Showing posts with label DOD Authorization. Show all posts
Showing posts with label DOD Authorization. Show all posts

Friday, April 12, 2019

Bills Introduced – 04-11-19


Yesterday, with just the Senate in Washington (the House has already departed on their Easter Recess), there were 94 bills introduced. Only one of those bills will receive future coverage in this blog:

S 1215 A bill to authorize appropriations for fiscal year 2020 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sen. Inhofe, James M. [R-OK] 

Wednesday, April 29, 2015

Bills Introduced – 04-28-15

Seventy-four bills were introduced in the House and Senate yesterday. Three of those may be of specific interest to readers of this blog:

HR 2074 To enhance rail safety and provide for the safe transport of hazardous materials, and for other purposes. Rep. Norcross, Donald [D-NJ-1] 

S 1114 A bill to enhance rail safety and provide for the safe transport of hazardous materials, and for other purposes. Sen. Menendez, Robert [D-NJ]

S 1118 A bill to authorize appropriations for fiscal year 2016 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal... Sen. McCain, John [R-AZ]

It looks like the first two bills are companion measures that may specifically address crude oil train issues. It may be a wider hazmat transportation emergency response bill based upon the vinyl chloride derailment a couple of years ago in New Jersey.


S 1118 is the Senate version of the annual DOD authorization bill. The House version (HR 1735) did not contain any cybersecurity provisions. We will have to wait and see if the Senate version does.

Monday, December 9, 2013

Congressional Hearings – Week of 12-8-13

This may be the last week that both Houses of Congress are in session this year and there are a lot of things yet to be done. This only includes one hearing of potential specific interest to readers of this blog and that is an oversight hearing on the Coast Guard. There are a couple of on-going Conference Committee meetings that may or may not be meeting this week.

Coast Guard Hearing

The Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will be holding a hearing Wednesday looking at “Coast Guard Mission Execution: How is the Coast Guard Meeting Its Mission Goals?” No witness list has yet been published so I can only guess if the MTSA program will be addressed at this hearing; probably not.

Senate Floor Action

The Senate may or may not get its collective act together and take action on S 1197, the FY 2014 DOD Authorization bill. This got caught up in the application of the nuclear option on nomination filibusters before Thanksgiving. We may see some interesting legislative shenanigans used to get this passed before the House and Senate adjourn for the year.

House Floor Action


If conference committees can complete their work on time then the House (and Senate) may get a chance to take final action on a couple of interesting bills this week, all of them dealing with spending or authorizations. The Ag Authorization bill (HR 2642) and a Budget Resolution (H. Con. Res 25) may get done, but I’m not holding my breath. And of course S 1197 may come their way yet under one bill number or another.

And, of course, we are likely to see a new continuing resolution introduced this week.

Sunday, June 9, 2013

HR 1960 Reported in House – FY 2014 NDA

On Friday the House Armed Services Committee reported (though the House was not in session) HR 1960, the National Defense Authorization Act for Fiscal Year 2014. A copy of the actual report is not currently available at the GPO site, but it is available on the Library of Congress site by clicking on the report number.

Cybersecurity

I mentioned in an earlier post that the version of HR 1960 that was introduced did not have any cybersecurity language, but that that might change during the ‘legislative process’. That is certainly the case now. The following cybersecurity related sections are now in the bill:

Sec. 214. Limitation on availability of funds for defensive cyberspace operations of the Air Force.
Sec. 811. Additional contractor responsibilities in regulations relating to detection and avoidance of counterfeit electronic parts.
Sec. 812. Amendments relating to detection and avoidance of counterfeit electronic parts.
Subtitle D—Cyberspace-Related Matters
Sec. 931. Modification of requirement for inventory of Department of Defense tactical data link systems.
Sec. 932. Defense Science Board assessment of United States Cyber Command.
Sec. 933. Mission analysis for cyber operations of Department of Defense.
Sec. 934. Notification of investigations related to compromise of critical program information.
Sec. 935. Additional requirements relating to the software licenses of the Department of Defense.

Section 214 is probably the most significant in the terms of money in that it withholds 10% of the Air Force FY 2014 funding for procurement, RDT&E, and Defensive Cyberspace Operations until 30 days after the Secretary of the Air Force submits a report to Congress on the Application Software Assurance Center of Excellence. No additional information on this section is available in the Committee Report.

