Showing posts with label HR 1668. Show all posts
Showing posts with label HR 1668. Show all posts

Wednesday, November 18, 2020

HR 1668 Passed in Senate – IoT Cybersecurity

Yesterday the Senate passed HR 1668, the IoT Cybersecurity Improvement Act of 2020, by unanimous consent. The bill was passed in the House in September and alert readers will recall that the version voted upon in the House was not the version reported out of Committee. The bill now goes to the President for signature. There have been no indications from the White House about how President Trump intends to deal with this bill.

As I mentioned in my earlier post, it seems to me that this is more of an IT security bill than an IoT security bill, other than for the requirement for GAO to report on “broader Internet of Things efforts, including projects designed to assist in managing potential security vulnerabilities associated with the use of traditional information technology devices, networks, and systems” {§8(a)}.

Thursday, September 17, 2020

HR 1668 – Review of Text Passed in House

 As I noted Tuesday night, the House passed a version of HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2020, that was different from both the introduced and reported versions of the bill. Yesterday the GPO printed the version of the bill that was passed by the House. In this post I will look at the differences between the version reported out of the House Oversight and Reform Committee and the version passed in the House.

Sense of Congress

The passed bill inserted a new §2, Sense of Congress, in the bill. That new section lays responsibility for cybersecurity of the executive branch with the President working through the Director of the OMB and the Secretary of Homeland Security. It further makes the claim that “the strength of the cybersecurity of the Federal Government and the positive benefits of digital technology transformation depend on proactively addressing cybersecurity throughout the acquisition and operation of Internet of Things devices by the Federal Government” {§2(3).

Finally it provides a description of ‘Internet of Things devices’ taken from the January 7th, 2020 draft of the National Institute of Standards draft internal report 8259. The description in that report states:

“The IoT devices in scope for this publication [emphasis added] have at least one transducer (sensor or actuator) for interacting directly with the physical world and at least one network interface (e.g., Ethernet, Wi-Fi, Bluetooth, Long-Term Evolution [LTE], Zigbee, Ultra-Wideband [UWB]) for interfacing with the digital world. The IoT devices in scope for this publication [emphasis added] can function on their own and are not only able to function when acting as a component of another device, such as a processor.

Note: the text emphasized above was not included in the description provide in §2(4).

Definitions

Section 2 of the reported bill included definitions of the following terms:

• Agency,

• Covered device,

• Director of OMB,

• Director of the Institute [National Institute of Standards and Technology (NIST)], and

• Security vulnerability.

Section 3 of the passed bill does not include definitions of ‘covered device’. It adds definitions for the following terms:

• Information system [IT-limited definition from 44 USC 3502],

• National security system,

• Operational technology, and

• Secretary [of Homeland Security].

Ongoing NIST Activities

The reported bill contained a §3, Completion of Ongoing Efforts Relating to Considerations for Managing Internet of Things Cybersecurity Risks. This section included a requirement for NIST to publish a report on “the following considerations for covered devices”:

• Secure development,

• Identity management,

• Patching, and

• Configuration management.

This section was not included in the passed version of the bill.

Security Standards

Section 4(a) of the reported bill required NIST (within 6 months) to publish guidelines under 15 USC 278g-3 on {§4(a)}:

• The appropriate use and management by the agencies of covered devices owned or controlled by the agencies, and
• Minimum information security requirements for managing security vulnerabilities associated with such devices.

Section 4(b) then went on to require the Cybersecurity and Infrastructure Security Agency (CISA) to establish standards based upon those guidelines for “covered devices owned or controlled by agencies, except those considered national security systems” {§4(b)(1)(A)}.

In the passed version of the bill, NIST is required (within 90 days) to develop and publish (again under §278g-3) “standards and [emphasis added] guidelines for the Federal Government on the appropriate use and management by agencies of Internet of Things devices owned or controlled by an agency and connected to information systems owned or controlled by an agency, including minimum information security requirements for managing cybersecurity risks associated with such devices” {§4(a)(1)}.

The OMB is then (within 180-days of the establishment of the ‘standards and guidelines’) required to review “agency information security policies and principles” for IoT based upon the NIST developed standards and guidelines; again with an exception for ‘national security systems’.

Petition to Exclude Devices

Section 5 of the reported bill would have required the OMB to establish a process for agencies to petition to have devices not designated as ‘covered devices’ subject to the guidelines established by NIST or standards established by CISA.

