Showing posts with label HR 3510. Show all posts
Showing posts with label HR 3510. Show all posts

Tuesday, October 6, 2015

House Passes HR 3510 – Cybersecurity Strategy

This evening the House passed HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015 on a voice vote. There was only 10 minutes (out of an authorized 40 minutes) of debate on the bill before the vote.

As I noted in an earlier post there is really nothing in the bill that specifically addresses control system security issues, but neither does it specifically address IT security issues. This is a very broadly written bill that does not even distinguish between government cybersecurity issues and regulatory cybersecurity issues.


This bill is unlikely to attract even this much attention in the Senate if it is considered there. I would expect that it would be taken up at the end of the day under the unanimous consent process which normally involves no debate.

Homeland Security Committee Marks-Up Multiple Bills

Last Wednesday the House Homeland Security Committee held a markup hearing that dealt with a large number of bills. As I mentioned in an earlier post some of those bills will be of specific interest to readers of this blog. Those include:

HR 3350, the Know the CBRN Terrorism Threats to Transportation Act;
HR 3490, the Strengthening State and Local Cyber Crime Fighting Act;
HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015;
HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015;
HR 3573, the DHS Science and Technology Reform and Improvement Act of 2015;
HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act;
HR 3586, the Border and Maritime Coordination Improvement Act; and
HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015.

HR 3350 was adopted without amendments on a voice vote.

HR 3490

HR 3490 was amended and adopted by a voice vote. Rep. Ratcliffe (R,TX) proposed substitute language reflecting the changes made to the bill in a Subcommittee markup which was adopted by a voice vote. Two amendments were offered by Rep. Jackson-Lee (D,TX). The first dealt with chain-of-custody training. The second dealt reaffirmed the supremacy of the fourth and fifth amendments with respect to the provisions of this bill. Both amendments were adopted by voice vote.

HR 3503

HR 3503 was amended and adopted by a voice vote. Two amendments were introduced by Rep. Loudermilk (R,GA). The first dealt with a requirement for DHS to conduct an assessment for accessibility and interoperability of the information systems used to share homeland security information between the Department and fusion centers. The second required DHS to enter into a memorandum of understanding about what types of information fusion centers would share with DHS. Both amendments were adopted by voice vote.

HR 3510

HR 3510 was amended and adopted by a voice vote. Rep. Clawson (R,FL) introduced one amendment which dealt with privacy concerns. That amendment was adopted by a voice vote.

HR 3578

HR 3578 was amended and adopted by a voice vote. Eight amendments, including alternative language offered by Rep. Ratcliffe, were offered and all were adopted on voice votes. The alternative language made no substantive changes of particular interest to readers of this blog. Of the remaining seven amendments only one of specific.

That amendment by Rep. Langevin (D,RI) that modifies the new §322 the bill adds to the Homeland Security Act of 2002. That section addressed cybersecurity R&D and this amendment adds a new activity to be addressed by DHS S&T; “support, in coordination with the private sector, the review of source code that underpins critical infrastructure information systems” {new §322(b)(4)}.

HR 3583

This bill was amended and adopted by a voice vote. Of the seven amendments offered and adopted only one would be of specific interest to readers of this blog. It was offered by Rep. Payne (D,NJ), the Ranking Member of the Committee.

The amendment modifies 6 USC 321e(c)(1); adding a new duty to job of Department Chief Medical Officer. That new requirement is specifically requiring the provision of advice on “how to prepare for, protect against, respond to, recover from, and mitigate against the medical effects of terrorist attacks or other high consequent events utilizing chemical, biological, radiological, or nuclear agents or explosives”. This wording still limits that advice to ‘chemical agents’ so it would not include advice on response to industrial chemical incidents unless they were used as part of a terrorist attack.

HR 3586

The bill was amended and adopted by a voice vote. Rep. Miller (R,MI) offered an amendment in the form of a substitute. That substitute language softened much of the language in the bill but did not make any substantive changes of particular interest to readers of this blog. None of the other ten amendments that were adopted on this bill were of specific interest to readers of this blog.

HR 3584

This bill was amended and adopted by a voice vote. None of the eight amendments adopted on this bill substantially affected areas of specific interest to readers of this blog.

