Showing posts with label DOD. Show all posts
Showing posts with label DOD. Show all posts

Thursday, June 25, 2026

Review - S 4693 Introduced – Hybrid Space Architecture

Earlier this month, Sen Cruz (R,TX) introduced S 4693, the Nodes, Enterprise Workloads, and Hybrid Operations, Resilience, Integration, Zero-Trust, Orbital Networks (NEW HORIZON) Act, The bill would require DOD to carry out an operational pilot program to “to evaluate the use of commercially available orbital data center services and space-based cloud computing capabilities relevant to national security space and joint mission requirements”. No new funding is authorized by this bill. 

I can find no legislation in the 118th Congress that would appear to be similar to S 4693. I will be providing limited coverage of this bill under my Space Geek content offerings. Additionally, because of security requirements in the S 4693, I will be providing additional coverage of the bill. 

A press release from Cruz's office quoted the Senator as saying: 

“Data generated in space goes underutilized because of network bandwidth issues between satellites and ground stations. This legislation enables the Department of War to conduct operational testing on space-based data processing and storage, and will help to reduce latency, improve resilience, and enhance operational effectiveness across military and intelligence missions. I am proud to introduce this bill with Senator Hickenlooper.” 

Moving Forward  

Neither Cruz, nor his sole cosponsor, are members of the Senate Armed Services Committee to which this bill was assigned for consideration. This means that there is unlikely to be adequate influence to see the bill considered by that Committee. Were the Committee to take up the bill, I suspect that there might be enough bipartisan support for the bill to be ordered reported favorably, but as a standalone bill, it is unlikely to move to the floor of the Senate. A more likely path would be to include the bill’s language in the National Defense Authorization Act (NDAA) that was beginning to wend it separate ways through House and Senate. 


For more information about the provisions of this bill, including a brief commentary on some of the orbital data center issues not addressed by this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4693-introduced-hybrid-space-architecture - subscription required. 

Saturday, June 20, 2026

S 4697 – HALO Act and Cybersecurity

Earlier this month, I mentioned-in-passing the introduction of S 4697, a bill to provide for design and safety requirements for autonomous and semi-autonomous weapon systems. I do not normally spend much time following weapons development legislation, but I did read the text of this bill after it was published yesterday. And I am glad that I did, because it contains cybersecurity provisions that deserve a brief discussion here. 

Paragraph 3(d)(2) requires that an autonomous weapon system or semi-autonomous weapon system is designed with system safety, anti-tamper mechanisms, and cybersecurity in accordance with Department instructions and military standards governing cybersecurity and system safety. Those standards are not described further in this bill, nor are they further referenced by statute or regulation. While making it difficult to evaluate what standards are required, it does provide DOD with a certain amount of leeway to select the most appropriate cybersecurity standards for such weapons. 

Later, in subsection 6(e) the legislation addresses the need to periodically test these autonomous and semi-autonomous weapons. It requires DOD to conduct quarterly cyber tests and evaluations to verify that the system is resilient and survivable in contested cyberspace. It is not clear whether that quarterly testing would be done on each deployed weapon system, a statistically significant number of randomly selected systems, or a lab maintained representative system. The first option would be the most expensive and would present additional problems when dealing with currently deployed weapon systems. The second option would conform to standards for quality assurance testing, but that kind of testing is not applicable for systems that are at potential of cyber-attack. The last would be pro forma testing to ensure that there are no design issues that allow system degradation over time. 

The final item of interest here is found in subsection 10(a). That subsection notes that the requirements of this legislation do not apply to autonomous or semi-autonomous cyberspace capabilities. The term ‘cyberspace capabilities’ is not one of the terms defined in §2, but I would expect that they are referring to cyberattacks on computer systems (IT and OT) rather than kinetic attacks that could physically damage structures, equipment or personnel. Interestingly, the definitions of ‘autonomous weapon system’ and ‘semi-autonomous weapon system’ do not differentiate between kinetic and virtual attacks. This really needs additional clarification, especially where such cyberspace capability attacks result in kinetic effects because of loss of control in operational systems. 

Thursday, April 9, 2026

Review – HR 7924 Introduced – DOD Trucking Security

 Last month, Rep Stefanik (R,NY) introduced HR 7924, the Trucking Security and CCP Disclosure Act of 2026. The bill would require DOD to only use motor carriers that have been certified not be owned or controlled by, and does not have significant business relationships with, any entity identified on the most recent list of Chinese military companies. It would also require DOT’s Federal Motor Carrier Safety Administration (FMCSA) to develop and maintain a ‘Secure Defense Freight Carrier Registry’. No new funding is authorized by this legislation. 

