Showing posts with label DOE Cybersecurity. Show all posts
Showing posts with label DOE Cybersecurity. Show all posts

Tuesday, August 13, 2019

S 2095 – DOE Cybersecurity


Last month Sen. Gardner (R,CO) introduced S 2095, the Enhancing Grid Security through Public-Private Partnerships Act. The bill would require the Department of Energy (DOE) to establish a voluntary security program for electric utilities and provide a report to Congress on cybersecurity of electricity distribution systems. This bill is very similar to HR 359, which was ordered favorably reported by the House Energy and Commerce Committee last month.

Differences in the Bills


There are a number of differences between the two bills. Many of them are strictly structural; the definitions are in §2 of the Senate bill and §5 of the House bill. Others are editorial in nature; adding ‘of a State’ following ‘political subdivision’ in the Senate version. These changes are of interest only to grammarians, lawyers and judges.

Other changes are of more consequence. The senate bill does not include the section on electricity interruption information that was included as §4 in the House bill. There are two changes (an addition and a deletion) to the voluntary security program described in §3 of S 2095 (see below). Finally, the Senate bill adds a 1 year deadline for the required report to Congress on cybersecurity and distribution systems.

Security Program


The security program in this bill was originally introduced in HR 5240 in the 115th Congress. That program would have required DOE to:

• Develop, and provide for voluntary implementation of, maturity models, self-assessments, and auditing methods for assessing the physical security and cybersecurity of electric utilities;
• Provide training to electric utilities to address and mitigate cybersecurity supply chain management risks;
• Increase opportunities for sharing best practices and data collection within the electric sector;
• Assist with cybersecurity training for electric utilities;
• Advance the cybersecurity of third-party vendors that work in partnerships with electric utilities; and
• Provide technical assistance for electric utilities subject to the program.

S 2095 modifies that program by removing the requirement for DOE to assist with cybersecurity training. This bill would substitute a requirement for DOE to “to assist with threat assessment and cybersecurity training for electric utilities” {§3(a)(2)}.

Moving Forward


Neither Booker nor his single cosponsor {Sen. Bennet (D,CO)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. With no representation on that Committee it is unlikely that this bill will receive consideration.

The House version of the bill received bipartisan support in the markup of the bill last month in the House Energy and Commerce Committee. I suspect that this bill would also receive bipartisan support if it were considered in Committee. The changes described above would have no significant bearing on the support this bill would receive.

NOTE on HR 359


In my post on the introduction of HR 359 I noted that it would be considered by the full House on January 11th, 2019 under the suspension of the rules process. This had been scheduled, along with the consideration of two other cybersecurity bills, HR 360 and HR 370. None of those bills were considered.

It looked like the new Democratic leadership was going to act quickly (if somewhat inadequately) on some critical infrastructure cybersecurity measures. It did not happen for reason which have not been made public. With that initial quick intent to pass these three cybersecurity bills, it is odd that no action was taken in Committee until a subcommittee markup (with no amendments) in May and full Committee markup in July.

The bipartisan support for these bills in Committee would seem to indicate that the bills would easily pass in the House under the suspension of the rule process. I would have thought that the initial pass on considering these bills indicated that there was an intent to revise these bills to include some sort of regulatory authority to insure that facilities complied with the ‘voluntary measures’ included in the bill. The lack of amendments in Committee would seem to indicate that the leadership has decided that such cybersecurity mandates were not going to make it to the President’s desk.

I suspect that all three House bills will be considered by the full House in September.

Friday, July 12, 2019

Bills Introduced – 07-11-19


Yesterday with both the House and Senate in session there were 64 bills introduced. Four of those bills may see additional coverage in this blog:

HR 3699 To codify the Transportation Security Administration's responsibility relating to securing pipelines against cybersecurity threats, acts of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of pipelines, and for other purposes. Rep. Cleaver, Emanuel [D-MO-5]

HR 3710 To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 3714 To amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security. Rep. Deutch, Theodore E. [D-FL-22]

S 2095 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threat to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO]

I will be watching HR 3710 and S 2095 for specific language referring to industrial control system security issues. For HR 3714 I will be watching for general cybersecurity language while hoping for ICS mentions.

