Showing posts with label HR 5035. Show all posts
Showing posts with label HR 5035. Show all posts

Monday, July 21, 2014

Congressional Hearings – Week of 7-20-14

There are just two weeks now before Congress starts their extended summer vacation. There are a number of hearings being held this week, but only one that may be remotely of specific interest to readers of this blog; and intel hearing of sorts.

On Wednesday the House Homeland Security Committee will be holding a hearing on "The Rising Terrorist Threat and the Unfulfilled 9/11 Recommendation." The witness list includes two former commissioners from the National Commission on Terrorist Attacks Upon the United States; Jamie S. Gorelick and Thomas H. Kean Jr.. Perhaps one of them will remind the Committee that one of the unaddressed recommendations of the Commission was the reform of Congressional oversight of the Homeland Security Department; political power is still more important than counter terrorism.


The House is going to take another pass (according to the Majority Leader’s web site) at trying to pass HR 5035, the NIST Reauthorization Act of 2014, under suspension of the rules on Tuesday. This had been listed for last week, but was not offered for consideration on the floor. Apparently the leadership thinks that they have the concerns about NIST cooperation with NSA worked out.

Tuesday, July 15, 2014

Bills Introduced – 07-14-14

Twenty-four bills were introduced yesterday and one of those may be of specific interest to readers of this blog:

HR 5099 Latest Title: To amend the National Institute of Standards and Technology Act to remove the National Security Agency from the list of the entities consulted during the development of information systems standards and guidelines. Sponsor: Rep Grayson, Alan (D,FL)

Earlier this morning I reported on the non-consideration of HR 5035, I suspect that this bill may the part of the response that caused the Republican leadership from withdrawing the consideration of HR 5035 under suspension of the rules.

As I explained in an earlier post, the sole provision of HR 5035 that addressed the NSA influence issue was no more than a pro forma wrist slap of no real consequence. This bill is probably going to be an over-reaction in the other direction.


It will have little chance of succeeding, Grayson is probably not an influential enough member of the opposition on the House Space Science and Technology Committee to force this bill onto the Committee’s markup list. Having said that, it did derail the consideration of HR 5035 and may force that bill to a markup hearing where further attention can be focused on the relationships between NIST and NSA.

House Did Not Consider HR 5035

According to the House Floor Summary for today, the House did not consider HR 5035, the NIST reauthorization bill that I described this weekend. It is still listed on the Majority Leader’s web site for consideration on Monday, July 14th so there is no official reason given for why the bill was not addressed today. I suspect that there was enough concern about the NIST-NSA relationship that was not adequately addressed in this bill to make this slightly more controversial than the Leadership was willing to risk on considering the bill under suspension of the rules.


There is an outside chance that the bill could get added to tomorrow’s session. I suspect that, if I am right about why the bill was not considered today, it will be considered next week under a rule with limited amendments.

Saturday, July 12, 2014

HR 5035 Introduced – NIST Authorization

As I mentioned earlier Rep. Bucshon (R,IN) the Chair of the Subcommittee on Research and Technology of the House Science, Space and Technology Committee, introduced HR 5035, the NIST Reauthorization Act of 2014. This is the two-year re-authorization of the National Institute of Standards and Technology.

Cybersecurity

There is only one place in this bill where cybersecurity activities are specifically addressed. Section 12 of the bill would amend 15 USC 278g-3, the Computer Standards Program. This section of the USC provides for NIST being responsible for setting standards for the security of government computer systems (not including ‘national security systems) and the information within those systems.

The only change made to this section is the removal of the words “the National Security Agency” from §278g-3(c)(1). This section currently requires the Director to “consult with other agencies and offices (including, but not limited to, the Director of the Office of Management and Budget, the Departments of Defense and Energy, the National Security Agency, the Government Accountability Office, and the Secretary of Homeland Security) to assure” that proper appropriate information security policies, procedures, and techniques are used by government agencies.

Apparently this revision was put into place because of Snowden revelations that NIST recommended less than adequate encryption standards under recommendations of NSA. If this is the reason, the crafters of this language are taking very limited action against the NSA because section only applies to the security of government systems and not NIST standards that would be used by the private sector.

Even with government IT security, this amendment to §278g-3 only deals with lower security standards associated with government IT systems not associated with national security systems. Paragraph (b) of the section still requires NIST to coordinate with NSA to establish guidelines “for identifying an information system as a national security system consistent with applicable requirements for national security systems” {§278g-3(b)(3)}.

There are almost certainly other mentions of working with NSA in 15 USC Chapter 7 {for example §278g-4(a)(3)} that could have also been addressed if Congress was serious about severing ties between NIST and NSA. So this amendment is a symbolic congressional wrist slap of the NSA with no real consequences.

Moving Forward


According to the Majority Leader’s web site, HR 5035 will be considered by the House on Monday under suspension of the rules. Barring some unforeseen circumstance, this should mean that the bill will pass with a minimum of fuss and bother, very little debate and no amendments. It is likely to get equally swift and cursory attention in the Senate.

Thursday, July 10, 2014

Bills Introduced – 7-9-14

Both the House and Senate are in Washington operating in that grey space between the electioneering modes and legislative modes. Thirty-five bills were introduced yesterday; one of which may be of specific interest to readers of this blog:

HR 5035 Latest Title: To reauthorize the National Institute of Standards and Technology, and for other purposes. Sponsor: Rep Bucshon, Larry (R,IN)


I’ll be watching for potential cybersecurity language in this bill.
 
/* Use this with templates/template-twocol.html */