Showing posts with label HR 1975. Show all posts
Showing posts with label HR 1975. Show all posts

Tuesday, September 24, 2019

Committee Hearings – Week of 09-22-19


This week with both the House and Senate in session (but preparing for a 2-week break) there is a full slate of politically oriented hearings slated in the House and the Senate Appropriations Committee will try to address some additional spending bills. Two markup hearings this week (one on each side of the Capital) will look at bills covered in this blog.

Senate Spending Bills – Markups


The Senate Appropriations Committee will try to get four spending bills reported to the Senate this week:

Interior, Environment, and Related Agencies (IER) – Subcommittee – Tuesday;
Commerce, Justice, Science, and Related Agencies (CJS) – Subcommittee – Tuesday;
DHS – Subcommittee – Tuesday;
IER, CJS, DHS, and Legislative Branch – Full Committee - Thursday

I suspect that the IER and CJS bills may be successfully reported, but the DHS bill (because of ‘the Wall’ and immigration) is at the heart of the controversy holding up Senate consideration of spending bills. I really do not expect the Committee to report a DHS spending bill.

Markup Hearings


On Wednesday the House Homeland Security Committee will hold a markup hearing on three bills:

HR 1975, the Cybersecurity Advisory Committee Authorization Act of 2019
HR 4432, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act
HR ____, the National Commission on Online Platforms and Homeland Security Act

HR 4432 has not yet been published, either by the GPO or the Committee and the final bill has not yet been introduced (expected today?).

With only three bills on the agenda, we may see some amendments offered and very briefly discussed, but none have yet been published on the hearing page.

On Wednesday the Senate Energy and Natural Resources Committee will hold a markup hearing covering 21 bills.

S 2095, the Enhancing Grid Security through Public-Private Partnerships Act;
S 2333, the Energy Cybersecurity Act of 2019; and
HR 1420, the Energy Efficient Government Technology Act

On the Floor


As I mentioned yesterday, the House is scheduled to take up HR 3710, the Cybersecurity Vulnerability Remediation Act on Wednesday. It will likely pass with significant bipartisan support, but I will be surprised if it is taken up in the Senate this year.

There is a good chance that the Senate could take up HR 4378, the continuing resolution that was passed last week. That bill would extend the current funding rate for the federal government through November 21st. It would be taken up under the unanimous consent process and I suspect that Sen. McConnel (R,KY) would want to try to do that as soon as possible. That would leave room for the House to come up with a ‘cleaner’ CR if there is an objection to the bill in the Senate. The Senator to watch will be Sen. Paul (R,KY).

Tuesday, April 23, 2019

HR 1975 Introduced – Cybersecurity Advisory Committee


Last month Rep. Katko (R,NY) introduced HR 1975, the Cybersecurity Advisory Committee Authorization Act of 2019. The bill would require the DHS Cybersecurity and Infrastructure Security Agency (CISA) to establish a cybersecurity advisory committee to advise the Director on the development, refinement, and implementation of policies, programs, rulemakings, planning, training, and security directives pertaining to the mission of CISA.

Composition


The Committee would be composed of 35 individuals representing State and local governments and of a broad range of industries, including {new §2215(c)(1)(C)}:

Defense.
Education;
Financial services;
Healthcare;
Manufacturing;
Media and entertainment;
Chemicals;
Retail;
Transportation;
Energy;
Information Technology; and
Communications.

Moving Forward


Katko is a member of the House Homeland Security Committee, one of the three committees to which this bill was assigned for consideration. This means that it is likely that this bill will receive consideration in that Committee. None of the current cosponsors of the bill are members of the other two committees to which the bill was assigned. This greatly decreases the possibility that this bill will be considered in those committees. There is a reasonable chance that the bill could move to the floor without action by the Energy and Commerce or Oversight and Reform committees if the Homeland Security Committee were to strongly indorse the bill.

There is nothing in this bill that would engender serious opposition. If the bill were to be considered it would probably receive broad bipartisan support. I suspect that there is a good chance that this bill will come to the floor of the House under the suspension of the rules process.

Commentary


There is no language in this bill that specifically identifies control system cybersecurity as a targeted interest of the Committee. But, having said that, it seems clear to me that the crafters of the bill intended operational technology cybersecurity to be included in the Committee’s purview. One just has to look at the industrial sectors specified to see that a wide variety of industrial control systems are core technologies for many of the sectors. I do have a minor concern, however, that the support side (vendors, integrators and researchers) of control system security may not receive any recognition in this committee. This concern could be reduced by changing the name of one of the industries from ‘information technology’ to ‘information and operational technology’.

The Federal government has successfully used this type of advisory committee to help provide regulators with a wide span of technical expertise. There have periodically been complaints about the ‘influence’ these industry insiders have over the regulatory process. Usually, this type of complaint has been short circuited by ensuring the inclusion of counter-industry advocacy representative like labor organizations or privacy groups. For this Committee, I think the failure to include representative of privacy groups is a significant shortcoming that should be corrected before this legislation makes its way to the President.

Friday, March 29, 2019

Bills Introduced – 03-28-19


Yesterday with both the House and Senate in session there were 106 bills introduced. Two of these may see future coverage in this blog:

HR 1975 To establish in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security a Chief Information Security Officer Advisory Committee. Rep. Katko, John [R-NY-24] 

S 954 A bill to provide grants to State, local, territorial, and Tribal law enforcement agencies to purchase chemical screening devices and train personnel to use chemical screening devices in order to enhance law enforcement efficiency and protect law enforcement officers. Sen. Brown, Sherrod [D-OH]

CISO’s typically have responsibility for operational technology in addition to information technology. It will be interesting to see if the definitions used in HR 1975 reflect that dichotomy.

I suspect that this bill will contain language specifying fentanyl detection. While detection of that dangerous (toxic) drug is certainly important to law enforcement officers, I will be watching for language that includes a broader array of toxic chemical detections in the grant program.

 
/* Use this with templates/template-twocol.html */