Monday, January 14, 2019

HR 359 Introduced – DOE Cybersecurity


Last week Rep. McNerney (D,CA) introduced HR 359, the Enhancing Grid Security through Public-Private Partnerships Act. This bill is nearly identical to HR 5240 that was introduced last session and cleared through the House Energy and Commerce Committee without modification. While the earlier bill did not make it to the floor of the House, HR 359 will be considered under suspension of rules tomorrow.

The only differences between the two bills in that HR 359 now includes ‘the Electric Reliability Organization’ in the §2(a) list of organizations with which the Secretary of Energy will consult in developing the program to promote and advance physical security and cybersecurity of electric utilities. The second and final change is that the new bill includes a definition f ‘the Electric Reliability Organization’ in the list of definitions in §5. Needless to say, these changes are inconsequential.

The House leadership expects that this bill will pass with substantial bipartisan support; the same support that it received in Committee last session.


Friday, November 30, 2018

Bills Introduced – 11-29-18


Yesterday with both the House and Senate in Washington, there were 52 bills introduced. Three of those bills may see future coverage in this blog:

HR 7188 To extend by two years the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 7192 To enhance the early warning reporting requirements for motor vehicle manufacturers, and for other purposes. Rep. Cartwright, Matt [D-PA-17] 

S 3677 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO] 

With the Chair and Ranking Member of both the House Homeland Security and House Energy and Commerce Committees as cosponsors, HR 7188 will move to the floor of the House early next week. It will be interesting to see what “and for other purposes” are included in this bill. Needless to say this means that HR 6992 and S 3405 are effectively dead.

I would normally be watching HR 7192 specific cybersecurity reporting requirements, but this bill has little to no chance of being considered in the 115th Congress. We may see this again next year.

S 3677 could be interesting, but it will not see any action this year. Again, this will probably be reintroduced next year.

Monday, March 12, 2018

HR 5174 Introduced – DOE Cybersecurity Responsibilities


Last week Rep. Walberg (R,MI) introduced HR 5174, the Energy Emergency Leadership Act. The bill would generally set the Department responsibilities for energy emergency response and energy cybersecurity.

Responsibilities


The bill amends 42 USC 7133 which identifies the general function of the eight Assistant Secretaries in the Department of Energy. It adds a twelfth activity; energy emergency and energy security functions. These include “responsibilities with respect to infra9
structure, cybersecurity, emerging threats, supply, and emergency planning, coordination, response, and restoration” {§7133(a)(12(A)}. This also encompasses responsibility for providing, upon request, “technical assistance, support, and response capabilities with respect to energy security threats, risks, and incidents" {§7133(a)(12(B)} to State, local, or tribal governments or energy sector entities.

Moving Forward


This bill is currently scheduled for markup on Wednesday. Walberg’s cosponsor {Rep. Rush (D,IL) is the Ranking Member of the Energy Subcommittee to which this bill has been assigned for consideration. This almost certainly means that this bill will receive substantial bipartisan support in Wednesday’s hearing, future Energy and Commerce Committee hearings and probably on the floor of the whole House. There is nothing in this bill that would drive significant opposition.

Commentary


The one thing that is certainly missing from this bill is an effective definition of ‘cybersecurity’. Because of the nature of scope of DOE operations, the definition would clearly need to include operations technology and its attendant control systems. Again, this bill would be a good place to add the definitions that I have previously proposed (here for example). I would add a new paragraph (c):

(c) Definitions- In this chapter (42 USC Chapter 84, Department of Energy) the following definitions apply:

(1) The term ‘information system’ has the meaning given the term in section 3502 of title 44;

(2) The term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes including but not limited to; energy production, transportation, access control, and facility environmental controls;

(3) The term ‘cybersecurity risk’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;

(4) The term ‘incident’ means an occurrence that actually, or imminently jeopardizes, without lawful authority:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;

This would then require changing the word ‘cybersecurity’ in paragraph 12(A) to ‘cybersecurity risk’. This would ensure that the assigned Assistant Secretary was focused on the risk to information systems and control systems, not the mechanics of system security.

 
/* Use this with templates/template-twocol.html */