Showing posts with label FY 2017 NDAA. Show all posts
Showing posts with label FY 2017 NDAA. Show all posts

Friday, December 2, 2016

House Adopts S 2943 Conference Report – 2017 NDAA

Today the House accepted the Conference Report on S 2943, the FY 2017 National Defense Authorization Act (NDAA), by a strongly bipartisan vote of 375 – 34. The cybersecurity provisions of both HR 4909 and the Senate version of S 2943 were included in the final version with some modifications.

Cybersecurity Provisions


The cybersecurity provisions in the bill included (the page numbers refer to the explanation of the provision in the Conference Report):

Sec. 1641 [HR 4909, §1631] Special emergency procurement authority to facilitate the defense against or recovery from a cyber attack (pg 2717);
Sec. 1642 [S 2943, §1633] Limitation on termination of dual-hat arrangement for Command of the United States Cyber Command (pg 2717);
Sec. 1643 [S 2943, §1632] Cyber mission forces matters (pgs 2717-8);
Sec. 1644 [HR 4909, §1633] Requirement to enter into agreements relating to use of cyber opposition Forces (pg 2718);
Sec. 1645 [S 2943, §1631] Cyber protection support for Department of Defense personnel in positions highly vulnerable to cyber attack (pg 2718);
Sec. 1646 [HR 4909, §1634] Limitation on full deployment of joint regional security stacks (pg 2719);
Sec. 1647 [HR 4909, §1637] Advisory committee on industrial security and industrial base policy (pgs 2719-20);
Sec. 1648 [HR 4909, §1632] Change in name of National Defense University’s Information Resources Management College to College of Information and Cyberspace (pg 2720);
Sec. 1649 [S 2943, §1635] Evaluation of cyber vulnerabilities of F–35 aircraft and support systems (pg 2720);
Sec. 1650 [S 2943, §1637 and §1634] Evaluation of cyber vulnerabilities of Department of Defense critical infrastructure (pg 2721);
Sec. 1651 [HR 4909, §1639] Strategy to incorporate Army reserve component cyber protection teams into Department of Defense cyber mission force (pg 2721);
Sec. 1652 [S 2943, §1636] Strategic plan for the Defense Information Systems Agency (pgs 2721-2);
Sec. 1653 [S 2943, §1638] Plan for information security continuous monitoring capability and comply-to-connect policy; limitation on software licensing (pg 2722);
Sec. 1654 [S 2943, §1639 and §1640] Reports on deterrence of adversaries in cyberspace (pgs 2722-3); and
Sec. 1655 [HR 4909, §1638] Sense of Congress on cyber resiliency of the networks and communications systems of the National Guard (pg 2723).

Control System Security


Control system security is now addressed in two of those sections; §1644 and §1650.

Section 1644 addresses the use and training of cyber opposition forces in military exercises. The Conference Committee added a new subsection (c) that calls for the development of a joint training program and certification “for the protection of control systems”. The development is to be completed by June 30th, 2017.

Section 1650 addresses the evaluation of cyber vulnerabilities within DOD critical infrastructure. It incorporates the ‘cyber informed methodologies’ that I discussed earlier. That terminology is not actually used, but the pilot program required in subsection (b) and the tools for that pilot described in subsection (e) clearly apply to those types of methodologies.

Moving Forward



The Senate is likely to take up the Conference Report next week. They are very likely to accept the report under their unanimous consent procedures.

Thursday, July 7, 2016

Rule for Consideration of S 2943 – FY 2017 NDAA

Last night the House Rules Committee adopted a rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act. As part of the adoption of H Res 809 the language of HR 4909 will be substituted for the language of S 2943. The House would then vote on a motion to insist on its amendment and request a conference.

Since HR 4909 passed along generally party lines, it would be highly unlikely that the Senate would accept the ‘new’ House language for S 2943. The Senate would be expected to also insist on their own language and vote for a conference. It is very probable that the conference could complete its work and both houses accept the conference report before the end of the fiscal year.


