Showing posts with label HR 118. Show all posts
Showing posts with label HR 118. Show all posts

Wednesday, January 25, 2023

Review - HR 280 Introduced – Cyber Vulnerability Disclosures

Earlier this month, Rep Jackson-Lee introduced HR 280, the Cyber Vulnerability Disclosure Reporting Act. The bill would require DHS to prepare “a report that contains a description of the policies and procedures developed for coordinating cyber vulnerability disclosures”. No funding is authorized by this bill.

The bill is identical to HR 118 that was introduced last session. No action was taken on that bill in Committee.

Moving Forward

Jackson-Lee has not yet been assigned to any Committees, so it is difficult to determine if she has enough influence to see the bill considered in the House Homeland Security Committee to which this bill was assigned for consideration. I see nothing in the bill that would engender any organized opposition. I suspect that the bill would receive bipartisan support were it considered in Committee, and it would probably be able to be considered in the full House under the suspension of the rules process (limited debate, no floor amendments, and super-majority required for passage).

 

For more details about the provisions of the bill, including my commentary on the lack of necessity for the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-280-introduced - subscription required.

Friday, January 29, 2021

HR 118 Introduced – Vulnerability Disclosure Reporting

Earlier this month Rep Jackson-Lee introduced HR 118, the Cyber Vulnerability Disclosure Reporting Act. The bill would require DHS to prepare “a report that contains a description of the policies and procedures developed for coordinating cyber vulnerability disclosures” {§2(a)}. This is the same language that Ms Jackson-Lee introduced as HR 43 in the 116th Congress. No action was taken on HR 43.

The Report

The unclassified report would be submitted to Congress within 240 days of the date of enactment. The requirement for establishing the policies and procedures is found in 6 USC 659(m). That subsection provides that:

“The Secretary, in coordination with industry and other stakeholders, may develop and adhere to Department policies and procedures for coordinating vulnerability disclosures.”

The bill would require an annex to the report that would contain information on {§2(a)}:

• Instances in which such policies and procedures were used to disclose cyber vulnerabilities in the prior year; and

• The degree to which such information was acted upon by industry and other stakeholders.

Moving Forward

Jackson-Lee is (as of yesterday) a member of the House Homeland Security Committee to which this bill was assigned for consideration. She should have enough influence in the Committee to ensure that this bill could be considered if she is willing to exert that influence. There is nothing in this bill that cause any organized opposition to the bill. The bill would very likely receive strong bipartisan support (as an earlier version, HR 3202  did in the 115th Congress) both in Committee and on the floor of the House.

Commentary

It is odd that this bill was being introduced this year when there was no action taken on the bill in the previous session. Jackson-Lee did not use her significant influence in Committee last year to have the bill considered.

On the other hand, with the current concern about cybersecurity, there is a good chance that this bill will move forward early in this session, either as a standalone measure or included in some larger cybersecurity legislation.

One last item, the bill probably should have been updated to require CISA to prepare the report not DHS.

Tuesday, January 5, 2021

Bills Introduced – 1-4-21

Yesterday with both the House and Senate in session (117th Congress), there were 192 bills introduced. Of those bills four may receive further coverage in this blog:

HR 117 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training and Employment Apprentice Program, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 118 To require the Secretary of Homeland Security to submit a report on cyber vulnerability disclosures, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18]

HR 119 To require the Director of National Intelligence to conduct a study on the feasibility of establishing a Cyber Defense National Guard.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 171 To require the Secretary of Commerce to establish a task force to identify vulnerabilities in supply chains for United States entities, and for other purposes.  Rep. Stevens, Haley M. [D-MI-11]

It is not unusual to see such a large number of bills introduced during the first month of a new Congress. A very large number of the bills being introduced are political statements with a number of them being re-introduced in each new session. Again, the vast majority of bills introduced in Congress are never considered in committee, fewer are brought to the floor of the respective house for consideration, and even fewer make it to the President’s desk for signature. Seeing a particularly objectionable bill introduced is not cause for undue alarm; the 537 politicians in congress need to make political statements to their supporters from time to time.

I suspect that HR 117 will apply only to the federal government workforce. If that is the case it will probably not be covered here.

Both HR 118 and HR 119 will receive future coverage in this blog.

I will be watching HR 171 for language and definitions that address cybersecurity vulnerabilities, but I suspect that this will be dealing with commercial vulnerabilities in supply chains.

 
/* Use this with templates/template-twocol.html */