This afternoon the Senate accepted the Conference Report on
HR 4310 by a roll-call
vote of 81 to 14. The ‘Nays’ were about equally divided between Republicans
and Democrats. The National Defense Authorization Act FY 2013 with its cybersecurity
provisions now goes to the President for signature.
Showing posts with label HR 4310. Show all posts
Showing posts with label HR 4310. Show all posts
Friday, December 21, 2012
House Accepts HR 4310 Conference Report
As expected the House voted yesterday along generally
bipartisan lines to agree to the Conference Report on HR 4310, the National
Defense Authorization Act FY 2013. The vote
was 315 to 107 with 30 Republicans and 77 Democrats voting against the
measure.
A unanimous consent agreement was reached in the Senate for
consideration of the Conference Report, probably sometime today. There will be
one hour of debate and a vote on the measure.
As I noted in an earlier
blog post there are a number of cyber related provisions included in the
final version of the bill including requirements for defense contractors to
report cyber-breaches and provisions for secure development requirements for
defense software.
Wednesday, December 19, 2012
Rules Committee to Look at HR 4310 Conference Report
Today the House Rules Committee web site announced a hearing
to be held this afternoon to formulate the Rule for the consideration of the
Conference Committee Report on HR 4310, the National Defense Authorization
Act of FY 2013. The Report includes language for the revised version of HR 4310
that was adopted by the Conference Committee.
Cybersecurity Provisions
Nothing in the final version of the bill directly addresses
industrial control system security, but there are a number of cyber provisions
in the bill. They include:
§244. Report on cyber and
information technology research investments of the Air Force.
§931. Implementation strategy for
Joint Information Environment.
§932. Next-generation host-based
cyber security system for the Department of Defense.
§933. Improvements in assurance of
computer software procured by the Department of Defense.
§934. Competition in connection
with Department of Defense tactical data link systems.
§935. Collection and analysis of
network flow data.
§936. Competition for large-scale
software database and data analysis tools.
§937. Software licenses of the
Department of Defense.
§938. Sense of Congress on
potential security risks to Department of Defense networks.
§939. Quarterly cyber operations
briefings.
§940. Sense of Congress on the
United States Cyber Command.
§941. Reports to Department of
Defense on penetrations of networks and information systems of certain
contractors.
I have covered most of these in some detail in earlier blog
posts on the Committee
Report on HR 4310, House
floor action on the bill, the
introduction of S 3254, and
the Senate floor action on that bill. Only two of the House provisions made
it to the final bill, §244 and §939. There are two provisions that I cannot
find in either the House or Senate versions of the bill (§931 and §936), but
neither of them deal with cybersecurity so I did not look real hard for the earlier
versions.
The three most significant provisions that will almost
certainly have an impact on civilian cybersecurity are found in §932, §933, and
§941. The host-based cybersecurity systems developed for DOD will almost
certainly affect the development of similar systems for non-defense critical
infrastructure systems. The software development security protocols should also
migrate well to control system development. Finally, the network penetration
reporting requirements will almost certainly find their way into any
cybersecurity legislation for critical infrastructure protection.
Moving Forward
The rule reported by the Committee will certainly be a
closed rule with no floor amendments allowed. There will be a limited debate;
probably 40 minutes. And, when this comes to a floor vote on Thursday evening
or Friday it will almost certainly pass with a substantially bipartisan vote.
Friday, December 14, 2012
HR 4310, NDA, In Conference
It didn’t take the Senate long to respond to the House
action on HR 4310, the National Defense Authorization FY 2013. On
Wednesday, the same day the bill was returned without action, the
Senate passed two additional amendments to the bill and passed it again. On
Thursday the House looked
at the bill again, didn’t like the Senate version and decided to go to
Conference. Neither action took long, less than one hour total in both houses.
As one would expect with a bill this complicated the
Conference Committee is quite large, so it will be interesting to see if they
can agree on a compromise version of the bill that can pass in both the Senate
and the House in the two plus weeks that we have before the 113th
Congress is sworn in on January 3rd. I expect that they will.