The House is currently debating H Res 809. The vote should come later today or tomorrow.

Tuesday, July 5, 2016

Committee Hearings – Week of 7-3-16

This week the House is in town, back from their extended 4th of July holiday. The Senate is taking their ‘week’ off this week and will only be meeting in pro forma sessions. Currently there is only one hearing of interest scheduled for this week; a Rules Committee hearing on the 2017 NDAA.

Hearing


The Rules Committee will be meeting on Wednesday to prepare their rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act (NDAA). The House already passed their version of the bill (HR 4909) which has some important differences from the Senate bill.

It is too early to tell if the House is just going to substitute the HR 4909 language or actually amend the Senate bill. That should be more obvious as we get closer to the hearing.

On the Floor



The House will take up S 2943 sometime later this week. They will also be considering HR 4361, a federal information security bill; not one that I have been following.

Wednesday, June 15, 2016

S 2943 Passed in Senate – FY 2017 NDAA

Yesterday the Senate completed consideration of S 2943, the FY 2017 National Defense Authorization Act. One additional amendment was adopted and then the bill passed by a strongly bipartisan vote of 85-13.

None of the amendments adopted during the consideration of this bill included cybersecurity language. The original bill did include significant cybersecurity provisions, including a requirement for DOD to conduct a cyber-informed engineering pilot program.

The House passed its own version of the NDAA (HR 4909) last month by a more partisan vote. There will almost certainly be a conference committee to iron out the differences between the two bills.


According to TheHill.com: “The White House is threatening to veto the Senate version [of the NDAA] over several of its policy provisions, including restrictions on Guantanamo Bay detainee transfers and a cap on the size of the White House National Security Council staff.” There were more than enough Yea votes on S 2943 to overcome a veto, so it is not clear that such a veto would actually be forthcoming if those provisions made it into the compromise bill.

Wednesday, June 8, 2016

More Amendments to S 2943 – FY 2017 NDAA – 06-07-16

Yesterday there were 107 Amendments proposed for S 2943, the FY 2017 National Defense Authorization Act, currently under consideration in the Senate. Two of those amendments may be of specific interest to readers of this blog:

• SA 4465. Mr. JOHNSON (R,WI) – SEC. 1097. Critical Infrastructure Protection Act. Pgs S3553-4
• SA 4531. Mr. BOOKER (D,NJ) – SEC. 1097. Implementation of outstanding transportation security requirements. Pg S3589

The Amendments


Johnson’s amendment is essentially the EMP defense language seen in the reported version of S 1846.

The Booker amendment would require the TSA to complete (within six months) two railroad security rulemakings required by the the Implementing Recommendations of the 9/11 Commission Act of 2007 (6 U.S.C. 1162 and 1167). Those requirements address:

§1162 - Railroad carrier assessments and plans
§1167 - Railroad security training program

Moving Forward



The Senate began actual consideration of amendments to S 2943 yesterday. The adopted 18 amendments; all but two by voice votes. None of the amendments that I have been reporting on here were considered. Consideration of amendments continues today and there are two amendment cloture votes scheduled for Thursday. At this point it does not look like the Senate will vote on the bill this week.

Friday, May 27, 2016

Amendments to S 2943, FY 2017 NDAA – 04-25-16

On Wednesday the Senate voted 98 – 0 on a cloture vote to proceed with consideration of S 2943, National Defense Authorization Act for Fiscal Year 2017. Additionally, 93 new amendments were proposed to be considered for that bill. Two of those amendments may be of specific interest to readers of this blog:

SA 4205 (pg S3212) – Sen. Rounds (R,SC) - SEC. 1227. Imposition of sanctions with respect to significant activities undermining cybersecurity conducted on behalf of or at the direction of the government of Iran; and

SA 4226 (pg S3221) – Sen. Cantwell (D,WA) - SEC. 1641. Pilot program on training for national guard personnel on cyber skills for the protection of industrial control systems associated with critical infrastructure.

