White House circulating draft of executive order on cybersecurity
The White House is circulating a draft of an executive order aimed at protecting the country from cyber attacks, The Hill has learned. — The draft proposal, which has been sent to relevant federal agencies for feedback …
Context & Ripple Effects
The draft order lands after a legislative dead end: in May 2012 the White House reiterated it would veto CISPA in its current form, and with Congress unable to produce a cybersecurity bill the administration is turning to its own pen. Circulating the text to relevant federal agencies for feedback is the standard pre-signing step, which signals this is meant to be issued rather than merely floated.
The pickup is unusually broad for an unconfirmed draft — The Hill's report traveled same-day to the Washington Post, Forbes, SiliconANGLE, The Next Web, Government Technology News, Daily Dot, and GamePolitics — reflecting how much attention any unilateral move on critical-infrastructure security commands while the statutory route is blocked.
First-order effects
- Federal agencies receiving the draft must now comment on a proposal that would direct their cybersecurity activities without new statutory authority, shaping what they can require of critical-infrastructure operators.
Second-order effects
- Private-sector owners of critical infrastructure face the prospect of voluntary security standards set by the executive branch, and industry groups that lobbied on CISPA will shift their attention from Capitol Hill to the comment process.
Third-order effects
- If the order is signed, it establishes executive action as the default instrument for US cybersecurity policy whenever legislation stalls — a template successors can extend or replace, and one that keeps standards voluntary rather than mandated by law.
The trend: US cybersecurity governance is migrating from stalled legislation toward presidential executive orders, with each administration layering new orders on top of the last.