Showing posts with label HR 5175. Show all posts
Showing posts with label HR 5175. Show all posts

Tuesday, September 9, 2025

Review - Bills Introduced – 9-8-25

Yesterday, with both the House and Senate in session, there were 62 bills introduced. One of those bills will receive additional coverage in this blog:

HR 5167 To authorize appropriations for fiscal year 2026 for intelligence and intelligence-related activities of the United States Government, the Community Management Account, and the Central Intelligence Agency Retirement and Disability System, and for other purposes. Crawford, Eric A. "Rick" [Rep.-R-AR-1] 

Space Geek Legislation

I would like to mention one bill under my limited Space Geek coverage in this blog:

HR 5175 To require the Secretary of Defense to initiate discussions, through the Quad, with Australia, India, and Japan to identify mutual areas of interest with respect to the formulation of best practices in space, cooperation on space situational awareness, and space industrial policy, and for other purposes. Crow, Jason [Rep.-D-CO-6] 

 

For more information on these bills, including legislative history for similar bills in the 118th, as well as two bills mentioned in passing, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-8-25 - subscription required.

Wednesday, November 20, 2019

Bills Introduced – 11-19-19


Yesterday with both the House and Senate in session there were 55 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 5175 To amend title 49, United States Code, to provide enhanced safety in pipeline transportation, and for other purposes. Rep. Crawford, Eric A. "Rick" [R-AR-1]

S 2893 A bill to amend the Comprehensive Environmental Response, Compensation, and Liability Act of 1980 to provide for the consideration of climate change, and for other purposes. Sen. Harris, Kamala D. [D-CA] 

Friday, January 18, 2019

HR 370 Introduced – Pipeline Security


Last week Rep. Upton (R,MI) introduced HR 370, the Pipeline and LNG Facility Cybersecurity Preparedness Act. This bill is nearly identical to the version of HR 5175 that was reported in the House last session. That bill never made it to the floor of the House for consideration. The bill would provide the Department of Energy with some level of responsibility for pipeline security (specifically including cybersecurity) but without any regulatory authority in the area. The respective responsibilities of DHS/TSA and DOT/PHMSA in the area would not be affected.

Moving Forward


The Republicans have yet to announce their committee rosters yet so it is too early to tell if Upton will be back on the Energy and Commerce Committee, the Committee to which this bill was referred for consideration. His single co-sponsor {Rep. Loebsack (D,IA)} is a member of that Committee so this bill may end up being considered in Committee.

There is a lesser chance that the bill will move directly to the floor of the House for consideration as so many bills reintroduced in the previous session are. If Upton were really hoping for that to happen, he probably should have had Loebsack listed as the sponsor of the bill.

This bill will almost certainly be approved with substantial bipartisan support. The modifications made in the marked-up version of the previous bill were designed to throw bones to the other committees (Transportation and Homeland Security) that might object to the bill overstepping into their areas of oversight. Additionally, the revised language now seen in this ‘original bill’ easy any potential industry concerns by clarifying that the tools and procedures developed by DOE under direction of this bill {in §2(3) and §2(6)} would be available for ‘voluntary use’ by industry and not mandated.

If this bill makes it through the backroom processes in the House and is considered on the floor, it will be sent to the Senate with bipartisan support.

Wednesday, May 9, 2018

Energy and Commerce Committee Takes up Cybersecurity Bills


Today in a markup hearing that was billed as being about opioid abuse legislation (and mostly was) the House Energy and Commerce Committee took up four cybersecurity bills that had previously been adopted in subcommittee action. The all four cybersecurity bills were adopted by voice votes with two of them being amended. The action on these cybersecurity bills came at the end of the almost 4-hour long hearing.

The four cybersecurity bills were:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act;
HR 5239, Cyber Sense Act; and
HR 5240, Enhancing Grid Security through Public-Private Partnerships Act

Committee Amendments


The pipeline cybersecurity bill was amended. The amendment was offered by Rep. Upton (R,MI) who is the Chair of the Energy Subcommittee. The major portion of this amendment was the addition of §3, Savings Clause. That section states:

“Nothing in this Act shall be construed to modify the authority of any Federal agency other than the Department of Energy relating to physical security or cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, or liquefied natural gas facilities.”

