Showing posts with label FAA Authorization. Show all posts
Showing posts with label FAA Authorization. Show all posts

Monday, July 31, 2023

Review - HR 3935 Received in Senate – FAA Reauthorization

Last week, HR 3935, the Securing Growth and Robust Leadership in American Aviation Act (informally the FAA reauthorization act) officially arrived in the Senate. The delay was due to incorporating amendments that were adopted during the debate on the bill the previous week. Several new provisions were added to the bill before it passed in the House by a strongly bipartisan vote of 351 to 69.

New Sections

There were a large number of new sections added, both during the debate and in the House Rules Committee which added language from H 3559, FAA Research and Development Act of 2023, and HR 3796, To provide for the extension of taxes funding the Airport and Airway Trust Fund and to require the designation of certain airports as ports of entry. Newly added sections of potential interest here include:

§635. Protection of public gatherings

§853. Sense of Congress encouraging the FAA to welcome the use of unmanned aerial vehicles.

§858. Assessment by Inspector General of the Department of Transportation of counter-UAS system operations.

§871. Prohibition on procurement of foreign-made unmanned aircraft systems

§1146. Report on aviation cybersecurity directives.

Moving Forward

This is one of the perennial, ‘must pass’ bills for Congress. The Senate’s Commerce, Science, and Transportation Committee will craft their own version of the legislation. They will typically then take up the House bill, with one of the first amendments being considered being substitute language taken from the Senate version of the bill. The House will then have a chance to take up the revised language, but generally, the House will demand their version of the language. To resolve the differences, a conference committee will be formed to develop a consensus version of the bill, which will then go back to the two bodies for a final vote in each house of Congress.

The bipartisan vote for HR 3935 in the House bodes well for its eventual passage.

 

For more details about the changes made in the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3935-received-in-senate - subscription required.

Monday, October 1, 2018

Committee Hearings – Week of 09-30-18


This week with just the Senate in Washington (the House is officially on the campaign trail and is unlikely to be in Washington until after the November election) there is a substantially lower number of hearings being held. One hearing of note is the Senate version of the review of the implementation of positive train control (PTC).

PTC Implementation


On Wednesday the Senate Commerce, Science, and Transportation Committee will conduct an oversight hearing on the “Implementation of Positive Train Control”. The witness list will include:

• Ronald Batory, Federal Railroad Administration;
• Susan Fleming, Government Accountability Office;
• Kevin Corbett, NJ Transit; and
Scot Naparstek, Amtrak

This will essentially be a replay of the House hearing that was held a couple of weeks ago. The GAO report from that hearing provides an excellent summary of the PTC program and the problems that the industry is having with implementing this technological nightmare. It also points out some of the problems that the FRA is having (and will continue to have) with the oversight of program. The conclusion from that report will certainly raise the ire of everyone that saw the PTC program as the solution to deadly train wrecks, but were not really read in on what the program was actually attempting to do; that ‘everyone’ includes a whole slew of congresscritters.

On the Floor


On Friday the Senate began their consideration of the House amendment to HR 302 that I mentioned last week. This amended bill will provide a two-year authorization for the FAA. It also includes a number of other (and wildly unrelated) measures designed to ensure that the bill will be considered and ultimately approved. The most interesting provision is found in Division H of the bill; the Preventing Emerging Threats Act of 2018, the counter-UAS language that I have discussed elsewhere.

The Senate is scheduled to take up the bill this afternoon with a cloture vote scheduled for 5:30. It looks like the Senate will stay in session tonight until the bill is passed. Sharp-eyed readers will note that the link above shows that a number of inconsequential amendments were agreed to on HR 502 before the announcement was made concerning this week’s process on HR 302. This is a rather typical example of ‘filling the amendment tree’ to allow the Majority Leader to control the debate on a bill while complying with Senate rules requiring consideration of amendments. No other amendments have been offered on this bill.

