Showing posts with label Cyber Security Legislation. Show all posts
Showing posts with label Cyber Security Legislation. Show all posts

Sunday, April 1, 2012

HR 4263 Introduced – Cyber Security

Last Tuesday Rep. Bono-Mack (R,CA) introduced HR 4263, the “Strengthening and Enhancing Cybersecurity by Using Research, Education, Information, and Technology (SECURE IT) Act of 2012. While this bill has the same title as S 2151 and the language is nearly identical for large portions of the bill, there are a large number of not so subtle differences between the two bills.

First off there are a large number of relatively wording changes between the two bills. Most of these changes are insignificant and will be of interest only to legal scholars and lawyers arguing civil cases involving cybersecurity matters.

There are a number of significant additions in this bill not found in S 2151.  They include grant funding provisions (revised § 413), minor cloud computing provisions (new § 404), the creation of a cybersecurity university-industry task force (new § 405), the establishment of requirements of cybersecurity automation and checklists for government systems (new § 414) and the establishment of an NIST cybersecurity research program (new § 415).

Grant Funding


One thing this new bill does is to provide actual continuing funding authority for a number of cybersecurity grant programs over the next three fiscal years. Section 413 is completely re-written (from the S 2151 version) and it now provides funding for:

• Computer and Network Security Research Grants [$90,000,000/year]

• Computer and Network Security Research Centers [$4,500,000/year]

• Computer and Network Security Capacity Building Grants [$19,000,000/year]

• Scientific and Advanced Technology Act Grants [$2,500,000/year]

Of course there is no mention of where the money will come from for these grants. That will have to be worked out before this bill could come to the floor under House Rules.

Industrial Control Systems

 

None of the ICS security related provisions that I have identified in S 2151 have been significantly changed in this bill. There is one additional, if very brief, mention of industrial control systems in this legislation. It is found in the new §415 in a modification of §20 of the National Institute of Standards and Technology Act where it adds new ‘Intramural Security Research’ under sub-paragraph (e) it includes “carry out research associated with improving security of industrial control systems” {§415 adds §20(e)(4)}. It’s not much, but it is something.

Monday, February 21, 2011

S 413 Introduced – Cyber Security

Last Thursday Senators Lieberman (D, CT), Collins (R, ME) and Carper (D, DE) introduced S 413, the Cybersecurity and Internet Freedom Act of 2011. This bill would establish the Office of Cyberspace Policy (OCP) in the White House and the National Center for Cybersecurity and Communications (NCCC) in DHS. The OCP Director would have cyber security budget approval authority and the NCCC Director would have regulatory authority over cybersecurity activities within the Federal Government.

While this bill is mainly directed at “information infrastructure” there is one section in Title II that addresses cyber risks to covered critical infrastructure (§248) that very carefully never specifically limits its application to ‘information’ systems. That section requires the Director of the NCCC to “issue interim final regulations establishing risk-based security performance requirements to secure covered critical infrastructure against cyber risks through the adoption of security measures that satisfy the security performance requirements identified by the Director” {§248(b)(1)} within 270 days of passage of this bill.

Generally speaking the wording of this section looks like the crafters intend for establishment of a regulatory scheme similar in construction and operation to the CFATS regulations for high-risk chemical facilities. This nine page section of the bill certainly deserves a more detailed look in future blogs.

According to a press release on the Homeland Security and Governmental Affairs Committee web site, there “is no so-called ‘kill switch’ in our legislation because the very notion is antithetical to our goal of providing precise and targeted authorities to the President”. In fact, §2(c) specifically says that under this legislation “neither the President, the Director of the National Center for Cybersecurity and Communications, or any officer or employee of the United States Government shall have the authority to shut down the Internet”. This kill-switch issue stalled the earlier version of this bill in the last session. Hopefully this bill will now have a chance to move forward in the legislative process.

BTW: The official GPO version of this bill is not yet available. Sen. Lieberman has made a copy of the bill available via a link on the Senate Homeland Security Committee web site.

Sunday, February 20, 2011

S 372 Introduced – Cyber Security

Last week Sen. Cardin (D, MD) introduced S. 372, the Cybersecurity and Internet Safety Standards Act. It’s a high sounding title and addresses a serious potential security problem by requiring another study. I know that studies are important, but there comes a time when Congress must actually propose solutions to the problems it has identified.