This amendment indirectly addresses the roles of both the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) and DHS’ Transportation Security Administration in protecting pipeline safety and security. This should alleviate the conflicts with the House Transportation and Infrastructure Committee and the House Homeland Security Committee over jurisdictional issues that I identified in my earlier post.

The enhancing grid security bill was amended. The amendment was offered by Rep. Latta (R,OH). It added the Electric Reliability Organization as one of the agencies with which the Department of Energy would consult in developing the program outlined in the bill. The amendment also provided a definition of the term ‘Electric Reliability Organization’.

Moving Forward


This was probably the last time that there would be any opportunity to modify the language in these four bills. It is likely that they will move to the House floor, probably before the summer recess. They will almost certainly be considered under the House suspension of the rules provisions that limits debate and prohibits amendments from the floor. They will all almost certainly pass with broad bipartisan support.

If any of these bills get taken up by the Senate (impossible to predict) it will probably be under similar abbreviated consideration provisions as we will see in the House.

Friday, April 20, 2018

House Subcommittee Marks-Up Energy Security Bills


On Wednesday the Subcommittee on Energy, of the House Committee on Energy and Commerce, held a markup hearing on five energy bills. Four of the bills have been covered in this blog and those bills passed on voice votes; two of them were amended with substitute language from the original offerors. The four the bills that have been addressed in this blog:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act (amended);
HR 5239, Cyber Sense Act (amended); and
HR 5240, Enhancing Grid Security through Public-Private Partnerships Act

HR 5175 Changes


The one change made to HR 5175 in the substitute language is relatively minor. It adds a phrase to §2(1) to expand the coordination requirement by adding: “including through councils or other entities engaged in sharing, analysis, or sector coordinating”.

HR 5239 Changes


The changes to HR 5239 are mainly grammatical and would have little to do with the operation of the Cyber Sense program that is proposed by this bill. There is one potentially significant change; §2(b)(7) from the original bill was removed. That paragraph had provided a requirement for the Secretary of Energy to “establish procedures for disqualifying products that were tested and identified as cyber-secure under the Cyber Sense program but that no longer meet the qualifications to be identified cyber-secure products”. There is nothing in the revised program that would prohibit that disqualification.

Moving Forward


The bipartisan support received in the subcommittee will almost certainly be duplicated when these bills are taken up by the whole committee. The question then will be to see if the sponsors and the Committee leadership have enough influence (or are willing to expend the effort to influence) to bring these bills before the full House. I firmly expect that we will see some version of these bills reach the floor under the suspension of the rules procedure in the House. Again, that means limited debate and no floor amendments. I would not be surprised to see all five bills considered on a single day.

Commentary


The removal of the language in HR 5239 providing for the establishment of a process to disqualify products that no longer meet the Cyber Sense standards brings up an interesting legal situation. As I said earlier, there is nothing in the bill that would specifically prohibit the Secretary from establishing such rules. But, having said that, a good lawyer could argue before a friendly judge that the removal of the specific authority to establish such a disqualification process from the language in the bill establishes a congressional intent that such authority can no longer be exercised by the Secretary absent specific authorization by Congress.

What this very well could end up meaning is that once a vendor becomes authorized to use the ‘Cyber Sense’ label on their product, they will no longer have to work to maintain the ‘Cyber Sense’ standards because the Secretary would not have the authority to require the vendor to remove the ‘Cyber Sense’ labeling. If the vendor flaunting of the ‘Cyber Sense’ standards becomes wide spread, the efficacy of the whole program would be called into question, destroying the process.

If this problem is to be addressed, it will almost certainly have to be done during the Energy and Commerce mark-up hearing that will probably be conducted in the next couple of weeks. After that, if the bill moves forward, it would almost certainly be under processes in both the House and Senate that would not allow for amendments to the bill from the floor.

Tuesday, March 13, 2018

Not a Markup Hearing


Well, it turns out that the Energy Subcommittee hearing on the four DOE emergency response and security bills is not a mark-up hearing after all. Last night the witness list was announced, so it seems as if this will be an information gathering hearing with a possible mark-up at some later date.

Updated Hearing Information


The witness list includes:

Mark Menezes, US Department of Energy;
Scott Aaronson, Edison Electric Institute;
Mark Engels, Dominion Energy;
Kyle Pitsor, National Electrical Manufacturers Association;
Zachary Tudor, Idaho National Laboratory; and
Tristan Vance, Indiana Office of Energy Development

The links provided above are to the witness testimony that will be presented at tomorrow’s hearing. The Sub-Committee staff has also produced a background document for the meeting.

