Showing posts with label Cybersecurity Workforce. Show all posts
Showing posts with label Cybersecurity Workforce. Show all posts

Friday, July 12, 2024

Review - HR 8469 Introduced – Diverse Cybersecurity Workforce

Back in May, Rep Brown (D,OH) introduced HR 8469, the Diverse Cybersecurity Workforce Act of 2024. The bill would require CISA to establish, within their current Cybersecurity Education and Training Assistance Program (CETAP), a new program to promote the cybersecurity field to disadvantaged communities. It would authorize $20 million per year through 2030 to support the program.

Moving Forward

While Brown is not a member of the House Homeland Security Committee to which this bill was assigned for consideration, four of her cosponsors {Rep Carter (D,LA), Rep Ramirez (D,IL), Rep Thompson (D,MS), Rep Goldman (D,NY), and Rep Jackson-Lee (D,TX)} are members. This means that there may be sufficient influence to see the bill considered in Committee, but with the lack of any Republican cosponsor (because this is, after all a diversity program) and adding a new program to CISA’s slate, means that the legislation will have a hard-time getting enough support form committee republicans to be able to move the program to the floor of the House under the suspension of the rules process.

 

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-8469-introduced - subscription required.

Monday, March 5, 2018

Committee Hearings – Week of 03-04-18


This week, with both the House and Senate in Washington for a congressional full-week, budget hearings will be the big news. There will be, however, some other hearings of interest; four of particular interest to readers of this blog; two markup hearings, a cybersecurity workforce hearing, and a Coast Guard programs hearing.

Markup Hearings


On Wednesday the Senate Homeland Security and Governmental Affairs will ‘continue’ their hearing of last week so that they can start the markup of HR 2825, a DHS authorization bill, that I mentioned last week. The bill was not considered last week because some new amendments were not ready for submission. There is also a possibility that a Senate version of the bill will be introduced this week and then that would be marked up instead of HR 2825.

The House Homeland Security Committee will meet on Wednesday to markup 11 bills. Bills of particular potential interest to readers of this blog include:

HR 5074, the DHS Cyber Incident Response Teams Act

I have not had a chance to review the first five on the list yet, but I will try to get that done before Wednesday.

Cybersecurity Workforce


On Wednesday two subcommittees of the House Homeland Security Committee will hold a joint hearing to look at “Examining DHS’ Efforts to Strengthen its Cybersecurity Workforce”. There is no witness list published yet, but I suspect that we will have either a GAO of DHS IG report presented at this hearing. In any case, the problems that DHS (and the rest of the government) is having identifying their cybersecurity needs and then finding the people to fill the requisite positions is just a reflection of the generally increasing need for cybersecurity specialists in the economy as a whole.

 Coast Guard Programs


On Wednesday the Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing to look at “Implementation of Coast Guard Programs”. No witness list is currently available. There is a remote chance that the Maritime Transportation Security Act (MTSA) program implementation will be addressed. If it is it will almost certainly be touching on the TWIC Reader Rule; we are still waiting on the long overdue publication of a final rule.

Saturday, August 12, 2017

NIST Cybersecurity Workforce RFI Comments – 08-05-17

This is part of a continuing series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier posts in the series were:


This week there were only four new submissions posted to the NIST web site. Those were from:


AT&T pointed at a report that it had helped prepare for the Federal Communications Commission on cybersecurity workforce development in the communication’s sector.

The comments from Southern Utah University pointed at the course outline for their Masters program in Cybersecurity & Information Assurance. They also emphasized the need for academia and industry to cooperate in providing internship/apprenticeship opportunities for students or early career professionals.

The UI LABS – DMDII comments outline work that organization has done looking at the DFARS cybersecurity requirements for DOD contractors. They point out their research points to the problems that many of those contractors are having complying with the 109 cybersecurity requirements outlined in NIST 800-171.


UMass Lowell describes the certification program they have developed for implementation of the NIST Cybersecurity Framework.

Saturday, August 5, 2017

NIST Cybersecurity Workforce RFI Comments – 08-05-17

This is part of a continuing series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier posts in the series were:


There were comments received from 76 different organizations this week, some with multiple submissions. There is no way that I am going to do even a cursory review of that many submissions; I will leave that to the professionals at NIST. Instead I’ll select some of the submissions and hit some high points; all perfectly arbitrary and non-random.

One very important point was made by Anna Johnston from the Information Systems Security
Association (ISSA) in Colorado Springs, CO. She noted that: “Too many businesses are seeking to hire senior cyber personnel to do basic diagnostics, patching, etc., when those tasks can be done by more junior cyber-skilled people.” Everyone wants rock stars to be backup singers. Great if you can afford it, but expect high-turnover.