Thursday, September 27, 2018

Bills Introduced – 09-26-18


Yesterday with both the House and Senate in Session (and the election recess quickly approaching) there were 61 bills introduced. Of those, three may receive additional attention in this blog:

HR 6913 To direct the Secretary of Commerce to establish a working group to recommend to Congress a definition of blockchain technology, and for other purposes. Rep. Guthrie, Brett [R-KY-2] 

H Res 1082 Providing for the concurrence by the House in the Senate amendment to H.R. 302, with an amendment. Rep. Williams, Roger [R-TX-25]

S 3513 A bill to establish a deadline for the establishment of a process to allow applicants to petition the Administrator of the Federal Aviation Administration to prohibit or restrict the operation of an unmanned aircraft in close proximity to a fixed site facility. Sen. Cortez Masto, Catherine [D-NV]

With the exception of H Res 1082 (which passed in the House yesterday by a vote of 398 to 23) it is unlikely that these bills will see any action between now and the end of the session in December.

The resolution is the vehicle for changing HR 302 into the FAA Reauthorization Act (plus boondoggles) that I described on Tuesday. I presume that the actual text of the amendment is what I linked to in that post, but we will have to wait and see what is actually included in the official text to be sure.

I am assuming that the ‘blockchain’ definition being requested in HR 6913 will be related to cybersecurity, but it is really to early to be sure. I am not sure for what use Guthrie is intending the definition, but this will be interesting to watch, if and when this is addressed.

S 3513 becomes potentially important with yesterday’s inclusion of the ‘Preventing Emerging Threats Act of 2018’ language in the revised HR 302. Declaring UAS ‘no fly zones’ around critical infrastructure will be ineffective unless Congress gets around to extending authorization to intercept violating UAS, but this could be an important first step; again if and when this is passed.

Friday, April 27, 2018

HR 4 Further Amended and Passed in House – FAA Authorization


Today the House finished consideration of the amendments cleared by the House Rules Committee for HR 4, the FAA Reauthorization Act of 2018. They then passed the bill by a strongly bipartisan vote of 393 to 13; the No votes were nearly evenly split between Republicans and Democrats.

There were two remaining amendments from those I described earlier left to be considered today. Amendment #111 (FEMA emergency response plan support) was passed by a voice vote as part of en block amendment 4. Amendment #98 (FAA artificial intelligence report) was not offered during the consideration of the bill either today or yesterday.

The Senate will probably take up the bill with a substitute language amendment that will address a number of different issues with some language in common. This typically would lead to a conference committee to work out the differences between the two bills.

House Amends HR 4 – FAA Authorization Act


The House started consideration of HR 4, the FAA Reauthorization Act of 2018, today. Amendments were taken in numerical order with a number of en bloc considerations. The last amendment considered this evening was #97.

Of the UAS amendments that I described in my earlier post, all have been adopted by voice votes. Amendments #25 and #26 were considered as part of en block #1. Amendment #47 was taken up on its own. And amendment #80 was taken up as part of en block #3.

The House will resume consideration of HR 4 on Friday morning (okay, technically that is this morning now).

Sunday, April 22, 2018

HR 4 Introduced – FAA Reauthorization


Earlier this month Rep. Schuster (R,PA) introduced HR 4, the FAA Reauthorization Act of 2018. The bill includes a number of provisions that address unmanned aircraft system (UAS) operations and aviation cybersecurity.

UAS Provisions


The bill addresses UAS issues in two separate sub-titles; Sub-Title B of Title 3 and Sub-Title C of Title 7. Between these two sub-titles there are 17 separate sections addressing a wide variety of UAS topics. Of those, the following may be of specific interest to readers of this blog:

§337. Evaluation of aircraft registration for small unmanned aircraft;
§338. Study on roles of governments relating to low-altitude operation of small unmanned aircraft;
§341. Cooperation related to certain counter-UAS technology.

Section 337 of the bill requires FAA to “develop and track metrics to assess compliance with and effectiveness of the registration of small unmanned aircraft systems” {§337(a)} required by the interim final rule published in December of 2015. It would also require the DOT Inspector General to report to Congress on both the metric development required and the overall “reliability, effectiveness, and efficiency of the Administration’s registration program for small unmanned aircraft” {§337(b)(2)}.

Section 338 of the bill requires the DOT Inspector General to begin a study of the “the regulation and oversight of the low-altitude operations of small unmanned aircraft and small unmanned aircraft systems” {§338(a)(1)} and the appropriate roles of Federal, State, local, and Tribal governments in regulating UAS operations below 400 ft above ground level (AGL). An obligatory report to Congress is required.

