Showing posts with label HR 2810. Show all posts
Showing posts with label HR 2810. Show all posts

Monday, November 13, 2017

HR 2810 Conference Report – 2018 NDAA

This week the conference committee considering the differences in the House and Senate versions of HR 2018, the FY 2018 National Defense Authorization Act (NDAA) published their report on a final version of the bill. Additionally, the bill contains an explanation of how the conferees came to compromise language.

Cybersecurity Provisions


As is to be expected there are a number of cyber related provisions found in the bill. The list below shows the title of the appropriate sections and the pages within the report for both the actual language adopted by the conference and the discussion of how that language was arrived at.

§1090. Providing assistance to House of Representatives in response to cybersecurity events. (pgs 326-7; discussion pg 933)
§1110. Pilot program on enhanced personnel management system for cybersecurity and legal professionals in the Department of Defense. (pgs 352-6; discussion pg 950)

Subtitle C—Cyberspace-Related Matters
PART I—GENERAL CYBER MATTERS
§1631. Notification requirements for sensitive military cyber operations and cyber weapons. (pgs 457-8; discussion pgs 1016-7)
§1632. Modification to quarterly cyber operations briefings. (pg 459; discussion pg 1017)
§1633. Policy of the United States on cyberspace, cybersecurity, and cyber warfare. (pgs 459-60; discussion 1017-8)
§1634. Prohibition on use of products and services developed or provided by Kaspersky Lab. (pgs 460-2; discussion pg 1018)
§1635. Modification of authorities relating to establishment of unified combatant command for cyber operations. (pg 462; discussion pgs 1018-9)
§1636. Modification of definition of acquisition workforce to include personnel contributing to cybersecurity systems. (pg 462; discussion pg 1019)
§1637. Integration of strategic information operations and cyber-enabled information operations. (pg 462-5; discussion 1019-20)
§1638. Exercise on assessing cybersecurity support to election systems of States. (pg 465; discussion pg 1020)
§1639. Measurement of compliance with cybersecurity requirements for industrial control systems. (pg 465; discussion pg 1020)
§1640. Strategic Cybersecurity Program. (pgs 465-7; discussion pgs 1020-1)
§1641. Plan to increase cyber and information operations, deterrence, and defense. (pg 467; discussion pg 1021)
§1642. Evaluation of agile or iterative development of cyber tools and applications. (pgs 467-9; discussion pg 1021)
§1643. Assessment of defense critical electric infrastructure. (pg 469; discussion pg 1021)
§1644. Cyber posture review. (pgs 469-70; discussion pgs 1021-2)
§1645. Briefing on cyber capability and readiness shortfalls. (pgs 470-1; discussion pg 1022)
§1646. Briefing on cyber applications of blockchain technology. (pg 471; discussion pg 1022)
§1647. Briefing on training infrastructure for cyber mission forces. (pgs 471-2; discussion pg 1022)
§1648. Report on termination of dual-hat arrangement for Commander of the United States Cyber Command. (pg 472; discussion pgs 1022-3)

PART II—CYBERSECURITY EDUCATION
§1649. Cyber Scholarship Program. (pgs 473-4; discussion pg 1023)
§1649A. Community college cyber pilot program and assessment. (pgs 474-5; discussion pg 1023)
§1649B. Federal Cyber Scholarship-for-Service program updates. (pgs 475-6; discussion pg 1023)
§1649C. Cybersecurity teaching. (pg 477; discussion 1023)

The one provision listed above that may be of specific interest to readers of this blog is §1639. It requires the Secretary of Defense to measure “the progress of each element of the Department of Defense in securing the industrial control systems of the Department against cyber threats, including such industrial control systems as supervisory control and data acquisition systems, distributed control systems, programmable logic controllers, and platform information technology” {§1639(a)}. This measurement is to be included in the scorecard used in the implementation of the DOD Cybersecurity Discipline Implementation Plan.

An interesting term is used here; ‘platform information technology’. It is a military term that can be defined as computer hardware and/or software used to support operations technology. In an industrial control system environment this would certainly include human machine interfaces and data historians as well as the communications systems involved in the control system.

Unmanned Aircraft Systems


There are a number of provisions in the revised language for HR 2810 that refer to unmanned aircraft systems (UAS). One is of potential interest to readers of this blog because it addresses DOD authority to deal with intrusive UAS at or near DOD facilities or operations.

§1692. Protection of certain facilities and assets from unmanned aircraft. (pgs 509-12; discussion pgs 1038-40)

This provision will provide an exemption for DOD from the air piracy provisions of 49 USC 46502 and from “any provision of title 18 (USC)” {§1692(a)} for actions taken to protect DOD covered facilities from the threat posed by UAS. This would include actions taken to {§1692(b)}:

• Detect, identify, monitor, and track the unmanned aircraft system or unmanned aircraft, without prior consent, including by means of intercept or other access of a wire communication, an oral communication, or an electronic communication used to control the unmanned aircraft system or unmanned aircraft;
• Warn the operator of the unmanned aircraft system or unmanned aircraft, including by passive or active, and direct or indirect physical, electronic, radio, and electromagnetic means;
• Disrupt control of the unmanned aircraft system or unmanned aircraft, without prior consent, including by disabling the unmanned aircraft system or unmanned aircraft by intercepting, interfering, or causing interference with wire, oral, electronic, or radio communications used to control the unmanned aircraft system or unmanned aircraft;
• Seize or exercise control of the unmanned aircraft system or unmanned aircraft;
• Seize or otherwise confiscate the unmanned aircraft system or unmanned aircraft; or
• Use reasonable force to disable, damage, or destroy the unmanned aircraft system or unmanned aircraft.

