This, by the way, is the original Democratic "Rockefeller bill" take on the "cybersecurity" problem, and what I was actually invoking when I said Obama's preferred version of CISPA was worse than CISPA; what he actually came up with (this EO) is less bad than what I assumed he'd come up with (the Rockefeller bill).
In short:
The Rockefeller solution to the critical infrastructure problem is:
1. Allow the government to, with some due process mechanism, designate private entities as "critical infrastructure"
2. Allow the government to define, more or less by fiat, a set of qualified auditors for critical infrastructure
3. Mandate that critical infrastructure operators get audited
Without being a policy analyst for the CIP world, just a guy who writes code in it, these seem like a good idea. The only thing I would add is a point 4- failing audits should hurt/cost. There needs to be an incentive to not fail.
The key problems to avoid lie around point 2. It can not become a case of regulatory capture. Nor, for that matter, should be a bunch of IT security yahoos who don't understand the unique demands that CIP/SCADA systems have.
(By the way, if anyone wants to talk about this sort of thing, feel free to email me).
In short:
The Rockefeller solution to the critical infrastructure problem is:
1. Allow the government to, with some due process mechanism, designate private entities as "critical infrastructure"
2. Allow the government to define, more or less by fiat, a set of qualified auditors for critical infrastructure
3. Mandate that critical infrastructure operators get audited