Yesterday the House passed HR
3710, the Cybersecurity Vulnerability Remediation Act, by a voice
vote. While there was 12 minutes of
debate on the bill, no one spoke against the measure. The bill now goes to
the Senate where, if it is taken up, it will probably be considered under their
unanimous consent process. No further amendments are expected to this legislation.
Showing posts with label HR 3710. Show all posts
Showing posts with label HR 3710. Show all posts
Friday, September 27, 2019
Monday, September 23, 2019
HR 3710 Reported in House – Cybersecurity Vulnerabilities
Last month the House Homeland Security Committee published their
report on HR
3710, the Cybersecurity Vulnerability Remediation Act. The Committee held
their markup
hearing back in July and ordered the bill reported without amendment. The
bill is currently
scheduled for consideration under the House suspension of the rules process
on Wednesday. There will be limited floor debate, no amendments may be offered
from the floor and a supermajority is required for passage.
Commentary
The Committee did not deal with the copywrite issue or
software ownership issue that I mentioned in my blog post on the introduction of
the bill. This means that any mitigation measures that the Cybersecurity and
Infrastructure Security Agency publishes as a result of this bill will have to
be limited to the generic measures that CISA already includes in the control
system security advisories published by NCCIC-ICS. CISA is not going to be able
to publish any true ‘hacks’ of the affected software or firmware because of
these issues and the bill would do nothing to provide liability protection for owners
or users that would use such ‘hacks’ even if reported by CISA.
Making changes to the software, owned in most cases by the
vendor not the facility in which the software operates, could be held to be a
violation of 18
USC 1030(a)(5)(A) for CISA or any researcher providing a software ‘hack’ to
CISA or a violation of 18 USC 1030(a)(5)(C) for facility owners that employed
such a software hack to their systems.
So again, we have Congress taking action to solve a
cybersecurity action that is really no action at all. There is a potential (but
very unlikely) way for the House to correct this bill, even under the
suspension of the rules process. Under a motion to reconsider after passage,
the bill could be sent back to the Homeland Security Committee with direction to
offer an amendment. That amendment would read:
On page 4, line 21; insert “(a)”
before “The director”;
On page 5, line 2; delete the period
after “dor” and insert a colon;
On page 5, after line 2; insert:
“(b) Not withstanding 18 USC
1030(a)(5), the publication by CISA of any mitigation measure that changes the
programing of a computer or device to provide a mitigation measure as described
in (a) is not considered to be a fraud related activity as defined in §1030;
and
“(c) Not withstanding 18 USC
1030(a)(5), the use of a mitigation measure described in (b) by a government
agency or private entity to mitigate a vulnerability defined in (a) is not
considered to be a fraud related activity as defined in §1030.”
On page 6, line 15; insert “(a)”
before “The Under”;
On page 6, line 23; delete the
period at the end and insert “; and”
On page 6, after line 23;
insert:
“(b) Not withstanding 18 USC 1030(a)(5),
the submission to CISA of suggested changes to the affected software to mitigate
an identified vulnerability as part of the program described in (a) is not
considered to be a fraud related activity as defined in §1030.”
I do not really expect that this would happen, but I can
always be surprised by congresscritters. More likely such changes would have to
be undertake in the Senate Homeland Security Committee if/when they markup HR
3710 after it passes in the House, but before it is considered under the
unanimous consent process in the Senate. Again, I would not really expect that
to happen. It would be too much like actually trying to accomplish something.
Saturday, August 31, 2019
Bills Introduced – 08-30-19
Yesterday with both the House and Senate meeting in proforma
session (almost no one present) there were 15 bills introduced. One of these
bills will receive future consideration in this blog:
HR
4217 To amend the Homeland Security Act of 2002 to develop tools to help
State and local governments establish or improve cybersecurity, and for other
purposes. Rep.
Katko, John [R-NY-24]
This bill would (text has already been published) would
establish three separate cybersecurity grant programs for State and local
governments.
