Introduction
In recent years, the U.S. Congress has considered several bills intended to improve cybersecurity information sharing while raising privacy concerns. The Cyber Intelligence Sharing and Protection Act (CISPA), H.R. 624, passed the House of Representatives in 2013 but was referred to the Senate Intelligence Committee and did not become law. CISPA should not be confused with the separate Cybersecurity Information Sharing Act (CISA), which Congress enacted in 2015. Both proposals prompted substantial debate about privacy, government access to data, and information sharing between companies and public agencies. Although the two proposals were similar in several respects, they followed different legislative paths.
Both proposals concerned the exchange of information about computer-security threats among government agencies, companies, and other entities. The Department of Homeland Security was expected to develop procedures for sharing cyber-threat information with the Director of National Intelligence, the Departments of Justice and Defense, private companies, and other non-governmental institutions. Both proposals also allowed the private sector and the federal government, and in some circumstances other government agencies and private organizations, to exchange cyber-threat information. They also sought to provide legal and privacy protections to organizations that voluntarily shared information about threats and security measures.
One of the most influential advocates of CISA was Senator Dianne Feinstein, who described passage of the legislation as “an important step for the development of our cyber security” and referred to a balance among security, privacy, and responsibility. Feinstein and other CISA supporters argued that information sharing between government and private companies would help these groups identify hackers attempting to steal information and prepare defenses. Because such information sharing would be voluntary, supporters also argued that companies and government agencies should remove irrelevant personal information before sharing data and that the law would therefore not violate the privacy rights of businesses or users.
Critique On The Bill
Opponents of the bill argued that its language left room for abuse and gave government agencies too much authority over individuals’ information. Critics, including privacy and civil-liberties organizations, argued that information collected for computer security could be used for purposes unrelated to cybersecurity. They therefore maintained that CISA provided overly broad authority and insufficient protection for consumer privacy.
In the United States, CISPA (H.R. 3523 and later H.R. 624) was proposed as legislation to allow the government and technology and manufacturing companies to exchange information about cyber-espionage and Internet traffic. The stated purpose of the bill was to help the U.S. government investigate cyber threats and protect networks against cyber-attacks (“HR as reported to”, n.d.).
The legislation was introduced on November 30, 2011, by Representative Michael Rogers (R-MI) and had 111 co-sponsors. It was considered by the House of Representatives on April 26, 2012, but was not passed by the U.S. Senate. President Barack Obama’s advisers stated that the bill did not provide adequate guarantees of privacy and personal freedom and said that the White House would veto it (Morgan Little, April 9, 2012).
In February 2013, the House introduced the bill again. It passed the House on April 18, 2013, but did not advance through the Senate. On July 10, 2014, the Senate considered the Cybersecurity Information Sharing Act (CISA), a similar proposal concerning the exchange of cybersecurity information.
In January 2015, the House again considered cybersecurity-information-sharing legislation. Related measures were examined by congressional committees and subcommittees dealing with intelligence, crime, terrorism, national security, investigations, constitutional matters, and civil justice. The legislative process eventually led to information-sharing provisions being incorporated into broader federal legislation.
Social Media Issues
CISPA received support from companies such as Microsoft, Facebook, AT& T, and IBM, which argued that the legislation would make it easier and more effective to share relevant information about government and cybersecurity threats. However, it was criticized by privacy and civil-liberties advocates, including the Electronic Frontier Foundation, the American Civil Liberties Union, Free Press, Fight for the Future, and Avaaz.org. A range of conservative and libertarian organizations also raised concerns. Critics argued that CISPA placed too few restrictions on how and when the government could access private Internet information. Moreover, they feared that the new authority could be used to monitor the general public rather than only malicious hackers (“Save The Internet”, 2012).
Following criticism, Congress discussed revisions to CISPA, including changes concerning intellectual-property protection. Even when provisions concerning intellectual-property theft were narrowed or removed in later drafts, opponents continued to object to the government’s ability to receive and use information about web traffic.
CISPA was proposed as an amendment to the National Security Act of 1947. The legislation defined cyber-threat intelligence and described information concerning vulnerabilities or threats to private or public networks and systems. It also provided for elements of the intelligence community, under procedures created by the Director of National Intelligence, to share cyber-threat information with the private sector and encouraged reciprocal information sharing.
