Last night, during the debate on HR 1540, the National Defense Authorization Act for Fiscal Year 2012, one of the measures that was debated and voted upon was an amendment offered by Rep. Langevin (D, RI) that specifically dealt with cyber security issues; making it the first time this session that the whole House has taken a vote on a cyber security measure.
HR 1136
Looking at the actual language for Amendment #49, found in House Report 112-88 (the report accompanying H. Res 276, the rule governing the debate of HR 1540), it turns out that this ‘Amendment’ was actually a virtual copy of HR 1136, the Executive Cyberspace Coordination Act of 2011, a bill introduced by Langevin back in March. As I noted in a blog about the bill when it was introduced, this bill was essentially an IT security bill dealing mainly with Federal cyber security. There was a section on ‘critical infrastructure’ that actually mentioned SCADA systems, but there were no real ICS cybersecurity requirements.
After the authorized 10 minutes of debate on the amendment the House voted it down on a voice vote. A recorded vote was ‘demanded’ by Rep. Langevin. As of 11:00 pm EDT last night that vote had not yet occurred. In bills with these lengthy debates and amendment processes (152 amendments were offered on this bill) the House pulls a bunch of these recorded votes together to minimize the time the Members actually have to spend on the floor of the House. A vote will be held sometime today.
This vote on a virtual copy of HR 1136 does not mean that this bill is legally dead. It is technically possible that the bill could still wend its way through the committee review and voting process to make its way back to the floor of the House. Possible but unlikely, otherwise Langevin would not have taken this to the floor as an amendment to a virtually unrelated bill; controversial amendments like this seldom pass as an amendment.
GPS Interference
Earlier this week in a blog posting about this bill I discussed the provisions of HR 1540 dealing with the GPS interference controversy. In that I dismissed an amendment by Rep. Turner (R, OH) modifying provisions of §911 of the bill dealing with the FCC’s approval of the new cell phone service by LightSpeed. That was based upon the summary of the amendment that described it as a ‘Sense of Congress’ measure. The actual amendment was published in the House Rules Committee report and it is a tad bit more potent than a ‘Sense of Congress’ measure.
The language of the Turner Amendment would actually prohibit the FCC from providing final approval of the LightSpeed license “until the Commission has resolved concerns of widespread harmful interference by such commercial terrestrial operations to the Global Positioning System devices of the Department of Defense.” {§911(a)}. This would be a much more effective response than what I had described.
Unfortunately, this still does not address the potential for interference with GPS timing signals used by some control system components. No one has actually reported interference problems with the timing signals, but I have found no reports that anyone has bothered testing this issue.
Turner’s amendment is #149 in the list of amendments to be debated on the floor during the consideration of this bill, so it will be one of the last ones considered. It will probably come up for a vote late this evening. It will be interesting to see how this vote turns out.
Continued Debate
I don’t know how long the House continued their debate of this bill last night. They will be back at it again when the come back to work today. A final vote on the bill will certainly be held before the House goes home for the long Memorial Day Weekend. The final version of the bill will almost certainly pass, probably with bipartisan support.
Showing posts with label HR 1136. Show all posts
Showing posts with label HR 1136. Show all posts
Thursday, May 26, 2011
Saturday, March 19, 2011
HR 1136 Introduced – Cyber Security
On Thursday Rep. Langevin (D, RI) introduced HR 1136, the Executive Cyberspace Coordination Act of 2011. This bill, like most cybersecurity legislation introduced to date, deals principally with the security of Federal electronic information systems. It does, however, provide authority for the regulation of private sector information systems that support industrial control systems in critical infrastructure.
Federal Information System Security
This bill would provide a “comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets” {§3551(1)}. It would establish the Office for Cyberspace within the Executive Office of the President headed by a Director that would be appointed by the President with the consent of the Senate. The Director would serve as a member of the National Security Council. The bill would also require the President to appoint a Federal Chief Technology Officer (Federal CTO) in a separate Office of the Federal Chief Technology Officer within the Executive Office.
Within the Office for Cyberspace the legislation would also create the Federal Cybersecurity Practice Board. The Board would be chaired by the Director and would include representatives of various Federal agencies including OMB, DOD and the Federal law enforcement community. This Board would “be responsible for developing and periodically updating information security policies and procedures” {§3554(c)(1)} for protecting the Federal government’s information technology systems.
The Director is also given the responsibility to “review and offer a non-binding approval or disapproval of each agency’s annual budget to each such agency before the submission of such budget by the head of the agency to the Office of Management and Budget” {§3555(c)(2)}. Lacking actual budget control authority the Director would act more as an advisor than a controller of the security of Federal information technology systems.
This lack of real control authority is reflected in the specific requirement for each agency to “develop, document, and implement an agencywide [sic] information security program” {§3556(b)}. Additionally, the Secretary of Commerce (in consultation with the DHS Secretary) is given broad authority to “promulgate information security standards pertaining to Federal information systems” {§3557(a)(1)(A)}.
