accurate summary of the what the bill does, this is too vague.
The 199 Graham Leach Biley Act
Thise Aact, passed in of 1999 requires banks to produce appropriate security notifications and give all of their clients the option of not allowing financial institutions to share their personal information with third parties. Conversely, since many businesses keep breaking this regulation, --how? And you don’t end a sentence with a comma.
I propose that committee members people, (not just Member of Congress) who disobeys the law face stiff penalties, including fines and prison sentences. Consequently, all staff members must be adequately trained on different security issues. To facilitate effective compliance with the legislation, the state should assess and update security measures in big and small companies. So this does not apply just to Members of Congress. You need to read more about this and write a more accurate summary of what it does and what its impact is.
Ethical issues in cyber-security
In addition to updating previous legislation, the issue of cyber principles should be addressed. After all, although they are rarely discussed in cybersecurity debates, regulations and codes are critical components of an effective information security program. They are necessary if institutions want to regulate and prosecute criminal activity both internally and externally. Sadly, essential stakeholders in the IT industry are now using ethical misunderstandings to promote increasingly unethical conduct. This is because, according to (Harris 2019), individuals constantly look at issues in varied contexts, misconstruing them to meet their overall objectives. One of the most common ethical misunderstandings is that those who create computer viruses are covered by the first clause. The data should be freely exchanged, making the exchange of private information or even trade secrets legal and ethical.
Recommendations to efficiently revise the Computer Fraud and Abuse Act
There is a need to strengthen the laws inside the computer fraud and abuse actCFAA (you use the abbreviation for the rest of the paper after the first time when you write it out) since it is very ambiguous, enabling investigators to define it as they see fit. Although there is much that needs to be reformed, the first and most crucial step would be to abolish regulations that only serve the state's needs (Hayslip, 2018). Ok this is a federal law not a state one. So you need to separate what state’s do and what the feds do.
At the state level, The California Expansive "Computer Data Fraud and Access Act" is an excellent example of a law that has been designed with enough specificity to protect more than the state's needs. The bill is outstanding in connecting itself with the regulations of the CFAA, although it is a little more precise. It safeguards companies, citizens, and federal agencies from interception and unauthorized access to computer data and systems.
The legislation should be updated to reflect the changing nature of cyber-threats. Unusual attacks usually leave no apparent clues for IT specialists to investigate to stay ahead of the game. As a result, they are vulnerable to a variety of attacks. Using analysis tools to counteract this, I suggest using an analytics-driven methodology to identify, react to, and investigate attacks rapidly. If this approach is in place, entities may constructively search for alerts to minimize their potential effects and absorb and seek other risks that are special to them. The method also aids in detecting malicious events happening at any point along the threat detection path.
The CFAA requires careful enforcement to improve this situation since the American Government still lacks a consented requirement for the privacy of recognizable, confidential data that is not relevant to health data. I propose that it be modeled after the "General Data Protection Regulation" in Great Britain. This law regulates the export of private data from the European Union to other countries. Its fundamental goal is to ensure that individuals have control over their data.
REFERENCES
Doyle, C. (2014, October 15). Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute and Related Federal Criminal Laws. Retrieved from fas.org: https://fas.org/sgp/crs/misc/97-1025.pdf European Parliament. (2016, May 4). Rules for the protection of personal data inside and outside the EU. Retrieved from europa.eu: https://ec.europa.eu/info/law/law-topic/dataprotection_en
DOJ, 2019. Electronic communications Privacy act of 1986 (ECPA). (n.d.). Retrieved April 22, 2021, from https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1285
D. (2013, March 20). Is the Computer Fraud and Abuse Act the 'worst law in technology'? Retrieved from theguardian.com: https://www.theguardian.com/commentisfree/2013/mar/20/computer-fraud-abuse-actlaw-technology
FindLaw. (2018, February 26). New York computer crimes laws. (2018, February 26). Retrieved April 22, 2021, from https://statelaws.findlaw.com/new-york-law/new-york-computer-crimes-laws.html
Force, J. (2018, December 20). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy. Retrieved April 22, 2021, from https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Greenberg, A. (2017, June 03). CISA cybersecurity BILL Advances despite privacy concerns. Retrieved April 22, 2021, from https://www.wired.com/2015/03/cisa-cybersecurity-bill-advances-despite-privacy-critiques/
Harris, S. (2019). CISSP All-in-One Exam Guide (8th ed.). New York City, New York: McGrawHill Edu.
Herberger, C. (2018, June 5). 2018: Snapshot of the Most Important Worldwide Cybersecurity Laws, Regulations, Directives and Standards. Retrieved from radware.com: https://blog.radware.com/security/2018/06/cybersecurity-laws-regulations-directivesstandards/
Haferkamp, R (2020, August 28). How to write the acceptable use policy your business needs. Retrieved April 22, 2021, from https://www.cnbwaco.com/how-to-write-the-acceptable-use-policy-your-business-needs/
Hayslip, A., & Hayslip, G. (2018, March 16). 9 policies and procedures you need to know about if you're starting a new security program. Retrieved April 22, 2021, from https://www.csoonline.com/article/3263738/9-policies-and-procedures-you-need-to-know-about-if-youre-starting-a-new-security-program.html
ITLaw. (n.d.). California Comprehensive Computer Data Access and Fraud Act. Retrieved from wikia.org: https://itlaw.wikia.org/wiki/California_Comprehensive_Computer_Data_Access_and_Fraud_Act
Knowles, A. (2016, October 12). Tough Challenges in Cybersecurity Ethics. Retrieved from securityintelligence.com: https://securityintelligence.com/tough-challengescybersecurity-ethics/
Nigrini, M. (2020, May 12). Forensic analytics: Methods and techniques for forensic accounting investigations, 2nd edition. Retrieved April 22, 2021, from https://www.wiley.com/en-us/Forensic+Analytics%3A+Methods+and+Techniques+for+Forensic+Accounting+Investigations%2C+2nd+Edition-p-9781119585763
Schwartz, K. D. (2019, June 4). Cybercrimes Go Unreported More Often Than People Think, Report Finds. Retrieved from itprotoday.co: https://www.itprotoday.com/security/cybercrimes-go-unreported-more-often-peoplethink-report-finds
Snell, J. G. (2012, March). A Handbook of Civil and Criminal Issues For In-House Counsel. Retrieved from morganlewis.com: https://www.morganlewis.com/~/media/files/docs/archive/privacy_computer_crimes_han dbook_march2012.ashx .
State of New York. (2006). CJI2d [NY] PENAL LAW ARTICLE 156 - OFFENSES INVOLVING COMPUTERS. Retrieved from nycourts.gov: https://www.nycourts.gov/judges/cji/2PenalLaw/156/art156hp.shtml
Stoner, J. (2019). Getting Ahead of The Adversary. Retrieved from splunk.com: https://www.splunk.com/en_us/form/splunk-and-johns-hopkins-demonstrate-threathunting-tactics.html ?
Vanko, K. J. (2011, September 15). Does the Illinois Computer Crime Prevention Law Benefit Employers? Retrieved from non-competes.com: http://www.noncompetes.com/2011/09/does-illinois-computer-crime-prevention.html
Zetter, Kim. (2014). Hacker Lexicon: What Is the Computer Fraud and Abuse Act? Wired. Retrieved from https://www.wired.com/2014/11/hacker-lexicon-computer-fraud-abuse-act/