Last week, Rep Gottheimer (D,NJ) introduced HR 10671, the Securing Our Critical Infrastructure Act. The bill would reinstate and revise a recently expired CISA ransomware notification program to turn it into a program to notify small water utilities of known vulnerabilities. No new funding is authorized.
This bill would amend §105, Ransomware Vulnerability Warning Pilot Program, of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Division Y of PL 117-103, 136 STAT. 1055). The authorization for that program {§105(g)} terminated on March 15th, 2026. That program was codified at 6 USC 652 Note.
Moving Forward
Neither Gottheimer, nor any of his four cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for consideration. This means that it is unlikely that there will be sufficient influence to see the bill considered by that Committee. Without additional spending for CISA to fund this new program, there is no way that the Agency would have enough personnel to support these new requirements. I suspect that common knowledge of that fact will ensure that there would be minimal Republican support for this legislation, if it were to be considered.
Commentary
This is an unusual solution to the problem of vulnerabilities in water treatment facilities. It assumes that the problem facing these facilities is lack of knowledge about the vulnerabilities in their systems. However, even if that is true (a topic for another day), I am pretty sure that setting up this program in CISA is not the way to go. Most importantly, why should CISA focus such efforts on water systems when they are not the Sector Specific Agency responsible for that sector. The appropriate SSA would be the Environmental Protection Agency (EPA).
For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-10671-introduced-vulnerability - subscription required.
No comments:
Post a Comment