Archived Content

The following content is from an older version of this website, and may not display correctly.

A US legislative committee approved a bill that would appropriate $150 million for research and development of methods to enhance security of the federal government's enormous IT infrastructure.

The full bill is a recommended budget allocation for the Department of Homeland Security's science and technology activities for the next two years.

The Homeland Security Science and Technology Authorization Act of 2010 was passed unanimously by the House Homeland Security Committee Thursday.

Next step in the legislative process is for the House of Representatives to vote on the legislation.

It would allocate a total of about $2.3 billion to be spent over the next two years, of which $75,000 million per year would be spent on cyber security R&D efforts in 2011 and in 2012.

Stated purpose of the research effort is to "improve the ability of the United States to prevent, protect against, detect, respond to and recover from acts of terrorism and cyber attacks, with an emphasis on research and development relevant to large-scale, high-impact attacks.

" The committee recommended that funding be used to create more secure Internet protocols and architectures, improve attack and intrusion detection and attack containment and reduce vulnerabilities in process-control systems, among other purposes.

Another appropriation the bill prescribes is a relatively small sum to fund a project that may have far-reaching consequences on the ecosystem of IT vendors that supply the US government - the largest IT consumer in the world.

DHS under secretary is planning to partner with the Academy of Sciences' National Research Council to conduct a study of methods to "promote market mechanisms" to enhance cyber security.

Proposed "incentives" the $500,000 study will look into include imposing liability on vendors for damages and system breaches, requiring critical-infrastructure operators to comply with certain best practices under threat of civil penalty, requiring companies to report their cyber security practices and security risk insurance, among other regulations.