Interesting side note: While Congresscritters are not in
Washington, staffs certainly are. The House Homeland Security Committee filed
six committee reports in yesterday’s session. Two of those (HR
3318 and HR
3710) will likely be addressed here in more detail when the reports are
actually published next week.
Monday, July 15, 2019
HR 3710 Introduced – Cybersecurity Vulnerabilities
Last week Rep. Jackson-Lee (D,TX) introduced HR 3710,
the Cybersecurity Vulnerability Remediation Act. The bill would amend 6
USC 659 to allow the National Cybersecurity and Communications Integration
Center (NCCIC) to “identify, develop, and disseminate actionable protocols to
mitigate cybersecurity vulnerabilities” {new §659(n)}.
Changes to Section 659
Section 2 of the bill first adds a definition of ‘cybersecurity
vulnerability’ taken from ‘security vulnerability; in 6
USC 1501. It then goes on to modify the functions of the NCCIC in §659(c). The revisions
would make that paragraph read:
(c) Functions
The cybersecurity functions of the
Center [NCCIC] shall include-
•••
(5)(A) conducting integration and
analysis, including cross-sector integration and analysis, of cyber threat
indicators, defensive measures, cybersecurity risks, and incidents; and
(B) sharing mitigation protocols to counter cybersecurity
vulnerabilities pursuant to subsection (n); and
(C) (B) sharing the
analysis conducted under subparagraph (A) and mitigation protocols to counter cybersecurity vulnerabilities
in accordance with subparagraph (B) with Federal and non-Federal
entities;
•••
(9) sharing cyber threat
indicators, defensive measures, mitigation protocols to counter cybersecurity vulnerabilities
and other information related to cybersecurity risks and incidents with Federal
and non-Federal entities, including across sectors of critical infrastructure
and with State and major urban area fusion centers, as appropriate;
Finally, it would add a new paragraph (n):
(n) PROTOCOLS TO COUNTER
CYBERSECURITY VULNERABILITIES.—The Director may, as appropriate, identify,
develop, and disseminate actionable protocols to mitigate cybersecurity
vulnerabilities, including in circumstances in which such vulnerabilities exist
because software or hardware is no longer supported by a vendor.
Vulnerability Disclosure
Section 3 of the bill would require a report to Congress on
how the Cybersecurity and Infrastructure Security Agency (CISA) on how the
Agency carries out its vulnerability disclosure responsibilities described in §659(m). That report
would include activities undertaken to “to disseminate actionable protocols to
mitigate cybersecurity vulnerabilities” {§3(a)} outlined in this bill. That unclassified report
would include:
• A description of the policies and procedures
relating to the coordination of vulnerability disclosures.
• A description of the levels of activity in furtherance
of such subsections (m) and (n) of §659;
• Any plans to make further improvements to how
information provided pursuant to such subsections can be shared (as such term
is defined in §659)
between the Department and industry and other stakeholders.
• Any available information on the degree to which
such information was acted upon by industry and other stakeholders; and
• A description of how privacy and civil liberties
are preserved in the collection, retention, use, and sharing of vulnerability
disclosures.
Vulnerability Competition
Section 4 of the bill would allow CISA to “establish an incentive-based
program that allows industry, individuals, academia, and others to compete in
providing remediation solutions for cybersecurity vulnerabilities”. No funding
is provided.
Moving Forward
As I mentioned in an earlier post, this bill will be marked
up by the House Homeland Security Committee tomorrow. I do not expect any amendments
will be offered and the bill will almost certainly receive bipartisan support.
I expect that the bill will be considered by the full House under the suspension
of the rules process; limited debate and no floor amendments. It is very likely
to pass with strong bipartisan support.
Commentary
The final phrase in §659(n)
is very interesting; “including in circumstances in which such vulnerabilities
exist because software or hardware is no longer supported by a vendor.” This
clearly recognizes that software (and of course, operating systems) is (are)
quite frequently used well after the vendor stops providing support and that
this significantly increases the risk associated with that continued use. And,
I would assume that the ‘competition’ outlined in §4 is primarily aimed at these out-of-support
systems.