Moving Forward


The House Rules Committee is currently scheduled to hold a hearing this evening to construct the rule for the floor consideration of the conference report. This will almost certainly be a structured rule with limited debate and no floor amendments. The House is then scheduled to take up the conference report under that rule on Tuesday. It will almost certainly pass with some measure of bipartisan support; as it will later in the week in the Senate.

Commentary


It would have been helpful if §1639 had included some sort of requirement for DOD to publicly publish the measurement guidelines that would be used to evaluate the cybersecurity of industrial control systems. Those guidelines could be very useful for other large organizations to conduct a similar high-level review of the cybersecurity of ICS.

In the section on UAS protections for DOD facilities I find it extremely interesting that the language ‘any provision of’ 18 USC was used instead of just references to the specific aircraft protection provisions of 18 USC 32. Other provisions that could have been specifically included:

§39A - Aiming a laser pointer at an aircraft;
§1030 - Fraud and related activity in connection with computers; or
§2511 - Interception and disclosure of wire, oral, or electronic communications prohibited.


Of course, lawyers are well known for their ability to attempt to stretch legal requirements to cover unusual circumstances, so perhaps the crafters of §1692 were justified in their use of ‘any provisions’. We will just have to wait and see how much the lawyers at DOD stretch that language to include not so reasonable actions taken against UAS and their pilots.

Tuesday, September 26, 2017

Senate Considers Debating S 1579 – FY 2018 NDAA

Yesterday the Senate agreed to begin debating the consideration of S 1579, the FY 2018 National Defense Authorization Act. This was the original senate version of the NDAA that served as the template for McCain’s substitute language for HR 2810 that was passed in the Senate last week. This is an unusual move as the House has yet to consider the Senate amendments to HR 2810. Even if the House were to reject the Senate amendments there would still be the resulting conference committee to work out the differences in the two versions.

Earlier in the day the Senate did make a minor correction to the wording of two amendments that were adopted on the floor, SA 1065 (pg S 5760) and SA 1086 (pg S 5768). Both amendments made changes to the funding tables in §4301, but they failed to include the words: “At the end of Division F add the following:” at the start of the amendment. The adjustments were made under the unanimous consent procedure, the way minor editorial errors are normally corrected post-passage. This should not be the reason for the consideration of S 1579.


There is no explanation of the consideration of this bill in the Congressional Record today, nor have I seen anything in the national news. I am going to keep an eye on this.

Wednesday, September 20, 2017

Senate Passes HR 2810 – FY 2018 NDA

On Monday the Senate passed HR 2810, the FY 2018 National Defense Authorization Act (NDAA) by a strongly bipartisan vote of 89 to 8; even the opposition was bipartisan with three Republicans, four Democrats and one Independent voting Nay.

Of all of the amendments that I discussed in my series of blog posts over the last two weeks, only three were adopted:

• Reed (for Kaine) Amendment No. 1089, to establish opportunities for scholarships related to cybersecurity.
• McCain (for Portman) Amendment No. 712, to require a plan to meet the demand for cyberspace career fields in the reserve components of the Armed Forces.
• McCain (for Portman) Amendment No. 1055, to require a report on cyber applications of blockchain technology.

They were all considered as part of an en bloc amendment [pgs S5787-8] offered by Sen. McCain (R,AZ) at the end of the final debate on HR 2810. The en bloc amendment was adopted by unanimous consent [pg S5796].


Since there are significant differences between the versions of this bill passed in the House and Senate, it is very likely that there will be a conference committee appointed. There is, however, a very slight chance that the House will agree to the Senate amendment to the bill when it returns from their week working in their districts.

Saturday, September 16, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-14-17

On Thursday, after voting to close debate on the McCain substitute language amendment (SA 1003), the Senate agreed to a final vote on HR 2810, the FY 2018 National Defense Authorization Act (NDAA), at 5:30 pm EDT on Monday, September 18th, 2017. Meanwhile, more amendments continue to be proposed. In addition to the previously proposed amendments (see here, here, here, here and here) a large number of possible amendments to HR 2180 were proposed in the Senate on Thursday; only one of which may be of specific interest to readers of this blog:

SA 1089. Mr. KAINE -  SEC. 1661. Cyber Scholarship Opportunities Act of 2017 (pgs S5768-9);

Cyber Scholarships


Amendment SA 1089 is pretty nearly the same as SA 849 that Sen. Kaine (D,VA) proposed on September 7th, 2017. The only difference is that the latest version removes the section on ‘Findings’ that explains why Kaine thinks that cyber scholarships are necessary.

