Showing posts with label Current Issues In Information Law. Show all posts
Showing posts with label Current Issues In Information Law. Show all posts

Thursday, June 14, 2012

Seek Out What You Do Not Understand


By Charlotte Walden

We've all seen them.  Every time we patiently wait to use that new software program that we have just downloaded off the Internet, it is there. It stands between us and our coveted application.  The “it” that is being referred to, of course, is none other than the legally binding license agreement. You know, the one everyone clicks “agree” to, but never reads the terms and conditions to. Yeah, that one. Yet, licensing agreements are important and should be read, not ignored just because you want the latest and greatest technology. The following provides a good example of this principle: seek out what you do not understand/know.

What is about to unfold, then, is a chilling tail of irony. A tale where those who are in a profession to assist others in research, fail to research something for themselves. It is a tale that teaches those who are not only in the library profession, but in any other profession, about the importance of knowing and understanding licensing agreements.  

In her article, located in the recent edition of American Libraries, Deborah Caldwell-Stone accuses librarians of meeting a demand without fully researching the effects of that demand (2012). Specifically, Caldwell-Stone is refering to the agreement between Amazon and public libraries that allowed users to borrow library books on their Kindles (2012).

Well, that’s not so bad isn’t it? Shouldn’t we be happy that libraries will still be able to provide a service in the digital age? Yes, but not when these agreements violate a user’s privacy, like the Kindle, Amazon, and public library’s agreement does.

According to Caldwell-Stone,

[The agreement between Amazon and digital publishers] govern users’ rights and define the rules that control what can and cannot be done with the ebook or other digital content.

Thus, if the license that governs the library’s loan of the ebook requires the library to track and retain user data associated with a particular ebook and disclose that information to [Amazon], the library is obligated to track, retain, and disclose that information…
(2012)

Wait!?!?!?! Did that just say something about the “library tracking and retaining your data” and “disclosing” it to Amazon? Yes, it did. And so, every time someone checks out a book from the library on their Kindle, Amazon has access to that library user’s information. (Caldwell-Stone, 2012)  And aren’t librarians suppose to uphold users’ privacy rights?  Indeed they are, which is why some librarians, even before Caldwell-Stone’s article came out, were very upset by this arrangement (please see the video). As the LibrarianinBlack points out, this lack of research on may have also broken a few laws (2012).

Yet, as many have contended, licensing agreements are hard to understand (Patoway, 2012), which is probably why many of us just click. Or, as Caldwell-Stone contends, in our haste to provide the latest and greatest service, we make detrimental decisions. But, either excuse is a poor justification for not learning what you are agreeing to. Library professionals should be ashamed of such thinking. If you don’t understand a license agreement, find a way to understand it.

In this world of technology, we are used to instant gratification—and don’t think companies do not love to use instant gratification against us—but instant gratification has consequences that could affect us and our users. Thus, in our professional lives, we should always research what it is we are agreeing to—as it is legally binding—or else we will face the disdain of our peers, lawsuits and/or lose the trust of our users.


References:


Caldwell-Stone, D. (2012, May 29). A digital dilemma: E-books and user’s rights. American libraries. Retrieved from http://americanlibrariesmagazine.org/features/05292012/digital-dilemma-ebooks-and-users-rights.  

LibrarianinBlack (2011, October 18). Libraries got screwed by Amazon and Overdrive. YouTube video. Retrieved from http://www.youtube.com/watch?v=moy1w89TOss&feature=plcp.

Patowary, K. (2012, June 4). Make EULAs easier to read with EULAlyzer. Instantfunds. Retrieved from http://www.instantfundas.com/2012/06/make-eulas-easier-to-read-with.html

Wednesday, June 6, 2012

CISPA: The Finale



By Charlotte Walden


Alas, unless there is some news from the Senate, this will be the final CISPA blog.  To recap, the previous CISPA blogs have established that, if CISPA becomes law, private corporations may voluntarily share cyber threat information with the federal government. Furthermore, CISPA limits what the federal government and certified entities can do with cyber threat information; CISPA also trumps many privacy and public disclosure laws.