Initiatives For Progression
In an April 16, 2012, press release, the House Permanent Select Committee on Intelligence announced changes to CISPA. The amendments included provisions intended to limit federal-government liability and clarify the use of information voluntarily shared with the government. The bill also included provisions intended to prevent government use of cyber-threat information for purposes unrelated to cybersecurity or national security and to focus the legislation on unauthorized access to networks or systems. Previously collected cyber-threat information could also be used in circumstances involving threats of physical harm or serious exploitation. Existing laws, including provisions relating to law enforcement and the National Center for Missing and Exploited Children, already permitted some forms of voluntary information sharing (“Jump up Current Status”, 2012).
Bill sponsors Mike Rogers and Dutch Ruppersberger responded on April 25, 2012, to opposition from the Obama administration concerning the lack of critical-infrastructure regulation. They argued that such regulation was outside the jurisdiction of the Intelligence Committee and stated that they had prepared amendments intended to address criticisms, especially those related to Americans’ privacy and civil liberties.
The sponsors also sought to amend the bill to address opponents’ concerns and narrow the definition of malware and other cyber threats. The proposed changes were intended to limit the use of information that private companies or the government knew was unrelated to a cyber threat.
However, Sharon Bradford Franklin of the Constitution Project argued that the recent amendments did not resolve the bill’s civil-liberties concerns. Although she welcomed efforts to engage with privacy advocates, she maintained that some changes could worsen rather than alleviate the problems and therefore argued that Congress should not pass CISPA.
Rainey Reitman of the Electronic Frontier Foundation similarly argued that the bill’s authors had not adequately responded to criticism and that the proposed changes did not resolve serious concerns about weakening Internet users’ privacy rights. Protests against CISPA continued as representatives prepared for a vote.
Kendall Burman of the Center for Democracy and Technology said that the bill’s authors had made some positive changes but that the amendments still did not address the main privacy concerns of Internet users. In April 2012, the U.S. Office of Management and Budget issued a statement strongly opposing the bill and recommending a presidential veto.
After years of debate over cybersecurity and surveillance, the Senate passed related cybersecurity-information-sharing legislation by a 74–21 vote. The Cybersecurity Information Sharing Act (CISA) was a controversial measure intended to encourage companies and government agencies to share information about hackers and their methods. Government and industry had discussed such information sharing for more than a decade. In 2013, the House had passed CISPA, a predecessor to CISA, but the measure did not advance after President Barack Obama threatened a veto because of privacy concerns. Senator Dianne Feinstein (D-Calif.) introduced an early version of CISA in July 2014, and she and Senator Richard Burr (R-N.C.) continued to work on the legislation. High-profile breaches involving Sony Pictures, Home Depot, the Office of Personnel Management, and other organizations helped maintain congressional attention on cybersecurity.
A central concern about CISA was accountability and confidentiality when businesses transmitted information about clients, particularly to the government. Although the bill limited corporate liability in some circumstances, critics argued that companies and public institutions should at least be required to remove information that could identify individuals before transmitting records.
Critics also argued that information sharing alone would not do much to prevent successful cyber-attacks. The federal government already had an organization for exchanging cybersecurity-threat information. In 2003, the Department of Homeland Security created the U.S. Computer Emergency Readiness Team (US-CERT) to gather, analyze, disseminate, and respond to cybersecurity information from government agencies, the private sector, and researchers. CISA could help collect information about malware, but critics questioned how effectively that information would be used. In addition, much of the legislation focused on how federal agencies would share information with one another rather than on how private organizations would access the resulting data.
Some privacy advocates and cybersecurity specialists stressed that exchanging indicators of new malware, suspicious network activity, and other threats would do little by itself to prevent attacks. They argued that information sharing should be combined with improvements in procurement, encryption, software patching, and the security of obsolete systems. The Electronic Frontier Foundation summarized this argument in its criticism of CISA, while Scientific American published explanatory material intended to help readers understand the controversy and its implications.
Failures Of The Act
After the controversy surrounding the Stop Online Piracy Act (SOPA), Congress again considered cybersecurity legislation through the Cyber Intelligence Sharing and Protection Act (CISPA). The bill passed the House of Representatives, while related Senate proposals were also discussed. Unlike SOPA, which focused heavily on piracy and intellectual property, CISPA was presented as a cybersecurity measure intended to improve the sharing of information about threats that could damage networks. Because the bill invoked “national security” and other purposes and included government, military, and intelligence agencies, critics argued that it granted broad powers and immunities for the use of information supplied by individual companies. Like SOPA, it therefore drew objections from Internet-privacy and civil-liberties advocates who considered its definitions and applications too broad.
