Showing posts with label Committee Report. Show all posts
Showing posts with label Committee Report. Show all posts

Friday, March 30, 2018

HR 5074 Reported in House – Cyber Response Teams


Earlier this month the House Homeland Security Committee published their report on HR 5074, the DHS Cyber Incident Response Teams Act of 2018. The bill was passed in the House on March 19th. The date on the report is also the 19th, but the report was not actually published by the GPO until well after the debate and vote in the House.

Authorizing Existing Programs


The report makes it clear that the ‘cyber hunt and incident response teams’ authorized by the bill are, in fact, the activities currently being undertaken by the US-CERT and the National Cybersecurity and Communications Integration Center’s (NCCIC’s) Hunt and Incident Response Teams (HIRT). This is the reason that the bill specifies {§2(b)} that no additional funding is authorized; the funding for these activities is already included in the line items for NCCIC spending.

The provisions of the new 6 USC 148(f)(2) authorizing the use of “cybersecurity specialists from the private sector” on the existing US-CERT and HIRT teams is, however, a potential expansion of the capabilities of those teams. The Report states that allowing the participation of these outside experts would (pg 2) “allow industry professionals to bring innovative approaches and ideas into the federal government and makes progress in bringing the technical expertise and skills that help execute the DHS role in cybersecurity”.

Commentary


Neither the report nor the bill mentions any of the response activities of the DHS Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) which also operates as part of the NCCIC and was formerly part of the US-CERT (Actually, the current relationship between the ICS-CERT and the current US-CERT is not actually very clear.) Presumably, since the bill would add the term ‘control systems’ (even though undefined) to §148 {via (f)(1)(D)} the response activities of ICS-CERT, especially their away teams, would fall broadly under the authorization provided in this bill.

Unfortunately, the failure to define the term ‘control system’ or modify the definition of ‘information system’ in §148(a)(5) to specifically include control systems means that this bill would do nothing to actually codify the importance of control system security in NCCIC activities or oversight. This is unlikely to change if/when this bill is considered in the Senate.

Sunday, May 8, 2016

HR 4909 Reported in the House – NDAA

Yesterday the House Armed Services Committee published their report on HR 4909. While the original bill did not contain any specific cybersecurity language, the bill revised in numerous subcommittee and Committee hearings did add a number of cybersecurity related provisions and the Committee Report adds additional cybersecurity discussions and requirements.

Added Cybersecurity Provisions


A number of new cybersecurity provisions were added to this bill. They include:

Sec. 231. Strategy for assured access to trusted microelectronics
Sec. 232. Pilot program on evaluation of commercial information technology.
Sec. 911. Establishment of unified combatant command for cyber operations.
Sec. 1631. Special emergency procurement authority to facilitate the defense against or recovery from a cyber-attack.
Sec. 1632. Change in name of National Defense University’s Information Resources Management College to College of Information and Cyberspace.
Sec. 1633. Requirement to enter into agreements relating to use of cyber opposition forces.
Sec. 1634. Limitation on availability of funds for cryptographic systems and key management infrastructure.

None of these cybersecurity requirements is going to have a significant direct impact on civilian cybersecurity activities and none of them directly address control system security issues. The only one that comes close is §231, which continues and expands the DOD reporting requirements on the issue of supply chain security for microelectronics. This will only directly affect DOD contractors, but ultimately could have an effect on the whole supply chain security environment down the road.

Section 231 would require DOD, after conducting studies and issuing reports to Congress, to issue a directive by September 30th, 2020 that would describe how DOD entities would “access assured and trusted microelectronics supply chains for Department of Defense systems” {§231(d)}. The key word here is ‘trusted’ which is defined as “the ability of the Department of Defense to have confidence that the microelectronics function as intended and are free of exploitable vulnerabilities, either intentionally or unintentionally designed or inserted as part of the system at any time during its life cycle” {§231(f)}.

Discussions in the Report


As we see with any authorization or spending bill report, there are a number of discussions in the report where the Committee provides additional guidance and directives to the Department of Defense. The discussion that may be of interest to readers of this blog include:

• Cellular and broadband signals exploitation (pg 79);
• Counter-unmanned aerial systems roadmap (pg 80):
• Non-destructive counterfeit parts detection tools (pg 89);
• Social media analysis cell (pg 91);
• National Guard Cyber Protection Teams (pg 135):
• Cyber Science Education at the Service Academies (pg 147);
• Wassenaar Arrangement Impacts to the Department of Defense (pg 221); and
• Facility Industrial Control Systems (pg 374)

The Committee encourages SOCOM to continue their efforts to “efforts to utilize commercial technology to conduct cellular and broadband survey, active interrogation, and directional finding capabilities from unmanned aerial systems”. While this technology certainly has ongoing military application in counter-terrorism operations, the potential use of the same technology in civilian law enforcement operations raises all sorts of interesting controversies.