Section 341 of the bill would require DOT to consult with DOD about efforts to streamline the deployment of systems “in the national airspace system intended to mitigate threats posed by errant or hostile unmanned aircraft system operations”.

Cybersecurity Provisions


The cybersecurity sub-title includes six sections. Of these, the following three sections may be of specific interest to readers of this blog:

§732. Cabin communications, entertainment, and information technology systems cybersecurity vulnerabilities.
§733. Cybersecurity threat modeling.
§736. Cybersecurity research and development program.

Section 732 would require the FAA to “determine the research and development needs associated with cybersecurity vulnerabilities of cabin communications, entertainment, and information technology systems on civil passenger aircraft” {§732(a)}. Those R&D needs would include an assessment of:

• Technical risks and vulnerabilities;
• Potential impacts on the national airspace and public safety; and
Identification of deficiencies in cabin-based cybersecurity.

Section 733 would require the FAA, in consultation with the National Institute of Standards and Technology, to “develop an internal FAA cybersecurity threat modeling program to detect cybersecurity vulnerabilities, track how those vulnerabilities might be exploited, and assess the magnitude of harm that could be caused by the exploitation of those vulnerabilities” {§733(a)(1)}.

Section 736 would require the FAA to “establish a research and development program to improve the cybersecurity of civil aircraft and the national airspace system” {§737(a)}. In support of that program the FAA would be required to establish a plan to implement that program. The plan would include objectives, proposed tasks, milestones, and a 5-year budgetary profile. The FAA would also be required to commission a National Academies study of that plan.

Moving Forward


This bill is scheduled to be considered by the House this week. The House Rules Committee will hold a hearing on Tuesday to prepare the rule for the consideration of the bill. There have been 231 proposed amendments to the bill submitted to the Committee for consideration. These amendments include a number that address either UAS or cybersecurity provisions.

I suspect that we will have a managed rule for this bill that will include a relatively small number of those amendments. I suspect that the bill will pass with at least some bipartisan support. This is one of those ‘must pass’ bills that Congress has to deal with every year. We have not yet seen a Senate version of the bill, but the Senate will take up their own version of the bill which typically means that a conference committee will have to be convened to work out the differences between the two versions.

Commentary


I am more than a little concerned that this bill addresses (§341) the deployment of weapon systems to mitigate the threat of UAS systems without addressing the legal issues associated with interfering with the operation of aircraft. While the bill does not specifically mention weapons the vague use of the phrase “systems in the national airspace system intended to mitigate threats” can only be considered weapons. Whether those weapons conduct physical attacks to destroy the UAS or electronic attacks to cause the UAS to crash (any landing outside of the control of the pilot/operator is a crash; controlled or otherwise) still mean that the systems employed are weapons.

See my discussion of HR 5366 to see the extent of the legal complications that are apparently being ignored in this section.

Sunday, April 15, 2018

Bills Introduced – 04-13-18


On Friday, with just the House in session, there were 23 bills introduced. Of those, three may be of specific interest to readers of this blog:

HR 4 To reauthorize programs of the Federal Aviation Administration, and for other purposes. Rep. Ryan, Paul D. [R-WI-1]

HR 5515 To authorize appropriations for fiscal year 2019 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 5517 To improve assistance provided by the Hollings Manufacturing Extension Partnership to small manufacturers in the defense industrial supply chain on matters relating to cybersecurity, and for other purposes. Rep. Panetta, Jimmy [D-CA-20]

The first two are important authorization bills. The FAA bill has already been printed and includes a title on unmanned aircraft systems that will be looked at here. The NDAA will be watched for cybersecurity provisions. Note that it is odd for Speaker Ryan to introduce the FAA authorization bill and even more so for him to use one of his reserved bill numbers.

I will be looking at HR 5517 for control system security issues. The defense industrial base regulation is always a potential forward indicator of possible congressional action on cybersecurity issues.

Wednesday, July 13, 2016

House and Senate Pass HR 636 - FAA Authorization Bill

On Monday the House adopted a version of HR 636 that substituted new language for that adopted by the Senate in April by a voice vote. The cybersecurity provisions in the Senate language were removed and a new cybersecurity section was added. One of the two unmanned aircraft provisions associated with critical infrastructure facilities was completely re-written and the other remained mainly intact.