The Obama administration threatened to veto the bill and expressed strong opposition in a formal memorandum. At the same time, the White House indicated that it was open to some cybersecurity legislation, leaving open the possibility of a compromise proposal reaching the president’s desk. The following sections describe some of the most relevant provisions of CISPA.
“Circuits:” How Does CISPA Work?
The purpose of the bill was to facilitate greater information exchange between the government and private companies such as Google and Facebook. CISPA would allow companies to share certain customer or other private information with the U.S. government, including intelligence agencies, and its provisions could override some other federal and state restrictions. The bill therefore raised the possibility that a wide range of content could be shared when companies considered it related to a “cyber threat.” This raised an important question: what exactly falls under the definition of a “cyber threat”?
What Is The Purpose Of CISA?
The bill calls on government agencies, businesses, and other organizations to share information about security threats. The idea is that this shared information would help different groups identify hackers attempting to steal information from computer systems and prepare stronger defenses. However, critics argued that the legislation did not provide sufficiently clear definitions of how information would be shared, who would manage it, or how it would ultimately be used.
Who Is In Favor Of CISA?
Among the sponsors were Dianne Feinstein (D-Calif.), Richard Burr (R-N.C.), Bill Nelson (D-Fla.), and Angus King (I-Maine). The Financial Services Roundtable, the U.S. Chamber of Commerce, and organizations representing the U.S. financial-services sector also supported the legislation.
Who Is Opposed To That?
Opponents included organizations such as the Electronic Frontier Foundation, the Center for Democracy and Technology, and Fight for the Future. Critics also included individuals and groups from the information and communications industry, security specialists, academics, and some members of Congress.
What Are The Arguments Against CISA?
Senator Wyden and other critics of CISA argued that information shared by companies could give the National Security Agency and other government officials additional opportunities to monitor customers. They also argued that transferring information to government agencies or other third parties could create new opportunities for data theft. In their view, the legislation did not fully address underlying security problems such as obsolete software, unencrypted files, and other vulnerabilities that hackers exploit. The program was based on voluntary information sharing and did not directly require every participant to improve those underlying weaknesses.
The Senate rejected several amendments that would have narrowed the definition of cyber threats or required additional removal of information that could identify individual customers before sharing. Other amendments provided legal safeguards against certain antitrust and privacy claims. The government also stated that information received under the legislation would not be used to prosecute offenses unrelated to the permitted purposes.
What Happens Next?
CISA was expected to be reconciled with information-sharing bills passed by the House of Representatives. The combined legislation would then go to the White House. After enactment, the Attorney General of the United States would have a specified period to complete procedures for collecting and disseminating cyber-threat information.
Amendments That The Senate Should Adopt
As the Senate considered the Cybersecurity Information Sharing Act (CISA), the bill’s sponsors and individual senators proposed numerous amendments. Although some changes did not substantially affect the legislation, others could either strengthen or weaken the value and likelihood of information sharing.
Fundamentals Of Information Exchange
Information exchange focuses on sharing information about threats and weaknesses in network security between the private sector and government actors. Like a traffic application that uses reports from multiple users to warn others about hazards, cybersecurity information sharing can help public and private organizations identify attacks and vulnerable systems. For this reason, information exchange should focus on threat indicators and technical information rather than personal data such as the content of email. Such information can also be made available to law-enforcement agencies when appropriate for investigating and prosecuting cybercrime.
To maintain this separation, supporters argued that private-sector participants needed liability protection and appropriate protection from Freedom of Information Act (FOIA) disclosure. Without such safeguards, companies could hesitate to share information because it might later be used against them by litigants, regulators, competitors, or cyber adversaries. Although information sharing is not a complete solution, it can improve the information available to participating organizations and thereby strengthen cybersecurity.
CISA was also expanded to address matters beyond basic information-sharing arrangements. Title II focused on strengthening U.S. capabilities for detecting network attacks and required management strategies, plans, and assessments following failures to detect attacks such as the breach at the Office of Personnel Management (OPM). Title III addressed the federal cybersecurity workforce and required agencies to identify workforce needs and develop plans to address IT staffing deficiencies. Other provisions concerned mobile security, cyber diplomacy, the Department of State, the apprehension of cybercriminals, emergency cybersecurity, health-sector security, and vulnerable infrastructure.