For readers of this blog, the real question is what cybersecurity provisions will remain in the bill if/when it does get through the conference process? Only time will tell.
Thursday, December 13, 2012
House Returns Both Versions of NDA to Senate
Yesterday the House passed H.
Res 829, a very short measure that returned H 4310 and S 3254 to the Senate
without action. Readers of this blog will recall that these two identical bills
were passed
last week in the Senate and are the National Defense Authorization Act FY
2013.
The two bills were returned because, “in the opinion of this
House, contravenes the first clause of the seventh section of the first article
of the Constitution of the United States and is an infringement of the
privileges of this House” {§1(a)(1)}. This constitutional
provision maintains that all “Bills for raising Revenue shall originate in
the House of Representatives” {Article 1, Section 7}.
I did not notice a tax provision in the language, but I wasn’t
looking for one either. Apparently the Chairman of the House Ways and Means
Committee (or more likely the Committee Staff) did, because he was the one
responsible for this Resolution. There was no debate on the issue in the House
and its full consideration took only 53 seconds.
I thought that it was unusual that the Senate amended HR
4310, substituting the language from the Senate bill as this is typically done
with spending bills not authorization bills. That is done to avoid just this
type of issue. It appears that in using HR 4310 as the vessel in this case
stepped on the toes of the House Ways and Means Chairman as his Committee had
no say in that bill.
It will be interesting to see if the Senate takes the matter
back up and removes the offending section of the bill or just lets this go
until the next session. I kind of expect the latter. If they do that the cybersecurity
provisions of the 113th Congress version of this bill will undoubtedly
be different.
Monday, December 10, 2012
Congressional Hearings – Week of 12-10-12
I’m a little bit late with this this week, but I have been
waiting to see if anything interesting is going to happen on the committee side
of things while the leadership tries to work out the tax deal. Even with the
wait I have to reach out to a House Rules Committee hearing on a yet to be
introduced resolution; oh well the 113th Congress is waiting
impatiently in the wings.
The Rules Committee is meeting tomorrow evening to craft a
resolution providing “for consideration of motions to suspend the rules”. I
suspect that this resolution will deal with the last minute bill that will deal
with the ‘fiscal cliff’ and modifications of the House Rules that will allow
for the quick up-or-down vote on the bill. What will be interesting is if the
wording will allow the leadership to slip anything else into the closing
minutes of the 112th Congress like a much talked about FY 2013
Omnibus Spending Bill. I’m not holding my breath.
Tomorrow the House will take up the issue of Going to Conference
on HR 4310. This will be an almost pro forma discussion with the only question
being what will the conferees be required to ‘insist upon’ in the conference
committee? Not that these insistences are really binding, but it will provide a
look at what the leadership actually thinks is important to keep in the National
Defense Authorization bill.
Oh well, this year and this Congress are fast approaching
their final days.
Wednesday, December 5, 2012
Senate Amends and Passes HR 4310 – NDA Goes to Conference
Last night when I
reported on the passage of S 3254 I missed one of those interesting parliamentary
moves that show up frequently in the Senate. After passage of their version of
the National Defense Authorization bill Sen Reid (D,NV) called up HR
4310, the House version that passed back in May. The Senate then amended
that bill by substituting the language from S 3254 for the House language. Now
instead of S 3254 going to the House for a vote there will be a conference
committee formed to resolve the differences in the two bills.
As best as I can tell in a quick scan of things none of the
cybersecurity or cyber-warfare provisions in the two bills are the same. There
is no telling what will make it into the final bill until we see the version
coming out of conference.
Saturday, May 19, 2012
House Passes HR 4310 with Cyber Measures
Yesterday, after two long days of debate including the
consideration of over 100 amendments the House passed H4310, the National
Defense Authorization Act for Fiscal Year 2013, by a bipartisan vote of 299 to
120. The cyber provisions of the bill that I described in an earlier
blog remain in the bill (one with a floor revision). Three cyber-related
amendments to the bill were considered during the floor debate; all passed by
voice vote.
