Federal legislation introduced in the US Senate this week would give President Obama the power to declare a cybersecurity emergency and then shut down both public and private networks including Internet traffic coming to and from compromised systems.
The proposed legislation, introduced April 1, also would give the President the power to "order the disconnection of any Federal government or United States critical infrastructure information systems or networks in the interest of national security."
Some critics of the bill say that phrase needs to be more clearly defined.
"We are confident that the communication networks and the Internet would be so designated [as critical infrastructure], so in the interest of national security the president could order them disconnected.," said Leslie Harris, president and CEO at the Center for Democracy and Technology (CDT), , which promotes democratic values and constitutional liberties for the digital age.
Harris and the CDT don't think such sweeping power is good news for anyone, including private networks that could be shut down by government order. Those same networks would be subject to government mandated security standards and technical configurations.
The bill says the president must have a comprehensive national cybersecurity strategy in place 12 months after the bill passes.
"This is pretty sweeping legislation," says Harris. "Seems the President could turn off the Internet completely or tell someone like Verizon to limit or block certain traffic," she said. "There is a lot to worry about in this bill."
In addition, an agency appointed by the President would control how and when systems are restored.
The power could conceivably extend to large service provider networks such as those run by Google, Microsoft, AOL, Yahoo and others who offer online services and applications to corporations and consumers.
Proponents including officials from the Center for Strategic and International Studies (CSIS) say the legislation is comprehensive and strong and reflects the need for thorough debate around digital security that is long overdue.
The bill was introduced by West Virginia Democratic Sen. John Rockefeller, the chairman of the Senate Committee on Commerce, Science, and Transportation, and Sen. Olympia Snowe, a Republican from Maine.
Rockefeller said in a statement the bill loosely parallels the recommendations presented in December to Obama by a CSIS panel. The panel recommended naming an assistant for cyberspace and a National Security Council (NSC) director to coordinate government response to cyber threats.