Showing posts with label Cyber Hygiene. Show all posts
Showing posts with label Cyber Hygiene. Show all posts

Thursday, July 13, 2017

S 1475 Introduced – Cyber Hygiene

Last month Sen. Hatch (R,UT) introduced S 1475, the Promoting Good Cyber Hygiene Act of 2017. This is very similar to HR 3010. While not strictly a companion measure (due to changes in formatting, word order and organization) this bill would establish the same voluntary cybersecurity program; principally for use by the Federal Government.

Moving Forward


Unlike the sponsorship situation with HR 3010, Sen. Markey (D,MA), a cosponsor of this bill, is a member of the Senate Commerce, Science, and Transportation Committee (Hatch is not) so there is a possibility that this bill could be considered by that Committee.

Markey has worked hard on establishing a reputation as a cybersecurity gadfly (I use that term with a certain amount of admiration) in the Senate. Unfortunately, his scattergun approach to crafting cybersecurity language has left him with a significant amount of inherent opposition to his bills; none of the bills that he has offered to date (admittedly still early in the session) has been considered in Committee.

Commentary



This bill sounds good, but, like its companion, it has some serious definition problem in the IoT provisions. That ICS-inclusive definition has essentially no effect on the study required because that study is to be to consider the effects of the identified cybersecurity concerns upon Federal IT systems.

Friday, June 30, 2017

Bills Introduced – 06-29-17

Yesterday, with the House and Senate preparing to leave for their extended 4th of July holiday, there were 122 bills introduced. As with any time there is an extended congressional absence from Washington, most of these bills were introduced solely for the purpose of providing talking points (well bragging points) during fund raising and campaign activities back home. Few will see any sort of activity in Washington.

Of the bills introduced, there is one that may be of specific interest to readers of this blog:

S 1475 A bill to provide for the identification and documentation of best practices for cyber hygiene by the National Institute of Standards and Technology, and for other purposes. Sen. Hatch, Orrin G. [R-UT]


This bill is probably a companion bill to HR 3010 which I will be reviewing later today.

Friday, June 23, 2017

Bills Introduced – 6-22-17

Yesterday, with both the House and Senate in session there were 67 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 3010 To provide for the identification and documentation of best practices for cyber hygiene by the National Institute of Standards and Technology, and for other purposes. Rep. Eshoo, Anna G. [D-CA-18]

S 1405 A bill to amend title 49, United States Code, to authorize appropriations for the Federal Aviation Administration, and for other purposes. Sen. Thune, John [R-SD]

As readers of this blog would expect, HR 3010 will only receive further coverage here if it contains specific control system security language.

The FAA authorization act will be watched for cybersecurity provisions.

Friday, October 2, 2015

Bills Introduced – 10-01-15

On Thursday there were 49 bills introduced in the House and Senate. Of these only three may be of specific interest to readers of this blog:

HR 3664 To provide for the identification and documentation of best practices for cyber hygiene by the National Institute of Standards and Technology, and for other purposes. Rep. Eshoo, Anna G. [D-CA-18]

HR 3669 To amend title 18, United States Code, to provide a criminal penalty for operating drones in certain locations, and for other purposes. Rep. Garamendi, John [D-CA-3]

S 2121 A bill to facilitate and enhance the declassification of information, including in the Legislative Branch, and for other purposes.

HR 3664 sounds to be too generic to be of specific interest here, but that “for other purposes” phrase tacked on the end could hide some interesting stuff.

I suspect that the types of ‘certain locations’ called for in the HR 3669 will not include critical infrastructure, but we will have to wait for publication to be sure.

Without knowing who the sponsor of S 2121 is (see the note below) it is hard to gauge what this bill is really attempting to do. I will take a look at it when it is published because of the potential to effect government information sharing with the private sector.


NOTE: The Congress.gov web site seems to be having some sort of problem today. They were very late in getting the list of bills introduced yesterday published today. Even then a number of the House bills and none of the Senate bills provided sponsor information; they reported “Sponsor information not received”. I’m pretty sure that this will get worked out.
 
/* Use this with templates/template-twocol.html */