Showing posts with label HR 5074. Show all posts
Showing posts with label HR 5074. Show all posts

Monday, February 18, 2019

S 315 Introduced – DHS Cyber Response Teams


Last month Sen. Hassan (D,NH) introduced S 315, the DHS Cyber Hunt and Incident Response Teams Act of 2019. The bill would authorize the current cyber incident response teams in the DHS NCCIC. The bill is very similar to HR 5074 from the 115th Congress which passed in the House but was never taken up in the Senate.

The bill does not name the teams, but the description certainly refers to the incident investigation teams associated with US-CERT and ICS-CERT. The bill specifically mentions ‘control systems’ {6 USC 659(f)(1)(D)} but does not provide a definition for that term.

Hassan and her two cosponsors {Sen. Peters (D,MI) and Sen. Portman (R,OH)} are all influential members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This should mean that the bill has a good chance of being considered in that Committee. A recent article over on Politico.com pointed out, however, how hard it is to get cybersecurity legislation through that Committee. Since this bill does not contain any new authority for NCCIC nor does it approve any new funding, this bill may be able to avoid that cybersecurity trap.

NOTE: HR 1158 was recently introduced in the House with a similar sounding name, but the text has not yet been published. I suspect that it will be very similar to this bill.

Tuesday, August 14, 2018

S 3309 Introduced – Cyber Incident Response Teams


Last month Sen. Hassan (D,NH) introduced S 3309, the DHS Cyber Incident Response Teams Act of 2018. This bill is nearly identical to HR 5074 which was passed in the House in March on a voice vote. The bill essentially authorizes the existing response teams of the US-CERT and ICS-CERT in the National Cybersecurity and Communications Integration Center's (NCCIC).

The differences between the two bills are editorial in nature and are only of interest to legislative grammarians. This new version does still include the same ‘control system security’ language found in the House bill. Similarly, it does not include a definition of ‘control system’.

Moving Forward


Both Hassan and her cosponsor, Sen. Portman (R,OH), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill (and HR 5074) was assigned for consideration. Normally, this would mean that there would be a possibility that the bill could be considered in Committee. This late in the session, however, I suspect that the only consideration that this bill will receive is as a potential amendment to the DHS authorization bill when that bill comes up for consideration after the election.

Nothing in this bill should draw any sort of opposition other than the fact that it would require the House to subsequently reconsider their vote on HR 5074, a cumbersome process going into election season. I suspect that if the Senate were to take up this bill as a stand-alone measure it would consider the House language under the unanimous consent process.

Commentary


Since the existing response teams from NCCIC are already included in the DHS funding, there is no real need in either of these bills for authorization of new funding. It would have been helpful for Congress to increase the funding so that the activities (and number) of these teams could be expanded, but that is unlikely in the current spending climate.

Of specific interest is the language specifically authorizing the use of “cybersecurity specialists from the private sector” {new §148(f)(2)}. This establishes the Congressional intent that these teams are not an inherently governmental service. This may have some interesting legal implications further down the road.

There are two other interesting things missing from this authorization language (in both bills). First, there is no mention of protections for the information gathered by the response teams. This means that there is no specific reason why a Freedom of Information Act request for results of the investigations of these teams should be denied. This could be a cause for organizations to not request support from these teams.

The second is the lack of any requirement for these teams to coordinate their activities with the FBI or some other law enforcement activity. Nor is there any requirement to preserve forensics evidence during the investigations conducted by these teams. At some point the government is going to have to go after the folks conducting these attacks and the preservation of chain of custody and other legal requirements of preserving evidence is going to raise its ugly head.

Friday, March 30, 2018

HR 5074 Reported in House – Cyber Response Teams


Earlier this month the House Homeland Security Committee published their report on HR 5074, the DHS Cyber Incident Response Teams Act of 2018. The bill was passed in the House on March 19th. The date on the report is also the 19th, but the report was not actually published by the GPO until well after the debate and vote in the House.

Authorizing Existing Programs


The report makes it clear that the ‘cyber hunt and incident response teams’ authorized by the bill are, in fact, the activities currently being undertaken by the US-CERT and the National Cybersecurity and Communications Integration Center’s (NCCIC’s) Hunt and Incident Response Teams (HIRT). This is the reason that the bill specifies {§2(b)} that no additional funding is authorized; the funding for these activities is already included in the line items for NCCIC spending.

The provisions of the new 6 USC 148(f)(2) authorizing the use of “cybersecurity specialists from the private sector” on the existing US-CERT and HIRT teams is, however, a potential expansion of the capabilities of those teams. The Report states that allowing the participation of these outside experts would (pg 2) “allow industry professionals to bring innovative approaches and ideas into the federal government and makes progress in bringing the technical expertise and skills that help execute the DHS role in cybersecurity”.

Commentary


Neither the report nor the bill mentions any of the response activities of the DHS Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) which also operates as part of the NCCIC and was formerly part of the US-CERT (Actually, the current relationship between the ICS-CERT and the current US-CERT is not actually very clear.) Presumably, since the bill would add the term ‘control systems’ (even though undefined) to §148 {via (f)(1)(D)} the response activities of ICS-CERT, especially their away teams, would fall broadly under the authorization provided in this bill.