There is a significant problem with this approach. While the
vendors have stopped support for these systems, I do not think that most would
surrender their copywrite rights or outright ownership of the ‘non-supported’ systems.
This means that it would be a violation of any of a number of Federal (and
probably international) laws to modify the software, firmware or operating
system to mitigate any vulnerabilities found after the close of support on the
product without the specific authorization of the vendor. These issues will
have to be resolved by Congress.
Committee Hearings – Week of 7-14-19
With both the House and Senate in Washington and looking
towards their extended summer recess, there are a number of interesting
hearings on the schedule for this week. In addition to the House Rules
Committee hearing
on HR 3494 there will be two markup hearings addressing cybersecurity bills and
two other hearings that may address cybersecurity issues.
Cybersecurity Markups
On Tuesday the Senate Energy and Natural Resources Committee
will conduct a markup
hearing on 23
bills. Bills of interest here include:
• S
174, a bill to provide for the establishment of a pilot program to identify
security vulnerabilities of certain entities in the energy sector. (King/Risch);
and
• S
715, a bill to improve the productivity and energy efficiency of the
manufacturing sector by directing the Secretary of Energy, in coordination with
the National Academies and other appropriate Federal agencies, to develop a
national smart manufacturing plan and to provide assistance to small- and
medium-sized manufacturers in implementing smart manufacturing programs, and
for other purposes. (Shaheen)
On Tuesday the House Homeland Security Committee will
conduct a markup
hearing on 18 bills. Bills of interest here include:
• HR 3710, (Ms. Jackson Lee) The “Cybersecurity
Vulnerability Remediation Act” (not yet reviewed here).
Both of these hearings are going to be dealing with a large
number of bills. I do not expect much in the way of amendments and very little
discussion.
Cybersecurity (?) Hearings
On Wednesday the Energy Subcommittee of the House Energy and
Commerce Committee will be holding a
hearing on “The Future of Electricity Delivery: Modernizing and Securing
Our Nation’s Electricity Grid”. The witness list includes:
• Karen Evans, DOE;
• Juan Torres, National Renewable Energy Laboratory;
• Kelly Speakes-Backman, Energy Storage Association;
and
• Katherine Hamilton, Advanced Energy Management
Alliance
This is almost certainly going to focus on energy supply
security, not cybersecurity, but Evans is the head of Office of Cybersecurity,
Energy Security, and Emergency Response (CESER), so there will likely be some
questions about grid cybersecurity.
On Thursday the House Oversight and Reform Committee will
hold a
hearing with Kevin K. McAleenan. There is no official indication of the
topics to be discussed, but I suspect that it will focus on ‘border security
issues.’ There is a slight chance that cybersecurity questions will be
addressed to the Acting Secretary.
Friday, July 12, 2019
Bills Introduced – 07-11-19
Yesterday with both the House and Senate in session there
were 64 bills introduced. Four of those bills may see additional coverage in
this blog:
HR
3699 To codify the Transportation Security Administration's responsibility
relating to securing pipelines against cybersecurity threats, acts of
terrorism, and other nefarious acts that jeopardize the physical security or
cybersecurity of pipelines, and for other purposes. Rep.
Cleaver, Emanuel [D-MO-5]
HR
3710 To amend the Homeland Security Act of 2002 to provide for the
remediation of cybersecurity vulnerabilities, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]
HR
3714 To amend title 18, United States Code, to reauthorize and expand the
National Threat Assessment Center of the Department of Homeland Security. Rep.
Deutch, Theodore E. [D-FL-22]
S
2095 A bill to provide for certain programs and developments in the
Department of Energy concerning the cybersecurity and vulnerabilities of, and
physical threat to, the electric grid, and for other purposes. Sen.
Gardner, Cory [R-CO]
I will be watching HR 3710 and S 2095 for specific language referring
to industrial control system security issues. For HR 3714 I will be watching
for general cybersecurity language while hoping for ICS mentions.
