Showing posts with label HR 1344. Show all posts
Showing posts with label HR 1344. Show all posts

Thursday, April 25, 2019

HR 2130 Introduced – State Cybersecurity Grants


Earlier this month Rep. Kilmer (D,WA) introduced HR 2130, the State Cyber Resiliency Act. The bill would establish a new Federal Emergency Management Administration (FEMA) grant program to develop and implement a State cyber resiliency program. This bill is nearly identical to HR 1344 from the 115th Congress; no action was taken on that bill.

Differences in the Bills


There are no substantive changes made in the bill. The only differences are minor editorial changes like substituting ‘5-year’ for ‘five-year’; cosmetic changes only.

Moving Forward


Kilmer is not a member of either the House Homeland Security nor Transportation and Infrastructure Committees to which this bill was assigned for consideration. Rep. McCaul (R,TX), his sole cosponsor, is an influential member of the Homeland Security Committee, so it is possible that this bill will see consideration in that Committee this session. This is different from last year when none of the eleven cosponsors were members of the appropriate committees.

I do not see anything in this bill that would engender any specific opposition to this bill. There is no specific authorization of funds for the grant program so that ‘problem’ has been avoided. I suspect that there would be substantial bipartisan support for the bill if/when it is considered in Committee. That would lead to the bill being considered under the House suspension of the rules process if it makes it to the floor of the House.

Monday, March 13, 2017

S 516 Introduced – Cybersecurity Grants

Earlier this month Sen. Warner (D,VA) introduced S 516, the State Cyber Resiliency Act. This is a companion bill to HR 1344, introduced on the same day in the House. Warner is not on the Senate Homeland Security and Governmental Affairs Committee, to which the bill was referred for consideration. This means that the bill will be unlikely to proceed in the Senate either.

Sunday, March 12, 2017

HR 1344 Introduced – State Cybersecurity Grant Program

Earlier this month Rep. Kilmer (D,WA) introduced HR 1344, the State Cyber Resiliency Act. The bill would establish a new Federal Emergency Management Administration (FEMA) grant program to develop and implement a cyber resiliency program.

Cyber Resiliency Program


The bill would provide grants for States establishing cyber resiliency programs designed to assist State and local governments “in preventing, preparing for, protecting against, and responding to cyber threats” {§2(a)}. The FEMA Administrator would approve State plans that were {§(2)(d)(1)(B)}:

• Enhancing the preparation, response, and resiliency of computer networks, industrial control systems, and communications systems performing such functions against cybersecurity threats or vulnerabilities;
• Implementing a process of continuous cybersecurity vulnerability assessments and threat mitigation practices to prevent the disruption of such functions by an incident within the State;
• Ensuring that entities performing such functions within the State adopt generally recognized best practices and methodologies with respect to cybersecurity;
• Mitigating talent gaps in the State government cybersecurity workforce, enhancing recruitment and retention efforts for such workforce, and bolstering the knowledge, skills, and abilities of State government personnel to protect against cybersecurity threats and vulnerabilities;
• Protecting public safety answering points and other emergency communications and data networks from cybersecurity threats or vulnerabilities;
• Ensuring continuity of communications and data networks between entities performing such functions within the State, in the event of a catastrophic disruption of such communications or networks;
• Accounting for and mitigating, to the greatest degree possible, cybersecurity threats or vulnerabilities related to critical infrastructure or key resources, the degradation of which may impact the performance of such functions within the State or threaten public safety;
• Providing appropriate communications capabilities to ensure cybersecurity intelligence information-sharing and the command and coordination capabilities among entities performing such functions;
• Developing and coordinating strategies with respect to cybersecurity threats or vulnerabilities in consultation with neighboring States or members of an information sharing and analysis organization.

