Showing posts with label Cyber Response Teams. Show all posts
Showing posts with label Cyber Response Teams. Show all posts

Tuesday, June 11, 2019

House Passes HR 1158 – Cyber Response Teams


Yesterday, the House passed HR 1158,, (corrected bill number, thanks to Toshio Miyachi for catching my error - see the comment below) the DHS Cyber Incident Response Teams Act of 2019, by a voice vote. There were no voices of dissent during the eight minutes of debate on the Floor of the House.

One common theme in the voices raised in support of the bill was the importance of the use of ‘private-sector capabilities’ to address these growing and evolving threats. Rep. McCaul (R,TX), the author of the bill, noted that it “really provides a force multiplier, and I think it is a very important step forward in the right direction” {pg H4368}.

A similar bill  (HR 5074) was passed in the 115th Congress, but it was not taken up by the Senate. This year the Senate Homeland Security and Governmental Affairs Committee has favorably reported a similar Senate bill (S 315). It is no yet clear whether either version of the legislation will make it to the floor of the Senate for consideration. If one of the two bills is considered, it will almost certainly be done under the Senate’s unanimous consent process.

Monday, June 10, 2019

Committee Hearings – Week of 06-09-19


This week with both the House and Senate in session spending bills start to move to the Floor of the House and the FY 2020 NDAA finally finishes up.

FY 2020 Spending Bills


Tuesday, House, Full Committee, DHS;
Tuesday, House, Full Committee, Financial Services;

This afternoon and tomorrow the House Rules Committee will hold hearing on the rule to consider HR 2740, the first FY 2020 spending minibus. As I mentioned on Saturday, this bill includes the original HR 2740 (LHHE), HR 2729 (Legislative Branch), HR 2968 (DOD), HR 2839 (State), and HR 2960 (EW). The two meetings will set which amendments will be considered during the Floor debate which will begin on Tuesday or Wednesday.

HR 2500 – FY 2020 NDAA


With the subcommittee work finally finishing up last week, the full House Armed Services Committee is set to take up HR 2500, the FY2020 National Defense Authorization Act (NDAA) Wednesday. We should see a report and final version of the bill this week.

On the Floor


This afternoon the House will take up seven homeland security related bills under the suspension of the rules process. This will include HR 1158 – DHS Cyber Incident Response Teams Act of 2019. This bill is expected to receive strong bipartisan support; it will certainly pass.

Monday, March 4, 2019

HR 1158 Introduced – Cyber Response Teams


Last month Rep. McCaul (R,TX) introduced HR 1158, the DHS Cyber Incident Response Teams Act of 2019. This bill is similar to S 315 that was introduced in January. The bill would provide authorization for the current US-CERT and ICS-CERT response teams in the DHS NCCIC.

Differences


The differences between the two bills are not drastic, but the subtle differences may have an effect on the operation of these teams.

The ‘new’ language added to HR 1158 is relatively inconsequencial. In the added paragraph (f)(1)(E) (this bill references the outdated ‘6 USC 148’ instead of ‘6 USC 659’), for instance substitutes “the Under Secretary appointed under section 103(a)(1)(H)” for the “Secretary” used in the Senate bill.

The language from S 315 that is removed is somewhat more interesting. The most common change is the frequent removal of the words ‘cyber hunt’ from the description of the response teams in the bill, but this is not universally removed so it should have no impact.

A significantly more important change is found in paragraph (f)(2) {which was (f)(4) in the Senate bill, a paragraph numbering change of no apparent importance}. The Senate bill reads:

“CYBERSECURITY SPECIALISTS.— After notice to, and with the approval of, the entity requesting action by or technical assistance from the Center, the Secretary may include cybersecurity specialists from the private sector on a cyber hunt and incident response team.”

The House bill completely deletes the opening phrase; removing any option for an affected party asking for NCCIC response assistance to decide if they want non-governmental personnel involved in the investigation process.

Moving Forward


McCaul is an influential member of the House Homeland Security Committee, the committee to which this bill was assigned consideration, so there is a good chance that this bill will be considered in committee. There is nothing in the bill that would draw any significant opposition so it should pass, both in committee and on the floor of the House, with significant bipartisan support.

Monday, February 18, 2019

S 315 Introduced – DHS Cyber Response Teams


Last month Sen. Hassan (D,NH) introduced S 315, the DHS Cyber Hunt and Incident Response Teams Act of 2019. The bill would authorize the current cyber incident response teams in the DHS NCCIC. The bill is very similar to HR 5074 from the 115th Congress which passed in the House but was never taken up in the Senate.

The bill does not name the teams, but the description certainly refers to the incident investigation teams associated with US-CERT and ICS-CERT. The bill specifically mentions ‘control systems’ {6 USC 659(f)(1)(D)} but does not provide a definition for that term.

Hassan and her two cosponsors {Sen. Peters (D,MI) and Sen. Portman (R,OH)} are all influential members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This should mean that the bill has a good chance of being considered in that Committee. A recent article over on Politico.com pointed out, however, how hard it is to get cybersecurity legislation through that Committee. Since this bill does not contain any new authority for NCCIC nor does it approve any new funding, this bill may be able to avoid that cybersecurity trap.

NOTE: HR 1158 was recently introduced in the House with a similar sounding name, but the text has not yet been published. I suspect that it will be very similar to this bill.

