Showing posts with label HR 3875. Show all posts
Showing posts with label HR 3875. Show all posts

Friday, December 11, 2015

House Passes Three Homeland Security Bills

Yesterday the House passed three homeland security related bills under suspension of the rules; all with no significant opposition and little debate.

The three bills were:

HR 3875, Department of Homeland Security CBRNE Defense Act of 2015 – Voice vote
HR 3578, DHS Science and Technology Reform and Improvement Act of 2015 – 416 - 0 
HR 3869, State and Local Cyber Protection Act of 2015 – Voice vote


I do not think that these bills will be considered by the Senate before the year-end recess, but they will likely be taken up under the unanimous consent process early next year.

Thursday, November 5, 2015

Homeland Security Bills Marked Up

Yesterday the House Homeland Security Committee held a markup hearing at which seven bills were approved (some after amendment) by voice votes. Only two of those bills (HR 3875 and HR 3878) may be of specific interest to readers of this blog.

HR 3875 – CBRNE Office

Rep. McCaul (R,TX) offered an amendment in the form of a substitute for this bill. It removed some of the language that I mentioned in my earlier post that made it seem that this bill was primarily a biosecurity bill. It also added new language to the proposed Title XXII of the Homeland Security Act of 2002 that created four Divisions within the proposed CBRNE Office; the Chemical Division, the Biological Division, the Nuclear Division and the Explosive Division.

The revised language still does not include the chemical security folks from the DHS Infrastructure Security Compliance Division (ISCD), but it did add specific language providing for a continuation of the Chemical Defense Program (that I first mentioned here) under the Chemical Division.

An amendment to the revised language was offered by Rep. Thompson (D,MS). It made a number of word changes to clarify certain issues, but there were no modifications to the intent of the bill.

Both amendments were agreed to by voice votes.

HR 3878 – Port Cybersecurity

Rep. Torres (D,CA) offered substitute language for the bill which was essentially a complete re-write of the original language, if not the general intention, of the bill. A new §2 of the bill would require the development and implementation of “a maritime cybersecurity risk assessment model” {§2(1)}. Additionally the section would also require the establishment of guidelines “for voluntary reporting of maritime-related cybersecurity risks and incidents” {§2(4)}.

The new language also removes all specific mention of the Maritime Information Sharing and Analysis Center; substituting more generic language (“at least one information sharing and analysis organization” representing the maritime community). The other information sharing provisions have had minor wording changes.

An amendment to the revised language was offered by Rep. Donovan (R,NY). It would add an additional section to the bill that would amend portions of 46 USC regarding maritime security plans under the Maritime Transportation Security Act. First it would modify §70101(b)(1)(C) to add ‘cybersecurity’ as one of the areas of weakness to be evaluated in facility and vessel vulnerability assessments. Second it would modify §70103(c)(3)(C) to add ‘cybersecurity’ as one of the required provisions of a vessel or facility security plan. Area security plans were not addressed by this amendment.

The Torres language on cybersecurity provisions on area and facility site security plans was revised slightly by the Donovan amendment, but it still only applies those requirements to plans approved after the development of the new cybersecurity risk assessment model required by the bill has been completed. Thus existing security plans would not be required to be changed to reflect the cybersecurity requirements until their next five year renewal.

Both amendments were approved.

Moving Forward

Both of these bills appear to be on Chairman McCaul’s fast track for consideration. It is very likely that these will be considered on the floor of the House before the end of the year. Neither bill has any provisions that will spark any serious opposition so they will both probably be considered under suspension of the Rules.

Commentary

The changes to the CBRNE Office bill that were made yesterday make a lot of sense to me. The establishment of the five offices reflecting the different attack vectors seems like it has the potential to centralize the Departments disparate efforts at reducing the probability of a high-consequence CBRNE attack. It would also place CBRNE on a bureaucratic par with Cybersecurity within the Department.

