Article Written By Scott Bradner
April 6, 2009 (Network World) The timing of two cybersecurity bills just introduced by Sen. John D. Rockefeller IV (D-W.Va.), Sen. Olympia Snowe (R-Maine) and Sen. Bill Nelson (D-Fla.) seems a bit funny. It is not so much that they were introduced on April Fools' Day; more importantly, they were introduced before the widespread review of U.S. cybersecurity ordered by President Obama is completed by Melissa Hathaway, acting senior director for cyberspace for the National Security and Homeland Security Councils.
It would seem to make more sense to wait and see what Hathaway thinks is broken before submitting bills to fix it. While I expect that the bills will be changed when Hathaway reports her findings in a few weeks, the current bills are interesting and have the potential to impact just about everyone in the network or network security business.
The first bill (S 778) would establish an Office of National Cybersecurity Advisor within the Executive Office of the President. The second (S 773), which goes by the title of "The Cybersecurity Act of 2009," covers a grab bag of topics designed to "ensure the continued free flow of commerce within the United States and with its global trading partners through secure cyber communications", among other things.
Continue Reading This Article on Computerworld...
Yet another USA government attempt at cybersecurity
Moderators: Moderator, Global Moderator
Yet another USA government attempt at cybersecurity

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it
[/color]
-
Riftt
Yet another USA government attempt at cybersecurity
it's a shame that through their added security measures they will be adding to the level of vulnerability that already exists. it should be common knowledge that the more you add to your security the more you risk completely compromising what and who you try to protect. that's why i dont run firewalls or virus scanners they open you up wider then a vanilla computer because of their own vulnerabilities, notably overflows, i do however suggest running a traffic analyzer, preferably one of your own engineering. in the end, they are waisting their time with these security based cyberlaws, what will help is to educate the end user, if you dont, you have a handful of companies that claim to be reliable and try to make security tools etc when you could have a considerably larger community of endusers with the knowledge who can collaborate together and take security into their own hands. all the people need is information.