Thursday, February 14, 2019

Bills Introduced – 02-13-19


Yesterday with both the House and Senate in session there were 98 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 1158 To authorize cyber incident response teams at the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10] 

HJ Res 45 Making further continuing appropriations for fiscal year 2019, and for other purposes. Rep. Biggs, Andy [R-AZ-5]

S 482 A bill to strengthen the North Atlantic Treaty Organization, to combat international cybercrime, and to impose additional sanctions with respect to the Russian Federation, and for other purposes.  Sen. Graham, Lindsey [R-SC] 

I will be watching S 482 for language that would include attacks on industrial control systems in the definition of ‘cybercrime’, but I am not holding my breath.

There was one other oddly named bill that I will personally be watching (but will probably not be writing about here), S 483. Introduced by Sen. Roberts (R,KS) it is titled: “A bill to enact into law a bill by reference.” Odd.

Friday, March 30, 2018

HR 5074 Reported in House – Cyber Response Teams


Earlier this month the House Homeland Security Committee published their report on HR 5074, the DHS Cyber Incident Response Teams Act of 2018. The bill was passed in the House on March 19th. The date on the report is also the 19th, but the report was not actually published by the GPO until well after the debate and vote in the House.

Authorizing Existing Programs


The report makes it clear that the ‘cyber hunt and incident response teams’ authorized by the bill are, in fact, the activities currently being undertaken by the US-CERT and the National Cybersecurity and Communications Integration Center’s (NCCIC’s) Hunt and Incident Response Teams (HIRT). This is the reason that the bill specifies {§2(b)} that no additional funding is authorized; the funding for these activities is already included in the line items for NCCIC spending.

The provisions of the new 6 USC 148(f)(2) authorizing the use of “cybersecurity specialists from the private sector” on the existing US-CERT and HIRT teams is, however, a potential expansion of the capabilities of those teams. The Report states that allowing the participation of these outside experts would (pg 2) “allow industry professionals to bring innovative approaches and ideas into the federal government and makes progress in bringing the technical expertise and skills that help execute the DHS role in cybersecurity”.

Commentary


Neither the report nor the bill mentions any of the response activities of the DHS Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) which also operates as part of the NCCIC and was formerly part of the US-CERT (Actually, the current relationship between the ICS-CERT and the current US-CERT is not actually very clear.) Presumably, since the bill would add the term ‘control systems’ (even though undefined) to §148 {via (f)(1)(D)} the response activities of ICS-CERT, especially their away teams, would fall broadly under the authorization provided in this bill.

Unfortunately, the failure to define the term ‘control system’ or modify the definition of ‘information system’ in §148(a)(5) to specifically include control systems means that this bill would do nothing to actually codify the importance of control system security in NCCIC activities or oversight. This is unlikely to change if/when this bill is considered in the Senate.

Friday, March 2, 2018

HR 5074 Introduced – DHS Cyber Response Teams


Last month Rep. McCaul (R,TX) introduced HR 5074, the DHS Cyber Incident Response Teams Act of 2018. The bill would amend the authorizing language (6 USC 148) for the National Cybersecurity and Communications Integration Center (NCCIC) to establish cyber hunt and incident response teams within that organization.

Cyber Response Teams


Section 2 of the bill would require the NCCIC to maintain ‘cyber hunt and incident response teams’. These teams would be used ‘upon request’ to provide {new §148(f)(1)}:

• Assistance to asset owners and operators in restoring services following a cyber incident;
• The identification of cybersecurity risk and unauthorized cyber activity;
• Mitigation strategies to prevent, deter, and protect against cybersecurity risks;
Recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate;

The NCCIC would be authorized to use cybersecurity specialists from the private sector on these teams.

Moving Forward


McCaul is the Chair of the House Homeland Security Committee to which this bill was assigned for consideration. That would make it a near certainty that this bill would be considered in committee in the not too distant future. Its movement to the House floor is not so clear.

I see nothing in this bill that would draw significant opposition, particularly since not new funds are authorized to financially support these teams. I suspect that this bill would receive bipartisan support, both within the Committee and on the floor of the House. I am concerned, however, about the lack of a Democrat cosponsor.

Commentary


The biggest problem with this bill is that the authorizing language is, of necessity, included in §148. That section continues to rely on IT limited definitions of ‘information systems’ {§148(a)(5)} that does not include industrial control systems. The specific use of the terms ‘cyber risk’ and ‘incident’ and the definitions of both being specifically tied to that system definition, only aggravates the issue.

Having said that, the bill does specifically include ‘control system security’ in the description of support that the teams would provide. Unfortunately, the term ‘control system security’, as well as the problematic ‘cyber hunt’ are left undefined. This bill would have been a good spot to make the changes in definitions that I have suggested in earlier posts (here for example).

The oddest part of the bill is found in the new §148(f)(4) where the obligatory reports to Congress are mentioned. This bill would only require reports from the NCCIC to congressional committees once every four years on the activities of these new teams and there is no requirement for any GAO or DHS IG follow-up reporting. It is almost as if McCaul is saying: “We do not want to know what these teams are doing. Don’t bother us and we won’t bother you.” [OOPS, it says "each of the first four fiscal years"; so annual reporting is required. 03-20-18 08:30 EDT]

Finally, there is the funding issue. Section 2(b) of the bill specifically states that no additional funds are authorized and that the activities are to “be carried out using amounts otherwise authorized to be appropriated”. This means that the money and personnel headcount to support these teams are going to have to come at the expense of some other NCCIC processes. This is almost certainly the reason that the bill specifically authorizes the use of private sector cybersecurity specialists on the teams. Contractors are cheaper (no federal benefits, specifically retirement costs) and there are no practical headcount limitations.

 
/* Use this with templates/template-twocol.html */