Showing posts with label HR 360. Show all posts
Showing posts with label HR 360. Show all posts

Friday, June 11, 2021

Review - HR 2928 Introduced – Cyber Sense Program

Back in March Rep Latta (R,OH) introduced HR 2928, the Cyber Sense Act of 2021. The bill would require DOE to establish “a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system” {§2(a)}. Similar bills have passed in the House in the last three sessions of congress, most recently HR 360 in the 116th.

Moving Forward

On Thursday of this week the House Energy and Commerce Committee held a markup hearing where this bill was considered. The Committee considered HR 2928 without amendments and ordered it favorably reported to the House by a voice vote. The bill will be considered by the full House, likely before the Summer Recess. The bill will be considered under the suspension of the rules process. This means limited debate, no floor amendments and a super majority will be required for passage. The bill will almost certainly pass (yet again) with strong bipartisan support.

Commentary

I would like to propose a value-added feature that should be made part of the Cyber Sense Program, a software bill of materials {SBOM, as defined in §10(j) of EO 14028} requirement for all product. This would help DOE notify other vendors of potential vulnerabilities in their systems due to new vulnerabilities being reported to DOE in other affected products. This will be especially critical while there is a CEII restriction on publication of the vulnerability. To make this happen, we could revise §2(b)(2):

(2) for products and technologies tested under the Cyber Sense program, the Secretary would establish:

(i) a requirement to submit a software bill of materials (SBOM), as that term is defined in §10(j) of EO 14028 for each product or technology submitted for evaluation;

(ii) and maintain cybersecurity vulnerability reporting processes and a related database; and

(iii) provide notification to affected vendors when a vulnerability reported to the Cyber Sense program potentially affects their product, based upon their SBOM listing on file with the program.

For a more detailed analysis of this legislation see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-2928-introduced (subscription required).

Friday, October 2, 2020

Bills Introduced – 10-1-20

Yesterday, with both the House and Senate in session (an unusual October session in an election year), there were 67 bills introduced. One of those bills will receive additional coverage in this blog:

S 4795 A bill to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Sen. Rosen, Jacky [D-NV] 

It is unusual for this bill to be introduced this late in the session when the House just passed their version of the bill this week. It will be interesting to see what the differences are between this bill and HR 360.

Wednesday, September 30, 2020

House Passes 3 DOE Cybersecurity Bills – 9-29-20

Yesterday the House considered three Department of Energy cybersecurity related bills under the suspension of the rules process. All three bills passed by voice vote.

The three bills were:

HR 359, the Enhancing Grid Security through Public-Private Partnerships Act,

HR 360, the Cyber Sense Act of 2019, and

HR 362, the Energy Emergency Leadership Act

I have not covered HR 362 here in this blog. It would amend 42 USC 7133(a); specifically adding ‘cybersecurity’ as one of the functions which would be assigned to one of more of the eight Assistant Secretaries in the Department.

Moving Forward

These three bills now move to the Senate for possible consideration. None of the bills is important enough in the grand scheme of things to be considered on the floor of the Senate under normal order (debate, amendment and multiple votes), especially this late in a COVID-19, election-year limited session. The only hope that these bills have for action in the Senate would be consideration under the unanimous consent process. The voice votes yesterday would seem to indicate that that could be possible.

Unfortunately, unanimous consent motions can be stopped by the objection of a single Senator. That objection would not necessarily have anything to do with the provisions of the bill but could be used as a lever for one or more Senators to have their way on some other legislative priority. I will be pleasantly surprised if any of these bills are considered in the Senate

Commentary

Of the three bills, only HR 360 has the potential of accomplishing anything in the cybersecurity realm. The other two bills are Congressional ‘we did something’ bills that essentially reaffirm actions already taken by DOE.

But even HR 360 will be of limited effect since it is a voluntary program for vendors and utilities. The only real mandate is the prohibition on information sharing by DOE about vulnerabilities discovered during testing. Since vendors could still continue to sell the vulnerable devices (especially outside of the utility market), this could actually increase the risks for end users, even within the ‘protected’ electric sector.

Of course, the biggest drawback to HR 360 is that the lack of funding for the proposed Cyber Sense program.

Monday, September 28, 2020

House to Take Up 5 Cybersecurity Bills

This week the House is scheduled to take up 50 bills under the suspension of the rules process. Five of those bills are related to cybersecurity. The suspension of the rules process calls for limited debate and no amendment of the bill to be accepted from the floor. Bills are required to get a supermajority vote to pass.

