Showing posts with label HR 3101. Show all posts
Showing posts with label HR 3101. Show all posts

Friday, November 17, 2017

S 2083 Introduced – Port Cybersecurity

Earlier this month Sen. Harris (D,CA) introduced S 2083, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. This bill is essentially identical to the version of HR 3101 that was passed in the House last month.

While Harris is not a member of the Senate Commerce, Science, and Transportation Committee (the committee to which this bill was assigned for consideration), her co-sponsor, Sen Sullivan (R,AK) is. This means that there is a chance that the Committee could take up the bill.

It is unusual for companion legislation to be introduced this late in the process. It probably means that Harris does not think that there is a reasonable chance that the Senate will take up HR 3101, even though there was bipartisan support for that bill in the House. That is not unusual, the House passes a lot of bills that are never taken up by the Senate; the Senate is slower to pass legislation.

If this bill is marked up by the Commerce Committee there will be a better chance that it will be taken up by the whole Senate. Unless there are significant amendments made to the bill, there is a good chance that the House would accept the Senate version of the bill and not require it to go to conference.


It is unlikely that this bill will receive any consideration this year.

Wednesday, November 8, 2017

Bills Introduced – 11-07-17

Yesterday with both the House and Senate in session, there were 49 bills introduced. Of those, on may be of specific interest to readers of this blog:

S 2083 A bill to enhance cybersecurity information sharing and coordination at ports in the United States, and for other purposes. Sen. Harris, Kamala D. [D-CA]


This bill may (possibly?) be a companion bill to HR 3101 that was recently passed in the House. I suspect that it is a re-write of the bill instead of trying to get the Senate Homeland Security and Governmental Affairs Committee trying to take up and amend HR 3101. I’ll know better when the bill is printed.

Wednesday, October 25, 2017

HR 3101 Passed in House – Port Cybersecurity

Yesterday the House passed HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017, by a voice vote.

As I noted in an earlier post the version of the bill approved yesterday is not the same version that was reported by the House Homeland Security Committee. The amended text is available in the Congressional Record. The change is inconsequential; a reformatting of the list of organizations to be included in the information sharing recommendations in §2(5).

This bill had wide bipartisan support in the House and will likely have the same in the Senate if it reaches the floor for consideration, not a necessarily guaranteed action. I do suspect that the bill will eventually be considered under the Senate’s unanimous consent provisions with no debate, no vote, and few Senators on the floor of the Senate. Nothing untoward in this, it is just the way that the Senate expeditiously handles non-controversial legislation. A single objection from the floor would prevent the action going forward, so the leadership is careful about how the process is used.


As I have noted in previous discussions, this bill continues to use the IT-limited cybersecurity definitions of 6 USC 148. This means that the provisions of this bill do not specifically include control system cybersecurity in the vulnerability assessment and security plan provisions the added cybersecurity requirements for 46 USC §70102 and §70103. This is a serious deficiency in the bill, and it will not be corrected as no further amendment processes are likely to be included in the future consideration of the bill.

Monday, October 23, 2017

HR 3101 Reported in House – Port Cybersecurity

Last week the House Homeland Security Committee published their report on HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. The same day, the House Transportation and Infrastructure Committee was discharged from further consideration of the bill.

HR 3101 was ordered reported without amendment when it was considered by the Committee on 9-7-17. This typically means that there is little to be gained by reviewing the report. But, with Transportation and Infrastructure Committee being discharged from consideration, it is important to look at the included letter (pgs 15) from the Chair of that Committee {Rep. Shuster (R,PA)} to see if there were any conditions imposed when he acquiesced in allowing the bill to move forward.

Sure enough, there were two conditions, both agreed to by Chairman McCaul (R,TX). The second, is the standard requirement that the Transportation and Infrastructure Committee be represented in any conference (if required) on the bill. The first is:

“Further, this is conditional on our understanding that mutually agreed upon changes to the legislation will be incorporated into the bill prior to floor consideration.”

There are no changes in the reported version of HR 3101, as I would expect given the fact that no amendments were adopted by the Committee. We will not be able to see the changes that are being made until today’s Congressional Record is published tomorrow (remember, the bill is being considered on the floor today). Interestingly, neither will any of the members of Congress that will be voting on the bill. Such is the power of committee chairs.


I do not expect that the changes will be major and I do not really look for them to make changes to affect the IT-centric nature of this bill.

Thursday, September 7, 2017

HR 3101 Passes in Committee – Port Cybersecurity

This morning the House Homeland Security Committee adopted HR 3101, a bill that would establish a number of modest cybersecurity requirements for (and in support of) port operations. No amendments were offered and the bill was adopted in a voice vote; signifying significant bipartisan support.

As I mentioned in my earlier post, this bill relies on the IT-centric definition of cyber risk that would exclude control systems from the modest requirements established by this bill.


The bill will probably be taken up in the House at some future (probably not near future) date under the suspension of the rules provisions. No floor amendments would be allowed under those circumstances and a supermajority would be required for passage. If the bill makes it to the floor of the Senate, it would almost certainly pass.

