Showing posts with label HR 1960. Show all posts
Showing posts with label HR 1960. Show all posts

Sunday, June 30, 2013

S 1197 Introduced – FY 2014 DOD Authorization

As I noted earlier Sen. Levin (D,MI) introduced S 1197, the National Defense Authorization Act for Fiscal Year 2014, and the bill has been reported favorably by the Senate Armed Services Committee. As expected the bill has some significant cybersecurity provisions including support for the development of tools for checking software code vulnerability, looking at the use of National Guard troops for homeland cyber-response tasks and controls on the trade in ‘cyber-weapons’.

Cyberspace Subtitle

Subtitle D of Title IX (DOD Organization and Management) deals with ‘Cyberspace-Related Matters’. Most of the provisions relate to cyber-warfare but some deal with cybersecurity related matters. The eight sections within the Subtitle are:

• Section 941: Authorities, capabilities, and oversight of the United States Cyber Command.
• Section 942: Joint software assurance center for the Department of Defense.
• Section 943: Supervision of the acquisition of cloud computing capabilities for intelligence analysis.
• Section 944: Cyber vulnerabilities of Department of Defense weapon systems and tactical communications systems.
• Section 945: Strategy on use of the reserve components of the Armed Forces to support Department of Defense cyber missions.
• Section 946: Control of the proliferation of cyber weapons.
• Section 947: Integrated policy to deter adversaries in cyberspace.
• Section 948: Centers of Academic Excellence for Information

Probably the most significant of the DOD provisions in this Subtitle can be found in §941. It provides for the separation of the DOD cyber-warfare (offensive and defensive) organizations from the cyber intelligence program and the information security program in DOD. This specifically includes providing separate hardware and internet access capabilities for US Cyber Command (USCC) separate from the National Security Agency. It does not, however, address the current fact that the commander of both the NSA and the USCC are the same person.

Software Assurance Tools

Section 942 requires DOD to establish a Joint Software Assurance Center separate from the one established by the National Security Agency (more separation of USCC from NSA). The new JSAC would work with the NSA agency to establish a “program of research and development to improve automated software code vulnerability analysis and testing tools” {§942(c)(3)}.

The Committee report further emphasizes this the importance of this program in the Committee report (pg 46, Adobe 69) by providing an additional $10 million for the Air Force version of this proposed organization, Application Software Assurance Center of Excellence (ASACOE).

The Committee report also notes that this proposed JSAC would help the military comply with the §933 requirements of the FY 2103 National Defense Authorization Act.

There is nothing in §942 that would address the availability of such tools for work in the civilian sector, but it is reasonable to suppose that it might be made available to DHS in support of cybersecurity activities in the critical infrastructure sectors.

Homeland Cyber Response

It is apparent that the use of National Guard cyber-warriors is the ‘cybersecurity’ idea of the year. We have seen it proposed in two identical bills (HR 1640 and S 658) and a version was included in the House DOD spending bill, HR 2397, Committee Report. This bill provides yet a third version of the idea as part of §945 examination of the use of the Reserve Components in DOD cyber missions.

DOD and DHS would be required to take a coordinated look at the use of National Guard in a cyber homeland defense role. The bill specifically tasks the two departments to get input from the Governors on “State cyber capabilities, and State cyber needs that cannot be fulfilled through the private sector” {§945(b)(2)}. This is part of the requirement to determine if the National Guard, operating under State status “can operate under unique and useful authorities to support domestic cyber missions and requirements of the Department or the United States Cyber Command” {§945(b)(4)}.

The bill even goes so far as to suggest that DOD looks into if it would be appropriate to hire part-time National Guard Technicians with appropriate cybersecurity expertise to assist “the National Guard in protecting critical infrastructure [emphasis added] and carrying out cyber security missions in defense of the United States homeland” {§945(b)(5)}.

Operation of the National Guard units under State status is an important legal distinction. Because of restrictions on the domestic use of military forces under the Posse Comitatus Act (18 USC 1385) it would be necessary to use National Guard units under the command of Governors to participate in many cyber related homeland defense missions.

Control of Cyber Weapons

Section 946 addresses attempt to control the international trade in cyber weapons. It requires the President to establish yet another “interagency process to provide for the establishment of an integrated policy to control the proliferation of cyber weapons” {§946(a)}.

