I agree auditing isn't a silver bullet, and I honestly don't think the federal government should be doing anything here. If they care about the security of "critical infrastructure", whatever that is, they can provide funding for compliance and then demand accreditation before the system is deployed.
But CISPA, is just a way to funnel data about every person in the world into a giant government database in secret. It dwarfs the NSA wiretapping scandal and it allows companies to violate their own privacy policies and shelter them from justified lawsuits.
That is absolutely not what CISPA is about. If the government wanted to funnel private data to giant government databases, their best move would be to do nothing, because that action is already mostly lawful under ECPA. ECPA provides unchecked latitude for service providers to disclose private data so long as it's done in the course or protecting or maintaining the service. CISPA adds restrictions to this process.
(I don't support CISPA, but not for this bullshit tinfoil hat reason).
The amount of misinformation circulating around CISPA is very dispiriting. People are being deluded into thinking there's some giant conspiracy, and the only reason that's happening is so that unscrupulous interest groups can fundraise or drive ad revenue from rageviews.
But CISPA, is just a way to funnel data about every person in the world into a giant government database in secret. It dwarfs the NSA wiretapping scandal and it allows companies to violate their own privacy policies and shelter them from justified lawsuits.