Cybersecurity


Section 2111 of the bill would require the FAA to develop “a comprehensive and strategic framework of principles and policies to reduce cybersecurity risks to the national airspace system, civil aviation, and agency information systems”. It would require the FAA’s Aircraft Systems Information Security Protection Working Group (ASISPWG) to identify and address cybersecurity risks associated with aircraft systems {§2111(a)(2)(1)(A)} including:

• To assess cybersecurity risks to aircraft systems;
• To review the extent to which existing rulemaking, policy, and guidance to promote safety also promote aircraft systems information security protection;
• Cybersecurity risks associated with in-flight entertainment systems;
• Whether in-flight entertainment systems can and should be isolated and separate, such as through an air gap, under existing rulemaking, policy, and guidance; and
• To provide appropriate recommendations to the Administrator if separate or additional rulemaking, policy, or guidance is needed to address cybersecurity risks to aircraft systems;

Critical Infrastructure Overflight


Section 2209 is a rewrite of §2154 that was adopted from S 2658. It requires the FAA to establish procedures for critical infrastructure facilities to apply to the FAA “to prohibit or restrict the operation of an unmanned aircraft in close proximity to a fixed site facility” {§2209(a)}. The bill would limit such restrictions to the following types of facilities:

• Critical infrastructure, such as energy production, transmission, and distribution facilities and equipment;
• Oil refineries and chemical facilities;
• Amusement parks; and
• Other locations that warrant such restrictions.

Section 2210 is essentially the same language that was found in Senate bill. It would allow critical infrastructure owners more latitude in their use of drones in inspection and monitoring activities.

Moving Forward



With the July 15th authorization deadline fast approaching, it appears that the Senate has accepted the House language on HR 636 by a vote of 89 to 4. The bill will go to the President who will certainly sign the bill.

Wednesday, April 13, 2016

HR 636 Amendments – 04-12-16

Yesterday there were 44 amendments proposed to HR 636. Only one of those will be of specific interest to readers of this blog; SA 3679. This amendment is now the substitute language that will turn HR 636 into the Federal Aviation Administration Reauthorization Act of 2016. The previous substitute language amendment was dropped (tabled) yesterday by Sen. McConnell.

New Language


The new substitute language is pretty much the same language as the previous version. The amendments that had been adopted in the Senate have been added into this newer version. In addition, there has been a new title added to the bill, Title VII, that deals with the Airport and Airway Trust Fund.

I have not gone back and checked to see if all of the language in all of the sections of the bill, but I have done so for the four sections that I have been specifically covering in the bill:

• Sec. 2154. Applications for designation. [same]
• Sec. 4109. Cybersecurity. [same]
• Sec. 4110. Securing aircraft avionics systems. [same as added]
• Sec. 5029. Aviation cybersecurity. [same as modified]

Moving Forward


Cloture on the new amendment was filed yesterday, so there will be a vote on that tomorrow. It looks like McConnell intends to have a final vote on this bill this week. The cloture vote tomorrow will tell the tale on the chances of him getting his way.


Meanwhile today a number of Senators will have to make a decision if they are going to re-submit amendments to the new language that had been proposed to the old substitute. That plus the normal string of new amendments will ensure that I have a goodly number of amendments to peruse tomorrow.

Thursday, April 7, 2016

HR 636 Amendments in Senate – 04-06-16

HR 636 is the legislative vehicle that the Senate is using to consider the Federal Aviation Administration Reauthorization Act of 2016. An amendment (SA 3464) was offered yesterday by Sen. Thune (R,SD; Chair of the Senate Commerce, Science and Transportation Committee) that will be the substitute language that will form the basis of the bill to be considered. Fourty-nine other amendments were also proposed yesterday, including three cybersecurity amendments and a unmanned aircraft systems (UAS) amendment that may be of specific interest to readers of this blog.

