Showing posts with label HR 1731. Show all posts
Showing posts with label HR 1731. Show all posts

Monday, April 22, 2019

HR 1731 Introduced – Cybersecurity Reporting


Last month Rep. Hines (D,CT) introduced HR 1731, Cybersecurity Disclosure Act of 2019. The bill would require the Securities and Exchange Commission to establish rules requiring the reporting of whether there was cybersecurity expertise on the board of directors or other governing body of each company required to file annual reports. This is a companion bill to S 592.

Hines and both of his two cosponsors {Rep. Heck (D,WA) and Rep. Meeks (D,NY)} are members of the House Financial Services Committee to which this bill was assigned for consideration. This means that the bill can probably be expected to receive consideration. I see nothing in the bill that would cause any serious opposition; it would probably receive bipartisan support.

Hines introduced a similar bill last session (HR 6638) that died without action. Part of the reason was it’s relatively late introduction in the session, but it was also unlikely to receive active support from the more business friendly Republican leadership of the Committee. When (if) this bill is considered in Committee, the vote will provide a better view of how much bipartisan support the bill would actually receive on the floor. The bill is only likely to get House action if it can draw the super-majority support necessary for passage under the suspension of the rules process.

Friday, March 15, 2019

S 592 Introduced – Cybersecurity Reporting


Last month Sen. Reed (D,RI) introduced S 592, the Cybersecurity Disclosure Act of 2019. The bill would require the Securities and Exchange Commission to establish rules requiring the reporting of whether there was cybersecurity expertise on the board of directors or other governing body of each company required to file annual reports. The bill is very similar to HR 6638 that was introduced last summer in the 115th Congress. No action was taken on that earlier bill. It looks like Rep. Himes reintroduced that bill in the House earlier this week but it will be a week or two until the bill is printed.

Differences Between Bills


The main difference between S 592 and the earlier House bill is that this bill amends the Securities Exchange Act of 1934 by adding a new §14C which would become 15 USC 78n-3 if the bill becomes law. The earlier bill made essentially the same requirements as a stand alone measure.

The new bill also takes a little bit of puffery out of the final paragraph of the bill. The change is shown below:

“(c) CYBERSECURITY EXPERTISE OR EXPERIENCE.— For purposes of subsection (b), the Commission, in consultation with NIST, shall define what constitutes expertise or experience in cybersecurity, such as professional qualifications to administer information security program functions or experience detecting, preventing, mitigating, or addressing cybersecurity threats, using commonly defined roles, specialities, knowledge, skills, and abilities, such as those provided in NIST Special Publication 800–181 entitled ‘‘NICE Cybersecurity Workforce Framework’’, or any successor thereto.”

Interestingly, this language deletion removes the final faint traces for the need for the definition of the term ‘information system’ that remains in the bill. The control system friendly definition of ‘information system’ was used to support the use of that term in the definition of ‘cybersecurity threat’ that was only used in the phrase deleted above. Both definitions remain in the new bill.

Moving Forward


Reed is a member of the Senate Banking, Housing and Urban Affairs Committee to which this bill was assigned for consideration. Additionally, his cosponsors include Sen. Warner (D,VA), the Ranking Member of the Security, Insurance, and Investment Subcommittee and two Republican members of the Committee. This means that it is very likely that the bill will be considered in Committee.

There is nothing in the bill that would seem to draw any obvious opposition, so it should pass in Committee. Whether or not it will make it to the floor for consideration is very difficult to determine. This bill would normally be considered under the unanimous consent process and a single voice in opposition would prevent it from being considered under that process. And the voice could be raised in ire over something the SEC had done and have nothing to do with this bill.

Commentary


This is all and good to call for cybersecurity experience on corporate boards, but there are not that many people that would fit the probable description to go around to all of the corporate boards in the country.

The bigger question would be is it really necessary? While it would be hard to find a corporation that did not have at least some level of cybersecurity exposure, do all of them have enough that require board level oversight? With the relative scarcity of board-level qualified cybersecurity experts available, there should probably be mandatory cybersecurity representation on some specific subset of corporations, either size limits or in specific sectors (banking, insurance, energy sector, etc). Of course, that bill would be much harder to write.

Thursday, March 14, 2019

Bills Introduced – 03-13-19


Yesterday with both the House and Senate in session there were 87 bills introduced. Two of these were cybersecurity related bills that may receive additional coverage in this blog:

HR 1731 To amend the Securities Exchange Act of 1934 to promote transparency in the oversight of cybersecurity risks at publicly traded companies. Rep. Himes, James A. [D-CT-4]

S 771 A bill to amend section 21 of the Small Business Act to require cyber certification for small business development center counselors, and for other purposes. Sen. Rubio, Marco [R-FL]

I will be watching these bills for specific language and or definitions related to industrial control system security.

