Showing posts with label HR 3583. Show all posts
Showing posts with label HR 3583. Show all posts

Tuesday, April 26, 2016

House Passes HR 3583 – The PREPARE Act

This evening the House passed HR 3583, the PREPARE Act. There were only sixteen minutes of debate and a voice vote. The bill reauthorizes and makes minor modifications to a number of emergency response and planning grant programs.

The bill requires a DHS report on the cybersecurity of FirstNet, the nationwide first responder network. It also requires DHS to establish a Social Media Working Group to enhance public communications during emergencies. And it requires the DHS Office of Health Affairs to establish a medical stockpile program for DHS employees.


It is likely that this bill will be taken up by the Senate under their unanimous consent procedures; again with limited debate and no actual vote.

Monday, April 25, 2016

Committee Hearings – Week of 04-24-16

Both the House and Senate are in Washington this week and there are an unusual number of markup hearings scheduled that may be of specific interest to readers of this blog. A number of cybersecurity related bills will be addressed as well as another pipeline safety bill.

Pipeline Safety


The House Energy and Commerce Committee will hold a two-day markup hearing starting Tuesday. Among the 22 bills to be considered is an as of yet un-introduced pipeline safety bill. This is not the same as last week’s HR 4937; that bill was the House Transportation and Infrastructure’s bill. I’ll have more details on the differences between the three bills now under consideration in a later post.

NOTE: This hearing will also take up HR 2031, the Anti-Swatting Act of 2015.

Cybersecurity


On Wednesday the House Armed Services Committee will hold a markup hearing of HR 4909, the National Defense Authorization Act (NDA) for FY 2017. While the original bill did not have any cybersecurity provisions, last week the Emerging Threats and Capabilities Subcommittee did add a number of new sections addressing cybersecurity issues; including:

• Section 221—Strategy for Assured Access to Trusted Microelectronics
• Section 806—Amendments Related to Detection and Avoidance of Counterfeit Electronic Parts
• Section 1631—Special Emergency Procurement Authority to Facilitate the Defense Against or Recovery from a Cyber Attack
• Section 1632—Change in Name of National Defense University's Information Resources Management College to College of Information and Cyberspace
• Section 1633—Requirement to Enter into Agreements Relating to Use of Cyber Opposition Forces
• Section 1634—Limitation on Availability of Funds for Cryptographic Systems and Key Management Infrastructure

On Wednesday the Senate Commerce, Science and Transportation Committee will hold a markup hearing addressing six bills; including the:

S 2607, Developing Innovation and Growing the Internet of Things (DIGIT) Act; and
• S 2817, Space Weather Research and Forecasting Act (text still not available).

On Thursday the House Homeland Security Committee will hold a markup hearing on four bills; including HR 4743, the National Cybersecurity Preparedness Consortium Act of 2016. It will be interesting to see if they address the definition issue so that the bill would also address control system security issues.

On the Floor


The House will consider two bills under suspension of the rules this week that may be of specific interest to readers of this blog:

HR 3583 – PREPARE Act, as amended
HR 4240 – No Fly for Foreign Fighters Act

As usual these will be considered under limited debate and no amendments from the floor.


The Senate resumes consideration of the military construction spending bill. There is a possibility that another spending bill may come up for consideration late this week.

Tuesday, October 6, 2015

Homeland Security Committee Marks-Up Multiple Bills

Last Wednesday the House Homeland Security Committee held a markup hearing that dealt with a large number of bills. As I mentioned in an earlier post some of those bills will be of specific interest to readers of this blog. Those include:

HR 3350, the Know the CBRN Terrorism Threats to Transportation Act;
HR 3490, the Strengthening State and Local Cyber Crime Fighting Act;
HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015;
HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015;
HR 3573, the DHS Science and Technology Reform and Improvement Act of 2015;
HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act;
HR 3586, the Border and Maritime Coordination Improvement Act; and
HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015.

HR 3350 was adopted without amendments on a voice vote.