Substitute Language


SA 3464 (pgs S1717 thru S1756) is based upon the version of S 2658 that was approved after extensive amendments in Thune’s Committee. As I have noted earlier that bill included a cybersecurity section, a large number of UAS provisions, and a specific provision allowing facility owners to request designation of their facilities as no-fly zones for UAS and other aircraft. The overflight (§2154) and cybersecurity provisions (§4109) made it intact into SA 3464.

A number of additional sections appear in SA 3464 that were not in the version of S 2658. One of specific interest to readers of this blog is a second section of cybersecurity requirements; §5029, Aviation Cybersecurity. That new section would require the Administrator to:

• Establish a comprehensive cybersecurity aviation framework;
• Assess the potential cost and timetable of developing and maintaining an agency-wide threat model to strengthen cybersecurity across the Federal Aviation Administration;
• Implement DOT IG recommendations for security of FAA facilities and systems;
• Establish requirements for the Aircraft Systems Information Security Protection Working Group; and
• Submit 90-day and 1-year progress reports to Congress.

The comprehensive cybersecurity aviation framework would require the Administrator to establish principles and policies that would {§5029(a)(1)}:

• Clarify cybersecurity roles and responsibilities of offices and employees, including governance structures of any advisory committees addressing cybersecurity at the Federal Aviation Administration;
• Recognize the interactions of different components of the national airspace system and the interdependent and interconnected nature of aircraft and air traffic control systems;
• Identify and implement objectives and actions to reduce cybersecurity risks to the air traffic control information systems, including actions to improve implementation of information security standards and best practices of the NIST, and policies and guidance issued by the OMB for agency systems;
• Support voluntary efforts by industry, RTCA, Inc., or standards-setting organizations to develop and identify consensus standards, best practices, and guidance on aviation systems information security protection; and
• Establish guidelines for the voluntary sharing of information between and among aviation stakeholders pertaining to aviation related cybersecurity incidents, threats, and vulnerabilities.

Cybersecurity Amendments


Of the fifty amendments that were submitted yesterday there were four that specifically dealt with cybersecurity matters. Three of those were submitted by Sen. Markey (D,MA) and the other by Sen. Nelson (D,FL). Those amendments are:

• SA 3468, Markey – Amends §5029 by adding “(f) Disclosure of Cyberattacks by the
Aviation Industry”;
• SA 3469, Markey – Amends §5029 by adding “(d) Incorporation of Cybersecurity into Requirements for Air Carrier Operating Certificates and Production Certificates”
• SA 3470, Markey – Amends §5029 by adding “(f) Managing Cybersecurity Risks of Consumer Communications Equipment”
• SA 3474, Nelson – Adds a new section “Securing Aircraft Avionics Systems”

SA 3468 would require the Administrator to prescribe regulations requiring air carriers and manufacturers to disclose cyberattacks to the FAA. The attacks would have to be reported whether or not they were successful. The attacks would have to be reported “whether or not the system is critical to the safe and secure operation of the aircraft, or any maintenance or ground support system for aircraft, operated by the air carrier or produced by the manufacturer, as the case may be” {§5029(f)(1)}.

SA 3469 would require the Secretary of Transportation to prescribe regulations to incorporate
requirements relating to cybersecurity into the requirements for obtaining an air carrier operating certificate or a production certificate under chapter 447 of 49 USC. Those regulations would include requirements to {§5029(d)(2)}:

• Require all entry points to the electronic systems of each aircraft operating in United States airspace and maintenance or ground support systems for such aircraft to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;
• Require the periodic evaluation of the measures described in subparagraph (A) for security vulnerabilities using best security practices, including the appropriate application of techniques such as penetration testing; and
• Require the entry point measures to be periodically updated based on the results of the evaluations conducted above.

SA 3470 would make the DOT-FCC’s Commercial Aviation Communications Safety and Security Leadership Group responsible for evaluating the cybersecurity vulnerabilities of broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers that is installed before, on, or after, or is proposed to be installed on or after, the date of the enactment of this Act. Specifically, the Leadership Group would be required to {§5029(f)(2)}:

• Ensure the development of effective methods for preventing foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board such aircraft; and
• Require the implementation by covered air carriers, covered manufacturers, and communications service providers of all technical and operational security measures that are deemed necessary and sufficient by the Leadership Group to prevent cyberattacks described above.

