We've all seen them. Every time we patiently wait to use that new
software program that we have just downloaded off the Internet, it is there. It
stands between us and our coveted application.
The “it” that is being referred to, of course, is none other than the
legally binding license agreement. You know, the one everyone clicks “agree”
to, but never reads the terms and conditions to. Yeah, that one. Yet, licensing
agreements are important and should be read, not ignored just because you want
the latest and greatest technology. The following provides a good example of
this principle: seek out what you do not understand/know.
What is about to unfold,
then, is a chilling tail of irony. A tale where those who are in a profession
to assist others in research, fail to research something for themselves. It is
a tale that teaches those who are not only in the library profession, but in
any other profession, about the importance of knowing and understanding
licensing agreements.
In her article, located in
the recent edition of American Libraries,
Deborah Caldwell-Stone accuses librarians of meeting a demand without fully
researching the effects of that demand (2012). Specifically, Caldwell-Stone is
refering to the agreement between Amazon and public libraries that allowed
users to borrow library books on their Kindles (2012).
Well, that’s not so bad
isn’t it? Shouldn’t we be happy that libraries will still be able to provide a
service in the digital age? Yes, but not when these agreements violate a user’s
privacy, like the Kindle, Amazon, and public library’s agreement does.
According to Caldwell-Stone,
[The
agreement between Amazon and digital publishers] govern users’ rights and
define the rules that controlwhat can and cannot be
done with the ebook or other digital content.
Thus,
if the license that governs the library’s loan of the ebook requires the
library to track and retain user data associated with a particular ebook and
disclose that information to [Amazon], the library is obligated to track,
retain, and disclose that information…
(2012)
Wait!?!?!?!
Did that just say something about the “library tracking and retaining your
data” and “disclosing” it to Amazon? Yes, it did. And so, every time someone checks
out a book from the library on their Kindle, Amazon has access to that library
user’s information. (Caldwell-Stone, 2012) And aren’t librarians suppose to uphold users’
privacy rights?
Indeed they are, which is why some
librarians, even before Caldwell-Stone’s article came out, were very upset by
this arrangement (please see the video). As the LibrarianinBlack points out,
this lack of research on may have also broken a few laws (2012).
Yet,
as many have contended, licensing agreements are hard to understand (Patoway,
2012), which is probably why many of us just click. Or, as Caldwell-Stone
contends, in our haste to provide the latest and greatest service, we make
detrimental decisions. But, either excuse is a poor justification for not
learning what you are agreeing to. Library professionals should be ashamed of
such thinking. If you don’t understand a license agreement, find a way to
understand it.
In
this world of technology, we are used to instant gratification—and don’t think
companies do not love to use instant gratification against us—but instant
gratification has consequences that could affect us and our users. Thus, in our
professional lives, we should always research what it is we are agreeing to—as it
is legally binding—or else we will face the disdain of our peers, lawsuits and/or
lose the trust of our users.
Alas,
unless there is some news from the Senate, this will be the final CISPA blog. To recap, the previous CISPA
blogs have established that, if CISPA becomes law, private corporations may
voluntarily share cyber threat information with the federal government.
Furthermore, CISPA limits what the federal government and certified entities
can do with cyber threat information; CISPA also trumps many privacy and public
disclosure laws.
But
what about the federal government sharing cyber threat information with private
corporations? What about the federal government sharing information with other
federal departments and agencies? Can I sue the government or a certified
entity if they do not use my information in accordance with CISPA? Why was
CISPA written? These are the questions that the following paragraphs will
answer.
The Federal Government Sharing Information
With Private Companies and other Government Agencies or Departments
On
April 13, 2012, Facebook Vice President of U.S. Policy, Joel Kaplan,
revealed Facebook’s support for CISPA. In that post, Kaplan wrote that CISPA
will allow the federal government to share information about “an
intrusion or other attack. . . with private companies . . . [in order to
ensure] better the protection for users and . . .systems” (Kaplan, 2012). What
part of CISPA was Kaplan writing about? Why section 1104 (a)(1) of course!
Yet, since CISPA gives the Director of National Intelligence the power to
create regulations dealing with how the government (read: members of the
intelligent community, a term that may also include private corporations) will
share cyber threat intelligence with the private sector and utilities, CISPA
will have to become law in order to find out what the that scheme may be. If
CISPA does not pass, we will never know what the Director’s scheme would have
been.
