www.forbes.com/business/newswire/2004/04/01/rtr1320997.html
By Andy Sullivan WASHINGTON Reuters - The United States government may need to step in to protect the nations computer networks from viruses, worms and other cyber-attacks, a technology-industry group said Thursday in a reversal of a long-held stance. Business groups have lobbied successfully for years against cyber-security laws or regulations, but the task force concluded that critical systems that oversee power plants, banks and other sensitive areas may need government regulation. It is possible that national security or critical infrastructure may require a greater level of security than the market will provide, the report said. Any such gap should be filled by appropriate and tailored government action that interferes with market innovation on security as little as possible, said the task force, which was led by Microsoft Corp and Computer Associates International Inc.
The report says programmers should be held personally accountable for security holes in the software they write. Task force co-chairman Ron Moritz said the report calls for a limited government role, such as helping to develop certification standards for software that runs in sensitive systems. Still, it does reflect a new attitude in the private sector, he said. We all have a better appreciation and understanding of the challenges we face, said Moritz, chief security strategist for Computer Associates. Viruses, worms and other cyber-attacks can clog networks and knock Web sites offline, costing businesses billions of dollars in lost productivity. Emergency-response centers, automatic tellers and freight trains have been idled by attacks in the past, and experts worry that water-treatment plants and other critical infrastructure could fall victim in the future. The Bush administration released a plan to increase online security last year, but it contained few hard-and-fast requirements for the businesses that control roughly 85 percent of the nations Internet infrastructure. Experts say businesses can still be held liable for security breaches, thanks to court decisions and new laws in areas such as accounting, banking and consumer protection. The report said industry groups should work with the Homeland Security Department to look at ways to reduce liability, as well as examining whether new rules are needed. The report also recommends an industry-wide bounty program to help track down hackers and virus writers, similar to a program set up by Microsoft last year. Task force members include high-tech companies like Hewlett-Packard Co.
|