Showing posts with label HR 1560. Show all posts
Showing posts with label HR 1560. Show all posts

Friday, April 24, 2015

HR 1731 Amended and Passed in House

Yesterday the House passed HR 1731, the National Cybersecurity
Protection Advancement Act of 2015, in a bipartisan vote of 355 to 63. Earlier the House approved all eleven amendments (including the Port cybersecurity report amendment) included in the rule for consideration of the bill. Ten of the amendments were adopted by voice votes and the one roll call vote was a near unanimous 405 to 8.


As specified in the rule for consideration of the bill, HR 1731 will be appended to the end of HR 1560 and no further action will be taken on HR 1731. The revised version of HR 1560 will be published by the GPO in the near future.

Wednesday, April 22, 2015

HR 1560 Amended and Passed in House

This afternoon the House passed HR 1560, the Protecting Cyber Networks Act, by a bipartisan vote of 307 to 116. Even the no votes were largely bipartisan 37 Republicans and 79 Democrats.
Earlier in the day the House adopted all five of the amendments  included in the debate by the House Rules Committee. Only one of those required a voice vote and that was strongly bipartisan as well; 313 to 110.


As I noted yesterday, the House will take up HR 1731, the National Cybersecurity Protection Advancement Act of 2015. That bill is also expected to pass, though I don’t expect all eleven amendments to be adopted before the final vote. That bill does contain language providing for a specific role for the DHS ICS-CERT in the National Cybersecurity and Communications Integration Center. To that extent, it does obliquely address industrial control system security.

Tuesday, April 21, 2015

Rules Committee Adopts Rule for Cyber Sharing Bills

This evening the House Rules Committee held a hearing to craft the rule for the consideration of HR 1560 and HR 1731 (Wednesday and Thursday respectively) later this week on the floor of the House. These two bills are the latest cybersecurity bills attempting to encourage and control the sharing of cybersecurity threat information between government agencies and the private sector.

Each bill will be considered separately under a structured rule with limited debate and a pre-selected set of amendment to be considered. If each bill is adopted (a pretty good certainty) the Clerk of the House is directed to mash the two bills together by adding the provisions of HR 1731 to the end of HR 1560. The revised HR 1560 will then be sent to the Senate for consideration.

General Bill Provisions

I have started to review these bills on a number of occasions both before and after their amendments in committee (HR 1560, intel; HR 1731, homeland security), but both bills have become even more convoluted than normal in the frequent (and apparently poorly coordinated) attempts to placate the concerns of the privacy advocates that have been the main opponents of previous attempts at crafting information sharing bills.

Both bills strive to allow and encourage the private sector to share cyber threat information with each other and federal agencies. In numerous places and manners there have been attempts made to make it clear that personally identifiable information is not included in the sharing process.

The differences in the two  bills is more a matter of focus and procedure rather than any real difference in intent. HR 1560 establishes a stand-alone process for information sharing while HR 1731 amends two sections of the United States Code (6 USC 148 and 6 USC 131) to provide statutory law to support that information sharing.

ICS Security Issues

Both of these bills were generally crafted to address information sharing about threats to IT systems. HR 1560 made a brief concession to the idea of industrial control systems also being vulnerable to cyber-attack by specifically including “industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controller” {§11(8)(B)} in the definition of ‘information system’. Otherwise there is no specific mention of measures to address the unique security threats to industrial control systems.

HR 1731 does go a bit further. In the amendment to 6 USC 148 (included in PL 113-282 passed last December) that modifies the mandatory composition of the National Cybersecurity and Communications Integration Center the DHS ICS-CERT is added as a represented organization with the following specific responsibilities {§148(d)(1)(G)}:

∙ Coordinate with industrial control systems owners and operators;
∙ Provide training, upon request, to Federal entities and non-Federal entities on industrial control systems cybersecurity;
∙ Collaboratively address cybersecurity risks and incidents to industrial control systems;
∙ Provide technical assistance, upon request, to Federal entities and non-Federal entities relating to industrial control systems cybersecurity; and
∙ Shares cyber threat indicators, defensive measures, or information related to cybersecurity risks and incidents of industrial control systems in a timely fashion.

Floor Amendments

Before today’s hearing there were a number of amendments submitted to the Rules Committee for possible inclusion in the floor action on these bills; 25 for HR 1560 and 38 for HR 1731. The final rule selected 5 of those for HR 1560 and 11 for 1731.