Section 932 will probably have a longer term impact on DOD cyber-operations. A major component of this study will be the review of the command relationship between the United States Cyber Command and the National Security Agency since the Commander and the Director are one and the same person. The Defense Science Board is specifically tasked with looking at that relationship and:

• The positive and negative impact on the Command resulting from a single individual simultaneously serving as the Commander of the United States Cyber Command and the Director of the National Security Agency {§932(b)(1)(A)};
• How the respective oversight activities of the Commander and the Director affect the ability of each entity to complete the respective missions of such entity {§932(b)(1)(B)};
• The dependencies of the Command and the Agency on one another {§932(b)(1)(C)};
• The ability of the existing management structure of the Command and the Agency to identify and adequately address potential conflicts of interest {§932(b)(1)(D)};
• The ability of the Department of Defense to train and develop, through professional assignment, individuals with the appropriate subject-matter expertise and management experience to support both the cyber operations missions of the Command and the signals intelligence missions of the Agency {§932(b)(1)(D)}.

The importance of this report is further highlighted by the requirement of a follow-up report (within 30 days) by the Secretary of Defense and the Director of National Intelligence on their assessment of the situation {§932(c)(2)}.

The report to Congress required by §933 sounds fairly straight forward when reading the legislative language. It is when you get to the discussion of the section in the Committee Report that the full import of this report. That discussion makes it clear that ‘cyber-operations’ are not limited to nice, clean digital attacks, but incorporates the full spectrum of military response including “a mix of forces necessary to conduct assured operations, including systems such as penetrating bombers, submarines with long range cruise missiles, Conventional Prompt Global Strike (CPGS), and survivable senior leadership command and control.”

A portion of this report seems to be directly targeted at the provisions of HR 1640 and S 658, the Cyber Warrior Act of 2013. The legislative language requires the Chief of the National Guard Bureau to report to Congress on his “assessment of the role of the National Guard in supporting the cyber operations mission of the Department of Defense” {§933(d)}. The Committee report language goes much further:

“While the committee supports these considerations, it is also concerned that current legislative proposals to dictate National Guard units for each of the states and territories is premature and may be detrimental to the overall national effort. In addition to the hefty price tag, which is estimated to be about $400.0 million per year, current proposals only address National Guard participation and do not include the Reserve Component. Whereas only the Army and the Air Force have National Guard units, all of the military services have Reserve Components that have unique authorities and capabilities that should be addressed by the national effort. The committee believes that more time is needed to evaluate full participation of the Reserve Components, including the implications and limitations of using National Guard forces in a `title 32' capacity, before broader action is taken. The committee encourages the Department to examine these issues in the course of the mission analysis required by this section.”

Interestingly, the reports required by both §932 and §933 are required to be prepared in ‘unclassified form’ (with classified annexes, of course). With the requirement in this bill (§1078) to post such DOD reports on a public web site, we may actually get a chance to see these reports.

Chemical Safety

There is an oddly out-of-place amendment to the Toxic Substances Control Act. Section 315 of this bill would amend 15 USC 2602(2)(B)(v) to expand the TSCA firearms exemption specifically to “any component of such an article (including, without limitation, shot, bullets and other projectiles, propellants when manufactured for or used in such an article, and primers)”. This is probably due to efforts by some environmentalists to require DOD to change their ammunition to exclude such toxic material as lead.

Moving Forward

The House Rules Committee will be holding two hearings this week to define the Rule for the consideration of HR 1960 before the House later this week. The first hearing will be on Tuesday to craft the rule. The second hearing will be Wednesday afternoon to determine what amendments will be offered on the floor. So there may still be changes to the cybersecurity provisions of this bill before it is voted upon by the House.


This bill will certainly pass in the House, historically by a substantially bipartisan vote. A different version will be considered in the Senate and then a compromise version will be worked out in Conference.

Tuesday, December 4, 2012

Senate Passes S 3254


This evening the Senate passed S 3254 the National Defense Authorization Act FY 2013, by a vote of 98-0. As I noted in earlier blog posts, this bill has a number of cybersecurity and cyber warfare provisions. It will now move to the House for consideration, possibly as early as this week.

Monday, June 11, 2012

S 3254 Introduced – DOD Authorization


This last week Sen. Levin (D,MI) introduced S 3254, the  National Defense Authorization Act for Fiscal Year 2013. While, as expected, there is nothing in this bill that directly addresses ICS security issues, there are some issues raised in Title IX of Division A in the bill that might be of interest to the cybersecurity community. Additional issues are raised in the Committee Report.

Interconnected Networks


Section 923 of the bill requires the Secretary of Defense take actions to “to substantially reduce the number of sub-networks and network enclaves across the Department of Defense, and the associated security and access management controls” {§923(a)}. There are a number of good reasons given for requiring this action; they include:

• Visibility for the United States Cyber Command in the operational and security status of all networks, network equipment, and computers.

• Elimination of redundant network security infrastructure and personnel.

• Rationalization and consolidation of cyber attack detection, diagnosis, and response resources, and elimination of gaps in security coverage.