But what about the federal government sharing cyber threat information with private corporations? What about the federal government sharing information with other federal departments and agencies? Can I sue the government or a certified entity if they do not use my information in accordance with CISPA? Why was CISPA written? These are the questions that the following paragraphs will answer.  

The Federal Government Sharing Information With Private Companies and other Government Agencies or Departments

On April 13, 2012, Facebook Vice President of U.S. Policy,  Joel Kaplan, revealed Facebook’s support for CISPA. In that post, Kaplan wrote that CISPA will allow the federal government to share  information about  “an intrusion or other attack. . . with private companies . . . [in order to ensure] better the protection for users and . . .systems” (Kaplan, 2012). What part of CISPA was Kaplan writing about? Why section 1104 (a)(1) of course!  Yet, since CISPA gives the Director of National Intelligence the power to create regulations dealing with how the government (read: members of the intelligent community, a term that may also include private corporations) will share cyber threat intelligence with the private sector and utilities, CISPA will have to become law in order to find out what the that scheme may be. If CISPA does not pass, we will never know what the Director’s scheme would have been.  

Yet, CISPA does reveal how the federal government can share cyber threat information with other federal government agencies and departments. Section 1104 (b)(2) (A) states the head of the department of agency of the federal government who receives cyber threat information must provide that information to the National Cyber Security and Communications Integration Center of the Department of Homeland Security. Once this information is provided to the center, the federal department or agency may request the center to provide cyber threat information to another department or agency. (see section 1104(b)(2(B) of CISPA).  Some argue that this provision will allow cyber threat information to be used for massive data mining purposes.(Imagery, 2012). Others claim it will help protect cyber security (Kaplan, 2012).  Again, the age old debate of trading civil liberties for security rears its ugly head.


CISPA and Legal Recourse

But wait a minute. Earlier, these CISPA blogs revealed that Facebook supported CISPA, but wasn’t Facebook and other companies adamantly opposed to PIPA and SOPA earlier this year? What makes CISPA different? Some think that because CISPA takes the pressure to regulate users off private companies and gives that pressure to the government, Facebook and others like it (Explainers, 2012).  Others think that the provision that exemptions certified entities  from being sued is why former protestors of PIPA and SOPA like it (Kardell 2012). Section 1104 (b)(4) of CISPA is the section that exempts certified entities from being sued.

The Electronic Frontier Foundation (EFF), one of the many organizations who oppose this bill, contends that this liability exemption for certified entities  is “vague” and that the exemption could potentially harm innocent parties (Jaycox, 2012). For instance, the EFF argues, “[i]f a company learns about a security flaw, fails to fix it, and users' information is misused or stolen, companies cannot be held liable as long as the company acted ‘in good faith’”  (Jaycox, 2012). Essentially, CISPA limits judicial oversight of a certified entity’s activity with cyber threat information, which, in all honesty, could be your information (Jaycox, 2012).

However, while a person may be limited to bring a suit against a certified entity, a person may be able to bring a suit against the federal government who intentionally or willfully violates the cyber threat information use provisions of section 1104 (b)(3)(C) or subsection (c). [See section 1104 (d)(1) of CISPA]. However, one has two years after the violation of the applicable sections in order to bring a suit. Some find this to be problematic. As the EEF has pointed out, given the exemption from public disclosure, a person who has been wronged may have no idea that they have been wronged until well after the two-year statute of limitations (Timm, 2012). This, of course, depends on when the statute of limitations begins to run. Does it start the day the government violates the applicable section? Or does it start when you realize you have been wronged? Whatever the case, the EFF's point has merit.  Thus, it is quite possible, that this provision is merely smoke and mirrors and provides no judicial oversight of the federal government’s activities with your information what so ever.   

Why Was  CISPA Written In The First Place?

So, CISPA provides little judicial oversight, exempts cyber threat information from privacy and public disclosure laws, and allows private companies to voluntarily share cyber threat information (which could be your information) with the federal government. And just who is responsible for this bill and why was it created?

