Showing posts with label Auto Cybersecurity. Show all posts
Showing posts with label Auto Cybersecurity. Show all posts

Friday, January 5, 2024

Review - NHTSA Publishes Impaired Driving Prevention Technology ANPRM

Today, DOT’s National Highway Transportation Safety Administration (NHTSA) published an advanced notice of proposed rulemaking (ANPRM) for “Advanced Impaired Driving Prevention Technology” in the Federal Register (89 FR 830-857). NHTSA is considering a rulemaking that would gather the information necessary to develop performance requirements and require that new passenger motor vehicles be equipped with advanced drunk and impaired driving prevention technology through a new Federal Motor Vehicle Safety Standard (FMVSS). This rulemaking is required by §24220(c) of the Infrastructure Investment and Jobs Act (PL 117-58, 135 STAT. 832).

NHTSA is seeking information about such technologies that may currently be available or are under development. The series of questions posed by this ANPRM include specific questions dealing with cybersecurity requirements and tools that may be required by the rulemaking.

Public Comments

NHTSA is soliciting public comments on the ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2022-0079). Comments should be submitted by March 5th, 2024.

Commentary

NHTSA is late with this ANPRM. Section 24220 requires this rulemaking to be completed by November 15th, 2024; NHTSA will be hard pressed to develop a new safety standard by that time. While Congress did give NHTSA an out for delaying the final rule {§24220(e)}, I am fairly certain that those processes were designed to deal with delays in technology development. With the publication of this ANPRM, NHTSA is just now publicly looking for information about the state of the technology. The federal government is becoming increasingly inefficient, in Congress because of political issues and in the executive branch due to underfunding and understaffing (which appear to be the result of congressional inefficiencies).

 

For more information about this rulemaking, including a list of the cybersecurity questions that NHTSA wants answered, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nhtsa-publishes-impaired-driving - subscription required.

Friday, November 6, 2015

Bills Introduced – 11-5-15

Yesterday there were 95 bills introduced in the House and the Senate as the House prepared to depart for their Veterans Day Recess. Of the bills introduced only three may be of specific interest to readers of this blog:

HR 3994 To direct the Administrator of the National Highway Traffic Safety Administration to conduct a study to determine appropriate cybersecurity standards for motor vehicles, and for other purposes. Rep. Wilson, Joe [R-SC-2]

H Con Res 92 Providing for a conditional adjournment of the House of Representatives and a conditional recess or adjournment of the Senate. Rep. Woodall, Rob [R-GA-7]

S 2249 A bill to amend title 18, United States Code, to impose criminal penalties for the unsafe operation of unmanned aircraft. Sen. Whitehouse, Sheldon [D-RI] 

HR 3994 will almost certainly include a report to Congress that might actually get used to craft appropriate legislation.

S 2249 the focus in the title on ‘unsafe operation’ sounds interesting, but is certainly prone to causing unintended consequences.


The adjournment resolution sends the House home yesterday for their Veterans Day Recess (excuse me ‘district work session’). The Senate will return to Washington on Monday and probably Tuesday before they start their recess. Both houses of Congress will be back in Washington on Monday, November 16th.

Monday, October 19, 2015

Committee Hearings – Week of 10-19-15

Both the House and Senate are back in Washington this week after their Columbus Day Recess (excuse me; ‘district work session’). There are three hearings currently scheduled that may be of specific interest to readers of this blog; two cybersecurity related hearings and one terror threat briefing.

Cybersecurity

The Commerce, Manufacturing and Trade Subcommittee of the House Energy and Commerce Committee will be holding a hearing on Wednesday looking at “Examining Ways to Improve Vehicle and Roadway Safety”. The discussions will be centered on a committee draft of new automotive safety legislation that includes a title specifically addressing cybersecurity issues.

The witness list includes:

• Mitch Bainwol, Alliance of Automobile Manufacturers
• John Bozzella, Global Automakers
• Joan Claybrook, Former Administrator, NHTSA
• Greg Dotson, Center for American Progress
• Maneesha Mithal, Federal Trade Commission
• Mark Rosekind, Administrator, NHTSA
• Peter Welch, Automobile Dealers Association
• Ann Wilson, Motor & Equipment Manufacturers Association

I don’t typically review legislation before it is introduced, but I’ll give a brief overview of the cybersecurity provisions of this bill. Title III of the bill is called “Privacy, Hacking Prohibition, and Cyber Security”. Section 301 establishes privacy rules for information collected by privately owned motor vehicles. Section 302 prohibits hacking (access without authorization) “an electronic control unit or critical system of a motor vehicle, or other system containing driving data for such motor vehicle, either wirelessly or through a wired connection”. And §303 establishes the Automotive Cybersecurity Advisory Council that does not include anyone from ICS-CERT (or DHS in general) or security researchers.

Please note that none of the witnesses has any cybersecurity background so it is unlikely that we will hear anything of real substance about cybersecurity at this hearing; other than, of course, please leave our systems alone.

The other cybersecurity related hearing is before the Energy Subcommittee of the House Science, Space and Technology Committee on Wednesday. That hearing will address “Cybersecurity for Power Systems”.

The witness list includes:

• Bennett Gaines, CIO, FirstEnergy Service Company
• Annabelle Lee, Electric Power Research Institute
• Brent Stacey, Idaho National Lab
• Greg Wilshusen, Government Accountability Office

There is a better chance of a technical discussion at this hearing.

Terror Threat

The House Homeland Security Committee will be holding a hearing looking at “Worldwide Threats and Homeland Security Challenges” on Wednesday.

The witness list includes:

• James B. Comey, Director FBI;
• Jeh C. Johnson, Secretary DHS;
• Nicholas J. Rasmussen, Director, National Counterterrorism Center

No actionable intelligence, of course; just an overview of the cruddy state of the world.

On the Floor


There is one bill that is scheduled to come to the floor of the House this week that may be of specific interest to readers of this blog; HR 3350, the Know the CBRN Terrorism Threats to Transportation Act. It will be considered on Tuesday under suspension of the rules. Again, this means limited debate and no floor amendments. It also means that it is likely to pass with bipartisan support. It passed in the Homeland Security Committee on a voice vote without amendments.
 
/* Use this with templates/template-twocol.html */