• Reduction of barriers to information sharing and enhancement of the capacity to rapidly create collaborative communities of interest.

• Enhancement of access to information through authentication-based and identity-based access controls.

• Enhancement of the capacity to deploy, and achieve access to, enterprise-level services.

• Separation of server and end-user device computing to facilitate server and data center consolidation and a more secure tiered and zoned network architecture.

The one thing that seems to be missing from this reasoning is that if Cyber Command has easy ‘visibility’ of all of these networks, it means that an adversary who successfully penetrates one of these networks can achieve that same visibility. Just think about a single low-ranking intelligence analyst’s unfettered access that lead to Wiki Leaks.

Host Based Cybersecurity


Section 924 requires the DOD CIO to “develop a strategy to acquire next-generation host-based cybersecurity tools and capabilities” {§924(a)}. This next-gen capability should eliminate the current problems with signature based threat detection techniques. An important part of this new system is that it be expandable to include more than just intrusion detection. That potential tool set, yet to be developed, should include {§924(b)(2)}:

• Insider threat detection;

• Continuous monitoring and configuration management;

• Remediation following infections; and

• Protection techniques that do not rely on detection of the attack, such as virtualization, and diversification of attack surfaces.

An additional requirement is that it should be “designed for ease of deployment to potentially millions of host devices of tailored security solutions depending on need and risk, and to be compatible with cloud-based, thin-client, and virtualized environments as well as battlefield devices and weapons systems” {§924(b)(2)}.

While this is the holy grail of security systems, if anyone has the resources to get one developed that meets these requirements, it will be DOD and DARPA. Even if they only half-succeed, it will be a major accomplishment. The only question is since such a system will undoubtedly classified, will the Government allow its use by critical infrastructure that needs the same level of protection against similar attackers.

Improving Software Security


While an improved cybersecurity system will go a long way to protecting DOD computer systems, they will only be as secure as the software that runs on those systems. Section 925 would require an improved software acquisition process. This new process would require:

• Update of development and acquisition models {§(925(b)};

• Requirements for secure code development practices {§(925(c)}; and

• Verification of effective implementation {§(925(d)}.

There is an interesting sub-paragraph to this section that has the misleading title of “Study on additional means of improving software security” {§(925(e)}. What it is really being required is a study to look at ways of ensuring that procured software meets the security needs of the Department. The methods suggested include:

• Liability for defects or vulnerabilities in software code.

• So-called ‘‘clawback’’ provisions on earned fees that enable the Department to recoup funds for security vulnerabilities discovered after software is delivered.

• Exemption from liability for rigorous conformance with secure development processes.

• Warranties against software defects and vulnerabilities.

Because of the size of the DOD purchasing pocket book this could be a change in the way that software security is addressed in the market place. If these types of actions become the standards for software security assurance, there will be a wholesale change in the way software is developed and sold; probably an over due change.

Cyber-Operations Facilities


Anyone that has spent time in the military knows that all services have extensive physical facilities where the weapons of war are tested, evaluated, and most importantly where their use is practiced. The Senate Armed Services Committee takes the Department to task in its report for “its lack of attention to its cyber ranges” (pg 67; Adobe 87). An extensive discussion covering three pages of the Committee Report identifies a number of instances where funding and resourcing of existing and developing cyber ranges have declined in recent years.

The Committee requires DOD to prepare a report to Congress that identifies a central management structure for the oversight of cyber range “infrastructure, funding and personnel” (pg 69; Adobe 91). The report will also identify the sources of funding and resources for the modernization and operation of the cyber ranges.

Cybersecurity Personnel


Everyone knows that there is a severe shortage of personnel with a cybersecurity background. The Department of Defense has a large number of personnel slots that need to be filled in this area. The Committee Report notes that “that every effort must be made to successfully recruit, train, and motivate for military service young people with computer skills to operate and defend the Department of Defense’s computer networks and infrastructure” (pg 117; Adobe 139).

The Report requires DOD to provide a ‘letter report’ to Congress within 180 days of this legislation becoming law that:

• Describes current programs for identifying, recruiting, training, and retaining young people with outstanding computer skills for military service;

• Reports any human capital or specialty shortfalls in cyber defense career fields; and

• Describes bonuses or any non-traditional or non-standard recruiting practices that are employed by the military services to locate and recruit young people for cyber-related career fields.

Development of Cybersecurity Expertise


The Committee Report (pg 180, Adobe 202) “encourages the Department of Defense to continue to support multi-disciplinary programs of study and research that focus on developing U.S. cyber security expertise and tackling vital cyber security issues”. Included in those issues, the Committee specifically included the protection of critical infrastructure “which the Department would be called upon to defend in the event of a cyber attack on the United States”.