This amendment would require that the current Federal Cyber Scholarship-for Service program (15 USC 7442) be expanded to include a pilot program of scholarships at at least five community colleges for students who are pursuing associate degrees or specialized program certifications in the field of cybersecurity and either “have bachelor’s degrees; or are veterans of the armed forces” {§1662(a)(2)}. No additional funding is provided for the new scholarship requirements.

Commentary


Just a reminder, as of this writing, none of the amendments that I have addressed in this series of blog post (with the obvious exception of SA 1003) have even been considered on the floor of the House, much less adopted. There is a remote chance that some may be considered on Monday, but I do not really expect it.

This large number of amendments proposed for a ‘must pass’ bill like the NDAA is not unusual. With the political horse trading involved in getting enough votes to pass a bill like this, there is always the possibility that some pet bit of legislative language can be inserted via the Senate amendment process. It takes relatively little effort by a Senator’s staff to craft most of these amendments (frequently just cut and paste from a previously submitted bill), so it is kind of like buying a $1 lottery ticket when the pot is really high. A piece of legislation that might never see the light of day in the normal legislative process can become law because it was attached to an important bill.

A less well-known fact is that one of these little suspected gems may have already been added to the substitute language that was offered on this bill. I certainly did not do a full detailed analysis of every portion of the bill. Getting a new section added or a current section slightly revised can be the price of support for a bill like this. Depending on how much McCain trusts his committee staff and how significant the change was, he may not even know the details about those types of changes to the substitute language before it was proposed.

This is one of the reasons that I do not try to cover each of the potentially interesting amendments with the same level of detail as I use to cover interesting legislation. There is a very small chance of the amendments being considered or passed. The effort that I do make, reflects on bits of legislative language that I find illustrative of either poorly or well written legislative language, unique ideas, or really slick pieces of legislative legerdemain. 

Thursday, September 14, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-13-17

Yesterday the Senate actually began consideration of HR 2810, the FY 2018 National Defense Authorization Act (NDAA). Meanwhile, more amendments continue to be proposed. In addition to the previously proposed amendments (see here, here, here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including five that may be of specific interest to readers of this blog:

• SA 1003. Mr. MCCAIN - National Defense Authorization Act for Fiscal Year 2018 substitute language (pgs S5487-671);
• SA 1009. Mr. SASSE - cyberspace solarium commission (pgs S5674-6);
• SA 1019. Ms. HARRIS - pilot program on integrating into the department of defense workforce individuals with cybersecurity skills and technical expertise whose services are supported by private persons (pg S5678);
• SA 1025. Mr. WHITEHOUSE - botnet prevention (pgs S5680-1); and
• SA 1055. Mr. PORTMAN - report on cyber applications of blockchain technology (pg S5701-2)

Substitute Language


The substitute language (SA 1003) from Sen. McCain (R,AZ), and the staff of the Senate Armed Services Committee, is arguably the most important amendment to be offered to date, as it will form the working basis for the language that will be considered on the floor of the Senate. This language is based (as expected) on S 1519, the original Senate NDAA bill and it includes each of the cybersecurity related sections that I identified in S 1519.

Cyberspace Solarium Commission


SA 1009 would require DOD to establish the Cyberspace Solarium Commission with a mandate to “develop a consensus on a strategic approach to protecting the crucial advantages of the United States in cyberspace against the attempts of adversaries to erode such advantages” {SA 1009(a)}. The name harkens back to Eisenhower’s 1953 National Security Council’s Solarium Special Committee that was used to help formulate Eisenhower’s containment strategy vis-à-vis the Soviet Union.

The Commission would be tasked with {SA 1009(f)}:

• Weighing the costs and benefits of various strategic options to reach the goal of protecting the US cyberspace advantage;
• Reviewing adversarial strategies and intentions, current programs for the protection of the US cyberspace advantage, and the capabilities of the Federal Government to understand if and how adversaries are currently being deterred or thwarted in their aims and ambitions; and
• Evaluating the current allocation of resources for understanding adversarial strategies and intentions and protecting the US cyberspace advantage.

Botnet Prevention


This proposed amendment from Sen. Whitehouse (D,RI) and Sen. Graham (R,SC) is very similar to S 2931 that was introduced in the 114th Congress by Graham and Whitehouse. This amendment does not deal with DOD issues, but the Senate rules do allow for the consideration of extraneous amendments.

Moving Forward



The Senate held a cloture vote today on the McCain substitute language amendment and it passed with a bipartisan vote of 84 to 9. When the Congressional Record for today is published tomorrow I expect that we will see that some amendments were dealt with today, but at this point I have no idea which ones.

