Mr. Speaker, I ask unanimous consent that all Members may have 5 legislative days to revise and extend their remarks and include extraneous material on the bill H.R. 624. I yield myself such time as I may consume. I want to thank my…
Mr. Speaker, I ask unanimous consent that all Members may have 5 legislative days to revise and extend their remarks and include extraneous material on the bill H.R. 624.
I yield myself such time as I may consume.
I want to thank my ranking member and both the Republican and Democratic staffs and the Republican and Democratic members of the Intelligence Committee for 2 years of long hours in negotiated efforts to reach the point that we are.
I want to back up just a little bit and tell you how we got to where we are today. We sat down some 2 years ago when the ranking member and I assumed the leadership of the Intelligence Committee and we looked at the one threat that we knew existed but we were not prepared to handle as Americans, both the private sector and the government. And we knew that we had to do something about this new and growing and misunderstood cyber threat and what it was doing to our intellectual property across the country, what it was doing to the freedom and open Internet that we so enjoy and are increasingly dependent on and the commercial value of our growing economy. And it was at risk. The private sector was at risk because people were stealing their identities, their accounts, their intellectual property, and subsequent to that, their jobs, and people began to question the value of getting on the Internet and using it for commercial purposes. Their trust in the free and open Internet the way we've embraced it in the United States really was at risk.
How do we solve that problem? We knew that nation states were investing millions and billions of dollars to generate cyber warriors to go in and crack your computer network. I don't care if you had intellectual property--those blueprints that made your business successful, or maybe it was your bank account, or your ability to have a transaction. If they could interrupt that, they could do great harm to our economy and to the United States.
We saw nation-states like Russia and China and now Iran and North Korea and others developing military-style attacks to actually do harm to the U.S. economy, to hurt the very men and women who get up every day and play by the rules and think that the Internet would be a safe place for them to interact when it comes to commerce. We want that to continue.
So we sat down and we talked to industry folks, people who are in the business, high-tech industry folks from Silicon Valley, financial services folks from New York City, manufacturers from across the Midwest, who were losing intellectual property due to theft from nation-states like China. We talked to privacy groups. We talked to the executive branch. And over the last 2 years, there were some 19 adjustments to this bill on privacy.
We believe this: this bill will not work if Americans don't have confidence that it will protect your privacy and civil liberties while allowing one very simple thing to happen: cyber threat material, that malware that goes on your computer and does bad things, allows somebody else to take over your computer to attack a bank, allows them to go on your computer and steal your personally identifiable information and use it in a crime, allows them to go into your network at work and steal your most valuable company secrets that keep you alive and build great products here in the United States--could we allow the government to share what they know with the private sector and allow the private sector to share when it comes to just that cyber threat, those zeros and ones in a pattern that equates to malicious code traveling at hundreds of millions of times a second the speed of light, can we share that in a way to stop them from getting in and stealing your private information?
And the good news is the answer is, yes, we can do this. We can protect privacy and civil liberties, and we can allow this sharing arrangement, but not of your identity, not of your personally identifiable information. As a matter of fact, if that's what's happening, it won't work. But at the speed of light, from machine to machine, from your Internet service provider before it ever gets into your network they bounce out the nastiest stuff that's in there that's going to take over your computer, steal your money, steal your personally identifiable information, steal your company secrets. And they can identify that by a pattern and kick it out. They'll say, Something looks bad about that. Can the government take a look at that and say, you know what? This is a Chinese attack, it's an Iranian attack, it's a North Korean attack--let's defend our networks. It's really very simple.
Today, what you see is a collaborative effort. This isn't a bill by Dutch Ruppersberger and Mike Rogers and this is the only way it has to be. We have taken suggestions from all the groups I just talked about, from privacy to the executive branch to industry to other trade associations. And this is the bill that mutually all of those people, representing tens of millions of employees around this country, said this is the way you do this and protect the free and open Internet and you protect civil liberties. And you finally raise that big red sign that tells people like China and Iran and Russia, stop. We're going to prevent you from stealing America's prosperity.
I heard a lot of debate earlier on the rule. I've heard a lot of misinformation. There are people who don't like it for whatever reason, maybe it's conviction, maybe it's politics, maybe it's political theater. And I have a feeling there's a little bit of all of that when they talk about this bill.
