Showing posts with label Cyber Incident Response Teams. Show all posts
Showing posts with label Cyber Incident Response Teams. Show all posts

Tuesday, August 14, 2018

S 3309 Introduced – Cyber Incident Response Teams


Last month Sen. Hassan (D,NH) introduced S 3309, the DHS Cyber Incident Response Teams Act of 2018. This bill is nearly identical to HR 5074 which was passed in the House in March on a voice vote. The bill essentially authorizes the existing response teams of the US-CERT and ICS-CERT in the National Cybersecurity and Communications Integration Center's (NCCIC).

The differences between the two bills are editorial in nature and are only of interest to legislative grammarians. This new version does still include the same ‘control system security’ language found in the House bill. Similarly, it does not include a definition of ‘control system’.

Moving Forward


Both Hassan and her cosponsor, Sen. Portman (R,OH), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill (and HR 5074) was assigned for consideration. Normally, this would mean that there would be a possibility that the bill could be considered in Committee. This late in the session, however, I suspect that the only consideration that this bill will receive is as a potential amendment to the DHS authorization bill when that bill comes up for consideration after the election.

Nothing in this bill should draw any sort of opposition other than the fact that it would require the House to subsequently reconsider their vote on HR 5074, a cumbersome process going into election season. I suspect that if the Senate were to take up this bill as a stand-alone measure it would consider the House language under the unanimous consent process.

Commentary


Since the existing response teams from NCCIC are already included in the DHS funding, there is no real need in either of these bills for authorization of new funding. It would have been helpful for Congress to increase the funding so that the activities (and number) of these teams could be expanded, but that is unlikely in the current spending climate.

Of specific interest is the language specifically authorizing the use of “cybersecurity specialists from the private sector” {new §148(f)(2)}. This establishes the Congressional intent that these teams are not an inherently governmental service. This may have some interesting legal implications further down the road.

There are two other interesting things missing from this authorization language (in both bills). First, there is no mention of protections for the information gathered by the response teams. This means that there is no specific reason why a Freedom of Information Act request for results of the investigations of these teams should be denied. This could be a cause for organizations to not request support from these teams.

The second is the lack of any requirement for these teams to coordinate their activities with the FBI or some other law enforcement activity. Nor is there any requirement to preserve forensics evidence during the investigations conducted by these teams. At some point the government is going to have to go after the folks conducting these attacks and the preservation of chain of custody and other legal requirements of preserving evidence is going to raise its ugly head.

Tuesday, March 20, 2018

House Passes HR 5074 – Cyber Incident Response Teams


Yesterday the House passed HR 5074, the DHS Cyber Incident Response Teams Act of 2018, by a voice vote. The bill would authorize the establishment and use of “cyber hunt and incident response teams” in the National Cybersecurity and Communications Integration Center (NCCIC). No additional funding is provided in this bill.

As I mentioned yesterday, this bill has been officially referred to as being considered “as amended” and no amendments were offered or approved when the bill was considered by the House Homeland Security Committee. The Congressional Record for yesterday (pg H 1661) makes the same statement. I have reviewed the original bill, the reported version (published overnight) and the version published in the Record and can find no differences between these three versions. Maybe there will be some explanation when the Committee Report (H Rept 115-607) is printed later this week.

It is difficult to predict whether or not this bill will be taken up by the Senate. If it does make it to the Senate floor, I suspect that it will be at the end the day under the Senate’s ‘without objection’ procedures; meaning no debate and no vote.

If this bill does become law, it will have an interesting potential consequence. With the use of the term ‘control systems’ in the new paragraph (f)(1)(D) of 6 USC 148, we see an official opening of the NCCIC to consideration of control system incidents, particularly since the term is used with these incident response teams. The IT-limited definition of ‘information systems’ in §148 has not specifically prohibited NCCIC from consideration of ICS incidents, but it has not provided specific authorization either. I would still prefer to see the definition of ‘information systems’ at §148(a)(5) to an ICS inclusive definition (as in §1501), but the provision in this bill should make it reasonably clear that NCCIC should consider control system incidents as part of its area of interest.

 
/* Use this with templates/template-twocol.html */