Showing posts with label Policy. Show all posts
Showing posts with label Policy. Show all posts

Saturday, October 13, 2018

Interesting Executive Actions: President Trump's Executive Orders and More

(Updated 10-13-2018)

Executive orders, Presidential memoranda, Presidential determinations, Presidential proclamations, Administrative orders, Presidential notices, Presidential sequestration orders and National security presidential memoranda; White House NewsList of executive actions by Donald Trump


Executive Orders (EO):

Federal Register:
2018 Donald Trump Executive Orders
2017 Donald Trump Executive Orders


Interesting 2018 Executive Orders 13820 to 13852 (No. 56 to 88)

EO 13840: Ocean Policy to Advance the Economic, Security, and Environmental Interests of the United States
EO 13834: Efficient Federal Operations
EO 13833: Enhancing the Effectiveness of Agency Chief Information Officer
EO 13826: Federal Interagency Council on Crime Prevention and Improving Reentry
EO 13823: Protecting America Through Lawful Detention of Terrorists
EO 13822: Supporting Our Veterans During Their Transition From Uniformed Service to Civilian Life [More]

Friday, October 12, 2018

The China Challenge: Economic Sticks and What To Do About Them

The Senate Foreign Relations Committee is holding a three-part hearing series under the 'Subcommittee on East Asia, The Pacific, and International Cybersecurity Policy' on a topic it calls "The China Challenge." The first hearing "The China Challenge, Part 1: Economic Coercion as Statecraft," was held on July 24, 2018, the second "The China Challenge, Part 2: Security and Military Developments" was held on September 5, 2018 and the third is pending.

The first hearing was attended by two witnesses, Dan Blumenthal of American Enterprise Insititute (AEI) and Ely Ratner of Center for a New American Security (CNAS). During his testimony, Mr. Ratner presented a report prepared by CNAS titled "China's Use of Coercive Economic Measures." For a better understanding of what is meant by coercive economic measures, here is part of the introduction from Chapter 1 of the report:
China has long used economic statecraft as a pillar of its foreign policy. Historically, Chinese leaders used economic inducements ranging from gifts to the promise of loans and investments to solidify relationships with foreign governments and advance Chinese influence. [...]

In 2013, China launched the Belt and Road Initiative (BRI), a potentially $1 trillion, almost 70-country global infrastructure development initiative that is likely to significantly expand Chinese influence from Asia to Europe. [...]

Over the past decade, however, China has also used the “sharp end” of its economic statecraft, turning to coercive economic measures as a tool. The authors define coercive economic measures as China’s restrictions on trade or investment intended to impose financial or economic costs on a target in pursuit of a foreign policy objective or to influence a foreign government to offer policy concessions to China. As used here, coercion indicates the use, or threatened use, of economic “sticks,” but not the use of positive inducements or other tools, as commonly included in academic definitions.

Sunday, September 30, 2018

LEO Mental Health and Wellness Act

H.R. 2228 the “Law Enforcement Mental Health and Wellness Act of 2017” was signed into law January 10, 2018.




Wednesday, September 19, 2018

FinTech Hearing: Examining Digitization, Data, and Technology

Brian Knight of George Mason University testified before Congress yesterday September 18, 2018 at at hearing titled "Fintech: Examining Digitization, Data, and Technology." From the Chaiman's opening statement:
Today, I hope to hear from our witnesses about the ways in which fintech is changing the financial sector and the improvements that can be made to ensure the regulatory landscape welcomes that innovation; what kind of data is being collected and used, and how such data is secured and protected; and what are the opportunities and challenges going forward?

From Mr. Knight's statement, pertaining to data collection:
As the Treasury Report notes, the ability of financial service providers to collect and utilize a broader and more diverse selection of consumer data has the potential to improve the provision of financial services, especially to consumers who are poorly served by the status quo.3 Not only could cost-effective access to more data help established firms improve their offerings, it could also encourage competition and innovation from new entrants.  
While the ability to access and utilize more data has a significant upside, it also presents risks. For example, it is possible that the more granular a dataset a financial institution collects on a consumer, the more harm a security breach could cause. Data that might be relatively harmless at one level of detail could become highly sensitive at another. What could be labeled “professional or medical services” at one level of detail could be labeled “marriage counseling” at another. While obtaining more information could allow financial services providers to offer better products, we should also be alert to the risks that could develop.  
Additionally, as the Treasury Department notes, there are divergent regulations at the state level regarding data security and breach notification.4 These different requirements can increase compliance costs for firms and result in citizens being regulated by sets of rules put in place without consultation with them, the consumers.5 Given the predominantly interstate nature of cybersecurity, there is little question that Congress could constitutionally preempt state law to create consistent national standards, and given the costs of the status quo, it may want to consider doing so.

A FinTech hearing was also held earlier this year. Mr. Knight testified at that hearing as well.



