Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Monday, September 12, 2016

Congressional Hearings – Week of 9-11-16

This week with both the House and Senate in town there will be two cybersecurity related hearings that may be of specific interest to readers of this blog. Those two hearings address information sharing and encryption.

Cybersecurity Markup


On Tuesday the House Homeland Security Committee will be holding a markup hearing that will cover a number of bills. Of specific interest will be HR 5459, Cyber Preparedness Act of 2016. Substitute language for that bill will be considered. That substitute does include the ‘missing’ definition of ‘cybersecurity risk’ taking it from 6 USC 148(a)(1). Unfortunately, that definition still uses the limited definition of ‘information system’ from 44 USC 3502(8). Thus there is still not authority provided for sharing information about control system security issues.

Encryption


The Senate Armed Services Committee will be holding a hearing on Tuesday looking at Encryption and Cyber Matters. There may be a closed session at the end of the public portion of the hearing. The witness list includes:

• Marcell J. Lettre II, Under Secretary Of Defense For Intelligence; and
• Michael S. Rogers, United States Cyber Command

On the Floor

There is one cyber related bill that will be taken up in the House today under their suspension of the rules process. House Resolution 847 addresses the perceived need for a national strategy for the Internet of Things to promote economic growth and consumer empowerment. This resolution was introduced last week, but I have not posted a review because it does not include a single mention of cybersecurity concerns. Since today’s consideration will not include an amendment process the resolution will be published without this critical area being considered. Fortunately, nothing more will come from this action, this only being a symbolic resolution.


There are news reports (for example) that we could see a continuing resolution coming out of the Senate this week. There will be lots of political gaming going on in the lead up to the Senate vote and the subsequent House vote (if it passes in the Senate).

Tuesday, June 28, 2016

Committee Hearings – Week of 6-26-16

This week only the Senate is in Washington; the House has already started their long 4th of July weekend. There are two hearings of potential interest to readers of this blog; both dealing with cybersecurity issues.

IOT and Transportation


The first hearing will be conducted this morning by the Senate Commerce, Science and Transportation Committee on “How the Internet of Things (IoT) Can Bring U.S. Transportation and Infrastructure into the 21st Century”. The witness list includes:

• Carlos Monje, DOT;
• Seleta Reynolds, Los Angeles Department of Transportation
• Jordan Kass, C.H. Robinson
• Doug Davis, Intel Corporation
• Robert Edelstein, AECOM

Cybersecurity issues may be (hopefully) raised during this hearing.

DOD – Cybersecurity and Encryption



The Senate Armed Services Committee will be holding a hearing on Thursday on “National Security Cyber and Encryption Challenges”. This is a closed hearing so we will probably hear nothing about the actual discussion here. Admiral Rogers is currently the only scheduled witness for this hearing.

Wednesday, March 23, 2016

Bills Introduced – 03-22-16

With only the House in session yesterday there were 19 bills introduced. Of those one may be of specific interest to readers of this blog:

HR 4839 To prohibit the Government from requiring any person to assist in devising a method for breaking the encryption of a wire or oral communication. Rep. Salmon, Matt [R-AZ-5] 


I doubt that there will be any ICS related tie-ins on this bill, but it will be interesting to see what definitions are used. After yesterday’s terror attacks in Belgium, I really don’t suspect that this bill has much of a chance of being considered with all of the calls for law enforcement and intelligence access to encrypted communications being so vehemently renewed.

Tuesday, March 1, 2016

Bills Introduced – 02-29-16

With both the House and Senate in session yesterday there were 16 bills introduced. Only two of those may be of specific interest to readers of this blog:

HR 4651 To establish in the legislative branch the National Commission on Security and Technology Challenges. Rep. McCaul, Michael T. [R-TX-10]

S 2604 A bill to establish in the legislative branch the National Commission on Security and Technology Challenges. Sen. Warner, Mark R. [D-VA]


Okay, these are actually going to be the same bill; known as companion bills – designed to encourage immediate consideration in both houses of Congress. This is the bill that was much discussed over the weekend, but no text is yet available.

Thursday, February 11, 2016

Bills Introduced – 02-10-16

Yesterday with both the House and Senate in session 35 bills were introduced. Of those three may be of specific interest to readers of this blog:

HR 4517 To provide for greater transparency in and user control over the treatment of data collected by mobile applications and to enhance the security of such data. Rep. Johnson, Henry C. "Hank," Jr. [D-GA-4]

HR 4528 To preempt State data security vulnerability mandates and decryption requirements. Rep. Lieu, Ted [D-CA-33]

S 2528 A bill to promote the safe manufacture, use, and transportation of lithium batteries and cells, and for other purposes. Sen. Nelson, Bill [D-FL]

The two cybersecurity bills probably do not include any control system provisions, but they do provide an interesting look at Congress’ increasing and expanding interest in cybersecurity matters. I doubt that they will get much coverage on this blog.


The wide use of lithium batteries in consumer electronics makes for real interesting transportation (particularly by air) rules due to the risk of fires from these batteries. It will be interesting to see how Congress weighs in on the situation.

Wednesday, December 23, 2009

CSSP Web Page Update 12-23-09

The DHS-CERT Control Systems Security Program (CSSP) web page has been updated. There is now a link to the Industrial Control Systems Joint Working Group’s (ICSJWG) announcement of their spring meeting in Austin, TX, as well as a link to a new publication about the use of encryption to protect industrial control systems. ICSJWG Spring Meeting The ICSJWG is a part of Critical Infrastructure Partnership Advisory Council (CIPAC). According to the meeting announcement web page the “goal of the ICSJWG is to continue and enhance the collaborative efforts of the industrial control systems stakeholder community in securing CIKR by accelerating the design, development, and deployment of secure industrial control systems.” The spring meeting will be held over April 6th thru 8th in Austin, TX. The conference will include presentations by industry leaders in control systems cybersecurity, updates from the ICSJWG Subgroups, and the Introduction to Industrial Control Systems Cybersecurity training course. Further details, including a call for papers, will be forthcoming. ICS Encryption The CSSP has introduced a new publication, the Control Systems Communications Encryption Primer. According to the Abstract the “primer addresses the use of encryption systems within control systems environments”. It addresses the problems of applying encryption techniques to industrial control systems, acknowledging that these techniques “can introduce significant design challenges as they add complexities and operational limitations to the environment”. There will be more on this Primer in a future blog.
 
/* Use this with templates/template-twocol.html */