The Automation Federation asks an interesting question; why isn’t cybersecurity included as a base fundamental skill in every part of our education system? They note: “Little attention is paid to the millions of workers in the middle, who are most likely the ones who need the most knowledge on how to perform their day to day tasks in a cyber secure manner.”

The California Governor’s Office of Emergency Services response addresses an often overlooked aspect of cybersecurity; emergency response. They that California is attempting to develop a strategy “intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among California's workforce of cybersecurity professionals, and expand cybersecurity awareness and public education”.

The Center for Long-Term Cybersecurity (CLTC) points out a long standing problem with government hiring of cybersecurity professionals; the “cumbersome security clearance processes that often cause applicants to lose interest in government jobs before their application process is completed, and security policies that can unnecessarily isolate employees from their social and
professional networks”.

The Energy Sector Security Consortium, Inc. (EnergySec) makes two important points. First the continuing disconnect between IT and OT cybersecurity, noting that:

“Although NICE has a workforce framework, it is not widely used in our industry to identify the security roles or job descriptions. The roles identified in the framework are mostly applicable to traditional Information Technology aspects of business vs. the Operational Technology (e.g. industrial control systems).”

Second, they note the very real need for entry-level jobs “to provide a bridge from the emerging academic programs to mid and senior levels positions”.

While the Security University’s response has a very odd organization it does make a series of interesting points. Very importantly, they note:

“95% of cyber security professionals do not require a cybersecurity degree for a high wage in demand cyber job. They need qualified and validated skills learned from seasoned, skilled cybersecurity professionals with a practicum that demonstrates the student has learned a process and methodology that uses cybersecurity tools and understands enough of the risk policy to determine how to defend based on known threats in order to defend against unknown threats.”

Tenable makes an interesting observation in their response:

“However, our efforts to expand the human workforce will inevitably fall short of the insatiable demand for cyber talent, and we have to prepare for that. We need to have a complementary focus on technology and automation, enabling us to make the most of the human experts we have. Asymmetrically leveraging our cyber talent through the use of technology is the only path to success.”

The Coast Guard response also makes a very important point:


“Cybersecurity training and education must be agile in its planning, assessment, development and delivery cycle to adapt to the speed at which technology drives change and the need to adapt.”

Saturday, July 29, 2017

NIST Cybersecurity Workforce RFI Comments – 07-29-17

This is the second in a series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier post in the series was:


Comments posted (16) this week came from:


Issues addressed include:

• The private sector vs government pay differential;
• The use of Cyber Security Gaming and Simulations Cloud (CGSC) academies to engage K12 students and teachers;
• The lack of standard metrics or data for cybersecurity education, training, and workforce development programs;
• The NIST NICE Regional Alliances for Multistakeholder Partnerships Program (RAMPS);
• The  NCSF Controls Factory™ model created by Larry Wilson, CISO in the university (U of Massachusetts) president’s office to engineer, operate and manage the business risk of a NIST Cybersecurity Program;
• Vehicle cybersecurity workforce development program paper;
• The Scholarships for Women Studying Information Security (SWSIS) program; and
• Support for academic training programs.


A much higher percentage of respondents attempted to specifically answer the question that were posed in the RFI document (marked with *). Those responses may be worth reading depending on the amount detail one is looking for in the RFI. NIST will certainly pay close scrutiny to those submissions.

Saturday, July 22, 2017

NIST Cybersecurity Workforce RFI Comments – 07-22-17

This is the first in a series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. Comments posted this week came from:


 One commenter specifically responded to questions posed by NIST in their RFI. The others were long form explications of viewpoints about specific issues. One was a copy of an article published on CIODive.com addressing some different non-traditional cybersecurity-training activities that have been tried. Another suggested that we need to start looking at specialization training for cybersecurity personnel rather than generalist training. And the last one addressed the need for rapid changes in cybersecurity training programs to reflect changes in the environment.


The comments from Eric Baechle provided specific responses for the NIST questions. The views from Eric paint a very bleak picture of how cybersecurity specialists are utilized at one, unnamed agency (presumably government agency, but that is not exactly clear). Not unexpectedly they paint a picture of an agency management that does not understand the complexities of the cybersecurity problems being addressed by the specialized workforce nor the work actually being done by their cybersecurity team. While this is not directly a workforce development issue (other than apparently there is no effort in this organization being made to continue developing the skills of the team being employed) it does help to explain why there may be retention issues and employee burnout affecting cybersecurity operations.