Congressmen Mike Rogers introduced CISPA to prevent foreign companies from stealing secret information from US databases (Beadon, 2012). The goal of CISPA is to ensure foreign companies do not gain unfair advantage over U.S. companies (Beadon, 2012). It is because of this, Rogers reasons, why private companies and the federal government need to share sensitive information.  (Beadon, 2012). It is because of this, Rogers reasons, why we need CISPA. While some argue that Roger's proposed legislation has merit to protect the U.S.'s Internet systems from cyber attacks (Kaplan, 2012), the bill, as it stands now, is too imperfect for reasons stated throughout this blog. 




After reading through these blogs and visiting the referenced links, please discuss what you think of CISPA. This blog contends that CISPA has the could create a disincentive to share certain types of information online, but this blog is also an open forum for concurrence and dissent. Perhaps you believe that the potential censorship CISPA might create would spawn a new way of sharing information. Or perhaps you see things a different way. On an additional note, for those curious, click here for a list of CISPA supporters. 

References:


Beadon, Leigh. (2012, Mat 7). CISPA sponser warns bill is needed because China’s Chinese hackers from China are stealing all-American secrets (China!).  Techdirt. Retrieved from http://www.techdirt.com/articles/20120504/08384918786/cispa-sponsor-warns-bill-is-needed-because-chinas-chinese-hackers-china-are-stealing-all-american-secrets-china.shtml.

Downes, Larry. (2012, April 27). Why CISPA can’t be fixed. Forbes. Retrieved from http://www.forbes.com/sites/larrydownes/2012/04/25/why-cispa-cant-be-fixed/.


Explainers. (2012, April). All about CISPA, the bill that wants to erode your online privacy. Lifehacker. Retrieved from http://lifehacker.com/5900962/why-microsoft-and-facebook-are-pro+cispa-but-anti+sopa.

Imagery. (2012, May 2). CISPA destroys privacy and shares data with the government. Weather imagery: A little mix of everything. Retrieved from http://www.weatherimagery.com/blog/cispa-destroys-privacy-and-shares-data-with-government/.

Jaycox, M. How the expansive immunity clauses in CISPA will facilitate abuse of user privacy. Electronic frontier foundation. Retrieved from https://www.eff.org/deeplinks/2012/04/how-expansive-immunity-clauses-cispa-will-facilitate-abuse-user-privacy-0.

Kaplan, J. (2012, April 13).  A message about CISPA. Facebook.  Retrieved from: http://www.facebook.com/note.php?note_id=10150723305109455.

Kardell, N. (2012, April 30). CISPA, approved by the House, poses threat to internet freedom. The National Law Review. Retrieved from http://www.natlawreview.com/article/cispa-approved-house-poses-threat-to-internet-freedom.

Timm, T. (2012, Aril 25). CISPA, “national security,” and NSA’s ability to read your e-mails. Electronic frontier foundation. Retrieved from https://www.eff.org/deeplinks/2012/04/cispa-national-security-and-nsa-ability-read-your-emails.

Friday, June 1, 2012

So, What Is Cyber Threat Information/Intelligence Under CISPA and What Is All This Internet Commotion About? Part II


By Charlotte Walden

The first CISPA blog established that private companies, such as Facebook and Google, might voluntarily share cyber threat information/intelligence with the federal government. But before discussing cyber threat information in more detail, it is best to discuss the importance of finding a bill, via the Library of Congress’s website, that has every body talking. By going directly to the text of the bill, the reader can decide for themselves which claims are valid and which are not. By relying solely on what someone else says a bill is, without ever having read the text for oneself, one has no way to substantiate the other’s claims. Indeed, without actually reading the text, one may very well oppose something they may have otherwise supported.

Though reading through and researching proposed legislation is a long and arduous process, it will help facilitate a more informed discussion about the proposed legislation. It is also hoped that the reader will imitate the writer’s process whenever the reader is curious about proposed legislation. Perhaps, after reading through the text yourself, you will disagree with the contention of this blog that CISPA is likely to cause a self-censorship amongst Internet users.  Or perhaps you won't. But how will you know if you never read the text for yourself?