I still would have preferred to see ISCD added to the Chemical Defense Office, but I suspect that if the Senate does not make that move (a low probability event, I doubt that any amendments will be made to the bill as it will probably be considered under unanimous consent provisions at the end of a daily session) I suspect that this would be one of the changes that would be recommended by the Secretary in his initial report to Congress required by the bill.

The revised language on the port cybersecurity bill are also a substantial step forward. Even before the Donovan amendment the changes that were made bring the language within the current information sharing meme that is wending its way through conference committee. This internal consistency of language is important from a bureaucratic point of view.

For critical infrastructure like ports I would have preferred to see some mandatory level of cybersecurity reporting. Using the general concepts used in the recent NRC cybersecurity reporting rule, this bill should have mandated reporting of cybersecurity events that had a cyber-physical impact (or at least those that affected the handling of hazardous chemicals) and specifically encouraged reporting cybersecurity events that affected safety security, or emergency response.


I was very happy to see the Donovan amendment make the statutory changes necessary to make the changes to vulnerability assessments and security plans. I am not sure, however, if the failure to include maritime area security plans in those changes was deliberate or an oversight. I suspect that it was deliberate and I would tend to agree that requiring cybersecurity security plan coverage at the vessel and facility level is probably more important than trying to deal with it at the area level.

Wednesday, November 4, 2015

HR 3876 Introduced – Autonomous Vehicle Report

On Monday Rep. Meng (D,NY) introduced HR 3876, the Autonomous Vehicle Privacy Protection Act of 2015. The bill would require the GAO to publish a public report on the readiness of the DOT to address autonomous vehicle technology challenges.

The only thing specifically required of the report is that it should address “consumer privacy protections” {§2}.

Moving Forward

Meng is not a member of the House Transportation Committee so she is unlikely to have the pull necessary to have this bill considered in Committee. If this bill were to make it to the floor of the House there is nothing in the very short bill that would draw organized opposition. I expect that it would be considered under suspension of the rules and would pass with bipartisan support.

Commentary


Most of the concern about cybersecurity in Congress is related to the security of personal information, not operations security. This bill reflects that limited level of cybersecurity awareness. I would really think that ensuring that the control system is safe from outside interruption or control should be a higher priority than protecting the limited amount of personal information that can be found in the computer systems in autonomous vehicles.

HR 3875 Introduced – CBRNE Office

On Monday Rep. McCaul (R,TX) introduced HR 3875, the Department of Homeland Security CBRNE Defense Act of 2015. The bill would establish the Chemical, Biological, Radiological, Nuclear, and Explosives Office at the Assistant Secretary level within the Department of Homeland Security via the addition of a new Title XXII to the Homeland Security Act of 2002. The CBRNE office would “coordinate, strengthen, and provide chemical, biological, radiological, nuclear, and explosives (CBRNE) capabilities in support of homeland security” {new §2201(a)}.

The bill would move the following current DHS operations into the new CBRNE Office {new §2202}:

• The Office of Health Affairs;
• Domestic Nuclear Detection Office;
• CBRNE threat awareness and risk assessment activities of the Science and Technology Directorate;
• The CBRNE functions of the Office of Policy and the Office of Operations Coordination; and
• The Office for Bombing Prevention of the National Protection and Programs Directorate

The new Assistant Secretary would be required to conduct periodic “terrorism risk assessments of chemical, biological, radiological, and nuclear threats” {new §2205(a)}. The risk assessments would be shared in both classified form with appropriately cleared Federal, State, local, tribal, and territorial officials and in an unclassified form with “Federal, State, local, tribal, and territorial officials involved in prevention and preparedness for chemical, biological, radiological, and nuclear events” {new §2205(d)(4)}.

The bill would also task the DHS Under Secretary of Intelligence and Analysis to “support homeland security-focused intelligence analysis of terrorist actors, their claims, and their plans to conduct attacks involving chemical, biological, radiological, or nuclear materials or explosives against the United States” {new §2206(a)(1)}. I&A would be required to share the developed information with “share appropriate information regarding such threats to appropriate State, local, tribal, and territorial authorities” {new §2206(a)(5)}.