Friday, July 21, 2017

Bills Introduced – 07-20-17

With both the House and Senate in session, there were 72 bills introduced yesterday. Of those, three may be of specific interest to readers of this blog:

S 1603 An original bill making appropriations for Agriculture, Rural Development, Food and Drug Administration, and Related Agencies programs for the fiscal year ending September 30, 2018, and for other purposes. Sen. Hoeven, John [R-ND]

S 1609 An original bill making appropriations for energy and water development and related agencies for the fiscal year ending September 30, 2018, and for other purposes.  Sen. Alexander, Lamar [R-TN]

S Con Res 22 A concurrent resolution expressing the sense of Congress on the use of the Intergovernmental Personnel Act Mobility Program and the Department of Defense Information Technology Exchange Program to obtain personnel with cyber skills and abilities for the Department of Defense. Sen. Rounds, Mike [R-SD]

The two spending bills will be watched for cybersecurity measures.


Another ‘sense of congress’ resolution on cybersecurity; I’m not sure what is going on here, but this will also be watched for definitions and wording.

Friday, August 7, 2015

Bills Introduced – 08-06-15

Seven bills were introduced in the Senate yesterday in a pro forma session specifically designed to allow the late submission of bills while the Senate started their five week summer recess. Of those bills there was only one that might be of specific interest to readers of this blog:

S 2007 A bill to create a consistent framework to expedite the recruitment of highly qualified personnel who perform information technology, cybersecurity, and cyber-related functions to enhance cybersecurity across the Federal Government. Sen. Bennet, Michael F. [D-CO]


Since the Federal government should be the single largest employer of cybersecurity professionals, their hiring practices should be of interest to other cybersecurity employers and employees alike.

Sunday, June 12, 2011

S 1159 Introduced – Cybersecurity Workforce

Last week Sen. Gillibrand (D, NY) introduced S 1159, the Cyberspace Warriors Act of 2011. As the name would suggest, this bill addresses cybersecurity personnel issues in the Department of Defense. Increasing the size of the cyber security workforce in the Active, Reserve, and civilian components of the Defense Department will have inevitable short term and long term effects on the cybersecurity workforce working on industrial control system issues.

Cyber Security Workforce Study

This bill would require the Secretary of Defense to hire an outside entity to review the cybersecurity workforce situation in DOD, specifically concentrating the recruitment, retention and development of ‘cyberspace experts’. An important component of the study would be the production of a “statement of capabilities and number of cyberspace operations personnel required to meet the defensive and offensive cyberspace operation requirements of the Department of Defense” {§2(b)(2)(A)}.

Along with the statement of personnel requirements for DOD’s cybersecurity workforce the study would be required to assess “the sufficiency of the numbers and types of personnel available for cyberspace operations, including an assessment of the balance of military personnel, Department of Defense civilian employees, and contractor positions” {§2(b)(2)(B)}.

The study would also look at the variety of “recruiting, training, and affiliation mechanisms” the Department could use “to address challenges to recruitment, retention, and training” {§2(b)(2)(D)} along with the identification of the types of incentives that DOD could use to overcome those challenges.

Finally, the study would look at the “legal, policy, or administrative impediments to attracting and retaining cyberspace operations personnel” {§2(b)(2)(F)} and propose “for legislative or policy changes necessary to increase the availability of cyberspace operations personnel” {§2(b)(2)(G)}.

Potential Effects on ICS Security

Not addressed in the current language of this bill would be the potential effects on the civilian cybersecurity situation caused by this increase in cybersecurity staffing at DOD. In the short term one would expect, because of the general shortage of cyber security personnel, particularly in the industrial control system realm, that any increase in the recruitment of personnel with current expertise for the DOD program would have a negative effect on the availability of personnel for civilian cybersecurity work.

Over the longer term, as DOD training and incentives for college training of cyber security increased, the overall size of the cybersecurity workforce would be expected to increase. Since military personnel with high-value skill sets have relatively low retention rates due to compensation (both base pay and bonuses) limits imposed by Congress, there would be an expected long-term increase in the availability of experienced cybersecurity personnel in the civilian sector.

It would be interesting to see if this study identifies industrial control system security as one of the specific skill sets necessary for the DOD cybersecurity program. I would expect that any offensive cyber operations would need the capability to affect industrial control systems of various sorts. Defensive cyber operations conducted by DOD could also require protection of a variety of industrial control systems.

I would expect that there would be much more focus on information technology systems, but this study could have a long-term effect on the industrial control system security personnel situation.
 
/* Use this with templates/template-twocol.html */