Showing posts with label HR 3834. Show all posts
Showing posts with label HR 3834. Show all posts

Tuesday, November 13, 2012

Cybersecurity Legislation in the Lame Duck Session


Michelle Kincaid has an interesting outlook on cybersecurity legislation potential in the lame duck session in her cybersecurity blog post. While I don’t see anything in particular to disagree with, it is important to remember that political calculations change significantly in a lame duck session, making it much more difficult to successfully predict political outcomes.

While most people focus on legislators that are on their way out, who may (or may not) vote on principle instead of political motives now that they may never face the voters again, there is a new crop of Senators that are now starting into their two year election cycle; many of them will now begin paying more attention to political posturing than principle.

Legislation in the Senate


Most of the cybersecurity legislation attention is being focused on consideration of S3414. Sen. Reid (D,NV) that may bring this back to the floor for consideration this week and there is even a remote chance that it could pass in the Senate. The key stumbling block to its passage will be reaching an agreement with the Republicans on what amendments would be considered before a final vote on the bill. It is unlikely that, even if this bill does get passed in the Senate, that it will pass in the House where there is much more opposition to increasing government regulations.

Overlooked in most discussions of cybersecurity legislation is the fact that there are three bills that have already been passed in the House and are waiting for Senate action. They are

HR 2096, Cybersecurity Enhancement Act of 2012;

HR 3523, Cyber Intelligence Sharing and Protection Act; and

HR 3834, Advancing America's Networking and Information Technology Research and Development Act of 2012

While the CISPA bill is more than a little controversial, the other two bills had strong bipartisan support in the House ( HR 2096 passed 395-10 and HR 3834 passed on a voice vote). While being far from comprehensive bills either of these could probably pass in the Senate if the leadership took the effort to bring them to a vote. These bills may provide Reid with a way of saying that the Senate dealt with cybersecurity legislation in this session.

Legislation in the House


With no Senate passed bills to consider, the House still has one cybersecurity bill that has been reported out of committee that could be considered on the floor with minimal effort; HR 3674, the PRECISE Act of 2012. This bill is actually the closest thing to a House counterpart to S 3414 in that it actually provides VERY limited authority for DHS to regulate cybersecurity in critical infrastructure. This could probably pass a House floor vote without any real problem, but it is too late for this to make it through the Senate as well.

If this bill had been passed in the regular session (and it was put on the house calendar back in July and then ignored) it would have provided a more useful discussion tool for Senate consideration of cybersecurity. It actually would form a pretty good basis for the executive order that is reportedly being worked on by the Administration.

If Rep. Lungren (R, CA) is returned for the 113th Congress (the vote count has still not been certified and is trending against him) then I would expect to see this bill re-introduced in January.

Saturday, April 28, 2012

Cybersecurity Week Votes – Friday


The House closed out their Cybersecurity Week Friday by passing two more cybersecurity bills. Both dealt with research issues and one may actually have a minimal impact on control system security issues. HR 2096, the Cybersecurity Enhancement Act of 2011, passed by a vote of 395-10; certainly a bipartisan vote, especially since all of the ‘Nays’ were Republican. HR 3834, the Advancing America’s Networking and Information Technology Research and Development Act of 2012, passed by a voice vote.

Cyber-Physical Systems


HR 3834 introduces the term ‘cyber-physical systems’ to describe a wide range of control and monitoring systems. These systems are added to the list of research topics addressed in amends the High-Performance Computing Act of 1991. Unfortunately this act does not provide any specific funding for these research priorities so the money has to come out of existing priorities.

Oh well, control systems are now at least considered in a piece of cybersecurity legislation.

Moving Forward


As I mentioned yesterday, neither of these bills is in any way controversial, they don’t cost any real money, so they can be expected to be passed relatively easily in the Senate. They will also allow everyone to point to them as proof that the Congress takes cybersecurity seriously and has actually done something about it.
Having accomplished so much this week both the House and Senate will take a previously scheduled two-week recess.

Sunday, April 22, 2012

Congressional Hearings – Week of 4-23-12


This is going to be an interesting week with Cybersecurity Week finally coming to the House, unfortunately ICS security is not on the agenda. The Lungren bill (HR 3674) is not currently scheduled to be considered, but if the report is filed in time, it may still make it to the floor this week. Two budget hearings round out the offerings that might be of interest to the chemical-security and cyber-security communities.

Cybersecurity Week


The first day of the House week (Tuesday) cyber-week will start off with a hearing before the House Homeland Security Committee’s Subcommittee on Oversight, Investigations and Management entitled; “America is Under Cyber Attack: Why Urgent Action is Needed”. It certainly sounds appropriate if just a tad bit ironic as we have been waiting for congressional action for some time.