There are no comparable requirements in the passed version of the bill.

Coordinated Disclosure

Section 6 of the reported bill would have required NIST to develop guidelines “for the reporting, coordinating, publishing, and receiving of information about” {§6(a)(1)} security vulnerabilities for a covered device owned, or controlled, by an agency (or a contractor providing a covered device to an agency) and the resolution of such vulnerabilities. The developed guidelines should align with ISO 29147 and ISO 30111 {§6(b)(2)}. The guidelines for contractors would include information on “on the type of information about security vulnerabilities that should be reported to the Federal Government, including examples thereof” {§6(a)(3)}.

Section 5 of the passed bill includes similar language except that instead of ‘covered device’ the section refers to “information systems owned or controlled by an agency (including Internet of Things devices owned or controlled by an agency)”.  In addition to the requirement that the guidelines align with the two ISO documents mentioned in the reported bill, §5 requires that the guidelines are “consistent with the policies and procedures produced” {§5(b)(3)} under the coordinated disclosure requirements of 6 USC 659(m).The requirement for contractor reporting was not included. Finally, §5 concludes with establishing that DHS will be responsible for “the implementation of the guidelines published” under this section.

The passed version of the bill includes an additional section (§6) addressing the implementation of the coordinated disclosure guidelines. Section 6(a) requires the OMB (within 2 years) to “develop and oversee the implementation of policies, principles, standards, or guidelines as may be necessary to address security vulnerabilities of information systems (including Internet of Things devices).” Section 6(b) requires DHS to “provide operational and technical assistance to agencies on reporting, coordinating, publishing, and receiving information about security vulnerabilities of information systems (including Internet of Things devices).”

Operational Technology

Section 8 of the passed bill has no counterpart in the reported bill. It requires GAO (within one year) to brief Congress “on broader Internet of Things efforts, including projects designed to assist in managing potential security vulnerabilities associated with the use of traditional information technology devices, networks, and systems” {§8(a)} with IoT devices and operational technology devices, networks, and systems.

Moving Forward

The passage of this bill by a voice vote indicates that there is some level of bipartisan support for this bill. This is important because a bill of this sort is not ‘important’ enough to be considered under the normal debate and amendment process in the Senate. This late in the session the only way that this bill would be considered in the Senate is under the unanimous consent process. Unfortunately, the only way that a bill makes it through that process is for not one single Senator to voice opposition to the bill. I suspect that this bill could make it through such a process, but it could be blocked by a Senator making a point about, or needing support for, something completely unrelated to this bill.

Commentary

First, let me address the unusual way this was brought to the floor in the House. Rep Maloney (D,NY) was the one who actually brought the bill to the floor for consideration. She began the consideration process by saying: “Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 1668) to leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes, as amended.”

That phrase ‘as amended’ can be used to cover a wide variety situations. Typically, it is used to describe a bill that has been amended in the Committee process. It is used from time to time to include a bill that has been amended outside of the process by committee leadership when new information has become available, changes are necessary to get some additional floor support for the bill or to better reflect the intent of the leadership. I suspect that in this case the final reason was the primary driver of the changes being made to the bill. Maloney is the Chair of the House Oversight and Government Reform Committee.

Looking at the bill as passed, it is clear that Maloney is not really interested in IoT cybersecurity. The lack of a definition of the term ‘Internet of Things device’, the discussion in §2 notwithstanding, indicates how little Maloney cares about IoT. The changes to the bill, while still including multiple references to ‘IoT devices’, make this a bill about information system cybersecurity. It provides a small incremental increase in the authority of OMB and DHS to address information system cybersecurity and expands the authority for DHS to continue its recent mandate for government agencies to implement vulnerability disclosure programs.

The addition of §8 of the bill reflects Maloney’s future commitment to the authors and supporters of the bill that passed in Committee that the Committee will continue to look at IoT cybersecurity and actually adds the expanded topic of control system security to that future consideration.

Tuesday, September 15, 2020

HR 1668 Passed in House – IoT Cybersecurity

 

Today the House took up HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, under the suspension of rules provisions. The bill was passed by a voice vote. The House Oversight and Reform Committee amended and adopted the bill back in June, but it does not appear that that was the version of the bill that was passed by the House today.

