Showing posts with label HR 4915. Show all posts
Showing posts with label HR 4915. Show all posts

Thursday, July 27, 2023

Bills Introduced – 7-26-23

Yesterday, with both the House and Senate in session and preparing to depart for their month-long summer recess, there were 134 bills introduced. Two of those bills will receive additional attention in this blog:

HR 4915 To amend title 10, United States Code, to codify the program of the Office of Small Business Programs of the Department of Defense known as Project Spectrum, and for other purposes. Joyce, David P. [Rep.-R-OH-14] 

S 2499 A bill to extend the authorization of the Chemical Facility Anti-Terrorism Standards Program of the Department of Homeland Security. Peters, Gary C. [Sen.-D-MI] 

I am still waiting to see the Congressional Record for yesterday’s meeting to see if HR 4470 was taken up by the Senate. It could be a while as the Senate did not adjourn until after midnight. If HR 4470 did pass, then the introduction of S 2499 does not make much sense. If it did not pass then S 2499 would be a rewrite of S 2178 that would include language to resurrect the CFATS program which will die today if not reauthorized by Congress.

Funding exists for CFATS through September 30th to keep the staff paid while the program winds down, but authority to take any actions (inspections, approvals, even requiring/accepting Top Screen information) disappeared (will disappear at midnight? I am not sure) if HR 4470 was not passed yesterday. So, a new bill would be required to re-instate the previous authority and provide an extension of the authority through a future date. The chance of S 2178 passing in the Senate and House today or tomorrow are slim (but not impossible) and the current plan is for both bodies to adjourn tomorrow and not return until September 5th for the Senate and September 12th for the House. While those plans are always subject to change, it does not look likely at this time.

Monday, December 16, 2019

HR 4915 Introduced – SBA Cybersecurity Loans


Earlier this year Rep Schneider introduced HR 4915, the Small Business Cybersecurity Enhancement Act. The bill would establish a cybersecurity loan guarantee program in the Small Business Administration (SBA).

Definitions


The bill adds a new §49 to the Small Business Act. A key definition in the new §49(a) is the term ‘cybersecurity technology and services’. It defines the purpose of that term as being limited to computer hardware, software, and related technology that “supports the prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation” {new §49(a)(1)(A)(i)(I)}.

The definition specifically includes {new §49(a)(1)(A)}:

• An insurance product available for purchase by an eligible small business that provides coverage for losses caused by a cyber attack on such business;
• Services related to the installation of computer hardware, software, and related technology described under clause (i); or
• Training on security principles for employees of an eligible small business.

Loan Guarantees


The bill provides for the SBA providing loan guarantees of up to 90% of loans used to {new §49(b)(1)}:
• Acquire cybersecurity technology and services for use in the business operations of the eligible small business; and
• To defray the costs associated with the installation or use of such cybersecurity technology and services.

The maximum amount of any single loan guarantee is $50,000 and the total amount of principal guaranteed by the SBA in a single year is $500 million. The authority provided in this bill to make such loans is limited to a period of just five years while individual loan guarantees may be for a period of up to seven years.

Moving Forward


Scott and one of his cosponsors {Rep Crow (D,CO)} are both members of the House Small Business Committee to which this bill was assigned for consideration. This means that there is a good chance that this bill may be considered in Committee. I see nothing in the language of the bill that would cause any serious opposition. I suspect that it would receive bipartisan support both in Committee and on the floor of the House if it were considered.

Commentary


The key definition in this bill is IT restrictive. It would not allow for loans to be made for cybersecurity protections for operational technology like building maintenance systems or access control and would certainly not cover industrial control system security measures. I am not sure that that was the intention, but it certainly results from the definition.

Changing the definition would be much easier if someone had made the changes that I had proposed to 6 USC 659. If those changes had been made, we could reference them in changing the definition of ‘cybersecurity technology and services’ in this bill. With that not being done we will have to add a couple of definitions to this bill:

(4) the term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes, including manufacturing, transportation, access control, and facility environmental controls;

(5) the term "information system" has the meaning given that term in section 3502(8) of title 44;

(6) the term "cybersecurity risk"-

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement;
(4) the term "cybersecurity incident" means an occurrence that actually or imminently jeopardizes, without lawful authority:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;

Then I would go back and modify the portion of the existing language in §49(a)(a)(A)(i):

(i) computer hardware, software, and related technology that—

(I) supports the prevention of damage to, protection of, and restoration of computers, electronic communications systems, electronic communications services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation reduces the cybersecurity risk to an information system or control system; or

(II) provides for the recovery from, or mitigates the damage from, a cybersecurity incident; and

(II III) is purchased by an eligible small business;

• • • [Renumbering as appropriate]

Thursday, October 31, 2019

Bills Introduced – 10-30-19


Yesterday with both the House and Senate in session there were 54 bills introduced. One of those bills may receive future consideration in this blog:

HR 4915 To amend the Small Business Act to provide loan guarantees for the acquisition of cybersecurity technology and services by eligible small businesses, and for other purposes. Rep. Schneider, Bradley Scott [D-IL-10] 

I will be watching this bill for language and definitions that would specifically allow loans for control system cybersecurity or medical device cybersecurity.

 
/* Use this with templates/template-twocol.html */