Showing posts with label HR 3710. Show all posts
Showing posts with label HR 3710. Show all posts

Friday, September 27, 2019

HR 3710 Passed in House – Cybersecurity Vulnerabilities


Yesterday the House passed HR 3710, the Cybersecurity Vulnerability Remediation Act, by a voice vote. While there was 12 minutes of debate on the bill, no one spoke against the measure. The bill now goes to the Senate where, if it is taken up, it will probably be considered under their unanimous consent process. No further amendments are expected to this legislation.

Monday, September 23, 2019

HR 3710 Reported in House – Cybersecurity Vulnerabilities


Last month the House Homeland Security Committee published their report on HR 3710, the Cybersecurity Vulnerability Remediation Act. The Committee held their markup hearing back in July and ordered the bill reported without amendment. The bill is currently scheduled for consideration under the House suspension of the rules process on Wednesday. There will be limited floor debate, no amendments may be offered from the floor and a supermajority is required for passage.

Commentary


The Committee did not deal with the copywrite issue or software ownership issue that I mentioned in my blog post on the introduction of the bill. This means that any mitigation measures that the Cybersecurity and Infrastructure Security Agency publishes as a result of this bill will have to be limited to the generic measures that CISA already includes in the control system security advisories published by NCCIC-ICS. CISA is not going to be able to publish any true ‘hacks’ of the affected software or firmware because of these issues and the bill would do nothing to provide liability protection for owners or users that would use such ‘hacks’ even if reported by CISA.

Making changes to the software, owned in most cases by the vendor not the facility in which the software operates, could be held to be a violation of 18 USC 1030(a)(5)(A) for CISA or any researcher providing a software ‘hack’ to CISA or a violation of 18 USC 1030(a)(5)(C) for facility owners that employed such a software hack to their systems.

So again, we have Congress taking action to solve a cybersecurity action that is really no action at all. There is a potential (but very unlikely) way for the House to correct this bill, even under the suspension of the rules process. Under a motion to reconsider after passage, the bill could be sent back to the Homeland Security Committee with direction to offer an amendment. That amendment would read:

On page 4, line 21; insert “(a)” before “The director”;
On page 5, line 2; delete the period after “dor” and insert a colon;
On page 5, after line 2; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the publication by CISA of any mitigation measure that changes the programing of a computer or device to provide a mitigation measure as described in (a) is not considered to be a fraud related activity as defined in §1030; and
“(c) Not withstanding 18 USC 1030(a)(5), the use of a mitigation measure described in (b) by a government agency or private entity to mitigate a vulnerability defined in (a) is not considered to be a fraud related activity as defined in §1030.”
On page 6, line 15; insert “(a)” before “The Under”;
On page 6, line 23; delete the period at the end and insert “; and”
On page 6, after line 23; insert:
“(b) Not withstanding 18 USC 1030(a)(5), the submission to CISA of suggested changes to the affected software to mitigate an identified vulnerability as part of the program described in (a) is not considered to be a fraud related activity as defined in §1030.”

I do not really expect that this would happen, but I can always be surprised by congresscritters. More likely such changes would have to be undertake in the Senate Homeland Security Committee if/when they markup HR 3710 after it passes in the House, but before it is considered under the unanimous consent process in the Senate. Again, I would not really expect that to happen. It would be too much like actually trying to accomplish something.

Saturday, August 31, 2019

Bills Introduced – 08-30-19


Yesterday with both the House and Senate meeting in proforma session (almost no one present) there were 15 bills introduced. One of these bills will receive future consideration in this blog:

HR 4217 To amend the Homeland Security Act of 2002 to develop tools to help State and local governments establish or improve cybersecurity, and for other purposes.  Rep. Katko, John [R-NY-24]

This bill would (text has already been published) would establish three separate cybersecurity grant programs for State and local governments.

Interesting side note: While Congresscritters are not in Washington, staffs certainly are. The House Homeland Security Committee filed six committee reports in yesterday’s session. Two of those (HR 3318 and HR 3710) will likely be addressed here in more detail when the reports are actually published next week.

Monday, July 15, 2019

HR 3710 Introduced – Cybersecurity Vulnerabilities


Last week Rep. Jackson-Lee (D,TX) introduced HR 3710, the Cybersecurity Vulnerability Remediation Act. The bill would amend 6 USC 659 to allow the National Cybersecurity and Communications Integration Center (NCCIC) to “identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities” {new §659(n)}.