A quick look at the version of the bill printed in the Congressional Record [pg H4351] shows some significant differences from the introduced version and the substitute language taken up by the Committee. A quick-look listing of some of the differences includes:

• Passed version contains a ‘Sense of Congress’ section 2,

• Passed version does not include a definition of ‘covered device’, and

• Passed version adds definitions for ‘operational technology’, ‘information system’.

According to yesterday’s Congressional Record, the House Oversight and Reform Committee published their Report on the bill yesterday, but an official version of the Report has not yet been published by the GPO. A reported version of the bill is, however available, and it does not look like the version passed in the House yesterday.

I will have more on this as I get more information.

Sunday, June 16, 2019

Committee Amended and Adopted HR 1668 – IoT Cybersecurity


This week the House Oversight and Reform Committee adopted substitute language for HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019, by a voice vote. The new language was a complete re-write of the bill.

Changes in Definitions


In §2 of the bill there were significant changes in the definition provided. First the revised language added definitions for ‘Director of OMB’ and ‘Director of the Institute’ (NIST).

Next the definition of ‘covered device’ was substantially changed. The ‘connected to the internet’ and ‘computer processing capability’ portion of the original definition was kept (but reformatted), but the ‘is not a general-purpose computer’ exception portion of the definition was expanded and revised. The new language included a substantial revision of the ‘programmable logic controls’ language of the original bill to now read{§2(2)(C)(iv)}:

Programmable logic controller with an industrial control system specifically not designed for connection to the internet;

A new exception was also added to the definition{§2(2)(C)(v)}; ‘subcomponent of a device’. The new ‘covered device’ definition also removed provisions in the original bill that would have required OMB to establish a process for petitioning for a device to be specifically considered a ‘covered device’.

Finally, the freestanding definition of ‘security vulnerability’ was changed to an incorporation of the definition from 6 USC 1501. The earlier definition was essentially an expansion of the §1501 definition (it had added ‘firmware’ and ‘combination of 2 or more of these factors’), but the §1501 definition relies on the expanded definition of ‘information system’ that specifically includes control system language.

Security Standards


Section 3 of the original bill was spread out into two separate sections. The first would require the National Institute of Standards and Technology (NIST) to complete its current activities ‘regarding considerations for managing the security vulnerabilities of Internet of Things’ {§3} by December 31st, 2019. This is essentially the same language from §3(a)(1) of the original bill with a revision of the date (extended three months) to complete the actions.

The provisions of §3(b) in the original bill were expanded and modified in §4 of the revised language. First the requirement for NIST to establish ‘standards’ for use of internet of things devices by federal government was changed to establishing ‘guidelines’ which the OMB would later convert to ‘standards’.

The closing paragraph of §4 of the revised language requires that “the Federal Acquisition Regulation shall be revised to implement” the standards required to be set by OMB in §4(b). The simplified language in this new paragraph was designed to accomplish the requirement of §4(a) and (b) of the original language.

New Petition Requirement


The petition requirement that was removed from the definition of ‘covered device’ was moved to and expanded in §5 of the revised language. The new section would allow an ‘interested party’ to petition for a covered device to be exempt from the standards set in §4(b). The petitioner would have to establish that the procurement of the covered device {§5(b)(3)(A)}:

With limited data processing and software functionality would be unfeasible; or
That does not meet the standards promulgated by the Director of OMB under this Act is necessary for national security or for research purposes.

Coordinated Disclosure


Section 6 of the revised language is a substantial rewrite of §5 and §6 of the original bill. It would still require NIST to establish guidelines with respect to “reporting, coordinating, publishing, and receiving of information” {§6(a)(1)} security vulnerabilities of covered devices and the resolution of those vulnerabilities. The new language does add a requirement for ‘consultation’ with the DHS Cybersecurity and Infrastructure Security Agency (CISA) in the development of the guidelines.

Another important new addition to the guideline requirements is found in §6(b)(3); ensure such guidelines are consistent with the policies and procedures developed by CISA under 6 USC 659(m).

OMB would be required to convert the guidelines developed by NIST into standards to be used by government agencies using covered devices. This requirement specifically applies to including those standards in Federal Acquisition Regulations (FAR).

Section 7 of the bill requires all contractors to comply with the requirements of the standards developed by OMB. It would specifically require each agency Chief Information Officer to “determine if such offeror or contractor has complied with each standard promulgated under section 6(c) with respect to such covered device” {§7(a)(1)(A)}.

Moving Forward


Technically, the House Science, Space, and Technology Committee still needs to act on this bill. This could end up being something as simple as a letter from the Chair saying that he agrees with the changes being offered by the Oversight Committee. Or we could see a full committee markup of the bill.

In any case, this bill may actually see its way to the floor of the House. With the bipartisan support that the revised language received in Committee, it is likely that it would be considered under the suspension of the rules process and would probably pass with similar support.

Commentary


Well, Rep. Kelly (D,IL), or more probably her staff, tried to correct the problems with the definition of ‘covered device’ that I had previously identified in the Senate version of this bill (S 734). Unfortunately the changes made just confuse the issue more.

First, we have a measure of grammatical confusion. As written “programmable logic controller with an industrial control system specifically not designed for connection to the internet” would make it seem that an ‘industrial control system’ was part of a PLC instead of the other way around. Next, there is some subject confusion with the phrase ‘specifically not designed for connection to the internet’ (not to mention the awkward word order); does it refer to the PLC or the ICS. If we are to keep the intended (I think) concept here I would suggest the following revision of this language{§2(2)(C)(iv)}:

“programmable logic controller that is a component of an industrial control system which is specifically designed not to connect to the internet;”

There are still problems with this definition, mainly because it uses terms that are not further defined in the bill nor are they a part of general government usage. Does an ICS include building environmental systems or access control systems? Does the existence of a port designed to allow network connections to the device equate to ‘connect to the internet’ or must the device be physically (cable or WiFi or Bluetooth, or radio) attached to a network that connects to the internet?

If Congress does not specify in legislation than agencies like NIST and OMB get to make the decision. In many ways this can make for more agile regulation development. Unfortunately, it may leave the efficacy and the impact of the regulations to the whims of the regulators. In this case, an aggressive NIST or OMB staffer could decide that a close interpretation of the current exemption language would only apply to the PLC of a building environmental control system, but not the HMI used by the system or the sensors or actuators attached to the PLCs. Since those devices were equipped with ports that could allow internet connections, they would be included in the ‘covered device’ definition and would be regulated by the OMB standards. Or they could go the other way and decide that no one would intend to connect these devices to the internet (even though they had components that could allow such a connection) so they were not ‘covered devices’ and thus not regulated.

While I understand that congresscritters are not technically equipped to make many of these decisions, I am still uncomfortable in allowing the kind of regulatory leeway that I describe above to be exercised by nameless bureaucrats who may (NIST probably, OMB not so sure) a better technical background to make such decisions.

Wednesday, June 12, 2019

HR 1668 Hearing – IOT Cybersecurity


This morning the House Oversight and Reform Committee will be holding a business meeting that will include the markup of HR 1668. Rep. Kelly (D,IL), the sponsor of the bill, is offering substitute language for the bill which is essentially a complete re-write. Changes include a complete rewrite of the definition of ‘covered device’ which specifically excludes a wide range of devices including {§2(2)(c)(iv)}:

Programmable logic controller with an industrial control system specifically not designed for connection to the internet [emphasis added].

I will have more on this revised language in a future blog post.

Sunday, April 21, 2019

HR 1668 Introduced – IoT Cybersecurity


Last month Rep. Kelly (D,IL) introduced HR 1668, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. This is a companion bill to S 734.

Kelly (and at least two other cosponsors) is a member of the House Oversight and Reform Committee, one of the two committees to which this bill was assigned for consideration. Rep. Foster (D,IL) is a member of the House Science, Space, and Technology Committee, the other Committee to which the bill was assigned. This means that there is a decent chance that this bill will be considered in these committees.

This bill is more likely to advance in the House than S 734 is to advance in the Senate. I suspect that there would be significant bipartisan support and the bill would be passed in the House under the suspension of the rules process.

Tuesday, March 12, 2019

Bills Introduced – 03-12-19


Yesterday with both the House and Senate in session there were 33 bills introduced. Two of these will receive future mention in this blog:

HR 1668 To leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Rep. Kelly, Robin L. [D-IL-2]

S 734 A bill to leverage Federal Government procurement power to encourage increased cybersecurity for Internet of Things devices, and for other purposes. Sen. Warner, Mark R. [D-VA]

These bills are probably companion bills according to an article published yesterday on TheHill.com. Similar sounding bills (see here for example) have been introduced in the last two sessions of Congress and they have all suffered from an overly broad definition of ‘internet connected device’ that left them essentially useless. It will be interesting to see if anything has changed.

 
/* Use this with templates/template-twocol.html */