Showing posts with label HR 4310. Show all posts
Showing posts with label HR 4310. Show all posts

Friday, December 21, 2012

Senate Accepts Conference Report on HR 4310


This afternoon the Senate accepted the Conference Report on HR 4310 by a roll-call vote of 81 to 14. The ‘Nays’ were about equally divided between Republicans and Democrats. The National Defense Authorization Act FY 2013 with its cybersecurity provisions now goes to the President for signature.

House Accepts HR 4310 Conference Report


As expected the House voted yesterday along generally bipartisan lines to agree to the Conference Report on HR 4310, the National Defense Authorization Act FY 2013. The vote was 315 to 107 with 30 Republicans and 77 Democrats voting against the measure.

A unanimous consent agreement was reached in the Senate for consideration of the Conference Report, probably sometime today. There will be one hour of debate and a vote on the measure.

As I noted in an earlier blog post there are a number of cyber related provisions included in the final version of the bill including requirements for defense contractors to report cyber-breaches and provisions for secure development requirements for defense software.

Wednesday, December 19, 2012

Rules Committee to Look at HR 4310 Conference Report


Today the House Rules Committee web site announced a hearing to be held this afternoon to formulate the Rule for the consideration of the Conference Committee Report on HR 4310, the National Defense Authorization Act of FY 2013. The Report includes language for the revised version of HR 4310 that was adopted by the Conference Committee.

Cybersecurity Provisions


Nothing in the final version of the bill directly addresses industrial control system security, but there are a number of cyber provisions in the bill. They include:

§244. Report on cyber and information technology research investments of the Air Force.

§931. Implementation strategy for Joint Information Environment.

§932. Next-generation host-based cyber security system for the Department of Defense.

§933. Improvements in assurance of computer software procured by the Department of Defense.

§934. Competition in connection with Department of Defense tactical data link systems.

§935. Collection and analysis of network flow data.

§936. Competition for large-scale software database and data analysis tools.

§937. Software licenses of the Department of Defense.

§938. Sense of Congress on potential security risks to Department of Defense networks.

§939. Quarterly cyber operations briefings.

§940. Sense of Congress on the United States Cyber Command.

§941. Reports to Department of Defense on penetrations of networks and information systems of certain contractors.

I have covered most of these in some detail in earlier blog posts on the Committee Report on HR 4310, House floor action on the bill, the introduction of S 3254, and the Senate floor action on that bill. Only two of the House provisions made it to the final bill, §244 and §939. There are two provisions that I cannot find in either the House or Senate versions of the bill (§931 and §936), but neither of them deal with cybersecurity so I did not look real hard for the earlier versions.

The three most significant provisions that will almost certainly have an impact on civilian cybersecurity are found in §932, §933, and §941. The host-based cybersecurity systems developed for DOD will almost certainly affect the development of similar systems for non-defense critical infrastructure systems. The software development security protocols should also migrate well to control system development. Finally, the network penetration reporting requirements will almost certainly find their way into any cybersecurity legislation for critical infrastructure protection.

Moving Forward


The rule reported by the Committee will certainly be a closed rule with no floor amendments allowed. There will be a limited debate; probably 40 minutes. And, when this comes to a floor vote on Thursday evening or Friday it will almost certainly pass with a substantially bipartisan vote.

Friday, December 14, 2012

HR 4310, NDA, In Conference


It didn’t take the Senate long to respond to the House action on HR 4310, the National Defense Authorization FY 2013. On Wednesday, the same day the bill was returned without action, the Senate passed two additional amendments to the bill and passed it again. On Thursday the House looked at the bill again, didn’t like the Senate version and decided to go to Conference. Neither action took long, less than one hour total in both houses.

As one would expect with a bill this complicated the Conference Committee is quite large, so it will be interesting to see if they can agree on a compromise version of the bill that can pass in both the Senate and the House in the two plus weeks that we have before the 113th Congress is sworn in on January 3rd. I expect that they will.