Tuesday, September 18, 2018

Improving Tech Expertise for Congress

Georgetown Law’s Institute for Technology Law & Policy held a workshop in June 2018 to discuss improving tech and science policy resource services for Congress. Here are some details from the report:
This report summarizes the presentations and reflections of a group convened by Georgetown Law’s Institute for Technology Law & Policy in June 2018 to discuss strategies for improving science and technology policy resources for Congress. The workshop considered recent proposals for reestablishing a technology assessment function in Congress, such as reviving the Office of Technology Assessment (OTA), or shifting tech assessment responsibilities to the Government Accountability Office (GAO) or Congressional Research Service (CRS). It also considered whether certain aspects of tech assessment can be met by outside groups such as the National Academies. The workshop brought together former OTA staff and leadership, current congressional staffers, academics and policy experts for a two-hour discussion.1

Monday, September 17, 2018

Smarter IoT Privacy Protections for Kids (CA SB 327)

From a WaPo article:
A bill to set cybersecurity standards for Web-connected devices — from thermostats to webcams to cars — is awaiting Gov. Jerry Brown’s (D) signature after cruising through the state legislature late last month. If Brown signs it, California would become the first state to pass legislation to govern security of the Internet of Things...
The California bill, SB-327, seeks to address some of those flaws, setting baseline cybersecurity standards for IoT devices where none exist. 

A most recent bill analysis is posted at California's Legislation Information website. The analysis includes a summary of existing law, a summary of this bill, background, comments, fiscal effects, and those groups in support and those opposed with a brief summary of their arguments. Here are some comments from the 8/28/18 Senate Floor Analysis:
Consumer devices that connect to the internet have moved well beyond the traditional desktop PC to include a wide variety of consumer electronics, such as microwaves, refrigerators, and children’s toys. While such capabilities may increase product functionality, many consumers are uninformed about the consequences of owning connected devices. Consumers may buy a device without realizing how it makes use of the internet, what types of information it collects, and how that information is used, until well after they have begun using the device in their home. Some internet connected toys, for example, prompt children to provide personal data verbally - including their parents’ names, the name of their school, and where they live – and explicitly reserve the right to conduct direct marketing towards kids. An alarming number of these internet connected devices lack even the most basic security features, rendering them vulnerable to hacking and coordinated cyber attacks.
This bill creates a common sense security requirement for internet connected devices that can evolve as technology evolves. Mirroring a provision in California’s Data Breach Law, this bill requires manufacturers to equip their devices with reasonable security features appropriate to the nature of the device and the information it collects.

Sunday, September 16, 2018

California Consumer Privacy Act

In June 2018, California passed the "California Consumer Privacy Act of 2018" (or AB 375). The law is scheduled to go into effect January 1, 2020, however, it may be subject to legislative changes brought on by internet and tech companies. It will essentially give the residents of California 1) the right to know the data businesses are collecting on them 2) the right to modify or delete their data or opt-out of it being shared and 3) the right to action under a data breach. The privacy law is the first of its kind in the US. Here are a few more links on the matter:


"California Consumer Privacy Act" website | Source: caprivacy.org

Wednesday, September 12, 2018

IoT Security and the Looming Legal ‘Feeding Frenzy’

The lawyer who is representing the 220,000 plaintiffs in the 2015 Jeep hack class action lawsuit,  Ijay Palansky, presented at Black Hat USA 2018. He outlines the potential pathways of harm for the IoT including DDoS attacks, IoT ransomware, data breaches, privacy-related events, potential for cyber-physical, etc. He offers that there are currently few precedents or standards of care for how the law applies to tech and the complex IoT supply chain ecosystem. Here are his presentation slides and abstract:
Legal Liability for IOT Cybersecurity Vulnerabilities
There has been much discussion of "software liability," and whether new laws are needed to encourage or require safer software. My presentation will discuss how -- regardless of whether new laws are passed -- a tidal wave of litigation over defective IoT cybersecurity is just over the horizon.
The presentation will focus on a well-known example: Charlie Miller and Chris Valasek's 2015 Jeep hack. I'm lead counsel in the ongoing federal litigation over the cybersecurity defects Charlie and Chris exposed, and that are shared by 1.4 million Chrysler vehicles. As far as I know, our case is one of the first, and the biggest, that involves claims that consumers should be compensated for inadequate cybersecurity in IoT products.
This case is the tip of the iceberg. IOT products are ubiquitous, and in general their cybersecurity is feeble, at best. In the event of a cyberphysical IoT hack that causes injury, there are established legal doctrines that can be used to impose liability every company involved in the design, manufacturing, and distribution of an exploited IoT device or even its cyber-related components. Such liability could be crippling, if not fatal, for organizations that don't know how to properly handle and prepare for potential lawsuits.
Taking steps to minimize legal exposure before an accident happens or a lawsuit is filed—in the design, manufacture, product testing, and marketing phases of an IoT product—can be the difference between life and death for IoT companies. Knowing what steps to take and how to take them requires an understanding of the core legal principles that will be applied in determining whether a company is liable.
Article.