With that said, let’s turn back to CISPA. In the last blog, the discussion mentioned cyber threat intelligence and cyber threat information very briefly, but without going into further detail; this blog will rectify that deficiency.

I. Cyber Threat Information/Intelligence: A Recap

First, CISPA defines cyber threat information and cyber threat intelligence similarly. Section 1104 (h)(4) defines cyber threat information and section 1104(h)(5) of CISPA defines cyber threat intelligence. The definitions are as follows:

The term ‘cyber threat information’ means information directly pertaining to— (whereas cyber threat intelligence means “intelligence in possession of an element of the intelligence community directly pertaining to—)
                 (i)  a vulnerability of a system or network of a government or private entity;

              (ii)   a threat to the integrity, confidentiality, or availability of a system or network of a government or private entity or any information stored on, processed on, or transiting such a system or network;

               (iii)  efforts to deny access to or degrade, disrupt, or destroy a system or network of a government or private entity; or

                    (iv)    efforts to gain unauthorized access to a system or network of a government or private entity, including to gain such unauthorized access for the purpose of exfiltrating information stored on, processed on, or transiting a system or network of a government or private entity.


(B) EXCLUSION.—Such term does not include information pertaining to efforts to gain unauthorized access to a system or network of a government or private entity that solely involve violations of consumer terms of service or consumer licensing agreements and do not otherwise constitute unauthorized access.

Thus, private companies are only allowed to voluntarily share your information if it fits the above definition.  However, some people are concerned that this definition could start a modern day McCarthyism. As one blogger put it, “depending on one’s political leanings, [a group or organization could land on the government’s watch list]” (Samson, 2012). This should and has raised concerns amongst librarians. If interpreted in a certain way, the cyber threat definitions could hinder information sharing on the Internet. For instance, if one looked at the structure of government as a system, then subversive comments on Facebook or subversive websites found on Google could constitute a vulnerability under the cyber threat definitions. Since vulnerability is not defined in CISPA, it is not quite clear what the drafters have in mind. Thus, with the potential of being placed on a government watch list, some dissenters might be afraid to share certain types of information on the Internet due to vague definitional terms.  


II. Limitations On Cyber Threat Information

After information is determined to be cyber threat information, CISPA sets up limitations on cyber threat information. Specifically, CISPA places limitations on how cyber threat information is shared, on what the government can do with cyber threat information, and on the sources where cyber threat information can come from.

A.   Limitations On Sharing Cyber Threat Information

Section 1104(b)(3)  states “Cyber threat information shared in accordance with paragraph (1)

[Editor's Note: paragraph (1) is a reference to the section about voluntarily sharing cyber threat information amongst certified entities and the Federal Government]—

(A) shall only be shared in accordance with any restrictions placed on the sharing of such information by the protected entity or self-protected entity authorizing such sharing, including appropriate anonymization or minimization of such information;

·               (Editor's Note: Some opponents believe this provision will allow companies like Facebook to share     
                comments with the federal government without redacting any personal information (Cole, 2012)).

(B) may not be used by an entity to gain an unfair competitive advantage to the detriment of the protected entity or the self-protected entity authorizing the sharing of information;

(C) if shared with the Federal Government

(i)  shall be exempt from disclosure under section 552 of title 5, United States Code

·      (Editor's Note: This is the Freedom of Information Act [FOIA], which allows the public to access federal agency records—although there are nine [9] exemptions that prevent such disclosure. Since cyber threat information deals with national security issues[see section 1104(b)(3)(C)(v) of CISPA] and FOIA already exempts information dealing with national security concerns [see 5 U.S.C.§ 552(b)(1)], it is likely that some cyber threat information would have been exempt from disclosure under FOIA without CISPA's exemption. This is exactly a point the American Library Association [ALA] made. In a letter stating their disapproval of CISPA, the ALA and other organizations stated:

[CISPA] unwisely and unnecessarily cuts off all public access to cyber threat information before the public and Congress have the chance to understand the types of information that are withheld under the bill. Much of the sensitive information private companies are likely to share with the government is already protected from disclosure under the FOIA. Other information that may be shared could be critical for the public to ensure its safety. The public needs access to some information to be able to assess whether the government is adequately combating cybersecurity threats and, when necessary, to hold officials accountable (American Association of Law Libraries et al., 2012).

