For the first time in the Distilling Cyber Policy podcast, Alex Botting and Jen Ellis from the Center for Cybersecurity Policy & Law are re-joined by guests from earlier this season: Lee Licata, Deputy Section Chief for National Security Data Risk at the Department of Justice (DOJ), and Grant Dasher, the Acting Technical Deputy Director for Cybersecurity at the Cybersecurity and Infrastructure Agency (CISA).

Both came on to discuss the then-recently released Executive Order 14117 on "Preventing Access to Americans' Bulk Sensitive Data and United States Government-Related Data by Countries of Concern" and the associated Advanced Notice of Proposed Rulemaking (ANPRM). EO 14117 directed the DOJ to establish and implement new regulations to address the threat from certain countries of concern attempting to access and exploit Americans’ sensitive personal data. The ANPRM proposed prohibiting and restricting certain transactions involving Americans' bulk personal data, as well as sensitive government data, to specific countries of concern such as China, Russia, Iran, North Korea, Cuba, and Venezuela - as well as territories controlled by these nations, such as Hong Kong and Macau. 

Since then, the DOJ issued a Notice of Proposed Rulemaking (NPRM), with written comments from the public due by Nov. 29. Additionally, as directed by the EO, CISA has developed proposed security requirements to apply to classes of restricted transactions identified in the NPRM. The public can read CISA’s notice and request for comment in the Federal Register here. The proposed security requirements include cybersecurity measures such as basic organizational cybersecurity policies and practices, physical and logical access controls, data masking and minimization, encryption, and the use of privacy-enhancing techniques. 

In the episode, Lee and Grant dig into the proposed rule and the proposed security requirements, which just like the ANPRM, cover six categories of sensitive personal data, including human genomic data. They also share details on the next steps of the rulemaking process. 

This week’s news segment covers:

For our Community Corner segment, we are joined by the fabulous Rebekah Brown and John Scott Railton, both Senior Researchers at the Citizen Lab at the University of Toronto. Rebekah and JSR share details from Rivers of Phish, their recent report on Russian-origin phishing operations, and the evolving nature of social engineering online.

You can find the latest Distilling Cyber Policy episode on Spotify and Apple. As always, if you would like to submit something for the Community Corner segment, or have topic ideas for upcoming episodes, please email iaj01@venable.com.

Ines Jordan-Zoob

Read Next

EU’s Cyber Resilience Act Enters Into Force

New product cybersecurity requirements are coming to the EU single market after years of intense debate and negotiation in Brussels, as the European Union’s Cyber Resilience Act officially enters into force.

Through the Looking Glass: An Updated Vision for the Office of the National Cyber Director

The ONCD was established to advise the President on cybersecurity and has matured into a key component of cybersecurity policymaking. However, changes are needed to ensure the efficacy of the office, especially as it relates to other agencies.

The U.S. and UN Cybercrime Convention: Progress, Concerns, and Uncertain Commitments

The U.S. issued an updated position seeking to move forward the UN Convention Against Cybercrime, a treaty intended to improve the global community’s ability to combat evolving cybercrime threats.