Wednesday, September 13, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-12-17

Yesterday the Senate leadership continued to work out a deal for determining which proposed amendments would be considered on the floor for HR 2810, the FY 2018 National Defense Authorization Act (NDAA). Meanwhile, more amendments continue to be proposed. In addition to the previously proposed amendments (see here, here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including three that may be of specific interest to readers of this blog:

• SA 948. Mr. MORAN - national guard bureau public-private cyber-security coalition (pg S5222)
• SA 989. Mr. ROUNDS - cybersecurity of industrial control systems. (a) designation of integrating official (pg S5234)
• SA 1001. Mr. ROUNDS - designation of official for matters relating to integrating cybersecurity and industrial control systems within the department of defense (pg S5240)

ICS Cybersecurity


Both of the proposed amendments from Sen. Rounds (R,SD) would require DOD to designate a single individual to be responsible “for all matters relating to integrating cybersecurity and industrial control systems within the Department of Defense” {§1630C(a)(1)}. The difference between the two amendments is that SA 989 identifies broader responsibilities for that designated individual. Those responsibilities would include {§1630C(a)(2)}:

• Developing, implementing, and be accountable for plans, programs, and policies to improve the cybersecurity of industrial control systems [only in SA 989]; and
• Developing Department-wide certification standards for integration of industrial control systems and taking into consideration frameworks set forth by the National Institute of Standards and Technology for the cybersecurity of such systems [in both amendments].

SA 989 would also require DOD to consider conducting pilot programs designed to “to assess the feasibility and advisability of implementing various solutions for protecting industrial control systems against cyber-attacks and discerning the specific criteria that a solution should demonstrate in order to be certified for military use” {§1630C(b)(1)}. Priority would be given to “the determination of certification criteria for military energy industrial control systems” {§1630C(b)(2)}.

Moving Forward


More political wrangling on what amendments to include in the debate on HR 2810 is expected overnight. There was one amendment voted upon today (in a round-about manner) and we could see additional votes tomorrow.


Tuesday, September 12, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-11-17

Yesterday the Senate voted to close debate on the motion to close further debate on the motion to proceed to consideration of HR 2810, the FY 2018 National Defense Authorization Act (NDAA) by a vote of 89 to 3.This is the first step in the process to begin consideration of HR 2810. In addition to the previously proposed amendments (see here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including five that may be of specific interest to readers of this blog:

• SA 856. Mr. BROWN - Collaboration between federal aviation administration and department of defense on unmanned aircraft systems (pg S5118);
• SA 867. Ms. WARREN - Report on significant security risks of defense critical electric infrastructure (pgs S5121-2);
• SA 868. Mr. VAN HOLLEN - Strengthening allied cybersecurity (pgs S5122-3);
• SA 919. Mr. MCCAIN - Report on training infrastructure for cyber forces (pg S5146);
• SA 922. Mr. MCCAIN - Unmanned aircraft systems that pose a threat to the safety or security of certain department of defense facilities and assets (pg S5147)

Electric Infrastructure Security Risks


Yesterday’s amendment by Sen. Warren (D,MA) is nearly identical to the one she proposed last week (SA 794). The only change that I could see is that her staff added a definition of ‘security risk’:

“The term ‘‘security risk’’ shall have such meaning as the Secretary of Defense shall determine, in coordination with the Director of National Intelligence and the Secretary of Energy….”

Not much of a definition, but it does lay the onus for coming up with a useful definition with the people technically qualified to make the assessment.

DOD and UAS


SA 922 takes an interesting approach to the problem of shooting down unmanned aircraft systems (UAS) in United States airspace. Currently, damaging or shooting down an aircraft in US airspace is a criminal act under 18 USC 32 and there is no exemption in that section for actions by military personnel. This amendment would tangentially approach that problem for UAS by allowing the military to ‘seize’ UAS irrespective of the restrictions in 18 USC. Interestingly, there is no indication in the amendment on how DOD would be expected to seize those UAS or in what condition they would be when seized.

That authority would only be available at some very limited ‘covered facilities or assets’. Those would be defined as facilities relating to:

• The nuclear deterrence mission of the Department of Defense, including with respect to nuclear command and control, integrated tactical warning and attack assessment, and continuity of government;
• The missile defense mission of the Department; or
• The national security space mission of the Department.

Moving Forward


Yesterday’s vote is a pretty good indication that the Senate leadership has worked out an agreement on how to proceed with the consideration of HR 2810. There are still some procedural measures where that consideration could be derailed by a sizeable minority of the Senators, but at this point it looks like a much-amended HR 2810 will eventually get a floor vote in the Senate, maybe even this month.


When it eventually passes it will almost certainly be referred to a conference committee to work out the differences between the House and Senate versions of the bill. Still, we are likely to see a final version of the bill on the President’s desk well before the December deadline on other measures clogs up the legislative process.

Monday, September 11, 2017

Committee Hearings – Week of 09-10-17

Both the House and Senate are in town this week with most focus being on floor activities in both houses. There will be two hearings this week that may be of particular interest to readers of this blog; one on energy reliability and one on self-driving trucks.

Energy Reliability


On Tuesday the Energy Subcommittee of the House Energy and Commerce Committee will be holding a hearing on “Powering America: Defining Reliability in a Transforming Electricity Industry”. The witness list includes:

• Paul Bailey, American Coalition for Clean Coal Electricity;
• Gerry Cauley, North American Electric Reliability Corporation;
• Neil Chatterjee, Federal Energy Regulatory Commission;
• Kyle Davis, Enel Green Power North America, Inc;
• Marty Durbin, American Petroleum Institute;
• Patricia Hoffman, U.S. Department of Energy;
• Tom Kiernan  American Wind Energy Association;
• Maria G. Korsnick, Nuclear Energy Institute;
• Kelly Speakes-Backman, Energy Storage Association;
• Susan F. Tierney, Analysis Group, Inc.; and
• Steve Wright, Chelan Public Utility District

This hearing is on system reliability and ensuring the flow of electricity to customers. Interestingly, there is no mention in the background memo on this hearing on how this reliability may be effected by cybersecurity concerns. Admittedly, the reliability topic is complicated enough without considering cybersecurity, but it will be interesting to see if it is mentioned in the testimony and questioning.

