Showing posts with label HR 3350. Show all posts
Showing posts with label HR 3350. Show all posts

Tuesday, October 20, 2015

House Passes HR 3350

This evening the House passed HR 3350, the Know the CBRN Terrorism Threats to Transportation Act, after only 9 minutes of debate earlier in the day. The final vote was 416 to 0.


This is a feel good bill without much substance and that is reflected in the vote. The report required by the bill is also likely to be a feel good report without much substance. That is not because of any specific shortcoming of TSA. Rather it is because the bill only provides 90 days to complete the report and at least half of that time will be taken up by bureaucratic reviews and rewrites. But since there are no real requirements for content in the report, no one at the TSA will spend much time or effort on the report.

Monday, October 19, 2015

Committee Hearings – Week of 10-19-15

Both the House and Senate are back in Washington this week after their Columbus Day Recess (excuse me; ‘district work session’). There are three hearings currently scheduled that may be of specific interest to readers of this blog; two cybersecurity related hearings and one terror threat briefing.

Cybersecurity

The Commerce, Manufacturing and Trade Subcommittee of the House Energy and Commerce Committee will be holding a hearing on Wednesday looking at “Examining Ways to Improve Vehicle and Roadway Safety”. The discussions will be centered on a committee draft of new automotive safety legislation that includes a title specifically addressing cybersecurity issues.

The witness list includes:

• Mitch Bainwol, Alliance of Automobile Manufacturers
• John Bozzella, Global Automakers
• Joan Claybrook, Former Administrator, NHTSA
• Greg Dotson, Center for American Progress
• Maneesha Mithal, Federal Trade Commission
• Mark Rosekind, Administrator, NHTSA
• Peter Welch, Automobile Dealers Association
• Ann Wilson, Motor & Equipment Manufacturers Association

I don’t typically review legislation before it is introduced, but I’ll give a brief overview of the cybersecurity provisions of this bill. Title III of the bill is called “Privacy, Hacking Prohibition, and Cyber Security”. Section 301 establishes privacy rules for information collected by privately owned motor vehicles. Section 302 prohibits hacking (access without authorization) “an electronic control unit or critical system of a motor vehicle, or other system containing driving data for such motor vehicle, either wirelessly or through a wired connection”. And §303 establishes the Automotive Cybersecurity Advisory Council that does not include anyone from ICS-CERT (or DHS in general) or security researchers.

Please note that none of the witnesses has any cybersecurity background so it is unlikely that we will hear anything of real substance about cybersecurity at this hearing; other than, of course, please leave our systems alone.

The other cybersecurity related hearing is before the Energy Subcommittee of the House Science, Space and Technology Committee on Wednesday. That hearing will address “Cybersecurity for Power Systems”.

The witness list includes:

• Bennett Gaines, CIO, FirstEnergy Service Company
• Annabelle Lee, Electric Power Research Institute
• Brent Stacey, Idaho National Lab
• Greg Wilshusen, Government Accountability Office

There is a better chance of a technical discussion at this hearing.

Terror Threat

The House Homeland Security Committee will be holding a hearing looking at “Worldwide Threats and Homeland Security Challenges” on Wednesday.

The witness list includes:

• James B. Comey, Director FBI;
• Jeh C. Johnson, Secretary DHS;
• Nicholas J. Rasmussen, Director, National Counterterrorism Center

No actionable intelligence, of course; just an overview of the cruddy state of the world.

On the Floor


There is one bill that is scheduled to come to the floor of the House this week that may be of specific interest to readers of this blog; HR 3350, the Know the CBRN Terrorism Threats to Transportation Act. It will be considered on Tuesday under suspension of the rules. Again, this means limited debate and no floor amendments. It also means that it is likely to pass with bipartisan support. It passed in the Homeland Security Committee on a voice vote without amendments.

Tuesday, October 6, 2015

Homeland Security Committee Marks-Up Multiple Bills

Last Wednesday the House Homeland Security Committee held a markup hearing that dealt with a large number of bills. As I mentioned in an earlier post some of those bills will be of specific interest to readers of this blog. Those include:

HR 3350, the Know the CBRN Terrorism Threats to Transportation Act;
HR 3490, the Strengthening State and Local Cyber Crime Fighting Act;
HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015;
HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015;
HR 3573, the DHS Science and Technology Reform and Improvement Act of 2015;
HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act;
HR 3586, the Border and Maritime Coordination Improvement Act; and
HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015.

HR 3350 was adopted without amendments on a voice vote.