Since there is not currently a legal definition of ‘cyber weapons’ the same interagency process is also required to identify “the types of dangerous software that can and should be controlled through export controls” {§946(b)(1)}. The Committee Report notes:

“This process will require developing definitions and categories for controlled cyber technologies and determining how to address dual use, lawful intercept, and penetration testing technologies.” (pg 159, Adobe 181)

It is clear that someone on the Senate Armed Forces Committee staff realizes that many of these ‘cyber weapons’ might have legitimate uses in the cybersecurity field. The Committee Report states:

“However, the approaches developed must also take into account the needs of legitimate cybersecurity professionals to mitigate vulnerabilities, and not stifle innovation in tools and technology that are necessary for national security and the cybersecurity of the Nation.” (pg 160, Adobe 182)

The section requires the identification of methods that should be used to “suppress the trade in cyber tools and infrastructure that are or can be used for criminal, terrorist, or military activities while preserving the ability of governments and the private sector to use such tools for legitimate purposes of self-defense” {§946(b)(2)}.

Moving Forward


I expect that the Senate will move forward with its consideration of S 1197 in the few weeks remaining before the Summer Recess. The bill will pass after some significant amendments are offered and wrangled over. The Senate will then vote to substitute the wording from this bill for the House wording of HR 1960. The bill will then go to conference to work out the differences between the two bills. That won’t happen until sometime later this year, probably after the start of FY 2014.

Friday, June 14, 2013

House Passes HR 1960 with 5 of 6 Cyber Amendments

This afternoon the House passed HR 1960, the National Defense Authorization Act for Fiscal Year 2014 with a bipartisan vote (315 – 108). The fifth cyber-amendment was adopted earlier in the day on a voice vote with a number of other amendments in en bloc amendments #8. The one remaining cyber-amendment {102 #267 Version 1 DeSantis (R,FL)} approved by the House Rules Committee earlier this week was not considered by the House.


Thursday, June 13, 2013

House Adopts Some Cybersecurity Amendments to HR 1960

Today the House began consideration of the amendments to HR 1960, the DOD FY 2014 Authorization bill. As expected this will be a multi-day consideration process.  The Committee of the Whole House (the procedure under which legislation is debated) considered and adopted four of the six amendments that I described in an earlier blog post. Those bills were adopted en bloc by a voice vote. They included:

• 98 #220 Version 2 Cárdenas (D,CA) Revised Ensures that an assessment of the retention, recruitment, and management of the cyber operation forces is included in a comprehensive mission analysis of cyber operations by the Department of Defense.

• 99 #218 Version 2 Cárdenas (D,CA) Revised Ensures that the investigations launched by the Department of Defense related to the compromise of critical program information include an estimate of economic losses resulting from the intrusion and any actions needed to protect intellectual property.

• 100 #126 Version 1 Ruiz, Raul (D,CA) Requires the Secretary of Defense to submit a report to the Congress on the feasibility of establishing a small business cyber technology office to assist small business concerns in providing cybersecurity solutions to the Federal Government.

• 101 #219 Version 1 Cárdenas (D,CA) Authorizes the Department of Defense to create a education program to assist small business understand cyber security threats.


The remaining two cybersecurity amendments will probably be considered tomorrow.

Rules Committee Adopts Rule for Amending HR 1960

Early this morning the House Rules Committee adopted H Res 260, a structured rule for the consideration of amendments to HR 1960, the FY 2014 DOD authorization bill. The rule provides for the consideration of 172 amendments to the bill on the floor of the House with up to 10 minutes of debate authorized for each of the amendments (this could take some time).

There is an interesting provision of the rule which could significantly shorten the time it takes to consider these amendments. At any time in the debate the Chair of the House Armed Services Committee can offer the remain amendments en-bloc (all at one vote) with just 20 minutes of debate for all of the amendments to be considered. This makes it more likely that the later amendments in this extensive list will be adopted.

Cybersecurity Amendments

Six of the amendments to be considered deal with cybersecurity issues.

