Showing posts with label HR 3359. Show all posts
Showing posts with label HR 3359. Show all posts

Monday, November 26, 2018

HR 2825 Reported in Senate – FY2018 DHS Authorization


The Senate Homeland Security and Governmental Affairs Committee published their report on HR 2825, the Department of Homeland Security (DHS) Authorization Act of 2017, as amended by that Committee back in March. There is no new information of consequence in this report, but its publication does effectively clear this bill for consideration by the full Senate.

Interestingly this bill does also include authorization language for the DHS Cybersecurity and Infrastructure Security Agency which was earlier authorized by the passage of HR 3359. There are some differences in the CISA authorization language in the two bills. The language of this bill would supersede the language of HR 3359 if it is adopted.

CISA Authorization


The first major difference between the two bills is the addition of the responsibility for the oversight of electromagnetic pulse (EMP) and geomagnetic disturbance (GMD) protection and preparedness activities. This is initially set forth in the new 6 USC 2202(c)(5) (pg 940). The requirement is further outlined in the new 6 USC 2204 setting forth the duties of the Infrastructure Security Division of CISA.

Section 2204(d)(6) requires annual reports to Congress on “the threats and con5
sequences, as of the date of the information, of electromagnetic events to the critical infrastructure of the United States”. That report would include outlining DHS activities with respect to {new §2204(d)(6)(B), pg 958}:

• Risk assessments;
• Mitigation actions;
• Coordination with the Department of Energy to identify critical electric infrastructure assets subject to EMP or GMD risk; and
Current and future plans for engagement with the Department of Energy, the Department of Defense, the National Oceanic and Atmospheric Administration, and other relevant Federal departments and agencies;

The report to Congress would also address present and future collaborative efforts the Department has (or plans to have) with critical infrastructure owners and operators as well as {new §2204(d)(6), pg 958}:

• An identification of internal roles to address electromagnetic risks to critical infrastructure; and
• Plans for implementation and protecting and preparing United States critical infrastructure against electromagnetic threats.

The final major difference between the two bills with respect to CISA authorization is the way they handle the movement of Federal Protective Service within DHS. HR 3359 allowed the Secretary to either move FPS into CISA or some other organization within DHS and then report to Congress on that move. HR 2825 instead requires the Secretary to make a determination on the best place to move FPS and then seek Congressional approval for that move.

There are a couple of relatively minor wording changes in the language of the two bills. One is rather odd. In the new §2202(i), the savings clause that affirms that the revision in both bills has no effect on any existing authorities the following final phrase found in HR 3359 is absent in HR 2825:

“including the authority provided to the Sector-Specific Agency specified in section 61003(c) of division F of the Fixing America’s Surface Transportation Act (6 U.S.C. 121 note; Public Law 114–94).”

Moving Forward


As I mentioned earlier this report now clears the bill for potential consideration by the whole Senate. The bipartisan support seen in Committee should mean that the bill would pass the Senate. The problem here, this late in the session is that it will be difficult to bring up the bill in normal order with debate and further amendments. Practically speaking this means that this bill would have to be passed under the unanimous consent process which could be stopped by the opposition of a single senator to even relatively minor provisions in the bill. I suspect that this report is the last we will see of this bill in the 115th Congress.

Wednesday, November 14, 2018

HR 3359 Senate Amendment Accepted by House – CISA Authorization


Yesterday the House accepted the Senate’s amendment to HR 3359, the Cybersecurity and Infrastructure Security Agency Act of 2018. The bill creates the Cybersecurity and Infrastructure Security Agency (CISA) within DHS. The bill was passed earlier this year in the House. The Senate amendment was accepted by the House by ‘unanimous consent’, so no actual vote was taken, but a single voice in objection would have derailed the process.

The bill now goes to the President for signature. There has been no objection raised by the Administration about this bill. In fact, there has been lots of pressure to pass the measure.

Thursday, October 4, 2018

Senate Amends and Passes HR 3359 – DHS Reorganization


Yesterday the Senate amended and passed HR 3359, the ‘Cybersecurity and Infrastructure Security Agency Act of 2018. The bill creates the Cybersecurity and Infrastructure Security Agency within DHS. The bill was passed earlier this year in the House. Two amendments were made; the first (SA 4403, pg S6497) substitute language from Sen. Johnson (R,WI) and the second a minor amendment (SA 4404, pg S6502) from Sen. Murkowski (D,MO). Both amendments and the bill were adopted without debate or vote. The bill will now have to be reconsidered by the House.

Substitute Language


Most of the additions made by the Johnson amendment added references to ‘Sector-Specific Agency’. This included a new definition of that term added in the new §2201.

The language regarding the transfer of the DHS Federal Protective Service {§3(b)} was greatly expanded. The original bill provided that DHS could transfer the FPS to the new CISA. The substitute language approved yesterday expands on that by providing instructions on what needs to occur if DHS declines to make that move. This would include specific notifications to Congress and the involvement of the OMB in subsequent evaluation of what to do with the FPS.

A new §4 of the bill was added that requires a report to Congress by DHS on the “leadership role of the Department in cloud-based cybersecurity deployments for civilian Federal departments and agencies” {§4(b)}.