Interestingly, this hearing is just two days away and there are still not any witnesses listed on the Committee web site. Dale Peterson took advantage of that fact last week to do an interesting piece on DigitalBond about the types of witnesses he would like to see appear before this panel. I added my two cents worth, but both Dale and I know (and so do most other observers) that we will just see the typical witnesses that we always see and that doesn’t include anyone from the industrial control system trenches.

While the House gets ready on Thursday to start actual consideration of cybersecurity legislation there is one last cyber-threat hearing with an interesting twist. The the Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee will be holding a hearing on the Iranian Cyber Threat to the U.S. Homeland. I must have missed the one about the Russian mafia cyber-threat and the Chinese cyber-threat.

Oh, yes. No witness list for this hearing either.

The main point of Cybersecurity Week is, of course, to pass cybersecurity legislation. Starting on Thursday this week the full House will consider:

H.R. 2096 - Cybersecurity Enhancement Act of 2011, as amended
H.R. 3834
- Advancing America's Networking and Information Technology Research and Development Act of 2012
H.R. 4257
- Federal Information Security Amendments Act of 2012

H.R. 3523 - Cyber Intelligence Sharing and Protection Act, Rules Committee Print

The first three will be considered ‘under suspension of the rules’. This is an abbreviated debate process to be used on bills that the leadership is sure will pass. It takes a 60% vote to pass a bill under this procedure so it isn’t a process taken lightly by the leadership.

The controversial cybersecurity bill, HR 3523, is planned to come to the floor starting Thursday with a probable vote on Friday. This bill will be considered under a rule that will allow for at least some floor amendments. The Rules Committee has not yet set the date and time for the hearing where the rule will be developed but they have set the deadline for submitting amendments for Tuesday afternoon.

Budget Hearings


Two different hearings this week will look at different versions of the FY13 Energy and Water Development Appropriations Bill.  On Tuesday the Senate Appropriations Committee’s Labor, Health and Human Services, and Education, and Related Agencies Subcommittee will be doing their markup of the as of yet unnumbered Senate bill. The House Appropriations Committee is a little further along in the process with their bill; they will be holding a full Committee markup on Wednesday.

Wednesday, February 8, 2012

HR 3834 Adopted by Voice Vote

Yesterday the House Science, Space and Technology Committee adopted an amended version of HR 3834, the Advancing America’s Networking and Information Technology Research and Development Act of 2012, by a voice vote. A voice vote is a sure sign of bipartisan support, or at least lack of significant opposition.

The sole amendment adopted (actually the only one considered) was an editorial housekeeping amendment submitted by Chairman Hall (R,TX). The only thing of significance to this amendment was that this sort of cleaning up of the language of the bill is normally done with an amendment in the form of a substitute. That significance is only of interest to the connoisseurs of congressional procedures.

As I noted on Monday, this bill is a cybersecurity R&D bill of limited significance to the ICS community.

Monday, February 6, 2012

HR 3834 Introduced – Cyber Security Research

Late last month Rep Hall (R,TX), the Chair of the House Science, Space and Technology Committee, introduced HR 3834, the Advancing America’s Networking and Information Technology Research and Development Act of 2012. This bill amends the High-Performance Computing Act of 1991 to authorize activities for support of networking and information technology research.

Cyber-Physical Systems


While the bill spends a great deal of time substituting the words ‘networking and information’ for the term ‘high-performance computing’ there are some changes made to the research priorities outlined in the original act. One of those changes deals with the introduction of a new research topic, cyber-physical systems. That is defined in §2(f)(1) as:

“physical or engineered systems whose networking and information technology functions and physical elements are deeply integrated and are actively connected to the physical world through sensors, actuators, or other means to perform monitoring and control functions”.

I cannot find anywhere in the bill where the term ‘industrial control system’ is used, but this ‘cyber-physical system’ certainly sounds like the definition, in the broadest sense, of an industrial control system.

Sec 4(a)(3) amends Section 101(a)(1) of the High-Performance Computing Act of 1991 (15 U.S.C. 5511) calling for a collaborative research and development effort that provides “for increased understanding of the scientific principles of cyber-physical systems and improve the methods available for the design, development, and operation of cyber-physical systems that are characterized by high reliability, safety, and security”.

Finally §4(b) requires the establishment a temporary university-industry task force “to explore mechanisms for carrying out collaborative research and development activities for cyber-physical systems, including the related technologies required to enable these systems, through a consortium or other appropriate entity with participants from institutions of higher education, Federal laboratories, and industry. The task force would prepare a report to Congress on its findings and then disband.

No Funding


The bill does not provide any specific authorization for funding this collaborative research and development effort. The existing 15 USC 5511 language calls for the President’s budget to allocate funding for the National High-Performance Computing Program (to be renamed by this bill as the Networking and Information Technology Program) from the various agencies that support the Program.

The only hope that the research activities outlined for cyber-physical systems would get some specific future funding would be if a future Congress were to provide that funding after receiving, reviewing and acting on the task force recommendations called for above. So hold your breath and hope for the best.
 
/* Use this with templates/template-twocol.html */