Self-Driving Trucks


On Wednesday the Senate Commerce, Science, and Transportation Committee will be holding a hearing to look at “Transportation Innovation: Automated Trucks and Our Nation's Highways”. The witness list includes:

• Scott G. Hernandez, Colorado State Patrol
• Troy Clarke, Navistar
• Ken Hall, International Brotherhood of Teamsters
• Deborah Hersman, National Safety Council
• Chris Spear, the American Trucking Associations

While I have focused on cybersecurity issues associated with automated driving systems, this hearing reminds us that there are other concerns that are also going to have to be faced with this next stage of industrial automation; jobs.

On the Floor


I have already mentioned the two big bills seeing floor action this week, HR 3354 in the House and HR 2810 in the Senate.

There really is not much else happening on the floor of either house this week of specific interest, but you always have to be careful saying that. The Senate calendar is always up in the air with all sorts of jockeying for position and both intra-party and inter-party wrangling keeping the schedule very flexible. The House is usually much easier to predict since the Majority Leader actually publishes a weekly schedule.

But even the staid House throws up the occasional odd-ball scheduling change now and again. Today was a good case in point. This was supposed to be a speechifying day with no votes scheduled; at least that is what the Majority Leader’s schedules said. This is typical on Monday’s as it allows for some travel flexibility for members coming back to Washington from their districts. But then, at 4:23 pm EDT, Rep. Reichert (R,MN) asked unanimous consent that HR 3732 be discharged from committee and be considered on the floor of the House. With no debate and no vote, the bill was passed.

Interestingly this bill was introduced today (probably by Reichert, but I cannot tell until tomorrow for sure until the Library of Congress prints the list of bills introduced today) with broad title of “To amend section 1113 of the Social Security Act [42 USC 1313] to provide authority for increased fiscal year 2017 and 2018 payments for temporary assistance to United States citizens returned from foreign countries”. I suspect that a connected constituent was getting a run-around from the Social Security Administration and this bill was designed to remove a funding excuse for that runaround.

There were probably very few people on the floor of the House when this matter came up. The consideration of this bill was a mere formality (and it may die a slow death waiting in the Senate for action), but there was almost certainly no legislative trickery involved. Both parties keep at least one ‘responsible’ (to the leadership) member on the floor to object to any skullduggery being played under the guise of ‘unanimous consent’; a single voice crying from the back of the chamber would have killed the consideration of this bill. So, the leadership of both parties consented to this bill being passed, and no one has raised a stink about it. That means that the bill would almost certainly have passed if it had been considered under regular order.


But, it does just go to show that the politicos in Congress can get things done when they really want to, so we must keep a close eye on them.

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-7-17

This week the Senate is scheduled to take up HR 2810, the FY 2018 National Defense Authorization Act (NDAA). In addition to the amendments introduced before the summer recess, Senators began proposing new amendments to HR 2810 last week. Those amendments included three that may be of interest to readers of this blog:

SA 794. Ms. WARREN - report on significant security risks of the national electric grid (pg S5008);
SA 824. Mr. THUNE - cybersecurity training program in the army senior reserve officers’ training corps (pg S5006); and
SA 849. Mr. KAINE - Cyber Scholarship Opportunities (pgs S 5072-3)

Electric Grid Study


The electric grid security study would be conducted by DOD (in coordination with the Director of National Intelligence and the Secretary of Energy) and would specifically look at:

• Identification of significant security risks to defense critical electric infrastructure posed by significant malicious cyber-enabled activities;
• An assessment of the potential effect of the security risks identified pursuant to paragraph (1) on the readiness of the Armed Forces; and
• An assessment of the strategic benefits derived from, and the challenges associated with, isolating military infrastructure from the national electric grid and the use of microgrids by the Armed Forces.

DOD is also expected to include in the report recommendations to:

• Eliminate or mitigate the security risks identified pursuant above; and
• Address the effect of those security risks on the readiness of the Armed Forces identified above.
A one of the key terms in this amendment that is specifically defined is ‘significant malicious cyberenabled activities’. In addition to the expected malware attacks and service disruption attacks it specifically includes more purely IT-centric attacks to:

• Deny access to or degrade, disrupt, or destroy an information and communications technology system or network; or
• Exfiltrate, degrade, corrupt, destroy, or release information from such a system or network without authorization.

Including these IT type attacks greatly expands the potential scope of this study. To somewhat limit that, the second IT-centric attack is restricted to those attacks that are conducted for the purposes of:

• Conducting influence operations; or
• Causing a significant misappropriation of funds, economic resources, trade secrets, personal identifications, or financial information for commercial or competitive advantage or private financial gain

Moving Forward


The cloture motion for HR 2810 was filed on Thursday and the vote on cloture is scheduled for 5:30 pm (EDT) today. If the leadership has worked out a deal on the amendment process (and it looks like it may have) then the 60-votes will be available to start the that process. I expect that we will see some additional amendments offered this week before a potential final vote on Thursday.