There was one amendment that added an additional responsibility to those discussed for ICS-CERT about. That amendment (#15) would have added the responsibility to evaluates and make recommendations to the Under Secretary on industrial control systems that are essential for food, medicine, and medical device production or processing and wholesale delivery. This amendment will not be considered on the floor of the House.

There were two amendments {both submitted by Rep. Hahn (D,CA)} to HR 1560 that addressed port cybersecurity issues; one requiring a report to congress (#1) and the second prohibiting giving additional Port Security Grants to ports that had not conducted “a cybersecurity vulnerability assessment, as defined by the Secretary of Homeland Security” (#2). The first was one of the amendments that will be considered on the floor of the House.

Moving Forward

Both of these bills will probably pass this week in the House. There will be significant opposition to the bill because of perceived privacy issues, but I don’t think that it will be enough to derail either bill.


It is unlikely that the final version of HR 1560 will be considered by the Senate. The Senate will consider their own version of an information sharing bill next week. The language for that bill will then likely be transferred to HR 1560 setting up the need for a conference committee to work out the differences in the bill. It is very likely that a final version will be passed by both houses before the summer recess.

Monday, April 20, 2015

Committee Hearings – Week of 04-19-15

Both the Senate and House will be in session this week, though the House is only working three days. A lot of hearings on spending matters, but the big news is cybersecurity information sharing.  There is one other cybersecurity hearing and the CSB chair nominee hearing will be held.

Information Sharing

The two competing House bills on cybersecurity information sharing will hit the floor this week; HR 1560 on Wednesday and HR 1731 on Thursday. Before that can happen the Rules Committee will have to meet to set up the rule for the consideration of the two bills; HR 1731 today and HR 1560 tomorrow.

Other Cybersecurity

The House Committee on Small Business will hold a hearing on Wednesday on “Small Business, Big Threat: Protecting Small Businesses from Cyber Attacks”. Looking at the witness list and the meeting notice it certainly looks like this will focus on IT and breach issues instead of control system security, but you never can tell.

Spending

The Homeland Security Subcommittee in both the House and Senate will hold hearings on FEMA spending this week. The Senate on Wednesday and the House on Thursday. Also on Wednesday the THUD subcommittee in the Senate will hold a hearing on the FY 2016 DOT spending.

CSB Chair

The Senate Environment and Public Works Committee will be holding a nomination hearing on Wednesday for Vanessa Sutherland to be a Member and Chairperson of the Chemical Safety and Hazard Investigation Board. Ms. Sutherland is currently the Chief Counsel at PHMSA. Management and leadership questions will probably dominate this hearing given the current problems at CSB.


Wednesday, March 25, 2015

Bills Introduced – 03-24-15

Yesterday the House and Senate introduced 65 bills. Only two of those may be of specific interest to readers of this blog:

HR 1560 - To improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes. Rep. Nunes, Devin [R-CA-22]

S Res 110 - A resolution expressing the sense of the Senate about a strategy for the Internet of Things to promote economic growth and consumer empowerment.  Sen. Fischer, Deb [R-NE]

While the official copy of HR 1560 has not yet been published by the GPO, the House Intelligence Committee does have a copy of the bill, a summary, and a section-by-section review of the bill available on their web site. I have not yet had a chance to do a complete review of the bill, but it does specifically include industrial control systems in its definition of information systems {§11(8)(b)}.

This will be the last mention of S Res 110. The bill was introduced and passed yesterday in the Senate. It was passed by unanimous consent in the closing minutes of yesterday’s session. No vote was taken and there were probably few members even present. Again the official copy of the resolution has not been printed by the GPO, but Sen. Fischer has a copy on her web site.


The bill was feel good statement of the ‘sense of the Senate’ that the internet of things is a good thing to be encouraged in a way that “maximizes the promise connected technologies hold to empower consumers, foster future economic growth, and improve our collective social well-being”. The closest thing to a statement about the concerns relating to security of the IOT is found in the closing statement exhorting innovators to “commit to improving the quality of life for future generations by developing safe [emphasis added], new technologies aimed at tackling the most challenging societal issues facing the world”. Please save us from well-meaning but technologically inept politicians.
 
/* Use this with templates/template-twocol.html */