Showing posts with label HR 5081. Show all posts
Showing posts with label HR 5081. Show all posts

Tuesday, June 26, 2018

House Passes STSAC Authorization and ICS Security Bills


Yesterday the House passed two bills that have been covered in this blog; HR 5081, the Surface Transportation Security and Technology Accountability Act of 2018, and HR 5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018. Both bills were considered under the suspension of the rules process and were approved by voice votes.

I do not often mention the ‘floor debate’ about bills considered under the suspension of the rule process because that debate is normally congratulations about the bipartisan effort to develop the bill in committee. While we certainly saw a good measure of this in the debate on ICS cybersecurity bill, we also saw a potentially important mention of the DHS ICS-CERT.

In his brief speech supporting the bill, Rep. Langevin (D,RI) talked at some length about the important work being done by ICS-CERT. He started by explaining his amendment adopted by the House Homeland Security Committee on vulnerability disclosures (pg H5631):

“During the committee consideration, I was also proud to offer an amendment to codify ICS-CERT’s coordinated vulnerability disclosure program [emphasis added] that ensures ICS vulnerabilities can be reported securely, promptly, and responsibly.”

He goes on to note (pg H5632):

“The coordinated vulnerability [disclosure] program does just that by helping critical infrastructure owners and operators who receive notices from ICS-CERT about discovered vulnerabilities and effective patches before malicious actors have a chance to exploit any flaws. Mr. Speaker, this bill would empower ICS-CERT to carry out this mission fully and effectively [emphasis added].”

While I have been critical of the bill’s failure to mention both ICS-CERT and US-CERT as the organizations that carry out the specified work of the National Cybersecurity and Communications Integration Center (NCCIC), the specific mention of the role of ICS-CERT in the congressional debate on this bill will go a long way is preserving the existence of, and defining the role of, that organization.

Monday, June 25, 2018

Committee Hearings – Week of 06-24-18


With both the House and Senate in session this week it looks to be a busy week for Committee work. We are still seeing spending bills being marked-up and we have three cybersecurity related authorization bills. There will also be a Senate mark-up of the TWIC Reader Delay bill in that body.

Spending Bills

Monday – House Rules Committee – HR 6157 DOD;
Tuesday – House Rules Committee – HR 6157 DOD;
Tuesday – House Committee – LHHS;
Tuesday – Senate Sub-Committee – DOD;
Tuesday – Senate Sub-Committee – LHHS;
Thursday – Senate Committee – DOD;
Thursday – Senate Committee – LHHS

The Senate will finish work on HR 5895, the FY 2019 EWR spending bill Monday evening. The House will take up HR 6157, the FY 2019 DOD spending bill, either late Tuesday or on Wednesday.

Cybersecurity Authorization Bills


The three authorization bills with a cybersecurity nexus are for the National Telecommunications and Information Administration (NTIA), the National Institute of Science and Technology (NIST) and the intelligence community.

On Tuesday the Communications and Technology Subcommittee of the House Energy and Commerce Committee will hold a hearing on their draft of an authorization bill for NTIA. The witness list includes:

• Michael D. Gallagher, Entertainment Software Association;
• John Kneuer, JKC Consulting; and
Joanne S. Hovis, CTC Technology and Energy

The draft bill includes two ‘Sense of Congress’ sections on cybersecurity threats and supply chain vulnerabilities, and on preservation of domain name system and WHOIS service.
On Wednesday the House Science, Space, and Technology Committee will hold a mark-up hearing for three as of yet unintroduced bills. One of those is the draft of the NIST authorization bill. The draft includes a section on general cybersecurity and a separate section on IoT with cybersecurity language included.

On Thursday the House Intelligence Committee will hold the inevitably closed-hearing on their mark-up of the as of yet unpublished FY 2019 Intelligence Authorization Act. The draft is not publicly available and, of course, the good stuff will be in the classified annex to the bill.

TWIC Reader Rule


On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a mark-up hearing on eight bills, including S 3094. The text of that bill has not yet been published by the GAO, but it sounds like it should be a companion bill to HR 5729, the Transportation Worker Identification Credential Accountability Act of 2018. After having reviewed the Coast Guard NPRM on their proposed selective delay of the implementation of the TWIC Reader Rule, it seems unlikely that the two legislative delay attempts and the CG delay are very closely related to the same issues.

On the Floor


In addition to the two spending bills on the floor this week, we will also see the House take up two bills of potential interest to readers of this blog. Later today the House will consider HR 5081, the Surface Transportation Security and Technology Accountability Act of 2018, and HR 5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018. Both bills will be taken up under the suspension of the rules provisions. This means limited debate and no floor amendments. It also means that the leadership expects serious bipartisan support for both bills since a super-majority is required for passage.

The House is also scheduled to take up a motion to go to conference on HR 5515, the FY 2019 DOD authorization bill, that passed in the Senate last week.