Yet, FOIA is not the only public disclosure law cyber threat information is exempt from, cyber threat information is also exempt from disclosure under state, local, tribal, or regulation [see section 1104(b)(D)].


So, taken with the voluntary sharing scheme, CISPA's exemptions from public disclosure law creates a situation like Jeremy Bentham's panoptic prison, where the public does not know if they are actually being watched, but behave as though they are being watched--which, in this case, the behavior may result in a redacting of certain types of information on the internet. While such anti-public disclosure provisions may be helpful for national security purposes, they also have the potential to hinder information sharing for fear of Big Brother. Therein lies a great debate between national security and civil liberties). 

(ii) shall be considered proprietary information and shall not be disclosed to an entity outside of the Federal Government except as authorized by the entity sharing such information;

(iii) shall not be used by the Federal Government for regulatory purposes;

(vi) shall not be provided by the department or agency of the Federal Government receiving such cyber threat information to another department or agency of the Federal Government under paragraph(2)(A)[Note: this refers to the provision that allows sharing between federal agencies…more on that in a later blog] if—

(I) the entity providing such information determines that the provision of such information will undermine the purpose for which such information is shared; or

(II) unless otherwise directed by the President, the head of the department or agency of the Federal Government receiving such cyber threat information determines that the provision of such information will undermine the purpose for which such information is shared; and

(v) shall be handled by the Federal Government consistent with the need to protect sources and methods and the national security of the United States; and

(D) shall be exempt from disclosure under a State, local, or tribal law or regulation that requires public disclosure of information by a public or quasi-public entity.


B.   Limitations On How The Government Can Use This Information

Section 1104(c)(1) of CISPA states “[t]he Federal Government may use cyber threat information shared with the Federal Government in accordance with subsection (b)

[Editor's Note: the subsection referred to sets up the voluntary sharing of cyber threat information amongst certifies entities and the federal government]—

(A) for cybersecurity purposes;

(B) for the investigation and prosecution of cybersecurity crimes;

(C) for the protection of individuals from  the danger of death or serious bodily harm and the investigation and prosecution of crimes involving such danger of death or serious bodily harm;

(D) for the protection of minors from child pornography, any risk of sexual exploitation, and serious threats to the physical safety of such minor, including kidnapping and trafficking and the investigation and prosecution of crimes involving child pornography, any risk of sexual exploitation, and serious threats to the physical safety of minors, including kidnapping and trafficking, and any crime referred to in 2258A(a)(2) of title 18, United States Code; or

(E) to protect national security of the US


CISPA also requires the government to take “reasonable efforts” to limit the impact on privacy and civil liberties (see section 1104(c)(5)). Although, if one asks any lawyer or law student to describe what “reasonable efforts” might mean, one will soon realize that this does not offer much protection. Again, broad terms create a further disincentive for the public to share information on the Internet. 

Furthermore, on an additional note related to privacy and CISPA, the word “notwithstanding” used in Section 1401 (b)(1)(A) and section 1401 (b)(1)(B) [the sections that allow certified entities to voluntarily share information with the federal government] has raised concerns amongst the public. For instance, the non-partisan Congressional Review Committee stated that by using the word “notwithstanding” in any legislation, the drafters intend to “supersede any conflicting provisions of previous law” (Beth, 2003). This means, as some have contended, that, aside from being exempt from disclosure laws, CISPA could trump many privacy laws (McCallugh, 2012). The notwithstanding provisions have even lead some to claim that CISPA could violate the unreasonable search and seizure clause (4th Amendment) of the U.S. Constitution. (Please see the embedded YouTube video). 



