Showing posts with label HR 2708. Show all posts
Showing posts with label HR 2708. Show all posts

Monday, June 15, 2015

Rules Committee Approves Rule for HR 2596

This evening the House Rules Committee met to develop the rule for the floor consideration of HR 2596, the FY 2016 intelligence authorization bill. As expected the bill will be considered under a structured rule with only 16 amendments allowed to be offered on the House floor tomorrow.

Five of the amendments may be of specific interest to readers of this blog:

#2 Rep. Israel (D,NY) - Requires the Director of National Intelligence to provide report to the congressional intelligence and defense committees on the cyber threat trends identified by the Cyber Threat Intelligence Integration Center, an assessment of collaborative efforts between federal agencies, and recommendations to improve those collaborative efforts.

#5 Rep. Keating (D,MA) - Restores reporting requirement on the progress of the Federal Bureau of Investigation in implementing information-sharing principles.

#7 Rep. Rooney (R,FL) - Requires a report detailing the Intelligence Community's utilization of the National Science Foundation's CyberCorps Scholarship for Service program.

#8 Rep. Moulton (D,MA) - Requires a report and briefing regarding the impacts on the intelligence community (IC) of the recently disclosed cyber breach at OPM.

#13 Rep. Wilson (R,SC) - Directs the Director of National Intelligence to study how we measure cyber attacks and report to the relevant committees in both a classified and unclassified format.


Sharp eyed readers will note the similarity of amendment #13 to HR 2708 that I reported on earlier today. Apparently the Rules Committee did not share my opinion on the inappropriateness of this measure.

HR 2708 Introduced – Cyber Attack Metrics

Last week Rep. Wilson (R,SC) introduced HR 2708, a bill that would direct the Director of National Intelligence to conduct a study on cyber-attack standards of measurement. The preliminary findings would be reported to Congress in 180-days and the final report within 1-year.

The Director would conduct a study (in conjunction with DHS, DOD, and the FBI) to determine standards that could “be used to measure the damage of cyber incidents for the purposes of determining the response to such incidents” {§1(a)(1)}. Those standards would “include a method for quantifying the damage caused to affected computers, systems, and devices” {§1(a)(2)}.

Moving Forward

Wilson is not a member of the House Intelligence Committee so it is extremely unlikely that the Committee will take up this bill for consideration. If this ever does make it to the floor there is certainly nothing in the bill that would raise any significant opposition.

Commentary


This is one of the sillier pieces of legislation that I have seen. While there is certainly a place for determining the cost of a cyber-attack it is almost certainly not an intelligence function; at least not if we are measuring the cost in the United States.

Wednesday, June 10, 2015

Bills Introduced – 06-09-15

Yesterday there were 34 bills introduced in the House and Senate. Of those there were two that may be of interest to readers of this blog:

HR 2702 To amend title 49, United States Code, with respect to passenger motor vehicle crash avoidance information, and for other purposes. Rep. Rokita, Todd [R-IN-4]

HR 2708 To direct the Director of National Intelligence to conduct a study on cyber attack standards of measurement. Rep. Wilson, Joe [R-SC-2]

HR 2702 may be of interest depending on how the crash avoidance information is obtained and shared. The chance of any cybersecurity language being included is quite low.

HR 2708 will almost certainly be an interesting bill. I can’t wait to find out what Wilson means by ‘cyber attack standards of measurement’. Are these metrics for our offense or defense?
 
/* Use this with templates/template-twocol.html */