This bill does none of the things I've heard talked about in the rule--that
it's an exchange of information that they've never seen with the government. This is not a surveillance bill. It does not allow the national security agencies or the Department of Defense or any of our military organizations to monitor our domestic networks. It does not allow that to happen. We would not allow that to happen.
So some notion that that's happening is just wrong, and some of the folks who are pretending otherwise know it's wrong. This is important.
You know, the Iranians, by public report, are laughing at our shores, looking for weaknesses in our financial institutions. They're not doing it for benevolence. They're doing it to try to create chaos in our markets here at home. This isn't 10 years or 20 years. This is today. It's happening today.
The average credit card in your purse, Madam Chair, will be hit 300,000 times today by bad actors trying to get in and steal your personal information--all those cardholders' information--and use it to commit a crime.
Today, hundreds of millions of times across this great country companies will be besieged by DDoS attacks trying to overwhelm their systems and shut them down and not allow commerce to happen, by people who are trying to get into their networks and steal something valuable.
This bill is that right balance between our privacy, civil liberties, and stopping bad guys in their tracks from ruining what is one-sixth of the U.S. economy. It's that important, and it's important that we get at it today.
We must do more to improve our cybersecurity, and this bill is that vital first step toward that bill. Our intelligence agencies collect important information overseas about advanced foreign cyber threats that could dramatically assist the private sector. That information is the intelligence community's unique value-added when it comes to our cybersecurity.
Unfortunately, we are not getting the full value of those intelligence insights. As I said, the intelligence community is not monitoring the Internet. They don't know what's happening on the domestic Internet. So when there is a nasty piece of source code or malicious source code attacking the private sector, the only way we're going to know that is if we--and these folks are victims of crime, by the way--if we allow them, in a classified environment, to share malicious source codes--zeros and ones in the right pattern--with the government and say, Hey, I am the victim of a crime. Here's what it looks like. Can you help? The government needs to be able to share this threat intelligence so that the private sector can protect its own networks.
The government is going to reciprocate. Our intelligence services go overseas. They find out what the bad guys are doing. They come back and protect the government networks. The problem is, because of laws and policies and procedures, we can't share that with the private sector so they can protect their own networks. Wouldn't it be great if they know what's coming? If you know what you're looking for, you can stop it. That's really what we're talking about doing here, Madam Chair.
We must also modernize the law to give the private sector clear authority to share cyber threat information within the private sector, as well as the government, on a voluntary, anonymous basis.
Again, if you believe in the free and open Internet and you look at all the bills that have been introduced, there is a chomping at the bit in this town to go out and try to put their mitts on the Internet. They want to get in there and start regulating and standards and setting up procedures. They want to get in from business-to-business communication. They want the government to be at every corner of the Internet. I reject that wholly. It's the wrong approach. It will not work. It will bring the Internet to a halt. This is the only bill that doesn't have new mandates, new authorizations for any government involvement in the Internet.
It does something very simple. I'm going to repeat it a lot today, Madam Chair. It allows the government to share zeros and ones in the right pattern with the private sector. And zeros and ones from the private sector, when they know it's malicious and attacking their networks, they share it with the government and say, This is a problem. Can you help me? That's what this bill does. And we've got a long list of privacy protections and restrictions to make sure that that's all that this bill does. The bill achieves all of these important goals that I just walked through, and it will empower the private sector, which already does significant work to protect computer networks, to do even more.
The bill will allow the government to share cyber threat intelligence more widely with American companies in operationally usable form so they can help prevent state-sponsored cyber spies from stealing American trade secrets. It also provides clear, positive authority to allow companies to share cyber threat information with others in the private sector. It also provides authority to allow those companies to share threat information on a purely voluntary and anonymized basis with the government, meaning no personal identifying information.
This bill will not require additional Federal spending. It will not require the creation of a vast new government bureaucracy. It will not impose any Federal regulations or unfunded mandates on the private sector. To the contrary, it will be a critical, bipartisan first step toward enabling America's private sector to better defend itself from the advanced state-sponsored cyber threats in which we live in today.
I'm very proud of the open and transparent process that produced this bill. We've had a great conversation over the last 2 years with a broad range of private sector companies, trade groups, privacy and civil liberties advocates, and the executive branch. I appreciate all the constructive input we have received from the process. This bill has been revised every step of the way in this process, and all of that has been based on discussions with all the groups I just mentioned.
I just want to cover some of the privacy protections we've added along the way.
