Showing posts with label HR 5394. Show all posts
Showing posts with label HR 5394. Show all posts

Sunday, December 22, 2019

HR 5394 Introduced – Cybersecurity Coordination


Earlier this month Rep Taylor (R,TX) introduced HR 5394, the Strengthening State and Local Cybersecurity Defenses Act. The bill would amend 6 USC 659; adding a number of coordination, education and assistance responsibilities to the Cybersecurity and Infrastructure Security Agency (CISA) charter to provide cybersecurity support to a wide variety of public and private entities in the country.

Definitions


The bill would add a new definition to 6 USC 651; ‘entity’. This term would be very broadly defined as including {new §651(4)}:

• An association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;
• A government agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and
• The general public.

New CISA Coordination Responsibilities


The bill would add a new paragraph (n) to 6 USC 659, entitled ‘Coordination’. That paragraph would require CISA to coordinate (to the extent practicable) with Federal and non-Federal entities (specifically including the Multi-State Information Sharing and Analysis Center) to:

• Conduct exercises with Federal and non-Federal entities;
• Provide operational and technical cybersecurity training related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents to entities to address cybersecurity risks or incidents, with or without reimbursement;
• Assist entities, upon request, in sharing cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among entities, in order to increase situational awareness and help prevent incidents;
• Provide entities timely notifications containing specific incident and malware information that may affect such entities or individuals with respect to whom such entities have a relationship;
• Provide and periodically update via a web portal and other means tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security;
• Work with senior Federal and non-Federal officials, including State and local Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;
• Provide, upon request, operational and technical assistance to entities to implement tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion detection capability, to assist such entities in detecting cybersecurity risks and incidents;
• Assist entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;
• Ensure that entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security developed by the Department and other appropriate Federal entities for ensuring the security and resiliency of civilian information systems; and
• Promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.

Moving Forward


Taylor and four of his cosponsors {Ranking Member Rogers (R,AL), Green (D,TX), Guest (R,MS) and Slotkin (D,MI)} are members of the House Homeland Security Committee to which this bill was assigned for consideration. This bill will almost certainly be considered in Committee early next year. There is nothing in the language of the bill that would engender any significant opposition to the bill.

When the bill is considered (and it is likely to reach the floor) it will receive significant bipartisan support. When it is considered on the floor of the House it will be considered under the suspension of the rules process; limited debate, no floor amendments and will require a super-majority to pass.

Commentary


This is another one of the cybersecurity bills being considered this session that are purely motherhood and apple pie attempts by Congress to make it look like they are doing something about cybersecurity. There is nothing in the bill that CISA is not already doing or DHS has not been doing for quite some time before before the investiture of CISA.

If Taylor really wants this bill to accomplish something, he could straighten out the definitions in §659 that officially (though not actually in practice) limits CISA from looking at control system security, by excluding all but pure information technology systems from their purview. Again, I would refer Taylor, and the Committee Staff, to my blog post from February where I discuss the cybersecurity definition problem in detail and provide legislative language to correct those problems.

Thursday, December 12, 2019

Bills Introduced – 12-11-19


Yesterday with both the House and Senate in session there were 34 bills introduced. One of those bills may see further coverage in this blog:

HR 5394 To amend the Homeland Security Act of 2002 to require certain coordination between the Department of Homeland Security and Federal and non-Federal entities relating to cybersecurity risks and incidents, and for other purposes. Rep. Taylor, Van [R-TX-3] 

Wednesday, June 8, 2016

Bills Introduced – 06-07-16

With both the House and Senate in session there were 27 bills introduced yesterday. Of those five may be of specific interest to readers of this blog:

HR 5388 To amend the Homeland Security Act of 2002 to provide for innovative research and development, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 5389 To encourage engagement between the Department of Homeland Security and technology innovators, and for other purposes. Rep. Ratcliffe, John [R-TX-4]

HR 5390 To amend the Homeland Security Act of 2002 to authorize the Cybersecurity and Infrastructure Protection Agency of the Department of Homeland Security, and for other purposes. Rep. McCaul, Michael T. [R-TX-10]

HR 5393 Making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2017, and for other purposes. Rep. Culberson, John Abney [R-TX-7] 

HR 5394 Making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2017, and for other purposes. Rep. Diaz-Balart, Mario [R-FL-25]

The first three bills are those that I mentioned yesterday in my post about congressional hearings. The House Homeland Security Committee will be marking up these bills today. The text for the first two of these bills is currently available from the GPO. This means that I’ll be able to give a little more detail in this post on those bills.

HR 5388 would add a new section to the Homeland Security Act of 2002 authorizing the DHS S&T Directorate to support cybersecurity research and development. Unfortunately, the bill uses the limited definition of information system that does not include control systems so no control system specific security research would be supported. And, as is usual, there are no additional funds authorized for this new program so it effectively dilutes S&T research monies.

HR 5389 would authorize DHS to establish local coordination offices in areas of the country where there were concentrations of “innovative and emerging technology developers and firms” {§2(a)(1)} for the purposes of ‘engagement’ with such entities. Such engagement efforts (again without additional funding) would include {§2(b)(2)}:

• Ensure proven innovative and emerging technologies can be included in existing and future acquisition contracts;
• Coordinate with organizations that provide venture capital to businesses, particularly small businesses and startup ventures, as appropriate, to assist the commercialization of innovative and emerging technologies that are expected to be ready for commercialization in the near term and within 36 months; and
• Address barriers to the utilization of innovative and emerging technologies and the engagement of small businesses and startup ventures in the acquisition process.

HR 5390 is the bill authorizing the re-organization and re-naming of the DHS National Protection and Programs Directorate to emphasize its role in cybersecurity.

The last two bills are spending bills. I will be watching both of them for cybersecurity provisions in both the bills and committee reports. I will, of course, also be watching the transportation bill (and report) for chemical transportation safety and security provisions.

Commentary


It would be interesting to have the Congressional Budget Office do an analysis of how much bills like HR 5388 and HR 5389 reduce funding for current programs that will have money taken from them to support the new programs outlined in these bills.

Now, I fully support keeping federal spending under control, but Congress has gotten really stupid in the way that they authorize new programs without providing any additional funding for them. The money is going to have to come from somewhere and their failure to designate where it will come from means that the public will probably never know what tradeoffs are being made to support these new efforts.


I really suspect that these bills are more political theater than actual efforts to accomplish anything.
 
/* Use this with templates/template-twocol.html */