Showing posts with label HR 5077. Show all posts
Showing posts with label HR 5077. Show all posts

Wednesday, May 25, 2016

HR 5077 Passes in House – Intel Authorization

Yesterday the House passed HR 5077, the Intelligence Authorization Act for Fiscal Year 2017, by a broadly bipartisan vote of 371 – 35. The bill had been debated (pgs H2901-H2905) on the floor on Monday for all of 27 minutes, most of which was used for praising the bipartisan leadership of the Intelligence Committee.


The bill will probably be considered in the Senate under their unanimous consent process where it will be approved without debate or vote.

Tuesday, May 24, 2016

HR 5077 Reported in House – FY 2017 Intel Authorization

Last week the House Intelligence Committee issued their report on HR 5077, the Intelligence Authorization Act for Fiscal Year 2017. While there is little in the bill that directly concerns cybersecurity, the topic receives a significant amount of attention in the Committee Report.

Cybersecurity Concerns


As with the cybersecurity mention in the actual bill, the Committee Report coverage of the topic is mainly limited to requirements for reports to Congress. The cybersecurity related reports include:

• Unclassified cybersecurity incident information sharing with the National Cybersecurity
and Communications Integration Center (NCCIC);
• Increasing the DHS I&A’s utilization of cybersecurity expertise of the National Labs; and
• Improving the cybersecurity training within national intelligence program (NIP) funded undergraduate and graduate computer science programs;

The one actual cybersecurity action requirement found in the Committee Report deals with supply chain security issues for the intelligence community (IC). The Committee is concerned that current IC acquisition guidelines do not adequately address cybersecurity issues in the supply chain. The Committee is requiring the Director of National Intelligence (DNI) to review and consider revising those guidelines to:

• Expand risk management criteria in the acquisition process to include cyber and supply chain threats;
• Require counterintelligence and security assessments as part of the acquisition and procurement process;
• Propose and adopt new education requirements for acquisition professionals on cyber and supply chain threats; and
• Factor in the cost of cyber and supply chain security.

Moving Forward


The floor debate on HR 5077 took place yesterday evening and a recorded vote was requested. That vote should take place today. As I mentioned earlier, I expect that the bill will pass with substantial bipartisan support.

Commentary


It is heartening to see the Intelligence Committee endorse unclassified information sharing about cybersecurity incidents. The intelligence community by its very nature is secretive in their operations and is reluctant to share the information they gain from their activities for fear of compromising their intelligence collection assets and techniques. Extracting information of any sort from that classified data that can be shared with a wider audience is a difficult undertaking for the intelligence community and they need to be continuously prodded by their overseers to ensure that they make a reasonable effort to do so.


In my very brief time working in tactical level intelligence in the Army I learned first-hand how difficult it is to sort through classified intelligence data to extract out useful information for those at the point of the spear that could be shared without compromising the data collection process. The absolutely necessary vetting and approval process for the unclassified intelligence products produced almost made the effort counterproductive and did made it very difficult to produce useable time-sensitive information. The effort really was worthwhile and should be actively pursued at all levels in the intelligence community.

Wednesday, May 4, 2016

HR 5077 Introduced – FY 2017 Intel Authorization Bill

Last week Rep. Nunes (R,CA) introduced HR 5077, the Intelligence Authorization Act for Fiscal Year 2017. Analysis of this bill is complicated because significant portions (How much? Don’t know.) are classified for fairly obvious reasons. The unclassified portion available to the public does include one cybersecurity provision; a requirement for a port cybersecurity report.

Port Cybersecurity Report


Section 604 requires the Under Secretary of Homeland Security for Intelligence and Analysis to submit a report on port cybersecurity to the congressional intelligence committees. The report will cover the “cybersecurity threats to, and the cyber vulnerabilities within, the software, communications networks, computer networks, or other systems employed by” {§604(a)}:

• Organizations conducting significant operations at seaports in the United States;
• Maritime shipping concerns of the United States; and
• Organizations conducting significant operations at transshipment points in the United States.

The report will include:

• A description of any recent and significant cyberattacks or cybersecurity threats directed against software, communications networks, computer networks, or other systems employed by the port entities described above; and
• An update on the status of the efforts of the Coast Guard to include cybersecurity concerns in the National Response Framework, Emergency Support Functions, or both, relating to the shipping or ports of the United States.

The report will also include an intelligence assessment of:

• Any planned cyberattacks directed against such software, networks, and systems;
• Any significant vulnerabilities to such software, networks, and systems; and
• How such entities and concerns are mitigating such vulnerabilities.

Moving Forward


Nunes is the Chair of the House Intelligence Committee and this is one of those ‘must pass’ authorization bills. The battles have been fought behind closed doors on this bill and will not see the light of day. This bill will be considered on the floor of the House, probably with limited debate and amendments. That is limited in the terms of time; we know that it will be limited to unclassified information.

The Senate will probably have their own version of the bill that will be passed in that body and then a conference committee will work out the differences between the two bills.

Commentary


The port cybersecurity report required in this report would be significantly different than the one in HR 3878 that was passed in the House last December. This is much more of an intelligence report than a security systems report that was described in the earlier bill. The bill does not state this (an understandable oversight from the Intel Committee staff) but the report will certainly be classified and probably will not be shared further than with the Coast Guard’s Captains of the Port.


It would have been nice to see a requirement for an unclassified version of the report so that more sharing could be done with the information, but you never get much unclassified information from the intel community. It just goes too much against the grain.

Thursday, April 28, 2016

Bills Introduced – 04-27-16

Yesterday, with both the House and Senate in session, there were 35 bills introduced. One of those may be of specific interest to readers of this blog:

HR 5077 To authorize appropriations for fiscal year 2017 for intelligence and intelligence-related activities of the United States Government, the Community Management Account, and the Central Intelligence Agency Retirement and Disability System, and for other purposes. Rep. Nunes, Devin [R-CA-22]


As with most of the spending bills that I watch, this one will be covered as and if it addresses cybersecurity issues.
 
/* Use this with templates/template-twocol.html */