The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Report on Securing and Growing the Digital Economy
Report on Securing and Growing the Digital Economy artwork

017 - Appendix 6 Cybersecurity Legislation Overview

Report on Securing and Growing the Digital Economy · 2026-03-05 · 10 min

0:00--:--

Key moments - from our scoring

Substance score

6 / 100

Five dimensions, 20 points each

Insight Density1 / 20
Originality1 / 20
Guest Caliber0 / 20
Specificity & Evidence4 / 20
Conversational Craft0 / 20

This episode provides a comprehensive chronological overview of U.S. cybersecurity legislation from 1984 through 2015, as documented in Appendix 6 of the Commission on Enhancing National Cybersecurity's Report. The episode catalogs 22 major legislative acts that shaped federal cybersecurity policy, tracking the evolution from early computer fraud laws like the Computer Fraud and Abuse Act (1986) through sector-specific regulations like HIPAA (1996) and the Gramm-Leach-Bliley Act (1999), to modern frameworks including FISMA (2002), the Homeland Security Act (2002), and the Cybersecurity Act of 2015. Key institutions emerge throughout: NIST (National Institute of Standards and Technology) as the primary standards-setting body, DHS (Department of Homeland Security) as the coordinating agency for federal cybersecurity efforts, and OMB (Office of Management and Budget) overseeing federal policies. The legislation progressively expands in scope - from criminalizing unauthorized computer access to mandating incident reporting, establishing federal data center consolidation requirements (FITARA), and requiring cybersecurity threat information sharing between public and private sectors (CISA). This episode serves compliance officers, policy advisors, and government IT leaders who need to understand the legislative foundation of modern cybersecurity requirements.

Key takeaways

  • →NIST (National Institute of Standards and Technology) was designated as the lead agency for developing federal cybersecurity standards under the Computer Security Act of 1987 and FISMA, and continues to play a central role in security guidelines and standards development.
  • →The Computer Fraud and Abuse Act of 1986 expanded criminal liability beyond unauthorized access to include data destruction and password distribution, establishing foundational computer crime law.
  • →FISMA (Federal Information Security Management Act of 2002) requires all federal agencies to implement basic cybersecurity measures and incident reporting, with revisions in 2014 modernizing these requirements.
  • →Sector-specific legislation like HIPAA, Gramm-Leach-Bliley, and the Energy Policy Act extended cybersecurity requirements to healthcare, financial, and energy infrastructure sectors.
  • →The Cybersecurity Information Sharing Act (CISA) of 2015 encouraged public-private sector collaboration on sharing cybersecurity threat information.

In this episode

  1. 1Early Cybersecurity Legislation 1980s: Computer Fraud and Abuse Acts
  2. 2Federal Agency Cybersecurity Standards 1987-1995
  3. 3Sector-Specific Legislation 1996-1999: Healthcare, Finance, and Infrastructure
  4. 4Post-9/11 Cybersecurity Framework 2002-2007
  5. 5Healthcare Data Security and Smart Grid Standards 2008-2009
  6. 6Workforce and Public-Private Partnership Initiatives 2014-2015

Mentioned

Commission on Enhancing National CybersecurityNational Institute of Standards and TechnologyNational Security AgencyOffice of Management and BudgetDepartment of Homeland SecurityNational Science FoundationFederal Energy Regulatory CommissionNational Cybersecurity and Communications Integration CenterLibriVoxColin McMahon

Topics in this episode

CybersecurityComputer Fraud and Abuse ActNational Institute of Standards and Technology (NIST)Federal Information Security Management Act (FISMA)Health Insurance Portability and Accountability Act (HIPAA)Gramm-Leach-Bliley ActSarbanes-Oxley ActDepartment of Homeland Security (DHS)Cybersecurity Information Sharing Act (CISA)Office of Management and Budget (OMB)futureeconomygovernmentdefense

Questions this episode answers

What did the Computer Fraud and Abuse Act of 1986 make illegal?

The 1986 Computer Fraud and Abuse Act built on the 1984 law by making additional actions illegal, including destruction of data without authorization and distribution of stolen passwords.