The bill prohibits the government from requiring private sector entities to provide information to the government. There is nothing in here that has any requirement that the private sector must share cyber threat information. If they don't think it's in their best interest to stop that cyber crime, they don't have to say a word. If they do, they're allowed to share just that cyber threat information with the right agencies in real time. Again, this is machine to machine so that they can deal with the international nature of that threat.
It encourages the private sector to anonymize or minimize the information it voluntarily shares with others, including the government.
In addition, the bill requires an annual independent inspector general audit and report to Congress of all voluntary information sharing with the government. That's another layer of oversight. We have built multiple layers of oversight into this bill so that we can gain the confidence of the public in its purpose, intent, and success.
The bill significantly limits the Federal Government's use of information voluntarily provided by the private sector, including a restriction on the government's ability to search that data--very important.
The bill also enforces the restrictions on the government by levying penalties against the government through Federal court lawsuits for any violations of those restrictions. Again, another layer of oversight.
In the markup, we've made some progress, as well, between the ranking member and the members on the committee negotiating and working out what changes we can make to, again, improve the confidence that people have in this bill. We have improved this bill every step of the way for the last 2 years, and the markup was no different. At our markup, which voted the bill out of committee on a strong 18-2 vote, we adopted five important amendments to further strengthen the bill's protections and safeguards.
We adopted an amendment by Mr. Langevin that made it clear that the bill contained no new authority to allow companies to hack back into networks in other companies. It certainly wasn't intended in the legislation. I thought it was a well-intended amendment. The last thing we want to do is
unleash digital vigilantism across the country and what that might do to our ability to continue to rely on the Internet as an engine of commerce.
We've put in place the private sector use restriction that limits companies' use of information received to only cybersecurity purposes. Mr. Heck and Mr. Himes worked diligently on this amendment to improve the bill and make it very clear that this is just about cybersecurity and cybersecurity purposes.
The bill previously gave the government authorization to create procedures to protect privacy and civil liberties and prevent the government's retention of personal information not necessary to understand a cyber threat. Last week's amendment makes those procedures mandatory. That was by Mr. Himes. We agreed that was the right place to put the burden to make sure there was no personal identifiable information that was not necessary to determine the nature of the attack.
We also struck the bill's authorized government ``national security'' use of information received from the private sector. This would have provided the government flexibility in the future to address advanced cybersecurity threats. In conversations with government national security lawyers in recent months, they assured us that this flexibility wouldn't be required in the near future. In light of that, and given the widespread misunderstanding this language was generating, we thought it was prudent to take it out. Ms. Sewell from Alabama offered that amendment and worked with the committee to make sure it was adopted.
We also added additional oversight in the already very strong oversight structure in the bill to monitor the government's receipt and use of cyber threat information voluntarily provided by the private sector. We added roles for the Privacy and Civil Liberties Board and the individual agency privacy officers to provide additional oversight of the government's use of information received from the private sector under this bill.
I'm also very proud to cosponsor an amendment today with Mr. McCaul and Mr. Thompson of Mississippi, Mr. Ruppersberger and myself that would put a civilian face on the privacy sector cyber information sharing with this government. It was a concern by many. It was something we had long debates and conversations on, and I think we came to an agreement that will at least end that debate. It puts the appropriate civilian face so that, again, people can have confidence in the intention of this bill and what it will do to protect cybersecurity on networks or allow the private sector to protect their own networks and protect civil liberties of Americans.
Other elements of the government, such as the intelligence community, will still receive the information they need to play their important roles, but only after it has been minimized and screened by a civilian entity like the DHS or, in some rare cases, the FBI.
This bill already contains several levels of strong protections to ensure that it improves cybersecurity without compromising our important civil liberties, but this bill will add a significant new privacy protection to that existing structure.
Again, Madam Chair, you can see the level of effort that we are doing here to protect privacy and civil liberties and still have a workable bill that stops nation-states like China, Russia, Iran, and North Korea from getting into your networks and stealing your property.