Tuesday, September 5, 2017

Committee Hearings – Week of 09-04-17

Yes, the House and Senate have actually returned to Washington; it must be September. Spending (including Harvey Relief) and debt limits are the big items that will have to be addressed before the end of the month. But, this week, in addition to the spending bill hearing this evening, there are two cybersecurity hearings scheduled and one cybersecurity bill on the floor of the House that may be of interest to readers of this blog.

Cybersecurity Hearings


The House Homeland Security Committee will hold a markup hearing on Thursday with four bills under consideration. The one of specific interest here is HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. No amendments to this bill are currently listed on the Committee web site.

The Cybersecurity and Infrastructure Protection Subcommittee of the House Homeland Security Committee will be holding an information hearing on Thursday. It will address “Challenges of Recruiting and Retaining a Cybersecurity Workforce”. The witness list is not currently available.

On the Floor


As I mentioned earlier, there is one cybersecurity related bill scheduled to be considered by the House this week; HR 3388, the SELF DRIVE Act. Additional cybersecurity provisions found in this bill are addressed here, here and here. This bill contains some of the most comprehensive cybersecurity provisions that I have seen to date and may end up having far ranging indirect impacts outside of the automotive world. This will be considered Wednesday under the suspension of the rules provisions that limit debate and require a supermajority for passage.


The bulk of the time on the floor of the House this week will be consumed with the consideration of HR 3354, the Make America Secure and Prosperous Appropriations Act, 2018. The House is taking this up early to provide time to recover if it fails in either the House or Senate. There is still a reasonable chance that we are going to end up with a last minute continuing resolution to keep the government operating at the end of the month.

Tuesday, July 18, 2017

HR 3101 Introduced – Port Cybersecurity

Last month Rep. Torres (D,CA) introduced HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. The bill establishes a number of modest cybersecurity requirements for (and in support of) port operations.

Federal Requirements


Section 2 of the bill establishes federal requirements for cybersecurity risk assessments, information sharing and coordination. First it requires DHS to conduct (and subsequently evaluate) a risk assessment for maritime cybersecurity based upon the NIST Cybersecurity Framework. Next, it requires DHS to ensure that at least one maritime information sharing analysis committee (ISAC) participates in the National Cybersecurity and Communications Integration Center.

Paragraph (4) requires DHS to establish “guidelines for voluntary reporting of maritime-related cybersecurity risks and incidents (as such terms are defined in section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)) to the Center [NCCIC]”. The next paragraph then requires DHS to “to report [on] and make recommendations to the Secretary on enhancing the sharing of information related to cybersecurity risks and incidents between relevant Federal agencies and State, local, and tribal governments”.

Local Requirements


Section 3 of the bill establishes local cybersecurity requirements. First it requires each Maritime Security Advisory Committee “to facilitate the sharing of cybersecurity risks and incidents to address port-specific cybersecurity risks, which may include the establishment of a working group of members of Area Maritime Security Advisory Committees to address port-specific cybersecurity vulnerabilities” {§2(1)}. Next it requires all new maritime or facility security plan (under 46 USC 70103) to “include a mitigation plan to prevent, manage, and respond to cybersecurity risks” {§2(2)}.

Specifically §4 amends two separate provision of 46 USC {§70102(b)(1)(C) – facility and vessel assessments – and §70103(c)(3)(C) – vessel and facility security plans} by adding the word “cybersecurity” after “physical security”. It would also add a requirement for vessel and facility security plans to address the “prevention, management, and response to cybersecurity risks” {new §70103(c)(3)(C)(v)}.

Moving Forward


While Torres is not a member of either committee to which the bill has been assigned for consideration, two of her cosponsors are {Rep. Correa (D,CA) – Homeland Security; and Rep. Wilson (D,FL) – Transportation and Infrastructure}. This means that there is at least a chance that either or both of these committees could consider HR 3101.

I do not see anything in the bill that would engender any significant opposition. If the bill were to be considered on the floor of the House it is likely that it would pass, probably under the suspension of the rules provision.

Commentary


Once again, the provisions of this bill rely on the 6 USC 148(a)(1) definition of ‘cybersecurity risk’, a definition that is limited to information systems and does not include control systems. This would mean that the requirements of this bill would not apply to operation of any of the many critical control systems found on vessels or in maritime facilities.


I would again like to point to a solution to this definitional problem in port cybersecurity legislation that I proposed in an earlier blog post. It would still use the existing, IT-centric, definition of ‘information system’, but would add a new definition for ‘control system’ and then combine both terms in the definition of ‘cybersecurity risk’.

Thursday, June 29, 2017

Bills Introduced – 6-28-17

Yesterday with both the House and Senate in session there were 48 bills introduced. Of those only one may be of specific interest to readers of this blog:

HR 3101 To enhance cybersecurity information sharing and coordination at ports in the United States, and for other purposes. Rep. Torres, Norma J. [D-CA-35]

It will be interesting to see if the bill includes control system cybersecurity provisions.
 
/* Use this with templates/template-twocol.html */