For readers of this blog, the real question is what cybersecurity provisions will remain in the bill if/when it does get through the conference process? Only time will tell.

Thursday, December 13, 2012

House Returns Both Versions of NDA to Senate


Yesterday the House passed H. Res 829, a very short measure that returned H 4310 and S 3254 to the Senate without action. Readers of this blog will recall that these two identical bills were passed last week in the Senate and are the National Defense Authorization Act FY 2013.

The two bills were returned because, “in the opinion of this House, contravenes the first clause of the seventh section of the first article of the Constitution of the United States and is an infringement of the privileges of this House” {§1(a)(1)}. This constitutional provision maintains that all “Bills for raising Revenue shall originate in the House of Representatives” {Article 1, Section 7}.

I did not notice a tax provision in the language, but I wasn’t looking for one either. Apparently the Chairman of the House Ways and Means Committee (or more likely the Committee Staff) did, because he was the one responsible for this Resolution. There was no debate on the issue in the House and its full consideration took only 53 seconds.

I thought that it was unusual that the Senate amended HR 4310, substituting the language from the Senate bill as this is typically done with spending bills not authorization bills. That is done to avoid just this type of issue. It appears that in using HR 4310 as the vessel in this case stepped on the toes of the House Ways and Means Chairman as his Committee had no say in that bill.

It will be interesting to see if the Senate takes the matter back up and removes the offending section of the bill or just lets this go until the next session. I kind of expect the latter. If they do that the cybersecurity provisions of the 113th Congress version of this bill will undoubtedly be different.

Monday, December 10, 2012

Congressional Hearings – Week of 12-10-12


I’m a little bit late with this this week, but I have been waiting to see if anything interesting is going to happen on the committee side of things while the leadership tries to work out the tax deal. Even with the wait I have to reach out to a House Rules Committee hearing on a yet to be introduced resolution; oh well the 113th Congress is waiting impatiently in the wings.

The Rules Committee is meeting tomorrow evening to craft a resolution providing “for consideration of motions to suspend the rules”. I suspect that this resolution will deal with the last minute bill that will deal with the ‘fiscal cliff’ and modifications of the House Rules that will allow for the quick up-or-down vote on the bill. What will be interesting is if the wording will allow the leadership to slip anything else into the closing minutes of the 112th Congress like a much talked about FY 2013 Omnibus Spending Bill. I’m not holding my breath.

Tomorrow the House will take up the issue of Going to Conference on HR 4310. This will be an almost pro forma discussion with the only question being what will the conferees be required to ‘insist upon’ in the conference committee? Not that these insistences are really binding, but it will provide a look at what the leadership actually thinks is important to keep in the National Defense Authorization bill.

Oh well, this year and this Congress are fast approaching their final days.

Wednesday, December 5, 2012

Senate Amends and Passes HR 4310 – NDA Goes to Conference


Last night when I reported on the passage of S 3254 I missed one of those interesting parliamentary moves that show up frequently in the Senate. After passage of their version of the National Defense Authorization bill Sen Reid (D,NV) called up HR 4310, the House version that passed back in May. The Senate then amended that bill by substituting the language from S 3254 for the House language. Now instead of S 3254 going to the House for a vote there will be a conference committee formed to resolve the differences in the two bills.

As best as I can tell in a quick scan of things none of the cybersecurity or cyber-warfare provisions in the two bills are the same. There is no telling what will make it into the final bill until we see the version coming out of conference.

Saturday, May 19, 2012

House Passes HR 4310 with Cyber Measures


Yesterday, after two long days of debate including the consideration of over 100 amendments the House passed H4310, the National Defense Authorization Act for Fiscal Year 2013, by a bipartisan vote of 299 to 120. The cyber provisions of the bill that I described in an earlier blog remain in the bill (one with a floor revision). Three cyber-related amendments to the bill were considered during the floor debate; all passed by voice vote.