We have yet to find a single U.S. company that opposes this bill. In fact, we have the enthusiastic support of nearly every sector of the economy, because they are under assault from foreign cyber attacks and they need our help. They need it now. Companies and industry groups from across the country, including Intel, the chip maker, IBM, the Internet Security Alliance, the U.S. Chamber of Commerce, the Business Roundtable, TechAmerica, TechNet, companies of Silicon Valley, the Financial Services Roundtable, U.S. Telecom, the Nuclear Energy Institute, and the National Association of Manufacturers, just to name a few, have sent the committee letters of support. And that list is growing by the day of people who are encouraged by the very light touch of the government; no new programs, no new authorizations, it's not a surveillance bill. This is the only appropriate way to try to deal with this problem.
By allowing the private sector to expand its own cyber defense efforts and to employ classified information to protect systems and networks, this bill will harness private-sector drive and innovation while also keeping the government out of the business of monitoring and guarding private-sector networks.
This important legislation would enable cyber threat sharing and provide clear authority for the private sector to defend its own networks while providing strong protections for privacy and civil liberties.
Madam Chair, with this great collaborative effort, with the effort facing this country, when you see this many Republicans and Democrats coming together, recognizing the threat and crafting a bill that meets that very important standard, this is the bill we should all stand up and enthusiastically support, and I reserve the balance of my time.
Madam Chair, I yield 3 minutes to a current military officer and great member of the Intelligence Committee, the gentleman from Nevada (Mr. Heck).
Madam Chair, I am proud to yield 3 minutes to a leader on the Homeland Security
Committee and the chair of the House Admin Committee, the gentlelady from Michigan (Mrs. Miller).
Madam Chair, I yield 2 minutes to a former military officer, the distinguished gentleman from Kansas (Mr. Pompeo).
I yield an additional 60 seconds to the gentleman.
I don't have any further speakers, and so I will continue to reserve the balance of my time to close.
Madam Chair, I yield myself 30 seconds.
I just want to make very, very clear--and I thank the gentlelady for working with us, she is a great member of the committee--nowhere in this bill does it allow the military to collect information on private citizens in the United States. This is not a surveillance bill. It does not allow it to happen. That needs to be very, very clear in this debate. It does not allow the military to surveil private networks in the United States. Period. End of story. That's the biggest part of our privacy protections. Again, I want to thank the gentlelady for working with us, but that's just an inaccurate statement, and I want to make that clear for the Record.
I reserve the balance of my time.
I continue to reserve the balance of my time.
Madam Chair, I yield myself the remaining time.
I just want to quickly, Madam Chair, address some of the moving targets on the bill. When we move to change something in the bill, the 19 privacy amendments, people who still decide they don't like it for, again, whatever reason, move their challenges of why they don't like it.
The newest, I think, straw man is that this somehow would violate contract law. Nothing in this bill allows you to avoid contract law. Nothing.
It's a red herring. It is not accurate. Nothing in this bill would allow this to happen. The fact that someone who was in the technical business would say this hurts job growth, that's interesting. The sheer number of companies who support this, from the Business Roundtable to the Financial Services Business Group to TechNet, who has companies like Intel Corporation, Symantec, Juniper, Oracle, EMC, social media, all stand up and say this is the right approach. It will allow us to protect our consumers of our product from foreign governments stealing their private information.
We need to understand what this bill is and what it is not. It is not a surveillance bill. Nothing in here authorizes surveillance. We're going to have an amendment to clarify that, to say it in the law so people can regain that confidence.
We argue, Read the bill. It's 27 pages. It is very clear. It is predominantly protections of your civil liberties, and it also allows companies to voluntarily share malicious source code--and that's source code that's committing a crime against their consumers and their company--with the Federal Government so they can go back overseas and find the Chinese or the Iranians or the Russians or the North Koreans who are perpetrating that crime. This bill is nothing more. It does do that.
Thanks to the ranking member and all who have gotten to this point. I look forward, Madam Chair, to the debate on the amendments, and I yield back the balance of my time.
Madam Chair, I have an amendment at the desk.
I offer this amendment to ensure that library records, firearm sales records, medical records, and tax returns are not included in any information voluntarily shared with the government under CISPA. Though the underlying bill would not permit this information unless it was cyber threat information, I will support this amendment, as it is a clarification amendment that settles some Members' concerns and reflects an amendment that was passed last year overwhelmingly.
With that, Madam Chair, I urge this body's support of this clarification amendment, and I reserve the balance of my time.
I yield back the balance of my time.
Madam Chair, I demand a recorded vote.
Madam Chair, while I do not oppose the amendment, I ask unanimous consent to claim the time in opposition.
