Showing posts with label HR 3163. Show all posts
Showing posts with label HR 3163. Show all posts

Sunday, June 9, 2019

HR 3163 Reported in House – FY 2020 THUD Spending


Earlier this week Rep. Price (D,NC) introduced HR 3163, the Transportation, Housing and Urban Development, and Related Agencies (THUD) Appropriations Act, 2020. The House Appropriations Committee also published their Report on the bill. There are lots of interesting provisions in the bill as well as some important discussions in the Report.

Control System Security


Section 195 (pgs 103-4) of the bill would prohibit DOT from issuing grants “to entities that do not comply with practices for control system procurement recommended by the U.S. Department of Homeland Security’s National Cybersecurity and Communications Integration Center” {§195(a)} This overly broad language does include an escape clause whereby the Secretary can waive the requirement when it “would be inconsistent with the public interest” {§195(b)(1)}.

The Report address the cybersecurity of a specific type of control system; Positive Train Control (PTC). On page 54 the Committee urges the Federal Railroad Administration (FRA) “to establish enhanced cyber security methods, standards, and best practices for PTC systems and future versions of this technology”.

Automated Transportation Systems


Section 106 of the bill would establish, within the Office of the Secretary, a Highly Automated Systems Safety Center of Excellence. The HASSCE would {§106(b)}:

Serve as a single place within the Department of Transportation for expertise in automation and human behavior, computer science, machine learning, sensors, and other technologies involving automated systems;
Support all Operating Administrations of the Department of Transportation; and
Have a workforce composed of Department of Transportation employees, including direct hires or detailees from Operating [Modal] Administrations.

Employees of HASSCE would “audit, inspect, and certify highly automated systems to ensure their safety” {§106(c)}.

There is additional discussion of the role of HASSCE in the Report (pg 11). The role of the National Highway Transportation Safety Administration in the regulation of automated vehicles is addressed in pages 41 thru 42 of the Report.

Liquified Natural Gas by Rail


On page 53 of the Report the Committee ‘provides’ $2.5 million for “FRA to research and mitigate risks associated with the transportation of crude oil, ethanol, liquefied natural gas (LNG)”. That paragraph goes on to direct FRA and the Pipeline and Hazardous Material Safety Administration (PHMSA) “to continue to support cooperative research on the safe use of LNG in these applications [locomotive fuel and bulk rail transport] which could inform the development of new regulations”.

Page 75 provides a more detailed discussion of LNG by rail rulemaking being pursued by PHMSA. It directs PHMSA to fund a study by National Academies of Sciences, Engineering, and Medicine on the transportation of LNG by rail. The study would address multiple transportation scenarios and look at:

Release events;
Hazards when a spill is coupled with an ignition source;
Leak detection;
Impacted geographic areas;
Route terrain challenges; and
Emergency and first responder training and notification

The Report provides additional discussion of that last item, training, on pg 78. There the Committee “directs PHMSA to enhance its training curriculum for local emergency responders to account for LNG facilities and the transportation of LNG in rail tank cars.”

Commentary


It is odd that the Bill and the Committee Report both specifically address cybersecurity issues with transportation control systems, but then fail to address cybersecurity issues in their discussions of the HASSCE. While early discussions in DOT about highly automated driving systems did at least mention cybersecurity issues, there has been a glaring lack of such language in recent DOT rulemaking processes. Congress must insist that DOT include cybersecurity oversight in its regulation of automated driving systems. And it would have seemed to me that the language in §106 would have been an ideal place to do so.

With that in mind, I would like to suggest the following two changes to provisions within §106:

Revise §106(b)(1) to read:

(1) serve as a single place within the Department of Transportation for expertise in automation and human behavior, computer science, machine learning, sensors, cybersecurity, and other technologies involving automated systems;

Revise §106(c) to read:

(c) Employees of the Highly Automated Systems Safety Center of Excellence shall audit, inspect, and certify highly automated systems to ensure their safety and cybersecurity.

