{"id":201,"date":"2018-12-27T15:14:02","date_gmt":"2018-12-27T20:14:02","guid":{"rendered":"https:\/\/pbacyber.com\/?p=201"},"modified":"2018-12-28T08:40:11","modified_gmt":"2018-12-28T13:40:11","slug":"kaspersky-lab-inc-and-the-assessment-of-cybersecurity-risk","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2018\/12\/27\/kaspersky-lab-inc-and-the-assessment-of-cybersecurity-risk\/","title":{"rendered":"Kaspersky Lab Inc., and the Assessment of Cybersecurity Risk"},"content":{"rendered":"\n<p>By Peter F. Johnson, Superior Court of Pennsylvania<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Late last month, the United States Court of Appeals for the District of Columbia filed its decision in <em>Kaspersky Lab, Inc. v. United States Department of Homeland Security<\/em>, 18-5176, 2018 WL 6252798 (D.C. Cir. Nov. 30, 2018), upholding a congressional prohibition on the use of Kaspersky Lab products by federal agencies. The court ruled against Kaspersky Lab in concluding Kaspersky Lab failed to adequately allege Congress\u2019s prohibition amounted to an unconstitutional legislative punishment. The court\u2019s ruling additionally allowed to stand a narrower directive of the Department of Homeland Security (DHS), which Kaspersky Lab also challenged.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>While the case\u2019s holding turns on constitutional law and federal government procurement, the mechanism by which the government addressed a cybersecurity risk is a legal one. The approach highlights a role for legal counsel to play in cybersecurity, through assessment of vendor, contractor, or supply chain risk, whether when advising on corporate governance or performing contract review.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>In <em>Kaspersky Lab Inc.<\/em>, in consolidated cases, Kaspersky Lab challenged a directive of DHS and challenged the National Defense Authorization Act for Fiscal Year 2018 (NDAA), both of which prohibited the use of Kaspersky Lab products by the federal government. <\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Kaspersky Lab is a major cybersecurity vendor, perhaps most well known for its anti-virus software. It <a href=\"https:\/\/www.cnet.com\/news\/kaspersky-lab-denies-any-ties-to-russian-government\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"garnered (opens in a new tab)\">garnered<\/a> <a rel=\"noreferrer noopener\" aria-label=\"media (opens in a new tab)\" href=\"https:\/\/www.nytimes.com\/2017\/03\/16\/us\/politics\/michael-flynn-russia-paid-trip.html\" target=\"_blank\">media<\/a> <a rel=\"noreferrer noopener\" aria-label=\"attention (opens in a new tab)\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2017-07-11\/kaspersky-lab-has-been-working-with-russian-intelligence\" target=\"_blank\">attention<\/a> following the 2016 presidential election for its purported ties to the Russian go<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.cnet.com\/news\/kaspersky-lab-denies-any-ties-to-russian-government\" target=\"_blank\"><\/a>vernment.<\/p><br \/>\n\n\n\n<p><\/p>\n\n\n\n<p><p>DHS is responsible for the implementation of information security policies for executive agencies, pursuant to the Federal Information Security Modernization Act of 2014, 44 U.S.C.A. \u00a7\u00a7 3551-3559.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Per the facts of the case, Kaspersky Lab\u2019s troubles began in spring 2017, when, among other reports, congressional hearings highlighted ties between Kaspersky Lab\u2019s founder and Russia\u2019s modern-day successor of the KGB. At one such hearing, the heads of various U.S. intelligence agencies were asked whether they would install Kaspersky software on their own computers. All replied no.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Subsequent to the hearings, in September 2017 DHS issued a <a href=\"https:\/\/www.federalregister.gov\/documents\/2017\/09\/19\/2017-19838\/national-protection-and-programs-directorate-notification-of-issuance-of-binding-operational\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"directive (opens in a new tab)\">directive<\/a>, which required federal agencies to begin removing \u201cKaspersky-branded products\u201d within 90 days, based on \u201cthe risks presented.\u201d <em>National Protection and Programs Directorate; Notification of Issuance of Binding Operational Directive 17-01 and Establishment of Procedures for Responses<\/em>, 82 Fed. Reg. 43782-02. This directive underlies the first of Kaspersky Lab\u2019s two consolidated actions.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Congressional hearings on the topic of Kaspersky products continued throughout 2017, including a review of DHS\u2019s rationale in issuing its directive. Before a House committee, DHS explained the concerns leading to the directive, as summarized by the D.C. Circuit:<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"margin-left: 1em;\">\nFirst, \u201ccertain Kaspersky officials\u201d enjoy \u201cties\u201d to \u201cRussian intelligence and other government officials.