SA 3474 would require the Administrator to revise aircraft air-worthiness regulations to include provisions requiring “assurance that cybersecurity for avionics systems, including software components, is addressed and require that aircraft avionics systems used for flight guidance or aircraft control be isolated and separate from other networking platforms such as by using an air gap or such other means as the Administrator determines appropriate, except firewall, to protect the avionics systems from unauthorized external and internal access”.

Critical Infrastructure UAS Use


Sen. Inhofe (R,OK) proposed SA 3492 would add a new paragraph to one of the UAS. That new paragraph would require the Secretary of Transportation to establish a process to allow owners and operators of critical infrastructure to conduct UAS operations to conduct:

• Activities to ensure compliance with Federal or State regulatory, permit, or other requirements, including to conduct surveys associated with applications for permits;
• Activities to inspect, repair, construct, maintain, or protect covered facilities, including to respond to a pipeline, pipeline system, or electric energy infrastructure incident, or in response to or in preparation for a natural disaster, man-made disaster, severe weather event; or
• Activities not described above if the covered person notifies the local Flight Standards District Office before the operation of the unmanned aircraft system for such activities.

The process would allow the activities described above to be conducted beyond the visual line of sight of the individual operating the unmanned aircraft system; and without any restriction on the time of the operation.

Moving Forward


The Senate officially starts considering HR 636 today. This will be a multi-day operation with a large number of amendments. The tax provisions that I described yesterday were not included in the substitute language nor were they proposed separately yesterday. That means that additional behind the scenes work is still being done on that issue.

There have been few non-FAA amendments submitted through yesterday, but I expect that we will start to see those being offered today along with a large number of additional FAA specific amendments. This amendment offering process will continue for days.

Commentary


Markey is rapidly establishing the reputation as the cybersecurity regulation senator. His three amendments offered here were offered in slightly different forms during the consideration of S 2658 where it was voted down in an 8-16 vote (which indicates at least some bipartisan disapproval). As I noted in my earlier post this reflects a general mistrust of specificity in cybersecurity legislation. I would be surprised if any of the three Markey amendments made it to the floor of the Senate for consideration.

Markey’s reporting requirement amendment is quite specifically dead on arrival. I certainly applaud his attempt to get a cyber-attack reporting requirement established as I believe that some sort of reporting requirement in regulated industries is going to be necessary if we are going to be able to obtain some level of control over cybersecurity. Unfortunately, Markey’s all systems, successful or not requirement is too broadly written to be acceptable to the industry or be within the capabilities of the FAA to oversee.


The Nelson amendment has a better chance of being considered since it lacks much of the Markey specificity and puts the onus of developing actual requirements on the interagency working group. This provides Congress with the appearance of action without really being required to understand the details of the requirements imposed on the industry. Unfortunately, leaving an interagency committee to come up with regulations is a recipe for slow play and inadequate requirements.

Wednesday, April 6, 2016

Senate to Consider FAA Authorization as HR 636

The Senate will begin the pre-debate on consideration of HR 636 today. The bill passed by the House as the America's Small Business Tax Relief Act of 2015 will be used as the vehicle for a long-term reauthorization bill for the Federal Aviation Administration (FAA).

The details on the language that will be substituted for the House bill are still being developed. It will be based upon the version of S 2658 that was marked up last month in the Commerce, Science and Transportation Committee, but there will almost certainly be additional items added to that language before it is offered, probably today. The language on cybersecurity and critical infrastructure overflights that I reported on earlier will almost certainly remain in the substitute language, though modifications are possible.

Many observers believe that this may be the last major piece of legislation that will be passed by Congress before the elections. As such it is sure to attract an extensive amendment process on the floor of the Senate. Only two proposed amendments have been published to date, but that will certainly change today.


One issue that has been holding up the publication of the substitute amendment has been the extension of tax breaks for some forms of renewable energy that were overlooked last year in the spending bill. This is one of the reasons that HR 636 will be used as the ‘vehicle’ for this bill instead of considering S 2658; tax related bills must originate in the House.