• 98 #220 Version 2 Cárdenas (D,CA) Revised Ensures that an assessment of the retention, recruitment, and management of the cyber operation forces is included in a comprehensive mission analysis of cyber operations by the Department of Defense.

• 99 #218 Version 2 Cárdenas (D,CA) Revised Ensures that the investigations launched by the Department of Defense related to the compromise of critical program information include an estimate of economic losses resulting from the intrusion and any actions needed to protect intellectual property.

• 100 #126 Version 1 Ruiz, Raul (D,CA) Requires the Secretary of Defense to submit a report to the Congress on the feasibility of establishing a small business cyber technology office to assist small business concerns in providing cybersecurity solutions to the Federal Government.

• 101 #219 Version 1 Cárdenas (D,CA) Authorizes the Department of Defense to create a education program to assist small business understand cyber security threats.

• 102 #267 Version 1 DeSantis (R,FL) Prohibits funds from being authorized for collaborative cyber-security activities with the People's Republic of China.

• 166 #117 Version 1 Issa (R,CA) , Connolly (D,VA) Reforms the process by which Federal agencies procure products and services related to information technology.

NOTE: The first number in the above listing shows the order in which the amendment will be considered. It will be interesting to see at what point in the debate that the decision is made to consider the remaining amendments en bloc.

I have not yet had a chance to review them in detail but it does not appear that any of them specifically deal with control system security issues.

Moving Forward


The debate on HR 1960 could resume any time after H Res 260 is adopted by the House. I expect that that vote will happen today and we will see late night sessions today and tomorrow with a vote on the final bill on Friday morning. The bill will certainly pass, probably with substantial bipartisan support. Gaining that Democratic support is the main reason for the consideration of so many amendments.

Wednesday, June 12, 2013

House Rules Committee Adopts Initial Rule for HR 1960

Last night the House Rules Committee adopted the rule for the consideration of HR 1960, the FY 2014 DOD authorization bill. This rule (H. Res. 256) only covers the initial debate; a separate Rules Committee hearing this afternoon will consider what amendments will be debated and voted upon before the bill is brought to an actual vote.

Adoption of this Resolution, probably today, will clear the House for a 1 hour debate on the general merits of the bill. No amendments will be offered and no votes will take place.


As I noted in an earlier blog there are several cybersecurity related provisions included in the latest version of this bill. None of them deal specifically with control systems or non-defense related computer systems, but they may have an impact on future proposed cybersecurity legislation. Due to the size of the defense related (government, contract and vendor) computer system foot print these provisions could also influence how vendors handle cybersecurity issues in general.

Monday, June 10, 2013

Congressional Hearings – Week of 6-9-13

The summer recess gets a week closer and more attention gets turned to passing money bills. Both the Defense Authorization and Appropriations bills will be the topic of hearings this week. There will also be a counterterrorism hearing, a discussion about DHS communications with the public and a high level cybersecurity hearing.

Defense Department Money

As I mentioned earlier today the House Rules Committee will be holding two hearings on HR 1960. Tuesday there will be a rules hearing and Wednesday there will be the second hearing to consider what amendments will make it to the floor.

Also on Wednesday the House Appropriations Committee will be holding a markup of the FY 2014 DOD spending bill. There are currently no specific cybersecurity provisions in the bill, but we may see some added to the bill or the accompanying committee report.

Counterterrorism

The Subcommittee on Counterterrorism and Intelligence of the House Homeland Security Committee will be holding a hearing on Wednesday to look at "Protecting the Homeland Against Mumbai-Style Attacks and the Threat from Lashkar-e-Taiba”. The witness list includes:

• Dr. C. Christine Fair, Georgetown University;
• Mr. Joseph W. Pfeifer, New York City Fire Department
• Dr. Stephen Tankel, American University

DHS Communications

The Subcommittee on Oversight and Management Efficiency of the House Homeland Security Committee will be holding a hearing on Friday about “Why Can’t DHS Better Communicate with the American People?” The witness list includes:

• Mr. Robert Jensen, U.S. Department of Homeland Security
• Mr. Douglas Pinkham, Public Affairs Council

Cybersecurity

The Senate Appropriations Committee will be holding a public hearing (followed by a classified session) on Wednesday about “Cybersecurity: Preparing for and responding to the enduring threat”. The witness list includes:

• General Keith B. Alexander, U.S. Cyber Command and National Security Agency
• Rand Beers, Department of Homeland Security
• Patrick Gallagher, National Institute of Standards and Technology
• Richard McFeely, Federal Bureau of Investigation


There will certainly be questions asked about the development of the Cybersecurity Framework and its implementation.

