ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

US government wants firms' security secrets

Declan McCullagh, CNET News.com CNET News.com

Published: 17 Apr 2003 07:58 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The US Department of Homeland Security is hoping to convince technology and telecommunications firms that it's safe to share information about infrastructure vulnerabilities with the federal government.

This week, the new department published a set of proposed regulations designed to convince corporate America to hand over infrastructure information to the government, promising that it will be kept in the strictest confidence.

The proposal sweeps broadly, covering any data submitted to the government about any real or possible attack on "critical infrastructure or protected systems by physical or computer-based attack" or any programming errors, glitches or bugs that could endanger important services like the Internet, utilities or telephone networks.

Industry groups had worried for years about the potential negative consequences of handing over proprietary or embarrassing information to the federal government, fearing it could be leaked to the press or obtained through requests filed under the Freedom of Information Act (FOIA).

Their worries led to an amendment being added to the legislation enacted last year that created the department. It says that critical infrastructure information voluntarily submitted to federal agencies "shall be exempt from disclosure" through FOIA.

Advocates of open government protested the amendment, saying it was unnecessary since FOIA already said that sensitive information could not be disclosed.

David Sobel, general counsel of the Electronic Privacy Information Center, said at a congressional hearing last July that the department should not be completely immune to FOIA requests. "Any claimed private sector reluctance to share important data with the government grows out of, at best, a misperception of current law," Sobel said. "Exemption proponents have not cited a single instance in which a federal agency has disclosed voluntarily submitted data against the express wishes of an industry submitter."

The proposed rules published on Tuesday are the result of the legislation. Comments may be sent to cii.regcomments@DHS.gov on or before 16 June.

In charge of running the department's vulnerability collection and storage programme will be an undersecretary of the information analysis infrastructure protection directorate, who will be chosen by Secretary Tom Ridge. That person will oversee a vulnerability database to be called the Critical Infrastructure Information Management System.

The directorate is allowed to disclose some information in the database to the public when publishing a general alert. "In issuing a warning, the (directorate) shall protect from disclosure the source of any voluntarily submitted (information) that forms the basis for the warning; and any information that is proprietary, business-sensitive, relates specifically to the submitting person or entity, or is otherwise not appropriately in the public domain," the proposal says.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
43 out of 76 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Security Consultant - Immediate start

The desired candidate will have the following skillset: * Network Vulnerability Internal & External Testing * Configuration of Cisco switches / ...

MS Senior Support Analyst 25-30k Warrington

Essential criteria for those submitted should include Windows XP, Server 2000/20003 and should include an MCSE/MCSA qualification. Because of the ...

International Bluechip, Financial Software Tester, South Devon

You will be testing a range of software products, ensuring required compliance with Tax and Accounting Legislation, bug identification and producing ...

Discussions

RichardThurston RichardThurston

Government help

Friday 16 May 2008, 8:35 AM

2 comments
barrie barrie

Windows Driver Updates

Friday 16 May 2008, 3:14 AM

2 comments
jgj jgj

"what more do you need?"

Thursday 15 May 2008, 9:19 PM

5 comments
jgj jgj

"what more do you need?"

Thursday 15 May 2008, 9:19 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal