Showing posts with label Amendments. Show all posts
Showing posts with label Amendments. Show all posts

Wednesday, June 12, 2024

Rules Report for HR 8070 Published – FY 2025 NDAA

Since I published last night’s post on amendments to HR 8070, the FY 2025 National Defense Authorization Act, the House Rules Committee has published their Committee Print of their report on the rule (H Res 1287) for the consideration of HR 8070. This removes my concern about starting debate today on that bill. Below is the revised list of amendments of potential interest here with the amendment numbers that will be used in that debate. I have also added two amendments on uncrewed aircraft systems.

Cybersecurity Related Amendments

102. Panetta (CA), Bacon (NE), Trone (MD), Wagner (MO), Rodgers (WA), Schneider (IL): Creates a foreign military officer subject matter expert exchange program with key Middle East partners in areas such as artificial intelligence, military doctrine and spending, cyber resiliency, counterterrorism, and more. (10 minutes),

124. Green (TN): Mandates that the Department of Defense produce a report to Congress on the feasibility of furnishing the national guard of every state a cyber unit to ensure the state has the ability to quickly respond to cyber attacks. (10 minutes),

248. Joyce (OH): Authorizes the “Project Spectrum” program within the Office of Small Business Programs of the Department of Defense to provide Department of Defense suppliers that are small or medium businesses, through an online platform, digital resources and services that increase awareness about cybersecurity risks and help such entities to comply with the cybersecurity requirements of the defense acquisition system. (10 minutes), and

275. Banks (IN): Requires the Secretary of Defense to provide a plan for the growth of the Hacking for Defense program. (10 minutes).

Space Related Amendments

114. Gottheimer (NJ), Titus (NV), Moskowitz (FL): Expresses support for joint U.S.-Israel cooperation in the space arena between NASA and the Israel Space Agency, including joint U.S. Air Force and the Israeli Air Force’s newly created Space Force in areas of research, development, test, and evaluation. (10 minutes),

141. Himes (CT), Crawford (AR), Bergman (MI): Expresses the sense of Congress the importance of comprehensive cislunar Space Domain Awareness capabilities and the need to ensure the safety of flight of civil and commercial missions in cislunar space. Directs the Chief of Space Operations to deliver a report on three things: requirements for cislunar, the department’s plan for researching and developing technologies for cislunar, and how the department coordinates with the Cislunar Technology Strategy Interagency Working Group regarding the progress made on the objectives laid out in the November 2022 National Cislunar Science and Technology Strategy. (10 minutes),

262. Ivey (MD): Directs the GAO to study, and issue a report on, the potential threats to US interests posed by Iran, China, Russia, and other adversarial States through the antagonistic use of extraterrestrial satellites for combat, incapacitation of other satellites, cybersecurity intrusions, debilitation of critical infrastructure, and other aggressive purposes. (10 minutes),

274. Pettersen (CO), Crow (CO): Expresses a Sense of Congress that the Space Force continue its commitment to accelerating the development of very low earth orbit (VLEO) space capabilities. (10 minutes), and

280. Donalds (FL): Directs the U.S. Space Force to submit a report pertaining to its current and future potential use of nuclear thermal propulsion space vehicles and nuclear electric propulsion space vehicles, and how these nuclear-powered space vehicles can bolster America's national security. (10 minutes).

Vehicle Technology Related Amendments

239. Buchanan (FL): Requires the Comptroller General of the United States to conduct a study to assess ways unmanned vehicles can reduce overall operating expenses and costs at the Department of Defense. (10 minutes),

279. Walberg (MI), Dingell (MI): Requires the Secretary of Defense to conduct a study on the national security risks of highly automated vehicles associated with foreign adversary countries operating or testing in the United States. (10 minutes), and

344. Bergman (MI): Authorizes $10 million for Fuel Cell Multi-Modular Use (FC-MMU) utilizing hydrogen in FY25. (10 minutes).

UAS Related Amendments

278. Donalds (FL): Adds a Sense of Congress that Congress encourages the U.S. Armed Forces to utilize innovative technologies, such as artificial intelligence, quantum, advanced air mobility, and counter-uas, to ultimately defend the national security of the United States. (10 minutes), and

328. Gottheimer (NJ), Tenney (NY), Moskowitz (FL): Requires the Secretary of Defense to report on the status of U.S.-Israel cooperation on efforts to counter threats by Iran in the form of unmanned aerial systems (UAS), including loitering munitions, otherwise known as “suicide” and “kamikaze” drones. (10 minutes).

Saturday, October 1, 2022

HR 7900 Amendments Proposed – FY 2023 NDAA – 9-28-22

On Wednesday, with the Senate still not officially considering HR 7900, the FY 2023 National Defense Authorization Act, there were 285 amendments proposed to the substitute language (SA 5499) for that bill. Six of those amendments may be of interest here: 

SA 5789. Ms. ROSEN - At the appropriate place, insert the following: SEC. xx. Improving Cybersecurity of Small Entities

SA 5807. Mr. PORTMAN - At the appropriate place, insert the following: SEC. xxxxx. Technological Hazards Preparedness Training.

SA 5811. Mr. PORTMAN - At the appropriate place, insert the following: SEC. xxx. CISA Technical Corrections and Improvements.

SA 5815. Mr. PETERS - At the appropriate place, insert the following: DIVISION xx—Federal Information Security Modernization Act of 2022

SA 5933. Mr. PORTMAN - At the appropriate place in subtitle G of title X, insert the following: SECTION 10xx. Requirement for Information Sharing Agreements.

SA 5950. Mr. WARNER - At the appropriate place, insert the following: DIVISION xx—Intelligence Authorization Act for Fiscal Year 2023.

NOTE: Congress.gov has been having problems this week keeping up with the massive amount of information being included in the Congressional Record. They still have not yet published the Record for September 29th.

Tuesday, November 16, 2021

Senate Amendments to HR 4350 – 11-15-21

With the Senate starting the process for the consideration of HR 4350, the FY 2022 NDAA, there were 108 new amendments to that bill proposed in the Senate yesterday. Nine of those amendments made reference to cybersecurity issues:

SA 4560 - Sen King (I,ME): SEC. xx. Secure foundational internet protocols. [pg S8091],

SA 4561 - Sen King: DIVISION E: Defense of United States Infrastructure [pg S8091] Similar to S 2491,

SA 4580 - Sen Gillibrand (D,NY): SEC. 1601. Matters concerning cyber personnel requirements. [pg S8100] SA 3903 and SA 4181,

SA 4581 - Sen Gillibrand: SEC. xxx. Matters concerning cyber personnel education requirements. [pg S8101] SA 3903 and SA 4181,

SA 4598 - Sen Hassan (D,NV): DIVISION E: Federal Cybersecurity Workforce Expansion Act [pg S809] Similar to S 2274,

SA 4616 - Sen Warner (D,VA): DIVISION xx: Intelligence Authorization Act for Fiscal Year 2022 [pg S8128] Similar to S 2610,

SA 4624 - Sen Warner: SEC. xxx. Educational assistance for pursuit of programs of education in cybersecurity. [pg S8149],

SA 4637 - Sen Risch (R,ID): SEC. 1064. Think tank cybersecurity standards. [pg S8158], and

SA 4647 - Sen Peters (D,MI): DIVISION E: Federal Information Security Modernization Act of 2021 [pg S8179] Similar to S 2902.

Wednesday, October 27, 2021

Senate Amendments to HR 4350 – 10-26-21

While the Senate still has not officially started the consideration of HR 4350, the FY 2022 NDAA, there were 36 amendments proposed in the Senate yesterday. One of those amendments may be of interest here:

SA 3903 – Sen Warnock - SEC. 1601. Matters concerning cyber personnel requirements. [pg S7385]

The amendment requires DOD to look at the education and training requirements for ‘cyber operation, information operation, and software engineering military personnel’ and prepare a report to Congress on those requirements. The amendment specifically includes a requirement to determine if a graduate level education program on the lines of the current war colleges run by the three services is necessary.

Friday, May 27, 2016

Amendments to S 2943, FY 2017 NDAA – 5-26-16

Yesterday the Senate continued consideration of S 2943, the FY 2017 National Defense Authorization Act. An agreement was reached to continue consideration on June 6th when the Senate returns from their Memorial Day weekend. During the day yesterday a total of 134 amendments were offered for consideration. Two of those amendments may be of specific interest to readers of this blog:

The Amendments


The two amendments of potential interest were

SA 4244 (pg S3302) – Sen. Reed (D,RI) - SEC. 1097. Cybersecurity transparency.
SA 4303 (pg S3322) – Sen. Portman (R,OH) - SEC. 526. Plan to meet the demand for cyberspace career fields in the reserve components of the air force.

The Reed amendment is essentially identical to S 2410 introduced by Reed in December, 2015 establishing cybersecurity expertise requirements for corporate boards. The language does specifically include “industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers” {new §1097(a)(3)(B)} in the definition of ‘information system’.

The Portman amendment would require the Air Force to report to Congress on their plan “for meeting the increased demand for cyberspace career fields in the reserve components of the Air Force, in accordance with the recommendations of the National Commission on the Structure of the Air Force” {new §526(a)}.

Moving Forward


The Senate has only reached agreement on the consideration of one amendment so far (and it is not one of the amendments of concern here), but I expect that we will see a lot more movement when the Senate returns. Either of these two amendments could easily be adopted if they were to be considered in the floor debate.


The Reed amendment is not really a DOD related topic, but the Senate rules are quite generous about the topics that can be added in the amendment process. It all depends on how much political will Reed and any other amendment supporters can bring to bear on the Senate leadership.

Monday, May 16, 2016

Rules Committee Hearings for HR 4909 – FY 2017 NDAA

The House Rules Committee will be holding two hearings this week on HR 4909, the FY 2017 National Defense Authorization Act. The first meeting will be this evening and will set the general consideration rule for the bill. The second meeting will determine which of the 372 amendments submitted to date will be allowed to be offered during the floor debate of the bill. Only seven of those amendments may be of specific interest to readers of this blog; five relating to cybersecurity issues and two to TWIC issues.

Cybersecurity Amendments


There are five cybersecurity related amendments that the Rules Committee will consider. They are:

 #34 Sewell (D,AL) Allows cyber institutes to place a special emphasis on entering into a partnership with a local educational agency located in a rural, under served, or underrepresented community.
#44 Speier (D,CA) Establishes cybersecurity as a performance parameter for Department systems to protect critical information, mitigate cyber vulnerabilities, and respond to cyber-attacks.
#47 Meehan (R,PA) Expresses a sense of Congress that reiterates the importance of strong communications systems for the National Guard in the event of a cyber or terrorist attack.
#53 Walker (R,NC) Revised Provides that the President may not pursue bilateral cybersecurity working groups with the Russian Federation or the People’s Republic of China unless the President notifies Congress that Russia and China, respectively, has ceased carrying out state-sponsored economic, military, or industrial espionage in cyberspace against the United States or persons of the United States.
#136 Lofgren (D,CA) Prohibits using funds to mandate or request “backdoors” into commercial products that can be used to circumvent encryption or security protections.

None of these amendments would have any effect on industrial control system security issues.

TWIC Amendments


There are two amendments deal with Transportation Workers Identification Credentials (TWIC):

#164 Hunter (R,CA) Expands the use of the Transportation Worker Identification Credential (TWIC) regarding access at DoD installations.
#226 Donovan (R,NY) Expedites processing of applications for transportation security cards for separating members of the Armed forces and veterans to facilitate employment in the maritime industry.

The Hunter amendment requires DOD to use the TWIC program to allow transportation workers unescorted access to military installations pending the development and implementation of the Identity Management Enterprise Services Architecture. Hopefully, DOD will learn lessons from the TWIC implementation.

Moving Forward


The House is scheduled to take up HR 4909 on Thursday. I would be surprised if the House completes consideration of all three bills (includes military construction spending and Zika response spending) on Thursday and no votes are scheduled for Friday.


At this point there is no way of forecasting which (if any) of the above described amendments will be considered on the Floor of the House on Thursday.

Tuesday, April 12, 2016

HR 636 Amendments in Senate – 04-11-16

There were a total of 74 new amendments to HR 636, the FAA authorization bill, offered in the Senate yesterday. Two of those were cybersecurity related, SA 3621 and SA 3627. They were actually the same amendment, but one was amending the base bill (SA 3627) and the other was amending the substitute language (SA 3621). SA 3621 was one of the 12 amendments that were adopted by the Senate yesterday.

Security Aircraft Avionics Systems


Both of these amendments yesterday were proposed by Sen. Nelson (D,FL) and had similar intent to his amendment SA 3474 that I described last week. They did, however, provide more specifics as to how that intent would be accomplished.

Paragraph (a) of the proposed new section was re-formatted to have two subparagraphs, but the wording remained the same. Paragraph (b) was added to ensure that actions taken by the Administrator would be in accordance with “the recommendations of the Aircraft Systems Information Security Protection Working Group [link added] under section 5029(d) [discussed in last week’s post] of this Act”.

Paragraph (c) would add an additional tasking for the ASISPWG in §5029(d). The Working Group would also be required to look at “the cybersecurity risks of in-flight entertainment systems to consider whether such systems can and should be isolated and separate from systems required for safe flight and operations, including reviewing standards for air gaps or other means determined appropriate”.

Amendments Adopted


A number of amendments to the substitute language were adopted by unanimous consent. Two of those may be of specific interest to readers of this blog. The first was SA 3621 that is described above. The second was the unmanned aircraft system (UAS) amendment, SA 3492 (described here last week) that would allow critical infrastructure owners to fly UAS without restrictions on time of day or the requirement for the pilot to maintain visual contact with the UAS under certain circumstances.

Moving Forward


Debate on HR 636 continues today. I have seen no reports that Sen. McConnell has filed cloture to close off debate, so the discussions will continue at least through tomorrow. TheHill.com is reporting that the agreement on adding tax breaks for environmental issues overlooked in last year’s spending bill will not be included in HR 636 as I reported last week. It is not clear what effect this will have on the continued consideration of this bill.

Commentary


The avionics security amendment should be much more effective than the one that Nelson originally introduced. Ensuring that the Working Group recommendations are taken into account when the FAA writes the cybersecurity regulations will help ensure that the technical issues are adequately addressed.

Unless we see additional cybersecurity amendments proposed today or tomorrow (looking less likely) this will be the only additional security language included in the bill. The requirements in the substitute language and yesterday’s amendment will provide the FAA with lots of regulatory work for the next couple of years.

Will it be adequate to protect against all potential attacks on aircraft systems? Absolutely not. Anyone that thinks that a single set of regulations, no matter how well written, will stop all attacks completely misunderstands how security works. It is not possible to stop a determined, well financed and trained attacker.

Will the regulations help? Almost certainly. It will ensure that there is at least a minimum level of security at each of the airlines. More importantly, it puts airplane manufacturers on notice of their responsibility for ensuring minimum levels of cybersecurity on aircraft that they sell to the airlines. Finally, this bill will ensure that there is an official, documented discussion about the advisability of linking aircraft entertainment, communications, and control systems on a single network. When people’s reputations are put on the line, I would be willing to bet that they will agree (reluctantly to be sure in some cases) that establishing three separate networks will be less costly in the long run.

Could more be done? Certainly. The biggest thing lacking in this bill is formal language making some agency (I would nominate ICS-CERT, due to possible overlaps with non-aviation systems) to act as a coordinator between vendors, airlines and the cybersecurity research community for software and firmware vulnerability reports. Finally, on that topic, someone at the FAA needs to be formally designated as the final arbiter of whether or not an unfixed avionics system vulnerability is of high enough risk to ground aircraft until the vulnerability is appropriately mitigated.


It is not surprising that Congress has not attempted to address the software vulnerability disclosure and consequence issue here. It has studiously ignored the problem in all sectors of the economy. The potential consequences of an unaddressed vulnerability in this venue, however, have an extraordinary potential to result in a spectacularly public failure; the type of failure that ends in vocal finger pointing and blame laying. The political backlash will be of epic making proportions. And the resulting legislation will handicap the industry for decades to come as unintended consequences overwhelm the best intentioned manufacturers.

Wednesday, February 3, 2016

Amendments to S 2012 – 02-02-16

Yesterday there were 47 amendments proposed for S 2012, the Energy Policy Modernization Act of 2015. Of those, three may be of specific interest to readers of this blog:

SA 3186. Mrs. FISCHER (R,NE), pg S493;
SA 3196. Mr. KIRK (R,IL), pg S501;
SA 3197. Ms. COLLINS (R,ME), pg S501;

OSHA Retail Facility Exemption

Fisher’s amendment would stop the Occupational Health and Safety Administration (OSHA) from changing the way it interprets which facilities are exempted from the Process Safety Management Standards (PSM) on the basis of being a ‘retail facility’. OSHA announced their narrowing of the interpretation of the term ‘retail facility’ last July. This amendment would stop any enforcement actions on the new definition until a rulemaking was completed establishing the new definition.

Large Scale Cyber Incidents

The Kirk amendment would establish ‘large scale cyber incident’ as an incident that could be covered under the disaster relief provisions of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 USC 5121 et seq). It specifically adds the words ‘cyber incident’ to the definition of ‘major disaster’ {§5122(2)}.

The amendment would add a new definition for the term “cyber incident” {new §5122(14)} which would be defined as:

“Actions taken against critical infrastructure through the use of computer networks that result in a significant adverse effect on the provision of essential services {as described in §5189e(a)(1)} which:
“Lasts for a period of more than 24-hours; and
“Affects the provision of essential services in more than 1 State.”

The term ‘essential services’ in the current law means any entity that is contributing to efforts to respond to an emergency or major disaster and provides {§5189e(a)}:

• Telecommunications service;
• Electrical power;
• Natural gas;
• Water and sewer services; or
• Any other essential service, as determined by the President.

Critical Electric Infrastructure at Greatest Risk

The Collins amendment would define ‘critical electric infrastructure’ as “a system or asset of the bulk-power system, whether physical or virtual, the incapacity or destruction of which would negatively affect national security, economic security, public health or safety, or any combination of those matters” {new §225(a)(2)}. It then goes on to define ‘covered entity’ as a critical infrastructure entity under EO 13636, §9(a).

The amendment then requires FERC and the DOE Secretary to:

“Identify and propose prioritized, risk-based actions to mitigate cyber risk for each covered entity such that, to the greatest extent practicable, a cyber security incident affecting that covered entity would be less likely to result in catastrophic regional or national effects on public health or safety, economic security, or national security, given current and projected cyber risks” {new §225(b)(2)}.

As to be expected reports to congress are required on the identified cyber security incidents and proposed mitigation measures.

Moving Forward

It is now looking like there will be a cloture vote on the substitute language on Thursday. This means that there will be a cut off for submission of new amendments to that language this afternoon.

The Fisher amendment is partisan in nature and neither she nor any of her co-sponsors are on the Energy and Natural Resources Committee. I would be surprised if this makes the short list of amendments that will make it to the floor. If it does get to the floor it will probably not get the 60 votes normally needed for passage during the amendment process.

The Kirk amendment is relatively non-partisan, but Kirk is not on the Energy and Natural Resources Committee. This is an iffy amendment for the purposes of making it to the floor for consideration, but if it does make it to the floor, it will probably get the 60 votes for passage.

The Collins amendment is relatively non-partisan and Sen. Collins is a senior and influential member of the Senate. This amendment has a good chance of getting considered and would almost certainly get the 60 votes necessary for adoption if it does make it to the floor.

Commentary

The two cybersecurity amendments introduced yesterday are very limited in scope. While the Kirk amendment does include cyber incidents in disaster relief coverage it only does so with respect to incidents that happen coincidentally to other disasters. The wording does not even allow the cyber incident to be caused by the coincidental disaster.


The Collins amendment would provide less restrictions on its coverage, but it provides very wide latitude in what FERC and DOE designate as a cyber risk and how it would be mitigated. There is no reason to expect that FERC will be any more aggressive with defining those risk and mitigation measures than they are now.

Tuesday, February 2, 2016

Amendments to S 2012 – 02-01-16

Yesterday there were 40 more amendments introduced for S 2012, the Energy Policy Modernization Act of 2015. Of those, one may be of specific interest to readers of this blog:

SA 3163, Mrs. FISCHER (R,NE), pg S431

This amendment is essential S 2276, the Pipes Act. This is not exactly the same version that was discussed in my earlier post. The Senate Commerce, Science and Transportation Committee marked-up that bill back in December and the revised version has not yet been published. The two new rulemakings and the TSA pipeline security report mentioned in that earlier blog are included in the language of this proposed amendment.

Since this amendment is energy related and it did receive bipartisan support in Committee, there is a pretty good chance that this might make it to the short list of amendments that will be considered on the Senate floor. If it does, it will almost certainly be approved

Thursday, January 28, 2016

Amendments to S 2012 – 01-27-16

Yesterday there were 84 amendments submitted to S 2012 that is currently being considered in the Senate. Of those only one may be of specific interest to readers of this blog:

SA 2997 – Sen. Wyden (D,OR) – pg S 272

Internet of Things

Wyden’s amendment would add paragraph (d), Internet of Things (IOT), to §1021, Study and report on energy savings benefits of operational efficiency programs and services. It would require that the report required under §1021 would include an analysis of the impact of IOT technology on energy and water systems. It would be required to identify IOT technology solutions that {new §1021(d)(B)(ii)}, “through features embedded in hardware and software from the outset” … “promote security, privacy, interoperability, and open standards”.

Moving Forward

Yesterday was only the first day of consideration of this complex bill. At this point in their deliberations there is no clear indication of how many or which amendments will ultimately be considered on the floor of the Senate. If this amendment does make it to the floor it will likely be approved since it only requires a modification to an existing report.

Commentary

This amendment contains an interesting definition of IOT. Paragraph (d)(1) defines IOT as a set of technologies that:

• Connect to the Internet; and
• Provide real-time and actionable analytics and predictive maintenance


The inclusion of a requirement for ‘actionable analytics and predictive maintenance’ a number of devices that most people would lump together under the IOT rubric. Even in the industrial IOT realm operational devices connected to control systems in electric utility or water utility facilities would not fall under this relatively limited definition.

Tuesday, December 1, 2015

HR 8 Amendments

The House Rules Committee met this afternoon to craft the rule for the consideration of amendments to HR 8, the North American Energy Security and Infrastructure Act of 2015, on the floor of the House. A structured rule was approved with 38 amendments to be considered during the floor debate.

Amendments of Possible Concern

Of the six amendments that I discussed yesterday only four were included for possible consideration on the floor. Those four are:

4. Franks (R,AZ) #93 (LATE) (REVISED) Secures the most critical components of America's electrical infrastructure against the threat posed by a potentially catastrophic electromagnetic pulse.
9. Jackson-Lee (D,TX) #84 (LATE) Directs the Secretary of Energy to submit to the Committees on Energy and Commerce and Natural Resources of the House of Representatives and the Committee on Energy and Natural Resources of the Senate a report on methods to increase electric grid (10 minutes) resilience with respect to all threats, including cyber attacks, vandalism, terrorism, and severe weather, no later than 120 days after the date of enactment of the Act.
32. DeSaulnier (D,CA), Lowey (D,NY), Garamendi (D,CA) #34 Requires the Department of Energy to study the maximum level of volatility that is consistent with the safest practicable shipment of crude oil.
38. Norcross (D,NJ) #19 (REVISED) Directs the Secretary of Energy to study weaknesses in the security architecture of certain smart meters currently available.

The revision to the Franks amendment added an exemption from the requirements of the amendment for the Tennessee Valley Authority and the Bonneville Power Administration.  The revision to the Norcross amendment adds a requirement for the Secretary to ‘promulgate rules’ to correct the weaknesses discovered in the required study.

Moving Forward

The amendment process will probably start tomorrow. With only 10 minutes of ‘debate’ on each amendment it should go pretty quickly. I expect that there will be a final vote on the bill tomorrow. While the bill will almost certainly pass, the question will be how many Democrats vote for the bill. With the President promising a veto of the bill the Republicans need a total of 290 votes to override aveto.

Tuesday, November 3, 2015

STA Amendments to the House Floor

This afternoon the House Rules Committee met to determine which of the amendments proposed for HR 22 would be allowed to be offered on the floor of the House tomorrow. As I added to yesterday’s post there were a total of 29 amendments added to the rule for the consideration of HR 22.

Of the seven amendments that I described in yesterday’s post as being of specific interest to readers of this blog, only seven were include on the list of 29 amendments that may be offered on the floor. They are:

21. Jackson Lee (TX): Provides a report on the Internet of Things (IoT) and its potential to improve transportation services to the elderly and persons with disabilities as well as assist local, state and federal transportation planners in achieving better inefficiencies and cost effectiveness, while protecting privacy and security of persons who use IoT technology.

28. Barletta (PA), Lipinski (IL): Requires all legacy tank cars retrofit for continued Class 3 Flammable Liquid service to include enhanced top fittings protections for pressure relief valves.

29. Lynch (MA): Provides for an additional, independent safety review of an approved pipeline route or segment of route, should a state or tribal government deem it necessary.


I expect that all three of these amendments will pass.

Thursday, August 6, 2015

Amendments to S 754 – 08-05-15

Yesterday there were 23 additional amendments submitted in the Senate for S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015. Only three of those proposed amendments may be of specific interest to readers of this blog.

SA 2623. Ms. Collins, pgs S6411;
SA 2626. Mr. Whitehouse, pgs S6415-6; and
SA 2628. Mr. Wyden, pg S6419

The Amendments

The Collins amendment would require the owners of ‘critical cyber infrastructure’ to report to the DHS Secretary or appropriate agency head “if an information system of a covered entity that is essential to the operation of critical cyber infrastructure is successfully intruded upon” {new §lll(b)(1)}; note that there is no definition of ‘successfully intruded upon’ provided. The report would include {new §lll(b)(2)}:

A description of the technique or method used in such intrusion;
A sample of the malicious software, if discovered and isolated by the covered entity, involved in such intrusion;
Damage assessment; and
Such other matters as the Secretary or the appropriate agency head, as the case may be, consider appropriate.

The Whitehouse amendment would add a new section to the US criminal code; 18 USC 1030A. This new section would make it a federal crime “during and in relation to a felony violation of section 1030, to knowingly cause or attempt to cause damage to a critical infrastructure computer” {new §1030A(a)}. Unfortunately, because of the definition of ‘protected computer’ in §1030(e)(2) only attacks on financial institutions or communications companies would give rise to the underlying felony that is a required part of this new definition. I do not think that that was the intent.

The Wyden amendment would require the Secretary of Commerce to reconsider the rulemaking concerning the implementation of the Wassenaar Arrangement 2013 Plenary Agreements Implementation: Intrusion and Surveillance Items. The reconsideration would include drafting a supplemental of proposed rulemaking that is written in consultation with “civil society organizations, including privacy advocates, public and private sector technologists, security researchers, and public and private sector software developers” {new §ll(b)(1)}. The new proposed rule would be required to be:

Limited to the scope of the agreements reached at the plenary meeting of the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies in December 2013;
Consistent with the regulation of cybersecurity items by other countries participating in the Wassenaar Arrangement, as appropriate; and
Exclude cybersecurity items available for mass-market purchase from regulation under the proposed rule

Agreement to Consider the Bill

A unanimous consent agreement was reached yesterday to allow for the Senate to move forward with the consideration of the bill without having to go through a cloture procedure. That agreement calls for the consideration of 21 specific amendments; ten from the Republicans and eleven from the Democrats. There is a possibility that other amendments may be subsequently considered.


Of the seven amendments that I discussed here yesterday and today only one is on either list; Whitehouse 2626. Most of the remaining ones that I discussed were excluded from consideration because they did not directly deal with cybersecurity information sharing.

Wednesday, August 5, 2015

Amendments to S 754 – 08-04-15

While the Senate is trying to get S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015, to a floor vote before leaving on their summer recess at the end of the week, a number of amendments are being submitted that may or may not be considered before the final floor vote. Yesterday, for instance there were 65 such amendments submitted. Of those amendments only four may be of specific interest to readers of this blog:

SA 2573. Mr. Flake (R,AZ), pgs S6306-07;
SA 2576. Mr. Markey (D,MA), pgs S6309-10;
SA 2608. Ms. Warren (D,MA), pg S6321; and
SA 2609. Ms. Warren, pg S6321

The Flake amendment deals with electric grid cybersecurity issues and is a virtual copy of HR 2271 which has yet to be acted upon in the House. Similarly the Markey amendment is a copy of S 1806; his bill on automotive cybersecurity issues.

The two amendments by Warren both deal with liability issues. The first ensures that the provisions of §6 (Protection from Liability) of the bill are not misconstrued to apply to organizations that do not take actions to “action to address a cybersecurity threat or a security vulnerability”. Similarly SA 2609 adds a new paragraph to §6 that specifically requires an entity that receives information “regarding a cybersecurity threat or a security vulnerability under this Act” to take actions to “to address the threat or vulnerability” or be liable.


As of this morning’s publication of yesterday’s Congressional Record there was no agreement in place as to what amendments would or would not be taken up prior to the final vote on S 754.

Friday, April 19, 2013

More on Amendments to HR 624


Yesterday I noted that there had been a modification made to the amendment offered by Rep. Sanchez (D,CA), but from the information available at the time it was not clear what that amendment was. The Congressional Record for yesterday provides the expected details:

Insert ‘‘Security’’ after ‘‘Homeland’’ in the second instruction.

Two pages earlier in the Congressional Record (same link as above) there is also a notice that a 13th Amendment had been added to the Rule for the consideration of HR 624. This new amendment, submitted by Chairman McCaul (Homeland Security) would make DHS and the Justice Department the action agencies for receiving shared information by amending §1104(b)(1)(A)(ii) and §1104(b)(1)(A)(ii) by replacing the words “Federal Government” with “entities of the Department of Homeland Security and the Department of Justice designated under paragraphs (1) and (2) of section 2(b) of the Cyber Intelligence Sharing and Protection Act”. This amendment also passed in a voice vote of 409 – 5.

This last change was made to mollify some of the critics of the bill that were afraid that NSA and the military would become the action agencies for receiving this information. It is not clear at this point if this change would overcome President Obama’s intention to veto the bill.

The bill will now move to the Senate where, if it is actually brought to the floor of the Senate by Sen. Reid (D,NV), there is a good chance that a similar bipartisan vote would send the bill to the President.