Sunday, June 9, 2013

HR 1960 Reported in House – FY 2014 NDA

On Friday the House Armed Services Committee reported (though the House was not in session) HR 1960, the National Defense Authorization Act for Fiscal Year 2014. A copy of the actual report is not currently available at the GPO site, but it is available on the Library of Congress site by clicking on the report number.

Cybersecurity

I mentioned in an earlier post that the version of HR 1960 that was introduced did not have any cybersecurity language, but that that might change during the ‘legislative process’. That is certainly the case now. The following cybersecurity related sections are now in the bill:

Sec. 214. Limitation on availability of funds for defensive cyberspace operations of the Air Force.
Sec. 811. Additional contractor responsibilities in regulations relating to detection and avoidance of counterfeit electronic parts.
Sec. 812. Amendments relating to detection and avoidance of counterfeit electronic parts.
Subtitle D—Cyberspace-Related Matters
Sec. 931. Modification of requirement for inventory of Department of Defense tactical data link systems.
Sec. 932. Defense Science Board assessment of United States Cyber Command.
Sec. 933. Mission analysis for cyber operations of Department of Defense.
Sec. 934. Notification of investigations related to compromise of critical program information.
Sec. 935. Additional requirements relating to the software licenses of the Department of Defense.

Section 214 is probably the most significant in the terms of money in that it withholds 10% of the Air Force FY 2014 funding for procurement, RDT&E, and Defensive Cyberspace Operations until 30 days after the Secretary of the Air Force submits a report to Congress on the Application Software Assurance Center of Excellence. No additional information on this section is available in the Committee Report.

Section 932 will probably have a longer term impact on DOD cyber-operations. A major component of this study will be the review of the command relationship between the United States Cyber Command and the National Security Agency since the Commander and the Director are one and the same person. The Defense Science Board is specifically tasked with looking at that relationship and:

• The positive and negative impact on the Command resulting from a single individual simultaneously serving as the Commander of the United States Cyber Command and the Director of the National Security Agency {§932(b)(1)(A)};
• How the respective oversight activities of the Commander and the Director affect the ability of each entity to complete the respective missions of such entity {§932(b)(1)(B)};
• The dependencies of the Command and the Agency on one another {§932(b)(1)(C)};
• The ability of the existing management structure of the Command and the Agency to identify and adequately address potential conflicts of interest {§932(b)(1)(D)};
• The ability of the Department of Defense to train and develop, through professional assignment, individuals with the appropriate subject-matter expertise and management experience to support both the cyber operations missions of the Command and the signals intelligence missions of the Agency {§932(b)(1)(D)}.

The importance of this report is further highlighted by the requirement of a follow-up report (within 30 days) by the Secretary of Defense and the Director of National Intelligence on their assessment of the situation {§932(c)(2)}.

The report to Congress required by §933 sounds fairly straight forward when reading the legislative language. It is when you get to the discussion of the section in the Committee Report that the full import of this report. That discussion makes it clear that ‘cyber-operations’ are not limited to nice, clean digital attacks, but incorporates the full spectrum of military response including “a mix of forces necessary to conduct assured operations, including systems such as penetrating bombers, submarines with long range cruise missiles, Conventional Prompt Global Strike (CPGS), and survivable senior leadership command and control.”

A portion of this report seems to be directly targeted at the provisions of HR 1640 and S 658, the Cyber Warrior Act of 2013. The legislative language requires the Chief of the National Guard Bureau to report to Congress on his “assessment of the role of the National Guard in supporting the cyber operations mission of the Department of Defense” {§933(d)}. The Committee report language goes much further:

“While the committee supports these considerations, it is also concerned that current legislative proposals to dictate National Guard units for each of the states and territories is premature and may be detrimental to the overall national effort. In addition to the hefty price tag, which is estimated to be about $400.0 million per year, current proposals only address National Guard participation and do not include the Reserve Component. Whereas only the Army and the Air Force have National Guard units, all of the military services have Reserve Components that have unique authorities and capabilities that should be addressed by the national effort. The committee believes that more time is needed to evaluate full participation of the Reserve Components, including the implications and limitations of using National Guard forces in a `title 32' capacity, before broader action is taken. The committee encourages the Department to examine these issues in the course of the mission analysis required by this section.”