With regards to the control system supply chain security requirements of §195, the only recommended practices document that I can find on the CISA web site is the 2009 “Department of Homeland Security: Cyber Security Procurement Language for Control Systems”.

I am not sure how DOT would go about ensuring that those guidelines are being followed by organizations requesting various Transportation Department grants. Or, even more broadly, how they would determine what organizations would have control systems that would be covered by those recommendations.

Friday, June 7, 2019

Bills Introduced – 06-07-19


Yesterday with both the House and Senate meeting in proforma sessions (it was a short week for both) there were 16 bills introduced. Three of those will probably receive additional coverage in this blog:

HR 3156 To promote the use of smart technologies and systems in communities, and for other purposes. Rep. Clarke, Yvette D. [D-NY-9] 

HR 3163 Making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2020, and for other purposes. Rep. Price, David E. [D-NC-4]

HR 3164 Making appropriations for Agriculture, Rural Development, Food and Drug Administration, and Related Agencies programs for the fiscal year ending September 30, 2020, and for other purposes. Rep. Bishop, Sanford D., Jr. [D-GA-2]

We are seeing an unusual number of ‘smart technology’ bills in this session. This is typically an indication that a topic has garnered enough political attention that we can expect to see some action in the not too distant future. As is usual I will be watching HR 3156 for cybersecurity issues.

Sunday, May 6, 2012

Congressional Hearings – Week 5-8-12


The House and Senate come back to Washington this week. Two different committees will work on spending bills for DHS and a number of security related bills will be marked up in the House. The full House will consider a spending bill that could have cybersecurity provisions.

DHS Budget Hearings


Wednesday morning the Senate Appropriations Committee’s Homeland Security Subcommittee will hold a hearing to look at the President’s FY 2013 funding request for the Coast Guard. Adm. Papp, the Commandant, will be the sole witness.

Over in the House, at about the same time, the House Homeland Security Subcommittee will be marking up their FY 2013 DHS spending bill. A copy of the bill to be marked up will not be available until after both the subcommittee and the full committee have done their markups and reported the bill.

Security Related Markups


The House Homeland Security Committee will hold a markup hearing on Wednesday, looking at four separate bills. Three of the bills have some relationships to chemical security issues. They are:


• HR 3173, TWIC Processing; and


The WMD act looks like it will finally get its time in the sun. There will be an amendment in the nature of a substitute (ANS) offered by Chairman King. This is the same ANS that would have been considered back in February when the markup was previously scheduled. The bill concentrates on biohazards, the personal bĂȘte noir of Chairman King. Even the Metropolitan Medical Response System reauthorization contained in the does nothing to direct planning for a response for an attack on a chemical facility.

The TWIC processing bill was introduced last year and almost immediately added to HR 3116, the FY 2012 DHS Authorization bill, in the full committee markup of that bill. Since that bill has died a death of quiet neglect (yet again) the Committee will now try to get this bill passed on its own right. In an effort to make it easier for legitimate port workers to get their TWIC issued or renewed, the provisions of the bill will probably reduce the security of the documents according to the GAO.

The GAPS bill will add another study to the long list of ignored studies conducted by DHS. The bill requires the report to be classified, ignoring the rules for protecting port security information; just another classified report to gather dust.

All three bills will certainly be passed in committee, probably with some measure of bipartisan support. If/when they come to the floor of the House they will all probably pass there as well.

Other Spending Bills


The House will vote on two (maybe three) spending bills this week according to the House web site HR 5326, the appropriations bill for Commerce and Justice will be considered this week under rule (Rules Committee Hearing on Monday). There isn’t much in the actual bill about cybersecurity, but the Appropriations Committee Report briefly describes the FBI setting up cybersecurity equivalents of Joint Terrorism Task Forces. I’ll watch this for more cybersecurity coverage.

Two bills (one unnumbered as of today and HR 4966) would attempt to bypass some or all of the sequester provisions of last year’s spending bill will be considered this week. There is only a slim chance that security provisions could be included in the bills.
 
/* Use this with templates/template-twocol.html */