Cybersecurity Information Sharing Act
|Long title||To improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes|
The Cybersecurity Information Sharing Act (CISA S. 2588 [113th Congress], S. 754 [114th Congress]) is a United States federal law designed to "improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes". The law allows the sharing of Internet traffic information between the U.S. government and technology and manufacturing companies. The bill was introduced in the U.S. Senate on July 10, 2014, and passed in the Senate October 27, 2015. Opponents question CISA's value, believing it will move responsibility from private businesses to the government, thereby increasing vulnerability of personal private information, as well as dispersing personal private information across seven government agencies, including the NSA and local police.
The text of the bill was incorporated by amendment into a consolidated spending bill in the U.S. House on December 15, 2015, which was signed into law by President Barack Obama on December 18, 2015.
The Cybersecurity Information Sharing Act was introduced on July 10, 2014 during the 113th Congress, and was able to pass the Senate Intelligence Committee by a vote of 12-3. The bill did not reach a full senate vote before the end of the congressional session.
The bill was reintroduced for the 114th Congress on March 12, 2015, and the bill passed the Senate Intelligence Committee by a vote of 14-1. Senate Majority Leader Mitch McConnell, (R-Ky) attempted to attach the bill as an amendment to the annual National Defense Authorization Act, but was blocked 56-40, not reaching the necessary 60 votes to include the amendment. Mitch McConnell hoped to bring the bill to senate-wide vote during the week of August 3–7, but was unable to take up the bill before the summer recess. The Senate tentatively agreed to limit debate to 21 particular amendments and a manager's amendment, but did not set time limits on debate. In October 2015, the US Senate took the bill back up following legislation concerning sanctuary cities.
The main provisions of the bill make it easier for companies to share personal information with the government, especially in cases of cyber security threats. Without requiring such information sharing, the bill creates a system for federal agencies to receive threat information from private companies.
With respect to privacy, the bill includes provisions for preventing the sharing of personal data that is irrelevant to cyber security.  Any personal information that does not get removed during the sharing procedure can be used in a variety of ways. These shared cyber threat indicators can be used to prosecute cyber crimes, but may also be used as evidence for crimes involving physical force.
Sharing National Intelligence threat data among public and private partners is a hard problem and one that we should all care about. The National Intelligence Threat Sharing (NITS) project is intended as an innovative solution to this hard problem. Altogether NITS is both innovative and useful. But first, to ensure that NITS is trustworthy, private partners must be indemnified. Indemnification takes an act of Congress, literally.
The underlying impediment to more fulsome cooperation among buyers and sellers and peers within a supply chain is indemnification. Indemnification is needed to secure industry partners against legal responsibility for their actions. Unfortunately, Congressional refusal to offer indemnification remains an impediment to real collaboration. At least qualified immunity should be accorded. This is immunity of individuals performing tasks as part of the government's actions.
Businesses and trade groups
The CISA has received some support from advocacy groups, including the United States Chamber of Commerce, the National Cable & Telecommunications Association, and the Financial Services Roundtable.
BSA (The Software Alliance) appeared initially supportive of CISA, sending a letter on July 21, 2015 urging the senate to bring the bill up for debate. On September 14, 2015, the BSA published a letter of support for amongst other things cyber threat information sharing legislation addressed to Congress, signed by board members Adobe, Apple Inc., Altium, Autodesk, CA Technologies, DataStax, IBM, Microsoft, Minitab, Oracle, Salesforce.com, Siemens, and Symantec. This prompted the digital rights advocacy group Fight for the Future to organize a protest against CISA. Following this opposition campaign, BSA stated that its letter expressed support for cyber threat sharing legislation in general, but did not endorse CISA, or any pending cyber threat sharing bill in particular. BSA later stated that it is opposed to CISA in its current form. The Computer & Communications Industry Association, another major trade group including members such as Google, Amazon.com, Cloudflare, Netflix, Facebook, Red Hat, and Yahoo!, also announced its opposition to the bill.