What is not clear from this discussion is how the Senator’s would expect DOD to impose themselves between such critical infrastructure and cyber-attackers.

Friday, April 6, 2012

HR 4310 Introduced – DOD Authorization Bill

Just before Congress adjourned for their Easter Recess Rep McKeon (R,CA) introduced HR 4310, the National Defense Authorization Act for Fiscal Year 2013 and the GPO actually published the bill yesterday. This is one of those bills that I would expect to watch for cybersecurity provisions because of the DOD responsibilities in that field.

As with the FY 2012 bill we do not see any cybersecurity provisions in the initial iteration of the language of HR 4310. The cybersecurity programs in DOD are relatively small and are easily buried in the large dollar amounts authorized for the Department. We are very likely to see specific cybersecurity provisions added during the markup process and the House Armed Services Committee report on this bill may provide some funding details on larger cybersecurity programs.

In short, this is a bill to be watched.

Tuesday, December 6, 2011

S 1867 Becomes HR 1540

I missed this last Friday when I was looking at the Congressional Record for Thursday. After passing S 1867, the Senate also passed HR 1540, the House passed version of the DOD authorization bill. The passage of HR 1540 was one of those political games that Congress frequently plays; the Senate substituted the language of the just passed S 1867 for the language of the House version of the bill. BTW: no vote, no debate, just maneuvering.

Typically the Senate does this before the debate on a bill starts, but it achieves the same end. HR 1540 will go to Conference unless the House agrees to accept the Senate version of the bill. He House will take this up on the floor tomorrow. According to the Majority Leader's web site it is listed as “Motion to go to Conference on H.R. 1540” so it certainly looks like this will go to Conference. The floor action in the House will go quick tomorrow.

The new Senate language for HR 1540 was published in yesterday’s Congressional Record. It is also available on the GPO site. We’ll have to wait to see what comes out of the Conference Committee.

Saturday, November 19, 2011

S 1867 Introduced – DOD Authorization Bill

The Senate has apparently given up work on HR 2354 due to internal political squabbles and has now started work on the DOD authorization bill for FY 2012. Not content with the three bills that had been introduced in the Senate earlier this year covering the same subject (S 0981, S 1253, and S 1254) Sen. Levin (D,MI) this week introduced S 1867, the National Defense Authorization Act for Fiscal Year 2012.

BTW: Levin, the Chair of the Senate Armed Forces Committee, introduced all three previous versions of this bill.

Cybersecurity Provisions


There are four cyber security provisions in this new bill, but they are substantially the same as those found in S 1253. I discussed them in some detail in my blog on that bill’s introduction. The section titles are:

• Section 913. Review to identify interference with national security global positioning system receivers by commercial communications services [LightSquared provision];

• Section 931. Strategy to acquire capabilities to detect previously unknown cyber-attacks;

• Section 932. Program in support of department of defense policy on sustaining and expanding information sharing [WikiLeaks prevention]; and

• Section 1076. Study on the recruitment, retention, and development of cyberspace experts.

I haven’t had a chance to peruse the Committee Report on this new bill yet, but I would bet it contains substantially the same cyber security discussions found in the report from the S 1253. I did a write-up of that earlier report that might be interesting to re-read here.

Amendments to S 1867


As one would expect for an authorization bill for an agency as large and controversial as DOD, there are a lot of amendments that have been introduced for this bill. I’ll probably be doing a couple of blog posts on the amendments that would affect the chemical and cyber security communities.

One, however, did catch my attention as I was scanning the list; Amendment S 1229, introduced Friday by Sen. McCain (R,AZ). It would add §1088, “Cybersecurity collaboration between the Department of Defense and the Department of Homeland Security”, which would define the cybersecurity relationship between DOD and DHS.

There are not a lot of details in this amendment, but it would require the two departments to exchange officials to aid in the coordination of their efforts.

Wednesday, June 1, 2011

S 981 Introduced – DOD Authorization

Back on May 12th Sen. Levin (D, MI) introduced S 981, the National Defense Authorization Act for Fiscal Year 2012, but it only became available through the GPO website last Thursday. Alert readers will recognize the title of this bill as being the same as that found on HR 1540. This is not a companion bill as there are significant differences between the two bills.

Again I’ve looked at the bill looking for cyber security provisions, but, as I found in HR 1540 there are none listed. I would expect that the Armed Forces Committee Report when it is reported might have cyber security provisions. As with the floor debate of HR 1540, it would not be unexpected to see cyber security provisions added to this bill given the military’s role in protecting the nation’s cyber systems from foreign attack.
 
/* Use this with templates/template-twocol.html */