The bill also contains a number of obligatory reports to Congress. These include a report by the Secretary on the “the organizational structure of the management and execution of the Department of Homeland Security’s chemical, biological, radiological, nuclear, and explosives research and development activities” {§2(c)(1)}. That report would also be required to include “a proposed organizational structure for the management and execution of such chemical, biological, radiological, nuclear, and explosives research and development activities”.

Moving Forward

McCaul is, of course, the Chair of the House Homeland Security Committee, so this bill has a high chance of moving to the floor of the House. In fact, this bill will be one of the seven marked up by the full Committee this afternoon.

This is not much more than an organizational bill, so there will be little or no opposition to the bill in the House (or the Senate for that matter). I would expect to see this bill move to the floor of the House before the end of the year. It will almost certainly be considered under suspension of the rules with limited debate and no floor amendments.

Commentary

This bill continues to reflect the Chairman’s long time preoccupation with biological attacks on the United States. While this is supposed to address the standard panoply of non-conventional terrorist threats subtle language usage and the near complete ignoring of chemical threats show that focus.

For instance, the language on information sharing only address communicating information to one portion of the private sector; the “other national biosecurity and biodefense stakeholders” in §2206(a)(5). There is no mention of the chemical manufacturing community, apparently because no one recognizes a threat of terrorist attack against chemical manufacturing facilities as a mode of WMD attack on the US Homeland.

This ignoring of chemical threats is further evidenced by the failure to include the Infrastructure Security Compliance Division (ISCD), which enforces the current CFATS program and is charged with developing the long awaited Ammonium Nitrate Security Program. These two programs should obviously be part of any organization in DHS responsible CBRNE capabilities in the Department.


One of the big problems that ISCD has is that it has no direct intelligence support of its operations. The security program that it operates for chemical facilities operates in an intelligence vacuum, neither able to process information on potential threats received from the regulated community or share information on potential terrorist threats developed in other agencies. Adding ISCD to an organization like the CBRNE Office could help to alleviate that problem.

Tuesday, November 3, 2015

Bills Introduced – 11-2-15

With only the House in session yesterday (the Senate returned to Washington today) there were 14 bills introduced. Of those five were of possible interest to readers of this blog:

HR 3869 State and Local Cyber Protection Act of 2015. Rep. Hurd, Will [R-TX-23]

HR 3873 International Cyber Policy Oversight Act of 2015. Rep. McCaul, Michael T. [R-TX-10]

HR 3875 Department of Homeland Security CBRNE Defense Act of 2015. Rep. McCaul, Michael T. [R-TX-10]

HR 3876 Autonomous Vehicle Privacy Protection Act of 2015. Rep. Meng, Grace [D-NY-6]

HR 3878 Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2015. Rep. Torres, Norma J. [D-CA-35]

Three of these bills (HR 3869, HR 3875, and HR 3878) are the three to-be-introduced bills that I described in my post yesterday. They, along with four other bills, will be marked up in the House Homeland Security Committee tomorrow.

HR 3869 mainly deals with providing cybersecurity assistance to State and local governments, but it does include training and assistance in responding to cyber incidents.

HR 3873 requires the Secretary of State to develop a strategy to support the President’s 2011 International Strategy for Cyberspace.

HR 3875 requires the establishment of a CBRNE Office in DHS.

HR 3877 requires the GAO to publish a report on DOT’s readiness to address vehicle automation technology.

HR 3878 address cybersecurity requirements for ports.


Interestingly, each of these bills already have official versions of their language available from the GPO. Very unusual since it normally takes up to a week or two for bills to be published. The three bills that will be marked up tomorrow would normally be an exception to that rule, but not the other two.
 
/* Use this with templates/template-twocol.html */