Changes to Section 659


Section 2 of the bill first adds a definition of ‘cybersecurity vulnerability’ taken from ‘security vulnerability; in 6 USC 1501. It then goes on to modify the functions of the NCCIC in §659(c). The revisions would make that paragraph read:

(c) Functions
The cybersecurity functions of the Center [NCCIC] shall include-

•••

(5)(A) conducting integration and analysis, including cross-sector integration and analysis, of cyber threat indicators, defensive measures, cybersecurity risks, and incidents; and

(B) sharing mitigation protocols to counter cybersecurity vulnerabilities pursuant to subsection (n); and

(C) (B) sharing the analysis conducted under subparagraph (A) and mitigation protocols to counter cybersecurity vulnerabilities in accordance with subparagraph (B) with Federal and non-Federal entities;

•••

(9) sharing cyber threat indicators, defensive measures, mitigation protocols to counter cybersecurity vulnerabilities and other information related to cybersecurity risks and incidents with Federal and non-Federal entities, including across sectors of critical infrastructure and with State and major urban area fusion centers, as appropriate;

Finally, it would add a new paragraph (n):

(n) PROTOCOLS TO COUNTER CYBERSECURITY VULNERABILITIES.—The Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.

Vulnerability Disclosure


Section 3 of the bill would require a report to Congress on how the Cybersecurity and Infrastructure Security Agency (CISA) on how the Agency carries out its vulnerability disclosure responsibilities described in §659(m). That report would include activities undertaken to “to disseminate actionable protocols to mitigate cybersecurity vulnerabilities” {§3(a)} outlined in this bill. That unclassified report would include:

A description of the policies and procedures relating to the coordination of vulnerability disclosures.
A description of the levels of activity in furtherance of such subsections (m) and (n) of §659;
Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in §659) between the Department and industry and other stakeholders.
Any available information on the degree to which such information was acted upon by industry and other stakeholders; and
A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures.

Vulnerability Competition


Section 4 of the bill would allow CISA to “establish an incentive-based program that allows industry, individuals, academia, and others to compete in providing remediation solutions for cybersecurity vulnerabilities”. No funding is provided.

Moving Forward


As I mentioned in an earlier post, this bill will be marked up by the House Homeland Security Committee tomorrow. I do not expect any amendments will be offered and the bill will almost certainly receive bipartisan support. I expect that the bill will be considered by the full House under the suspension of the rules process; limited debate and no floor amendments. It is very likely to pass with strong bipartisan support.

Commentary


The final phrase in §659(n) is very interesting; “including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.” This clearly recognizes that software (and of course, operating systems) is (are) quite frequently used well after the vendor stops providing support and that this significantly increases the risk associated with that continued use. And, I would assume that the ‘competition’ outlined in §4 is primarily aimed at these out-of-support systems.

There is a significant problem with this approach. While the vendors have stopped support for these systems, I do not think that most would surrender their copywrite rights or outright ownership of the ‘non-supported’ systems. This means that it would be a violation of any of a number of Federal (and probably international) laws to modify the software, firmware or operating system to mitigate any vulnerabilities found after the close of support on the product without the specific authorization of the vendor. These issues will have to be resolved by Congress.

Committee Hearings – Week of 7-14-19


With both the House and Senate in Washington and looking towards their extended summer recess, there are a number of interesting hearings on the schedule for this week. In addition to the House Rules Committee hearing on HR 3494 there will be two markup hearings addressing cybersecurity bills and two other hearings that may address cybersecurity issues.

Cybersecurity Markups


On Tuesday the Senate Energy and Natural Resources Committee will conduct a markup hearing on 23 bills. Bills of interest here include:

S 174, a bill to provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. (King/Risch); and
S 715, a bill to improve the productivity and energy efficiency of the manufacturing sector by directing the Secretary of Energy, in coordination with the National Academies and other appropriate Federal agencies, to develop a national smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs, and for other purposes. (Shaheen)

On Tuesday the House Homeland Security Committee will conduct a markup hearing on 18 bills. Bills of interest here include:

HR 3318, (Mr. Joyce) The “Emerging Transportation Security Threats Act of 2019”;
HR 3699, (Mr. Cleaver) The “Pipeline Security Act” (not yet reviewed here);
HR 3710, (Ms. Jackson Lee) The “Cybersecurity Vulnerability Remediation Act” (not yet reviewed here).

Both of these hearings are going to be dealing with a large number of bills. I do not expect much in the way of amendments and very little discussion.