The five cybersecurity bills are:

HR 359 – Enhancing Grid Security through Public-Private Partnerships Act, as amended (Rep. McNerney – Energy and Commerce)

HR 360 – Cyber Sense Act of 2020, as amended (Rep. Latta – Energy and Commerce)

HR 5760 – Grid Security Research and Development Act (Rep. Bera – Science, Space, and Technology)

HR 5780 – Safe Communities Act of 2020, as amended (Rep. Underwood – Homeland Security)

HR 5823 – State and Local Cybersecurity Improvement Act, as amended (Rep. Richmond – Homeland Security)

Only one of these bills as being considered this week have been changed since they were adopted in committee. HR 359 has had the phrase “and other Federal agencies” removed from language requiring the DOE to consult with various organizations as “the Secretary determines appropriate”. This means that Congress does not want to even suggest that DOE might want to consult with CISA. This is an odd change.

The other oddity in this list is the inclusion of HR 5760. The language from this bill was mostly included in the recently passed HR 4447. That bill has little to no chance of being considered by the Senate. That means that taking up this bill in a stand-alone version would increase its chances of making it to the President’s desk for signature. It makes one wonder why it was added to HR 4447 in the first place; it might have been an attempt to politically buy the vote of Rep Weber (R,TX) who was a cosponsor of HR 5760. If so, it did not work; Weber was not one of the 7 Republicans to vote for the bill.

The House leadership expects each of these bills to pass this week with substantial bipartisan support. This means that there is some chance that the bills could be taken up by the Senate under their unanimous consent process. We will have to wait and see what kind of votes these bills actually get before we can assess what those chances might actually be.

Tuesday, August 13, 2019

S 2095 – DOE Cybersecurity


Last month Sen. Gardner (R,CO) introduced S 2095, the Enhancing Grid Security through Public-Private Partnerships Act. The bill would require the Department of Energy (DOE) to establish a voluntary security program for electric utilities and provide a report to Congress on cybersecurity of electricity distribution systems. This bill is very similar to HR 359, which was ordered favorably reported by the House Energy and Commerce Committee last month.

Differences in the Bills


There are a number of differences between the two bills. Many of them are strictly structural; the definitions are in §2 of the Senate bill and §5 of the House bill. Others are editorial in nature; adding ‘of a State’ following ‘political subdivision’ in the Senate version. These changes are of interest only to grammarians, lawyers and judges.

Other changes are of more consequence. The senate bill does not include the section on electricity interruption information that was included as §4 in the House bill. There are two changes (an addition and a deletion) to the voluntary security program described in §3 of S 2095 (see below). Finally, the Senate bill adds a 1 year deadline for the required report to Congress on cybersecurity and distribution systems.

Security Program


The security program in this bill was originally introduced in HR 5240 in the 115th Congress. That program would have required DOE to:

• Develop, and provide for voluntary implementation of, maturity models, self-assessments, and auditing methods for assessing the physical security and cybersecurity of electric utilities;
• Provide training to electric utilities to address and mitigate cybersecurity supply chain management risks;
• Increase opportunities for sharing best practices and data collection within the electric sector;
• Assist with cybersecurity training for electric utilities;
• Advance the cybersecurity of third-party vendors that work in partnerships with electric utilities; and
• Provide technical assistance for electric utilities subject to the program.

S 2095 modifies that program by removing the requirement for DOE to assist with cybersecurity training. This bill would substitute a requirement for DOE to “to assist with threat assessment and cybersecurity training for electric utilities” {§3(a)(2)}.

Moving Forward


Neither Booker nor his single cosponsor {Sen. Bennet (D,CO)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. With no representation on that Committee it is unlikely that this bill will receive consideration.

The House version of the bill received bipartisan support in the markup of the bill last month in the House Energy and Commerce Committee. I suspect that this bill would also receive bipartisan support if it were considered in Committee. The changes described above would have no significant bearing on the support this bill would receive.

NOTE on HR 359


In my post on the introduction of HR 359 I noted that it would be considered by the full House on January 11th, 2019 under the suspension of the rules process. This had been scheduled, along with the consideration of two other cybersecurity bills, HR 360 and HR 370. None of those bills were considered.

It looked like the new Democratic leadership was going to act quickly (if somewhat inadequately) on some critical infrastructure cybersecurity measures. It did not happen for reason which have not been made public. With that initial quick intent to pass these three cybersecurity bills, it is odd that no action was taken in Committee until a subcommittee markup (with no amendments) in May and full Committee markup in July.

The bipartisan support for these bills in Committee would seem to indicate that the bills would easily pass in the House under the suspension of the rule process. I would have thought that the initial pass on considering these bills indicated that there was an intent to revise these bills to include some sort of regulatory authority to insure that facilities complied with the ‘voluntary measures’ included in the bill. The lack of amendments in Committee would seem to indicate that the leadership has decided that such cybersecurity mandates were not going to make it to the President’s desk.

I suspect that all three House bills will be considered by the full House in September.