The Administrator would be able to approve grants to States for developing approved plans and then separate grants for State and local government activities implementing those plans. The implementing grants may be used specifically for {§2(g)(2)}:

• Supporting or enhancing information sharing and analysis organizations.
• Implementing or coordinating systems and services that use cyber threat indicators (as such term is defined in 6 USC. 1501) to address cybersecurity threats or vulnerabilities.
• Supporting dedicated cybersecurity and communications coordination planning;
• Establishing programs, such as scholarships or apprenticeships, to provide financial assistance to State residents who pursue formal education, training, and industry-recognized certifications for careers in cybersecurity and commit to working for State government for a specified period of time.

Moving Forward


Kilmer in not a member of either the House Homeland Security Committee or the Transportation and Infrastructure Committee, the two committees to which this bill was assigned for consideration. This means that it is unlikely that he will have sufficient influence to see the bill considered in either committee.

There is nothing in the bill that would draw significant opposition from any groups outside of Congress. The major stumbling block for this bill is that it authorizes a new spending program. Kilmer tries to avoid the problem not including a dollar amount in the authorization language included in the bill {§2(j)}. That would be set by the Appropriations Committee (to which Kilmer does belong) in the DHS spending bill.

Commentary


This bill is definitely intended to see States include control system security issues in their cyber resiliency. Industrial control systems are specifically mentioned in the outline of plan objectives {§2(d)(1)(B)(i)}. Where things start to get a little confusing is in the matter of definitions.

In discussing implementation grants the bill uses the term ‘cyberthreat indicators’ and references the definition in 6 USC 1501(5) which is based upon the control system inclusive definition of ‘information system’ found in that section. But later in the definition section of this bill {§2(k)} both the definition of ‘cybersecurity risk’ and ‘incident’ are adopted from 6 USC 148(a) which depends on the IT exclusive definition of ‘information system’.


That was necessary because those terms were not defined in §1501. It could have been avoided if the term ‘information system’ had been included in (k) and referenced the definition in §1501. That might have been a bit problematic because the ‘information system’ term is not directly used in this bill. A simpler way of dealing with this would have been to amend the definition in §148 to use that in §1501. This would have the added benefit of updating all other uses of ‘information system’ that rely on the §148 definition.

Friday, March 3, 2017

Bills Introduced – 03-02-17

With both the House and Senate preparing to leave for a long weekend there were 120 bills introduced yesterday. Of those six may be of specific interest to readers of this blog:

HR 1301 Making appropriations for the Department of Defense for the fiscal year ending September 30, 2017, and for other purposes. Rep. Frelinghuysen, Rodney P. [R-NJ-11]

HR 1309 To streamline the office and term of the Administrator of the Transportation Security Administration, and for other purposes. Rep. Katko, John [R-NY-24]

HR 1324 To amend the Communications Act of 1934 to provide for the establishment of cybersecurity standards for certain radio frequency equipment. Rep. McNerney, Jerry [D-CA-9]

HR 1335 To direct the Federal Communications Commission to issue rules to secure communications networks against cyber risks, and for other purposes. Rep. Clarke, Yvette D. [D-NY-9]

HR 1344 To provide grants to assist States in developing and implementing plans to address cybersecurity threats or vulnerabilities, and for other purposes. Rep. Kilmer, Derek [D-WA-6]

S 516 A bill to provide grants to assist States in developing and implementing plans to address cybersecurity threats or vulnerabilities, and for other purposes. Sen. Warner, Mark R. [D-VA]

Readers may remember that late last session Congress passed HR 2028 that provided temporary spending authority for FY 2017 until April 28th. It looks like HR 1301 may be the first in a series of bills extending that spending authority until the end of this fiscal year. I had kind of expected an omnibus spending bill and we still may see one for a number of the agencies with only a limited number of department specific bills such as this one.

I will only be covering HR 1309 if it contains specific provisions related to the surface transportation of hazardous chemicals.

It is interesting to see two bills addressing cybersecurity in communications. It is unclear how much of an overlap there will be with HR 1324 and HR 1335.


I would suspect that HR 1344 and S 516 are companion bills; identical bills that provide for parallel processing in both houses of congress to speed up the deliberative process. I suspect that these bills will extend grant eligibility but not expand the amount of grant moneys available.
 
/* Use this with templates/template-twocol.html */