Wednesday, October 21, 2015
HR 3710 Introduced – Methyl Bromide
Earlier this month Rep. LaMalfa (R,CA) introduced HR 3710,
the Safe Agriculture Production Act of 2015. The bill would allow State,
local and tribal officials to authorize the use of methyl bromide as a fumigant
to respond to an emergency event without regard to EPA restrictions on the use
of methyl bromide. The bill would completely rewrite the language of 7
USC 7719.
Authorization to Use
Methyl Bromide
The new paragraph (a) in the bill would allow an undefined
State, local or tribal authority to authorize the use of methyl bromide
(subject to objection by the Secretary of Agriculture) “the use of methyl
bromide for a qualified use if the authority determines the use is required to
respond to an emergency event”. The authorizing authority would have 5 days to
notify the Secretary and the Secretary would then have 5 additional days to
object to the use.
Paragraph (h)(1) provides the definition of an ‘emergency
event’ as a situation:
• That occurs at a location on
which a plant or commodity is grown or produced or a facility providing for the
storage of, or other services with respect to, a plant or commodity;
• For which the lack of
availability of methyl bromide for a particular use would result in significant
economic loss to the owner, lessee, or operator of such a location or facility
or the owner, grower, or purchaser of such a plant or commodity; and
• That, in light of the specific agricultural,
meteorological, or other conditions presented, requires the use of methyl
bromide to control a pest or disease in such location or fa-cility because there
are no technically or economically feasible alternatives to methyl bromide
easily accessible by the owner, lessee, or operator at the time and location of
the event.
The bill specifically allows the use of methyl bromide for
the ‘emergency event’ “regardless of whether the intended use is registered and
included in the label approved for the product by the Administrator of the
Environmental Protection Agency under such Act” {revised §7719(d)}. Under the
authority of this new language, such ‘emergency event’ authorization “shall be
deemed an authorized production, distribution, sale, shipment, application, or
use of such product under the Federal Insecticide, Fungicide, and Rodenticide
Act”.
Limitations on the
Use of Methyl Bromide
The only limitations on the use of methyl bromide beyond the
definition of an ‘emergency event’ are that a maximum of 20 metric tons per
event can be used at a specific location {revised §7719(e)(1)}, and no more than 150,000 metric tons
can be used in the United States in a given year {revised §7719(e)(2)}. That
second figure was based upon the critical use exception (CUE) amount set for
2011 by the EPA under the Montreal Protocol on Substances that Deplete the
Ozone Layer and 40
CFR Part 82. For comparison the CUE
recently set for 2016 is less than 1% of that amount (141 MT).
In order to ensure that there could be enough methyl bromide
available for ‘emergency event’ use that is not covered by the current CUE
authorization the bill would exempt methyl bromide from the current CUE
limitations by stating:
“Notwithstanding any other provision
of law [emphasis added], it shall not be unlawful for any person or
entity to produce or import methyl bromide, or otherwise supply methyl bromide
from inventories (produced or imported pursuant to the Clean Air Act for other
purposes) in response to an emergency event in accordance with subsection (a).”
{revised §7719(f)}
Moving Forward
LeMalfa and five of his cosponsors are members of the House
Agriculture Committee to which this bill has been referred. The sole Democratic
cosponsor, Rep. Costa (D,CA) is the Ranking Member of the Livestock and Foreign
Agriculture Subcommittee. There may be enough political pull to get this bill
considered by the Committee.
There will be internal political issues with getting this
bill to the floor of the House. The EPA’s regulation of methyl bromide was not
specifically addressed in the bill, so it was not referred to the Energy and
Commerce Committee. I do suspect, however, that that Committee may have
objections to this bill moving forward because they were not asked to review
it. It will be interesting to see if Ag Chairman Conway (R,TX) will get behind
this bill to move it forward.
The environmental lobby will definitely work hard against
this bill because methyl bromide is a chemical known to have effects on the
ozone layer. That lobby would not be able to stop the House from passing the
bill if it gets to the floor, but they would certainly be able to convince
Senate Democrats from allowing the bill to be considered on the floor of the
Senate.