Interestingly, the reports required by both §932 and §933 are required to be prepared in ‘unclassified form’ (with classified annexes, of course). With the requirement in this bill (§1078) to post such DOD reports on a public web site, we may actually get a chance to see these reports.

Chemical Safety

There is an oddly out-of-place amendment to the Toxic Substances Control Act. Section 315 of this bill would amend 15 USC 2602(2)(B)(v) to expand the TSCA firearms exemption specifically to “any component of such an article (including, without limitation, shot, bullets and other projectiles, propellants when manufactured for or used in such an article, and primers)”. This is probably due to efforts by some environmentalists to require DOD to change their ammunition to exclude such toxic material as lead.

Moving Forward

The House Rules Committee will be holding two hearings this week to define the Rule for the consideration of HR 1960 before the House later this week. The first hearing will be on Tuesday to craft the rule. The second hearing will be Wednesday afternoon to determine what amendments will be offered on the floor. So there may still be changes to the cybersecurity provisions of this bill before it is voted upon by the House.


This bill will certainly pass in the House, historically by a substantially bipartisan vote. A different version will be considered in the Senate and then a compromise version will be worked out in Conference.

Tuesday, June 4, 2013

Updated Markup Information – 06-04-13

The three markup hearings scheduled for tomorrow that I previously reported on have updated information available on the respective hearing web pages. The two subcommittee markups of spending bills now have draft copies of the bills available (Dept of Agriculture, DOD). The DOD Authorization markup now has links to copies of the markups from various Armed Forces Committee subcommittees.


I have not yet had a chance to do more than take a real quick cursory check of any of these new documents.

Sunday, June 2, 2013

Congressional Hearings – Week of 06-02-13

The House and Senate return to Washington, rested and refreshed from a very long Memorial Day weekend. Work starts to get serious on spending bills as the long summer recess approaches. The House has four spending related hearings scheduled for this week that might be of interest to readers of this blog. Also, floor action is expected on two spending bills; the military construction bill and the DHS FY2014 appropriations bill.

Rule Hearing on Two Appropriations Bills

As I mentioned in an earlier post, the House Rules Committee will be meeting Monday evening to consider the rules for House floor consideration of HR 2016, the military construction bill, and HR 2017, the FY 2014 DHS appropriations bill. I expect that both of these bills will get open rules with nearly unfettered submission of amendments from the floor.

The current floor calendar indicates that HR 2016 will be considered first, so we may not get to a final vote on HR 2017 until next week since the current plan is for the last vote for the week to take place Thursday afternoon.

Subcommittee Markup of Two Appropriations Bills

The House Appropriations Committee will have two subcommittee markup hearings this week; one for the Ag Dept bill and one for the DOD bill. Both hearings will be on Thursday. I usually watch the DOD bill for cybersecurity measures. I’m going to be watching the Ag bill this year for fallout from the West Fertilizer explosion.

Neither subcommittee has published a draft bill or report yet. I kind of expect to see those later this week.

DOD Authorization Bill

HR 1960 as introduced did not have any specific cybersecurity language associated with it. That may change when the full House Armed Services Committee meets on Thursday to markup the bill. At the very least I expect that we will see cybersecurity language in the Committee report on the bill, but we probably will not see that report for a week or two.

The Missing Hearings

As I write this there are no hearing posted for the Senate Environment and Public Works Committee. Sen. Boxer had promised to hold early hearings on the problems identified by the West Fertilizer Explosion in April. At the very least we should be able to expect to see her Committee address the Chemical Safety Board/ATF conflict; the Committee has oversight responsibility for the CSB. Similarly we could expect to see a House hearing from the Energy and Commerce Committee for the same reason.

