Showing posts with label Cyber Training. Show all posts
Showing posts with label Cyber Training. Show all posts

Monday, December 29, 2025

Review - S 438 Introduced – Cyber PIVOTT Act

Back in February Sen Rounds (R,SD) introduced S 438, the Providing Individuals Various Opportunities for Technical Training to Build a Skills-Based Cyber Workforce (Cyber PIVOTT) Act of 2025. The bill would require CISA to “establish education and training programs and facilitate internship and post-graduation Federal job opportunities at participating institutions”. No new funding would be authorized by this legislation.

This bill is very similar to HR 9770 that was introduced by Rep Green (R,TN) in September of 2024. On September 25th, 2025. The House Homeland Security Committee held a markup hearing on September 25th, 2024. The bill was amended and ordered to be reported favorably by a vote of 27 to 0. The report was never filed nor was an amended version of the bill published. No further action was taken.

On the same date that S 438 was introduced, Green introduced HR 1000 which was very similar to HR 9770. On February 26th, 2025, the House Homeland Security Committee held a business meeting where HR 1000 was considered. The Committee ordered the bill reported favorably without amendment by a near party-line vote of 17 to 8. It is not clear why there was such a radical change in support from Democratic members of the Committee. No further action has been taken on HR 1000 in the 119th Congress.

The differences between S 438 and HR 1000 are mostly formatting in nature with two exceptions. First, the definition section is expanded from 2 to 12 terms and is moved from subsection §1334(i) to (a). Secondly, a §1334(b)(5)(A)(ii) provides a broad FACA exemption to the advisory committee suggested in clause (i).

This bill would amend the Homeland Security Act of 2002 by adding a new section: §1334, CISA education and training programs and resources.

Moving Forward

While Rounds is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration, his sole cosponsor {Sen Peters (D,MI)} is the Ranking Member of that Committee. This means that there could be sufficient influence to see the bill considered in Committee. With no spending authorized in the legislation, I see nothing in the bill that would engender any organized opposition. I suspect that there would be some level of bipartisan support for the bill.

As with any bill under primary consideration of the Senate Homeland Security Committee, the main roadblock could be opposition by the Chair, Sen Paul (R,KY). Paul has an almost visceral objection to government programs, so it would not be surprising if he were to object to this PIVOTT program. And since he is the Chair, his objection would mean that the bill would not be considered by the Committee.

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-438-introduced-cyber-pivott-act - subscription required.

Thursday, February 27, 2025

HR 494 Introduced – Extends Coverage of Cyber Scholarship Program

Last month, Rep Connolly (D,VA) introduced HR 494, a bill that would make improvements to the Federal Cyber Scholarship for Service Program. It would amend 15 USC 7442(c) to extend the time covered by the program from three years to five years of study. No new funding is provided in the legislation.

This HR 494 is essentially identical to HR 10209 that was introduced in November of last year by Connolly. That bill was introduced too late in the session for any action to have been taken.

Neither Connolly, nor his sole cosponsor {Rep Strong (R,AL)}, are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there is likely not to be sufficient influence to see the bill considered in Committee. I suspect that there may be some opposition to this bill because it would dilute the number of scholarships that would be issued under the program as it is unlikely that additional funding would be provided to cover the longer scholarship period. That opposition would probably not be enough to kill the bill in Committee, but may be enough to stop its consideration before the full House under the suspension of the rules process.

Tuesday, February 25, 2025

Review - HR 1000 Introduced – PIVOTT Act

Last month, Rep Green (R,TN) introduced HR 1000, the Providing Individuals Various Opportunities for Technical Training to Build a Skills-Based Cyber Workforce (Cyber PIVOTT) Act of 2024. The bill would require CISA to “establish education and training programs and facilitate internship and post-graduation Federal job opportunities at participating institutions”. No new funding would be authorized by this legislation.

This bill would amend the Homeland Security Act of 2002 by adding a new section: §1334, CISA education and training programs and resources.

This bill is very similar to HR 9770 that was introduced by Green in September of 2024. On September 25th, 2025. The House Homeland Security Committee held a markup hearing on September 25th, 2024. The bill was amended and ordered to be reported favorably by a vote of 27 to 0. The report was never filed nor was an amended version of the bill published. No further action was taken.

Moving Forward

The House Homeland Security Committee will be holding a business meeting tomorrow where this bill will be considered. Based on the results when HR 9770 was considered last year, I suspect that there will be widespread, bipartisan support for the bill. Once the requisite report is published by the Committee this bill will almost certainly be taken up by the full House under the suspension of the rules process.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1000-introduced - subscription required.

Wednesday, October 16, 2024

Review – HR 9770 Introduced – Cyber PIVOTT Act

Last month, Rep Green (R,TN) introduced HR 9770, the Providing Individuals Various Opportunities for Technical Training to Build a Skills-Based Cyber Workforce (Cyber PIVOTT) Act of 2024. The bill would require CISA to “establish education and training programs and facilitate internship and post-graduation Federal job opportunities at participating institutions”. No new funding would be authorized by this legislation.