Interesting Info in Testimony


Menezes notes that (pg 1):

“To demonstrate our focus on the aforementioned mission [to protect the Nation’s critical energy infrastructure from physical security events, natural and man-made disasters, and cybersecurity threats], the Secretary announced last month that he is establishing an Office of Cybersecurity, Energy Security, and Emergency Response (CESER). This organizational change will strengthen the Department’s role as the Sector-Specific Agency (SSA) for Energy Sector Cybersecurity, supporting our national security responsibilities.”

Menezes also notes that (pg 6):

“Advancing the ability to improve situational awareness of OT networks is a key focus of DOE’s current activities. The Department is currently in the early stages of taking the lessons learned from CRISP and developing an analogous capability for threat detection on OT networks via the Cybersecurity for the Operational Technology Environment (CYOTE) pilot project. Observing anomalous traffic on networks – and having the ability to store and retrieve network traffic from the recent past – can be the first step in stopping an attack in its early stages.”

Engels notes that (pg 3):

“A more expedient [coordinating security activities of DOT and TSA] approach may be to encourage a Memo of Understanding (MOU)between DOE and TSA that outlines roles and responsibilities for dealing with cyber and physical security for the ONG sector. TSA already has an MOU with the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) which has responsibility for pipeline safety. Depending on the type of event, the TSA/DOT MOU has been critical in helping operators understand which Federal entity is the lead agency.”

Engels also notes that (pg 8):

“In 2016, TSA, again working with asset owners, industry associations, and the Department of Homeland Security’s Industrial Control System’s Cyber Emergency Response Team (DHS ICS-CERT), gathered input to update the Guidelines using the National Institute of Standards and Technology’s (NIST) Cyber Security Framework as a model. The updated [Pipeline Security] Guidelines are scheduled for release in the first half of 2018. Industry also provided input to augment the set of cybersecurity questions used in the Corporate Security Reviews (CSR) conducted by TSA.”

Engels also notes that (pgs 12-13):

“INL has undertaken several initiatives to stand up test environments for Industrial Control Systems (ICS). One such initiative was called RENDER (Risk Evaluation Nexus for Digital Age Energy Reliability). RENDER created a three way sharing arrangement involving the lab, the vendor and the asset owner. Previous projects excluded the asset owner from the equation, creating uncertainty associated with remediation of the vulnerabilities identified by INL. With RENDER, the asset owner not only could see what vulnerabilities were discovered, but provide input to the vendor about how critical or not the vulnerability was to the asset owner. This allowed the vendor to prioritize corrections that made the most sense to the asset owners.”

Tudor notes that (pg 4):

“INL developed and completed an initial pilot study of our proprietary Consequence driven, Cyber-informed Engineering (CCE) methodology with Florida Power and Light (FPL) through a Cooperative Research and Development Agreement (CRADA). CCE was developed to address the realization that constantly “chasing” threats and vulnerabilities, rather than getting ahead of these problems, is not sufficient to secure our critical systems. CCE is designed to assist asset owners in understanding the most effective and immediate actions they can take to eliminate the opportunity of the “worst-case” cyber-physical impacts from an attack by the most capable cyber adversaries. CCE leverages an organization’s knowledge and experiences with their systems and processes to “engineer out” the potential for the highest consequence events.”

This could be an interesting hearing.

Monday, March 12, 2018

HR 5175 Introduced – Pipeline Security


Last week Rep. Upton (R,MI) introduced HR 5175, the Pipeline and LNG Facility Cybersecurity Preparedness Act. The bill would require the Secretary of Energy to establish policies and procedures for the physical security and cybersecurity for pipelines and liquefied natural gas facilities.

Requirements


The bill would require the Secretary to {§2}:

• Establish policies and procedures to coordinate Federal agencies, States, and the energy sector to ensure the security, resiliency, and survivability of natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities;
• Coordinate response and recovery by Federal agencies, States, and the energy sector, to physical incidents and cyber incidents impacting the energy sector;
• Develop advanced cybersecurity applications and technologies for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities;
• Perform pilot demonstration projects relating to physical security and cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities with representatives of the energy sector;
• Develop workforce development curricula for the energy sector relating to physical security and cybersecurity for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities; and
Provide mechanisms to help the energy sector evaluate, prioritize, and improve physical security and cybersecurity capabilities for natural gas pipelines (including natural gas transmission and distribution pipelines), hazardous liquid pipelines, and liquefied natural gas facilities.