Moving Forward

All of these bills are apparently on Chairman McCaul’s (R,TX) agenda for moving to the floor of the House. I expect that there is a good chance that they will all make it to the floor prior to the end of the year and there is a chance that they will all arrive on the same day. With the broad bipartisan support seen in Committee I expect that they will all be considered under suspension of the rules with limited debate and not floor amendments. All of these bills should pass with substantial bipartisan support.

I do not see any of these bills as being a high priority for getting consideration in the Senate. Any of these bills could easily pass and none would have significant opposition; it is just a matter of legislative priorities about which of these might make it to the floor of the Senate.

Commentary

Not surprisingly, none of the suggestions that I have made here in this blog for improving any of these bills were included in the amendments that were adopted. Oh well, that is always the problem with being a voice crying in the wilderness; the few people that do hear you are not necessarily ones that can do anything about it.

There was that one odd amendment by Langevin on HR 3578 that kind of interests me. It does not cover control systems since this new section uses the definition of ‘information systems’ from 44 USC 3502 which interestingly only applies to Federal IT systems.

I’m not sure what Langevin was trying to accomplish with this ‘review of source code’. Okay I suppose that I could guess that he wants someone to check these IT programs for bugs, but reviewing the source code is not probably the most effective method of doing that. And the terminology ‘that underpins critical infrastructure information systems’ was obviously not written by a programmer. Now the vendor should already be conducting a source code review prior to publishing the software, so I am not sure what Langevin is expecting this to accomplish.

The real interesting thing about this amendment is not actually what it does or tries to do, but the fact that it is part of a new trend in legislation over the last month or so where there are bits of cybersecurity language being added to bills that are not overtly cybersecurity bills. In many ways this is probably a more practical way to cybersecurity provisions passed. Large, all-encompassing bills are going to always draw somebodies ire and we will see few of them actually become law. Small targeted provisions (even if poorly written like this one) in a bill that is not going to draw substantial opposition are much more likely to get passed.

The problem is, of course, how to you keep the ineffective or even offensive small cybersecurity provisions out of otherwise good legislation? Amendments like Langevin’s are not posted in advance for public review and I doubt anyone on the Committee (members or staff) are tech savvy enough to understand how ineffective this provision actually is. And once an amendment is adopted in full committee it is unlikely to get removed in the remaining portions of the legislative process.

Small cybersecurity provisions that are written into original legislation are likely to be seen by reviewers like me, but will generally be overlooked by most people. This means that only the most objectionable are likely to draw the kind of opposition that will have them removed from the bill or modified to make them more workable.


This new approach of adding small, limited cybersecurity provisions to other types of legislation is going to start to make things interesting in the legislative process.

Monday, October 5, 2015

Congressional Hearings – Week of 10-04-15 –

Both the House and Senate will be in session this week. Budget issues have been pushed to the backrooms so we are going to see a variety of issues coming up in hearing rooms this week. Hearing of probable interest to readers of this blog include: drones, NPPD organization, and maritime cybersecurity.

Drones

The Aviation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing on Wednesday on “Ensuring Aviation Safety in the Era of Unmanned Aircraft Systems”. The witness list includes:

• Michael G. Whitaker, Deputy Administrator, FAA
• James Hubbard, Deputy Chief, United States Forest Service
• Captain Tim Canoll, President, Air Line Pilots Association
• Rich Hanson, Director of Government and Regulatory Affairs, Academy of Model Aeronautics
• Dr. Mykel Kochenderfer, Professor of Aeronautics and Astronautics

NPPD Organization

On Wednesday the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee will hold a hearing on “Examining the Mission, Structure, and Reorganization Effort of the National Protection and Programs Directorate”. The witness list includes:

• Ronald J. Clark, Deputy Under Secretary, NPPD
• Chris P. Currie , US GAO
• Phyllis Schneck, Deputy Under Secretary, Cybersecurity and Communications, NPPD
• Suzannee Spaulding, Under Secretary, Cybersecurity and Communications, NPPD

Looking at the witness list this certainly looks like it will concentrating on the cybersecurity side of NPPD. I doubt, however, that much mention will be made of ICS-CERT.

Maritime Cybersecurity

The Border and Maritime Security Subcommittee of the House Homeland Security Committee will be holding a hearing on “Are Our Nation’s Ports at Risk for A Cyber-Attack?” The witness list includes:

Jeh C. Johnson, Secretary, DHS;
James B. Comey, Jr., Director, FBI;
Nicholas J. Rasmussen, Director, National Counterterrorism Center,

Don’t expect to hear too many actionable details from this hearing. It is going to concentrate of policy and broad threat overviews.