Which agency did NIST become responsible for under the Computer Security Act of 1987?

The Computer Security Act of 1987 designated NIST (then known as the National Bureau of Standards) as the lead agency for developing cybersecurity standards, with the National Security Agency providing assistance.

What did FISMA (Federal Information Security Management Act) of 2002 require federal agencies to do?

FISMA required all federal agencies to implement basic cybersecurity measures and designated NIST as responsible for developing security guidelines and guidance for securing federal civilian agency systems.

What is the Cybersecurity Information Sharing Act (CISA) and when was it enacted?

CISA, contained within the Cybersecurity Act of 2015, encouraged the sharing of cybersecurity threat information among public and private sector organizations.

What healthcare legislation built on HIPAA's data security requirements?

The Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 built on HIPAA by requiring notifications for health care data breaches and strengthening penalties for insufficient protection of healthcare data.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

1 / 20

The entire transcript is a LibriVox narrator reading a flat legislative timeline with no analysis, commentary, or non-obvious claims - just one-sentence descriptions of laws. There is zero insight per minute; it is a reference index read aloud.

This law made it illegal to access and use computers and computer networks without authorization to do so.
This law designated the Office of Management and Budget OMB as the agency responsible for federal agency cybersecurity policies.

Originality

1 / 20

This is a verbatim narration of a government commission appendix. There is no original thinking, no contrarian framing, no synthesis - only a chronological list of public laws as written by bureaucrats.

This appendix gives an overview of selected efforts by Congress to address cybersecurity
This law encouraged the public and private sectors to work together to improve cybersecurity in terms of research and development, workforce preparedness, and public awareness.

Guest Caliber

0 / 20

There is no guest and no host in any meaningful sense - only a LibriVox volunteer narrator reading a public domain government document. This is categorically not a podcast interview or discussion.

This is a LibriVox recording. All LibriVox recordings are in the public domain. For more information or to volunteer, please visit LibriVox dot org. Recording by Colin McMahon.

Specificity & Evidence

4 / 20

The transcript does contain specific law names, public law numbers, and precise dates, which prevents a zero score, but there is no outcome data, no metrics, no named case studies, and no evidence of real-world impact - just legislative catalogue entries.

Public Law ninety eight DASH four seven three Counterfeit Access Device and Computer Fraud and Abuse Act of nineteen eighty four October twelfth, nineteen eighty four.
Title eight Subtitle D of this law contains portions of what was originally HR twelve thirty two Federal Information Technology Acquisition Reform Act FITARA.

Conversational Craft

0 / 20

There is no conversation, no host, no questions, no follow-ups, and no dialogue of any kind. This is a single narrator reading a document from start to finish without interruption or interaction.

End of section sixteen recording by Colin McMahon. End of Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cybersecurity30public26nineteen24twenty20security19thousand19ninety18federal17information14four14eighty13dash13seven12five12national11nine10

Episode notes

On April 13, 2016, President Obama established The Presidents Commission on Enhancing National Cybersecurity to devise a comprehensive strategy for safeguarding our cyberspace and the economic foundations built upon it. The commissions final report, published in December 2016, provides a thorough examination of the current state of cybersecurity, anticipates future challenges, and presents actionable recommendations for the incoming Trump administration and future leaders. It emphasizes the critical roles that the military, government, and private sector must play in strengthening our defenses against cyber threats. Join us as we explore the insights and strategies laid out in this pivotal report. - Summary by TriciaG

Full transcript

10 min

Transcribed and scored by The B2B Podcast Index.