C.    Sources Where The Government May Not Get Cyber Threat Information


  Section 1104 (c) (4) of CISPA states the federal government mat not use cyber threat information from the following sources:

(A)        Library circulation records.
(B)        Library patron lists.
(C)        Book sales records.
(D)        Book customer lists.
(E)        Firearms sales records.
(F)        Tax return records.
(G)       Educational records.
(H)       Medical records.


III. Limitations Placed On Cyber Threat Intelligence

     Under section 1104 (a)(2)(A)(i-ii), CISPA states that only certified entities or persons with appropriate security clearance may share classified cyber threat intelligence. Additionally, cyber threat intelligence may only be shared for national security purposes and may only be used by a certified entity or persons with appropriate security clearance in a manner that prevents unauthorized disclosure (see section 1104 (a)(2)(B)-(C)).


A Summation of CISPA Thus Far

     So, as CISPA stands in the Senate right now, the bill would allow private companies to voluntarily share cyber threat information with the federal government. This bill would also exempt cyber threat information from many disclosure laws and from many privacy laws. There is also controversy over what cyber threat information means.

    The next CISPA blog will discuss more controversial provisions, as well as give the reader some insight about why others support this bill.


    References:

     American Association of Law Libraries et al. (2012) Coalition letter to house representatives. American Library Association. Retrieved from http://www.openthegovernment.org/sites/default/files/Rogers%20cybersecurity%20letter%202.pdf  
  
     Cole, J. (2012, April 28). Explaining the CISPA cybersecurity bill, the latest threat to your privacy. Informed comment. Retrieved from http://www.juancole.com/2012/04/explaining-the-cispa-cybersecurity-bill-the-latest-threat-to-your-privacy.html.

     Beth, R. S. (2003, August 4). How bills amend statutes. CRS report for Congress. Retrieved from http://lugar.senate.gov/services/pdf_crs/senate/procedure/How_Bills_Amend_Statutes.pdf 

     McCallugh, D. (2012, April 27). How CISPA would affect you (faq). Cnet news. Retrieved from http://news.cnet.com/8301-31921_3-57422693-281/how-cispa-would-affect-you-faq/ .

     Samson, T. (2012, April 30). Why CISPA could kill the cloud. (web blog). InfoWorld. Retrieved from http://www.infoworld.com/t/cloud-computing/why-cispa-could-kill-the-cloud-192014





Friday, May 25, 2012

So, What Is All This CISPA That You Have Been Hearing About?


By Charlotte Walden


On April 26, 2012, the U.S. House of Representatives passed an amendment, called the Cyber Intelligence Sharing and Protection Act or CISPA, to the National Security Act of 1947  (Tsukayama, 2012). If passed, CISPA will allow private corporations and the government to share certain types of information with one another  (Tsukayama, 2012). As of this blog, CISPA is now going through the Senate (Tsukayama, 2012).



If CISPA passes the Senate, and after undergoing a process to ensure both houses have passed identical legislation, President Obama has indicated that, at presentment, he will veto the amendment (Knox,  2012). However, article one section seven of the U.S. Constitution allows both houses to override the president’s veto by a 2/3rds majority vote. So, even with Obama's veto, there is still a possibility that CISPA could become law.

This should be disconcerting to librarians who value the free sharing of uncensored information.  If passed, CISPA could create a disincentive for people who want to share certain types of information over the Internet. For instance, as the reader will learn from these blogs, the information governed by CISPA is exempt from many public disclosure and privacy laws. This means that the public will not know whether or not the information they shared on the Internet has been shared with the federal government. In addition to lack of public disclosure and privacy, vague definitions also offer little guidance as to what kinds of information will trigger CISPA. Likewise, CISPA offers little to no legal remedy if the federal government or a private corporation uses certain types of information in a way that is not authorized by CISPA. Thus, if the public fears that:



1.     they will end up on a government watch list because they are unsure if their information will trigger CISPA,
2.     they will have no way of knowing if their information has ended up on such a watch list, and
3.     they will have little legal recourse for a wrong committed by the government or a private corporation, then
4.     the public will likely become more restrictive on the information they choose to share on the Internet.

