Showing posts with label Cybersecurity Vulnerabilities. Show all posts
Showing posts with label Cybersecurity Vulnerabilities. Show all posts

Friday, May 14, 2021

HR 2980 Introduced - Cybersecurity Vulnerability Remediation Act

Earlier this month Rep Jackson-Lee introduced HR 2980, the Cybersecurity Vulnerability Remediation Act. The bill would amend 6 USC 659 to allow the National Cybersecurity and Communications Integration Center (NCCIC) to “identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities” {new §659(n)}. The bill is essentially identical to HR 3710 that was passed in the House last session.

Changes to §659

The major change to 6 USC 659 made in this bill is the addition of a new sub-section (n):

“(n) Protocols To Counter Cybersecurity Vulnerabilities.—The [CISA] Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.”

Report on Vulnerabilities

Section 3 of the bill requires CISA to prepare a report to Congress on how it coordinates vulnerability disclosures under §659(m), Cybersecurity outreach, and how it “disseminate actionable protocols to mitigate cybersecurity vulnerabilities” under the new subsection (n). The report will include {§3(a)}:

• A description of the policies and procedures relating to the coordination of vulnerability disclosures,

• A description of the levels of activity in furtherance of such subsections (m) and (n) of such section 2209,

• Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in such section 2209) between the Department and industry and other stakeholders.

• Any available information on the degree to which such information was acted upon by industry and other stakeholders.

• A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures.

Moving Forward

Jackson-Lee is a member of the House Homeland Security Committee. She certainly has the influence to see this bill considered in Committee. In fact, as I mentioned earlier today, it looks like the bill will be skipping the committee consideration process based upon the passage of HR 3710 last session. The bill will almost certainly pass in the House with strong bipartisan support.

Commentary

As I mentioned in a couple of posts on HR 3710, the one real problem with this legislation is found in the last phrase in the new subsection (n): “…including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.” As long as the mitigation measures offered by CISA or researchers only address workaround or process measures, there should not be any significant issues. But such measures are seldom a real fix for the problem in practice. To really fix a software problem, one has to change the program.

Unfortunately, the only one who can change the program is the owner of the software. One of the peculiarities of modern technology is that the person who operates software is not typically the owner of the software; they buy a license. Making changes to the program without the permission of the owner is probably a violation of 18 USC 1030(a)(5). In my post on the House Homeland Security Committee report on HR 3710, I proposed ‘not withstanding’ language to address this potential fraud issue, but that ignores the larger issue of the liability issues of making changes to the software. And those issues are not addressed in this bill.

Friday, September 27, 2019

HR 3710 Passed in House – Cybersecurity Vulnerabilities


Yesterday the House passed HR 3710, the Cybersecurity Vulnerability Remediation Act, by a voice vote. While there was 12 minutes of debate on the bill, no one spoke against the measure. The bill now goes to the Senate where, if it is taken up, it will probably be considered under their unanimous consent process. No further amendments are expected to this legislation.

Monday, September 23, 2019

HR 3710 Reported in House – Cybersecurity Vulnerabilities


Last month the House Homeland Security Committee published their report on HR 3710, the Cybersecurity Vulnerability Remediation Act. The Committee held their markup hearing back in July and ordered the bill reported without amendment. The bill is currently scheduled for consideration under the House suspension of the rules process on Wednesday. There will be limited floor debate, no amendments may be offered from the floor and a supermajority is required for passage.

Commentary


The Committee did not deal with the copywrite issue or software ownership issue that I mentioned in my blog post on the introduction of the bill. This means that any mitigation measures that the Cybersecurity and Infrastructure Security Agency publishes as a result of this bill will have to be limited to the generic measures that CISA already includes in the control system security advisories published by NCCIC-ICS. CISA is not going to be able to publish any true ‘hacks’ of the affected software or firmware because of these issues and the bill would do nothing to provide liability protection for owners or users that would use such ‘hacks’ even if reported by CISA.

Making changes to the software, owned in most cases by the vendor not the facility in which the software operates, could be held to be a violation of 18 USC 1030(a)(5)(A) for CISA or any researcher providing a software ‘hack’ to CISA or a violation of 18 USC 1030(a)(5)(C) for facility owners that employed such a software hack to their systems.

So again, we have Congress taking action to solve a cybersecurity action that is really no action at all. There is a potential (but very unlikely) way for the House to correct this bill, even under the suspension of the rules process. Under a motion to reconsider after passage, the bill could be sent back to the Homeland Security Committee with direction to offer an amendment. That amendment would read:

On page 4, line 21; insert “(a)” before “The director”;
On page 5, line 2; delete the period after “dor” and insert a colon;
On page 5, after line 2; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the publication by CISA of any mitigation measure that changes the programing of a computer or device to provide a mitigation measure as described in (a) is not considered to be a fraud related activity as defined in §1030; and
“(c) Not withstanding 18 USC 1030(a)(5), the use of a mitigation measure described in (b) by a government agency or private entity to mitigate a vulnerability defined in (a) is not considered to be a fraud related activity as defined in §1030.”
On page 6, line 15; insert “(a)” before “The Under”;
On page 6, line 23; delete the period at the end and insert “; and”
On page 6, after line 23; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the submission to CISA of suggested changes to the affected software to mitigate an identified vulnerability as part of the program described in (a) is not considered to be a fraud related activity as defined in §1030.”

I do not really expect that this would happen, but I can always be surprised by congresscritters. More likely such changes would have to be undertake in the Senate Homeland Security Committee if/when they markup HR 3710 after it passes in the House, but before it is considered under the unanimous consent process in the Senate. Again, I would not really expect that to happen. It would be too much like actually trying to accomplish something.

Friday, July 12, 2019

Bills Introduced – 07-11-19


Yesterday with both the House and Senate in session there were 64 bills introduced. Four of those bills may see additional coverage in this blog:

HR 3699 To codify the Transportation Security Administration's responsibility relating to securing pipelines against cybersecurity threats, acts of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of pipelines, and for other purposes. Rep. Cleaver, Emanuel [D-MO-5]

HR 3710 To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 3714 To amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security. Rep. Deutch, Theodore E. [D-FL-22]

S 2095 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threat to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO]

I will be watching HR 3710 and S 2095 for specific language referring to industrial control system security issues. For HR 3714 I will be watching for general cybersecurity language while hoping for ICS mentions.

 
/* Use this with templates/template-twocol.html */