HR 3490

HR 3490 was amended and adopted by a voice vote. Rep. Ratcliffe (R,TX) proposed substitute language reflecting the changes made to the bill in a Subcommittee markup which was adopted by a voice vote. Two amendments were offered by Rep. Jackson-Lee (D,TX). The first dealt with chain-of-custody training. The second dealt reaffirmed the supremacy of the fourth and fifth amendments with respect to the provisions of this bill. Both amendments were adopted by voice vote.

HR 3503

HR 3503 was amended and adopted by a voice vote. Two amendments were introduced by Rep. Loudermilk (R,GA). The first dealt with a requirement for DHS to conduct an assessment for accessibility and interoperability of the information systems used to share homeland security information between the Department and fusion centers. The second required DHS to enter into a memorandum of understanding about what types of information fusion centers would share with DHS. Both amendments were adopted by voice vote.

HR 3510

HR 3510 was amended and adopted by a voice vote. Rep. Clawson (R,FL) introduced one amendment which dealt with privacy concerns. That amendment was adopted by a voice vote.

HR 3578

HR 3578 was amended and adopted by a voice vote. Eight amendments, including alternative language offered by Rep. Ratcliffe, were offered and all were adopted on voice votes. The alternative language made no substantive changes of particular interest to readers of this blog. Of the remaining seven amendments only one of specific.

That amendment by Rep. Langevin (D,RI) that modifies the new §322 the bill adds to the Homeland Security Act of 2002. That section addressed cybersecurity R&D and this amendment adds a new activity to be addressed by DHS S&T; “support, in coordination with the private sector, the review of source code that underpins critical infrastructure information systems” {new §322(b)(4)}.

HR 3583

This bill was amended and adopted by a voice vote. Of the seven amendments offered and adopted only one would be of specific interest to readers of this blog. It was offered by Rep. Payne (D,NJ), the Ranking Member of the Committee.

The amendment modifies 6 USC 321e(c)(1); adding a new duty to job of Department Chief Medical Officer. That new requirement is specifically requiring the provision of advice on “how to prepare for, protect against, respond to, recover from, and mitigate against the medical effects of terrorist attacks or other high consequent events utilizing chemical, biological, radiological, or nuclear agents or explosives”. This wording still limits that advice to ‘chemical agents’ so it would not include advice on response to industrial chemical incidents unless they were used as part of a terrorist attack.

HR 3586

The bill was amended and adopted by a voice vote. Rep. Miller (R,MI) offered an amendment in the form of a substitute. That substitute language softened much of the language in the bill but did not make any substantive changes of particular interest to readers of this blog. None of the other ten amendments that were adopted on this bill were of specific interest to readers of this blog.

HR 3584

This bill was amended and adopted by a voice vote. None of the eight amendments adopted on this bill substantially affected areas of specific interest to readers of this blog.

Moving Forward

All of these bills are apparently on Chairman McCaul’s (R,TX) agenda for moving to the floor of the House. I expect that there is a good chance that they will all make it to the floor prior to the end of the year and there is a chance that they will all arrive on the same day. With the broad bipartisan support seen in Committee I expect that they will all be considered under suspension of the rules with limited debate and not floor amendments. All of these bills should pass with substantial bipartisan support.

I do not see any of these bills as being a high priority for getting consideration in the Senate. Any of these bills could easily pass and none would have significant opposition; it is just a matter of legislative priorities about which of these might make it to the floor of the Senate.

Commentary

Not surprisingly, none of the suggestions that I have made here in this blog for improving any of these bills were included in the amendments that were adopted. Oh well, that is always the problem with being a voice crying in the wilderness; the few people that do hear you are not necessarily ones that can do anything about it.

There was that one odd amendment by Langevin on HR 3578 that kind of interests me. It does not cover control systems since this new section uses the definition of ‘information systems’ from 44 USC 3502 which interestingly only applies to Federal IT systems.

I’m not sure what Langevin was trying to accomplish with this ‘review of source code’. Okay I suppose that I could guess that he wants someone to check these IT programs for bugs, but reviewing the source code is not probably the most effective method of doing that. And the terminology ‘that underpins critical infrastructure information systems’ was obviously not written by a programmer. Now the vendor should already be conducting a source code review prior to publishing the software, so I am not sure what Langevin is expecting this to accomplish.

The real interesting thing about this amendment is not actually what it does or tries to do, but the fact that it is part of a new trend in legislation over the last month or so where there are bits of cybersecurity language being added to bills that are not overtly cybersecurity bills. In many ways this is probably a more practical way to cybersecurity provisions passed. Large, all-encompassing bills are going to always draw somebodies ire and we will see few of them actually become law. Small targeted provisions (even if poorly written like this one) in a bill that is not going to draw substantial opposition are much more likely to get passed.