Speaker 1: Section sixteen of Report on Securing and Growing the Digital Economy. This is a LibriVox recording. All LibriVox recordings are in the public domain. For more information or to volunteer, please visit LibriVox dot org. Recording by Colin McMahon. Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity. Appendix six Cybersecurity Legislation Overview. This appendix gives an overview of selected efforts by Congress to address cybersecurity nineteen eighty through nineteen eighty nine. One Public Law ninety eight DASH four seven three Counterfeit Access Device and Computer Fraud and Abuse Act of nineteen eighty four October twelfth, nineteen eighty four. This law made it illegal to access and use computers and computer networks without authorization to do so. Two. Public Law ninety nine Dash fouris seventy four Computer Fraud and Abuse Act of nineteen eighty six October sixteenth, nineteen eighty six. Building on the Counterfeit Access Device and Computer Fraud and Abuse Act of nineteen eighty four, this law made additional actions illegal, such as destruction of data without authorization and distribution of stolen passwords three. Public Law one hundred Dash two thirty five Computer Security Act of nineteen eighty seven January eighth, nineteen eighty eight. The Computer Security Act of nineteen eighty seven was established to ensure that all federal agencies implemented basic cybersecurity measures for protecting sensitive information. The law designated the National Bureau of Standards now known as the National Institute of Standards and Technology or NIST, as the lead agency for developing cybersecurity standards, with the National Security Agency and Essay providing assistance. This law was replaced by the Federal Informations Security Management Act in two thousand and two nineteen ninety through nineteen ninety nine. Four. Public Law one oh four Dash thirteen Paperwork Reduction Act of nineteen ninety five, May twenty fifth, nineteen ninety five. This law designated the Office of Management and Budget OMB as the agency responsible for federal agency cybersecurity policies. Five divisions D and E. Public Law one oh four Dash one oh six Klinger Cohen Act of nineteen ninety six February tenth, nineteen ninety six. The Klinger Cohen Act designated agency responsibilities related to their cybersecurity policies and processes. Six Public Law one oh four Dash one ninety one Health Insurance Portability and Accountability Act of nineteen ninety six, August twenty first, nineteen ninety six. The Health Insurance Portability and Accountability Act HIPPA included provisions for ensuring the security of sensitive healthcare information. Seven Title II Public Law one oh four Dash two ninety four National Information Infrastructure Protection Act, October eleventh, nineteen ninety six. Title II of this law revised the Computer Fraud and Abuse Act of nineteen eighty six by expanding the definitions of computer crime. Eight Title five Public Law one oh Sixdash one oh two Graham Leach Blidely Act of nineteen ninety nine, November twelfth, nineteen ninety nine. This law required financial institutions to protect the confidentiality of all sensitive data regarding their customers. Two thousand to two thousand nine. Nine Public Law one oh seven Dash two oh four Starbine's Oxley Act of two thousand two July thirty, two thousand and two. This law, directed at publicly owned US companies, contained requirements to produce annual assessments of internal control, including cybersecurity measures. Ten titles two and three. Public Law one oh seven DESH two ninety six Homeland Security Act of two thousand and two, November twenty five, two thousand and two. The Homeland Security Act established the Department of Homeland Security DHS to focus federal efforts on safeguarding the nation against threats, including cybersecurity threats, and to respond to disasters caused by those threats. Eleven Public Law one oh seven DESH three oh five Cybersecurity Research and Development Act, November twenty seventh, two thousand and two. The purpose of this law was to increase the federal government's funding of cybersecurity research and development. Several ways to do so were specified, including National Science Foundation NSF research grants, research fellowships awarded by NSF and NIST, the development of security configuration checklists by NIST to help agencies secure their computer hardware and software. The creation by NIST of the Computer Systems Security and Privacy Advisory Board, which was subsequently renamed the Information Security and Privacy Advisory Board ISSPAB. A study by the National Academy of Science of Critical Infrastructure cybersecurity, coordination of federal cybersecurity are and D efforts between NSF and NIST twelve, Title three Information Security Public Law one oh seven DH three forty seven. The Federal Information Security Management Act of two thousand and two December seventeenth, two thousand and two, also known as the e Government Act of two thousand and two. The Federal Information Security Management Act of two thousand and two FISMA was intended to ensure that all federal agencies implemented basic cybersecurity measures at a minimum fa LI. FISMA designated NIST as the agency responsible for developing security guidelines and guidance to be used for securing federal civilian agency systems. Section thirteen Public Law one oh nine DASH fifty eight Energy Policy Act of two thousand five, August eight, two thousand five. This law required the Federal Energy Regulatory Commission FEERC to develop standards for the reliability of certain types of electric power facilities. Fourteen Public Law one oh nine DASH two ninety five Department of Homeland Security Appropriations Act two thousand seven, October four, two thousand and six. This law required new regulations for chemical facility security, including cybersecurity requirements. Fifteen Public Law one ten DESH one forty Energy Independence and Security Act of two thousand seven December nineteen, two thousand seven. This law designated ANIST as the agency leading the effort to create interoperability standards for the smart grid. Sixteen Division A Title thirteen and Division B Title iov Public Law one eleven DASH five Health Information Technology for Economic and Clinical Health Act, February seventeen, two thousand nine. This law built on HIPPA by requiring notifications for health care data breaches and strengthening penalties for insufficient protection of healthcare data. Twenty ten to present. Seventeen Public Law one thirteen DASH two forty six Cybersecurity Workforce Assessment Act, December eighteenth, twenty fourteen. This law required regular assessments of the DHS Cybersecurity Workforce. Eighteen Public Law one thirteen DASH two seventy four Cybersecurity Enhancement Act of twenty fourteen, December eighteenth, twenty five fourteen. This law encouraged the public and private sectors to work together to improve cybersecurity in terms of research and development, workforce preparedness, and public awareness. Nineteen Public Law one thirteen two eighty two National Cybersecurity Protection Act of twenty fourteen, December eighteenth, twenty fourteen. The purpose of this law was to codify the responsibilities of the National Cybersecurity and Communications Integration Center NCCIC. Twenty Public Law one Thirteenash two eighty three Federal Information Security Modernization Act of twenty fourteen, December eighteenth, twenty fourteen. This law modified FISMA to revise cybersecurity incident reporting requirements for federal agencies, clarify certain federal agency cybersecurity authorities, and streamlined cybersecurity reporting. Twenty one Public Law one thirteen DESH ninety one National Defense Authorization Act for Fiscal year twenty fifteen December nineteenth, twenty fourteen. Title eight Subtitle D of this law contains portions of what was originally HR twelve thirty two Federal Information Technology Acquisition Reform Act FITARA. The law required some changes to federal information technology practices that had implications for cybersecurity, most notably quote consolidation of federal data centers end of quote twenty two division n Public Law one fourteen sh one thirteen Cybersecurity Act of twenty fifteen, December eighteenth, twenty fifteen. The Cybersecurity Act of twenty fifteen contains the Cybersecurity Information Sharing Act CISA. CISA encouraged the sharing of cybersecurity threat information among public and private sector organizations. End of section sixteen recording by Colin McMahon. End of Report on Securing and Growing the Digital Economy by the Commission on Enhancing National Cybersecurity