On the Floor

Among the many bills that will be considered in the House on Tuesday under suspension of the rules, there is one bill that might be of specific interest to readers of this blog:

HR 3510 – Department of Homeland Security Cybersecurity Strategy Act of 2015, as amended


This bill was marked up in Committee last week. There was one amendment adopted dealing with privacy issues. HR 3510 is expected to pass with bipartisan support, minimal debate and no floor amendments will be authorized.

Thursday, September 17, 2015

HR 3510 Introduced – Cybersecurity Strategy

Tuesday Rep. Richmond (D, LA) introduced HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015. The bill adds a new section to Subtitle C of title II of the Homeland Security Act requiring the DHS Secretary to develop a cybersecurity strategy for the Department.

Cybersecurity Strategy

The new §230 in the bill requires that the strategy include {§230(b)}:

• Strategic and operational goals and priorities to successfully execute the full range of the Secretary’s cybersecurity responsibilities; and
• Information on the programs, policies, and activities that are required to successfully execute the full range of the Secretary’s cybersecurity responsibilities.

The bill requires the Secretary to develop the strategy within 60 days of the bills adoption {§230(d)}. Then, thirty days after that the Secretary is required to develop a plan to implement the strategy.

The bill does prohibit the Secretary from reorganizing “departmental components or offices” {§230(f)}without Congressional authorization.

Moving Forward

The bill was considered in a markup hearing this morning in the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee. No amendments were offered and the bill was adopted by a voice vote. That typically indicates substantial bipartisan support for the bill.

Richmond is the Ranking member of the Subcommittee and on non-partisan bills (like this) that typically means that he has enough pull to see this bill through the committee consideration process. This is a bill that should move quickly to full committee consideration. When it makes it to the floor of the House is a completely different story. That will depend on whether or not Rep. McCaul (R,TX) gets behind the bill.

Because of the non-controversial nature of the bill and the fact that it requires no new regulations or funding, I would suspect that the bill would be considered under suspension of the rules and be approved by a substantially bipartisan vote if it does reach the floor.

Commentary

The bill does not make any distinction between statutory and regulatory responsibilities in defining what areas should be covered by the strategy. The bulk of the Departments statutory cybersecurity responsibility rests with Federal information system security, and that is undoubtedly the main focus of the intent of this legislation.

The relationship of the Secretary to private sector cybersecurity is a completely different matter. The CFATS program, for instance, does not include any specific reference to cybersecurity measures in its authorizing language (6 USC 622) but there are certainly cybersecurity requirements in the CFATS regulations {eg; 6 CFR 27.230(a)(8)}. It is unclear if the strategy is required to address the implementation of these cybersecurity requirements in DHS regulations.

Considering the short time limit for formulating the strategy and then the implementation plan I suspect that the Department would take the high-road and only include the statutory cybersecurity requirements in the development of the new strategy. It would make a great deal of sense to do so from a bureaucratic point of view and it would almost certainly satisfy the crafters of this legislation.


On the other hand, the public sector would probably benefit more from a strategy that is more focused on the regulatory responsibilities of the Department. Better codification of the requirements of Risk Based Performance Standard 8 for the CFATS program and a clearer understanding of the support to be provided by the ICS-CERT for activities under that RBPS would be a lot more helpful to chemical facilities covered by the CFATS program.

Wednesday, September 16, 2015

Bills Introduced – 09-15-15

With just the Senate in town yesterday (the House was in session for 2 minutes and no one came) there were 21 bills introduced. Of those only two may be of specific interest to readers of this blog:

HR 3505 To amend the Homeland Security Act of 2002 to improve the management and administration of the security clearance processes throughout the Department of Homeland Security, and for other purposes. Rep. Thompson, Bennie G. [D-MS-2]

HR 3510 To amend the Homeland Security Act of 2002 to require the Secretary of Homeland Security to develop a cybersecurity strategy for the Department of Homeland Security, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

HR 3505 will only be of interest if it contains provisions for providing security clearances to critical infrastructure for the purposes of information sharing.


HR 3510 will only be of interest if the strategy addresses either information sharing with the private sector (not too likely) or deals with guidance on how cyber security will be applied to regulated entities.
 
/* Use this with templates/template-twocol.html */