Some proposed amendments were considered harmful to information sharing. Senator Patrick Leahy (D-Vt.) proposed changes related to FOIA protections, while other amendments concerned personal-identification requirements and could increase the time needed to process shared information.
Another proposal involved a six-year sunset provision. Supporters of long-term information sharing argued that a sunset could weaken the certainty provided to companies that chose to participate in the program.
Another issue concerned extending certain legal rights to citizens of allied countries and the European Union in connection with privacy requests. This issue was linked to transatlantic negotiations over data transfer and raised broader questions about when foreign individuals could bring legal actions involving information held by U.S. institutions.
Exchange Information Makes Business In The United States Safe
Congress sought to ensure that information exchange would contribute to cybersecurity in the United States through several protections.
Protection from FOIA obligations and liability. CISA included protections relating to liability and Freedom of Information Act disclosure for information voluntarily shared under the program. Supporters argued that these measures would allow companies to exchange threat information without fearing that competitors, litigants, or malicious actors could readily use the shared information against them.
Use of shared information. CISA also defined circumstances in which government agencies could use shared information. Supporters argued that a sound policy should limit government use to important cybersecurity and related authorized purposes.
Optimization of privacy provisions. Privacy requirements needed to balance the protection of personal information with the practical need for rapid information sharing. Rather than requiring the removal of every piece of information in every circumstance, supporters favored reasonable standards for removing personal information. Automated methods and other information-sharing tools could help limit the amount of personal data transmitted while avoiding unnecessary delays.
Conclusion
In response to a deteriorating cybersecurity environment and an emerging technological arms race, President Obama issued an executive order on February 12, 2013, aimed at improving critical-infrastructure cybersecurity. The order addressed the identification of critical infrastructure, requested the creation of a framework to reduce cybersecurity risks, and established policy goals involving information sharing and the protection of privacy and confidential information. Sensitive cybersecurity information can include vulnerabilities that may also be bought and sold in private markets, raising questions about the effectiveness and incentives of information exchange. If access to threat information in private markets is valuable, policymakers must consider how government and private organizations should acquire and share such information without encouraging abuse.
Despite Obama’s efforts to protect critical infrastructure, the revival of CISPA returned attention to legislative approaches to cybersecurity. The executive order provided one mechanism for improving information sharing, but it did not resolve all questions addressed by proposed legislation. The government already possessed legal mechanisms for investigating unauthorized access to private networks, including court orders and national-security authorities. The policy question was therefore whether expanding voluntary information exchange would meaningfully accelerate cybersecurity investigations without unnecessarily weakening privacy protections.
The U.S. government and private sector also participate in markets for cybersecurity tools, vulnerabilities, and defensive technologies. At the same time, U.S. agencies are major customers in the information-technology market and have been reported to purchase information about software vulnerabilities. This creates a difficult policy balance: protecting critical infrastructure requires strong defensive capabilities, but expanding government and commercial demand for undisclosed vulnerabilities can also increase risks. Any legislation such as CISPA must therefore balance cybersecurity benefits with the legal protections and privacy rights of the population.
References
Morgan Little (April 9, 2012). “CISPA legislation is seen by many as SOPA 2.0”. Los Angeles Times. Retrieved April 30, 2012.
Rushe, Dominic (April 23, 2012). “Ron Paul says CISPA cyber terrorism bill would create ‘Big Brother’ culture.” London: GuardianUK. Retrieved April 23, 2012.
“HR 3523 as reported to the House Rules Committee” (PDF).
Jump up ^ “H.R. 3523”. Library of Congress. Retrieved April 5, 2012.
Jump up ^ “Current Status of CISPA.” GovTrack. Retrieved April 18, 2012.
“Save The Internet.” Free Press. Archived from the original on June 18, 2012. Retrieved April 16, 2012.
Jump up, (2013). “Internet Advocacy Coalition Announces Twitter Campaign to Fight Privacy-Invasive Bill (CISPA.” Retrieved from En.rsf.org.
Jump up, (2013, April). “Everything Anonymous.” Retrieved from AnonNews.org.
Academic Master Education Team is a group of academic editors and subject specialists responsible for producing structured, research-backed essays across multiple disciplines. Each article is developed following Academic Master’s Editorial Policy and supported by credible academic references. The team ensures clarity, citation accuracy, and adherence to ethical academic writing standards
Content reviewed under Academic Master Editorial Policy.
- Editorial Staff
- Editorial Staff
- Editorial Staff