Unfortunately, the failure to define the term ‘control system’ or modify the definition of ‘information system’ in §148(a)(5) to specifically include control systems means that this bill would do nothing to actually codify the importance of control system security in NCCIC activities or oversight. This is unlikely to change if/when this bill is considered in the Senate.

Tuesday, March 20, 2018

House Passes HR 5074 – Cyber Incident Response Teams


Yesterday the House passed HR 5074, the DHS Cyber Incident Response Teams Act of 2018, by a voice vote. The bill would authorize the establishment and use of “cyber hunt and incident response teams” in the National Cybersecurity and Communications Integration Center (NCCIC). No additional funding is provided in this bill.

As I mentioned yesterday, this bill has been officially referred to as being considered “as amended” and no amendments were offered or approved when the bill was considered by the House Homeland Security Committee. The Congressional Record for yesterday (pg H 1661) makes the same statement. I have reviewed the original bill, the reported version (published overnight) and the version published in the Record and can find no differences between these three versions. Maybe there will be some explanation when the Committee Report (H Rept 115-607) is printed later this week.

It is difficult to predict whether or not this bill will be taken up by the Senate. If it does make it to the Senate floor, I suspect that it will be at the end the day under the Senate’s ‘without objection’ procedures; meaning no debate and no vote.

If this bill does become law, it will have an interesting potential consequence. With the use of the term ‘control systems’ in the new paragraph (f)(1)(D) of 6 USC 148, we see an official opening of the NCCIC to consideration of control system incidents, particularly since the term is used with these incident response teams. The IT-limited definition of ‘information systems’ in §148 has not specifically prohibited NCCIC from consideration of ICS incidents, but it has not provided specific authorization either. I would still prefer to see the definition of ‘information systems’ at §148(a)(5) to an ICS inclusive definition (as in §1501), but the provision in this bill should make it reasonably clear that NCCIC should consider control system incidents as part of its area of interest.

Monday, March 19, 2018

Committee Hearings – Week of 03-18-18


There are a significant number of hearings scheduled this week with both the House and Senate in session. Budget hearings predominate, but none that are of specific interest to readers of this blog. In fact, I do not see any hearings of specific interest here this week. There are, however, two bills that will make it to the floor of the House this week that I am watching and, of course, there is a spending bill deadline approaching at the end of the week.

On the Floor of the House


There are a number of bills that are scheduled to come to the floor on Monday under the suspension of the rules provisions of the House. These provisions limit debate, prohibit floor amendments, and require a super-majority to pass. Bills of potential interest include:

HR 5074, the DHS Cyber Incident Response Teams Act of 2018;
HR 5089, Strengthening Local Transportation Security Capabilities Act of 2018;

Interestingly, both of these bills are listed in the Majority Leader’s schedule as being considered “as amended”. The Homeland Security Committee mark-up hearing for both of these bill resulted in an order for each bill that the bill be “reported to the House with a favorable recommendation, without amendment”. No report has been published for either bill (will probably be submitted today and published later this week), so I cannot tell if Chairman McCaul (R,TX) subsequently ordered some revisions be made to the bill. It would not be too unusual for minor technical revisions to be made after mark-up, but substantial revisions are seldom made.

FY 2018 Spending Bill


The current continuing resolution (CR, HR 1892) will expire on Friday night. The hope has been that the House and Senate will consider and pass an omnibus spending bill this week that would include all of the non-DOD operations of the government (DOD spending was included in the last CR). News reports (see here for example) would seem to indicate that there is still some hard negotiating to be done on this bill.

Is there a chance that there will be another CR? It increasingly seems that there is always a chance. One remote possibility is that a CR for the rest of the fiscal year could be passed, keeping the current funding levels. While the inclusion of DOD spending in HR 1892 would seem to make that possibility easier, it would violate the agreement to increase spending levels in non-DOD areas that allowed HR 1892 to eventually be passed.

Wednesday, March 7, 2018

House Homeland Security Committee Marks-up Legislation – 03-07-18


Today the House Homeland Security Committee held a markup hearing to look at 10 homeland security related bills (one of the scheduled bills HR 4627 was not considered). All of the bills passed by unanimous consent. Four of the bills were amended before passing.

Bills of potential specific interest to readers of this blog included:

HR 5074, the DHS Cyber Incident Response Teams Act, was adopted without amendment;
HR 5081, the Surface Transportation Security and Technology Accountability Act of 2018, was adopted without amendment; and
HR 5089, the Strengthening Local Transportation Security Capabilities Act of 2018, was adopted without amendment.

I suspect that all ten bills will make it to the House floor under the suspension of rules process that allows for limited debate and no floor amendments. Each of these bills should pass with broad bipartisan support; most of them without a roll-call vote.