Yet, CISPA does reveal how the federal government can share cyber threat information
with other federal government agencies and departments. Section 1104 (b)(2) (A)
states the head of the department of agency of the federal government who
receives cyber threat information must provide that information to the National
Cyber Security and Communications Integration Center of the Department of
Homeland Security. Once this information is provided to the center, the federal
department or agency may request the center to provide cyber threat information
to another department or agency. (see section 1104(b)(2(B) of CISPA).
Some argue that this provision will allow cyber threat information to be
used for massive data mining purposes.(Imagery, 2012). Others claim it will
help protect cyber security (Kaplan, 2012). Again, the age old debate of
trading civil liberties for security rears its ugly head.
CISPA and Legal Recourse
But
wait a minute. Earlier, these CISPA blogs revealed that Facebook supported
CISPA, but wasn’t Facebook and other companies adamantly opposed to PIPA and
SOPA earlier this year? What makes CISPA different? Some think that because
CISPA takes the pressure to regulate users off private companies and gives that
pressure to the government, Facebook and others like it (Explainers,
2012). Others think that the provision that exemptions certified entities
from being sued is why former protestors of PIPA and SOPA like it
(Kardell 2012). Section 1104 (b)(4) of CISPA is the section that exempts certified
entities from being sued.
The
Electronic Frontier Foundation (EFF), one of the many organizations who oppose
this bill, contends that this liability exemption for certified entities is “vague” and that the
exemption could potentially harm innocent parties (Jaycox, 2012). For instance,
the EFF argues, “[i]f a company learns about a security flaw, fails to fix it,
and users' information is misused or stolen, companies cannot be held liable as
long as the company acted ‘in good faith’” (Jaycox, 2012). Essentially,
CISPA limits judicial oversight of a certified entity’s activity with cyber
threat information, which, in all honesty, could be your information (Jaycox, 2012).
However,
while a person may be limited to bring a suit against a certified entity, a
person may be able to bring a suit against the federal government who
intentionally or willfully violates the cyber threat information use provisions
of section 1104 (b)(3)(C) or subsection (c). [See section 1104 (d)(1) of
CISPA]. However, one has two years after the violation of the applicable
sections in order to bring a suit. Some find this to be problematic. As the EEF
has pointed out, given the exemption from public disclosure, a person who has
been wronged may have no idea that they have been wronged until well after the
two-year statute of limitations (Timm, 2012). This, of course, depends on when the statute of limitations begins to run. Does it start the day the government violates the applicable section? Or does it start when you realize you have been wronged? Whatever the case, the EFF's point has merit. Thus, it is quite
possible, that this provision is merely smoke and mirrors and provides no judicial
oversight of the federal government’s activities with your information what so
ever.
Why Was CISPA Written In The First
Place?
So,
CISPA provides little judicial oversight, exempts cyber threat information from
privacy and public disclosure laws, and allows private companies to voluntarily
share cyber threat information (which could be your information) with the
federal government. And just who is responsible for this bill and why was it
created?
Congressmen
Mike Rogers introduced CISPA to prevent foreign companies from stealing secret
information from US databases (Beadon, 2012). The goal of CISPA is to ensure foreign companies do not gain unfair advantage over U.S. companies (Beadon, 2012). It is because of this, Rogers
reasons, why private companies and the federal government need to share
sensitive information. (Beadon, 2012). It is because of this, Rogers
reasons, why we need CISPA. While some argue that Roger's proposed legislation has merit to protect the U.S.'s Internet systems from cyber attacks (Kaplan, 2012), the bill, as it stands now, is too imperfect for reasons stated throughout this blog.
After reading through these blogs and visiting the
referenced links, please discuss what you think of CISPA. This blog contends that CISPA has the could create a disincentive to share certain types of information online, but this blog is also an open forum for concurrence and dissent. Perhaps you believe that the potential censorship CISPA might create would spawn a new way of sharing information. Or perhaps you see things a different way. On an additional note, for
those curious, click here for a list of CISPA supporters.
The
first CISPA blog established that private companies, such as Facebook and
Google, might voluntarily share cyber threat information/intelligence with the federal government. But before discussing cyber threat information in more
detail, it is best to discuss the importance of finding a bill, via the Library
of Congress’s website, that has every body
talking. By going directly to the text of the bill, the reader can decide for
themselves which claims are valid and which are not. By relying solely on what
someone else says a bill is, without ever having read the text for oneself, one
has no way to substantiate the other’s claims. Indeed, without actually reading
the text, one may very well oppose something they may have otherwise supported.
