Showing posts with label Critical Infrastructure Security. Show all posts
Showing posts with label Critical Infrastructure Security. Show all posts

Friday, May 13, 2016

DHS Announces PCII Listening Sessions

Today the Department of Homeland Security published a meeting notice in the Federal Register (81 FR 29799-29800) for a series of public listening sessions looking for input on their recent advance notice of proposed rulemaking (ANPRM) for updating the Protected Critical Infrastructure Information (PCII) program. The three listening sessions will be held in Arlington, VA. The dates will be May 12th, May 17th, and May 19th.

The Information Sought


DHS is specifically looking for information on (note this is a slightly different list that proposed in ANPRM):

• Automated submissions and an expansion of categorical inclusions;
• Marking PCII;
• Sharing PCII with foreign governments;
• Regulatory access;
• Safeguarding;
• Oversight and compliance;
• Alignment with other information protection programs; and
• The administration of PCII at the State, local, tribal, and territorial level

Public Comments


With five hours on each day available for public oral comments there should be plenty of time for everyone to get their say. Written comments may also be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2016-0032). Yes, this notice did include the docket # and it is the same as I provided in an earlier blog post. The deadline for written comments is still July 20th, 2016.

Commentary


I’m not sure why this notice was delayed in publication, but it certainly makes someone look silly for announcing a meeting for a date that has already passed. The remaining two dates are also fairly short notice, but then again I don’t suspect that DHS really expects anyone to make travel plans to attend these three sessions. These dates are almost certainly targeted at organizations with physical (or at least a lobbyist) presence in the Washington area.

I will be extremely disappointed if there are not more listening date announcements associated with this ANPRM and even more disappointed if they are not scattered across the country.

Sunday, August 11, 2013

HR 2952 Introduced – Critical Infrastructure Protection Technology

As I noted earlier Rep Meehan (R,PA) introduced HR 2952, the Critical Infrastructure Research and Development Advancement (CIRDA) Act of 2013. The bill would modify the Homeland Security Act of 2002 to establish programs within the Science and Technology (S&T) Directorate of the Department of Homeland Security to encourage the development of technologies for the protection of critical infrastructure.

Developing a Strategic Plan

Section 3 of the bill would add §318 to 6 USC Subchapter III (actually the section number would probably end up being §196 because of the silly way that Congress writes laws and then converts them to US Code) that would require the Under Secretary of Science and Technology to develop and transmit to Congress a “a strategic plan to guide the overall direction of Federal physical security and cybersecurity technology research and development efforts for protecting critical infrastructure” {§318(a)}.

That plan would include identifying:

• Critical infrastructure security risks and the associated security technology gaps {§318(b)(1)};
• A set of critical infrastructure security technology needs {§318(b)(2)};
• Laboratories, facilities, modeling, and simulation capabilities that will be required to support the research, development, demonstration, testing, evaluation, and acquisition of the security technologies {§318(b)(3)}; and
• Current and planned programmatic initiatives for fostering the rapid advancement and deployment of security technologies for critical infrastructure protection {§318(b)(4)}.

Public-Private R&D Consortiums

Section 319 would also be added, requiring a separate study by the Under Secretary. This one would address the use of “public-private research and development consortiums for accelerating technology development for critical infrastructure protection” {§319(a)}. The study would focus on privately owned critical infrastructure that would most benefit from the rapid advancement of security technology.

The study would include:

• A summary of the progress and accomplishments of on-going consortiums for critical infrastructure security technologies {§319(b)(1)};
• A prioritized list of technology development focus areas that would most benefit from a public-private research and development consortium {§319(b)(1)}; and
• A proposal for implementing an expanded research and development consortium program, including an assessment of feasibility and an estimate of cost, schedule, and milestones {§319(b)(1)}.

No Funding

As with most pieces of legislation that require the production of studies and reports to Congress, this bill does not provide any funding to DHS S&T to carry out any of this work. In fact, this bill goes the normal bill one better; §4 specifically states that no “additional funds are authorized to be appropriated to carry out this Act and the amendments made by this Act, and this Act and such amendments shall be carried out using amounts otherwise available for such purpose”.

Moving Forward

As with most study bills whether or not this bill moves through the legislative process will depend almost solely on how much pull the author can bring to bear to convince the leadership to move the bill along. It is non-controversial and something that really can’t be argued against since no money is being spent.

In any markup before the House Homeland Security Committee there will be bipartisan support for the bill after language is added to ensure that historically black colleges and universities as well as other minority institutions are included in any proposed research consortiums. I’m not sure why Republican authors of these types of bills don’t just automatically add such language (the Democrats always do) since they will support (or at least acquiesce to) such amendments when offered.

If this bill gets out of Committee it will be one of those bills that (if brought to the floor) will be considered under suspension of the rules and adopted by a bipartisan vote with minimal debate. It would then be passed in the Senate (if it sufficiently attracts the attention of the leadership) by unanimous consent with no debate.

Saturday, November 17, 2012

Another DHS-NPPD PCII Questionnaire ICR


On Friday the National Protection and Programs Directorate (NPPD) at DHS published a 60-day information collection request (ICR) notice in the Federal Register (77 FR 68795-68796) that would allow for the establishment of a questionnaire concerning the Protected Critical Infrastructure Information (PCII) program.

The Questionnaire


This is a different questionnaire from the one for which OMB recently approved a separate ICR. While the purpose of both questionnaires is to improve the PCII program, they are apparently targeted at different audiences. The earlier ICR was targeted at federal officials and contractors. According to this notice:

“This questionnaire is designed to gather information from PCII Officers that will be used by the NPPD/IP PCII Program to assess state and local programs, their compliance with PCII rules and requirements, and the specific needs of their accredited programs. These assessments are designed to help the DHS PCII Program and Officers to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures.”

We won’t see the actual questionnaire until the ICR is submitted to the Office of Management and Budget. That means that we won’t actually know what questions are being asked to accomplish the above objective.

Protecting PCII


I am concerned about the phrase “to ensure that PCII is being properly protected and to limit the potential for mishandling and improper disclosures”. The whole point of the PCII program is that the private sector voluntarily shares sensitive information about critical infrastructure with the federal government. The only incentive that the government is able to provide is that it will in turn provide actionable intelligence information that the participants might be able to use to protect their facilities.

Since everyone knows that that information will come infrequently at best (or hopes that it will be infrequent; no one wants to be targeted by terrorists) this is not much of an incentive. This means that any risk of governmental disclosure of the information will be enough to stop most facility owners from sharing critical information with the government.

NPPD certainly has a responsibility to ensure that the privately provided information shared with State and local officials continues to be protected from disclosure. There is nothing in this ICR notice that indicates that there are other tools being used by NPPD to ensure the adequate protection of the PCII information at the State and local level. I certainly wouldn’t advocate that all of the security measures be disclosed, but this notice that proposes that actions need to be taken to ensure that PCII is properly protected at the State and local level should include some sort of assurances that there are other measures already in place to ensure the same thing.

Public Comments


NPPD is soliciting public comments on this ICR. Comments can be filed using the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0046). Comments need to be filed by January 15, 2013.
 
/* Use this with templates/template-twocol.html */