There is still nothing specifically addressing industrial cybersecurity or control system security, but it does offer a look at the expansion of congressional interest in cyber operations. The interesting thing about the votes on these three cyber-related amendments is that they were considered as part of three separate ‘en bloc’ votes containing 15 or more other amendments. Such groupings are made up of non-controversial amendments because significant opposition to even one of the members of the group could result in all of the amendments being voted down.

Amending Offensive Operations in Cyberspace


In the earlier blog I noted that the bill considered this week amended the current congressional authority to conduct operations in cyberspace to specifically authorize clandestine operations in support of congressionally cleared operations. Rep. Rogers (R,MI) offered an amendment that would clarify that while clandestine operations would be authorized nothing “in this section shall be construed to authorize a covert action” {§954(d)}. While there may be more sophisticated explanations for the difference between ‘clandestine’ and ‘covert’ here it appears to rest upon the type of Congressional authorization required for the action.

Air Force and Cyber Security


Rep. Hanna (R,NY) offered an amendment that would require the Secretary to report on Air Force cyber operations research, science, and technology. Most of this is amendment is focused on military operations in cyberspace, but the last sub-paragraph requires the inclusion of a review of the “potential benefit to the Air Force for collaboration with private industry and the development of cyber security technology clusters” {§245(9)}. While not specific to control system security, any additional research into cybersecurity will probably be beneficial to the ICS  processes.

Interagency Coordination


The final cyber-related amendment was offered by Rep. Thornberry (R,TX) that would require the establishment of an interagency organization that would “coordinate and deconflict full-spectrum military cyber operations for the Federal Government” {§1084(a)}. While this is probably directed at DOD agencies (it does refer to military ‘cyber operations’ after all), this could be expanded to include non-DOD agencies like DHS. Coordination of government cyber operations (coordination of anything, for that matter) is probably a good thing in general.

Moving Forward


Now that it has passed in the House we can expect that the Senate will start with its own version of the bill (which I haven’t seen yet) and then the two will get reconciled in conference. It’s anybody’s guess as to what will survive that process.

Monday, May 14, 2012

HR 4310 Reported in House


As I mentioned in an earlier blog, the House will be considering HR 4310, the National Defense Authorization Act FY 2013. Since I wrote that post the House Armed Services Committee report has been published by the GPO. As we have come to expect there were some mentions of cybersecurity issues in the report. Interestingly the amended version of the bill included in that report contains two new sections referencing cybersecurity issues; none directly referencing control systems, but cybersecurity none-the-less. According to the House Rules Committee web site, this is the version of the bill that will be considered on the floor.

Cybersecurity Mentions


The three mentions of cybersecurity in the report include:

• Cyber Research of Embedded Systems, pg 86;

• Detection of Non-Signature Based Cyber Threats, pg 89;

• The Role of National Guard Cyber Defense Units, pg 201;

There are two sections added addressing cybersecurity issues in the actual bill are found in a new Subtitle E, Cyberspace-related Matters. They are:

• Section 941—Military Activities in Cyberspace; and

• Section 942—Quarterly Cyber Operations Briefings.

Cybersecurity Research


The two research priorities established in this report have definite possibilities for application in the control system security realm. While the report notes that “that the decreasing size and increasing computational power of many microelectronics has helped embed computers into practically every weapons system within the Department” it is becoming increasingly common for the same to be said about any number of industrial devices; and we are just now beginning to see concerns about the security of these computers in the public sector. Military research on securing this category of devices can certainly bear on security of devices in the civilian manufacturing sector.

The Committee notes that they are “concerned that the Department of Defense is not providing sufficient resources to acquire capabilities to detect and protect against cyber threats for which a signature has not yet been developed”. Anyone that follows cybersecurity issues will recognize that the same issue and concern applies to civilian computer systems, including control systems. The most successful attacks use 0-day vulnerabilities and properly executed can exist in the wild for some time before they are discovered. Any techniques that can successfully detect attacks using 0-day vulnerabilities will be valuable across the cybersecurity spectrum.