Since the bill will be amended in the Senate (the only question is when) a conference committee will be necessary to work out the differences in the bill. The passage of continuing resolution in HR 601 last week will make it easier for that conference to meet and work out the differences in the two versions of the bill. We might actually see a final vote on the bill before the end of the fiscal year (but do not hold your breath).

Monday, July 31, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 7-27-17

With the Senate possibly getting ready to take up HR 2810, the FY 2018 National Defense Authorization Act (NDAA) the amendment process started in earnest last week. While a significant number of amendments were submitted on Wednesday, I did not see any of potential specific interest to readers of this blog until Thursday. Those amendments included:

• SA 427. Mr. Brown - collaboration between federal aviation administration and department of defense on unmanned aircraft systems (pg s4455);
• SA 435. Mr. Rounds - report on progress made in implementing the cyber excepted personnel system (pgs s4456-7);
• SA 437. Mr. Rounds - sense of congress on establishing an award program for the cyber community of the department of defense (pg s4457);
• SA 461. Ms. Cantwell - collaboration on cybersecurity of industrial control systems for critical infrastructure (pg s4465);
• SA 488. Ms. Heitkamp - sense of congress on use of test sites for research and development on countering unmanned aerial systems (pgs s4474-5);
• SA 525. Mr. Whitehouse - United States-Israel cybersecurity cooperation (pgs s4526-7);
• SA 557. Mr. Gardner - mandatory Sanctions with respect to Iran relating to significant activities undermining United States cybersecurity (pgs s4533-4);
• SA 559. Mr. Gardner - comptroller general of the United States report on department of defense critical telecommunications equipment or services obtained from suppliers closely linked to a leading cyber-threat actor (pg s4534);
• SA 575. Mr. Nelson - protecting critical infrastructure against cyber attacks from foreign governments (pgs s 4538-9);
• SA 613. Ms. Cortez Masto - department of defense cyber workforce development pilot program (pg s4564);
• SA 623. Mr. Warner - department of defense cyber workforce development pilot program (pgs 4568-9);
• SA 655. Ms. Klobuchar - prohibition on use of federal funds for joint cybersecurity initiative with Russia (pg s 4574);
• SA 663. Mrs. Shaheen - prohibition on use of software platforms developed by Kaspersky lab;
• SA 666. Mr. Brown - cybersecurity cooperation with Ukraine (pg s4579);
• SA 686. Ms. Warren - report on significant security vulnerabilities of the national electric grid (pg s4587);
• SA 700. Ms. Harris - pilot program on integrating into the department of defense workforce individuals with cybersecurity skills whose services are donated by private persons (pg s4590);
• SA 712. Mr. Portman - plan to meet demand for cyberspace career fields in the reserve components of the armed forces (pg s4597);
• SA 713. Mr. Portman - department of defense integration of information operations and cyber-enabled information operations (pgs s4597-8);
• SA 725. Mr. Cassidy - report on cyber capability and readiness shortfalls of army combat training centers (pg s4604).

Industrial Control Systems


Three of these amendments specifically address (or at least include) industrial control system security issues.

Sen. Cantwell’s (D,WA) SA 461 would require DOD, DOE, and DHS to provide representative to a new Center of Excellence focusing on “cybersecurity of industrial control systems for critical infrastructure” {(b)(1)}. No funding nor further details are provided.

Sen. Nelson’s (D,FL) SA 575 is a ‘sense of Congress’ statement. It starts with a very bold and broad statement of the threat: “Authoritative evidence and testimony to Congress indicate that the United States Government cannot prevent cyber attacks by determined and capable adversaries from reaching critical infrastructure in the United States and that, absent major efforts to identify and eliminate vulnerabilities in the most critical nodes of the most critical infrastructure, such attacks would succeed in causing unacceptable damage to the United States” {(a)(1)}. It does require a report to Congress that would include “an analysis of cyber vulnerabilities in the most critical nodes of the most critical infrastructure” {(c)(1)} and a listing of potential design solutions. Again, no funding is provided.

Sen. Warren’s (D,MA) SA 686 would require another report to Congress on “the significant security vulnerabilities of the national electric grid that are susceptible to significant malicious cyber-enabled activities” {(a)(1)} and their effect on DOD. While control systems are not specifically mentioned in this amendment it does use the 6 USC 1501 definition of ‘security vulnerability’ that is based upon that section’s ICS-inclusive definition of ‘information system’. Again, no funding is provided.

Moving Forward


There is a possibility that the Senate will move forward to consider HR 2810 before they start their summer recess later next month. Those chances were decreased, however, when Sen. McCain (R,AZ; Chair of the Senate Armed Services Committee) returned to Arizona to undergo treatment for his newly diagnosed cancer.


Even if the bill does come to the floor for debate and amendment, there is no telling if/when any of the above amendments would be considered.

Friday, July 14, 2017

House Passes HR 2810 – FY 2018 NDAA

Today the House passed HR 2810, the FY 2018 National Defense Authorization Act (NDAA) by a substantially bipartisan vote of 344 to 81. All four cyber-related amendments passed by voice votes.