\u201d Second, Russian law \u201callow[s] Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks.\u201d And third, all antivirus software, including Kaspersky\u2019s, receives \u201cbroad access\u201d to the systems on which it operates. So like a thief who has stolen a security guard\u2019s master key, a cyberattacker can exploit antivirus software\u2019s \u201celevated privileges\u201d to inflict serious damage on the systems the software ostensibly protects. In the Department\u2019s view . . . the Directive \u201cis a reasonable, measured approach to the information security risks posed by . . . [Kaspersky] products to the federal government.\u201d<\/div><br>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p><em>Kaspersky Lab, Inc.<\/em>, at *2 (citing <em>Bolstering the Government\u2019s Cybersecurity: A Survey of Compliance with the DHS Directive: Hearing Before the House Subcommittee on Oversight, House Committee on Science, Space, and Technology<\/em>, 115th Cong. 22 (2017))<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Later in 2017, Congress passed the <a href=\"https:\/\/www.congress.gov\/bill\/115th-congress\/house-bill\/2810\/text\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"National Defense Authorization Act (NDAA) (opens in a new tab)\">National Defense Authorization Act (NDAA)<\/a> for Fiscal Year 2018, which included a provision prohibiting any element of the federal government from using \u201chardware, software, or services developed or provided\u201d by Kaspersky Lab or entities controlled by Kaspersky Lab. The president signed theact in mid-December 2017. The NDAA was the target of Kaspersky Lab\u2019s second consolidated action.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>The district court consolidated the two actions to resolve cross-motions for summary judgment and the government\u2019s motions to dismiss both cases. The district court granted the motion to dismiss the complaint against the NDAA, concluding Kaspersky Lab failed to adequately allege the Act\u2019s prohibition on the use of Kaspersky Lab products and services was a Bill of Attainder under the Constitution. Additionally, the district court concluded invalidating the directive alone would redress none of Kaspersky Lab\u2019s injuries, because NDAA covers more products and agencies than DHS\u2019s directive. Consequently, the district court dismissed that action for lack of standing.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>On appeal, the Court of Appeals for the D.C. Circuit agreed, determining through analysis of a straightforward three-part test, Kaspersky Lab failed to adequately allege Congress effected an impermissible legislative punishment by way of the NDAA\u2019s proscription on the use of Kaspersky Lab products and services. The holding allowed to stand the NDAA\u2019s prohibition, as well as the directive from DHS.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>The court\u2019s holding and reasoning is of limited import for most attorneys but, notably, the mechanism by which the government addressed a cybersecurity risk was a legal one. This approach demonstrates a role for law and thus for lawyers in shaping cybersecurity policy and practice. Counsel advising on corporate policy, or assessing risks present in contracts, may well consider the role that cybersecurity plays across all business functions.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><p>Further, it bore mention to DHS in their statements to Congress\u2014and to the D.C. Circuit in its analysis\u2014to address the particularly broad system access granted to antivirus software. In this way, both highlighted the importance of evaluating the scope of risk presented by individual technologies and technology-based partnerships. On this point too, there is a role for counsel in weighing and advising on those cybersecurity risks.<\/p><br><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>___________________________<\/p>\n\n\n\n<p><em>Peter F. Johnson, Esq. is the director of technology at the Superior Court of Pennsylvania<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Peter F. Johnson, Superior Court of Pennsylvania Late last month, the United States Court of Appeals for the District of Columbia filed its decision in Kaspersky Lab, Inc. v. United States Department of Homeland Security, 18-5176, 2018 WL 6252798 (D.C. Cir. Nov. 30, 2018), upholding a congressional prohibition on the use of Kaspersky Lab <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2018\/12\/27\/kaspersky-lab-inc-and-the-assessment-of-cybersecurity-risk\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[26,6],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/201"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=201"}],"version-history":[{"count":17,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/201\/revisions"}],"predecessor-version":[{"id":227,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/201\/revisions\/227"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}