HR 3490

HR 3490 was amended and adopted by a voice vote. Rep. Ratcliffe (R,TX) proposed substitute language reflecting the changes made to the bill in a Subcommittee markup which was adopted by a voice vote. Two amendments were offered by Rep. Jackson-Lee (D,TX). The first dealt with chain-of-custody training. The second dealt reaffirmed the supremacy of the fourth and fifth amendments with respect to the provisions of this bill. Both amendments were adopted by voice vote.

HR 3503

HR 3503 was amended and adopted by a voice vote. Two amendments were introduced by Rep. Loudermilk (R,GA). The first dealt with a requirement for DHS to conduct an assessment for accessibility and interoperability of the information systems used to share homeland security information between the Department and fusion centers. The second required DHS to enter into a memorandum of understanding about what types of information fusion centers would share with DHS. Both amendments were adopted by voice vote.

HR 3510

HR 3510 was amended and adopted by a voice vote. Rep. Clawson (R,FL) introduced one amendment which dealt with privacy concerns. That amendment was adopted by a voice vote.

HR 3578

HR 3578 was amended and adopted by a voice vote. Eight amendments, including alternative language offered by Rep. Ratcliffe, were offered and all were adopted on voice votes. The alternative language made no substantive changes of particular interest to readers of this blog. Of the remaining seven amendments only one of specific.

That amendment by Rep. Langevin (D,RI) that modifies the new §322 the bill adds to the Homeland Security Act of 2002. That section addressed cybersecurity R&D and this amendment adds a new activity to be addressed by DHS S&T; “support, in coordination with the private sector, the review of source code that underpins critical infrastructure information systems” {new §322(b)(4)}.

HR 3583

This bill was amended and adopted by a voice vote. Of the seven amendments offered and adopted only one would be of specific interest to readers of this blog. It was offered by Rep. Payne (D,NJ), the Ranking Member of the Committee.

The amendment modifies 6 USC 321e(c)(1); adding a new duty to job of Department Chief Medical Officer. That new requirement is specifically requiring the provision of advice on “how to prepare for, protect against, respond to, recover from, and mitigate against the medical effects of terrorist attacks or other high consequent events utilizing chemical, biological, radiological, or nuclear agents or explosives”. This wording still limits that advice to ‘chemical agents’ so it would not include advice on response to industrial chemical incidents unless they were used as part of a terrorist attack.

HR 3586

The bill was amended and adopted by a voice vote. Rep. Miller (R,MI) offered an amendment in the form of a substitute. That substitute language softened much of the language in the bill but did not make any substantive changes of particular interest to readers of this blog. None of the other ten amendments that were adopted on this bill were of specific interest to readers of this blog.

HR 3584

This bill was amended and adopted by a voice vote. None of the eight amendments adopted on this bill substantially affected areas of specific interest to readers of this blog.

Moving Forward

All of these bills are apparently on Chairman McCaul’s (R,TX) agenda for moving to the floor of the House. I expect that there is a good chance that they will all make it to the floor prior to the end of the year and there is a chance that they will all arrive on the same day. With the broad bipartisan support seen in Committee I expect that they will all be considered under suspension of the rules with limited debate and not floor amendments. All of these bills should pass with substantial bipartisan support.

I do not see any of these bills as being a high priority for getting consideration in the Senate. Any of these bills could easily pass and none would have significant opposition; it is just a matter of legislative priorities about which of these might make it to the floor of the Senate.

Commentary

Not surprisingly, none of the suggestions that I have made here in this blog for improving any of these bills were included in the amendments that were adopted. Oh well, that is always the problem with being a voice crying in the wilderness; the few people that do hear you are not necessarily ones that can do anything about it.

There was that one odd amendment by Langevin on HR 3578 that kind of interests me. It does not cover control systems since this new section uses the definition of ‘information systems’ from 44 USC 3502 which interestingly only applies to Federal IT systems.