The bill would add §2631b, Certification regarding affiliations with Chinese military companies for surface transportation contracts, to 10 USC Chapter 157. It would also add Chapter 140, Secure Defense Freight Carrier Registry, to 49 USC Subtitle IV. 

Moving Forward  

Stefanik is a member of the House Armed Services Committee to which this bill was assigned for primary consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in this bill that would engender organized opposition in that Committee.  

The other committee to which this bill was assigned, the House Transportation and Infrastructure Committee, will likely be a different situation. First there are no cosponsors for this bill assigned to that Committee, so there is no one to speak up for the bill in Committee. Second, there is going to be industry opposition to the driver vetting requirements. Motor carriers have problems keeping enough TWIC or HMI (the two TSA run vetting programs that would likely be required under DOT regulations) drivers on board for current regulatory requirements. This means that there will be some level of push back in that Committee were it to be considered. Whether it would be enough to prevent to bill from moving forward remains to be seen. 

According to a press release from Stefanik’s office, she and Sen Cotton (R,AR) are working to include the language from this bill in the upcoming FY 2027 National Defense Authorization Act. 

For more information on the provisions of the bill, including a commentary on political theater, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7924-introduced-dod-trucking-security - subscription required 

Friday, January 30, 2026

Review – HR 6631 Introduced – DOD Cybersecurity Education

Earlier this month Rep Elfreth (D,MD) introduced HR 6631, the Establishing Cyber Security Educational Programs at Academic Institutions Act. The bill would require DOD to collaborate with academic institutions to develop cybersecurity educational programs at such institutions. Collaboration with other federal agencies would ensure that the program would not compete or conflict with other such federal programs. No new funding is authorized.

Moving Forward

Both Elfreth and her sole cosponsor, Rep Luttrell (R,TX) are members of the House Armed Services Committee to hic this bill as assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition, and I would suspect that there should be bipartisan support for the legislation. We will have to wait and see if there is sufficient bipartisan support for the bill to be considered by the full House under the suspension of the rules process.

Commentary

While subsection 2(a) requires DOD to “develop cybersecurity [emphasis added] educational programs”, paragraph 2(c)(1) expands that scope to include “cyber defense, cyber operations, and cyber research”. This should be expected of a DOD sponsored program and would differentiate the overall program from those sponsored by other federal agencies. While graduates of these DOD programs could be expected to seek out DOT related jobs, or military commissions, the skills learned could still be applicable to civilian cybersecurity positions.

 

For more information on the provisions of this bill, including additional commentary on OT coverage, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6631-introduced-dod-cybersecurity - subscription required.

Wednesday, July 23, 2025

DOD Sends DFARS Cybersecurity Assessment Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOD’s Defense Acquisition Resource Center (DARC) on “Defense Acquisition Resource Center”. DOD published an interim final rule on rulemaking on September 29th, 2020. The notice of proposed rulemaking for the final rule was published on August 15th, 2024.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the contractual requirements associated with the CMMC 2.0 Framework in order to protect against the theft of intellectual property and sensitive information from the Defense Industrial Base (DIB) sector. The CMMC 2.0 Framework, as defined in Title 32 of the Code of Federal Regulations (CFR), assesses compliance with applicable information security requirements. This rule provides DoD with assurances that a DIB contractor can adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.”

I will probably not be covering this final rule in any detail, but I will at least announce its publication in the appropriate ‘Short Takes’ post.

Monday, January 6, 2025

OMB Approves Revised DIB Incident Reporting ICR – 1-3-24

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision of an information collection request from DOD on “DoD's Defense Industrial Base (DIB) Cybersecurity (CS) Activities Cyber Incident Reporting”. This ICR supports the incident reporting requirements of 10 USC 393.

The table below shows the revised burden estimate approved by OIRA:

The revised burden estimate is based upon the actual reporting conducted in 2021, 2022, and 2023.

Monday, September 16, 2024

Review - OMB Approves CMMC Documents – 9-13-24

On Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved nine documents related to updates to the DOD’s Cybersecurity Maturity Model Certification program. The documents include:

Final rule,

CMMC Model Overview

CMMC Assessment Guides (3 levels),

CMMC Scoping Guides (3 levels), and

CMMC Hashing Guide.                       

DOD continues to maintain their CMMC website, but notes that: “Updates to the CMMC website will be limited during the CMMC rulemaking process.”

I expect that the Final Rule and supporting guidance documents will be published in the Federal Register in the next week or two.

 

For more details about these CMMC documents, including links to the NPRM versions of the documents, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-cmmc-documents-9-13 - subscription required.