The problem is, of course, how to you keep the ineffective or even offensive small cybersecurity provisions out of otherwise good legislation? Amendments like Langevin’s are not posted in advance for public review and I doubt anyone on the Committee (members or staff) are tech savvy enough to understand how ineffective this provision actually is. And once an amendment is adopted in full committee it is unlikely to get removed in the remaining portions of the legislative process.

Small cybersecurity provisions that are written into original legislation are likely to be seen by reviewers like me, but will generally be overlooked by most people. This means that only the most objectionable are likely to draw the kind of opposition that will have them removed from the bill or modified to make them more workable.


This new approach of adding small, limited cybersecurity provisions to other types of legislation is going to start to make things interesting in the legislative process.

Thursday, July 30, 2015

Bills Introduced – 07-29-15

Yesterday there were 197 bills introduced in the House and Senate. Most of those (178) were from the House as it was leaving for the summer recess. Many of those bills were introduced just for the purposes of showing the voters and campaign contributors that the Congressman was actively working on issues important to those in the home district. Of the bills introduced yesterday just 11 may be of specific interest to readers of this blog:

HR 3299 To amend the Public Health Service Act to ensure preparedness for chemical, radiological, biological, and nuclear threats, and for other purposes. Rep. Brooks, Susan W. [R-IN-5]

HR 3305 To help enhance American network security and mitigate cybersecurity risks, and for other purposes. Rep. Hurd, Will [R-TX-23]

HR 3313 To amend the Homeland Security Act of 2002 to strengthen the ability of the Secretary of Homeland Security to detect and prevent intrusions against, and to use countermeasures to protect, agency... Rep. McCaul, Michael T. [R-TX-10]

HR 3326 To amend chapter 90 of title 18, United States Code, to provide Federal jurisdiction for the theft of trade secrets, and for other purposes. Rep. Collins, Doug [R-GA-9]

HR 3348 To direct the Attorney General to create a special reward program for individuals providing information leading to the apprehension and conviction of persons committing offenses under section 1030 of... Rep. Green, Al [D-TX-9]  

HR 3350 To require a terrorism threat assessment regarding the transportation of chemical, biological, nuclear, and radiological materials through United States land borders and within the United States, and... Rep. Higgins, Brian [D-NY-26]

HR 3360 To provide for identity protection coverage and other services for individuals exposed to the OPM security breaches, and for other purposes.

HR 3361 To amend the Homeland Security Act of 2002 to establish the Insider Threat Program, and for other purposes. Rep. King, Peter T. [R-NY-2]

HR 3402 To strengthen the ability of the Secretary of Homeland Security to detect and prevent intrusions against, and to use countermeasures to protect, government agency information systems and for other... Rep. Ruppersberger, C. A. Dutch [D-MD-2]

HR 3418 To enhance homeland security, including domestic preparedness and the collective response to terrorism, by improving the Federal Protective Service, and for other purposes. Rep. Thompson, Bennie G. [D-MS-2]

S 1890 A bill to amend chapter 90 of title 18, United States Code, to provide Federal jurisdiction for the theft of trade secrets, and for other purposes. Sen. Hatch, Orrin G. [R-UT] 

Cybersecurity

Not surprisingly a large number (7) of these bills deal (HR 3305, HR 3313, HR 3326, HR 3348, HR 3360, HR 3402, and S 1890) with cybersecurity issues. It looks like HR 3326 and S 1890 are companion bills that would make it a Federal offense to steal trade secrets. Three of the bills (HR 3313, HR 3360, and HR 3402) appear to deal with Federal computer systems (but may contain language for private sector cybersecurity). HR 3348 would establish a special reward program to deal with offenses under 18 US 1030, Fraud and related activity in connection with computers.

Chemical Security

I’m lumping the other four bills under the rubric of chemical security; though for two of them that only covers a portion of the threat to which the bills are responding. HR 3299 looks at CBRN issues from a public health perspective. HR 3350 would require a ‘terrorism threat assessment’ for CBRN related shipments within the United States; there will be some interesting definitions here. HR 3361 looks at insider threat response; this may also be a cybersecurity bill. And HR 3418 would strengthen the Federal Protects Service; which also provides critical infrastructure chemical facility support to facilities not covered under CFATS or MTSA programs.

Moving Forward

The Senate will be in Washington for another week or two. When they adjourn for summer recess I expect that we will see another large (but not so large) batch of bills introduced. In the meantime the Senate will continue to introduce a limited number of bills each day they are in session and there is a chance that an occasional bill will be introduced during the pro forma sessions that the House will hold between now and Labor Day.

It will take the GPO a while to work through this back log of bills, so I will continue to have fodder for my blog post while Congress is junketing, schmoozing voters, and sucking up to campaign contributors.


 
/* Use this with templates/template-twocol.html */