Showing posts with label HR 2928. Show all posts
Showing posts with label HR 2928. Show all posts

Wednesday, July 21, 2021

6 Cybersecurity Bills Passed in House – 7-20-21

Yesterday the House passed six cybersecurity bills as part of an en bloc vote on 21 bills that were considered on Monday and Tuesday under the suspension of the rules process. The recorded vote was 319 to 105 with the Republican vote nearly evenly split. The six cybersecurity bills were:

HR 2928 – Cyber Sense Act of 2021

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Tuesday, July 20, 2021

HR 2921 Passed in House – Enhanced Grid Security

Yesterday the House passed HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, by a voice vote (pg H3641). There was limited debate on the bill with no voices raised in opposition. This bill is unlikely to be considered in the Senate, certainly not through normal order. If it is taken up as stand-alone legislation it will be by the Senate’s unanimous consent process. This bill could be included in some other ‘more important’ legislation where it could be considered under regular order.

HR 2928, the Cyber Sense Act of 2021, was also taken up yesterday, but a recorded vote was demanded and action was deferred until today.

Monday, July 19, 2021

Committee Hearings – Week of 7-18-21

This week with both the House and Senate meeting in Washington, there will be a full slate of committee hearings. Hearings of interest include the markup of the Senate version of the FY 2022 National Defense Authorization Act, three cybersecurity hearings and the start of the consideration process for FY 2022 spending bills. And we will have an interesting slate of cybersecurity legislation being considered on the floor of the House.

NDAA Markup in Senate

The Senate Armed Services Committee will be marking up their version of the FY 2022 NDAA. Each subcommittee will be meeting to markup their portions of the NDAA on Monday and Tuesday. Then the full Committee will meet Wednesday and probably Thursday to complete the markup process. The subcommittee markups of interest here include:

• Monday - Subcommittee on Cybersecurity. CLOSED

• Tuesday - Subcommittee on Emerging Threats and Capabilities. CLOSED.

Cybersecurity Hearings

On Tuesday the House Small Business Committee will be holding a hearing on “Strengthening the Cybersecurity Posture of America’s Small Business Community”. This hearing is unlikely to specifically address control system security issues. The witness list will include:

• Tasha Cornish, Cybersecurity Association of Maryland, Inc.,

• Sharon Nichols, Mississippi Small Business Development Center,

• Kiersten Todt, Cyber Readiness Institute,

• Graham Dufault, The App Association,

On Tuesday the Subcommittee on Oversight and Investigations of the House Committee on Energy and Commerce will be holding a hearing on "Stopping Digital Thieves: The Growing Threat of Ransomware". This hearing is very likely to specifically address control system security issues and could get fairly technical. The witness list includes:

• Kemba Walden, Microsoft Corporation,

• Robert M. Lee, Dragos,

• Christian Dameff, M.D., M.S., Medical Director of Cybersecurity, UC San Diego Health,

• Charles Carmakal, FireEye-Mandiant

• Philip Reiner, Institute for Security and Technology

On Wednesday, the Senate Environment and Public Works Committee will be holding a hearing on “Addressing Cybersecurity Vulnerabilities Facing Our Nation’s Physical Infrastructure”. While the witness list is not yet available, there is a decent chance that there will be some discussion about control system cybersecurity issues. I would not be surprised to see witnesses from the water treatment sector.

Spending Bills

The House Rules Committee has announced that they are accepting amendments for the first spending bill for FY 2022. The House will be considering a minibus (multiple spending bills under one bill number), probably next week. The amendment deadline is Wednesday evening and the Committee is likely to hold their rulemaking hearing next Monday.

The slate for the first minibus is set to include:

Division A (Labor, Health and Human Services, Education),

Division B (HR 4356 – Agriculture, Rural Development),

Division C (Energy and Water Development),

Division D (HR 4345 – Financial Services and General Government),.

Division E (HR 4372 – Interior, Environment),

Division F (HR 4355 – Military Construction, Veterans Affairs),

Division G (Transportation, Housing, and Urban Development),

I do not typically review the FSG, or MCV spending bills, and the ARD bill contained nothing that I cover in this blog. The LHHS and THUD bills will probably be introduced today.

On the Floor

The House will be spreading their 27 bills considered under suspension of the rules over two days this week. The list includes seven cybersecurity bills:

• Monday

HR 2931 – Enhancing Grid Security through Public-Private Partnerships Act,

HR 2928 – Cyber Sense Act of 2021

• Tuesday

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Republicans have been forcing recorded votes on the suspension bills. Democrats have responded by voting on some and including the remainder in the vote on the language of the rule for consideration of bills under regular order. This may make reporting passage of these bills somewhat piece meal.

Saturday, July 10, 2021

S 2199 Introduced - Cyber Sense Act

Last month, Sen Rosen (D,NV) introduced S 2199, the Cyber Sense Act of 2020 (yep, it says 2020). The bill would require DOE to “establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system”. The bill is similar to HR 2928 which was adopted by the House Energy and Commerce Committee without amendment.

Definitions

Section 2(a) of the bill provides the definitions for four critical terms used in the bill (these definitions are not laid out in HR 2928, the terms are defined in passing), two by reference to existing definitions. There are no cybersecurity related definitions provided.

