Showing posts with label Cybersecurity Coordination. Show all posts
Showing posts with label Cybersecurity Coordination. Show all posts

Sunday, December 22, 2019

HR 5394 Introduced – Cybersecurity Coordination


Earlier this month Rep Taylor (R,TX) introduced HR 5394, the Strengthening State and Local Cybersecurity Defenses Act. The bill would amend 6 USC 659; adding a number of coordination, education and assistance responsibilities to the Cybersecurity and Infrastructure Security Agency (CISA) charter to provide cybersecurity support to a wide variety of public and private entities in the country.

Definitions


The bill would add a new definition to 6 USC 651; ‘entity’. This term would be very broadly defined as including {new §651(4)}:

• An association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;
• A government agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and
• The general public.

New CISA Coordination Responsibilities


The bill would add a new paragraph (n) to 6 USC 659, entitled ‘Coordination’. That paragraph would require CISA to coordinate (to the extent practicable) with Federal and non-Federal entities (specifically including the Multi-State Information Sharing and Analysis Center) to:

• Conduct exercises with Federal and non-Federal entities;
• Provide operational and technical cybersecurity training related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents to entities to address cybersecurity risks or incidents, with or without reimbursement;
• Assist entities, upon request, in sharing cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among entities, in order to increase situational awareness and help prevent incidents;
• Provide entities timely notifications containing specific incident and malware information that may affect such entities or individuals with respect to whom such entities have a relationship;
• Provide and periodically update via a web portal and other means tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security;
• Work with senior Federal and non-Federal officials, including State and local Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;
• Provide, upon request, operational and technical assistance to entities to implement tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion detection capability, to assist such entities in detecting cybersecurity risks and incidents;
• Assist entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;
• Ensure that entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security developed by the Department and other appropriate Federal entities for ensuring the security and resiliency of civilian information systems; and
• Promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.

Moving Forward


Taylor and four of his cosponsors {Ranking Member Rogers (R,AL), Green (D,TX), Guest (R,MS) and Slotkin (D,MI)} are members of the House Homeland Security Committee to which this bill was assigned for consideration. This bill will almost certainly be considered in Committee early next year. There is nothing in the language of the bill that would engender any significant opposition to the bill.

When the bill is considered (and it is likely to reach the floor) it will receive significant bipartisan support. When it is considered on the floor of the House it will be considered under the suspension of the rules process; limited debate, no floor amendments and will require a super-majority to pass.

Commentary


This is another one of the cybersecurity bills being considered this session that are purely motherhood and apple pie attempts by Congress to make it look like they are doing something about cybersecurity. There is nothing in the bill that CISA is not already doing or DHS has not been doing for quite some time before before the investiture of CISA.

If Taylor really wants this bill to accomplish something, he could straighten out the definitions in §659 that officially (though not actually in practice) limits CISA from looking at control system security, by excluding all but pure information technology systems from their purview. Again, I would refer Taylor, and the Committee Staff, to my blog post from February where I discuss the cybersecurity definition problem in detail and provide legislative language to correct those problems.

Thursday, December 12, 2019

Bills Introduced – 12-11-19


Yesterday with both the House and Senate in session there were 34 bills introduced. One of those bills may see further coverage in this blog:

HR 5394 To amend the Homeland Security Act of 2002 to require certain coordination between the Department of Homeland Security and Federal and non-Federal entities relating to cybersecurity risks and incidents, and for other purposes. Rep. Taylor, Van [R-TX-3] 

Friday, March 3, 2017

S 412 Introduced – Cybersecurity Coordination

Last month Sen. Peters (D,MI) introduced S 412, the State and Local Cyber Protection Act of 2017. The bill would require the National Cybersecurity and Communications Integration Center (NCCIC) to provide cybersecurity assistance to State and local government organizations. This bill is very similar to S 2665 that was introduced in the 114th Congress; no action was taken on the earlier bill.

The Assistance


The bill would amend 6 USC 148 by adding a new paragraph (n); State and Local Coordination on Cybersecurity. It would require the Center (where practicable) to {new §148(n)(1)}:

• Assist State and local governments in identifying information system vulnerabilities;
• Assist State and local governments in identifying information security protections commensurate with cybersecurity risks and the magnitude of the potential harm resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information systems or stored information;
• Provide and periodically update via a web portal tools, products, resources, policies, guidelines, and procedures related to information security;
• Coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, and procedures related to information security to secure and ensure the resiliency of State and local information systems;
• Provide operational and technical cybersecurity training to State and local government and fusion center analysts and operators to address cybersecurity risks or incidents;
• Provide privacy and civil liberties training to State and local governments related to cybersecurity
• Provide, upon request, operational and technical assistance to State and local governments to implement tools, products, resources, policies, guidelines, and procedures on information security;
• Assist State and local governments to develop policies and procedures for coordinating vulnerability disclosures procedures consistent with international and national standards in the information technology industry;
• Ensure that State and local governments are made aware of the tools, products, resources, policies, guidelines, and procedures on information security developed by the Department and other appropriate Federal departments and agencies for ensuring the security and resiliency of Federal civilian information systems.

Moving Forward


Peters is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This may mean that he has enough influence to ensure that this bill is considered in Committee. This version was introduced much earlier in the session so it may actually be considered.

There is nothing in the bill that would engender any significant opposition. If the bill does make it to consideration it should be able to pass with substantial bipartisan support.

Commentary


This bill still does not contain any mention of control system security. State and local governments operate a wide variety of control systems (traffic control systems, utility control systems and security control systems to mention a few) and the security of those systems is becoming increasingly important.

This bill frequently mentions the term ‘information security’. Since this bill amends §148 it relies on the definition of that term found in §148(a)(5) which refers back to the very limited, IT-based definition found in 44 USC 3502(8) instead of the broader, ICS-inclusive definition of the term found in 6 USC 1501(9). Simply changing the reference to the newer definition would extend the requirements of this bill to industrial control system security issues.


There are a wide variety of new requirements in this bill that will require personnel, time and materials to effect. Unfortunately, as is common in much legislation, there are no provisions in the bill for providing additional monies to fulfill these requirements. This means that any efforts made by the NCCIC to meet the requirements of this bill would have to draw down existing efforts in other areas of its operation. Where Congress does not provide guidance as to where this funding comes from, it is relying on the Executive Branch to make those decisions. This ultimately allows congress critters to complain about budgetary decisions without having to make those decisions themselves; just keep adding requirements and do not worry about paying for them. That is a great political game….

Friday, February 17, 2017

Bills Introduced – 02-16-17

Yesterday with the House and Senate getting ready to depart for their Presidential Day recess next week there were 154 bills introduced. Many of these bills were introduced to provide fundraising talking points next week, but one of the bills may be of specific interest to readers of this blog:

S 412 A bill to amend the Homeland Security Act of 2002 to require State and local coordination on cybersecurity with the national cybersecurity and communications integration center, and for other purposes. Sen. Peters, Gary C. [D-MI]


It will be interesting to see how this bill avoids the ‘unfunded federal mandate’ label. I’ll only be covering this bill if it specifically includes control system security issues.
 
/* Use this with templates/template-twocol.html */