The threat to forces from adversaries employing small unmanned aerial systems continues to grow. While the Army is conducting some anti-UAS research, the Committee is directing “the
Secretary of Defense to develop a technology roadmap for addressing gaps to counter the potential threats from terrorist or state actor uses of small UAS technology, with an emphasis on technology to support tactical level units, and fixed, high-value defense assets”. The value of such technology to protect critical infrastructure facilities in the homeland should also be studied.

The concern with counterfeit parts is apparently high on the Committee’s task list. They have encouraged the Department to “evaluate the need to identify or develop best-of-breed, non-destructive counterfeit parts detection tools that it can use, or that could be made available to defense industrial base suppliers, to support the overall mission of ensuring the integrity of electronic components of defense weapon systems”. Again, this type technology would have widespread applications throughout the electronics sector.

The Committee has increased the budget of the Joint Concept Technology Demonstration program by $10 Million to look into the “application of new technologies or concepts in this space, especially in the use of ever-increasing data from social media sources that can be leveraged to amplify and inform other warning, force protection and battlespace awareness activities of the Department of Defense”. Again, a potentially valuable military tool with uncomfortable applications in the civilian sector.

The brief discussion of the National Guard cyber protection teams (CPT) looks at funding issues and questions why the Army teams have not been integrated into the Cyber Command operational planning. They direct the DOD to provide additional information in the FY 2018 funding request.

In a very short discussion about cybersecurity training the Committee concludes by encouraging
“the Department to recognize the importance of cyber education within each of the U.S. military service academies and actively promote cyber sciences education and training within the service’s respective curriculum”.

Another Wassenaar report and briefing; the Committee “believes restricting export of these technologies may negatively impact use of such products for national security purposes”.

Military Industrial Control Systems


For the first time that I can remember, this Committee Report specifically address the security of industrial control systems in the military realm. It is a rather limited look, to be sure, in that it only addresses “industrial control systems integrated into systems and equipment such as air conditioners, utility meters, and other programmable controllers”.

The report applauds current efforts “to implement and promote secure procedures, adopt best government practices, and revise Department of Defense Unified Facility Criteria and Unified Facility Guide Specifications to address the cybersecurity vulnerabilities of industrial control systems”. The Committee would like to see these efforts expanded; encouraging “the Department’s cybersecurity community to look more closely at these classes of vulnerabilities and how to modify tactics, techniques, and procedures to better position the cyber mission forces to deal with new and emerging threats proactively”.

Moving Forward



This is one of those ‘must pass’ bills that needs to be passed every year. It is likely that this bill will be considered by the House in a full-blown debate and amend process later this month. The Senate will take up their own version of the bill (not yet introduced) and a conference committee will meet to iron out the differences. If past years are any indicator, final consideration of the bill will not take place until after the election in November.

Monday, June 29, 2015

S 1180 Reported in Senate – IPAWS Modernization Act

Last week the Senate Homeland Security and Governmental Affairs Committee published their report on S 1180, the Integrated Public Alert and Warning System (IPAWS) Modernization Act. The report contains some interesting supporting information from the Congressional Budget Office (CBO) as well as some background material on the existing IPAWS program.

Background

The existing IPAWS system which this bill is trying to codify and update was initiated in response to the 2006 EO 13407 signed by President Bush. The Report identifies two GAO reports (GAO-09-834 and GAO-13-375) that identified some of the problems that this bill attempts to resolve. The Committee Report does explain that improvements have been made at FEMA in response to those reports, but notes:

“This legislation will further this progress and help address many of the other problems stakeholders, Congress, and GAO previously identified, including helping to ensure sufficient training for emergency alerting officials, increasing collaboration at all levels of government, and ensuring Congress’s important role of oversight.”

CBO Information

The CBO is required to evaluate the costs of proposed legislation. For this bill they expect that the costs of the IPAWS upgrades would increase the funding needs over the next three years from the current spending level of $12 Million to $13 Million per year.

The CBO letter report explains that many of the requirement of this bill are currently being pursued by FEMA, but there are some new requirements for the system. Those new requirements include (pg 6):

Training state and local governments and other stakeholders to use the system;
Conducting nationwide testing of the system every three years: and
Ensuring that IPAWS can withstand terrorist attacks.

Moving Forward

This bill was introduced by Sen. Johnson (R,WI) the Chair of the HSGAC. He has moved it expeditiously through his committee and I expect that it will make it to the floor, perhaps before the summer recess. It will almost certainly be passed under the unanimous consent provisions.


Two similar bills in the House, HR 1472 and HR 1738, are still pending publication of their respective Committee Reports. There is still the jurisdictional controversy that will have to be resolved by the House leadership before one of these bills makes it to the floor in the House. S 1180 would tend to support the House Homeland Security Committee’s claim to jurisdiction over the IPAWS oversight.

Saturday, March 29, 2014

HR 4005 Reported in House – CG Authorization

Earlier this week the House Transportation and Infrastructure Committee published their report on HR 4005, Coast Guard and Maritime Transportation Act of 2014.

