Showing posts with label HR 1735. Show all posts
Showing posts with label HR 1735. Show all posts

Wednesday, November 11, 2015

S 1356 Passed in Senate – 2016 NDAA

Yesterday the Senate adopted the House amendment to S 1356, the National Defense Authorization Act 2016 by a decidedly bipartisan vote of 91 to 3. This bill was passed last Thursday in the House by a similar vote of 370 to 58. The funding provisions of this bill were in accordance with the recent budget agreement, so there has been no threat of veto of this bill.

As best as I can tell the non-funding provisions of this bill are the same as HR 1735 that was vetoed by the President. It certainly has the same cybersecurity related provisions.


BTW: There is not yet an official copy of the House version of this bill. The only thing currently available is the final draft version that had been circulated in the House prior to the vote last week.

Thursday, October 8, 2015

Senate Adopts HR 1735 Conference Report

Yesterday as expected the Senate the Senate accepted the Conference Report on HR 1735, the 2016 National Defense Authorization Act, by a vote of 70-23. The bill now goes to the President for signature. While a veto had been threatened, the vote to pass in both houses of Congress was certainly large enough to overturn a veto. It will be interesting to see if Obama makes a principled stand on this budgeting issue or if he just acquiesces and makes that fight another day.

Wednesday, October 7, 2015

HR 1735 Conference Report

Last week the Conference Committee charged with resolving the differences between the House and Senate on HR 1735, the National Defense Authorization (NDA) Act for Fiscal Year 2016, completed their work on the bill and published their Conference Report. Most of the cybersecurity related provisions of the bill in both the House and Senate versions remain in the bill.

Included Provisions of Interest

The list below includes all of the major cybersecurity provisions. Most of these are strictly military related and will have little or no specific impact on control system security issues in the private sector. I have briefly discussed most of these in earlier posts (here and here).

Sec. 885. Amendments concerning detection and avoidance of counterfeit electronic parts.
Sec. 888. Standards for procurement of secure information technology and cyber security systems.
Sec. 1603. Council on Oversight of the Department of Defense Positioning, Navigation, and Timing Enterprise.
Sec. 1641. Codification and addition of liability protections relating to reporting on cyber incidents or penetrations of networks and information systems of certain contractors.
Sec. 1642. Authorization of military cyber operations.
Sec. 1643. Limitation on availability of funds pending the submission of integrated policy to deter adversaries in cyberspace.
Sec. 1645. Designation of military department entity responsible for acquisition of critical cyber capabilities.
Sec. 1646. Assessment of capabilities of United States Cyber Command to defend the United States from cyber attacks.
Sec. 1647. Evaluation of cyber vulnerabilities of major weapon systems of the Department of Defense.
Sec. 1648. Comprehensive plan and biennial exercises on responding to cyber attacks.
Sec. 1649. Sense of Congress on reviewing and considering findings and recommendations of Council of Governors on cyber capabilities of the Armed Forces.

There are three other provisions that may be of specific interest to readers of this blog:

Sec. 1065. Report on the status of detection, identification, and disablement capabilities related to remotely piloted aircraft.
Sec. 1089. Reestablishment of Commission to Assess the Threat to the United States from Electromagnetic Pulse Attack.
Sec. 1603. Council on Oversight of the Department of Defense Positioning, Navigation, and Timing Enterprise.

Provisions Removed

There were a large number of provisions from either the House or Senate versions of the bill that did not make it into the final version of the bill approved by the Conference Committee. Those that may be of specific interest to readers of this blog include:

• Availability of cyber security and IT certifications for Department of Defense personnel critical to network defense;
• Priority processing of applications for Transportation Worker Identification Credentials for members undergoing discharge or release from the Armed Forces;
• Sense of Congress regarding cyber resiliency of National Guard networks and communications systems; and
• Comprehensive plan of Department of Defense to support civil authorities in response to cyber attacks by foreign powers.

The first three of these provisions were originally found in the House version of the bill; the final one was in the Senate version. For the second and third provisions in the above list the Conferees generally agreed with the purpose of the provision, but decided that it did not really belong in the NDA. For the TWIC provision they urged DOD and DHS “to consult to eliminate processing delays and waive fees for transitioning servicemembers and for honorably discharged veterans” (pg 672). For the cyber resiliency provision the report encourages “the National Guard to constantly explore ways to improve and expand its communications and networking capabilities to provide for enhanced performance and resilience in the face of cyber attacks or disruptions, as well as other instances of degradation” (pg 764).