Critical Infrastructure
The last 2½ pages of this bill address cybersecurity for critical infrastructure. The entire Title III of this bill relies upon one of the most sweeping definitions of ‘critical information infrastructure’ that I have ever seen. Section 301(1) of the bill states:
Having established a very expansive scope of the potentially regulated community this Title then provides the Secretary of Homeland Security the primary authority “in creation, verification, and enforcement of measures with respect to the protection of critical information infrastructure, including promulgating risk-informed information security practices and standards applicable to critical information infrastructures that are not owned by or under the direct control of the Federal Government” {§302(a)}.
This broad authority is tempered only by the requirement to coordinate with ‘sector specific regulatory agencies’ “in establishing [those] enforcement mechanisms” {§302(b)(2)}. Of course, DHS is that regulatory agency for a number of sectors including the chemical sector.
The only saving grace is that the scope and authority is so wide and all encompassing as to be practically meaningless. Any attempt to establish cybersecurity regulations under this authority would be tied up in court so fast that thousands of lawyers would get rich on the billable hours on these cases alone. Besides, there are no provisions in this legislation for establishing an agency within DHS to exercise this authority, or giving an existing agency that authority. So practically speaking, there is no one to write the regulations for industry to object to.
I expect that if this bill goes anywhere, that there will be substantial revisions to Title III.
Federal Information System Security
This bill would provide a “comprehensive framework for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets” {§3551(1)}. It would establish the Office for Cyberspace within the Executive Office of the President headed by a Director that would be appointed by the President with the consent of the Senate. The Director would serve as a member of the National Security Council. The bill would also require the President to appoint a Federal Chief Technology Officer (Federal CTO) in a separate Office of the Federal Chief Technology Officer within the Executive Office.
Within the Office for Cyberspace the legislation would also create the Federal Cybersecurity Practice Board. The Board would be chaired by the Director and would include representatives of various Federal agencies including OMB, DOD and the Federal law enforcement community. This Board would “be responsible for developing and periodically updating information security policies and procedures” {§3554(c)(1)} for protecting the Federal government’s information technology systems.
The Director is also given the responsibility to “review and offer a non-binding approval or disapproval of each agency’s annual budget to each such agency before the submission of such budget by the head of the agency to the Office of Management and Budget” {§3555(c)(2)}. Lacking actual budget control authority the Director would act more as an advisor than a controller of the security of Federal information technology systems.
This lack of real control authority is reflected in the specific requirement for each agency to “develop, document, and implement an agencywide [sic] information security program” {§3556(b)}. Additionally, the Secretary of Commerce (in consultation with the DHS Secretary) is given broad authority to “promulgate information security standards pertaining to Federal information systems” {§3557(a)(1)(A)}.
Critical Infrastructure
The last 2½ pages of this bill address cybersecurity for critical infrastructure. The entire Title III of this bill relies upon one of the most sweeping definitions of ‘critical information infrastructure’ that I have ever seen. Section 301(1) of the bill states:
“The term ‘critical information infrastructure’ means the electronic information and communications systems, software, and assets that control, protect, process, transmit, receive, program, or store information in any form, including data, voice, and video, relied upon by critical infrastructure, industrial control systems such as supervisory control and data acquisition systems, and programmable logic controllers. This shall also include such systems of the Federal Government.”I hate to be an English Nerd, but the comma behind the words ‘critical infrastructure’ means that any industrial control system or programmable logic controllers residing on, or being supported by, an electronic network of any sort makes that network a piece of ‘critical information infrastructure’. Taken to its logical extreme, this definition would include the electronics system in every modern automobile.
Having established a very expansive scope of the potentially regulated community this Title then provides the Secretary of Homeland Security the primary authority “in creation, verification, and enforcement of measures with respect to the protection of critical information infrastructure, including promulgating risk-informed information security practices and standards applicable to critical information infrastructures that are not owned by or under the direct control of the Federal Government” {§302(a)}.
This broad authority is tempered only by the requirement to coordinate with ‘sector specific regulatory agencies’ “in establishing [those] enforcement mechanisms” {§302(b)(2)}. Of course, DHS is that regulatory agency for a number of sectors including the chemical sector.
The only saving grace is that the scope and authority is so wide and all encompassing as to be practically meaningless. Any attempt to establish cybersecurity regulations under this authority would be tied up in court so fast that thousands of lawyers would get rich on the billable hours on these cases alone. Besides, there are no provisions in this legislation for establishing an agency within DHS to exercise this authority, or giving an existing agency that authority. So practically speaking, there is no one to write the regulations for industry to object to.
I expect that if this bill goes anywhere, that there will be substantial revisions to Title III.
Subscribe to:
Posts (Atom)