There is still nothing specifically addressing industrial
cybersecurity or control system security, but it does offer a look at the
expansion of congressional interest in cyber operations. The interesting thing
about the votes on these three cyber-related amendments is that they were
considered as part of three separate ‘en bloc’ votes containing 15 or more
other amendments. Such groupings are made up of non-controversial amendments
because significant opposition to even one of the members of the group could
result in all of the amendments being voted down.
Amending Offensive Operations in Cyberspace
In the earlier blog I noted that the bill considered this
week amended the current congressional authority to conduct operations in
cyberspace to specifically authorize clandestine operations in support of
congressionally cleared operations. Rep. Rogers (R,MI) offered an
amendment that would clarify that while clandestine operations would be
authorized nothing “in this section shall be construed to authorize a covert
action” {§954(d)}. While there may be more sophisticated explanations for the
difference between ‘clandestine’ and ‘covert’ here it appears to rest upon the
type of Congressional authorization required for the action.
Air Force and Cyber Security
Rep. Hanna (R,NY) offered
an amendment that would require the Secretary to report on Air Force cyber
operations research, science, and technology. Most of this is amendment is
focused on military operations in cyberspace, but the last sub-paragraph
requires the inclusion of a review of the “potential benefit to the Air Force
for collaboration with private industry and the development of cyber security
technology clusters” {§245(9)}. While not specific to control system security,
any additional research into cybersecurity will probably be beneficial to the
ICS processes.
Interagency Coordination
The final cyber-related amendment was offered by Rep.
Thornberry (R,TX) that would require the establishment of an interagency
organization that would “coordinate and deconflict full-spectrum military cyber
operations for the Federal Government” {§1084(a)}. While this is probably
directed at DOD agencies (it does refer to military ‘cyber operations’ after
all), this could be expanded to include non-DOD agencies like DHS. Coordination
of government cyber operations (coordination of anything, for that matter) is
probably a good thing in general.
Moving Forward
Now that it has passed in the House we can expect that the
Senate will start with its own version of the bill (which I haven’t seen yet)
and then the two will get reconciled in conference. It’s anybody’s guess as to
what will survive that process.
Monday, May 14, 2012
HR 4310 Reported in House
As I mentioned in an earlier
blog, the House will be considering HR 4310, the National Defense
Authorization Act FY 2013. Since I wrote that post the House Armed Services
Committee report has been published by the GPO. As we have come to expect there
were some mentions of cybersecurity issues in the report. Interestingly the
amended version of the bill included in that report contains two new sections
referencing cybersecurity issues; none directly referencing control systems,
but cybersecurity none-the-less. According to the House Rules Committee web
site, this is the version of the bill that will be considered on the floor.
Cybersecurity Mentions
The three mentions of cybersecurity in the report include:
• Cyber Research of Embedded
Systems, pg 86;
• Detection of Non-Signature Based
Cyber Threats, pg 89;
• The Role of National Guard Cyber
Defense Units, pg 201;
There are two sections added addressing cybersecurity issues
in the actual bill are found in a new Subtitle E, Cyberspace-related Matters.
They are:
• Section 941—Military Activities
in Cyberspace; and
• Section 942—Quarterly Cyber
Operations Briefings.
Cybersecurity Research
The two research priorities established in this report have
definite possibilities for application in the control system security realm.
While the report notes that “that the decreasing size and increasing
computational power of many microelectronics has helped embed computers into
practically every weapons system within the Department” it is becoming
increasingly common for the same to be said about any number of industrial
devices; and we are just now beginning to see concerns about the security of
these computers in the public sector. Military research on securing this
category of devices can certainly bear on security of devices in the civilian
manufacturing sector.
The Committee notes that they are “concerned that the
Department of Defense is not providing sufficient resources to acquire
capabilities to detect and protect against cyber threats for which a signature
has not yet been developed”. Anyone that follows cybersecurity issues will recognize
that the same issue and concern applies to civilian computer systems, including
control systems. The most successful attacks use 0-day vulnerabilities and
properly executed can exist in the wild for some time before they are
discovered. Any techniques that can successfully detect attacks using 0-day
vulnerabilities will be valuable across the cybersecurity spectrum.