Moving Forward


Upton is the Chair of the Energy Subcommittee of the House Energy and Commerce Committee. The bill is scheduled for markup on Wednesday. The bill will probably pass in both the Subcommittee and subsequent full Committee markup with substantial bipartisan support.

The main problem with this bill is that there will likely be substantial opposition from the Chair of the Homeland Security Committee since the Transportation Security Administration (over which Homeland Security has jurisdiction) already has official responsibility for security of pipeline operations. Not that the TSA has done much (nor have they been authorized to do much) about pipeline security beyond publishing security guidelines and conducting courtesy (without enforcement authority) inspections.

There is also likely to be opposition from the Transportation and Infrastructure Committee since that Committee has jurisdiction over the DOT’s Pipeline and Hazardous Material Safety Administration’s oversight of the safe operations of the pipelines covered in this bill. Many of the provisions of this bill directly impact safe operations as well as secure operations.

These intra-party conflicts between committee chairs will probably prevent this bill from reaching the floor of the House.

Commentary


This is another apple pie and motherhood bill that ‘shows’ that Congress is taking pipeline security (specifically including cybersecurity) seriously without allowing the executive branch to issue any regulations that would require industry to comply. It would eventually allow industry to work with DOE in the establishment of the policies and procedures without having to worry about spending a penny more than they thought necessary for protecting their investments.

The other major problem with this bill is that there is no authorization of funds or personnel to carry out these objectives. While it may be possible to establish ‘policies and procedures’ with no additional funding (as long as you have no timetable to meet), the development of ‘advanced cybersecurity applications and technologies’ requires unique expertise and research funding. Anything that is done in this area (and work does need to be done) will come at the expense of other DOE programs.

Committee Hearings – Week of 03-11-18


Both the House and Senate will be in Washington this week. Budget hearings continue to be the big news with hearings starting to get down to the agency level. There is also one cybersecurity markup hearing scheduled.

Budget Hearings

Coast Guard, House, Subcommittee – Wednesday
TSA, House, Full Committee – Wednesday
DOT, House, Subcommittee – Thursday
DOE, House, Subcommittee – Thursday

I do not pay much attention to budget hearings. They are just the start of the appropriations process and it is the end game that provides specific funding for specific programs that really means something in the real world.

Cybersecurity Markup


On Wednesday the Energy Subcommittee of the House Energy and Commerce Committee will hold a markup hearing looking at four bills dealing with cybersecurity issues in the Department of Energy. The bills include:

HR 5174, Energy Emergency Leadership Act;
HR 5175, Pipeline and LNG Facility Cybersecurity Preparedness Act;
HR 5239, Cyber Sense; and
HR 5240, Enhancing Grid Security

All of these bills were introduced last week and I have not seen official copies on the Congress.gov web site, so I have not reviewed any of these bills in detail. The links provided above are to Committee drafts of the bills; I will start my reviews later today based upon these copies.

Wednesday, March 7, 2018

Bills Introduced – 03-06-18


Yesterday, with both the House and Senate in session, there were 29 bills introduced. Of those, two may be of specific interest to readers of this blog:

HR 5175 To require the Secretary of Energy to carry out a program relating to physical security and cybersecurity for pipelines and liquefied natural gas facilities. Rep. Upton, Fred [R-MI-6]

HR 5179 To direct the Secretary of Homeland Security to coordinate a National Cyber Hacking Competition for high school students, and for other purposes. Rep. Barragan, Nanette Diaz [D-CA-44]

HR 5175 will be controversial as it would seem to take the oversight for the security if these facilities out of the hands of TSA. Of course, TSA has done little about the security of these facilities and nothing in the form of mandated security requirements. It will be interesting to see exactly what authority is given to DOE by this bill.

I will be watching HR 5179 to see what definitions are used (particularly the definition of ‘cyber hacking’) to see if this would include control system hacking and what policies are put into place to encourage future coordinated disclosures on the part of students who continue on in the cybersecurity research realm.

 
/* Use this with templates/template-twocol.html */