Cybersecurity (?) Hearings


On Wednesday the Energy Subcommittee of the House Energy and Commerce Committee will be holding a hearing on “The Future of Electricity Delivery: Modernizing and Securing Our Nation’s Electricity Grid”. The witness list includes:

Karen Evans, DOE;
Juan Torres, National Renewable Energy Laboratory;
Kelly Speakes-Backman, Energy Storage Association; and
Katherine Hamilton, Advanced Energy Management Alliance

This is almost certainly going to focus on energy supply security, not cybersecurity, but Evans is the head of Office of Cybersecurity, Energy Security, and Emergency Response (CESER), so there will likely be some questions about grid cybersecurity.

On Thursday the House Oversight and Reform Committee will hold a hearing with Kevin K. McAleenan. There is no official indication of the topics to be discussed, but I suspect that it will focus on ‘border security issues.’ There is a slight chance that cybersecurity questions will be addressed to the Acting Secretary.

Friday, July 12, 2019

Bills Introduced – 07-11-19


Yesterday with both the House and Senate in session there were 64 bills introduced. Four of those bills may see additional coverage in this blog:

HR 3699 To codify the Transportation Security Administration's responsibility relating to securing pipelines against cybersecurity threats, acts of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of pipelines, and for other purposes. Rep. Cleaver, Emanuel [D-MO-5]

HR 3710 To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 3714 To amend title 18, United States Code, to reauthorize and expand the National Threat Assessment Center of the Department of Homeland Security. Rep. Deutch, Theodore E. [D-FL-22]

S 2095 A bill to provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threat to, the electric grid, and for other purposes. Sen. Gardner, Cory [R-CO]

I will be watching HR 3710 and S 2095 for specific language referring to industrial control system security issues. For HR 3714 I will be watching for general cybersecurity language while hoping for ICS mentions.

Wednesday, October 21, 2015

HR 3710 Introduced – Methyl Bromide

Earlier this month Rep. LaMalfa (R,CA) introduced HR 3710, the Safe Agriculture Production Act of 2015. The bill would allow State, local and tribal officials to authorize the use of methyl bromide as a fumigant to respond to an emergency event without regard to EPA restrictions on the use of methyl bromide. The bill would completely rewrite the language of 7 USC 7719.

Authorization to Use Methyl Bromide

The new paragraph (a) in the bill would allow an undefined State, local or tribal authority to authorize the use of methyl bromide (subject to objection by the Secretary of Agriculture) “the use of methyl bromide for a qualified use if the authority determines the use is required to respond to an emergency event”. The authorizing authority would have 5 days to notify the Secretary and the Secretary would then have 5 additional days to object to the use.

Paragraph (h)(1) provides the definition of an ‘emergency event’ as a situation:

• That occurs at a location on which a plant or commodity is grown or produced or a facility providing for the storage of, or other services with respect to, a plant or commodity;
• For which the lack of availability of methyl bromide for a particular use would result in significant economic loss to the owner, lessee, or operator of such a location or facility or the owner, grower, or purchaser of such a plant or commodity; and
• That, in light of the specific agricultural, meteorological, or other conditions presented, requires the use of methyl bromide to control a pest or disease in such location or fa-cility because there are no technically or economically feasible alternatives to methyl bromide easily accessible by the owner, lessee, or operator at the time and location of the event.

The bill specifically allows the use of methyl bromide for the ‘emergency event’ “regardless of whether the intended use is registered and included in the label approved for the product by the Administrator of the Environmental Protection Agency under such Act” {revised §7719(d)}. Under the authority of this new language, such ‘emergency event’ authorization “shall be deemed an authorized production, distribution, sale, shipment, application, or use of such product under the Federal Insecticide, Fungicide, and Rodenticide Act”.

Limitations on the Use of Methyl Bromide

The only limitations on the use of methyl bromide beyond the definition of an ‘emergency event’ are that a maximum of 20 metric tons per event can be used at a specific location {revised §7719(e)(1)}, and no more than 150,000 metric tons can be used in the United States in a given year {revised §7719(e)(2)}. That second figure was based upon the critical use exception (CUE) amount set for 2011 by the EPA under the Montreal Protocol on Substances that Deplete the Ozone Layer and 40 CFR Part 82. For comparison the CUE recently set for 2016 is less than 1% of that amount (141 MT).

In order to ensure that there could be enough methyl bromide available for ‘emergency event’ use that is not covered by the current CUE authorization the bill would exempt methyl bromide from the current CUE limitations by stating:

Notwithstanding any other provision of law [emphasis added], it shall not be unlawful for any person or entity to produce or import methyl bromide, or otherwise supply methyl bromide from inventories (produced or imported pursuant to the Clean Air Act for other purposes) in response to an emergency event in accordance with subsection (a).” {revised §7719(f)}

Moving Forward

LeMalfa and five of his cosponsors are members of the House Agriculture Committee to which this bill has been referred. The sole Democratic cosponsor, Rep. Costa (D,CA) is the Ranking Member of the Livestock and Foreign Agriculture Subcommittee. There may be enough political pull to get this bill considered by the Committee.