Madam Chair, I do not oppose this amendment, which clarifies that classified intelligence shared by the government with a certified cybersecurity entity may only be used, retained, or further disclosed for cybersecurity purposes. The amendment is consistent with language that is already in the bill requiring the DNI, the Director of National Intelligence, to ensure that such classified information is carefully protected.
I appreciate the gentleman's working with us and the ACLU to find an amendment that we could all agree on. I do not oppose this further clarification and would urge support by this body of the amendment.
I reserve the balance of my time.
I continue to reserve the balance of my time.
Madam Chair, I yield myself such time as I may consume to clarify that this doesn't call for investigations of those crimes based on this material, but only protection of the individuals that may--and I want to stress ``may,'' because, again, the PII, the personal identifying information, is stripped clean. But in some rare, rare cases, you might find that you have located the child who has been subjugated to child pornography. In those cases, you don't want to throw that away. There are parents out there begging for us to find this child. It's very rare, it's exceptional, doesn't happen often, but in that very rare case--and, remember, there's no personally identifiable information. It would allow for the protection, not investigation.
I reserve the balance of my time.
Madam Chair, I yield back the balance of my time.
Madam Chair, I demand a recorded vote.
Madam Chairman, while I do not oppose the amendment, I ask unanimous consent to control the time in opposition.
Madam Chairman, I will support the clarification in this amendment.
The amendment clarifies that independent contractors are eligible to receive security clearances to handle cyber threat intelligence and cyber threat information shared under the bill, an important clarification amendment.
I appreciate the gentleman's work and effort in offering this amendment; And because the bill was not intended to exclude independent contractors, I will support this important clarification and would reserve the balance of my time.
I yield myself such time as I may consume.
I just want to address my friend from California, who is a thoughtful member of the intelligence community.
This is a position that much has been debated about: Should the government regulate into the private sector their use of the Internet? I argue that is a dangerous place to go. They will have to promulgate rules; they will have to set what reasonable standards are; they will have to determine what the private sector does on the Internet. That's government in the Internet. One of the things that we decided to avoid in this bill was not to make that mandate, the burden to make sure that no PII, personal identifying information, is mandated in this bill; and it's stripped out at the place where the burden should be: on the government. To make sure it happens, we have four different layers of oversight built in just to make sure what we say that they're supposed to do according to the law, they follow the law--four levels of review.
We shouldn't put the burden on the victims. We don't do it if somebody sticks a gun in your face on the street or robs the bank or robs your home. What's the difference if they're robbing your Internet or stealing your blueprints that steals American jobs? The difference? There is none. Theft is theft.
Let us not move to get the government into regulating. Aspects of the Internet between private to private has been the explosion of growth in one-sixth of our economy. Keep the government out of it.
That's what we decided to do. We came to a very sensible place that protects that PII, that personal identifying information, and allows the government to stay out of regulating the Internet.
I think that's the right prudent course. I think most Americans are with us. Certainly the broad specter of industries who have joined this, from the high-tech industry to the financial services to manufacturing, have said, This is the right way to go. You stay out of our business. We'll share with you when we're victims of a crime.
With that, I reserve the balance of my time.
I yield back the balance of my time.
Madam Chair, while I do not oppose the amendment, I ask unanimous consent to control the time in opposition.
Madam Chair, I yield myself such time as I may consume.
I want to thank the gentleman from Rhode Island (Mr. Langevin), who has been a tremendous leader on cybersecurity efforts on the Intelligence Committee. Much of our work there is classified and it goes unnoticed, and rightly so. I think it would be wrong for us not to commend in public your great leadership and efforts and work with us to try to make sure that this bill does what we say we want it to do. It has been a great privilege and pleasure to work with you throughout that process, and without that leadership, we wouldn't be standing on the floor today. I want to thank the gentleman for that.
I will support the amendment, which clarifies that entities located across multiple localities are intended to be covered by provisions in the bill exempting information shared under the bill from certain disclosures otherwise required of public or quasi-public entities. The amendment replaces the term ``local'' with ``political subdivision.'' Because there is no intention to exclude such entities, this is intended as a clarification, an important clarification, and I will gladly support the amendment, and again thank the gentleman for his work on the totality of both national security issues and cybersecurity.
I reserve the balance of my time.
I yield back the balance of my time.
Madam Chair, I demand a recorded vote.
Madam Chair, I move that the Committee do now rise.