Saturday, March 19, 2016

S 2658 – FAA and Cybersecurity

Earlier this week the Senate Energy, Commerce and Transportation Committee marked up S 2658, the Federal Aviation Administration Reauthorization Act of 2016. While the bill includes a number of sections on unmanned aviation systems (which I will cover in a later post), there was one section of the bill that concerns cybersecurity and there was an amendment offered in the markup that would have significantly increased the cybersecurity requirements of the bill.

NOTE: The GPO has finally printed a copy of the original bill, but that has already been superseded by substitute language that formed the basis for the Committee markup. All references to the bill in this post refer to that substitute language.

Section 4109


Section 4109 was included in the original version of the bill and made it whole into the substitute language. It is found in Title IV, Subtitle A; Next Generation Air Transportation System (pg 267). It would require the FAA Administrator to {§4109(a)}:

• Identify and implement ways to better incorporate cybersecurity measures as a systems characteristic at all levels and phases of the architecture and design of air traffic control programs, including NextGen programs;
• Develop a threat model that will identify vulnerabilities to better focus resources to mitigate cybersecurity risks;
• Develop an appropriate plan to mitigate cybersecurity risk, to respond to an attack, intrusion, or otherwise unauthorized access and to adapt to evolving cybersecurity threats; and
• Foster a cybersecurity culture throughout the Administration, including air traffic control programs and relevant contractors.

In short, the section recognizes that cybersecurity issues exist and leaves it to the professionals at the FAA to deal with the specifics while providing them the general authority to do so. And, of course, it included a requirement for the obligatory report to Congress after one year.

Markey Amendment


Sen. Markey (D,MA) introduced an amendment that would have virtually re-writen §4109. It started off with a new paragraph (a) that provided definitions of key terms. Those terms included:

• Covered air carrier;
• Covered manufacturer;
• Cyberattack;
• Critical software systems; and
• Entry point.

The paragraph (a) requirements (see above) from the bill would have been made paragraph (b) and the following paragraphs with detailed regulatory requirements would have been added:

• Disclosure of cyberattacks by the aviation industry;
• Incorporation of cybersecurity into requirements for air carrier operating certificates and manufacturer production certificates;
• Annual report to Congress on cyberattacks on aircraft systems as well as maintenance and ground support systems; and
• Managing cybersecurity risks of consumer communications equipment;

In general, Markey’s amendment would have provided the FAA with specific authority to craft the most comprehensive cybersecurity oversight regulations in the Federal government (outside of military contractors, anyway).

The Markey amendment was voted down by a vote of 8-12. The Committee does not provide details of the votes on their web page, but with a 13-11 Republican majority on the Committee, this means that at least 3 Democrats voted against the Markey amendment. In contrast, the overall bill (and the vast majority of the 60 submitted amendments) passed on a voice vote.

Moving Forward


As I remarked in an earlier post this bill will move to the Senate floor fairly quickly. The Senate just started their two week Easter recess, but I suspect that the Committee staff will be hard at work writing the report on this bill. I would not be surprised to see that report filed in one of the three pro forma sessions that the Senate has scheduled over the next two weeks, but at the very latest it should be published in the first full week of April when the Senate returns to Washington.

Commentary

While there is fairly widespread opposition in the cybersecurity community to additional regulation of cybersecurity, I firmly believe that public safety and security require more than voluntary application of cybersecurity principles in certain aspects of our society; especially since there has been such an obvious dearth of that voluntary application. Aviation safety and security, are in my estimation, one of the obvious areas where public good requires legislative and regulatory attention to cybersecurity.

The broadly shaped goals of the adopted version of §4109 can hardly be opposed because of specificity of equipment or protocols. The requirements are written with an absolute paucity of specificity. It does, however, rely upon a significant amount of cybersecurity acumen (if not necessarily technical knowledge) on the part of the FAA administration to establish the minimum level of regulatory oversight that the FAA needs to maintain over carriers and manufacturers to protect the public from cybersecurity vulnerabilities and their deliberate or accidental exploitation.

