"The National Institute of Standards and Technology’s Cybersecurity Framework is an excellent example of this... The Cybersecurity Framework — which contains guidance on how to identify, prevent, recover, and respond to security risks — is voluntary at this point, which means nobody follows it."
How "excellent" of an example could it be if no one follows it?
If he's worried about low-cost devices today that don't have security teams, it seems that fining companies for having security issues could lead to some percentage of them going bankrupt, which in turn would lead to more devices that are abandoned by their manufacturer post-launch.
I also think it would, to some degree, stifle innovation. Even if what's involved is paying some fee for some new security technology or license, that's still less money that a startup can spend on the part of the product that customers are paying for.
I wouldn't say we shouldn't have any sort of regulation whatsoever, I'm just skeptical that the government could do a good job of it.
>> We also need our standards to be flexible and easy to adapt to the needs of various companies, organizations, and industries. The National Institute of Standards and Technology’s Cybersecurity Framework is an excellent example of this, because its recommendations can be tailored to suit the individual needs and risks of organizations. The Cybersecurity Framework — which contains guidance on how to identify, prevent, recover, and respond to security risks — is voluntary at this point, which means nobody follows it. Making it mandatory for critical industries would be a great first step. An appropriate next step would be to implement more specific standards for industries like automobiles, medical devices, consumer goods, and critical infrastructure.
> How "excellent" of an example could it be if no one follows it?
I can be very excellent indeed, from the computer security perspective. The problem of why it's not followed is probably twofold: 1) organizations don't know about it (and aren't motivated to find out) and 2) business leaders don't want to spend the money to implement it if they do know. Making it mandatory nicely solves both of those issues.
> If he's worried about low-cost devices today that don't have security teams, it seems that fining companies for having security issues could lead to some percentage of them going bankrupt, which in turn would lead to more devices that are abandoned by their manufacturer post-launch.
That's no big loss, because those devices are inevitably abandoned today.
> I wouldn't say we shouldn't have any sort of regulation whatsoever, I'm just skeptical that the government could do a good job of it.
The government will do a better job at regulating in this area than anyone has ever done before, because no one has ever tried.
How "excellent" of an example could it be if no one follows it?
If he's worried about low-cost devices today that don't have security teams, it seems that fining companies for having security issues could lead to some percentage of them going bankrupt, which in turn would lead to more devices that are abandoned by their manufacturer post-launch.
I also think it would, to some degree, stifle innovation. Even if what's involved is paying some fee for some new security technology or license, that's still less money that a startup can spend on the part of the product that customers are paying for.
I wouldn't say we shouldn't have any sort of regulation whatsoever, I'm just skeptical that the government could do a good job of it.