Though
reading through and researching proposed legislation is a long and arduous
process, it will help facilitate a more informed discussion about the proposed
legislation. It is
also hoped that the reader will imitate the writer’s process whenever the
reader is curious about proposed legislation. Perhaps, after reading through the text yourself, you will disagree with the contention of this blog that CISPA is likely to cause a self-censorship amongst Internet users. Or perhaps you won't. But how will you know if you never read the text for yourself?
With
that said, let’s turn back to CISPA. In the last blog, the
discussion mentioned cyber threat intelligence and cyber threat information
very briefly, but without going into further detail; this blog will rectify
that deficiency.
I. Cyber Threat Information/Intelligence: A
Recap
First,
CISPA defines cyber threat information and cyber threat intelligence similarly.
Section 1104 (h)(4) defines cyber threat information and section 1104(h)(5) of
CISPA defines cyber threat intelligence. The definitions are as follows:
The term ‘cyber threat
information’ means information directly pertaining to— (whereas cyber
threat intelligence means “intelligence in possession of an element of the
intelligence community directly pertaining to—)
(i) a vulnerability
of a system or network of a government or private entity;
(ii) a threat to
the integrity, confidentiality, or availability of a system or network of a
government or private entity or any information stored on, processed on, or transiting
such a system or network;
(iii) efforts to
deny access to or degrade, disrupt, or destroy a system or network of a
government or private entity; or
(iv) efforts to
gain unauthorized access to a system or network of a government or private
entity, including to gain such unauthorized access for the purpose of
exfiltrating information stored on, processed on, or transiting a system or
network of a government or private entity.
(B) EXCLUSION.—Such term does
not include information pertaining to efforts to gain unauthorized access
to a system or network of a government or private entity that solely involve
violations of consumer terms of service or consumer licensing agreements and do
not otherwise constitute unauthorized access.
Thus,
private companies are only allowed to voluntarily share your information if it
fits the above definition. However, some people are concerned that this
definition could start a modern day McCarthyism. As one blogger put it,
“depending on one’s political leanings, [a group or organization could land on
the government’s watch list]” (Samson, 2012). This should and has raised
concerns amongst librarians. If interpreted in a certain way, the cyber threat
definitions could hinder information sharing on the Internet. For instance, if
one looked at the structure of government as a system, then subversive comments
on Facebook or subversive websites found on Google could constitute a
vulnerability under the cyber threat definitions. Since vulnerability is not
defined in CISPA, it is not quite clear what the drafters have in mind. Thus, with
the potential of being placed on a government watch list, some dissenters might
be afraid to share certain types of information on the Internet due to vague definitional terms.
II. Limitations On Cyber Threat Information
After information is determined to be cyber threat information, CISPA
sets up limitations on cyber threat information. Specifically, CISPA places
limitations on how cyber threat information is shared, on what the government
can do with cyber threat information, and on the sources where cyber threat
information can come from.
A.Limitations On Sharing
Cyber Threat Information
Section
1104(b)(3) states “Cyber threat informationshared in accordance
with paragraph (1)
[Editor'sNote:
paragraph (1) is a reference to the section about voluntarily sharing cyber
threat information amongst certified entities and the Federal Government]—
(A) shall only be
shared in accordance with any restrictions placed on the sharing of
such information by the protected entity or self-protected entity
authorizing such sharing, including appropriate anonymization or
minimization of such information;
· (Editor's Note: Some
opponents believe this provision will allow companies like Facebook to share comments with the federal government without redacting any personal information
(Cole, 2012)).
(B) may not be usedby an entity to gain an unfair competitive advantage to the detriment of
the protected entity or the self-protected entity authorizing the sharing of
information;
(C)
if shared with the Federal Government—
(i)shall be exempt
from disclosureunder section 552 of title 5, United States Code
·(Editor's Note: This is the Freedom
of Information Act [FOIA], which allows
the public to access federal agency records—although there are nine [9]
exemptions that prevent such disclosure. Since cyber threat information deals with
national security issues[see section 1104(b)(3)(C)(v) of CISPA] and FOIA already exempts information dealing with national security concerns [see 5
U.S.C.§ 552(b)(1)], it is likely that some cyber threat information
would have been exempt from disclosure under FOIA without CISPA's exemption. This is exactly a
point the American Library Association [ALA] made. In a letter stating their
disapproval of CISPA, the ALA and other organizations stated:
[CISPA]
unwisely and unnecessarily cuts off all public access to cyber
threat information before the public and Congress have the chance to
understand the types of information that are withheld under the bill. Much
of the sensitive information private companies are likely to share with the
government is already protected from disclosure under the FOIA. Other
information that may be shared could be critical for the public to ensure its
safety. The public needs access to some information to be able to
assess whether the governmentis adequately combating
cybersecurity threatsand, when necessary, to hold officials
accountable (American Association of Law Libraries et al., 2012).