The provisions of the Markey amendment were a lot more specific in their cybersecurity requirements, but still avoided the problems of specifying techniques or equipment. For example, in the proposed paragraph for air carrier certificate requirements, there was the following mandate {§4109(d)(2)(a)}:

“Require all entry points to the electronic systems of each aircraft operating in the United States airspace[,] and [the] maintenance or ground support systems for such aircraft[,] to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;”

Unfortunately, the opposition (both inside Congress and out) to any serious specificity in cybersecurity requirements is obvious and in the short term (at least) is clearly in the entrenched majority with substantially bipartisan support. But again, I want to remind people in the cybersecurity community, political support is fickle at best. All it requires is one cyber incident that obviously and publicly puts people in harm’s way or kills people and the politicians in Washington will craft the most demanding and potentially contradictory cybersecurity rules that one could imagine.

The one area of the Markey proposal that I would like to see again considered in any floor action on S 2658 would be a requirement for the reporting of cyberattacks by the aviation industry. I think that the Markey definition of cyberattack needs some work, but the basics are there. The definition in his amendment was: “the unauthorized access to aircraft electronic control or communications systems or maintenance or ground support systems for aircraft, either wirelessly or through a wired connection.” {§4109(a)(3)}.


Markey then went on in paragraph (c) to demand the DOT establish regulations for air carriers and manufacturers to report successful or attempted “cyberattack on any system on board an aircraft, whether or not the system is critical to the safe and secure operation of the aircraft”. Since this would include hacking the onboard entertainment system to get a free move or intercepting someone’s unencrypted wi-fi email, this language is overbroad. If it were limited to ‘electronic control or aircraft communications systems’ and specifically excluded passenger side communications or the entertainment system, it would be a more acceptable requirement.

Monday, March 14, 2016

Congressional Hearings – Week of 3-13-16

Both the House and Senate will be in Washington this week and budget issues continue to dominate the House hearing process. There are two hearings this week in the Senate that may be of specific interest to readers of this blog; one addresses self-driving cars and the second looks at two authorization bills: FAA and FCC.

Budget Hearings


The following House budget hearings may be of specific interest to readers of this blog:

Coast Guard – Transportation and Infrastructure Committee
NIST – Science, Space and Technology Committee
Cyber Command – Emerging Threats and Capabilities Subcommittee

It looks like the Cyber Command may finally get its own specific mention in the budget and spending bills. Congress has been pushing DOD to do this for a couple of years now.

Self-Driving Cars


The Commerce, Science and Technology Committee will be holding a hearing on Tuesday on “Hands Off: The Future of Self-Driving Cars”. The witness list includes:
• Chris Urmson, Google X
• Mike Ableson, General Motors Company
• Glen DeVos, Delphi Automotive
• Joseph Okpaku, Lyft
• Mary (Missy), Duke University

Reading the hearing summary, it does not sound like the witnesses will be talking about cybersecurity issues or safety standards.

FAA & FCC Authorization


On Wednesday the Commerce, Science, and Transportation Committee will be holding a hearing on the FAA (S 2658) and FCC (S 2644) authorization bills. The FCC bill is a very short and broadly written authorization bill that contains nothing about cybersecurity issues.

I have not had a chance to do a detailed review of the FAA bill yet as it has not been published by the GPO. The hearing web page has a link to a committee draft of the bill. It includes a number of provisions dealing with unmanned aerial systems. In the Next Generation Air Transportation title there is a section (§4109) dealing with cybersecurity.

On the Floor



There is nothing currently scheduled to come to the House floor that would be of specific interest to readers of this blog. As usual the Senate schedule is much more problematic. There continues to be a chance that there will finally be a resolution to the hold being placed on S 2012, the 2016 energy authorization bill, that will allow consideration of that bill to continue to a vote.

Thursday, March 10, 2016

Bills Introduced – 03-09-16

With just the Senate in session yesterday there were only 7 bills introduced. Of those just one may be of specific interest to readers of this blog:

S 2658 A bill to amend title 49, United States Code, to authorize appropriations for the Federal Aviation Administration for fiscal years 2016 through 2017, and for other purposes. Sen. Thune, John [R-SD]


Since the FAA is one of the agencies that could conceivably start regulating control system security, I’ve added it to the list of agencies that I will watch for congressional cybersecurity action in authorization and funding measures. There probably will not be any cybersecurity measures this year, but we did see one minor cybersecurity measure in HR 4441, the House bill on this topic, so I will watch this bill.
 
/* Use this with templates/template-twocol.html */