Senator Ron Wyden (D-OR) has objected to the bill based on a classified legal opinion from the Justice Department written during the early George W Bush Administration. The Obama administration states that it does not rely on the legal justification laid out in the memo. Wyden has made repeated requests to the US Attorney General to declassify the memo, dating at least as far back as when a 2010 Office of Inspector General report cited the memo as a legal justification for the FBI's warrantless wire-tapping program.
On August 4, 2015, White House spokesman Eric Schultz endorsed the legislation, calling for the senate to "take up this bill as soon as possible and pass it".
The United States Department of Homeland Security initially supported the bill, with Jeh Johnson, the secretary of the DHS, calling for the bill to move forward on September 15. However, in an August 3 letter to senator Al Franken (D-MN), the deputy secretary of the DHS, Alejandro Mayorkas, expressed a desire to have all connections be brokered by the DHS, given the Department's charter to protect the executive branch networks. In the letter, the DHS found issue with the direct sharing of information with all government agencies, advocating instead that the DHS be the sole recipient of cyberthreat information, allowing it to scrub out private information. In addition, the Department of Homeland Security has published a Privacy Impact Assessment detailing its internal review of the proposed system for handling incoming indicators from Industry.
Civil liberties groups
Privacy advocates opposed a version of the Cybersecurity Information Sharing Act, passed by the Senate in October 2015, that left intact portions of the law they said made it more amenable to surveillance than actual security while quietly stripping out several of its remaining privacy protections. CISA has been criticized by advocates of Internet privacy and civil liberties, such as the Electronic Frontier Foundation and the American Civil Liberties Union. It has been compared[by whom?] to the criticized Cyber Intelligence Sharing and Protection Act proposals of 2012 and 2013, which passed the United States House of Representatives, but did not pass the Senate.
Similar laws in different countries
- Anti-Counterfeiting Trade Agreement
- Chinese intelligence operations in the United States
- Communications Assistance for Law Enforcement Act
- Federal Information Security Management Act of 2002
- Freedom of information laws by country
- Intellectual Property Attache Act
- National Security Agency
- Vulnerabilities Equities Process
- "Discussion Draft of the 'Cybersecurity Information Sharing Act of 2014' (S.2588)" Archived 2014-08-25 at the Wayback Machine, 113th Congress, 2d Session, June 11, 2014.
- S.754 - Cybersecurity Information Sharing Act of 2015
- H.R.2029 - Military Construction and Veterans Affairs and Related Agencies Appropriations Act, 2016
- Budget bill heads to President Obama's desk with CISA intact
- Gregory S. McNeal (9 Jul 2014). "Controversial Cybersecurity Bill Known As CISA Advances Out Of Senate Committee". Forbes. Retrieved 31 Jul 2015.
- Andy Greenberg (12 Mar 2015). "CISA Cybersecurity Bill Advances Despite Privacy Concerns". Wired. Retrieved 27 Jul 2015.
- Charlie Mitchell (22 Jun 2015). "Senate vote falls short of approving defense act with CISA amendment". The Washington Examiner. Retrieved 28 Jul 2015.
- Erin Kelly (11 Jun 2015). "Democrats block effort to attach cybersecurity legislation to defense bill". USA Today. Retrieved 28 Jul 2015.
- Charlie Mitchell (20 Jul 2015). "Senate, once again, looks to bring back CISA". The Washington Examiner. Retrieved 27 Jul 2015.
- Katie Bo Williams (1 Oct 2015). "House Intel chief says cyber-sharing bill will pass 'overwhelmingly'". The Hill. Retrieved 4 Oct 2015.
- Kaveh Waddell (20 Oct 2015). "Cybersecurity Bill Nears Crucial Senate Vote". National Journal. Retrieved 20 Oct 2015.
- Kominsky, Mitchell (February 2014). "The Current Landscape of Cybersecurity Policy: Legislative Issues in the 113th Congress". Harvard Law School National Security Journal.
- Andy Greenberg (20 Mar 2015). "CISA Security Bill: An F for Security But an A+ for Spying". Wired. Retrieved 31 Jul 2015.