I’m not sure what Langevin was trying to accomplish with this ‘review of source code’. Okay I suppose that I could guess that he wants someone to check these IT programs for bugs, but reviewing the source code is not probably the most effective method of doing that. And the terminology ‘that underpins critical infrastructure information systems’ was obviously not written by a programmer. Now the vendor should already be conducting a source code review prior to publishing the software, so I am not sure what Langevin is expecting this to accomplish.

The real interesting thing about this amendment is not actually what it does or tries to do, but the fact that it is part of a new trend in legislation over the last month or so where there are bits of cybersecurity language being added to bills that are not overtly cybersecurity bills. In many ways this is probably a more practical way to cybersecurity provisions passed. Large, all-encompassing bills are going to always draw somebodies ire and we will see few of them actually become law. Small targeted provisions (even if poorly written like this one) in a bill that is not going to draw substantial opposition are much more likely to get passed.

The problem is, of course, how to you keep the ineffective or even offensive small cybersecurity provisions out of otherwise good legislation? Amendments like Langevin’s are not posted in advance for public review and I doubt anyone on the Committee (members or staff) are tech savvy enough to understand how ineffective this provision actually is. And once an amendment is adopted in full committee it is unlikely to get removed in the remaining portions of the legislative process.

Small cybersecurity provisions that are written into original legislation are likely to be seen by reviewers like me, but will generally be overlooked by most people. This means that only the most objectionable are likely to draw the kind of opposition that will have them removed from the bill or modified to make them more workable.


This new approach of adding small, limited cybersecurity provisions to other types of legislation is going to start to make things interesting in the legislative process.

Tuesday, September 29, 2015

HR 3583 Introduced – PREPARE Act

Last week Rep. McSally (R,AZ) introduced HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act. The bill reauthorizes and makes minor modifications to a number of emergency response and planning grant programs. Program changes of specific interest to readers of this blog include

• Cybersecurity protections for Public Safety Broadband Network;
• DHS use of social networking; and
• The medical countermeasures program

FirstNet Cybersecurity

Section 206 of the bill requires the DHS National Protection and Programs Directorate Under Secretary to provide Congress with a report on the cybersecurity support that DHS is providing to the Department of Commerce FirstNet program. Specifically the Under Secretary is tasked with the requirement “to identify and address cyber risks that could impact the near term or long term availability and operations of such [public safety broadband] network and recommendations to mitigate such risks”.

Social Networking

Section 207 of the bill would add §318 to the Homeland Security Act of 2002. It provides for the establishment of a DHS Social Media Working Group. Alert readers of this blog will realize that I recently reported that the HR 623, with nearly identical language, has been reported in the Senate.

Medical Countermeasures Program

Section 303 of the bill would add §527 to the Homeland Security Act of 2002. It establishes a medical countermeasures program under the DHS Chief Medical Officer. The program is to be designed to “facilitate personnel readiness, and protection for working animals, employees, and individuals in the Department’s care and custody, in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, or pandemic” {new §527(a)}.

Moving Forward

McSally is the Chair of the Emergency Preparedness, Response, and Communications Subcommittee of the House Homeland Security Committee. The Committee Chair, Rep. McCaul, is cosponsor of this bill. So there is certainly the political will and power to move this bill forward.

The Subcommittee marked-up this bill before it was introduced. The full Committee markup is scheduled for Wednesday. I suspect that the bill will be approved by a voice vote without further amendment. If so it will move to the floor of the House before the end of the year; probably to be considered under suspension of the rules with little debate and no floor amendments.

Commentary

The Congress is taking more and more actions like that seen here in specifying that DHS will report on the cybersecurity of FirstNet. These little one section toss offs in a wide variety of legislation are doing more to further the centralization of cybersecurity responsibility in DHS than any single piece of legislation could. I expect that this means that I am going to have to be watching a wider variety of bills to find those mentions that might be of specific interest to the control system security community.

I am not sure why the Social Media Working Group language is once again in legislation that is obviously heading to the floor. It was already passed in the House as a standalone bill. The only thing that makes a modicum of sense is that McSally and McCaul do not expect the Senate to actually take up HR 623 and they really want this group to be formed.

