Showing posts with label HR 1871. Show all posts
Showing posts with label HR 1871. Show all posts

Wednesday, July 21, 2021

6 Cybersecurity Bills Passed in House – 7-20-21

Yesterday the House passed six cybersecurity bills as part of an en bloc vote on 21 bills that were considered on Monday and Tuesday under the suspension of the rules process. The recorded vote was 319 to 105 with the Republican vote nearly evenly split. The six cybersecurity bills were:

HR 2928 – Cyber Sense Act of 2021

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Monday, July 19, 2021

Committee Hearings – Week of 7-18-21

This week with both the House and Senate meeting in Washington, there will be a full slate of committee hearings. Hearings of interest include the markup of the Senate version of the FY 2022 National Defense Authorization Act, three cybersecurity hearings and the start of the consideration process for FY 2022 spending bills. And we will have an interesting slate of cybersecurity legislation being considered on the floor of the House.

NDAA Markup in Senate

The Senate Armed Services Committee will be marking up their version of the FY 2022 NDAA. Each subcommittee will be meeting to markup their portions of the NDAA on Monday and Tuesday. Then the full Committee will meet Wednesday and probably Thursday to complete the markup process. The subcommittee markups of interest here include:

• Monday - Subcommittee on Cybersecurity. CLOSED

• Tuesday - Subcommittee on Emerging Threats and Capabilities. CLOSED.

Cybersecurity Hearings

On Tuesday the House Small Business Committee will be holding a hearing on “Strengthening the Cybersecurity Posture of America’s Small Business Community”. This hearing is unlikely to specifically address control system security issues. The witness list will include:

• Tasha Cornish, Cybersecurity Association of Maryland, Inc.,

• Sharon Nichols, Mississippi Small Business Development Center,

• Kiersten Todt, Cyber Readiness Institute,

• Graham Dufault, The App Association,

On Tuesday the Subcommittee on Oversight and Investigations of the House Committee on Energy and Commerce will be holding a hearing on "Stopping Digital Thieves: The Growing Threat of Ransomware". This hearing is very likely to specifically address control system security issues and could get fairly technical. The witness list includes:

• Kemba Walden, Microsoft Corporation,

• Robert M. Lee, Dragos,

• Christian Dameff, M.D., M.S., Medical Director of Cybersecurity, UC San Diego Health,

• Charles Carmakal, FireEye-Mandiant

• Philip Reiner, Institute for Security and Technology

On Wednesday, the Senate Environment and Public Works Committee will be holding a hearing on “Addressing Cybersecurity Vulnerabilities Facing Our Nation’s Physical Infrastructure”. While the witness list is not yet available, there is a decent chance that there will be some discussion about control system cybersecurity issues. I would not be surprised to see witnesses from the water treatment sector.

Spending Bills

The House Rules Committee has announced that they are accepting amendments for the first spending bill for FY 2022. The House will be considering a minibus (multiple spending bills under one bill number), probably next week. The amendment deadline is Wednesday evening and the Committee is likely to hold their rulemaking hearing next Monday.

The slate for the first minibus is set to include:

Division A (Labor, Health and Human Services, Education),

Division B (HR 4356 – Agriculture, Rural Development),

Division C (Energy and Water Development),

Division D (HR 4345 – Financial Services and General Government),.

Division E (HR 4372 – Interior, Environment),

Division F (HR 4355 – Military Construction, Veterans Affairs),

Division G (Transportation, Housing, and Urban Development),

I do not typically review the FSG, or MCV spending bills, and the ARD bill contained nothing that I cover in this blog. The LHHS and THUD bills will probably be introduced today.

On the Floor

The House will be spreading their 27 bills considered under suspension of the rules over two days this week. The list includes seven cybersecurity bills:

• Monday

HR 2931 – Enhancing Grid Security through Public-Private Partnerships Act,

HR 2928 – Cyber Sense Act of 2021

• Tuesday

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Republicans have been forcing recorded votes on the suspension bills. Democrats have responded by voting on some and including the remainder in the vote on the language of the rule for consideration of bills under regular order. This may make reporting passage of these bills somewhat piece meal.

Saturday, March 20, 2021

Homeland Security Markups – 3-18-21

On Thursday the House Homeland Security Committee held a markup hearing on seven bills. All of the bills were passed by unanimous consent after three of the bills were amended. The four bills that I have covered here in this blog included:

HR 1833 – Amended and passed,

HR 1850 – Passed,

HR 1871 – Passed

HR 1833 – DHS ICS Capabilities Enhancement Act

There were two amendments adopted for this bill. The first was proposed by Rep Langevin (D,RI). It inserted the words ‘Sector Risk Management Agencies’ in three places in the bill, indicating the need for NCCIC-ICS to coordinate their ICS security tasks in coordination with these agencies. This brings the bill more in-line with HR 5733 that was introduced in 2018.

The second amendment was proposed by Rep Torres (D,NY). It added a requirement for a GAO report within 2 years of the passage of this bill. GAO would be specifically tasked to address {new §2(c)}:

•Any interagency coordination challenges to the ability of the Director of the CISA to lead Federal efforts to identify and mitigate cybersecurity threats to industrial control systems,

• The degree to which the Agency has adequate capacity, expertise, and resources to carry out threat hunting and incident response capabilities to mitigate cybersecurity threats to industrial control systems, as well as additional resources that would be needed to close any operational gaps in such capabilities.