The Amendments


SA 4205 is almost identical to S 2756 that had been introduced by Rounds last month.

SA 4226 would require the Chief of the National Guard Bureau to establish a pilot program “to provide National Guard personnel with training on cyber skills for the protection of industrial control systems associated with critical infrastructure” {new §1641(a)}. The three year pilot program would be designed to “permit personnel who receive such training to assist National Guard Cyber Protection Teams in carrying out activities to protect systems and infrastructure” {new §1641(c)}. A report to Congress would be required after the pilot program was completed.

Moving Forward



It is still too early to see which amendments will actually reach the floor for consideration. The publication of the Congressional Record for Thursdays session later today may include a partial listing of the amendments that will be considered, but we will probably not know until the Senate returns from their Memorial Day weekend on June 6th exactly what all of those favored amendments will be.

Monday, May 23, 2016

S 2943 Introduced – FY 2016 NDAA

Last week Sen. McCain (R,AZ) introduced S 2943, the National Defense Authorization Act (NDAA) for Fiscal Year 2017. The House version of this bill (HR 4909) passed last week. It provides authorization for military activities for the next fiscal year.

Like the House bill, there is an entire subtitle of this bill (Subtitle C of Title XVI) related to cyber issues. The following sections are listed in that subtitle:

Sec. 1631. Cyber protection support for Department of Defense personnel in positions highly vulnerable to cyber attack.
Sec. 1632. Cyber Mission Forces matters.
Sec. 1633. Limitation on ending of arrangement in which the Commander of the United States Cyber Command is also Director of the National Security Agency.
Sec. 1634. Pilot program on application of consequence-driven, cyber-informed engineering to mitigate against cybersecurity threats to operating technologies of military installations.
Sec. 1635. Evaluation of cyber vulnerabilities of F–35 aircraft and support systems.
Sec. 1636. Review and assessment of technology strategy and development at Defense Information Systems Agency.
Sec. 1637. Evaluation of cyber vulnerabilities of Department of Defense critical infrastructure.
Sec. 1638. Plan for information security continuous monitoring capability and comply-to-connect policy.
Sec. 1639. Report on authority delegated to Secretary of Defense to conduct cyber operations.
Sec. 1640. Deterrence of adversaries in cyberspace.

There are no overlaps between the items found in this subtitle of the bill and the corresponding subtitle of the House version. Two of the sections in this version of the bill may be of specific interest to readers of this blog: §1634 and §1640

Cyber-Informed Engineering


Section 1634 requires the DOD to establish “a pilot program to assess the feasibility and advisability of applying consequence-driven, cyber-informed engineering methodologies to the operating technologies of military installations, including industrial control systems, in order to increase the resilience of military installations against cybersecurity threats and prevent or mitigate the potential for high-consequence cyberattacks.”

While I am waiting for the Armed Forces Committee report on S 2943 to see if there are any additional insights into what the Committee expects to see included in the ‘cyber-informed engineering’ pilot, I did find an interestingpaper [updated link, 23:21 1-28-17]on the topic from a couple of engineers at the Idaho National Laboratory. They note that modern industrial processes are constructed with the assumption that the control system is trusted, an assumption that is increasingly proving to be incorrect. They call for a new engineering design process that takes the potential insecurity of the control system into account as part of the design basis for the entire industrial process.

Deterrence of Adversaries in Cyberspace


In many ways §1640 is similar to HR 5220 and S 2905 in that it requires the President to report to Congress on “determining when an action carried out in cyberspace constitutes an act of war against the United States” {§1640(b)(1)}. The important difference here is that that report only comes after the Joint Chiefs of Staff provide a detailed report to Congress “on the military and nonmilitary options available to the United States to deter Russia, China, Iran, North Korea, and terrorist organizations in cyberspace” {§1640(a)(1)}. This makes the report more of a policy development requirement rather than just a political gotcha game.