Tuesday, November 3, 2009

HR 2868 Amendments

The Rules Committee has posted a summary of the 20 amendments that it had received by yesterday’s deadline for their consideration in formulating the rule that will be used to consider HR 2868 on the floor of the House later this week. The actual amendments are not currently available, so I can’t go into any great detail on their provisions, but I will take a general look at what is available and make my predictions on what would happen if they make it to the floor discussion. Doomed Amendments There are a number of amendments that have been proposed by Republican members of either the Energy and Commerce Committee or Homeland Security Committee that are almost certainly pro-forma amendments that are doomed to failure before they are even debated. Most of these were already voted down on a party line vote in committee. I’ll put these into three groups; anti-IST, anti-citizen enforcement or pro-CFATS Extension. There are a number of amendments that fall into the anti-IST category in that they would void or greatly restrict the provisions of §2111. These include: Austria (R, OH) #6, Barton (R, TX) #14, #16, #18, #20, Dent (R, PA) #5, and Upton (R, MI) #17. I would expect that two or maybe three of these would get to the floor for consideration. There are two anti-citizen enforcement provisions; McCaul (R, TX) #1, and Upton (R, MI) #15. One of these should make it to a floor vote. Then there are two amendments that would strike Title I of the bill and simply extend the current CFATS authorization; Dent (R, PA) #4, and Olson(X, TX) #9. Depending on the wording of the actual length of the extension, both bills might make it to a floor vote. Possible to Pass Once again, I am only able to see summaries, so I can only make a semi-educated guess as to which of the remaining amendments have a chance to pass a floor vote. This will be almost as accurate as a football bowl pool list; you don’t go for absolute accuracy, just play the percentages. The only Republican amendment left on the list is amendment #3 submitted by Rep. Flake (R, AZ). He has been a single minded crusader against earmarks this year and his amendment reflects that; it would prohibit earmarks of DHS grants established under this legislation. Since there are no earmarks in the current bill, it might pass. A shoe-in for passage on the floor is the amendment submitted by Chairman Thompson. This will make “a number of technical corrections and fixes typos and verbiage issues”. These almost always pass. The next best chance for floor passage is amendment #10 from Rep Hastings (D, FL). It would establish the position of Deputy Director of the Office of Chemical Facility Security responsible for interagency coordination and liaising with State and local government officials. Not only is this probably necessary, but it is added bureaucracy, always a good bet in legislation. Another good bet for passage is a GAO report required by amendment #8 submitted by Rep Titus (D, NV). This would require GAO to “determine best practices for transporting the chemicals that are used and produced at the facilities covered by the underlying legislation”. While this may sound like a straight hazmat transportation issue it may be an effort by the American Railroad Association to get the government to side with it its arguments with shipper reference hazmat liability issues. If the later is the case, the chances of passage go down significantly. There are two IST amendments that have a chance of passing. The first is from Rep Schrader (D, OR) and Kissell (D, NC) that would require DHS to report on the potential impacts of the IST provisions on ‘manufacturers or retailers of pesticide or fertilizer’. Studies only require time and effort on the part of DHS so this will probably pass. Rep. Cardoza’s (D, CA) amendment would require the Administrator to choose between the lower cost IST alternatives. This may not pass because it apparently ignores the fact that the Administrator will seldom make this decision, State officials will. Members may not see that distinction though so it still may pass. I know, I’m waffling. Amendment #2, submitted by Rep Halvorson (D, IL) was almost a waste of time to submit. According to the summary it would “permit [emphasis added] the Secretary to provide guidance, tools, methodologies, or software to assist small covered chemical facilities in complying with the security requirements”. Permit, but not require; it can’t hurt anyone so it should pass. Rep Marshall (D, GA) submitted amendment #7 that would “provide for the use of E-Verify as an additional measure designed to verify and validate legal authorization to work in the U.S.” as part of the background check provisions of §2115. This should pass because no one wants illegal to take good paying jobs that might be security related positions. Deserves to Fail The only remaining amendment listed on the Rules Committee web page is one that deserves to fail in my opinion. It is amendment #8 by Rep Foster (D, IL) and Lujan (D, NM) that gives special treatment to university and academic labs. It would require the Secretary to develop “appropriate protocols and security procedures” for these facilities if they were determined to be high-risk facilities. It is interesting that just before I read these summaries of amendments I had an exchange of emails with a PHD chemist who was concerned about a letter he had received from the American Chemical Society that included a brief letter that they wanted him to send to his representative about the upcoming consideration for HR 2868. He sent it to me because he objected to the following passage about academic labs:
“The Chemical Facility Anti-Terrorism Act of 2009 (H.R. 2868) is expected to direct the Department of Homeland Security (DHS) to design separate regulations for academic laboratories. As member of the American Chemical Society, I strongly support this regulatory distinction. Laboratories operate much differently than manufacturing sites. They often use more kinds of chemicals, but at much smaller amounts, on different timescales, and in experiments and processes that are frequently modified. This measure reduces the possibility that academic labs, a wellspring of our nation's scientific and technological innovation, would be forced to grapple with rules intended for industrial-scale facilities.”
He objected because he knows from personal experience that many (more probably most) academic labs suffer a severe blind spot when it comes to both safety and security. Now I have only been in one University chemistry lab (where I got my BS degree), but this reader confirms what I have heard from a number of graduates from a number of different universities, that university people dislike the inconvenience of security measures. They get in the way. The problem is that beyond the Top Screen, only facilities with significant amounts of dangerous chemicals are covered by the CFATS regulations. If a facility is determined to be a covered facility it needs to have rigorous security measures in place. It doesn’t matter if it is a university lab or chemical manufacturing facility, or a water treatment facility. If the risk is there the security measures need to be there. This is just one more instance of another group thinking that their place in life or society is more important than everyone else’s. They are demanding special attention because they are special. If they put our safety at risk, it is just too bad. It just gets in their way to try to establish minimal levels of security. This demand for special attention deserves the same treatment as all other such requests; a quick and firm denial. Moving Forward The Rules Committee will meet this afternoon and decide which of these amendments will make it to the floor. They will then craft a resolution explaining how the debate will be conducted. That resolution will not be printed at the GPO until tomorrow afternoon at the earliest. Fortunately the Rules Committee realizes this and will post a copy on their web site this evening. When that happens I will prepare a brief post outlining the rule. Then we wait and see when the matter actually comes to the floor. I keep hearing Wednesday, but that never comes directly from anyone in the Democratic House Leadership, so we don’t know for sure yet. Maybe we will hear something today.
 
/* Use this with templates/template-twocol.html */