{"id":55,"date":"2015-12-16T10:40:19","date_gmt":"2015-12-16T18:40:19","guid":{"rendered":"http:\/\/www.founditdata.com\/blog\/?p=55"},"modified":"2015-12-16T10:46:25","modified_gmt":"2015-12-16T18:46:25","slug":"cybersecurity-information-sharing-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.fidcyber.com\/blog\/security\/cybersecurity-information-sharing-what-you-need-to-know\/","title":{"rendered":"Cybersecurity Information Sharing: What You Need to Know"},"content":{"rendered":"<p><strong>The Latest<\/strong><\/p>\n<p>We are in \u201cthe red zone\u201d for the Senate\u2019s Cybersecurity Information Sharing Act (CISA), one of the first significant cybersecurity bills, currently in conference with a House version. So what does this mean for U.S. companies?<\/p>\n<p>Under CISA, companies would<strong> receive liability protection <\/strong>for<\/p>\n<ul>\n<li><strong>Monitoring information systems (including their own and those of their customers when given permission), <\/strong>and<\/li>\n<li><strong>Voluntarily sharing cyber threat information <\/strong>with other companies and the government.<\/li>\n<\/ul>\n<p>However, major concerns still plague the process, and some of the biggest names in technology (think Apple, Microsoft, LinkedIn, Facebook, Google, and others) vehemently oppose the bill. We outline some of the pros and cons here and what the bill\u00a0means for U.S. businesses:<\/p>\n<p><strong>The Pros<\/strong><\/p>\n<ul>\n<li>Better Baseline: New liability protections under CISA will likely raise the bar for security practices. Defining liability implies setting a baseline, and enterprise due care will expand in response. Liability protections also enable companies to set up their own network defenses to repel attackers.<\/li>\n<\/ul>\n<ul>\n<li>Real-Time Data: The quality of threat information and enterprise response could improve significantly. Companies that share and receive real-time threat information would be better informed about the threat environment, and could take action quickly.<\/li>\n<\/ul>\n<p><strong>The Cons<\/strong><\/p>\n<ul>\n<li>Privacy, the\u00a0Casualty (Again): Industry groups and privacy advocates fear the law would skirt multiple privacy concerns. As companies share threat information with each other and with government, there is a high likelihood that on occasion, personal data would accidentally be included. CISA\u2019s liability protection would cover companies that run into this type of situation, putting customer privacy at risk. So far there has been little thought paid to the consequences of a slip-up.<\/li>\n<\/ul>\n<ul>\n<li>Government Duplication: Others fear heavy government involvement in developing plans for cyber incidents that affect critical networks. In general, heavy government centralization of information sharing is seen as unnecessary and too sweeping, when companies like Facebook are already building their own information sharing capabilities like Threat Exchange.<\/li>\n<\/ul>\n<p>Despite the cons, we are still nearing the final stages of a significant cybersecurity bill. So what can we do moving forward?<\/p>\n<p><strong>The Takeaways<\/strong><\/p>\n<p>We discuss a few takeaways here for how to take action, but as CISA evolves, so will the implications for U.S. businesses. Here are the actions\u00a0we think will stay constant:<\/p>\n<ul>\n<li>Develop a company position on handling information sharing, stating whether real-time information sharing or data sanitization and privacy is the highest priority. Small and medium businesses in particular should take a hard look at participating if they don\u2019t have the infrastructure to support privacy best practices and stringent data security.<\/li>\n<li>Invest in educating network defenders. Sharing and receiving threat information and erecting network defenses requires ongoing education, strong network design and security practices, and organizational oversight.<\/li>\n<li>Update and streamline identity and access management, and ensure granular access controls for those interacting with information sharing portals.<\/li>\n<\/ul>\n<p>As security guru Bruce Schneier has stated, we\u2019re still squarely in the \u201cresponse era\u201d of cybersecurity. We\u2019ve evolved from learning about the threat landscape, we\u2019ve seen government and industry collaborate to build the NIST Cybersecurity Framework, and now the national dialogue is\u00a0focused on breach response and information sharing. The conversation about CISA reinforces that, but will have to make privacy a core component for us to evolve further.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Latest We are in \u201cthe red zone\u201d for the Senate\u2019s Cybersecurity Information Sharing Act (CISA), one of the first significant cybersecurity bills, currently in conference with a House version. So what does this mean for U.S. companies? Under CISA, &hellip; <a href=\"https:\/\/www.fidcyber.com\/blog\/security\/cybersecurity-information-sharing-what-you-need-to-know\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-55","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/posts\/55"}],"collection":[{"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/comments?post=55"}],"version-history":[{"count":1,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/posts\/55\/revisions"}],"predecessor-version":[{"id":56,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/posts\/55\/revisions\/56"}],"wp:attachment":[{"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/media?parent=55"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/categories?post=55"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fidcyber.com\/blog\/wp-json\/wp\/v2\/tags?post=55"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}