Thursday, August 8, 2024

OMB Approves DOD/DARC Cybersecurity Assessment NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking on “Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)”. The NPRM was sent to OIRA on May 15th, 2024. This rulemaking would amend an interim final rule that was published on September 29th, 2020.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“DoD is amending an interim rule to implement the CMMC framework 2.0 in order to protect against the theft of intellectual property and sensitive information from the Defense Industrial Base (DIB) sector. The CMMC framework, as defined in Title 32 of the Code of Federal Regulations (CFR), assesses compliance with applicable information security requirements. This rule provides the Department with assurances that a DIB contractor can adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.”

I am not likely to fully cover this rulemaking in this blog. I will, however, include a link to its publication in the appropriate ‘Short Takes’ post.

Friday, June 28, 2024

DOD Send 9 CMMC Model Guidance Documents to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received nine separate guidance documents for the DOD’s “Cybersecurity Maturity Model Certification (CMMC) Program”.  Those documents included:

Cybersecurity Maturity Model Certification (CMMC) Program,

CMMC Assessment Guide - Level 1,

CMMC Assessment Guide - Level 2,

CMMC Assessment Guide - Level 3,

CMMC Hashing Guide,

CMMC Model Overview,

CMMC Scoping Guide - Level 1,

CMMC Scoping Guide - Level 2,

CMMC Scoping Guide - Level 3

Guidance documents are not typically listed in the Unified Agenda, so there is no official abstract available for these publications. DOD has updated their CMMC website to provide an overview of the program revisions being proposed.

Wednesday, February 7, 2024

OMB Approves DOD Threat Information Sharing Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for DOD on “Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities”. The rulemaking was submitted to OIRA on December 7th, 2023. The notice of proposed rulemaking was published on May 11th, 2023.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“The DIB CS Program currently provides cyber threat information to cleared defense contractors. Proposed revisions would allow all defense contractors who process, store, develop, or transit DoD controlled unclassified information to be eligible for the program and to receive cyber threat information. Expanding participation will allow a broader community of defense contractors to participate in the DIB CS Program and is in alignment with the National Defense Strategy.”

We may see this published later this week in the Federal Register, but it is more likely to appear next week.

Tuesday, January 2, 2024

Pending Rulemakings of Interest – 1-2-24

Starting of a new year, it seems like a good time to take a look back at the rulemakings of interest here that are still pending in the OMB’s Office of Information and Regulatory Affairs (OIRA). The table below provides a listing of such rulemakings that I am watching (though that may not mean that there will be detailed reporting on them when published).

Received
Date

RIN

Agency

Rule Title

Status

11/13/2023

1625-AC77

DHS/ USCG

Cybersecurity in the Marine Transportation System

NPRM

04/11/2023

1670-AA01

DHS/ CISA

Chemical Facility Anti-Terrorism Standards (CFATS)

NPRM

12/14/2023

2126-AC17

DOT/ FMCSA

Motor Carrier Operation of Automated Driving System (ADS)-Equipped Commercial Motor Vehicles

NPRM

11/27/2023

0694-AI94

DOC/ BIS

Implementation of Additional Export Controls: Certain Advanced Computing Items and Semiconductor Manufacturing Items; Supercomputer and Semiconductor End Use; Updates to the Controls and Corrections

Final

1/03/2023

0694-AJ43

DOC/ BIS

Proposed Amendments to End-Use and End-User Based Export Controls, Including U.S. Persons Activities Controls: Military and Intelligence End Uses and End Users.

IFR?

10/31/2023

0694-AI45

DOC/ BIS

Revision of Licensing Requirements of Certain Cameras, Systems, or Related Components

IFR

08/16/2023

0694-AJ35

DOC/ BIS

Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities

NPRM

12/15/2023

2060-AU37

EPA/ OAR

National Emission Standards for Hazardous Air Pollutants: Ethylene Oxide Commercial Sterilization and Fumigation Operations

NPRM

12/12/2023

2070-AK73

EPA/ OCSPP

1-Bromopropane (1-BP); Regulation Under the Toxic Substances Control Act (TSCA)

NPRM

11/14/2023

2070-AK64

EPA/ OCSPP

Fees for the Administration of the Toxic Substances Control Act (TSCA)

Final

11/02/2023

2070-AK85

EPA/ OCSPP

N-Methylpyrrolidone (NMP); Regulation under the Toxic Substances Control Act (TSCA)

NPRM

10/11/2023

2050-AH17

EPA/ OLEM

Clean Water Act Hazardous Substance Facility Response Plans

Final

09/25/2023

2050-AH22

EPA/ OLEM

Accidental Release Prevention Requirements: Risk Management Program Under the Clean Air Act; Safer Communities by Chemical Accident Prevention

Final

12/07/2023

0790-AK86

DOD/ OS

Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities

Final

  

 
/* Use this with templates/template-twocol.html */