Wednesday, March 7, 2018

House Homeland Security Committee Marks-up Legislation – 03-07-18


Today the House Homeland Security Committee held a markup hearing to look at 10 homeland security related bills (one of the scheduled bills HR 4627 was not considered). All of the bills passed by unanimous consent. Four of the bills were amended before passing.

Bills of potential specific interest to readers of this blog included:

HR 5074, the DHS Cyber Incident Response Teams Act, was adopted without amendment;
HR 5081, the Surface Transportation Security and Technology Accountability Act of 2018, was adopted without amendment; and
HR 5089, the Strengthening Local Transportation Security Capabilities Act of 2018, was adopted without amendment.

I suspect that all ten bills will make it to the House floor under the suspension of rules process that allows for limited debate and no floor amendments. Each of these bills should pass with broad bipartisan support; most of them without a roll-call vote.


Monday, March 5, 2018

HR 5081 Introduced – Surface Transportation Advisory Committee


of policies, programs, initiatives, rulemakings, and security directives pertaining to surface transportation security” {new 6 USC 1621(b)(1)}.

STSAC


Section 1621(c) establishes the composition of the Committee. It will be composed of voting and non-voting members. The non-voting members would be appointed by specified government agencies and would be expected to provide advise to the Committee; presumably on how the agencies operate.

The voting members would represent the different modes of surface transportation. Those members would come from {§1621(c)(2)}:

• Associations representing such modes of surface transportation;
• Labor organizations representing such modes of surface transportation;
• Groups representing the users of such modes of surface transportation, including asset manufacturers, as appropriate; and
Relevant law enforcement, first responders, and security experts.

Moving Forward


Katko is the Chair of the Transportation and Protective Security Subcommittee of the House Homeland Security Committee. His two cosponsors are Rep. Watson-Coleman (D,NJ; Subcommittee Ranking Member) and Rep. McCaul (R,TX; Committee Chair). This is certainly strong, bipartisan support within the Committee.

The bill will be considered on Wednesday in the Committee markup hearing. I see nothing in the bill that would attract any significant opposition. It will receive bipartisan support in Committee and likely on the floor of the House should it make it there.

Commentary


These advisory committees are an effective way to get a wide range of industry input into how to effectively develop regulations. A lesser realized advantage of these groups is that it provides another information conduit for federal agencies to effectively communicate to the regulated communities.

Committee Hearings – Week of 03-04-18


This week, with both the House and Senate in Washington for a congressional full-week, budget hearings will be the big news. There will be, however, some other hearings of interest; four of particular interest to readers of this blog; two markup hearings, a cybersecurity workforce hearing, and a Coast Guard programs hearing.

Markup Hearings


On Wednesday the Senate Homeland Security and Governmental Affairs will ‘continue’ their hearing of last week so that they can start the markup of HR 2825, a DHS authorization bill, that I mentioned last week. The bill was not considered last week because some new amendments were not ready for submission. There is also a possibility that a Senate version of the bill will be introduced this week and then that would be marked up instead of HR 2825.

The House Homeland Security Committee will meet on Wednesday to markup 11 bills. Bills of particular potential interest to readers of this blog include:

HR 5074, the DHS Cyber Incident Response Teams Act

I have not had a chance to review the first five on the list yet, but I will try to get that done before Wednesday.

Cybersecurity Workforce


On Wednesday two subcommittees of the House Homeland Security Committee will hold a joint hearing to look at “Examining DHS’ Efforts to Strengthen its Cybersecurity Workforce”. There is no witness list published yet, but I suspect that we will have either a GAO of DHS IG report presented at this hearing. In any case, the problems that DHS (and the rest of the government) is having identifying their cybersecurity needs and then finding the people to fill the requisite positions is just a reflection of the generally increasing need for cybersecurity specialists in the economy as a whole.

 Coast Guard Programs


On Wednesday the Coast Guard and Maritime Transportation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing to look at “Implementation of Coast Guard Programs”. No witness list is currently available. There is a remote chance that the Maritime Transportation Security Act (MTSA) program implementation will be addressed. If it is it will almost certainly be touching on the TWIC Reader Rule; we are still waiting on the long overdue publication of a final rule.

Monday, February 26, 2018

Bills Introduced – 02-23-18


Last Friday, with the House and Senate meeting in pro forma session (almost all of the members were back in their districts), there were 9 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 5079 To amend the Homeland Security Act of 2002 to require the Department of Homeland Security to develop an engagement strategy with fusion centers, and for other purposes. Rep. Bacon, Don [R-NE-2]

HR 5081 To amend the Homeland Security Act of 2002 to establish within the Transportation Security Administration the Surface Transportation Security Advisory Committee, and for other purposes. Rep. Katko, John [R-NY-24]

I will be watching HR 5079 for the specific types of engagement being proposed to see if they might have an impact on information sharing in chemical security or cybersecurity areas.

HR 5081 will almost certainly be covered here for its potential impact on chemical transportation security activities.

 
/* Use this with templates/template-twocol.html */