Criminal Justice & the Rule of Law Cybersecurity & Tech Surveillance & Privacy

Susan Landau on Cybersecurity Bills

Jack Goldsmith
Thursday, May 3, 2012, 7:15 AM
Susan Landau is currently a visiting scholar at Harvard's Computer Science Department, formerly a Distinguished Engineer at Sun Microsystems, and the author of Surveillance or Security? The Risks Posed by New Wiretapping Technologies.  She is also one of the most knowledgeable people I know about cybersecurity policy.

Published by The Lawfare Institute
in Cooperation With
Brookings

Susan Landau is currently a visiting scholar at Harvard's Computer Science Department, formerly a Distinguished Engineer at Sun Microsystems, and the author of Surveillance or Security? The Risks Posed by New Wiretapping Technologies.  She is also one of the most knowledgeable people I know about cybersecurity policy.   She writes in with this comment about the pending cybersecurity bills:
We're in a very odd situation. There are four cybersecurity bills --- Lieberman-CollinsMcCainCISPALungren --- currently on the hill (CISPA has already passed in the House).  All four allow "information sharing" of cyber threats, but each bill proposes a different federal agency with which the private sector should share the information: Department of Homeland Security, military cybersecurity centers, unspecified federal agencies (the NSA likely to take the lead).  This makes no sense. The disparities between the bills make clear that the right solution, or set of solutions, is not yet at hand. The point to keep in mind is that cybersecurity is not one problem but multiple ones.  Protecting the control systems of the power grid from intrusion is fundamentally different from protecting private-sector proprietary information against electronic espionage, and the right set of laws, regulations, and techniques to do each properly will vary considerably. Instead of the four Congressional bills that can't agree on which way to pull, we should be devising narrowly targeted solutions that handle the different cyber risks differently.  In the long run, only such targeted cybersecurity solutions are likely to be effective.

Jack Goldsmith is the Learned Hand Professor at Harvard Law School, co-founder of Lawfare, and a Non-Resident Senior Fellow at the American Enterprise Institute. Before coming to Harvard, Professor Goldsmith served as Assistant Attorney General, Office of Legal Counsel from 2003-2004, and Special Counsel to the Department of Defense from 2002-2003.

Subscribe to Lawfare