If you want a sweeping description of the cyber security problem, this bill is willing to provide it. The findings section of the bill {§3(3)} notes that:

“The Government and the private sector need to work together to develop and enforce minimum voluntary or mandatory cybersecurity and Internet safety standards for users of computers to prevent terrorists, criminals, spies, and other malicious actors from compromising, disrupting, damaging, or destroying the computer networks, critical infrastructure, and key resources of the United States.”
Such a sweeping, all encompassing problem statement requires an equally sweeping study requirement. Section 4 of the legislation requires:

“The Secretary, in consultation with the Attorney General, the Secretary of Commerce, and the Director of National Intelligence, shall conduct an analysis to determine the costs and benefits of requiring providers to develop and enforce voluntary or mandatory minimum cybersecurity and Internet safety standards for users of computers to prevent terrorists, criminals, spies, and other malicious actors from compromising, disrupting, damaging, or destroying computer networks, critical infrastructure, and key resources.”
To make it perfectly clear that this is truly a sweeping study, a study to end all studies, a study to put the matter once and for all completely to rest, the bill goes on to ensure that the Secretary examines:

● “all relevant factors, including the effect that the development and enforcement of minimum voluntary or mandatory cybersecurity and Internet safety standards may have on homeland security, the global economy, innovation, individual liberty, and privacy; and” {§4(b)(1)}

● “any legal impediments that may exist to the implementation of such standards.” {§4(b)(2)}
When the Secretary files this most comprehensive report with Congress in a year, there will no longer be any reason for Congress not to be able to solve all of the cyber security ills of the world in a single piece of comprehensive, all encompassing and perfect cyber security legislation.

Please forgive the virulent sarcasm, but I am sick and tired of Congress trying to dump its inability to legislate on the Executive Branch. Let’s give this bill no additional attention and pass on to real legislation that actually does something.

BTW: The GPO web site is having some sort of problem and does not recognize the link to this and a couple of other bills. The copy of the bill I used for this review can be found on Thomas.loc.gov by searching for S 372.

Wednesday, November 17, 2010

New Cyber Security Legislation

This evening Chairman Thomson (D, MS), Chairman of the House Homeland Security Committee sent out a press release on new cyber security legislation introduced today. The press release describes a comprehensive piece of legislation that establishes a DHS Office of Cybersecurity & Communications and a “Cybersecurity Compliance Division to oversee the establishment of performance-based standards responsive to the particular risks to the .gov domain and critical infrastructure networks”.

Interestingly the term ‘information networks’ is not used in this press release or in the accompanying one page summary document. Of course, neither is there any specific mention of control systems either. I suspect that this bill would apply to both, but until I can see a copy of the actual legislation, I won’t know for sure.

I won’t know the bill number until today’s Congressional Record is published tomorrow morning. The bill itself may (if it is very short) or may not (if this is truly a comprehensive bill it will be long) be available tomorrow morning. Watch this space for additional information.

Friday, November 12, 2010

Lame Duck Congress

While many pundits are focused on prognostication about the 112th Congress that will start in January, next week the 111th Congress will return to finish out the last month and a half of their term. The same people will be in charge and the same issues have to be addressed. The big difference is that many won’t be returning, so they won’t need to worry about what the voters think while others know that they will have more power to persevere in the next Congress. These two facts will color what can be done.

Chemical Security Legislation

The current CFATS authority expires on December 3rd. Congress will take some sort of action on legislation to continue that program. The most likely effort will be a one year extension in the DHS budget bill. If an actual budget doesn’t pass (a very real possibility if the Democrats try to stuff a budget bill with last minute attempts to add programs that won’t have a chance in the upcoming Republican controlled House) any continuing resolution will contain a CFATS extension for the length of the CR. I won’t be surprised to see a couple of short term continuing resolutions to give the 111th more time to pass their budget bill (probably a single, huge bill).

There are a number of bills that specifically address CFATS ranging from HR 2477 (which makes the current program permanent), thru HR 2868 (which slightly modifies and extends CFATS for three years), to S 2996 (which extends CFATS for five years). The only one that has any chance of passage is HR 2868 and I’ve discussed a number of possible scenarios that might result in passage in earlier blogs (most recently), but I won’t waste any money on betting on passage.

Adding chemical security requirements to water treatment facility security requirements is currently only addressed by one bill (the Senate version of HR 2868 removed the House provisions that included this), S 3598. The Senate has held only one hearing on this bill and the Environment and Public Works Committee is unlikely to report this bill. If it does, the Democrats are unlikely to be able to muster 60 votes (because of the current IST provisions in the bill) to force a vote on this bill. If it does get to a floor vote, it would almost certainly pass and could be taken up and passed in the House if the Senate vote comes early enough. Needless to say that Greenpeace is pushing for this bill to be passed.

Cyber Security Legislation

There were a number of cyber security bills introduced in the 111th Congress. None really specifically address control system security issues. Only one has come to a floor vote, HR 4061, and it passed easily. No action has been taken in the Senate on that bill, no hearings and no committee votes. While it is unlikely to come to a floor vote, it would probably pass. It could make it to the floor at the very end of the session if the leadership really wanted to get some sort of cyber security bill passed and nothing else worked. If there were no floor amendments, this bill would not need to go back to the House for further action.