Cyber Warfare
While not directly related to control system security the
addition of §941 to this bill may have certain long term consequences for the
control system security community. This section revises the statement of
authority for DOD to conduct operations in cyberspace that was included in last
year’s DOD Authorization bill (P.L.
112–81). That law affirmed the authority to “conduct offensive operations
in cyberspace” {§954}. This revision will expand that to specifically include “the
authority to carry out a clandestine operation in cyberspace” {Revised §954(b)}
in support of congressionally authorized ‘use of military force’ or to defend
against a cyber-attack on an asset of the DOD.
The wording of this amended statement of authority would
seem to indicate that Congress would not authorize a Stuxnet-like attack on a
country like Iran against which Congress has not authorized the use of force.
One would like to think that any nation-state cyber-adversaries would
reciprocate (Riiight).
Interestingly this makes no provision for responding to
cyber-attacks on any US entity that is not an asset of the DOD. Congress could
certainly change this by specifically authorizing the use of force, but lacking
that there is no authorization for DOD to act. This is keeping with our
philosophy of close civilian control of military activities, but it certainly
doesn’t cause many of our potential adversaries to be concerned about
retaliation for cyber-attacks.
Moving Forward
Tomorrow afternoon the House Rules Committee will hold the
first of two hearings on this bill. The first will be held to establish the
debate parameters for consideration and the second will be consideration of
which amendments will be included in the floor debate (indicating that this won’t
be an open rule). According the HR
4310 page on the Committee web site at least 47 amendments have already
been offered (none concerning cybersecurity activities) but the submission
closing time won’t come until tomorrow afternoon; lots of time for more amendments.
Sunday, May 13, 2012
Congressional Hearings – Week of 5-14-12
Only three hearings this week that will be of potential
interest to the chemical or cybersecurity communities; all of them deal with
spending issues.
DOD Authorization Bill
On Tuesday afternoon the House
Rules Committee will meet to formulate the rule for the consideration of HR
4310, the National Defense
Authorization Act. As I noted in an earlier
blog there is no specific cybersecurity language in the original bill, but
we might expect some cybersecurity amendments offered on the floor later this week.
Additionally, the House Armed Services Committee Report was submitted on
Friday, but it has yet to be posted on the GPO web site; I’ll take a look at it
when it becomes available and comment on any cybersecurity related issues raised
in that in a later post.
DHS Appropriations Bills
Work continues on both the House and Senate versions of the
DHS FY 2013 spending bill this week. As I noted
last week the CFATS program is facing serious budget cuts and perhaps
(remote possibility to be sure) a failure to extend its authorization. The ISCD
problems have changed a previously untouchable program to one under the
gun.
The full House Appropriations Committee will
meet on Wednesday to complete the markup of the House bill. The
Appropriations Committee is usually very quick about introducing their bills
and filing their reports (usually on the same day) so I expect that we will see
the publication of the bill to be considered by the House sometime early next
week.
The Homeland Security Subcommittee of the Senate
Appropriations Committee will
meet for their markup of the Senate version of this bill on Tuesday. It
will be interesting to see if the Senate (which still hasn’t held any hearings
on the ISCD problems) bill treats the CFATS program as harshly as the House
bill appears to be going to do.
Friday, April 6, 2012
HR 4310 Introduced – DOD Authorization Bill
Just before Congress adjourned for their Easter Recess Rep McKeon (R,CA) introduced HR 4310, the National Defense Authorization Act for Fiscal Year 2013 and the GPO actually published the bill yesterday. This is one of those bills that I would expect to watch for cybersecurity provisions because of the DOD responsibilities in that field.
As with the FY 2012 bill we do not see any cybersecurity provisions in the initial iteration of the language of HR 4310. The cybersecurity programs in DOD are relatively small and are easily buried in the large dollar amounts authorized for the Department. We are very likely to see specific cybersecurity provisions added during the markup process and the House Armed Services Committee report on this bill may provide some funding details on larger cybersecurity programs.
In short, this is a bill to be watched.
Subscribe to:
Posts (Atom)