Draft cybersecurity executive order excludes commercial products
A new draft of the White House's cybersecurity executive order maintains the Administration's effort to improve the digital defenses of critical infrastructure — but it includes a number of changes, following several Administration meetings with stakeholders.
The Nov. 21 draft obtained by POLITICO grants more time to the feds to devise and implement a voluntary system to protect power plants, water systems and other forms of critical infrastructure from crippling attacks. Yet it makes clear that commercial products won't fall into that category. It further calls on the feds to figure out how to incentivize companies to agree to abide by new security standards. And it leaves it to agencies to figure out whether cybersecurity should factor into the federal procurement process. In general, the latest draft order follows the same contours as another draft that leaked at the end of September —improving cybersecurity practices at critical infrastructure, and pursuing new information-sharing capabilities. But the new version appears to specify in clearer terms that NIST would lead the way in developing a so-called Cybersecurity Framework, to identify gaps in the country's digital defenses and set forward standards and methodologies to address the risks. In the latest proposal, agencies have more time — 240 days, rather than 180 days — to put forward their initial draft of that framework, but still have a year after that to publish the final guidance. And the new version emphasizes the framework should be developed through "open public review and comment," and reviewed every three years. The September draft, shared among top deputies, had called on federal agencies to report on ways to make any new voluntary measures mandatory. The new draft preserves the section, and it asks agencies to evaluate if their current cybersecurity authorities are sufficient or duplicative. It also tasks the Pentagon and other agencies to determine whether the government procurement process — a multi-billion-dollar industry — should grant preferences to vendors adhering to strong cybersecurity standards. And it includes a key, highly desired carve-out for commercial IT: It makes clear those products cannot be designated as critical infrastructure at the greatest risk, which is an exception that industry had sought in legislation. The new draft further requires the Commerce and Treasury Departments to devise recommendations on how to incentivize companies to participate — a key sticking point for the Obama Administration, which has said it can only provide the best incentives to businesses through an act of Congress.