Tuesday, September 11, 2018

Cybersecurity and Infrastructure Security Agency Act

A bill (H.R. 3359) drafted to rename and reorganize DHS' NPPD (National Protection and Programs Directorate) as CISA (Cybersecurity and Infrastructure Security Agency) was introduced by Rep. Michael McCaul (R-TX) in July 2017. It passed in the House in December 2017, and is currently in the Senate with the Homeland Security Committee.

According to NPPD's Under Sec. Chris Krebs, "What we are trying to establish at the topline is… put a name on the door that tells stakeholders what we do,” said Krebs. “I need to be able to communicate, right out the gate. When I have that first meeting or have that phone call that says let’s work together, I’m not spending the first five minutes explaining what my name is." Here are a few more tweets and details about it.





Sunday, September 2, 2018

GCSC Thought Piece on Internet Policy Making

The University of Aarhaus’ Professor Emeritus Wolfgang Kleinwächter composed a thought piece for the Global Commission on the Stability of Cyberspace (GCSC) titled “Towards a Holistic Approach for Internet Related Public Policy Making”.

He reviews various layers and mechanisms of the global internet governance ecosystem and additionally suggests several options to build a more cohesive policy platform.

Professor Kleinwächter provides a general categorization of internet-related public policy issues that were identified in a 2015 UN Working Group on Enhanced Cooperation. 600 issues were identified. These issues are categorized into four baskets. He further lists more specialized topics for each basket along with their available stakeholder negotiation platforms.

The four baskets are Cybersecurity, Digital Economy, Human Rights, and Technology. From his thought piece:
Cybersecurity
  1. Norms of behavior of state and non-state actors in cyberspace: UNGGE, OSCE, G7, BRICS, GCSC, GCCS, WEF;
  2. Confidence building measures in cyberspace (CBMs): UNGGE, OSCE, ASEAN, G7, BRICS, GCSC, GCCS;
  3. Protection of the public core of the Internet and critical infrastructure as electricity, financial transactions, transportation services and electoral systems: UN, G7, ICANN/PIT, GCSC, GCCS, MSC, NATO;
  4. Moratorium for the development of lethal autonomous weapon systems (LAWS) and other Internet based offensive cyber weapons: GGECCW, GCCS;
  5. Dual-use technologies: Wassenaar Arrangement, GCSC, GCCS;
  6. Fight against cybercrime: Council of Europe, Interpol/Europol, GFCE, GCSC, GCCS, WEF, EU, AU;
  7. Fight against the terrorist use of ICTs: UN Security Council Counter Terrorism Committee, Interpol/Europol, GCCS, GCSC, WEF.
Digital Economy
  1. Digital Trade: G7, G20, WTO, UNCTAD, OECD, WEF, IGF;
  2. eCommerce: WTO, UNCTAD, UNDP, UNCITRAL, OECD, WEF;
  3. Infrastructure development: UN Regional Commissions, ITU, UNCTAD, IGF, WSIS;
  4. Industry 4.0: G20, G7, WEF, IGF, OECD;
  5. Internet of Things : G20, G7, ITU-T, IGF, WEF, OECD;
  6. Artificial Intelligence :G7, IGF, WEF, OECD;
  7. Protection of Intellectual Property: WIPO, WSIS, IGF, INTA, OECD, ICANN/Trademark Clearinghouse.
Human Rights
  1. Access to the Internet: UNESCO, ITU, WSIS, IGF, APC;
  2. Freedom of expression: HRC, UNESCO, Council of Europe, OSCE, WSIS, IGF, FOC, RWB, HRW;
  3. Privacy in the digital age: HRC, UNESCO, Council of Europe, WSIS, IGF, FOC, ICANN/Whois;
  4. Right to education: HRC, UNESCO;
  5. Right to culture: HRC, UNESCO;
  6. Online Media: HRC, UNESCO, Council of Europe, OSCE;
  7. Future of work: HRC, ILO, Global Commission on the Future of Work.
Technical
  1. IP addresses: RIRs, IGF, WSIS, ITU;
  2. Domain Name System: ICANN, IGF, WSIS, ITU;
  3. Root server system: ICANN/PIT, IGF;
  4. Internet protocols: IETF, W3C, IEEE, 3GPP, ITU, ETSI, IGF;
  5. IOT: ITU-T, IGF, WSIS;
  6. OTT: ITU-T, IGF.
He writes that many times these issues are discussed in disconnected silos and that only a limited number of platforms, such as the IGF, enable multistakerholder discussions and a more holistic approach to public policy making.