S 3480 is the Senate bill that is best positioned to come to a floor vote. As I have mentioned on a number of occasions, we have been waiting for the Senate Homeland Security and Governmental Affairs Committee’s report on this bill since June. There is some opposition to some provisions of this bill so there would probably be a fairly extensive number of floor amendments that would be faced. This would make this a time consuming bill to pass, making it difficult in this short session. If the leadership on both sides of the aisle could agree to limit the amendment process this bill could probably pass, but not in enough time to make it through the House.

Other Legislation of Interest

HR 2200, the TSA authorization bill, has been ordered reported in the Senate (last year), so it could come to the Senate floor. New concerns about cargo screening, and passenger screening technology could lead to a large number of floor amendments, again making this a time consuming bill to pass. It would have to go back to the House, because of changes made in committee. That makes it more difficult to pass in the short session.

HR 4842, the DHS S&T authorization bill, passed in the House but has had no action taken in the Senate. This could be a sleeper bill that could slide through a floor vote in the Senate if the leadership decides to take it up.

Watch Them Closely

While many people have called the 111th a ‘do nothing’ Congress, there have actually been a significant number of things passed. We will probably see a large number of little noticed bills making their way quickly through the legislative process in the lame duck session. Most will be mainly non-controversial, but lots of stuff can get tacked onto these bills. The budget bill(s) will be particularly vulnerable to stuffing with a number of Congress Critters trying one last time to get their personal favorite idea into law. This session could get very loud and very ugly, but we’ll have to pay close attention to the quiet stuff.

Wednesday, June 30, 2010

S 3538 Introduced

Last week Sen. Bond (R, MO) introduced S 3538, the National Cyber Infrastructure Protection Act of 2010 with the GPO posting a copy of the introduced bill today. This is another cyber security bill targeted mainly at protecting Federal government ‘information networks’. There is no mention of ‘industrial control systems’ or ‘SCADA’ in the proposed legislation. There are, however, some provisions that might be of interest to the chemical security community. The bill would establish within the Department of Defense a National Cyber Center. While the center would receive administrative and logistical support from DOD, the Director would report directly to the President and would not be part of the Executive Office of the President. This would make the Center very nearly a Cabinet level agency. It is when we delve down into the duties of the Director that we start to see some wording that could provide justification for the Center to have some affect on industrial cyber security activities for areas other than just ‘information networks’. The constant use of the modifying term ‘information networks’ through out the rest of the bill make these paragraphs standout because of the lack of that terminology. Imminent Cyber Attack For example §103(d)(7) requires the Director to “provide recommendations, on an ongoing basis, to Federal agencies, private sector entities, and public and private sector entities operating critical infrastructure for procedures to be implemented in the event of an imminent cyber attack that will protect critical infrastructure by mitigating network vulnerabilities”. This doesn’t appear to give the Director authority to develop or enforce cyber security regulations for companies operating critical infrastructure facilities. However, the fact that the Director would have budgetary authority over the cyber security activities of the executive branch agencies would give special weight to the Director’s recommendations. Cyber Security Intelligence Section 103(d)(11) would require the Director to “develop plans and policies for the sharing of cyber threat-related information among appropriate Federal agencies, and to the extent consistent with the protection of national security sources and methods, with State, tribal, and local government departments, agencies, and entities, and public and private sector entities that operate critical infrastructure”. The bill does not provide the Director with any specific intelligence collection or analysis capability. It does, however, specifically give the Director “access to all intelligence relating to cyber security collected by any Federal agency” {§104(b)}. To make the information sharing requirement really effective would require funding and staffing for a cyber security intelligence analysis unit within the Center. Vague Provisions Since these provisions do not provide explicit authorization for ‘SCADA’ or ‘ICS’ related regulatory actions, we will have to watch any hearings and reports to see if there is more concrete language that would provide clearer indications of ‘Congressional intent’ to support industrial cyber security activities by the Center or the Director. So, I’ll add this to the list of bills that I will watch for as we rapidly head for the election season this fall.

Monday, March 29, 2010

S773 Passed in Committee

This announcement is a little bit late, but on the 24th the Senate Commerce Committee voted in favor of requiring S773 to be favorably reported to the full Senate. A number of amendments were included with the action, all being passed by a single voice vote without apparent opposition. One of the amendments was the Sen. Rockefeller and Sen. Snows substitute language that they had reported on the previous week. Unfortunately, until the actual report is filed in the Senate, I won’t be able to comment upon the actual content of the reported version of the bill. Waiting for that report was the main reason that I didn’t report on passage of the bill. Now that the Senate is in their Easter Recess, that report cannot be filed any earlier than April 12th. So we will just have to wait and see if the Commerce Committee version of the bill contains any significant provisions affecting chemical facility control systems.
 
/* Use this with templates/template-twocol.html */