{"title":"(Re-)Configuring Federal Cybersecurity Regulation: From Critical Infrastructures to the Whole-of-the-Nation","authors":"Graham Streich","doi":"10.18060/27133","DOIUrl":null,"url":null,"abstract":"Cyberattacks are one of the greatest threats to the United States’ national security. Facing an increase in cyberattacks, the current patchwork of federal cybersecurity regulations does not maximize the country’s ex ante defense that should protect the entire nation. This Article examines federal agencies’ involvement in promulgating cybersecurity regulations and Executive Branch cybersecurity actions, identifying three shortcomings in the current framework: (1) the nation lacks a general cybersecurity agency with regulatory and enforcement authority, (2) cybersecurity programs often rely on business participation and leadership without incorporating non-profit organizations and individuals, and (3) cybersecurity approaches often overemphasize the importance of attributing attacks to the corresponding culprits. To rectify these weaknesses and maximize cyber defense, this Article argues that Congress shouldexpand the Cybersecurity and Infrastructure Security Agency’s rulemaking and enforcement authority to monitor and mitigate cyber threats across varying sectors, including government, businesses, insurers, non-profit organizations, and individuals.","PeriodicalId":81517,"journal":{"name":"Indiana law review","volume":" ","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2023-02-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Indiana law review","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.18060/27133","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Cyberattacks are one of the greatest threats to the United States’ national security. Facing an increase in cyberattacks, the current patchwork of federal cybersecurity regulations does not maximize the country’s ex ante defense that should protect the entire nation. This Article examines federal agencies’ involvement in promulgating cybersecurity regulations and Executive Branch cybersecurity actions, identifying three shortcomings in the current framework: (1) the nation lacks a general cybersecurity agency with regulatory and enforcement authority, (2) cybersecurity programs often rely on business participation and leadership without incorporating non-profit organizations and individuals, and (3) cybersecurity approaches often overemphasize the importance of attributing attacks to the corresponding culprits. To rectify these weaknesses and maximize cyber defense, this Article argues that Congress shouldexpand the Cybersecurity and Infrastructure Security Agency’s rulemaking and enforcement authority to monitor and mitigate cyber threats across varying sectors, including government, businesses, insurers, non-profit organizations, and individuals.