Program Established

Sections 2(b) and 2(c) in this bill are essentially identical to §2(a) and §2(b) respectively in the House bill. The only difference is that the House bill keeps referring to the ‘Cyber Sense Program’ where the Senate bill uses the term ‘Program’ after defining that in §2(a)(3) as meaning the ‘Cyber Sense Program’ established in §2(b).

Moving Forward

While Rosen is not a member of the Senate Energy and Natural Resources Committee, the committee to which this bill was assigned for consideration, three of her four cosponsors {Sen Hoeven (R,ND), Sen King (I,ME), and Risch (R,ID), are members and Hoeven is the Ranking Member of the Energy Subcommittee. This means that there is probably sufficient influence to see this bill considered in Committee.

The House version of this bill received bipartisan support and I would expect to see the same in Committee in the Senate. The problem remains moving the bill to the floor of the Senate. The bill is not important enough to be considered under regular order (debate, amendments, and, of course, two separate cloture votes) and I suspect that there would be sufficient opposition to stop consideration under the unanimous consent process.

The only way this bill is moving forward in the Senate is attached to some other, must pass piece of legislation.

Commentary

In my Substack post on HR 2928 I addressed my concerns about the information sharing restrictions in what is §2(d) in this bill. Many pieces of control system equipment are used outside of the bulk power system and restricting those outside that system from being notified of vulnerabilities is just not fair.

In my post on this blog I talked about adding a software bill of materials requirement to the House version of this bill. My interest in seeing that done remains.

Thursday, June 24, 2021

Bills Introduced – 6-23-21

Yesterday, with both the House and Senate in session, there were 63 bills introduced. Two of those bills may receive additional coverage in this blog:

S 2199 A bill to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Sen. Rosen, Jacky [D-NV] 

S 2201 A bill to manage supply chain risk through counterintelligence training, and for other purposes. Sen. Peters, Gary C. [D-MI]

I will be covering S 2199. I suspect that it is a companion measure to HR 2928.

As always, one has to be careful with the term ‘supply chain risk’. I will be watching this bill to see if that term is used in the cybersecurity sense and, if it does, whether the bill contains language and definitions that would include industrial control systems in its coverage.

Friday, June 11, 2021

Review - HR 2928 Introduced – Cyber Sense Program

Back in March Rep Latta (R,OH) introduced HR 2928, the Cyber Sense Act of 2021. The bill would require DOE to establish “a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system” {§2(a)}. Similar bills have passed in the House in the last three sessions of congress, most recently HR 360 in the 116th.

Moving Forward

On Thursday of this week the House Energy and Commerce Committee held a markup hearing where this bill was considered. The Committee considered HR 2928 without amendments and ordered it favorably reported to the House by a voice vote. The bill will be considered by the full House, likely before the Summer Recess. The bill will be considered under the suspension of the rules process. This means limited debate, no floor amendments and a super majority will be required for passage. The bill will almost certainly pass (yet again) with strong bipartisan support.

Commentary

I would like to propose a value-added feature that should be made part of the Cyber Sense Program, a software bill of materials {SBOM, as defined in §10(j) of EO 14028} requirement for all product. This would help DOE notify other vendors of potential vulnerabilities in their systems due to new vulnerabilities being reported to DOE in other affected products. This will be especially critical while there is a CEII restriction on publication of the vulnerability. To make this happen, we could revise §2(b)(2):

(2) for products and technologies tested under the Cyber Sense program, the Secretary would establish:

(i) a requirement to submit a software bill of materials (SBOM), as that term is defined in §10(j) of EO 14028 for each product or technology submitted for evaluation;

(ii) and maintain cybersecurity vulnerability reporting processes and a related database; and

(iii) provide notification to affected vendors when a vulnerability reported to the Cyber Sense program potentially affects their product, based upon their SBOM listing on file with the program.

For a more detailed analysis of this legislation see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-2928-introduced (subscription required).

Thursday, June 10, 2021

Energy & Commerce Committee Approves 3 Cybersecurity Bills

Today the House Energy and Commerce Committee held a markup hearing for six bills. Three of those bills were related to cybersecurity. All three cybersecurity bills were ordered reported favorably to the full House, each by voice votes. No amendments were offered on any these three amendments.

The three cybersecurity bills were:

HR 3078, the Pipeline and LNG Facility Cybersecurity Preparedness Act,

• HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, and

• HR 2928, the Cyber Sense Act of 2021

NOTE: To date, I have only reviewed HR 3078. None of these bills have yet been published by the GPO.

Wednesday, June 9, 2021

House Energy and Commerce Cybersecurity Markup Hearing Scheduled

The House Energy and Commerce Committee will be holding a markup hearing tomorrow. The agenda includes three cybersecurity bills:

HR 3078, the Pipeline and LNG Facility Cybersecurity Preparedness Act,

HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, and

HR 2928, the Cyber Sense Act of 2021

NOTE: Each of the links above are to committee prints of the bills. GPO has not yet gotten to these bills. I have not yet reviewed them.

Saturday, May 1, 2021

Bills Introduced – 4-30-21

Yesterday, with the House meeting in pro forma session and the Senate out of town until May 10th, there were 56 bills introduced. Two of those bills will receive additional coverage in this blog:

HR 2928 To require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Rep. Latta, Robert E. [R-OH-5] 

HR 2931 To provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Rep. McNerney, Jerry [D-CA-9]

 
/* Use this with templates/template-twocol.html */