The only way that this bill has any chance of getting
through the Senate is if it were included in either the agriculture spending or
authorization bills.
Commentary
This is an
interesting attempt by the agriculture lobby to get around the phase out of the
use of methyl bromide. It is an excellent pre-plant fumigant for ridding the
soil of pests that can destroy crops. The number of crops, however, on which
the EPA has continued to allow the use of methyl bromide has continued to
dwindle until next year it will only be allowed on strawberries and that will
cease for 2017. Food and feed importers also have a long history of using
methyl bromide to kill off pests in imported products and the EPA has reduced
those uses until now the only post planting application with an approved CUE is
cured bacon.
The Department of Agriculture’s Animal and Plant Health and
Inspection Service (APHIS) service has a long history of approving the use of
methyl bromide (here, here and here)
for incoming agriculture product fumigation. And they have continued to
essentially ignore the EPA’s efforts to eradicate the use of methyl bromide.
The most recent CUE notice, however, made it clear that
after 2016 there will not be large stocks of methyl bromide left in inventory
after the pre-plant season is over that can be pulled for uses approved by
APHIS. In fact, at the end of 2016 the methyl bromide producers and distributors
will be required to destroy any methyl bromide left over from the pre-plant
authorization.
The other methyl bromide problem is that the California
strawberry growers (and a number of other crop growers across the nation that
have already been phased out of methyl bromide use by the EPA) are not in
complete agreement with EPA that chloropicrin is going to be an effective
replacement for methyl bromide in preparing their fields for planting. While
they have lost the argument with the EPA and the Montreal Protocol folks, this
bill was almost certainly drawn with the intent of allowing them to go around
the EPA restrictions.
The 20 metric ton per location limit in the bill was not
aimed at any APHIS importation fumigation use. It was clearly aimed at
pre-plant use as was the 150 MT annual use limit. But how do they expect to be
able to get around the emergency event restrictions? Actually and quite simply,
there is no requirement for an emergency in the ‘emergency event’ definition.
All that is really required is for a determination to be made (by the field
owner) that “there are no technically or economically feasible alternatives to
methyl bromide”.
One other thing that needs to be considered with this bill
is the status of methyl bromide vis-Ã -vis the Chemical Facility Anti-Terrorism
Standards (CFATS) program. Methyl bromide was on the original proposed list of
DHS chemicals of interest (COI) that trigger the requirement for filing a Top
Screen data submission to DHS to determine if a facility was covered by the
CFATS program. It was removed in the final rule due to the ‘fact’ that it was
being phased out by the EPA. The current EPA plan is to have the national
inventory down to less than 2 metric tons by 2017; an amount that is not much
more than DHS would consider an actionable amount for a single facility.
Opening methyl bromide use back up to pre-plant activities (which
is clearly the unwritten intent of this bill) would force DHS to reconsider their
failure to list methyl bromide as a COI. This would very likely cause a number
of new facilities and distributors to come under the purview of the CFATS
program.
Friday, October 9, 2015
Bills Introduced – 10-08-15
With both the House and Senate in session yesterday (Note:
Yesterday was the last day in session for the Senate before the Columbus Day
recess next week) there were 53 bills introduced. Of those there was only one
that may be of specific interest to readers of this blog.
HR
3710 To amend the Plant Protection Act with respect to authorized uses of
methyl bromide, and for other purposes. Rep.
LaMalfa, Doug [R-CA-1]
I suspect that this bill would authorize the continued use
of methyl bromide as a fumigant for strawberry fields. This use has effectively
been phased out under the requirements of the Montreal Protocol to Protect the
Ozone Layer, but strawberry growers maintain that there is no other effective
fumigant to allow them to continue to economically grow strawberries.
Long time readers will probably fear (grin) that passage of
this bill will require me to resume my campaign to have DHS add methyl bromide,
a recognized toxic inhalation hazard (TIH) chemical, to the list of DHS
chemicals of concern.
Subscribe to:
Posts (Atom)