This bill would amend the Homeland Security Act of 2002 by adding a new section: §1334, CISA education and training programs and resources.

Moving Forward

On September 25th, the House Homeland Security Committee held a business meeting where they considered 21 pieces of legislation, one of which was HR 9770. The bill was amended (not currently available) and ordered to be reported favorably by a vote of 27 to 0. Once the Committee report is published, the bill will be available to be considered by the full House. The strongly bipartisan vote in Committee means that the bill will be brought to the floor under the suspension of the rules process and would be expected to pass with similar bipartisan support.

Commentary

While this bill may appear to be important for increasing the cybersecurity knowledge base of the federal government, it is lacking one major component – funding. The crafters of the bill accept no responsibility for the cost of the new program, leaving it up to the House Appropriations Committee to figure out the funding level necessary to support the new program as well as determining from where the funding will come. Given the Republicans desire to reduce federal spending, and because of how late this bill would be passed in the session (if that can in fact happen) there will almost certainly be no funding for this bill in FY 2025. If the Republicans retain control of the House after November 5th, there would likely be no funding for the legislation through FY 2027. With one of the cosponsors {Rep Guest (R,MS)} on the House Appropriations Committee, this fact is almost certainly understood by the crafters of the bill, making this a posturing bill, not a real attempt to address the cybersecurity staffing issue.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9770-introduced - subscription required. 

Wednesday, November 13, 2019

S 2775 Introduced – HACKED Act


Last week Sen Wicker (R,MS) introduced  S 2775, the Harvesting American Cybersecurity Knowledge through Education (HACKED) Act of 2019. The bill would modify a number of existing federal computer training related programs to specifically include cybersecurity training.

Programs Amended


This bill would make amendments to the following programs under the National Institute for Standards and Technology (NIST):

15 USC 7451 – National cybersecurity awareness and education program;
15 USC 7442 – Federal Cyber Scholarship-for-Service Program; and
15 USC 278g-3 – Computer standards program

This bill would make amendments to the following programs under the National Science Foundation (NSF):

42 USC 1862s-7 - Computer science education research;
42 USC 1862i – Scientific and technical education;
42 USC 1869c – Low-income scholarship program;
42 USC 1869 – Scholarships and graduate fellowships;
42 USC 1881b – Presidential awards for teaching excellence;
42 USC 1862s-6 – Presidential awards for excellence in STEM mentoring; and
42 USC 6621 - Coordination of Federal STEM education

This bill would make amendments to the following programs under the Department of Transportation:

49 USC 5505 - University transportation centers program;
49 USC 6503 - Transportation research and development 5-year strategic plan

Moving Forward


Wicker is the Chair of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. The bill is scheduled to be taken up by that Committee today as part of a business meeting. The bill will almost certainly be adopted by a significant bipartisan vote since no new funds are authorized by the bill.

Commentary


The biggest problem with this bill is that there is no definition of ‘cybersecurity’ anywhere in the bill. The underlying definitions for the NIST portions of the bill come from PL113-274. In my blog post about that bill I noted that while “industrial or supervisory control systems” are specifically mentioned in the underlying bill {§2(2)} they are only addressed in reference to IT specific information systems.

There are no definitions of ‘cybersecurity’ in any of the referenced NSF programs or DOT programs.

Now I have previously addressed a number of definitional issues related to cybersecurity. My most comprehensive attempt at coming up with cybersecurity definitions that were clearly applicable to both information and operational cyber systems can be found here. Unfortunately, I did not specifically address the term ‘cybersecurity’. I will try to take that up here.

I do not expect that this bill would be a good place (nor is this Committee the appropriate agent) to address each of the definitions that I proposed earlier, so I will try to accomplish this with just addressing two terms; ‘cybersecurity threat’ and ‘cybersecurity’. First, I would use the existing definition of ‘cybersecurity threat’ from 6 USC 1501; remember that definition relies on the ICS inclusive definition of ‘information system’ from that section. Then I would define ‘cybersecurity’:

Cybersecurity – The term cybersecurity means any actions, policies or procedures utilized to protect an information system (as that term is defined in 6 USC 1501) from a cybersecurity threat (as that term is defined in the same section) or mitigate the effects of a cybersecurity threat against such cybersecurity threat.

Wednesday, November 6, 2019

Bills Introduced – 11-04-19


Yesterday with the Senate in Washington and the House meeting in pro forma session there were 33 bills introduced. Two of those bills may receive future coverage in this blog:

HR 4987 To provide first responders with planning, training, and equipment capabilities for crude oil-by-rail and ethanol-by-rail derailment and incident response, and for other purposes. Rep. Herrera Beutler, Jaime [R-WA-3]

S 2775 A bill to improve the cyber workforce of the United States, and for other purposes. Sen. Wicker, Roger F. [R-MS]

Herrera-Beutler is an outspoken critic of oil trains, especially ones that traverse her district. It will be interesting to see if this bill drifts over into being designed to being an impediment to oil train formation or whether it remains a well-considered emergency response measure.

As always with cyber related bills I will be watching S 2775 for language and definitions to see if this bill specifically addresses control system security training.

 
/* Use this with templates/template-twocol.html */