There were a number of wording deletions made by the substitute language. These include the rather inconsequential deleting of the definitions of the terms ‘federal entity’ and ‘non-federal entity’.

One potentially significant deletion in the new §2202 is made in paragraph (e)(1) where the responsibilities of the new CISA Director are enumerated. Sub-paragraph (M) was deleted. That originally read:

“To ensure, in conjunction with the chief information officer of the Department, that any information databases and analytical tools developed or utilized by the Department—
“(i) are compatible with one another and with relevant information databases of other Federal Government agencies; and
“(ii) treat information in such databases in a manner that complies with applicable Federal law on privacy.”

Finally a change was made to the wording in the bill dealing with the Chemical Facility Anti-Terrorism Standards (CFATS) program. In explicating the responsibilities of the new Assistant Director for the new Infrastructure Security Division we see both an addition and deletion made to the wording of the original bill. The quote below shows both the addition (underlined) and the deletion (struck-through) made to §2204(b)(2).

“(2) carry out efforts, at the direction of the Director, to secure the United States high-risk chemicals and chemical facilities consistent with law, including the Chemical Facilities Anti-Terrorism Standards Program established under title XXI and the secure handling of ammonium nitrate program established under subtitle J of title VIII, or any successor programs;”

Commentary


I continue to believe that this change to the status of the current National Protection and Programs Directorate is mainly a smoke and mirrors change. I have had a number of people with closer connection to the operation of DHS inform me that this has to do mainly with the status of the new Director and the authority of the new agency to deal with administrative and spending matters; none of which is directly addressed in the language of the bill.

The change in wording of §2204(b)(2) has me a little bit concerned. Neither the addition or deletion has any direct affect on the CFATS program. The added ‘any successor’ language is typically a legal distinction addressing the fact that Congress could change the name of the program at any time. Similarly, the deleted words have no apparent practical effect on the inclusion of the CFATS program in the new Infrastructure Security Division. But, there is a nagging question in my mind as to why Johnson made these specific changes to the wording about the CFATS program; is there something in the works?

I am more concerned, however, with the deletion of §2202(e)(1)(M). I am not an active privacy advocate particularly when it comes to the Federal government; mainly because I suspect that we have completely surrendered any pretense of privacy protection and any attempts to put the genie back in the bottle are mainly for show rather than for any practical effect. Having said that, I am concerned that Johnson thought that it was appropriate to remove language from the bill that provided some modicum of privacy protection to information collected by DHS. It probably was not going to be very effective, but it at least made a show of being concerned.

Tuesday, December 12, 2017

House Passes HR 3359 CISA Authorization

Yesterday the House passed HR 3359, the Cybersecurity and Infrastructure Security Agency Act of 2017 by a voice vote. The bill is Rep. McCaul’s (R,TX) long awaited reorganization of the DHS National Protection and Programs Division (NPPD).

Commentary


This bill is really nothing more than an exercise in bureaucratic shuffling. The existing NPPD is now called CISA; an Under Secretary will be known as the Director and a number of sections in 6 USC are being renumbered. The most important part of the bill is found in section 4 of the bill; nothing in the bill confers new authorities or reduces existing authorities existing the day before this bill is enacted.

There is one subtle change made by this bill in the new definitions section 2201. There are two cybersecurity related definitions in this new section; both taken from existing statutes. The bill uses the IT-limited definition of ‘cybersecurity risk’ from the current 6 USC 148 (moving to §2209) and the ICS-inclusive definition of ‘cybersecurity threat’ from 6 USC 1501. The definitional disconnect between these two very similar (and closely intertwined) terms could cause some interesting confusion about the authority of this ‘new’ agency to address control system security issues.

Moving Forward



The bill moves forward to the Senate where it will pass with similar bipartisan support if it reaches the floor for consideration. The big question is whether or not the bill will have the leadership support necessary to bring it to the floor for consideration. At this point, I am not sure that it does.

Tuesday, July 25, 2017

Bills Introduced – 07-24-17

Yesterday with both the House and Senate back in session there were 37 bills introduced. Of those, four may be of specific interest to readers of this blog:

HR 3358 Making appropriations for the Departments of Labor, Health and Human Services, and Education, and related agencies for the fiscal year ending September 30, 2018, and for other purposes. Rep. Cole, Tom [R-OK-4]

HR 3359 To amend the Homeland Security Act of 2002 to authorize the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10]

HR 3362 Making appropriations for the Department of State, foreign operations, and related programs for the fiscal year ending September 30, 2018, and for other purposes. Rep. Rogers, Harold [R-KY-5]

HR 3364 To provide congressional review and to counter aggression by the Governments of Iran, the Russian Federation, and North Korea, and for other purposes. Rep. Royce, Edward R. [R-CA-39]

As usual I will be watching the two spending bills for cybersecurity measures (probably none in the case of these two bills, but you never know).

HR 3359 is the homeland security bill that I talked about briefly in my blog yesterday. The official text is not yet available, but I may review later today it based upon the committee draft that will be considered tomorrow by the House Homeland Security Committee.


HR 3364 may be of interest if the bill addresses cyber related aggression or cyber response to aggression by these three countries.
 
/* Use this with templates/template-twocol.html */