April 30, 2009 4:32 PM PDT

Senators aim to protect electric grid from hackers

by Stephanie Condon
  • Font size
  • Print
  • 14 comments

In the wake of recent reports describing the electric grid's vulnerabilities to hackers, two members of the U.S. Congress have introduced legislation giving federal regulators more authority to combat that possible threat.

The electric grid system that keeps the United States humming is worth more than $1 trillion and keeps the lights on for more than 300 million Americans. Federal regulators have complained they do not have enough authority over the electric grid networks, which recent reports have suggested may be vulnerable to infiltrations by Chinese and Russian spies--a new concern as utilities tie grid-monitoring control systems to open networks like the Internet.

Matching bills were introduced in the House and the Senate on Thursday to increase the authority of the Department of Homeland Security and the Federal Energy Regulatory Commission to secure the electric grid. The bills were introduced by Sen. Joe Lieberman (I-Conn.) and Rep. Bennie Thompson (D-Miss.), who chair the Homeland Security committees in their respective chambers.

"Our cybersystems are under constant attack," Lieberman said in a statement. "We rely on cyberspace for so much of what is at the heart of our way of life, and our systems are not protected. We are focusing on the electricity cyberstructure today because electricity is what so many critical sectors of the economy depend upon."

Utilities are already expected to comply with mandatory cybersecurity standards, but regulators have reported that utilities are likely downplaying the critical nature of their infrastructure to avoid compliance with the rules.

The legislation addresses that by giving FERC, DHS, and other national security agencies the authority to determine which physical or cyber assets should be deemed "critical electric infrastructure." The bill clarifies that "critical" infrastructure should refer to networks that are so vital to the United States that their incapacity would cause significant harm to the country's security, the economy, or public health at a national or regional level.

It also would enable FERC to issue rules or orders to protect critical electric infrastructure against threats--including emergency orders, which could be issued without prior notice if FERC determines an order is needed immediately to protect the grid from an imminent threat. Emergency orders would remain in place for 90 days, unless FERC opened them up to public comment.

In addition, the legislation calls for FERC and the DHS Secretary to establish within 120 days of its enactment interim measures to protect the electric grid.

The DHS would also be responsible for more oversight of grid protection programs. The legislation would require the department to conduct research to determine if the security of critical electric infrastructure has been compromised and to report its findings to Congress. The department would also have to produce regular reports with recommendations for creating a collective domestic response to a cyberattack by a terrorist, nation-state or person.

The legislation comes as the Obama administration is pushing through stimulus spending smart-grid development, which would connect the electric grid to more networks.

Stephanie Condon is a staff writer for CBSNews.com focused on the intersection of technology and politics. She is based in Washington, D.C. E-mail Stephanie.
advertisement
Recent posts from Politics and Law
'Don't-be-evil' Google spurns no-evil software
White House appoints cybersecurity chief
U.S. cap and trade looks out of reach in 2010
FTC's new strategy: Kick 'em when they're down
Plurk holding Microsoft's feet to code-copying fire
FTC wants Intel to mend its ways
Biden to unveil $2 billion in broadband grants
FTC pursues Intel on new front: Graphics chips
Add a Comment (Log in or register) (14 Comments)
  • prev
  • 1
  • next
by Maccess April 30, 2009 6:22 PM PDT
"Federal regulators have complained they do not have enough authority over the electric grid networks,..."

Exactly how will giving Federal Regulators more authority over the grid discourage foreign hackers from targetting th grid?

"Senators aim to protect electric grid from hackers..."

Exactly how will Senators protect the grid from hackers? By taking computer classes?
Reply to this comment
by Seaspray0 May 1, 2009 11:05 AM PDT
I feel safe now. The senators will protect us. LOL.
by nicmart April 30, 2009 6:22 PM PDT
How will the electric grid be protected from senators?
Reply to this comment
by declan00 April 30, 2009 9:22 PM PDT
Clearly you fail to understand the depth of knowledge about technology, and deep appreciation for the tradeoffs inherent in the computer security field, that our esteemed elected representatives no doubt possess.
Reply to this comment
by Get_Bent May 1, 2009 1:45 PM PDT
Following in the footsteps of ex-Senator Ted "the Internet is a bunch of tubes" Stevens....
by thirdpipe April 30, 2009 9:23 PM PDT
I recommend we make a law to protect the power grid from clueless Senators.
Reply to this comment
by icfdude May 1, 2009 8:22 AM PDT
I feel safer already. I wonder how much this will cost.
Reply to this comment
by KimTaylor aka Finiky May 1, 2009 8:53 AM PDT
This is an attempt to allow further intrusion into our personal lives. We already know the FBI abused it's privilege and spied on Americans, for no reason. This will allow the US Government to extend the Big Brother reach. This is bad bad legislation and all in the name of national security.
Reply to this comment
by Frewgle May 1, 2009 10:22 AM PDT
Welcome to Obamaland. Wait until Obama and Congress touch healthcare. Soon he will choose your doctor and hospital for you, and what procedures can be done for you. If they cost too much, well that wouldn't be fair to the other broke taxpayers....
by jpbgmail May 1, 2009 2:05 PM PDT
Get a clue, man.

How does this have anything to do with 'intrusion into your personal lives'. Do you have any idea about what protecting the 'grid' means? If you know anything about the electric generation/transmission/distribution system, you should know that it's based on ages old antique technology when security was an after-thought. With the movement toward modernizing & IP-enabling the grid, it's imperative that cybersecurity be studied, analyzed and implemented.

This has *nothing* to do with US government spying or bullcrap like that ...
by jpbgmail May 1, 2009 2:12 PM PDT
Hey Frewgle, dude .. remove those glasses man, they're just making you blind.

This has *nothing* to do with Obamaland or his tax policies or anything. The US electric grid is stuck in the 70s outdated technology. A 'smart' grid might enable new things like renewables, etc, but grid modernization itself is something that's desperately needed here.
by Eddie-c May 1, 2009 10:12 AM PDT
How about simply hiring I.T. staff that know what the hell they are doing and kick the current idiots there out??
Reply to this comment
by willdryden May 1, 2009 7:49 PM PDT
There is an easy way to secure it. Hardware IP addresses on a closed hard-wired network. Baring that, there is no security regardless of who is involved.
Reply to this comment
by jinnlost5 May 20, 2009 10:04 PM PDT
Safety is the first priority. I hope they learn from the past mistakes.

<a href="http://www.garrywillmott.com/">Garry</a>
Reply to this comment
(14 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Politics and Law

News at the intersection of technology, politics, and law, ranging from intellectual property to censorship to tech policy.

Add this feed to your online news reader

Politics and Law topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right