Moving Forward


The Senate Armed Services Committee has already completed their action on this bill (and I am expecting their report to be published today or tomorrow) so this bill is cleared to move to the Floor of the Senate. It is being reported on TheHill.com that this bill will come to the floor of the Senate this week, though it is not the first bill slated for floor action today.

There are a number of controversies that could arise in connection with this bill (unrelated to cybersecurity issues) that could slow consideration especially considering that the Senate is heading home for a week of campaigning at the close of the week. It would not be surprising to see some vocal posturing before the Memorial Day Recess and then more reasonable actions following the return to Washington.

When this bill is eventually passed, it will have to go to a conference committee to work out the significant differences with that House over a number of matters. It is not entirely clear at this point that a House-Senate compromise bill would be acceptable to the President as both sides try to make points going into the election. I suspect that a final version of this bill will only be achieved in the lame duck session.

Commentary


It is interesting to see a piece of legislation addressing a new and innovative engineering concept like cyber-informed engineering. It is less surprising that it was found in a defense authorization bill, particularly in the Senate. McCain did after all receive a pretty good technical education at the US Naval Academy. And as a military pilot he did come to have a pretty good personal understanding of the importance of good engineering. I am not saying that he came up with the concept, but he was better able to comprehend its importance when briefed on it by DOD than a less technologically trained congress critter would have.


In many ways the chemical engineering profession has embraced the basic idea behind this new engineering concept in the way they that have developed their stand-alone safety systems. Those systems were not developed with cybersecurity in mind, but rather to deal with problems with another less-than-trusted part of the chemical manufacturing process, the human operator. The lessons that chemical engineers have learned over the last couple of decades in dealing with human-engineering issues should be directly applicable to cyber-informed engineering.

Thursday, May 19, 2016

Bills Introduced – 05-18-16

With both the House and Senate in session yesterday twelve bills were introduced. Actually at this point there were twelve bills introduced in the Senate. Since the House did not adjourn until almost 1:00 am EDT this morning any bills introduced in the House yesterday were not included in yesterday’s listing on Congress.gov. In any case only one of the twelve bills listed may be of specific interest to readers of this blog:

S 2943 An original bill to authorize appropriations for fiscal year 2017 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sen. McCain, John [R-AZ]

NOTE: Title Corrected for date on 5-20-16 07:48 EDT.

Wednesday, May 18, 2016

House Begins Consideration of HR 4909

Yesterday the House began consideration of HR 4909, the FY 2017 National Defense Authorization Act (NDAA). The one hour of general debate was completed and the House considered the first 61 amendments approved by the House Rules Committee.

First Day Action


The first 61 amendments included two of the amendments that I discussed in a blog post on Monday.

34. Sewell (AL) #34 Allows cyber institutes to place a special emphasis on entering into a partnership with a local educational agency located in a rural, under served,or underrepresented community. (10 minutes)

15. Hunter (CA) #164 (REVISED) Expands the use of the Transportation Worker Identification Credential (TWIC) regarding access at DoD installations. (10 minutes)

Both of these amendments were included in blocks of amendments for consideration in a single vote. The Sewell amendment was included in en block #1 and the Hunter amendment was included in en block #2. Both blocks of amendments were adopted by voice votes, reflecting the low controversy level of each amendment included in the block.

Moving Forward


Consideration is resuming today with 120 additional amendments. Only two more of the amendments that I discussed on Monday were included in the list of amendments to be considered today:

104. Meehan (PA), Costello (PA) #47 Expresses a sense of Congress that reiterates the importance of strong communications systems for the National Guard in the event of a cyber or terrorist attack. (10 minutes)

115. Donovan (NY), Hunter (CA) #226 (REVISED) Expedites processing of applications for transportation security cards for separating members of the Armed forces and veterans to facilitate employment in the maritime industry.


I suspect that both of these amendments will be considered in block votes as well.
 
/* Use this with templates/template-twocol.html */