If the public is more restrictive on what they chose to share on the Internet, CISPA will likely have a censoring effect on the information that is made available on the Internet.

By using direct language from CISPA as it now appears, this blog will show the reader how CISPA works. Additionally, this blog will show the reader why some groups protest CISPA while others praise it.

Due to the size of the information that has been gathered for this topic, this blog will consist of multiple parts. The first part will show how corporations, like Google or Facebook, could, on a voluntary basis, share your information with the federal government. The second part will inform the the reader what kind of information will be governed under CISPA, as well as the limitations CISPA places on the use of that information. Finally, the last blog will show the reader how CISPA allows the federal government to share certain types of information with other federal agencies, as well as show the reader how CISPA offers little legal recourse. 


All right, let’s get started and ask:

I. What Part of CISPA Allows Private Corporations and the Federal Government To Share Information?


Under section 1104 (a)(2)(A)(i-ii), CISPA states that only certified entities or persons with appropriate security clearance may share classified cyber threat intelligence.

Great. But do you know who or what a certified entity is? Do you know what cyber threat intelligence means? Thought so.  Let’s break it down.


1. Cyber Threat Intelligence

According to section 1104 (h)(5), cyber threat intelligence “means intelligence in the possession of an element in the intelligence community directly pertaining to:


               (i)        a vulnerability of a system or network of a government or private entity;
            
               (ii)     a threat to the integrity, confidentiality, or availability of a system or network of a government or private entity or any information stored on, processed on, or transiting such a system or network;

               (iii)    efforts to deny access to or degrade, disrupt, or destroy a system or network of a government or private entity; or

               (iv)    efforts to gain unauthorized access to a system or network of a government or private entity, including to gain such unauthorized access for the purpose of exfiltrating information stored on, processed on, or transiting a system or network of a government or private entity. 


2. Certified Entity


A visualization of the certified entity definition.

A certified entity, according to section 1104 (h) (2), means “a protected entity, self-protected entity, or cyber security provider


             
              A.    gets security clearance from the Director of National Intelligence, AND
              B. can demonstrate to the Director that they can protect classified cyber threat intelligence





a.     Cybersecurity Provider


Section 1104 (h)(7) says a “cybersecurity provider means a non-governmental entity that provides goods or services intended to be
used for cybersecurity purposes.”
·      (. . . and as if that wasn’t enough) Cybersecurity purposes “means the purpose of ensuring the integrity, confidentiality, or availability of, or safeguarding, a system or network, including protecting a system or network from—
                      i.         a vulnerability to a system or network a threat to the integrity,
                     ii.         confidentiality, or availability of a system or network or any information stored on,processed on, or transiting such a system or network;
                   iii.         efforts to deny access to or degrade, disrupt, or destroy a system or network; OR  
                    iv.         efforts to gain unauthorized access to a system or network, including to gain such unauthorized access for the purpose of exfiltrating information stored on, processed on, or transiting a system or network.”

                    
b.    Protected Entity

Section 1104 (h)(11) says a protected entity “means an entity, other than an individual, that contracts with a cybersecurity provider for goods or services to be used for cybersecurity purposes.

c.     Self-Protected Entity

Section 1104 (h)(12) says “a self- protected entity means an entity, other than an individual, that provides goods or services for cybersecurity purposes to itself.”

All right, folks, with all those words, do you know who is authorized to share cyber security intelligence (i.e. who a certified entity is) under CISPA?

Need a hint?