Chemical Safety and Security

The Committee did not make any changes to the bill during its markup that had anything to do with chemical safety or the Coast Guard’s Maritime Transportation Safety Act (MTSA) during the markup of this bill last month.  

The only provision in the bill dealing, even tangentially, chemical safety and security is §202. This section deals with the Prevention and Response Workforce, the Coast Guard’s safety and security specialists, both enlisted and officer. The Committee Report describes this section this way:

“This section ensures servicemembers assigned to certain prevention and response jobs have opportunity for career advancement.”

Moving Forward

According to the Majority Leader’s web site HR 4005 will come to the House floor on Tuesday, April 1st. It will be considered under suspension of the rules, so no amendments will be considered. The House leadership certainly expects this bill to pass with wide bipartisan support.


Since there is no Senate version of this bill, it will likely be considered in the Senate before the summer recess. It is remotely possible that there will be no Senate amendments.

Tuesday, September 20, 2011

HR 908 Report Published

While yesterday was a pro forma session for the House it did allow for some housekeeping measures to be completed. One of those was the publication of the Energy and Commerce Committee Report on HR 908, the Full Implementation of the Chemical Facility Anti-Terrorism Standards Act, House Report 112-211.

Minority Views


There is very little new information in this report, as one would expect from a document that is supposed to reflect committee action on the bill in question. Probably the most interesting portion of the report is the ‘Minority Views’ portion at the end of the report. Surprisingly there is no mention of the topic of mandating inherently safer technology or even encouraging the replacement of dangerous chemicals with safer alternatives at high risk chemical facilities.

This section of the report does address the concern about the exemption of a number of classes of facilities from coverage under the CFATS regulations continued in this revision. The most obvious case of water treatment facilities is mentioned by not as in as much detail as the minority staff discussion of the exemption for NRC covered facilities or even federally owned facilities.

Another complaint that is addressed publicly for the first time in this report is the concern that the §550 authorization allows the Secretary to approve site security plans that do not meet the standards set forth in the Risk-Based Performance Standards published by the Department. This is based on the permissive language that states that the Secretary “may disapprove” instead of directed language like “will disapprove”.

The remainder of the minority concerns covered in this section are fairly standard objections that the Democrats have had with the existing program. They include worker protections against discrimination in the application of the background checks, whistleblower protections, concerns about the sharing of security information with the public and concerns about the lack of public and worker participation in security planning.

All in all the “Minority Views” section is well worth reading in this report, especially among the supporters of the current program. Addressing some of these concerns might make it easier to pass this legislation in both the House and Senate.

Wednesday, June 29, 2011

Committee Report on S 1253 – Cyber Security Matters

As I mentioned in yesterday’s blog on S 1253 I expected to find additional information on military cyber security matters in the Senate Armed Services Committee report on S 1253 (Sen Rept 112-26) and I wasn’t disappointed when I reviewed the 343 page document. I only found one new item (a discussion of USB security devices) but there are some interesting additional details about the subjects that I discussed in yesterday’s blog.

Previous Topics

For those readers who are specifically interested in any one of the particular topics that I covered yesterday here is a list of the topics and respective pages for the additional coverage (Note when using Adobe Reader® you have to add ‘22’ to the page number to get to the appropriate page, the Committee Report does not start arabic page numbering until after the table contents, a confusing, out-dated practice).

• GPS Interference – Pg 161

• Detecting Cyber Attacks – Pg 165-9

• WIKI Leaks Prevention – Pg 169

• Cyberspace Experts – Pg 184
The lengthy discussion on detecting cyber attacks based upon previously unidentified vulnerabilities is well worth the read. Of particular interest is the sanitized discussion of the capabilities of NSA to detect attacks based upon zero-day exploits (pgs 165-6). It would seem to me that a complimentary technique would be for NSA and other appropriate agencies (CERT and ICS-CERT for example) to conduct programs to actively look for vulnerabilities in critical software packages or systems.

USB Device Security

The Committee recommends a $3.0 million increase in the budget authorization for the Department’s Information Systems Security Program. This would be used to fund an, as of yet to be determined, additional number of File Sanitization Tools (FiST; don’t you love DOD acronyms?). These devices were developed by NSA ‘to check and cleanse the content of thumb drives’. These devices were initially developed when “military networks, including classified networks, were infected with a propagating virus that was initially introduced via USB flash drive or ‘thumb drive’ removable media devices” (pg 81) several years ago.

Interestingly it took the predecessor to the Cyber Command 16 months to require the use of such devices after NSA developed them within months of receiving the tasking. DOD initially determined that they would need 700 such devices, but to date (apparently two years after their development) only 57 have actually been purchased and deployed.

The Report notes that other mitigation efforts (including limiting the computers that can accept/use a USB memory device) have been put into place, but the Committee expresses some concern that this relatively inexpensive device (well relatively inexpensive for really sensitive computers) isn’t more widely used. DOD is in the process of determining how many additional units are actually needed, so the $3 million is based upon the Committee’s best guess of the cost.
 
/* Use this with templates/template-twocol.html */