For the provision addressing cyber certifications for DOD cyber personnel, the conferees suggested that there are probably few if any private sector certifications that are directly applicable to missions performed by DOD cyber personnel. Because of a lack of certainty about that assumption, however, the report encourages “the Secretary of Defense to examine the needs of the Department and determine the extent and role industry cyber security and IT certifications should play in workforce management” (pg 670).

For the final provision listed above the conferees noted that §1648 that was included in the reported version of the bill already includes “a comprehensive plan on Department of Defense support to civil authorities is required as part of a provision requiring the Secretary of Defense to conduct national-level cyber exercises” (pg 838) so that this provision was redundant.

Moving Forward


Last Thursday the House accepted the Conference report by a nearly party-line vote of 270-156. The President has threatened to veto the bill over a disagreement in how the bill gets around the current funding caps. The Senate did, however, vote to close debate on the bill yesterday by a vote of 73-26. That would tend to indicate that there were sufficient votes in both the House and Senate to override a presidential veto. The final vote in the Senate is due today.

Friday, June 26, 2015

Bills Introduced – 06-25-15

Yesterday there were 104 bills introduced in the House and Senate. Four of those bills may be of specific interest to readers of this blog:

HR 2886 To direct the Secretary of Transportation to establish an Automated and Connected Vehicle Research Initiative, and for other purposes. Rep. Lipinski, Daniel [D-IL-3]

HR 2899 To amend the Homeland Security Act of 2002 to authorize the Office for Countering Violent Extremism. Rep. McCaul, Michael T. [R-TX-10]

HR 2933 To amend title 49, United States Code, to establish a local rail facilities and safety program to award grants for freight capacity projects, and for other purposes. Rep. Larsen, Rick [D-WA-2]

H Res 340 Returning to the Senate H.R. 1735, a bill to authorize appropriations for fiscal year 2016 for military activities of the Department of Defense, for military construction, and for defense activities... Rep. Boustany, Charles W., Jr. [R-LA-3]

Based on the testimony presented in yesterday’s hearing on vehicle-to-vehicle communication it seems that the initiative called for in HR 2886 may be a little late. It will be interesting to see the actual language of the bill.

McCaul’s bill will probably only be of tangential interest to readers of this blog, but I certainly want to read the language first.

Unless HR 2933 contains specific language that would affect chemical hazmat shipments, I probably will not mention this bill again.

H Res 340 is one of those inter-house disagreements that is of interest mainly to insiders. It seems that the Parliamentarian of the House concluded that §636 of HR 1735 that was added in the Senate was a violation of Article I, Section 7, Clause 1 of the Constitution:

“All Bills for raising Revenue shall originate in the House of Representatives; but the Senate may propose or concur with Amendments as on other Bills.”


Such usurpation of the prerogatives of the House could not be countenanced and H Res 340 was drafted, offered and passed in the House without comment. The response in the Senate was just as quick; Sen. McCain offered a unanimous consent request that the Clerk of the Senate be directed to remove §636 from the engrossed version of the bill and it was approved without objection or additional discussion. The bill will arrive back in the House today for their decision to accept, amend or request a Conference. Everyone expects a request for Conference.

NOTE: The House accepted the revised HR 1735 yesterday, disagreed with the Senate amendments and requested Conference. Added 6-26-15 9:35 CDT.

Friday, May 15, 2015

House Amends and Passes 2016 NDA

This morning the House finished the amendment process on HR 1735, the National Defense Authorization Act for 2016. A large number of amendments to the bill were adopted including both of the amendments (drone and cybersecurity) that I mentioned in yesterday’s post on the bill. Both of the amendments were included in en bloc considerations adopted by voice vote yesterday. The final vote was a partially bipartisan vote of 269 to 151.


The Senate Armed Services Committee is finishing up their markup of the Senate version of the NDA. The full Senate will take up that bill in the coming weeks. Then a conference committee will be convened to work out the differences in the two bills before it is voted upon again by both house of Congress and shipped off to the President for signature. There has been a presidential threat to veto the current House version of the bill.

Thursday, May 14, 2015

Rules Committee Finalizes Debate Rule for NDA

Yesterday evening the House Rules Committee finished theirwork on the rule for the final consideration of HR 1735, the National Defense Authorization Act of 2016. The House completed the general debate portion of the consideration of the bill yesterday and the amendment process will begin today. The rule establishes a structured debate with only 126 amendments that can be considered on the floor during the consideration of this bill on the floor of the House.

Amendments

There are only two of the amendments that may be considered that might be of specific interest to readers of this blog. The first (#19) requires DOD to submit a report to Congress:

“(T)hat assesses the degree to which existing defense capabilities are able to detect, identify, and potentially disable remotely piloted aircraft within special use and restricted airspace. Requires the Secretary to identify how existing research and development Department resources can be leveraged to strengthen our nation’s ability to detect, identify, and disable unidentified or potentially malicious remotely piloted aircraft”

The second is a cyber security related amendment (#34) that amends an existing DOD contractor beach notification rule to specifically allow sharing of that breach information with entities for purposes of “cybersecurity, national security, and law enforcement”.

The Process

Each amendment must be offered in the order listed. There will be up to 10 minutes of debate on each amendment. At some point in the debate the remaining amendments may be considered en bloc with a single vote. The House is currently scheduled to be in session until Friday afternoon with the last vote to be completed by 3:00 pm EDT. While that ‘last vote’ will not necessarily be HR 1735, it very easily could be.


NOTE: The Senate is still working on their version of the NDA. That bill and this one will have to be reconciled in conference committee. We are a long way from seeing what will be in the final bill and there are no assurances that the President will sign the first pass at this legislation.

Tuesday, April 14, 2015

Bills Introduced – 04-13-15

The first day back in session and 55 bills are introduced. Seven of those may be of specific interest to readers of this blog:

HR 1731 To amend the Homeland Security Act of 2002 to enhance multi-directional sharing of information related to cybersecurity risks and strengthen privacy and civil liberties protections, and for other... Rep. McCaul, Michael T. [R-TX-10]

HR 1735 To authorize appropriations for fiscal year 2016 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year.. Rep. Thornberry, Mac [R-TX-13] 

HR 1738 To amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to modernize and implement the national integrated public alert and warning system to disseminate homeland... Rep. Bilirakis, Gus M. [R-FL-12]

HR 1753 To establish a National Office for Cyberspace, and for other purposes. Rep. Langevin, James R. [D-RI-2]

HR 1763 To provide for the minimum size of crews of freight trains, and for other purposes Rep. Young, Don [R-AK-At Large]

H Res 195 Expressing the sense of the House of Representatives about a national strategy for the Internet of Things to promote economic growth and consumer empowerment. Rep. Lance, Leonard [R-NJ-7] 

S 902 A bill to prohibit trespassing on critical infrastructure used in or affecting interstate commerce to commit a criminal offense. Sen. Schumer, Charles E. [D-NY]

HR 1731 is the new cybersecurity information sharing bill that is being marked up by the House Homeland Security Committee today.

HR 1735, the DOD spending bill, may contain cybersecurity language; we’ll see. This is one of the earliest spending bill introductions that I remember. We may actually see at least some of these passed before the start of the fiscal year.

HR 1738 is the second bill to address the national alerting system introduced this year. The first, HR 1472 is being marked up tomorrow. Unless something odd happens with either of these bills this will be the last time that they are mentioned.

HR 1753 could be interesting or it could be a bust. I’ll have to wait until I see the actual language to see if there is something specifically addressing control system security.

HR 1763 is a train safety issue. Unless the bill includes some specific mention of crude oil trains or hazmat shipments this will be the last mention here.

H Res 195 looks like it may be a response to S Res 110 that I lambasted when it was introduced. I’ll have more on this resolution later today.


S 902 looks like it is a re-issue of S 2934 that was introduced late in the last session of Congress. It was issued so late that I never really took a look at it. I’ll have to wait and see what it actually says before I decide to continue to cover it.
 
/* Use this with templates/template-twocol.html */