Tuesday, January 15, 2019

HR 360 Introduced – Cyber Sense Program


Last week Rep. Latta (R,OH) introduced HR 360, the Cyber Sense Act of 2019. The bill is nearly identical to HR 5239 introduced last session and adopted by the House Energy and Commerce Commission. The new bill is most closely related to the reported version of the earlier bill.

Moving Forward


This bill was scheduled to be considered (along with HR 359)  in the House today under the suspension of the rules process, but that has since changed. This was apparently done to provide time for the consideration of HJ Res 27 as I mentioned earlier.

This bill received bipartisan support in Committee during the last session and I suspect that it will again, if/when it reaches the floor of the House.

The House has still not made committee assignments for its members (beyond most Chairs and Ranking Members), so it is not yet possible to definitively comment on the possibility of this bill being considered in the House Energy and Commerce Committee, it that is not pre-empted by floor action. I suspect that Latta and his co-sponsor {Rep. McNerney (D,CA)} will be influential members of that Committee.

Commentary


I still have concerns about the information sharing restrictions in the bill. Most of the devices that would be covered under the Cyber Sense program would be used by manufacturing facilities outside of the electric sector. They could be substantially harmed by restricting the sharing of vulnerability information about those devices by making that information Critical Electrical Infrastructure Information (CEII).

As I outlined in my post on the introduction to HR 5239, I would much rather see a requirement to provide restricted early notification of vulnerabilities to organizations in the electric sector before universal notifications are made by NCCIC-ICS.

Interestingly, device vendors would probably not be restricted from publishing vulnerability reports on their own products, even if ‘protected’ by the CEII labeling. CEII restrictions only apply to government agencies within the United States.

Thursday, January 10, 2019

Bills Introduced – 01-09-19


Yesterday with both the House and Senate in session there were 89 bills introduced. Of these, three bills will likely receive future mention in this blog:

HR 359 To provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Rep. McNerney, Jerry [D-CA-9]

HR 360 To require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Rep. Latta, Robert E. [R-OH-5] 

HR 370 To require the Secretary of Energy to carry out a program relating to physical security and cybersecurity for pipelines and liquefied natural gas facilities. Rep. Upton, Fred [R-MI-6] 

Bills Also Worth Mentioning


I am also going to call attention here to six other bills here that would attempt to mitigate the effects of the current Federal Funding Fiasco. I will briefly discuss these bills in this post and will probably not mention them again in this blog.

HR 367 Making appropriations for Coast Guard pay in the event an appropriations Act expires before the enactment of a new appropriations Act. Rep. DeFazio, Peter A. [D-OR-4]

HR 371 Making appropriations for certain Federal employees working during the Government shutdown beginning on or about December 22, 2018, and for other purposes. Rep. Biggs, Andy [R-AZ-5]

HR 374 To make continuing appropriations for Coast Guard pay in the event that appropriations for Coast Guard pay in fiscal year 2019 expire and a new appropriations Act has not been enacted. Rep. Byrne, Bradley [R-AL-1]

HR 419 To make continuing appropriations for the Federal Aviation Administration for fiscal year 2019. Rep. Van Drew, Jefferson [D-NJ-2]

HR 421 Making continuing appropriations for the Coast Guard. Rep. Wild, Susan [D-PA-7] 

S 72 A bill to suspend the enforcement of certain civil liabilities of Federal employees and contractors during a lapse in appropriations, and for other purposes.  Sen. Schatz, Brian [D-HI]

FFF Effect Mitigation


As we quickly approach the 21-day FFF record it is interesting to note the efforts by a wide variety of congresscritters to protect various agencies and employees of the Federal government from the effects of the FFF. At first glance it would seem that these efforts are commendable as they would reduce the suffering of employees who are, after all, bearing the direct brunt of this political foofaraw.

On the other hand, and there is ALWAYS an ‘other hand’ when it comes to politics, I think that these efforts are misguided. While reducing the pain and suffering of these employees would be great for them and their families, it would also serve to reduce the political price for shutting down the government (or portions thereof) and make future shutdowns more likely.

On the first Tuesday in November, 2020, the voters of this country will remember this little game of political hostage taking. The hardcore supporters of both the President and the Democratic leadership of Congress will probably reward them for their intransience, but the vast majority of folks in the center will take revenge for those hurt during this FFF. They will go into the voting booth having decided who was mainly at fault (both sides share at least some portion of the blame) and will vote for their political retirement.

That is as it should be, there should be a high price to pay for using the disruption of the government as a political tool. Unfortunately, any measures taken to reduce the impact of that disruption will lesson the anger of the electorate and thus reduce the price to be paid for this game of political one-up-man-ship.  That could have the unintended consequence of extending the length of the current FFF and increase the chance of a repeat performance in FY 2020.

 
/* Use this with templates/template-twocol.html */