This Executive Order refers to a “Voluntary Critical Infrastructure Cybersecurity Program,” ordering that the Secretary “shall establish” a “voluntary program.” This “voluntary program” is the Department of Defense – Defense Industrial Base Voluntary Cyber Security and Information Assurance (DoD CISPA rule). This rule (DOD–2009–OS–0183/RIN 0790–AI60) became final in 2012, yet there was no Congressional law upon which this Executive Order is based. President Obama’s Executive Order is thus an attempt to make law by incorporating this final rule into an Executive mandate which would apply across networks with the President and Administration officials in direct command of an army of private contractors and federal agencies. The Administration thus must submit the Order to a court for review.