Yet, FOIA is not the only public disclosure law cyber threat
information is exempt from, cyber threat information is also exempt from disclosure under state, local, tribal, or regulation [see section 1104(b)(D)].
So, taken with the voluntary sharing scheme, CISPA's exemptions from public disclosure law creates a situation like Jeremy Bentham's panoptic prison, where the public does not know if they are actually being watched, but behave as though they are being watched--which, in this case, the behavior may result in a redacting of certain types of information on the internet. While such anti-public disclosure provisions may be helpful for national security purposes, they also have the potential to hinder information sharing for fear of Big Brother. Therein lies a great debate between national security and civil liberties).
(ii) shall be considered
proprietary information and shall not be disclosed to an entity outside
of the Federal Government except as authorized by the entity sharing
such information;
(iii) shall not
be used by the Federal Government for regulatory purposes;
(vi) shall not
be provided by the department or agency of the Federal Government receiving
such cyber threat information to another department or agency of the Federal
Government under paragraph(2)(A)[Note: this refers to the provision that
allows sharing between federal agencies…more on that in a later blog] if—
(I) the entity
providing such information determines that the provision of such information
will undermine the purpose for which such information is shared; or
(II) unless
otherwise directed by the President, the head of the department or agency of
the Federal Government receiving such cyber threat information determines that
the provision of such information will undermine the purpose for which such
information is shared; and
(v) shall be
handled by the Federal Government consistent with the need to protect
sources and methods and the national security of the United States; and
(D) shall be exempt
from disclosure under a State, local, or tribal law or regulation that requires
public disclosure of information by a public or quasi-public entity.
B.Limitations On How The
Government Can Use This Information
Section 1104(c)(1) of
CISPA states “[t]he Federal Government may use cyber threat
information shared with the Federal Government in accordance with
subsection (b)
[Editor's Note: the subsection
referred to sets up the voluntary sharing of cyber threat information amongst
certifies entities and the federal government]—
(A) for cybersecurity
purposes;
(B) for the investigation
and prosecution of cybersecurity crimes;
(C) for the protection
of individuals from the danger of death or serious bodily harm and
the investigation and prosecution of crimes involving such danger of
death or serious bodily harm;
(D) for the protection
of minors from child pornography, any risk of sexual exploitation, and
serious threats to the physical safety of such minor, including kidnapping and
trafficking and the investigation and prosecution of crimes involving child
pornography, any risk of sexual exploitation, and serious threats to the
physical safety of minors, including kidnapping and trafficking, and any crime
referred to in 2258A(a)(2) of title 18, United States Code; or
(E) to protect national security of the US
CISPA
also requires the government to take “reasonable efforts” to limit the impact
on privacy and civil liberties (see section 1104(c)(5)). Although, if one asks
any lawyer or law student to describe what “reasonable efforts” might mean, one
will soon realize that this does not offer much protection. Again, broad terms create a further disincentive for the public to share information on the Internet.
Furthermore,
on an additional note related to privacy and CISPA, the word “notwithstanding”
used in Section 1401 (b)(1)(A) and section 1401 (b)(1)(B) [the sections that
allow certified entities to voluntarily share information with the federal
government] has raised concerns amongst the public. For instance, the
non-partisan Congressional Review Committee stated that by using the word
“notwithstanding” in any legislation, the drafters intend to “supersede any
conflicting provisions of previous law” (Beth, 2003). This means, as some have
contended, that, aside from being exempt from disclosure laws, CISPA could
trump many privacy laws (McCallugh, 2012). The notwithstanding provisions have
even lead some to claim that CISPA could violate the unreasonable search and
seizure clause (4th Amendment) of the U.S. Constitution. (Please see
the embedded YouTube video).
C.Sources Where The
Government May Not Get Cyber Threat Information
Section
1104 (c) (4) of CISPA states the federal government mat not use cyber threat
information from the following sources:
(A)Library circulation
records.
(B)Library patron lists.
(C) Book sales records.
(D)Book customer lists.
(E) Firearms sales records.
(F) Tax return records.
(G)Educational records.
(H)Medical records.
