Showing posts with label HR 117. Show all posts
Showing posts with label HR 117. Show all posts

Tuesday, May 30, 2023

Review - HR 3208 Introduced – DHS Cybersecurity OJT

Earlier this month, Rep Jackson-Lee (D,TX) introduced HR 3208, the DHS Cybersecurity On-the-Job Training Program Act. The bill would establish in CISA “the ‘DHS Cybersecurity On-the-Job Training Program’ to voluntarily train Department employees who are not currently in a cybersecurity position for work in matters relating to cybersecurity at the Department.” No funding would be authorized by this legislation.

Moving Forward

Jackson-Lee and three of her six cosponsors {Rep Payne (D,NJ), Rep Thompson (D,MS), and Rep Clarke (D,NY)}, are members of the House Homeland Security Committee, to which this bill was assigned for consideration. This means that there could be sufficient influence to see this bill considered in Committee. While I see nothing in this bill that should engender any organized opposition, it seems odd that there are no Republican cosponsors for the bill. While this is a divided House, I still expect to see bipartisan support for bills like this which seem to be inherently non-partisan. That there are no Republican sponsors makes me suspect that there are issues here that I cannot see.

 

For more information about the provisions of this bill, as well as a discussion about differences from a similar bill introduced last session, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3208-introduced - subscription required.

Thursday, January 28, 2021

HR 117 Introduced – Cybersecurity OJT

Earlier this month Rep Jackson-Lee introduced HR 117, the DHS Cybersecurity On-the-Job Training and Employment Apprentice Program Act. The bill would require DHS to establish a program to “identify Department employees for work in matters relating to cybersecurity at the Department” {new §230A(a)}. The new program would be administered by the Cybersecurity and Infrastructure Security Agency.

NOTE: Congress.gov has added a new feature to their listings for bill language. I can now provide links to specific parts of the .txt version of the bills on their web site. That is not a major asset for a short bill like this, but for longer pieces of legislation this will be a great tool.

The Program

In carrying out this program CISA would be required to {new §230A(b)} :

• Identify diagnostic tools that can accurately and reliably measure an individual’s capacity to perform cybersecurity related jobs or serve in positions associated with network or computing security,

• In consultation with relevant Department component heads, identify a roster of positions that may be a good fit for the Program and make recommendations to the Secretary relating to such identified positions,

• Develop a curriculum for the Program, which may include distance learning instruction, in- classroom instruction within a work location, on-the-job instruction under the supervision of experienced cybersecurity staff, or other means of training and education as determined appropriate by the Secretary,

• Recruit individuals employed by the Department to participate in the Program, and

• Determine the best means for training and retention of Department employees enrolled in the Program.

No funds are appropriated for the new program.

Moving Forward

While official committee assignments have not yet been made to the House Homeland Security Committee to which this bill was assigned for consideration, Jackson-Lee has been an influential member of this Committee for a number of sessions. This bill is likely to be considered by the Committee and will probably receive bipartisan support.

If the bill makes it to the floor of the House, it will almost certainly be considered under the suspension of the rules process; limited debate, no floor amendments and a supermajority required for passage. I suspect that this bill would pass with a strong bipartisan majority.

NOTE: In the 117th Congress, that ‘supermajority’ requirement is going to be more problematic for a lot of bills. The narrower majority that the Democrats have this session combined with the larger number of more radical conservatives on Republican side will likely mean that there will be fewer bills passed under this process. Just how many fewer remains to be seen.

Commentary

This bill will only apply to federal agencies. As such I would not normally consider covering the bill in this blog. There are, however, two provisions for the OJT program that would be developed by CISA that may have practical impact on cybersecurity training in the private sector:

• Identify diagnostic tools that can accurately and reliably measure an individual’s capacity to perform cybersecurity related jobs or serve in positions associated with network or computing security, and

• Develop a curriculum for the Program, which may include distance learning instruction, in- classroom instruction within a work location, on-the-job instruction under the supervision of experienced cybersecurity staff, or other means of training and education as determined appropriate by the Secretary,

It will be interesting to see where they get (or develop in house?) “diagnostic tools that can accurately and reliably measure [emphasis added] an individual’s capacity to perform cybersecurity related jobs”. If such tools actual exist or can be developed they will be a boon hiring managers and trainers in the private sector. I would be very interested in seeing documentation supporting the contention of being able to ‘accurately and reliably’ measure this capacity in humans.

On a personal note, I took an early version of such a test that was provided by ITI (a 1970’s technology training company) just before I graduated from high school in 1971. As a result of the test results, I was offered a full scholarship for their two-year computer programming course. I wanted (then) to be a lawyer and politician, so I turned them down. Anyway, I have subsequently learned programming, but lack the attention-to-detail skills necessary to really become a programmer. That early aptitude test did not even try to capture that skill requirement.

The development of an actual OJT component as described in the bill would be a valuable contribution to the resolving the problem of increasing the number of entry level cybersecurity professionals. Now if they could get hiring managers to look for entry level folks, it would be an even greater contribution.

A final note here. This bill was introduced on January 4th. It was just published last night. The GPO is apparently still having COVID related problems processing bills. This is going to be an increasing problem as the pandemic continues to get worse and Congress writes more bills as their operations become more normalized.

Tuesday, January 5, 2021

Bills Introduced – 1-4-21

Yesterday with both the House and Senate in session (117th Congress), there were 192 bills introduced. Of those bills four may receive further coverage in this blog:

HR 117 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training and Employment Apprentice Program, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 118 To require the Secretary of Homeland Security to submit a report on cyber vulnerability disclosures, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18]

HR 119 To require the Director of National Intelligence to conduct a study on the feasibility of establishing a Cyber Defense National Guard.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 171 To require the Secretary of Commerce to establish a task force to identify vulnerabilities in supply chains for United States entities, and for other purposes.  Rep. Stevens, Haley M. [D-MI-11]

It is not unusual to see such a large number of bills introduced during the first month of a new Congress. A very large number of the bills being introduced are political statements with a number of them being re-introduced in each new session. Again, the vast majority of bills introduced in Congress are never considered in committee, fewer are brought to the floor of the respective house for consideration, and even fewer make it to the President’s desk for signature. Seeing a particularly objectionable bill introduced is not cause for undue alarm; the 537 politicians in congress need to make political statements to their supporters from time to time.

I suspect that HR 117 will apply only to the federal government workforce. If that is the case it will probably not be covered here.

Both HR 118 and HR 119 will receive future coverage in this blog.

I will be watching HR 171 for language and definitions that address cybersecurity vulnerabilities, but I suspect that this will be dealing with commercial vulnerabilities in supply chains.

 
/* Use this with templates/template-twocol.html */