There will be internal political issues with getting this bill to the floor of the House. The EPA’s regulation of methyl bromide was not specifically addressed in the bill, so it was not referred to the Energy and Commerce Committee. I do suspect, however, that that Committee may have objections to this bill moving forward because they were not asked to review it. It will be interesting to see if Ag Chairman Conway (R,TX) will get behind this bill to move it forward.

The environmental lobby will definitely work hard against this bill because methyl bromide is a chemical known to have effects on the ozone layer. That lobby would not be able to stop the House from passing the bill if it gets to the floor, but they would certainly be able to convince Senate Democrats from allowing the bill to be considered on the floor of the Senate.

The only way that this bill has any chance of getting through the Senate is if it were included in either the agriculture spending or authorization bills.

Commentary

 This is an interesting attempt by the agriculture lobby to get around the phase out of the use of methyl bromide. It is an excellent pre-plant fumigant for ridding the soil of pests that can destroy crops. The number of crops, however, on which the EPA has continued to allow the use of methyl bromide has continued to dwindle until next year it will only be allowed on strawberries and that will cease for 2017. Food and feed importers also have a long history of using methyl bromide to kill off pests in imported products and the EPA has reduced those uses until now the only post planting application with an approved CUE is cured bacon.

The Department of Agriculture’s Animal and Plant Health and Inspection Service (APHIS) service has a long history of approving the use of methyl bromide (herehere and here) for incoming agriculture product fumigation. And they have continued to essentially ignore the EPA’s efforts to eradicate the use of methyl bromide.

The most recent CUE notice, however, made it clear that after 2016 there will not be large stocks of methyl bromide left in inventory after the pre-plant season is over that can be pulled for uses approved by APHIS. In fact, at the end of 2016 the methyl bromide producers and distributors will be required to destroy any methyl bromide left over from the pre-plant authorization.

The other methyl bromide problem is that the California strawberry growers (and a number of other crop growers across the nation that have already been phased out of methyl bromide use by the EPA) are not in complete agreement with EPA that chloropicrin is going to be an effective replacement for methyl bromide in preparing their fields for planting. While they have lost the argument with the EPA and the Montreal Protocol folks, this bill was almost certainly drawn with the intent of allowing them to go around the EPA restrictions.

The 20 metric ton per location limit in the bill was not aimed at any APHIS importation fumigation use. It was clearly aimed at pre-plant use as was the 150 MT annual use limit. But how do they expect to be able to get around the emergency event restrictions? Actually and quite simply, there is no requirement for an emergency in the ‘emergency event’ definition. All that is really required is for a determination to be made (by the field owner) that “there are no technically or economically feasible alternatives to methyl bromide”.

One other thing that needs to be considered with this bill is the status of methyl bromide vis-à-vis the Chemical Facility Anti-Terrorism Standards (CFATS) program. Methyl bromide was on the original proposed list of DHS chemicals of interest (COI) that trigger the requirement for filing a Top Screen data submission to DHS to determine if a facility was covered by the CFATS program. It was removed in the final rule due to the ‘fact’ that it was being phased out by the EPA. The current EPA plan is to have the national inventory down to less than 2 metric tons by 2017; an amount that is not much more than DHS would consider an actionable amount for a single facility.


Opening methyl bromide use back up to pre-plant activities (which is clearly the unwritten intent of this bill) would force DHS to reconsider their failure to list methyl bromide as a COI. This would very likely cause a number of new facilities and distributors to come under the purview of the CFATS program.

Friday, October 9, 2015

Bills Introduced – 10-08-15

With both the House and Senate in session yesterday (Note: Yesterday was the last day in session for the Senate before the Columbus Day recess next week) there were 53 bills introduced. Of those there was only one that may be of specific interest to readers of this blog.

HR 3710 To amend the Plant Protection Act with respect to authorized uses of methyl bromide, and for other purposes. Rep. LaMalfa, Doug [R-CA-1]

I suspect that this bill would authorize the continued use of methyl bromide as a fumigant for strawberry fields. This use has effectively been phased out under the requirements of the Montreal Protocol to Protect the Ozone Layer, but strawberry growers maintain that there is no other effective fumigant to allow them to continue to economically grow strawberries.


Long time readers will probably fear (grin) that passage of this bill will require me to resume my campaign to have DHS add methyl bromide, a recognized toxic inhalation hazard (TIH) chemical, to the list of DHS chemicals of concern.
 
/* Use this with templates/template-twocol.html */