Showing posts with label HR 5459. Show all posts
Showing posts with label HR 5459. Show all posts

Monday, September 26, 2016

House Passes HR 5459 - Cyber Preparedness Act of 2015

This afternoon the House passed HR 5459, the Cyber Preparedness Act of 2015 by a voice vote after only ten minutes of debate under the House suspension of the rules process. The bill makes minor revisions to the Homeland Security Act of 2002 to enhance cybersecurity information sharing and makes enhancing cybersecurity an allowable use of DHS grants under the Urban Area Security Initiative and State Homeland Security Grant Program.

As I have noted in earlier blog posts, this bill continues to use an IT-limited definition of ‘cybersecurity risk’ that does not include industrial control systems. That does not mean that DHS cannot share ICS cybersecurity risk information with fusion centers, it is just not required to share that information.

If this bill is taken up by the Senate (not guaranteed by any stretch of the imagination this late in the session in an election year) it will probably be considered (and passed) under their ‘unanimous consent’ process that does not provide any opportunity for amendments on the floor.

Sunday, September 18, 2016

HR 5459 Amended in Committee

Earlier this week the House Homeland Security Committee amended and approved HR 5459, the Cyber Preparedness Act of 2015. The amendment made a number of relatively minor changes to the requirements for sharing cybersecurity information with fusion centers. The most important change was to add a definition of ‘cybersecurity risk’, adopting the language of 6 USC 148(a)(1). As I noted earlier, this definition does not include control systems.

Unfortunately, the way that that definition was added to the bill does not extend that definition to the expansion of authorized expenditures for grants under the Urban Area Security Initiative and State Homeland Security Grant Program. This may be less important than the addition of the definition earlier in the bill because DHS has a certain amount of leeway in how they disperse grants under these programs.


This bill is currently scheduled for consideration under suspension of the rules this Wednesday. It will likely pass with substantial bipartisan support. The big question facing this bill is whether or not it will be taken up by the Senate. This late in the session, it is likely that the only way this bill would come to the floor would be through the unanimous consent process. That would mean that there would be no further chances to amend this bill before it is sent to the President.

Monday, September 12, 2016

Congressional Hearings – Week of 9-11-16

This week with both the House and Senate in town there will be two cybersecurity related hearings that may be of specific interest to readers of this blog. Those two hearings address information sharing and encryption.

Cybersecurity Markup


On Tuesday the House Homeland Security Committee will be holding a markup hearing that will cover a number of bills. Of specific interest will be HR 5459, Cyber Preparedness Act of 2016. Substitute language for that bill will be considered. That substitute does include the ‘missing’ definition of ‘cybersecurity risk’ taking it from 6 USC 148(a)(1). Unfortunately, that definition still uses the limited definition of ‘information system’ from 44 USC 3502(8). Thus there is still not authority provided for sharing information about control system security issues.

Encryption


The Senate Armed Services Committee will be holding a hearing on Tuesday looking at Encryption and Cyber Matters. There may be a closed session at the end of the public portion of the hearing. The witness list includes:

• Marcell J. Lettre II, Under Secretary Of Defense For Intelligence; and
• Michael S. Rogers, United States Cyber Command

On the Floor

There is one cyber related bill that will be taken up in the House today under their suspension of the rules process. House Resolution 847 addresses the perceived need for a national strategy for the Internet of Things to promote economic growth and consumer empowerment. This resolution was introduced last week, but I have not posted a review because it does not include a single mention of cybersecurity concerns. Since today’s consideration will not include an amendment process the resolution will be published without this critical area being considered. Fortunately, nothing more will come from this action, this only being a symbolic resolution.


There are news reports (for example) that we could see a continuing resolution coming out of the Senate this week. There will be lots of political gaming going on in the lead up to the Senate vote and the subsequent House vote (if it passes in the Senate).

Wednesday, July 6, 2016

HR 5459 Introduced – Cybersecurity Information Sharing

Last month Rep. Donovan (R,NY) introduced HR 5459, the Cyber Preparedness Act of 2016 [Note: there is currently something wrong with this link at the GPO, alternative text of bill here]. The bill makes minor revisions to the Homeland Security Act of 2002 to enhance cybersecurity information sharing.

Fusion Centers and NCCIC


Section 2(1) of the bill would add ‘cybersecurity risk information’ to the list of types of information designated in 6 USC 124h(b)(6) and (b)(8) to be shared with fusion centers by DHS. Additionally, the same ‘cybersecurity risk information’ would be added to the list of types of information in §124h(d)(1) for which DHS would be required to “assist law enforcement agencies and other emergency response providers of State, local, and tribal governments and fusion center personnel in using information within the scope of the information sharing environment”.

Section 2(2) of the bill would amend 6 USC 148 addressing the information sharing responsibilities of the National Cybersecurity and Communications Integration Center (NCCIC). It would add fusion centers to the information sharing requirements of §148(c)(5)(B).

Grants


Section 3 of the bill would amend 6 USC 609 by adding “enhancing cybersecurity, including preparing for and responding to cybersecurity risks and incidents” to the list of permitted uses at §609(a) for which grants under the Urban Area Security Initiative or State Homeland Security Grant Program can be used.

As is fairly typical no additional funding is provided for either grant program.

Moving Forward


Donovan and all three of his cosponsors {McCaul (R,TX), Ratcliffe (R,TX), and Payne (D,NJ)} are influential members of the House Homeland Security Committee. That means that this bill has a good chance of moving forward through the committee review process. In fact, shortly after the bill was introduced, it was approved without amendments by the Emergency Preparedness, Response, and Communications Subcommittee.

There is nothing in this bill that would draw any sort or organized opposition. If the bill makes it to the floor of the House it would almost certainly be approved under the suspension of the rules procedure. The only question is if there is enough interest in the bill to get it to the floor of the House for consideration in the limited time remaining in the session.

Commentary


This is the type of ‘i-dotting and t-crossing’ legislative work that needs to take place to ensure that everyone has the appropriate authority to carry out legislative mandates that have been previously passed. Unfortunately, in this case, problems with the underlying definitions that are critical to the intent of the legislation are not addressed.

In this case we go back to the problem of the definition of ‘cybersecurity risk’. There is no definition of the term in §124h, so we are still left with the lack of any real authority to share cybersecurity risk information within the fusion center environment. In §148 we do have a definition {§148(a)(1)}, but it is one of those definitions that narrowly defines the term just with respect to IT systems. So again, we technically have no authority for the NCCIC to share information about cybersecurity risks that apply uniquely to industrial control systems.


Finally, as I have mentioned numerous times, expanding the allowable uses of federal grant monies is all well and good as long as the amount of available funding is already increased. In cases like the one here in this bill where that money pool is not enlarged, the expansion of the allowable uses has the direct effect of decreasing the money available to the existing list of potential grant uses. This means that grants will either be smaller (and less useful) or fewer grants for exiting programs will be approved. Either may be a perfectly legitimate outcome, but there is no discussion of those consequences when bills like this are discussed.

Tuesday, June 14, 2016

Bills Introduced – 06-13-16

Yesterday with both the House and Senate in session there were 16 bills introduced. Of these, only one may be of specific interest to readers of this blog:

HR 5459 To amend the Homeland Security Act of 2002 to enhance preparedness and response capabilities for cyber attacks, bolster the dissemination of homeland security information related to cyber threats, and for other purposes. Rep. Donovan, Daniel M., Jr. [R-NY-11]


Cybersecurity bills continue to proliferate. It will be interesting to see what this one adds to the information sharing universe.
 
/* Use this with templates/template-twocol.html */