Cyber Warfare


While not directly related to control system security the addition of §941 to this bill may have certain long term consequences for the control system security community. This section revises the statement of authority for DOD to conduct operations in cyberspace that was included in last year’s DOD Authorization bill (P.L. 112–81). That law affirmed the authority to “conduct offensive operations in cyberspace” {§954}. This revision will expand that to specifically include “the authority to carry out a clandestine operation in cyberspace” {Revised §954(b)} in support of congressionally authorized ‘use of military force’ or to defend against a cyber-attack on an asset of the DOD.

The wording of this amended statement of authority would seem to indicate that Congress would not authorize a Stuxnet-like attack on a country like Iran against which Congress has not authorized the use of force. One would like to think that any nation-state cyber-adversaries would reciprocate (Riiight).

Interestingly this makes no provision for responding to cyber-attacks on any US entity that is not an asset of the DOD. Congress could certainly change this by specifically authorizing the use of force, but lacking that there is no authorization for DOD to act. This is keeping with our philosophy of close civilian control of military activities, but it certainly doesn’t cause many of our potential adversaries to be concerned about retaliation for cyber-attacks.

Moving Forward


Tomorrow afternoon the House Rules Committee will hold the first of two hearings on this bill. The first will be held to establish the debate parameters for consideration and the second will be consideration of which amendments will be included in the floor debate (indicating that this won’t be an open rule). According the HR 4310 page on the Committee web site at least 47 amendments have already been offered (none concerning cybersecurity activities) but the submission closing time won’t come until tomorrow afternoon; lots of time for more amendments.

Sunday, May 13, 2012

Congressional Hearings – Week of 5-14-12


Only three hearings this week that will be of potential interest to the chemical or cybersecurity communities; all of them deal with spending issues.

DOD Authorization Bill


On Tuesday afternoon the House Rules Committee will meet to formulate the rule for the consideration of HR 4310, the National Defense Authorization Act. As I noted in an earlier blog there is no specific cybersecurity language in the original bill, but we might expect some cybersecurity amendments offered on the floor later this week. Additionally, the House Armed Services Committee Report was submitted on Friday, but it has yet to be posted on the GPO web site; I’ll take a look at it when it becomes available and comment on any cybersecurity related issues raised in that in a later post.

DHS Appropriations Bills


Work continues on both the House and Senate versions of the DHS FY 2013 spending bill this week. As I noted last week the CFATS program is facing serious budget cuts and perhaps (remote possibility to be sure) a failure to extend its authorization. The ISCD problems have changed a previously untouchable program to one under the gun.

The full House Appropriations Committee will meet on Wednesday to complete the markup of the House bill. The Appropriations Committee is usually very quick about introducing their bills and filing their reports (usually on the same day) so I expect that we will see the publication of the bill to be considered by the House sometime early next week.

The Homeland Security Subcommittee of the Senate Appropriations Committee will meet for their markup of the Senate version of this bill on Tuesday. It will be interesting to see if the Senate (which still hasn’t held any hearings on the ISCD problems) bill treats the CFATS program as harshly as the House bill appears to be going to do.

Friday, April 6, 2012

HR 4310 Introduced – DOD Authorization Bill

Just before Congress adjourned for their Easter Recess Rep McKeon (R,CA) introduced HR 4310, the National Defense Authorization Act for Fiscal Year 2013 and the GPO actually published the bill yesterday. This is one of those bills that I would expect to watch for cybersecurity provisions because of the DOD responsibilities in that field.

As with the FY 2012 bill we do not see any cybersecurity provisions in the initial iteration of the language of HR 4310. The cybersecurity programs in DOD are relatively small and are easily buried in the large dollar amounts authorized for the Department. We are very likely to see specific cybersecurity provisions added during the markup process and the House Armed Services Committee report on this bill may provide some funding details on larger cybersecurity programs.

In short, this is a bill to be watched.
 
/* Use this with templates/template-twocol.html */