Of concern to me is that this version of the §318 language is also missing any mention of monitoring social media to provide situational awareness to the Department. While the intel folks are trying desperately to monitor the social network communications of IS and AQ supporters, the emergency response folks are, due to excessive concern with avoiding the appearance of spying on the public, being forced to ignore the vital information that could be available in natural disasters and after attacks or manmade disasters. A vitally important requirement for this SMWG should be the development of tools to abstract information from publicly available social networks to support emergency response.

The medical countermeasures program also seems to be an overly limited, if certainly legitimate DHS program. DHS certainly has a responsibility to ensure that medically foreseeable countermeasures to CBRNE attacks are available to keep their troops in the field fully functioning in their emergency response and criminal investigation capacities in the event of such attacks.


With minimal expansion of responsibility, however, the DHS Office of Health Affairs could be developing plans and standards for the deployment of medical countermeasures to the general public. In particular, incidents like the acrylonitrile train wreck this summer point to the need for the centralized stockpiling and subsequent distribution of medical countermeasures for industrial chemical accidents. OHA could have been tasked in this bill with the requirement to identify those industrial chemicals requiring specific medical countermeasures that would not routinely be available to local emergency rooms. In conjunction with such a list they could have been required to submit a plan to Congress on how a regional stockpiling and distribution plan could be put together for such countermeasures.

Wednesday, September 23, 2015

Bills Introduced – 09-22-15

There were 27 bills introduced in the House and Senate yesterday even though the House was only minimally present in a pro forma session. Three of those bills and a Senate Amendment may be of specific interest to readers of this blog:

HR 3583 To reform and improve the Federal Emergency Management Agency, the Office of Emergency Communications, and the Office of Health Affairs of the Department of Homeland Security, and for other purposes. Rep. McSally, Martha [R-AZ-2] 

HR 3584 To authorize, streamline, and identify efficiencies within the Transportation Security Administration, and for other purposes. Rep. Katko, John [R-NY-24]

HR 3586 To amend the Homeland Security Act of 2002 to improve border and maritime security coordination in the Department of Homeland Security, and for other purposes. Rep. Miller, Candice S. [R-MI-10]

S Amdt 2669 Making continuing appropriations for the fiscal year ending September 30, 2016, and for other purposes. Sen. Cochran, Thad [R-MS] To H J Res 61, Hire More Heroes Act of 2015

Very Brief Summaries

I’ll be watching HR 3583 for possible effects on the chemical safety programs under OHA.

HR 3584 will be of potential interest for changes to surface transportation security programs.

HR 3586 will watched for changes to the MTSA program.

This amendment to HJ Res 61 will be the first pass at a continuing resolution to fund the government through December 11th. This will almost certainly be stalled by the Democrats because this version includes defunding of Planned Parenthood programs. The Republicans did try to defuse that issue by making those funds available to other women’s health programs, but the name ‘Planned Parenthood’ is as much a positive keystone for the Democrats as it is a negative keystone for the Republicans. There will be a cloture vote today on this amendment.

Side Note

Pro forma sessions of the House are typically attended by just three members; the acting speaker and a floor representative from each party and only involve administrative matters like receiving messages and introducing bills and resolutions. Every once in a while, however, there are actual legislative activities that take place and the results are the same as if the whole House was in attendance.

Yesterday was one of these occasions. During the six  minute long session the Foreign Affairs Committee was discharged from responsibility for H Res 50 that was introduced yesterday. The resolution was then brought to the floor for consideration, amended twice, and adopted by unanimous consent.

The resolution was introduced by Rep. Levin (D,MI) in response to concerns of the Ukrainian  community in Michigan about the Russian treatment of Nadiya Savchenko, a Ukranian military pilot, that was captured by pro-Russian forces in eastern Ukraine.


This is not an earth shattering bill and its passage obviously had the support of the leadership of both sides of the aisle in the House. It does show, however, that pro forma sessions in the House do need to be watched as legislative matters can be dealt with under unanimous consent rules without a quorum being present.
 
/* Use this with templates/template-twocol.html */