III. Limitations Placed On Cyber Threat
Intelligence
Under section 1104 (a)(2)(A)(i-ii), CISPA states that only certified entities
or persons with appropriate security clearance may share classified cyber
threat intelligence. Additionally, cyber threat intelligence may only be
shared for national security purposes and may only be used by a
certified entity or persons with appropriate security clearance in a manner
that prevents unauthorized disclosure (see section 1104 (a)(2)(B)-(C)).
A Summation of CISPA Thus Far
So,
as CISPA stands in the Senate right now, the bill would allow private companies
to voluntarily share cyber threat information with the federal government. This
bill would also exempt cyber threat information from many disclosure laws and
from many privacy laws. There is also controversy over what cyber threat
information means.
The
next CISPA blog will discuss more controversial provisions, as well as give the
reader some insight about why others support this bill.
On
April 26, 2012, the U.S. House of Representatives passed an amendment, called
the Cyber Intelligence Sharing and Protection Act or CISPA, to the National
Security Act of 1947 (Tsukayama, 2012). If passed, CISPA will allow
private corporations and the government to share certain types of information
with one another (Tsukayama, 2012). As of this blog, CISPA is now going
through the Senate (Tsukayama, 2012).
If
CISPA passes the Senate, and after undergoing a process to ensure both houses
have passed identical legislation, President Obama has indicated that, at
presentment, he will veto the amendment (Knox, 2012). However, article one section seven of the U.S. Constitution allows both houses to override the
president’s veto by a 2/3rds majority vote. So, even with Obama's veto,
there is still a possibility that CISPA could become law.
This
should be disconcerting to librarians who value the free sharing of
uncensored information. If passed, CISPA could create a
disincentive for people who want to share certain types of information over the
Internet. For instance, as the reader will learn from these blogs, the information governed by CISPA is exempt from many public disclosure and privacy laws. This means that the public will not know whether or
not the information they shared on the Internet has been shared with the
federal government. In addition to lack of public disclosure and privacy, vague
definitions also offer little guidance as to what kinds of information will
trigger CISPA. Likewise, CISPA offers little to no legal remedy if the federal
government or a private corporation uses certain types of information in a way
that is not authorized by CISPA. Thus, if the public fears that:
1.they will end up on a
government watch list because they are unsure if their information will
trigger CISPA,
2.they will have no way of
knowing if their information has ended up on such a watch list, and
3.they will have little
legal recourse for a wrong committed by the government or a private
corporation, then
4.the public will likely
become more restrictive on the information they choose to share on the
Internet.
If
the public is more restrictive on what they chose to share on the Internet,
CISPA will likely have a censoring effect on the information that is made
available on the Internet.
By
using direct language
from CISPA as it now appears, this blog will show the reader
how CISPA works. Additionally, this blog will show the reader why some groups
protest CISPA while others praise it.
Due
to the size of the information that has been gathered for this topic, this blog
will consist of multiple parts. The first part will show how corporations, like
Google or Facebook, could, on a voluntary basis, share your information with
the federal government. The second part will inform the the reader what kind of
information will be governed under CISPA, as well as the limitations CISPA
places on the use of that information. Finally, the last blog will show the
reader how CISPA allows the federal government to share certain types of
information with other federal agencies, as well as show the reader how CISPA offers
little legal recourse.
All
right, let’s get started and ask:
I. What Part of CISPA Allows Private
Corporations and the Federal Government To Share Information?
Under
section 1104 (a)(2)(A)(i-ii), CISPA states that only certified entities or persons
with appropriate security clearance may share classified cyber threat
intelligence.
Great.
But do you know who or what a certified entity is? Do you know what cyber
threat intelligence means? Thought so. Let’s break it down.
1. Cyber Threat Intelligence
According
to section 1104 (h)(5), cyber threat intelligence “means intelligence in the
possession of an element in the intelligence community directly pertaining to:
(i)a vulnerability of a system or network of a
government or private entity;
(ii)a threat to the integrity, confidentiality, or
availability of a system or network of a government or private entity or any
information stored on, processed on, or transiting such a system or network;
(iii)efforts to deny access to or degrade, disrupt,
or destroy a system or network of a government or private entity; or
(iv)efforts to gain unauthorized access to a system
or network of a government or private entity, including to gain such
unauthorized access for the purpose of exfiltrating information stored on,
processed on, or transiting a system or network of a government or private
entity.
2. Certified Entity
A visualization of the certified entity definition.