Well, as some point out, the definition of a cybersecurity provider (which is also a certified entity) most likely includes corporations like Symantec, Norton Anti-Virus, and the like (Westervelt, 2012). However, as others point out, this definition could include so much more. “For example,” as one blogger wrote, “Google and Microsoft offer [some form of cyber security service with their] productivity apps for email, word processing, spreadsheets, and so forth.” (Samson, 2012). “[Additionally], [a]n ISP such as Verizon or AT&T protects your data as it travels in and out of your network” (Samson, 2012). Thus, by definition, Google, Verizon, Facebook, and others could be certified entities. Yet, a certified entity is also someone who contracts with a cybersecurity provider (a protected entity) or provides cybersecurity purposes to itself (a self-protected entity). Thus, some have argued that, contrary to the quote above, Google and Facebook would fall under the self-protected entity sub-definition (Sottek, 2012).

Regardless, of which sub-definition they fall under, it is likely that companies such as Google and Facebook, as long as the Director of National Intelligence grants them the okay, would be considered a certified entity under CISPA. As it just so happens, Facebook, who vehemently opposed SOPA and PIPA earlier this year, is one of CISPA’s big supporters (Kaplan, 2012). More on that later…

All right, so now that we have some idea about who these certified entities might be, one must ask who these entities are allowed to share cyber threat information with?

II. The Federal Government, Voluntarily


Section 1104 (b)(1)(A)(ii) of CISPA states that a cybersecurity provider (which is a certified entity, remember) has the discretion to share cyber threat information, with the consent of a protected entity, with the Federal Government for National Security purposes.

Additionally, section 1104(b)(1)(B)(ii) states that self-protected entities may also share cyber threat information with the Federal Government for cyber security purposes.

By the way, for those who noticed the change in terms, the only difference between cyber threat information and cyber threat intelligence is that the former refers directly to the information itself [section 1104(h)(4)], while the latter only refers to the possession of such information [section 1104 (h)(5)].  Otherwise, both definitions are basically word for word.

So, with the language that is going through the Senate right now, CISPA sets up a voluntary sharing of cyber threat information between the Federal Government and certified entities, which could include Facebook, Google, and many others. Since this is a voluntary sharing, CISPA notes that certified entities will not be  liable for not participating in CISPA (see section 1104 (g)(5) of CISPA). Additionally, CISPA also states, nothing in the bill will be construed as requiring certified entities to share cyber threat information with the government (see section 1104(c)(3)). 


All right, that is all for today. Stayed tuned for more blogs that will show how CISPA allows your information, if it is deemed to be a cybersecurity threat, to be shared amongst federal agencies. The next blogs will also discuss limitations, liability exemptions, legal recourse, and CISPA’s relation to other privacy laws. Later blogs will also reveal why some groups oppose CISPA, while other groups support it. Until next time, ta ta.     

References

Kaplan, J. (2012, April 13). A message about CISPA. (Facebook post). Retrieved from http://www.facebook.com/notes/facebook-washington-dc/a-message-about-cispa/10150723305109455.

Knox, O. (2012, April 6). CISPA cybersecurity bill gets veto threat from Obama. ABC news. Retrieved from http://abcnews.go.com/Politics/OTUS/cispa-cybersecurity-bill-veto-threat-obama/story?id=16214940#.T8A4AL8087A

Samson, T. (2012, April 30). Why CISPA could kill the cloud. (web blog). InfoWorld. Retrieved from http://www.infoworld.com/t/cloud-computing/why-cispa-could-kill-the-cloud-192014

Sottek, T.C. (2012, April 27). The Cyber Intelligence Sharing and Protection Act Explained. Retrieved from http://www.theverge.com/2012/4/27/2976718/cyber-intelligence-sharing-and-protection-act-cispa-hr-3523 

Tsukayama, H. (2012, April 27). Cispa passes the House, privacy battle moves to the Senate. The Washington Post. Retrieved from http://www.washingtonpost.com/blogs/post-tech/post/cispa-passes-the-house-privacy-battle-moves-to-senate/2012/04/27/gIQA7cJBlT_blog.html

Westervelt, R. (2012, April 27). CISPA intelligence information sharing bill passes house, headed to senate. (web blog).  IT Knowledge Exchange. Retrieved from http://itknowledgeexchange.techtarget.com/security-bytes/cispa-intelligence-information-sharing-bill-passes-house-headed-to-senate/