Showing posts with label DHS Reorganization. Show all posts
Showing posts with label DHS Reorganization. Show all posts

Thursday, October 4, 2018

Senate Amends and Passes HR 3359 – DHS Reorganization


Yesterday the Senate amended and passed HR 3359, the ‘Cybersecurity and Infrastructure Security Agency Act of 2018. The bill creates the Cybersecurity and Infrastructure Security Agency within DHS. The bill was passed earlier this year in the House. Two amendments were made; the first (SA 4403, pg S6497) substitute language from Sen. Johnson (R,WI) and the second a minor amendment (SA 4404, pg S6502) from Sen. Murkowski (D,MO). Both amendments and the bill were adopted without debate or vote. The bill will now have to be reconsidered by the House.

Substitute Language


Most of the additions made by the Johnson amendment added references to ‘Sector-Specific Agency’. This included a new definition of that term added in the new §2201.

The language regarding the transfer of the DHS Federal Protective Service {§3(b)} was greatly expanded. The original bill provided that DHS could transfer the FPS to the new CISA. The substitute language approved yesterday expands on that by providing instructions on what needs to occur if DHS declines to make that move. This would include specific notifications to Congress and the involvement of the OMB in subsequent evaluation of what to do with the FPS.

A new §4 of the bill was added that requires a report to Congress by DHS on the “leadership role of the Department in cloud-based cybersecurity deployments for civilian Federal departments and agencies” {§4(b)}.

There were a number of wording deletions made by the substitute language. These include the rather inconsequential deleting of the definitions of the terms ‘federal entity’ and ‘non-federal entity’.

One potentially significant deletion in the new §2202 is made in paragraph (e)(1) where the responsibilities of the new CISA Director are enumerated. Sub-paragraph (M) was deleted. That originally read:

“To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—
“(i) are compatible with one another and with relevant information databases of other Federal Government agencies; and
“(ii) treat information in such databases in a manner that complies with applicable Federal law on privacy.”

Finally a change was made to the wording in the bill dealing with the Chemical Facility Anti-Terrorism Standards (CFATS) program. In explicating the responsibilities of the new Assistant Director for the new Infrastructure Security Division we see both an addition and deletion made to the wording of the original bill. The quote below shows both the addition (underlined) and the deletion (struck-through) made to §2204(b)(2).

“(2) carry out efforts, at the direction of the Director, to secure the United States high-risk chemicals and chemical facilities consistent with law, including the Chemical Facilities Anti-Terrorism Standards Program established under title XXI and the secure handling of ammonium nitrate program established under subtitle J of title VIII, or any successor programs;”

Commentary


I continue to believe that this change to the status of the current National Protection and Programs Directorate is mainly a smoke and mirrors change. I have had a number of people with closer connection to the operation of DHS inform me that this has to do mainly with the status of the new Director and the authority of the new agency to deal with administrative and spending matters; none of which is directly addressed in the language of the bill.

The change in wording of §2204(b)(2) has me a little bit concerned. Neither the addition or deletion has any direct affect on the CFATS program. The added ‘any successor’ language is typically a legal distinction addressing the fact that Congress could change the name of the program at any time. Similarly, the deleted words have no apparent practical effect on the inclusion of the CFATS program in the new Infrastructure Security Division. But, there is a nagging question in my mind as to why Johnson made these specific changes to the wording about the CFATS program; is there something in the works?

I am more concerned, however, with the deletion of §2202(e)(1)(M). I am not an active privacy advocate particularly when it comes to the Federal government; mainly because I suspect that we have completely surrendered any pretense of privacy protection and any attempts to put the genie back in the bottle are mainly for show rather than for any practical effect. Having said that, I am concerned that Johnson thought that it was appropriate to remove language from the bill that provided some modicum of privacy protection to information collected by DHS. It probably was not going to be very effective, but it at least made a show of being concerned.

Monday, October 23, 2017

House Passes HR 4038 – DHS Reorganization

This afternoon the House passed HR 4038, the DHS Accountability Enhancement Act, by a voice vote. There was only six minutes of debate on the bill.


I suspect that the bill will be taken up in the not too distant future in the Senate. It will most likely be considered in that body under their unanimous consent process; less debate and not even the easy formality of the voice vote.

Wednesday, June 8, 2016

Bills Introduced – 06-07-16

With both the House and Senate in session there were 27 bills introduced yesterday. Of those five may be of specific interest to readers of this blog:

HR 5388 To amend the Homeland Security Act of 2002 to provide for innovative research and development, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 5389 To encourage engagement between the Department of Homeland Security and technology innovators, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 5390 To amend the Homeland Security Act of 2002 to authorize the Cybersecurity and Infrastructure Protection Agency of the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10]

HR 5393 Making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2017, and for other purposes. Rep. Culberson, John Abney [R-TX-7] 

HR 5394 Making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2017, and for other purposes. Rep. Diaz-Balart, Mario [R-FL-25]

The first three bills are those that I mentioned yesterday in my post about congressional hearings. The House Homeland Security Committee will be marking up these bills today. The text for the first two of these bills is currently available from the GPO. This means that I’ll be able to give a little more detail in this post on those bills.

HR 5388 would add a new section to the Homeland Security Act of 2002 authorizing the DHS S&T Directorate to support cybersecurity research and development. Unfortunately, the bill uses the limited definition of information system that does not include control systems so no control system specific security research would be supported. And, as is usual, there are no additional funds authorized for this new program so it effectively dilutes S&T research monies.

HR 5389 would authorize DHS to establish local coordination offices in areas of the country where there were concentrations of “innovative and emerging technology developers and firms” {§2(a)(1)} for the purposes of ‘engagement’ with such entities. Such engagement efforts (again without additional funding) would include {§2(b)(2)}:

• Ensure proven innovative and emerging technologies can be included in existing and future acquisition contracts;
• Coordinate with organizations that provide venture capital to businesses, particularly small businesses and startup ventures, as appropriate, to assist the commercialization of innovative and emerging technologies that are expected to be ready for commercialization in the near term and within 36 months; and
• Address barriers to the utilization of innovative and emerging technologies and the engagement of small businesses and startup ventures in the acquisition process.

HR 5390 is the bill authorizing the re-organization and re-naming of the DHS National Protection and Programs Directorate to emphasize its role in cybersecurity.

The last two bills are spending bills. I will be watching both of them for cybersecurity provisions in both the bills and committee reports. I will, of course, also be watching the transportation bill (and report) for chemical transportation safety and security provisions.

Commentary


It would be interesting to have the Congressional Budget Office do an analysis of how much bills like HR 5388 and HR 5389 reduce funding for current programs that will have money taken from them to support the new programs outlined in these bills.

Now, I fully support keeping federal spending under control, but Congress has gotten really stupid in the way that they authorize new programs without providing any additional funding for them. The money is going to have to come from somewhere and their failure to designate where it will come from means that the public will probably never know what tradeoffs are being made to support these new efforts.


I really suspect that these bills are more political theater than actual efforts to accomplish anything.
 
/* Use this with templates/template-twocol.html */