A
certified entity, according to section 1104 (h) (2), means “a protected
entity, self-protected entity, or cyber security provider
A.gets security clearance from the Director of National Intelligence, AND B. can demonstrate to the Director that they can protect classified
cyber threat intelligence
a.Cybersecurity
Provider
Section
1104 (h)(7) says a “cybersecurity provider means a non-governmental entity that
provides goods or services intended to be
used
for cybersecurity purposes.”
·(. . . and as
if that wasn’t enough) Cybersecurity purposes “means the purpose of ensuring
the integrity, confidentiality, or availability of, or safeguarding, a system
or network, including protecting a system or network from—
i.a vulnerability to a system or network a threat to the integrity,
ii.confidentiality, or availability of a system or network or any
information stored on,processed on, or transiting such a system or network;
iii.efforts to deny access to or degrade, disrupt, or destroy a system or
network; OR
iv.efforts to gain unauthorized access to a system or network, including to
gain such unauthorized access for the purpose of exfiltrating information
stored on, processed on, or transiting a system or network.”
b.Protected
Entity
Section
1104 (h)(11) says a protected entity “means an entity, other than an
individual, that contracts with a cybersecurity provider for goods or services
to be used for cybersecurity purposes.
c.Self-Protected
Entity
Section
1104 (h)(12) says “a self- protected entity means an entity, other than an
individual, that provides goods or services for cybersecurity purposes to
itself.”
All
right, folks, with all those words, do you know who is authorized to share
cyber security intelligence (i.e. who a certified entity is) under CISPA?
Need
a hint?
Well,
as some point out, the definition of a cybersecurity provider (which is also a certified entity) most likely includes corporations like Symantec,
Norton Anti-Virus, and the like (Westervelt, 2012). However, as others point
out, this definition could include so much more. “For example,” as one blogger
wrote, “Google and Microsoft offer [some form of cyber security service with
their] productivity apps for email, word processing, spreadsheets, and so
forth.” (Samson, 2012). “[Additionally], [a]n ISP such as Verizon or AT&T
protects your data as it travels in and out of your network” (Samson, 2012). Thus, by definition, Google, Verizon, Facebook, and others could be certified entities. Yet, a certified entity is also someone who contracts with a cybersecurity
provider (a protected entity) or provides cybersecurity purposes to itself (a
self-protected entity). Thus, some have argued that, contrary to the quote
above, Google and Facebook would fall under the self-protected entity
sub-definition (Sottek, 2012).
Regardless,
of which sub-definition they fall under, it is likely that companies such as
Google and Facebook, as long as the Director of National Intelligence grants
them the okay, would be considered a certified entity under CISPA. As it just so
happens, Facebook, who vehemently opposed SOPA and PIPA earlier this year,
is one of CISPA’s big supporters (Kaplan, 2012). More on that later…
All
right, so now that we have some idea about who these certified entities might be,
one must ask who these entities are allowed to share cyber threat information
with?
II. The Federal Government, Voluntarily
Section
1104 (b)(1)(A)(ii) of CISPA states that a cybersecurity provider (which is a
certified entity, remember) has the discretion to share cyber threat
information, with the consent of a protected entity, with the Federal
Government for National Security purposes.
Additionally,
section 1104(b)(1)(B)(ii) states that self-protected entities may also
share cyber threat information with the Federal Government for cyber security
purposes.
By
the way, for those who noticed the change in terms, the only difference between
cyber threat information and cyber threat intelligence is that the former
refers directly to the information itself [section 1104(h)(4)], while the
latter only refers to the possession of such information [section 1104
(h)(5)]. Otherwise, both definitions are basically word for word.
So,
with the language that is going through the Senate right now, CISPA sets up a voluntary
sharing of cyber threat information between the Federal Government and
certified entities, which could include Facebook, Google, and many others. Since this is a voluntary sharing, CISPA notes that certified entities will not be liable
for not participating in CISPA (see section 1104
(g)(5) of CISPA). Additionally, CISPA also states, nothing in the bill will be construed as requiring
certified entities to share cyber threat information with the government (see
section 1104(c)(3)).
All
right, that is all for today. Stayed tuned for more blogs that will show how
CISPA allows your information, if it is deemed to be a cybersecurity threat, to
be shared amongst federal agencies. The next blogs will also discuss
limitations, liability exemptions, legal recourse, and CISPA’s relation to
other privacy laws. Later blogs will also reveal why some groups oppose CISPA,
while other groups support it. Until next time, ta ta.