Showing posts with label HR 1251. Show all posts
Showing posts with label HR 1251. Show all posts

Monday, April 19, 2021

Committee Hearings – Week of 4-18-21

This week, with both the House and Senate in session, there is a full slate of committee hearings. Budget hearings continue and there is one cyber workforce hearing scheduled. The House will take-up one chemical security bill and one piece of cyber related legislation this week.

FY 2022 Budget Hearings

4-21-21 Environmental Protection Agency House IER Subcommittee

Cyber Work Forces

On Wednesday the Senate Armed Services Committee will hold a hearing on “To receive testimony on the current and future cyber workforce of the Department of Defense and the military services.” The witness list includes:

• Lieutenant General Dennis Crall, DOD Joint Staff,

• Leonard Litton, Acting Deputy Assistant Secretary for Defense for Military Personnel,

• Veronica Hinton, Acting Deputy Assistant Secretary for Defense for Civilian Personnel Policy,

• John Sherman, Acting Department of Defense Chief Information Officer

Since a major portion of the DOD cyber workforce is on the civilian side of the House, this hearing should provide insights into some of  the problems facing the private sector cybersecurity workforce.

On the Floor

The House is scheduled to take up 23 bills this week under their suspension of the rules process. That means that there will be limited debate, no floor amendments, and the bills will require a supermajority to pass. The House leadership expects that all of the scheduled bills will receive significant bipartisan support.

Included in this week’s consideration are:

HR 397 – CBRN Intelligence and Information Sharing Act of 2021, and

HR 1251 – Cyber Diplomacy Act of 2021

I have not reviewed HR 1251 here as the bill contains no language or definitions that specifically address control system security concerns.

Monday, March 29, 2021

HR 1251 Introduced – Cyber Diplomacy Act of 2021

Last month Rep McCaul (R,TX) introduced HR 1251, the Cyber Diplomacy Act of 2021. The bill would establish an international cyber policy “to work internationally to promote an open, interoperable, reliable, unfettered, and secure Internet governed by the multi-stakeholder model” {§4(a)}.

Definitions

Section 3 of the bill establishes the definitions for three key terms used in the bill, the most important of which is ‘information and communications technology’ (ICT). That term is defined as “hardware, software, and other products or services primarily intended to fulfill or enable the function of information processing and communication by electronic means, including transmission and display, including via the Internet” {§3(2)}.

Policy Objectives

In implementing this policy, the bill requires the President to pursue the following objectives {§4(b)}:

• Clarifying the applicability of international laws and norms to the use of ICT.

• Reducing and limiting the risk of escalation and retaliation in cyberspace, damage to critical infrastructure, and other malicious cyber activity that impairs the use and operation of critical infrastructure that provides services to the public,

• Cooperating with like-minded democratic countries that share common values and cyberspace policies with the United States, including respect for human rights, democracy, and the rule of law, to advance such values and policies internationally,

• Encouraging the responsible development of new, innovative technologies and ICT products that strengthen a secure Internet architecture that is accessible to all,

• Securing and implementing commitments on responsible country behavior in cyberspace based upon accepted norms, and

• Advancing, encouraging, and supporting the development and adoption of internationally recognized technical standards and best practices.

Among the ‘accepted norms’ that the bill would require the President to support would be {§4(b)(5)(C)}:

“Countries should not conduct or knowingly support ICT activity that, contrary to international law, intentionally damages or otherwise impairs the use and operation of critical infrastructure providing services to the public, and should take appropriate measures to protect their critical infrastructure from ICT threats.”

Moving Forward

This bill was considered by the House Foreign Affairs Committee on February 25th, 2021. It was amended with substitute language (not currently available) and approved by the Committee (as part of an en bloc consideration) by voice vote. That would indicate wide bipartisan support for the bill which should carry over to the floor of the House. It is likely that the bill would be considered under the suspension of the rules process in the House.

Commentary

This is primarily an information and communications technology security bill. The new ICT terminology is an interesting expansion of the information technology concept to specifically include the necessary communications aspects that are really key to the efficacy of IT operations and security.

The one objective that seems to address industrial control system security is the oddly worded:

“Reducing and limiting the risk of escalation and retaliation in cyberspace, damage to critical infrastructure, and other malicious cyber activity that impairs the use and operation of critical infrastructure that provides services to the public,”

Parsing that out, there are two specifically operational technology related provisions that would attempt to reduce and limit:

• Damage to critical infrastructure, and

• Other malicious cyber activity that that impairs the use and operation of critical infrastructure that provides services to the public.

That, combined with the ‘accepted norm’ described above, would seem to make it clear that preventing cyber attacks on critical operational technology will be a key part of the foreign policy of the United States. How the crafters of this bill expect the President and the State Department to accomplish this by diplomatic means is unclear.

Wednesday, February 24, 2021

Bills Introduced – 2-24-21

Yesterday with both the House and Senate in session, there were 117 bills introduced. Of those bills, three may receive additional coverage in this blog:

HR 1229 To amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security. Rep. Deutch, Theodore E. [D-FL-22] 

HR 1251 To support United States international cyber diplomacy, and for other purposes. Rep. McCaul, Michael T. [R-TX-10]

S 391 A bill to amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security.  Sen. Grassley, Chuck [R-IA] 

I will be watching the two NTAC bills for language that addresses cybersecurity or chemical security issues. I suspect that these will be companion bills with essentially identical language.

I will be watching HR 1251 for language and definitions that are inclusive of control system security concerns.

 

Because many readers of this blog are intimately connected with the energy industry, I want to mention in passing S 398 that was introduced yesterday by Sen. Kennedy, John [R-LA]. The bill would amend the Homeland Security Act of 2002 to clarify that utility line technicians qualify as emergency response providers. I have not delved into what rights and benefits that this would provide to these brave and selfless folks that support our communities through all sorts of unpleasantness, but I am sure that it will not be enough. Kennedy is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned, so a letter writing campaign to Sen Peters (D,MI), the Chair of that Committee, to urge the Committee’s consideration of the bill might be in order.

 
/* Use this with templates/template-twocol.html */