Friday, April 24, 2015

HR 1731 Amended and Passed in House

Yesterday the House passed HR 1731, the National Cybersecurity
Protection Advancement Act of 2015, in a bipartisan vote of 355 to 63. Earlier the House approved all eleven amendments (including the Port cybersecurity report amendment) included in the rule for consideration of the bill. Ten of the amendments were adopted by voice votes and the one roll call vote was a near unanimous 405 to 8.


As specified in the rule for consideration of the bill, HR 1731 will be appended to the end of HR 1560 and no further action will be taken on HR 1731. The revised version of HR 1560 will be published by the GPO in the near future.

Wednesday, April 22, 2015

HR 1560 Amended and Passed in House

This afternoon the House passed HR 1560, the Protecting Cyber Networks Act, by a bipartisan vote of 307 to 116. Even the no votes were largely bipartisan 37 Republicans and 79 Democrats.
Earlier in the day the House adopted all five of the amendments  included in the debate by the House Rules Committee. Only one of those required a voice vote and that was strongly bipartisan as well; 313 to 110.


As I noted yesterday, the House will take up HR 1731, the National Cybersecurity Protection Advancement Act of 2015. That bill is also expected to pass, though I don’t expect all eleven amendments to be adopted before the final vote. That bill does contain language providing for a specific role for the DHS ICS-CERT in the National Cybersecurity and Communications Integration Center. To that extent, it does obliquely address industrial control system security.

Tuesday, April 21, 2015

Rules Committee Adopts Rule for Cyber Sharing Bills

This evening the House Rules Committee held a hearing to craft the rule for the consideration of HR 1560 and HR 1731 (Wednesday and Thursday respectively) later this week on the floor of the House. These two bills are the latest cybersecurity bills attempting to encourage and control the sharing of cybersecurity threat information between government agencies and the private sector.

Each bill will be considered separately under a structured rule with limited debate and a pre-selected set of amendment to be considered. If each bill is adopted (a pretty good certainty) the Clerk of the House is directed to mash the two bills together by adding the provisions of HR 1731 to the end of HR 1560. The revised HR 1560 will then be sent to the Senate for consideration.

General Bill Provisions

I have started to review these bills on a number of occasions both before and after their amendments in committee (HR 1560, intel; HR 1731, homeland security), but both bills have become even more convoluted than normal in the frequent (and apparently poorly coordinated) attempts to placate the concerns of the privacy advocates that have been the main opponents of previous attempts at crafting information sharing bills.

Both bills strive to allow and encourage the private sector to share cyber threat information with each other and federal agencies. In numerous places and manners there have been attempts made to make it clear that personally identifiable information is not included in the sharing process.

The differences in the two  bills is more a matter of focus and procedure rather than any real difference in intent. HR 1560 establishes a stand-alone process for information sharing while HR 1731 amends two sections of the United States Code (6 USC 148 and 6 USC 131) to provide statutory law to support that information sharing.

ICS Security Issues

Both of these bills were generally crafted to address information sharing about threats to IT systems. HR 1560 made a brief concession to the idea of industrial control systems also being vulnerable to cyber-attack by specifically including “industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controller” {§11(8)(B)} in the definition of ‘information system’. Otherwise there is no specific mention of measures to address the unique security threats to industrial control systems.

HR 1731 does go a bit further. In the amendment to 6 USC 148 (included in PL 113-282 passed last December) that modifies the mandatory composition of the National Cybersecurity and Communications Integration Center the DHS ICS-CERT is added as a represented organization with the following specific responsibilities {§148(d)(1)(G)}:

∙ Coordinate with industrial control systems owners and operators;
∙ Provide training, upon request, to Federal entities and non-Federal entities on industrial control systems cybersecurity;
∙ Collaboratively address cybersecurity risks and incidents to industrial control systems;
∙ Provide technical assistance, upon request, to Federal entities and non-Federal entities relating to industrial control systems cybersecurity; and
∙ Shares cyber threat indicators, defensive measures, or information related to cybersecurity risks and incidents of industrial control systems in a timely fashion.

Floor Amendments

Before today’s hearing there were a number of amendments submitted to the Rules Committee for possible inclusion in the floor action on these bills; 25 for HR 1560 and 38 for HR 1731. The final rule selected 5 of those for HR 1560 and 11 for 1731.

There was one amendment that added an additional responsibility to those discussed for ICS-CERT about. That amendment (#15) would have added the responsibility to evaluates and make recommendations to the Under Secretary on industrial control systems that are essential for food, medicine, and medical device production or processing and wholesale delivery. This amendment will not be considered on the floor of the House.

There were two amendments {both submitted by Rep. Hahn (D,CA)} to HR 1560 that addressed port cybersecurity issues; one requiring a report to congress (#1) and the second prohibiting giving additional Port Security Grants to ports that had not conducted “a cybersecurity vulnerability assessment, as defined by the Secretary of Homeland Security” (#2). The first was one of the amendments that will be considered on the floor of the House.

Moving Forward

Both of these bills will probably pass this week in the House. There will be significant opposition to the bill because of perceived privacy issues, but I don’t think that it will be enough to derail either bill.


It is unlikely that the final version of HR 1560 will be considered by the Senate. The Senate will consider their own version of an information sharing bill next week. The language for that bill will then likely be transferred to HR 1560 setting up the need for a conference committee to work out the differences in the bill. It is very likely that a final version will be passed by both houses before the summer recess.

Monday, April 20, 2015

Committee Hearings – Week of 04-19-15

Both the Senate and House will be in session this week, though the House is only working three days. A lot of hearings on spending matters, but the big news is cybersecurity information sharing.  There is one other cybersecurity hearing and the CSB chair nominee hearing will be held.

Information Sharing

The two competing House bills on cybersecurity information sharing will hit the floor this week; HR 1560 on Wednesday and HR 1731 on Thursday. Before that can happen the Rules Committee will have to meet to set up the rule for the consideration of the two bills; HR 1731 today and HR 1560 tomorrow.

Other Cybersecurity

The House Committee on Small Business will hold a hearing on Wednesday on “Small Business, Big Threat: Protecting Small Businesses from Cyber Attacks”. Looking at the witness list and the meeting notice it certainly looks like this will focus on IT and breach issues instead of control system security, but you never can tell.

Spending

The Homeland Security Subcommittee in both the House and Senate will hold hearings on FEMA spending this week. The Senate on Wednesday and the House on Thursday. Also on Wednesday the THUD subcommittee in the Senate will hold a hearing on the FY 2016 DOT spending.

CSB Chair

The Senate Environment and Public Works Committee will be holding a nomination hearing on Wednesday for Vanessa Sutherland to be a Member and Chairperson of the Chemical Safety and Hazard Investigation Board. Ms. Sutherland is currently the Chief Counsel at PHMSA. Management and leadership questions will probably dominate this hearing given the current problems at CSB.


Tuesday, April 14, 2015

Bills Introduced – 04-13-15

The first day back in session and 55 bills are introduced. Seven of those may be of specific interest to readers of this blog:

HR 1731 To amend the Homeland Security Act of 2002 to enhance multi-directional sharing of information related to cybersecurity risks and strengthen privacy and civil liberties protections, and for other... Rep. McCaul, Michael T. [R-TX-10]

HR 1735 To authorize appropriations for fiscal year 2016 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year.. Rep. Thornberry, Mac [R-TX-13] 

HR 1738 To amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to modernize and implement the national integrated public alert and warning system to disseminate homeland... Rep. Bilirakis, Gus M. [R-FL-12]

HR 1753 To establish a National Office for Cyberspace, and for other purposes. Rep. Langevin, James R. [D-RI-2]

HR 1763 To provide for the minimum size of crews of freight trains, and for other purposes Rep. Young, Don [R-AK-At Large]

H Res 195 Expressing the sense of the House of Representatives about a national strategy for the Internet of Things to promote economic growth and consumer empowerment. Rep. Lance, Leonard [R-NJ-7] 

S 902 A bill to prohibit trespassing on critical infrastructure used in or affecting interstate commerce to commit a criminal offense. Sen. Schumer, Charles E. [D-NY]

HR 1731 is the new cybersecurity information sharing bill that is being marked up by the House Homeland Security Committee today.

HR 1735, the DOD spending bill, may contain cybersecurity language; we’ll see. This is one of the earliest spending bill introductions that I remember. We may actually see at least some of these passed before the start of the fiscal year.

HR 1738 is the second bill to address the national alerting system introduced this year. The first, HR 1472 is being marked up tomorrow. Unless something odd happens with either of these bills this will be the last time that they are mentioned.

HR 1753 could be interesting or it could be a bust. I’ll have to wait until I see the actual language to see if there is something specifically addressing control system security.

HR 1763 is a train safety issue. Unless the bill includes some specific mention of crude oil trains or hazmat shipments this will be the last mention here.

H Res 195 looks like it may be a response to S Res 110 that I lambasted when it was introduced. I’ll have more on this resolution later today.


S 902 looks like it is a re-issue of S 2934 that was introduced late in the last session of Congress. It was issued so late that I never really took a look at it. I’ll have to wait and see what it actually says before I decide to continue to cover it.
 
/* Use this with templates/template-twocol.html */