The bill passed today will not be considered in the Senate. The Senate will take up their own version of the NDAA (S 1519) perhaps as soon as next week. Once the amendment process in the Senate is complete, a conference committee will be appointed to work out the differences in the two bills.

Thursday, July 13, 2017

HR 2810 Considered in House – Four Cyber Amendments Passed

Yesterday the House began consideration of HR 2810, the FY 2018 National Defense Authorization Act. All four of the cyber related amendments that I described yesterday were passed by voice votes as part of four separate en bloc amendments. The House tries to group uncontroversial amendments into groups to reduce the amount of time taken up in the debate/vote process.


• Thornberry en bloc 1 (Pages H5737–44) (included #22);
• Thornberry en bloc 3 (Pages H5749–53) (included #56); and
• Thornberry en bloc 4 (Pages H5753–56) (included #80 and #81)

The House is continuing consideration of HR 2810 today.

Wednesday, July 12, 2017

Rule for Consideration of HR 2810 – FY 2018 NDAA

Last night the House Rules Committee completed their work on the rule for consideration of HR 2810, the FY 2018 National Defense Authorization Act. The bill will be considered under a structured rule with only 88 of the 434 submitted amendments to be considered on the floor of the House.

Of those 88 amendments only four deal with cyber issues. Those amendments are:

22. Johnson, Mike (LA) #329 (REVISED) Requires the Army to conduct a report on the Army Combat Training Centers and the current resident cyber capabilities and training at such bases to examine potential training readiness shortfalls and pre-rotational cyber training needs are met.

56. Harper (MS), Brady, Robert (PA) #126 Authorizes the Speaker of the House with the concurrence of the Minority Leader to call upon the Executive Branch for additional resources in the event the House is the victim of a cyber-attack.

80. Correa (CA) #258 Requires the Department of Defense to update its cyber strategy; to require the President to develop a strategy for the offensive use of cyber capabilities; and to allow for technical assistance to North Atlantic Treaty Organization members.

81. Aguilar (CA) #95 (REVISED) Creates a talent management pilot program for the recruitment, training, professionalization, and retention of personnel in the cyber workforce of the Department of Defense.

None of these cyber initiatives specifically address control system security issues.

Monday, July 10, 2017

Committee Hearings – Week of 07-09-17

The House and Senate are back in Washington after their extended 4th of July weekend. Spending bills are the big item in the House this week; that and HR 2810, the FY2018 National Defense Authorization Act (NDAA)

Spending Bills


The House Appropriations Committee and its various subcommittees will be holding a number of hearings this week on the individual spending bills.


HR 2810


As I mentioned in an earlier post, the House Rules Committee is holding two meetings (Tuesday and Wednesday) on HR 2810, the FY 2018 NDAA. Generally, we can expect the first meeting to establish the general ground rules for debate on the floor of the House. The second will establish which amendments may be offered on the floor. The number will be large and will include the major Democrat wish-list amendments.


The House will begin consideration of HR 2810 on Wednesday and should finish with a final vote Thursday night.

Rules Committee Hearing on HR 2810 – FY 2018 NDAA

Tomorrow evening the House Rules Committee will hold [corrected meeting date information, 2130 EDT, 7-10-17] its first of two meetings on HR 2810, the FY 2018 National Defense Authorization Act (NDAA). Almost 400 amendments have been submitted to the Committee for possible floor consideration during the amendment process on HR 2810 later this week. Of those, 15 concern cybersecurity or cyberwarfare concerns. I am not providing a detailed analysis of each of these amendments at this time.

