Showing posts with label HR 1648. Show all posts
Showing posts with label HR 1648. Show all posts

Tuesday, April 11, 2023

Review - HR 1648 Introduced – Smart Airports

Last month, Rep Nehls (R,TX) introduced HR 1648, the Airport Technology and Efficiency Improvement Act of 2023. The bill would require the DOT’s Federal Aviation Administration (FAA) to establish a new pilot grant program “to support the acquisition and installation of ‘internet of things’ technologies by airports to create a more consumer-friendly and digitally connected airport experience.” The bill would authorize $5 million per year through 2029 to support the program.

Moving Forward

Nehls is a member of the House Transportation and Infrastructure Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see this bill considered in Committee. Other than the new spending authorized by the bill (which is generally going to be problematic in the 118th Congress), I see nothing in this bill that would engender any organized opposition. I suspect that the bill would pass with some level of bipartisan support (with most of the opposition coming from Nehls’ fellow Republicans) in committee and on the floor of the House if it made it that far.

Commentary

It is disappointing to see a bill at this late date that encourages (funds) the use of IoT devices in the public transportation sector without including at least a mention of needing to include basic cybersecurity protections for those devices. Nehls’ staff even included a privacy hat-tip in their inclusion of the subsection (d) prioritization of grants that “of grants to “projects that do not collect facial and biometric data of passengers not identified as a security threat”, but they forgot the large issue of general cybersecurity protections that would help guarantee those privacy concerns.

At a minimum, I would have changed the wording of subsection (b) to read:

“(b) Eligible Projects.—The Administrator may make a grant under the Program only for a project that facilitates the acquisition and installation by an airport of sensor systems, software, passenger signals, or other technologies, including cybersecurity protections for those systems, consistent with the purposes of the Program, including projects that facilitate­­­”


For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1648-introduced - subscription required.

Saturday, March 18, 2023

Bills Introduced – 3-17-23

Yesterday, with both the House and Senate meeting in pro forma session, there were 60 bills introduced. Four of those bills may receive additional attention in this blog:

HR 1623 To amend the Homeland Security Act of 2002 to exclude certain propane storage facilities from certain chemical security standards under the Department of Homeland Security, and for other purposes. Finstad, Brad [Rep.-R-MN-1] 

HR 1633 To enhance safety requirements for trains transporting hazardous materials, and for other purposes. Johnson, Bill [Rep.-R-OH-6] 

HR 1648 To establish a grant program for use of "internet of things" technologies in airports, and for other purposes. Nehls, Troy E. [Rep.-R-TX-22]

HR 1665 To direct the Secretary of Transportation to establish a program to provide grants to local governments to install publicly accessible safety charging stations for electric bicycles and scooters, and for other purposes. Velazquez, Nydia M. [Rep.-D-NY-7]

I will be covering HR 1623 and HR 1633.

I will be watching HR 1648 and HR 1665 for language and definitions that would specifically include cybersecurity requirements within the scope of the requirements of the legislation.

Sunday, April 21, 2019

HR 1648 Introduced – SBA Security Assistance


Last Month Rep. Chabot (R,OH) introduced HR 1648, the Small Business Advanced Cybersecurity Enhancements Act of 2019. The bill would require the Small Business Administration to establish a Central Small Business Cybersecurity Assistance Unit as well as regional cybersecurity assistance units.

Cybersecurity Assistance Units


The CSBCAU would be collocated with the DHS National Cybersecurity and Communications Integration Center (NCCIC) and would serve as a conduit for sharing cybersecurity threat information between small businesses and the federal government. All of the information sharing protections provided under the CISA legislation {6 USC 1503(c)} would apply to information sharing via the CSBCAU {new 15 USC 648(a)(9)(B)(iii)}. Information on cyberthreat indicators or defensive measures shared through the CSBCAU will not be subject to the narrow regulatory exemption found in 6 USC 1504(d) (5)(D)(ii)(I).

The regional small business cybersecurity assistance units will be part of each Small Business Administration (SBA) small business development center. The bill would require the SBA to set aside $1 million from the monies authorized for small business development centers for the operation of regional SBCAU’s.

Moving Forward


Chabot and both of his cosponsors {Rep. Balderson (R,OH) and Rep. Velasquez (D,NY)} are members of the House Small Business Committee, the Committee to which this bill was assigned for consideration. This means that there is a good chance that this bill will be considered in Committee.

There is nothing in this bill that would incur any significant opposition. I suspect that if it is considered in committee that it would pass with significant bipartisan support. If considered by the full House it would likely be considered under the suspension of the rules process with limited debate and no floor amendments. Again, it would probably pass with substantial bipartisan support.

Commentary


This bill is an attempt to encourage small business owners to participate in the existing cybersecurity information sharing program with CISA by using familiar SBA channels of communication. Unfortunately, it does not address the underlying issues that appear to be hindering businesses in general from participating in the information sharing process. That is the appearance that the information sharing process is a one-way street with little useable information flowing back to the private sector.

The one small sop thrown to the small business community, the §1504 exception will do little to add encouragement for small businesses to participate in the CISA information sharing process. Section 1504 allows units of the federal government to use information shared with NCCIC to be used to fine tune existing cybersecurity regulations. Since there are few areas of the federal regulatory system that are specifically allowed to regulate cybersecurity, this is a fairly unimportant exception.

There is no mention in this bill of industrial control system security issues. The findings section of the bill only mentions information technology security concerns. Fortunately, since this bill attempts to supplement the CISA information sharing process, it uses control system friendly definitions from 6 USC 1501 that are based on the definition of ‘information system’ that specifically includes control systems. Unfortunately, this is as unlikely to encourage small businesses to share control system security threat information with CISA as it is purely IT threat information. Congress needs to clearly identify the existing impediments to information sharing and rectify those before they can expect small businesses to become part of the process.

Saturday, March 9, 2019

Bills Introduced – 03-08-19


Yesterday with just the House in session there were 37 bills introduced. Of these just two may see future coverage in this blog:

HR 1648 To amend the Small Business Act to provide for the establishment of an enhanced cybersecurity assistance and protections for small businesses, and for other purposes. Rep. Chabot, Steve [R-OH-1]

HR 1649 To amend the Small Business Act to require cyber certification for small business development center counselors, and for other purposes. Rep. Chabot, Steve [R-OH-1] 

I will be watching both of these bills for specific language or definitions that would include industrial control systems in the coverage of the legislation. I am not, however, holding my breath.

 
/* Use this with templates/template-twocol.html */