I would like to think that the homeland security committees in both houses would hold hearings on the CFATS issues raised by the failure of West Fertilizer to complete a Top Screen submission for their holdings of anhydrous ammonia and ammonium nitrate. A possible explanation for there being no word on such a hearing might be that ISCD/NPPD has told the Committees on the QT that even if a Top Screen had been filed, the facility would not have been identified as a high-risk facility due to its rural location.


It may be a little too early yet, the dust is still settling on the CSB-ATF conflict. I would be surprised though if we haven’t seen at least one such hearing before the July 4th recess. In fact, this might be a good topic for a field hearing during that recess. It would be a good source of fireworks.

Monday, May 20, 2013

HR 1960 Introduced – NDA


As I noted last week Rep. McKeon (R,CA), Chairman of the House Armed Services Committee, introduced HR 1960, the National Defense Authorization Act for Fiscal Year 2014. This is one of the authorization bills that frequently contain cybersecurity language because of the increasing emphasis on cyber-warfare. As introduced, however, there are no significant mentions of cybersecurity. This may change during the legislative process.

Congressional Hearings – Week of 5-19-13


While both the House and Senate will be in Washington this week, we only have to worry about hearings from the House, at least those of us in the chemical safety/security and cybersecurity communities. There will be two House cybersecurity hearings and two hearings on spending matters.

Cybersecurity

Two different subcommittees of the House Energy and Commerce Committee will both be looking at cybersecurity issues on the same day. Fortunately one is in the morning and the other is in the afternoon; otherwise the cybersecurity staff would be hard pressed to whisper the right questions into the correct congressman’s ear.

In the morning the Energy and Commerce Subcommittee will be holding a hearing on “Cyber Threats and Security Solutions”. The witness list is available and it is lengthy. Dr. Gallagher, Director of NIST, will be the first panel; no prizes for guessing what he will be talking about.

The second morning panel (I almost expect a second and third panel) will include:

• Dave McCurdy, American Gas Association
• John M. (Mike) McConnell, Booz Allen Hamilton
• R. James Woolsey, Woolsey Partners LLC
• Michael Papay, Northrop Grumman Information Systems
• Phyllis Schneck, McAfee, Inc.
• Charles Blauner, Citigroup, Inc.
• Duane Highley, Arkansas Electric Cooperative Corporation
• Robert Mayer, United States Telecom Association

The afternoon hearing will be conducted by the Communications and Technology Sub-Committee and will address “Cybersecurity: An Examination of the Communications Supply Chain”. While this does not directly affect control system security (except of course where it interfaces with a communications network) many of the same issues will apply to the control systems supply chain. The Subcommittee does have a staff background memo up on the Committee web site that provides the witness list and a description of the topics to be addressed.

Money Hearings

We will need to monitor the outcome of two mark-up hearings this week that will be looking at money matters.

The House Appropriations Committee will be marking up the as yet un-numbered FY 2014 Homeland Security spending bill on Wednesday. I’ve already described some of the CFATS and TWIC related language that is in the draft document. The Homeland Security Subcommittee met last week to do their markup, but we will not seeing the results of that mark-up until the bill is introduced.

There will be a whole series of hearings this conducted this week by the various subcommittees of the House Armed Forces Committee on the FY 2014 National Defense Authorization Act, HR 1960. The one that will probably be of interest to the cybersecurity community will be the markup being conducted Wednesday by the Subcommittee on Intelligence, Emerging Threats and Capabilities. Again, we probably will not be seeing the results of this hearing until the Committee Report is prepared.

Wednesday, May 15, 2013

Bills Introduced – 05-15-13


We are starting to see the introduction of appropriations and authorizations bills for FY 2014, with one of each being submitted yesterday. The agriculture bill may contain chemical security or safety items in light of the West Fertilizer explosion. As always the DOD spending bill may be expected to include cybersecurity provisions.

S 954 Latest Title: An original bill to reauthorize agricultural programs through 2018. Sponsor: Sen Stabenow, Debbie (D,MI)

HR 1960 Latest Title: To authorize appropriations for fiscal year 2014 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sponsor: Rep McKeon, Howard P. "Buck" (R,CA)

We will just have to wait for the official publication of these bills to see what they actually contain.
 
/* Use this with templates/template-twocol.html */