10
Rep.
Prohibits DOD from contracting with telecom firms found by ODNI to be complicit with DPRK cyberattacks.
46
Rep.
Directs the Secretary of Defense to define “deterrence” in a cybersecurity landscape, and assess how this definition affects the overall cybersecurity strategy in the Department of Defense.
47
Dem.
Directs the Secretary of Defense to conduct a study on current DoD cyber authorities, structures, and capabilities needed to protect overall civilian and government infrastructure networks and systems of the United States. The study shall identify gaps in current authorities, capabilities, personnel, or other resources necessary to respond to cyber incidents.
126
Harper (MS), Brady, Robert (PA)
Bi-Partisan
Authorizes the Speaker of the House with the concurrence of the Minority Leader to call upon the Executive Branch for additional resources in the event the House is the victim of a cyber-attack.
141
Dem.
Requires certain secretaries to designate a lead agency for the purposes of carrying out a GPS backup demonstration.
182
Dem.
Directs the Secretary of Defense to develop plans for early detection, mitigation, and defense against state sponsored cyberattacks targeting federal public election assets, election administrators, election workers, or voter engagement efforts.
183
Dem.
Directs Secretary of Defense to develop effective countermeasures for cyber weapons developed for offensive purposes. (This amendment recognizes that as the U.S. enhances its cyber offense capability it is critical that it is prepared to defend networks against attacks by weapons it may have developed but later obtained by adversaries, rivals, or terrorists.
195
Dem.
Increases the Cyber Scholarship Program by $15,000,000 and increases cyber defense education for reservists and National Guard by $35,000,000 by decreasing funds provided beyond the budget request, by $50,000,000 for missile defense.
197
Dem.
Increases funding for Historically Black Colleges and Universities/minority institutions by $10,000,000; increases Army RDTE, Defensive Cyber Tool Development by $10,000,000; increases Air Force Offensive Cyberspace Operations by $30,000,000; while decreasing funds provided beyond the budget request, by $50,000,000 for missile defense.
258
Dem.
Requires the Department of Defense to update its cyber strategy; to require the President to develop a strategy for the offensive use of cyber capabilities; and to allow for technical assistance to North Atlantic Treaty Organization members.
330
Kilmer (WA), Lamborn (CO)
Bi-Partisan
Authorizes the State Cyber Resiliency Grant Program to assist state, local, and tribal governments in preventing, preparing for, protecting against, and responding to cyber threats.
345
Lieu (CA), Amash (MI), Lofgren (CA), DelBene (WA)
Bi-Partisan
Prohibits using funds to mandate or request “backdoors” into commercial products that can be used to circumvent encryption or security protections.
348
Dem.
States the Secretary of Defense shall establish a cooperative program between the Office of the Chief Information Officer of the Department of Defense, the Defense Procurement Acquisition Policy, and the National Institute of Standards and Technology-Manufacturing Extension Partnership.The cooperative program established shall educate and assist small- and medium-sized manufacturing firms in the Department of Defense supply chain in achieving compliance with NIST Special Publication 800–171 titled ‘‘Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations’’ as such publication is incorporated into the Defense Federal Acquisition Regulation Supplement.
350
Dem.
Expresses the sense of Congress that the Secretary of Defense should establish a cooperative program between the Office of the Chief Information Officer of the Department of Defense, the Defense Procurement Acquisition Policy, and the National Institute of Standards and Technology-Manufacturing Extension Partnership. The cooperative program established shall educate and assist small- and medium-sized manufacturing firms in the Department of Defense supply chain in achieving compliance with NIST Special Publication 800–171 titled ‘‘Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations’’ as such publication is incorporated into the Defense Federal Acquisition Regulation Supplement.
352
Lipinski (IL), Khanna (CA), Knight (CA), Moulton (MA), Eshoo (CA)
Bi-Partisan
Authorizes $5 million for the development of curriculum, recruitment materials, and best practices to expand the Hacking for Defense program. Expresses the sense of Congress that the program provides a unique pathway for veterans to leverage their military experience to solve national security challenges.


Saturday, June 24, 2017

HR 2810, NDAA – Cyber Subcommittee Markups

As I mentioned earlier this week the subcommittees of the House Armed Services Committee held a series of markup hearings looking at HR 2810, the FY 2018 National Defense Authorization Act (NDAA). The hearing of the Emerging Threats and Capabilities Subcommittee added Title XVI, Subtitle D – Cyber Related Matters, to the language of HR 2810.

Items in that subtitle include:

§1641—Notification Requirements for Sensitive Military Cyber Operations and Cyber Weapons
§1642—Modification to Quarterly Cyber Operations Briefings
§1643—Cyber Scholarship Program
§1644—Plan to Increase Cyber and Information Operations, Deterrence, and Defense

None of the above sections contain any language that specifically identifies or includes industrial control system (ICS). There are, however, a series of definition changes identified in §1643 that eliminate ‘information technology’, ‘information security’ or ‘IT’ references by substituting ‘cyber’. No definition of the term ‘cyber’ is provided.

Those definitions would be found in 10 USC Chapter 112, Information Security Scholarship Program. There is nothing in the Subcommittee report that would specifically indicate that this was done to add ICS programs to the scholarship program, but it would seem that that would be the major practical consequence of this change.


The full Committee is scheduled to markup HR 2810 on Wednesday.

Thursday, June 8, 2017

Bills Introduced – 06-07-17

Yesterday with both the House and Senate in session there were 49 bills introduced. Of those three may be of specific interest to readers of this blog:

HR 2807 To amend title 10, United States Code, to require congressional notification concerning sensitive military cyber operations and cyber weapons, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 2810 To authorize appropriations for fiscal year 2018 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 2812 To direct the President to develop a strategy for the offensive use of cyber capabilities, and for other purposes. Rep. Correa, J. Luis [D-CA-46] 

I promise that this is not being turned into a military blog (GRIN), but military cyber weapons and strategy will probably have a serious impact on cybersecurity for control systems in critical infrastructure. We should certainly, for example, be prepared to defend critical infrastructure facilities from those types of control system attacks that our military contemplates executing against such facilities in enemy countries.

I will be watching HR 2807 for the critical definitions involved in outlining ‘sensitive military cyber operations and cyber weapons’ to see if Congress is intending to keep an eye on counter control system operations.

As always, I watch the military authorization and spending bills for cybersecurity provisions.


Last session there were a number of efforts (see HR 2708, HR 3039, and HR 5220 for example) related to requiring the President to establish norms for deciding what types of cyber-attacks would be considered ‘acts of war’. It will be interesting to see how HR 2812 differs from these earlier unsuccessful attempts.
 
/* Use this with templates/template-twocol.html */