• The extent to which industrial control system stakeholders sought cybersecurity technical assistance from the Agency, and the utility and effectiveness of such technical assistance.

• The degree to which the Agency works with security researchers and other industrial control systems stakeholders to provide vulnerability information to the industrial control systems community.

Moving Forward

The unanimous consent passage of these measures indicates that there is wide spread, bipartisan support for all of these bills. I expect that all these bills will move to the floor of the House under the suspension of the rules process. Typically bills will not be considered by the Full House until reports are published, but that is not a requirement. I would not be surprised to see HR 1833 move to the floor when the House returns to session after the Easter break on April 13th.

Wednesday, March 17, 2021

HR 1871 Introduce - Transportation Security Transparency Improvement

Last week Rep Bishop (R,NC) introduced HR 1871 (GPO version not yet published, this is link to the Committee Print of the bill), the Transportation Security Transparency Improvement Act. The bill would require the TSA to review procedures and guidelines for the use of the Sensitive Security Information (SSI) designation of information.

SSI Review

Section 2(a) of the bill would require TSA to {§2(a)(1)}:

• Ensure clear and consistent designation of ‘‘Sensitive Security Information’’, including reasonable security justifications for such designation;

• Develop and implement a schedule to regularly review and update, as necessary, TSA Sensitive Security Information Identification guidelines;

• Develop a tracking mechanism for all Sensitive Security Information redaction and designation challenges;

• Document justifications for changes in position regarding Sensitive Security Information redactions and designations, and make such changes accessible to TSA personnel for use with relevant stakeholders, including air carriers, airport operators, surface transportation operators, and State and local law enforcement, as necessary; and

• Ensure that TSA personnel are adequately trained on appropriate designation policies.

Additionally, TSA would be required to conduct an outreach program to affected stakeholders “that regularly are granted access to Sensitive Security Information to raise awareness of the TSA’s policies and guidelines governing the designation and use of Sensitive Security Information” {§2(a)(2)}.

Moving Forward

As I previously reported, this bill is being considered by the House Homeland Security Committee on Thursday. I see nothing in this bill that would engender any organized opposition. I expect that it will receive broad bipartisan support in Committee. The bill would almost certainly be considered by the full House under the suspension of the rules process.

Commentary

The TSA’s SSI program is one of the sensitive but unclassified (SBU) information protection programs established after the 9/11 attacks. As with any information restriction program, it has been subject to criticism for over classification and abuse of classification over the years. Periodic reviews of these types of programs are certainly necessary.

The other portion of this bill dealing with security at ‘last point of departure airports’ (and I am not expanding this blog to cover that nightmare) includes both a ‘report to Congress’ requirement and an prevention of judicial review statement. Neither apply to the SSI provision.

I find it odd that there is no report to Congress provision in Section 2(a). The whole point of conducting a review is to establish accountability. This would be easy to correct by striking §2(b)(2) and adding a new §3:

“Section 3 – Report to Congress - Not later than 180 days after the date of the enactment of this Act, the Administrator of the Transportation Security Administration shall prepare a report for the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate on the guidelines described in Section 2. A copy of the Report will be posted on the Transportation Security Administration’s web site.”

Monday, March 15, 2021

Additional Markup Hearing Announced – 3-15-21

This afternoon the House Homeland Security Committee announced that it would hold a markup hearing on Thursday for seven recently introduced bills. The bills include:

HR 1833, the “DHS Industrial Control Systems Capabilities Enhancement Act of 2021”,

HR 1850, the “Supporting Research and Development for First Responders Act”,

HR 1871, the “Transportation Security Transparency Improvement Act”.

All three of these bills were introduced last week and the official, GPO, copies of these have not yet been published (probably will not be for about a month). The hearing website provides links to ‘committee prints’ of each of the bills listed and those are the links I have included above.

HR 1850

I did not announce the introduction of HR 1850 last week, because the bill description did not indicate anything of interest. Looking at the committee print, there is one subparagraph in the bill describing the activities of the National Urban Security Technology Laboratory (NUSTL) that has caused me to reevaluate that decision {new 6 USC 322(c)(1)}:

“(1) conduct tests, evaluations, and assessments of current and emerging technologies, including, as appropriate, the cybersecurity of such technologies that can connect to the internet [emphasis added], for emergency response providers;”

HR 1833 and HR 1871

I will be doing separate reviews of each of these bills before the markup hearing.

Saturday, March 13, 2021

Bills Introduced – 3-12-21

Yesterday, with just the House in session, there were 29 bills introduced. Two of those bills may received additional coverage in this blog:

HR 1870 To require the Secretary of Homeland Security to prioritize strengthening of local transportation security capabilities by assigning certain officers and intelligence analysts to State, local, and regional fusion centers in jurisdictions with a high-risk surface transportation asset and improving the timely sharing of information regarding threats of terrorism and other threats, including targeted violence, and for other purposes. Rep. Barragan, Nanette Diaz [D-CA-44]

HR 1871 To improve the understanding and clarity of Transportation Security Administration policies, and for other purposes. Rep. Bishop, Dan [R-NC-9]

I will be watching both of these bill for language and definitions that indicate coverage of chemical transportation security issues. I suspect that HR 1871 is less likely to include such language.

 
/* Use this with templates/template-twocol.html */