- Dibya Sarkar (Mar 5, 2015). "Industry rep: Businesses get stronger liability protection for sharing cyber threat info under CISA". Fierce Homeland Security. Archived from the original on September 22, 2015. Retrieved July 27, 2015.
- Chris Bing (20 Oct 2015). "Apple, Google and Friends Join Forces Ahead of Crucial CISA Decision". Retrieved 20 Oct 2015.
- James Rogers (20 Oct 2015). "Twitter slams controversial cybersecurity bill". Fox News. Retrieved 20 Oct 2015.
- Cory Bennett (July 21, 2015). "Software industry urges action on Senate cyber bill". The Hill. Retrieved July 27, 2015.
- "Congressional Leadership Data Agenda Letter" (PDF). BSA. September 14, 2015.
- "Betrayed by Tech". Fight for the Future.
- Barb Darrow (24 Sep 2015). "Apple, Microsoft, others slammed for supporting cybersecurity bill". Fortune. Retrieved 4 Oct 2015.
- Julie Bort (28 Sep 2015). "A few tweets from Salesforce's Marc Benioff threaten to squash a cyber-spying law". Business Insider. Retrieved 4 Oct 2015.
- "Security". www.bsa.org. Retrieved 2015-12-18.
- "CCIA Urges Senate To Improve Cybersecurity Information Sharing Act". www.ccianet.org/. Retrieved 2015-12-18.
- Eric Geller (12 Oct 2015). "Bernie Sanders comes out against CISA, a controversial cybersecurity bill". Daily Dot. Retrieved 20 Oct 2015.
- Dustin Volz (July 27, 2015). "What's Inside the Justice Department's Secret Cybersecurity Memo?". National Journal. Retrieved July 28, 2015.
- Trevor Timm (June 13, 2015). "A government surveillance bill by any other name is just as dangerous". The Guardian. Retrieved July 28, 2015.
- Mike Masnick (4 Feb 2015). "Senator Wyden Follows Up With Eric Holder On All Of The Requests The DOJ Has Totally Ignored". Tech Dirt. Retrieved July 31, 2015.
- Marc Ambinder (February 1, 2010). "Obama's Secret Wiretap Memo". DHS/NPPD/PIA-029 Automated Indicator Sharing. The Atlantic. Retrieved July 31, 2015.
- Cory Bennett (4 Aug 2015). "White House endorses Senate cyber bill". The Hill. Retrieved 4 Oct 2015.
- 16 Sep 2015. "Homeland Security chief pushes Senate to move cyber bill". The Hill. Retrieved 20 Oct 2015.
- Eric Geller (3 Aug 2015). "Homeland Security joins privacy groups in pushback against CISA". The Daily Dot. Retrieved 20 Oct 2015.
- "DHS/NPPD/PIA-029 Automated Indicator Sharing". The Department of Homeland Security. 28 Oct 2015. Retrieved 18 Dec 2015.
- "A Zombie Bill Comes Back to Life: A Look at The Senate's Cybersecurity Information Sharing Act of 2014", Mark Jaycox, Electronic Frontier Foundation (EFF), June 29, 2014.
- "Beware the Dangers of Congress’ Latest Cybersecurity Bill", Sandra Fulton, ACLU (Washington), June 27, 2014.
- S.2588 - Cybersecurity Information Sharing Act of 2014, Congress.gov, Library of Congress.
- "Cybersecurity Information Sharing Act will help protect us", Dianne Feinstein, San Jose Mercury News, July 21, 2014.
- Forbes: Controversial Cybersecurity Bill Known As CISA Advances Out Of Senate Committee, Gregory S. McNeal, July 9, 2014.
- Center for Democracy and Technology: Analysis of Cybersecurity Information Sharing Act, Gregory T. Nojeim and Jake Laperruque, July 8, 2014.
- - CISA Security Bill Passes Senate With Privacy Flaws Unfixed ANDY GREENBERG AND YAEL GRAUER Oct 27, 2015
-  2010 to 2015 government policy: cyber security