Showing posts with label HR 1833. Show all posts
Showing posts with label HR 1833. Show all posts

Sunday, August 1, 2021

S 2439 Introduced - DHS ICS Capabilities Enhancement

Last month, Sen Peters (D,MI) introduced S 2439, the DHS Industrial Control Systems Capabilities Enhancement Act. The bill is nearly identical to the version of HR 1833 which passed in the House on July 20th, 2021. The bill is currently scheduled to be considered by the Senate Homeland Security and Governmental Affairs Committee on Wednesday.

I made the following point in my post on HR 1833 that is also applicable to this bill:

“First off, it should be obvious to those that follow the control system security activities of CISA that this bill does not actually cause the Agency to undertake any new actions. It merely codifies the authority of CISA to do what it has been doing for quite some time. That could, however, be important in any period of budget constraint; agencies would be more likely to cut back programs and processes that have not been specifically authorized by Congress.”

I also made comment about my favorite topic definition of terms:

“As I was with HR 5733 [version of this bill in the 116th Congress, link added], I am concerned that the bill did not modify the subsection (c), Functions, portion of §659 to specifically address the industrial control system support outlined in the new subsection (p). While there are numerous mentions of similar cybersecurity responsibilities, all of the mentions include using terms defined in §659(a) that rely on the IT restrictive definition of information systems. If Congress is not going to address those definitional issues (and that is probably considered by the crafters of this bill as being beyond the scope of the legislation) then they should have included adding a subsection to §659(c) like this:

“(12) supporting the cybersecurity operations of industrial control systems as outlined in (p).”

Wednesday, July 21, 2021

6 Cybersecurity Bills Passed in House – 7-20-21

Yesterday the House passed six cybersecurity bills as part of an en bloc vote on 21 bills that were considered on Monday and Tuesday under the suspension of the rules process. The recorded vote was 319 to 105 with the Republican vote nearly evenly split. The six cybersecurity bills were:

HR 2928 – Cyber Sense Act of 2021

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Monday, July 19, 2021

Committee Hearings – Week of 7-18-21

This week with both the House and Senate meeting in Washington, there will be a full slate of committee hearings. Hearings of interest include the markup of the Senate version of the FY 2022 National Defense Authorization Act, three cybersecurity hearings and the start of the consideration process for FY 2022 spending bills. And we will have an interesting slate of cybersecurity legislation being considered on the floor of the House.

NDAA Markup in Senate

The Senate Armed Services Committee will be marking up their version of the FY 2022 NDAA. Each subcommittee will be meeting to markup their portions of the NDAA on Monday and Tuesday. Then the full Committee will meet Wednesday and probably Thursday to complete the markup process. The subcommittee markups of interest here include:

• Monday - Subcommittee on Cybersecurity. CLOSED

• Tuesday - Subcommittee on Emerging Threats and Capabilities. CLOSED.

Cybersecurity Hearings

On Tuesday the House Small Business Committee will be holding a hearing on “Strengthening the Cybersecurity Posture of America’s Small Business Community”. This hearing is unlikely to specifically address control system security issues. The witness list will include:

• Tasha Cornish, Cybersecurity Association of Maryland, Inc.,

• Sharon Nichols, Mississippi Small Business Development Center,

• Kiersten Todt, Cyber Readiness Institute,

• Graham Dufault, The App Association,

On Tuesday the Subcommittee on Oversight and Investigations of the House Committee on Energy and Commerce will be holding a hearing on "Stopping Digital Thieves: The Growing Threat of Ransomware". This hearing is very likely to specifically address control system security issues and could get fairly technical. The witness list includes:

• Kemba Walden, Microsoft Corporation,

• Robert M. Lee, Dragos,

• Christian Dameff, M.D., M.S., Medical Director of Cybersecurity, UC San Diego Health,

• Charles Carmakal, FireEye-Mandiant

• Philip Reiner, Institute for Security and Technology

On Wednesday, the Senate Environment and Public Works Committee will be holding a hearing on “Addressing Cybersecurity Vulnerabilities Facing Our Nation’s Physical Infrastructure”. While the witness list is not yet available, there is a decent chance that there will be some discussion about control system cybersecurity issues. I would not be surprised to see witnesses from the water treatment sector.

Spending Bills

The House Rules Committee has announced that they are accepting amendments for the first spending bill for FY 2022. The House will be considering a minibus (multiple spending bills under one bill number), probably next week. The amendment deadline is Wednesday evening and the Committee is likely to hold their rulemaking hearing next Monday.

The slate for the first minibus is set to include:

Division A (Labor, Health and Human Services, Education),

Division B (HR 4356 – Agriculture, Rural Development),

Division C (Energy and Water Development),

Division D (HR 4345 – Financial Services and General Government),.

Division E (HR 4372 – Interior, Environment),

Division F (HR 4355 – Military Construction, Veterans Affairs),

Division G (Transportation, Housing, and Urban Development),

I do not typically review the FSG, or MCV spending bills, and the ARD bill contained nothing that I cover in this blog. The LHHS and THUD bills will probably be introduced today.