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • She Convinced the Pentagon to Let Hackers In. Legally. With Katie MoussourisCyber Leaders · on Computer Fraud and Abuse Act92 / 100
  • Why Most Startups Fail: Founders Don’t Know What They Don’t Know YetBuilt Not Born: The Startup Go-To-Market Podcast · on Cybersecurity80 / 100
  • Episode 46 - from Tashkent to Termsheet with Victor OrlovskyThe GoingVC Podcast · on Cybersecurity77 / 100
  • Moving from Product Partnerships to Revenue: Jira Cooley on Owning the NumberBetween Product and Partnerships · on Cybersecurity76 / 100
  • Reframing Marketing ROI to Return on Objectives with Karl Van den BerghThe B2B CMO Podcast with Jon Miller and Sydney Sloan · on Cybersecurity75 / 100
  • Help Desk Heroes No More: Why Your IT Guy Now Talks StrategyNerds On Tap · on Cybersecurity72 / 100

More from Report on Securing and Growing the Digital Economy

All episodes →
  • 016 - Appendix 5 Cybersecurity Policy Overview31 / 100
  • 015 - Appendix 4 Executive Order 1371826 / 100
  • 014 - Appendix 1 Imperatives Recommendations and Action Items26 / 100
  • 013 - Imperative 6 Ensure an Open Fair Competitive and Secure Global Digital Economy IV Next Steps36 / 100
  • 012 - Imperative 5 Better Equip Government to Function Effectively and Securely in the Digital Age38 / 100
All Report on Securing and Growing the Digital Economy episodes →