Monday, March 5, 2018

Committee Hearings – Week of 03-04-18


This week, with both the House and Senate in Washington for a congressional full-week, budget hearings will be the big news. There will be, however, some other hearings of interest; four of particular interest to readers of this blog; two markup hearings, a cybersecurity workforce hearing, and a Coast Guard programs hearing.

Markup Hearings


On Wednesday the Senate Homeland Security and Governmental Affairs will ‘continue’ their hearing of last week so that they can start the markup of HR 2825, a DHS authorization bill, that I mentioned last week. The bill was not considered last week because some new amendments were not ready for submission. There is also a possibility that a Senate version of the bill will be introduced this week and then that would be marked up instead of HR 2825.

The House Homeland Security Committee will meet on Wednesday to markup 11 bills. Bills of particular potential interest to readers of this blog include:

HR 5074, the DHS Cyber Incident Response Teams Act

I have not had a chance to review the first five on the list yet, but I will try to get that done before Wednesday.

Cybersecurity Workforce


On Wednesday two subcommittees of the House Homeland Security Committee will hold a joint hearing to look at “Examining DHS’ Efforts to Strengthen its Cybersecurity Workforce”. There is no witness list published yet, but I suspect that we will have either a GAO of DHS IG report presented at this hearing. In any case, the problems that DHS (and the rest of the government) is having identifying their cybersecurity needs and then finding the people to fill the requisite positions is just a reflection of the generally increasing need for cybersecurity specialists in the economy as a whole.

 Coast Guard Programs


On Wednesday the Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing to look at “Implementation of Coast Guard Programs”. No witness list is currently available. There is a remote chance that the Maritime Transportation Security Act (MTSA) program implementation will be addressed. If it is it will almost certainly be touching on the TWIC Reader Rule; we are still waiting on the long overdue publication of a final rule.

Friday, March 2, 2018

HR 5074 Introduced – DHS Cyber Response Teams


Last month Rep. McCaul (R,TX) introduced HR 5074, the DHS Cyber Incident Response Teams Act of 2018. The bill would amend the authorizing language (6 USC 148) for the National Cybersecurity and Communications Integration Center (NCCIC) to establish cyber hunt and incident response teams within that organization.

Cyber Response Teams


Section 2 of the bill would require the NCCIC to maintain ‘cyber hunt and incident response teams’. These teams would be used ‘upon request’ to provide {new §148(f)(1)}:

• Assistance to asset owners and operators in restoring services following a cyber incident;
• The identification of cybersecurity risk and unauthorized cyber activity;
• Mitigation strategies to prevent, deter, and protect against cybersecurity risks;
Recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate;

The NCCIC would be authorized to use cybersecurity specialists from the private sector on these teams.

Moving Forward


McCaul is the Chair of the House Homeland Security Committee to which this bill was assigned for consideration. That would make it a near certainty that this bill would be considered in committee in the not too distant future. Its movement to the House floor is not so clear.

I see nothing in this bill that would draw significant opposition, particularly since not new funds are authorized to financially support these teams. I suspect that this bill would receive bipartisan support, both within the Committee and on the floor of the House. I am concerned, however, about the lack of a Democrat cosponsor.

Commentary


The biggest problem with this bill is that the authorizing language is, of necessity, included in §148. That section continues to rely on IT limited definitions of ‘information systems’ {§148(a)(5)} that does not include industrial control systems. The specific use of the terms ‘cyber risk’ and ‘incident’ and the definitions of both being specifically tied to that system definition, only aggravates the issue.

Having said that, the bill does specifically include ‘control system security’ in the description of support that the teams would provide. Unfortunately, the term ‘control system security’, as well as the problematic ‘cyber hunt’ are left undefined. This bill would have been a good spot to make the changes in definitions that I have suggested in earlier posts (here for example).

The oddest part of the bill is found in the new §148(f)(4) where the obligatory reports to Congress are mentioned. This bill would only require reports from the NCCIC to congressional committees once every four years on the activities of these new teams and there is no requirement for any GAO or DHS IG follow-up reporting. It is almost as if McCaul is saying: “We do not want to know what these teams are doing. Don’t bother us and we won’t bother you.” [OOPS, it says "each of the first four fiscal years"; so annual reporting is required. 03-20-18 08:30 EDT]

Finally, there is the funding issue. Section 2(b) of the bill specifically states that no additional funds are authorized and that the activities are to “be carried out using amounts otherwise authorized to be appropriated”. This means that the money and personnel headcount to support these teams are going to have to come at the expense of some other NCCIC processes. This is almost certainly the reason that the bill specifically authorizes the use of private sector cybersecurity specialists on the teams. Contractors are cheaper (no federal benefits, specifically retirement costs) and there are no practical headcount limitations.

Wednesday, February 21, 2018

Bills Introduced – 02-20-18


Yesterday, with the House and Senate meeting in pro forma session (most congresscritters back in their districts), there were 9 bills introduced. Of those one may be of specific interest to readers of this blog:

HR 5074 To authorize cyber incident response teams at the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10]

As usual with cybersecurity bills, I will be watching definitions closely to see if the provisions specifically apply to industrial control systems.

 
/* Use this with templates/template-twocol.html */