On the Floor

The House will be spreading their 27 bills considered under suspension of the rules over two days this week. The list includes seven cybersecurity bills:

• Monday

HR 2931 – Enhancing Grid Security through Public-Private Partnerships Act,

HR 2928 – Cyber Sense Act of 2021

• Tuesday

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Republicans have been forcing recorded votes on the suspension bills. Democrats have responded by voting on some and including the remainder in the vote on the language of the rule for consideration of bills under regular order. This may make reporting passage of these bills somewhat piece meal.

Friday, May 14, 2021

Cybersecurity Legislation Watch – 5-14-21

I received two emails from Congress.gov this morning about the publication of text for two cybersecurity bills. Anyone can sign up for this service for tracking changes in the files for individual pieces of legislation on that site. It has been especially valuable to me this session because of the large number of bills being introduced and the problems the Government Printing Office is having publishing text of those bills in a timely manner.

Anyway, back to the two bills. The two cybersecurity bills are:

HR 2980, the Cybersecurity Vulnerability Remediation Act, and

HR 3138, the State and Local Cybersecurity Improvement Act

Generally speaking, the GPO tries to publish the text of bills in the order that they were introduced. This keeps them out of problems with congresscritters screaming favoritism when someone else’s bill is published first. These two bills, however, are being published well outside of that sequence. This typically means that the leadership has notified the GPO of their particular interest in seeing these bills published early in the que.

Now I have not had time yet to do a detailed comparison, but it looks like each of these bills is substantially the same as bills introduced in the 116th Congress:

• HR 2980 – HR 3710, which passed in the House on September 26th, 2019, and

• HR 3138 – HR 5823, which passed in the House on September 30th, 2020

I suspect that later this afternoon when the House Majority Leader’s ‘The Weekly Leader’ is published outlining what will be happening in the House next week, we will see both of these bill on the list of bills that will be considered under the suspension of the rules process. Bills are not typically seen on the floor before they are considered in committee, but with the current attention on cybersecurity and the fact that both bills went through the committee process last session, this would not be a very unusual process.

There are two other cybersecurity bills that could also be considered on the floor next week, as they have both been considered in committee:

HR 1833, the DHS ICS Capabilities Enhancement Act, and

HR 1850, the Supporting Research and Development for First Responders Act

Saturday, March 20, 2021

Homeland Security Markups – 3-18-21

On Thursday the House Homeland Security Committee held a markup hearing on seven bills. All of the bills were passed by unanimous consent after three of the bills were amended. The four bills that I have covered here in this blog included:

HR 1833 – Amended and passed,

HR 1850 – Passed,

HR 1871 – Passed

HR 1833 – DHS ICS Capabilities Enhancement Act

There were two amendments adopted for this bill. The first was proposed by Rep Langevin (D,RI). It inserted the words ‘Sector Risk Management Agencies’ in three places in the bill, indicating the need for NCCIC-ICS to coordinate their ICS security tasks in coordination with these agencies. This brings the bill more in-line with HR 5733 that was introduced in 2018.

The second amendment was proposed by Rep Torres (D,NY). It added a requirement for a GAO report within 2 years of the passage of this bill. GAO would be specifically tasked to address {new §2(c)}:

•Any interagency coordination challenges to the ability of the Director of the CISA to lead Federal efforts to identify and mitigate cybersecurity threats to industrial control systems,

• The degree to which the Agency has adequate capacity, expertise, and resources to carry out threat hunting and incident response capabilities to mitigate cybersecurity threats to industrial control systems, as well as additional resources that would be needed to close any operational gaps in such capabilities.

• The extent to which industrial control system stakeholders sought cybersecurity technical assistance from the Agency, and the utility and effectiveness of such technical assistance.

• The degree to which the Agency works with security researchers and other industrial control systems stakeholders to provide vulnerability information to the industrial control systems community.

Moving Forward

The unanimous consent passage of these measures indicates that there is wide spread, bipartisan support for all of these bills. I expect that all these bills will move to the floor of the House under the suspension of the rules process. Typically bills will not be considered by the Full House until reports are published, but that is not a requirement. I would not be surprised to see HR 1833 move to the floor when the House returns to session after the Easter break on April 13th.

Tuesday, March 16, 2021

HR 1833 Introduced – DHS ICS Capabilities Enhancement Act

Last week Rep. Katko (R,NY) introduced HR 1833 (link is to Committee Print of bill), the DHS Industrial Control Systems Capabilities Enhancement Act of 2021. The bill is very similar to HR 5733 that was introduced in the 115th Congress and passed in the House in June of 2018. The bill would amend 6 USC 659(e)(1) to ensure that “activities of the Center [NCCIC] address the security of both information technology and operational technology, including industrial control systems” {new 659(3)(1)(I)}.

Industrial Control Systems

In addition to the amendment cited above the bill would also add a new subsection (p) to §659, Industrial Control Systems. That new subsection would require the Cybersecurity and Infrastructure Security Agency (CISA) to:

• Lead Federal Government efforts to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems,

• Maintain threat hunting and incident response capabilities to respond to industrial control system cybersecurity risks and incidents,

• Provide cybersecurity technical assistance to industry end-users, product manufacturers, other Federal agencies, and other industrial control system stakeholders to identify, evaluate, assess, and mitigate vulnerabilities,

• Collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, other Federal agencies, and other industrial control systems stakeholders, and

• Conduct such other efforts and assistance as the Secretary determines appropriate.

Moving Forward

Katko, and a number of his bipartisan cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for consideration. The fact that Katko is the Ranking Member of the Committee and Rep Thompson (D,MS) is the Chair explains the early consideration (markup this coming Thursday) of this bill by the Committee. The bill is almost certain to receive wide spread bipartisan support in Committee and by the Full House. The bill will be considered in the near future by the House under the suspension of the rules process.

Commentary

First off, it should be obvious to those that follow the control system security activities of CISA that this bill does not actually cause the Agency to undertake any new actions. It merely codifies the authority of CISA to do what it has been doing for quite some time. That could, however, be important in any period of budget constraint; agencies would be more likely to cut back programs and processes that have not been specifically authorized by Congress.

While this bill is similar to HR 5733 there are some interesting changes. First, for clarity’s sake, the section numbering is different because Congress rewrote much of the 6 USC when they stood up CISA as a separate agency within DHS back in November of 2018. For more substantive changes we need only look at the new subsection (p) in comparison to the same addition in the engrossed version of HR 5733.

First is (p)(1) the new version does not contain the phrase ‘in coordination with relevant sector specific agencies,’ following the opening word ‘lead’. This would reinforce the status of CISA as the lead agency for cybersecurity concerns in industrial control systems. This is further reinforced by adding the phrase ‘other Federal agencies’ to the list of entities to which CISA would be required in (p)(3) to provide technical assistance. This reinforcement is extended again in (p)(4) where the same phrase is added to the list of entities in the ‘industrial control system community’ that CISA would be expected to work with in collecting, coordinating, and providing vulnerability information.

As I was with HR 5733, I am concerned that the bill did not modify the subsection (c), Functions, portion of §659 to specifically address the industrial control system support outlined in the new subsection (p). While there are numerous mentions of similar cybersecurity responsibilities, all of the mentions include using terms defined in §659(a) that rely on the IT restrictive definition of information systems. If Congress is not going to address those definitional issues (and that is probably considered by the crafters of this bill as being beyond the scope of the legislation) then they should have included adding a subsection to §659(c) like this:

“(12) supporting the cybersecurity operations of industrial control systems as outline in (p).”

Monday, March 15, 2021

Additional Markup Hearing Announced – 3-15-21

This afternoon the House Homeland Security Committee announced that it would hold a markup hearing on Thursday for seven recently introduced bills. The bills include:

HR 1833, the “DHS Industrial Control Systems Capabilities Enhancement Act of 2021”,

HR 1850, the “Supporting Research and Development for First Responders Act”,

HR 1871, the “Transportation Security Transparency Improvement Act”.

All three of these bills were introduced last week and the official, GPO, copies of these have not yet been published (probably will not be for about a month). The hearing website provides links to ‘committee prints’ of each of the bills listed and those are the links I have included above.

HR 1850

I did not announce the introduction of HR 1850 last week, because the bill description did not indicate anything of interest. Looking at the committee print, there is one subparagraph in the bill describing the activities of the National Urban Security Technology Laboratory (NUSTL) that has caused me to reevaluate that decision {new 6 USC 322(c)(1)}:

“(1) conduct tests, evaluations, and assessments of current and emerging technologies, including, as appropriate, the cybersecurity of such technologies that can connect to the internet [emphasis added], for emergency response providers;”

HR 1833 and HR 1871

I will be doing separate reviews of each of these bills before the markup hearing.

Friday, March 12, 2021

Bills Introduced – 3-11-21

Yesterday, with both the House and Senate in session, there were 146 bills introduced. Two of those bills will receive additional coverage in the blog:

HR 1804 To amend the public participation requirements of the Comprehensive Environmental Response, Compensation, and Liability Act of 1980, and for other purposes. Rep. Carter, Earl L. "Buddy" [R-GA-1]

HR 1833 To amend the Homeland Security Act of 2002 to provide for the responsibility of the Cybersecurity and Infrastructure Security Agency to maintain capabilities to identify threats to industrial control systems, and for other purposes. Rep. Katko, John [R-NY-24]

Interesting turn of phrase “maintain capabilities to identify threats to industrial control systems” in the description of HR 1833. I look forward to seeing what it actually means.

NOTE: Corrected date in title to date of introduction 3-13-21 06:45 EST

 
/* Use this with templates/template-twocol.html */