Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This, by the way, is the original Democratic "Rockefeller bill" take on the "cybersecurity" problem, and what I was actually invoking when I said Obama's preferred version of CISPA was worse than CISPA; what he actually came up with (this EO) is less bad than what I assumed he'd come up with (the Rockefeller bill).

In short:

The Rockefeller solution to the critical infrastructure problem is:

1. Allow the government to, with some due process mechanism, designate private entities as "critical infrastructure"

2. Allow the government to define, more or less by fiat, a set of qualified auditors for critical infrastructure

3. Mandate that critical infrastructure operators get audited



Without being a policy analyst for the CIP world, just a guy who writes code in it, these seem like a good idea. The only thing I would add is a point 4- failing audits should hurt/cost. There needs to be an incentive to not fail.

The key problems to avoid lie around point 2. It can not become a case of regulatory capture. Nor, for that matter, should be a bunch of IT security yahoos who don't understand the unique demands that CIP/SCADA systems have.

(By the way, if anyone wants to talk about this sort of thing, feel free to email me).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: