Showing posts with label HR 5515. Show all posts
Showing posts with label HR 5515. Show all posts

Tuesday, March 26, 2019

S 734 Introduced – IOT Cybersecurity


Earlier this month Sen. Warner (D,VA) introduced S 734, the Internet of Things (IoT) Cybersecurity Improvement Act of 2019. Warner introduced a similarly titled bill last session (S 1691), but this bill is a complete re-write of the earlier effort.

Definitions


While last session’s bill had a long series of complicated definitions, this new bill only defines three terms: ‘agency’, ‘covered device’ and ‘security vulnerability’. The ‘agency’ definition is a proforma, yet necessary definition that is of little real importance. The definition of ‘covered device’ is new to this bill and replaces the term ‘internet-connected device’ from the earlier bill. The new term is defined as a physical object that {§2(2)(A)}:

• Is capable of connecting to and is in regular connection with the Internet;
• Has computer processing capabilities that can collect, send, or receive data; and
Is not a general-purpose computing device, including personal computing systems, smart mobile communications devices, programmable logic controls, and mainframe computing systems.

Sharp-eyed readers will note that this definition was taken from an amendment to HR 5515 last session that was proposed by Sen. Gardner (R,CO); one of the cosponsors to this bill.

Interestingly the definition of a covered device goes on to provide a requirement that the Office of Management and Budget (OMB) establish a process by which interested parties can petition to have a “a device that is not described in subparagraph (A) to be considered a device that is not a covered device” {§2(2)(B)(i)}.

The term ‘security vulnerability is defined as “any attribute of hardware, firmware, software, or combination of 2 or more of these factors that could enable the compromise of the confidentiality, integrity, or availability of an information system or its information or physical devices to which it is connected” {§(2)(3)}.

NIST Requirements


Section 3 of the bill requires the National Institute of Standards and Technology (NIST) to complete current efforts “regarding considerations for managing Internet of Things cybersecurity risks” {§3(a)(1)} to be completed by September 30th, 2019. Those considerations are to include, at a minimum {§3(a)(2)}:

• Secure Development;
• Identity management;
• Patching; and
• Configuration management.

By March 1st, 2020, NIST would be required to “develop recommendations for the Federal Government on the appropriate use and management by the Federal Government of Internet of Things devices owned or controlled by the Federal Government, including minimum information security requirements” {§3(b)(1)}.

Finally, NIST would be required within 180 days of the passage of this bill to publish a draft report on “the increasing convergence of traditional Information Technology devices, networks, and systems with Internet of Things devices, networks and systems and Operational Technology devices, networks and systems, including considerations for managing cybersecurity risks associated with such trends” {§(3)(c)}

OMB Requirements


Section 4 of the bill outlines the requirements for OMB to address IoT cybersecurity in the Federal Acquisition Regulations (FAR). Within 180 days of NIST’s publication of recommendations on the use of IoT devices, the OMB would be required to “issue guidelines for each agency that are consistent with such recommendations” {§4(a)}. Those guidelines would have to be consistent with the information security requirements of 44 USC Chapter 35, Subchapter II.

OMB and NIST would also be required to undertake reviews of the recommendations and guidelines described in this bill every five years.

Coordinated Disclosure Policy


Section 5 of the bill would establish NIST as the organization responsible for establishing policies and procedures for “for the reporting, coordinating, publishing, and receiving of information about” {§5(a)} security vulnerabilities of covered devices and their resolution. Those policies and procedures would be aligned as much as practicable with ISO 29147 and ISO 30111.

Section 6 of the bill would require OMB to issue guidelines to federal agencies on how to comply with the processes established by NIST.

Moving Forward


While Warner is not on the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration, one of his three cosponsors, Sen. Hassan (D,NH) is. This means that it is reasonable to assume that the bill may received consideration in that Committee. The main holdup is that the Chair, Sen. Johnson (R,WI), has deep-seated concerns about adding anything smacking of regulations concerning cybersecurity. While this bill does not specifically call for cybersecurity regulations, the ‘policies, procedures and guidelines’ that vendors selling covered devices to the government would be required to follow have the same general impact as regulations.

I would not be surprised if this bill did not make it out of Committee. One way that Johnson could ensure this is that after a markup hearing was held, the Committee report on the bill could be delayed indefinitely.

Commentary


This new version of the IoT cybersecurity bill is much better written than the version introduced in the last session. The limitations on the definition of ‘covered device’ generally make a reasonable distinction between ‘internet connected devices’ and IoT. I do, however, still have some nits to pick on the details of how that limitation/distinction is made.

The sub-paragraph in question removes ‘general-purpose computing devices’ from consideration as ‘covered devices’. It then lists the following examples of those g-p devices:

• Personal computing systems;
• Smart mobile communications devices;
• Programmable logic controls; and
Mainframe computing systems

Since none of these exclusionary terms are defined in the bill, I would suspect that the staffers who crafted this bill wanted to provide NIST and OMB with significant latitude in what would be included in the exclusion from the definition of IoT. Generally speaking, that is a good thing. Having said that, I do have problems with the term ‘programmable logic controls’. First off, I need to get a tad bit anal retentive here; the term should be ‘programmable logic controllers’.

In a broader context, even that corrected term may be an unnecessarily restrictive substitute for the term ‘industrial control system’. While PLCs are certainly very common components of industrial control system, there are a large number of other components of those systems that are not generally considered IoT (or IIoT, industrial internet of things), but could not be reasonably included in the term PLC.

While I am a strong believer in cybersecurity in industrial control system, I do not think that this bill and its loose regulatory framework are the appropriate place to establish standards for ICS cybersecurity and particularly the internet connected devices associated with industrial control systems. With that in mind, I would propose that the term ‘industrial control system’ should be substituted for the term ‘programmable logic controls’ in the definition of ‘covered device’.

Thursday, July 26, 2018

Rule to Consider Conference Report for HR 5515 – FY 2019 NDA


Last night the House Rules Committee crafted the rule for the consideration of the Conference Report on HR 5515. As is typical with conference reports, there will be limited debate and no amendments will be offered. This should come to the floor today.

We still do not have an official copy of the 2500+ page report. A quick review of the table of contents (which is 36 pages by itself) of the copy the Rules Committee has on their site shows that most of the cyber related provisions of both the House and Senate versions have made it into the final version of the bill. A more detailed analysis will take some time.

Monday, July 23, 2018

Committee Hearings – Week of 07-22-18


This week with both the House and Senate in session but the House preparing to head home for the LONG summer recess, there is a slightly abbreviated hearing schedule. There are only two hearings of interest, the ‘last’ spending bill and a homeland security markup hearing.

DHS Spending Bill


On Wednesday the House Appropriations Committee will markup the FY 2019 DHS spending bill. The Homeland Security Subcommittee finished their work last week. The draft the Committee is working on does not include language for a short-term extension of the CFATS program, but does continue funding for the program through FY 2019,

Homeland Security Markup


Tomorrow the House Homeland Security Committee will hold a markup hearing on 12 bills and one resolution. These will include the following bills of potential interest to readers of this blog:

HR 6443, the Advancing Cybersecurity Diagnostics and Mitigation Act; and
HR 6438, the DHS Countering Unmanned Aircraft Systems Coordinator Act.

I have not yet reviewed either of the above bills as the official versions have yet to be published. I will look at the Committee Drafts (linked above) later today and comment as necessary. Interestingly HR 6401, Chairman McCaul’s counter UAV bill is not on the list for consideration tomorrow. That bill was published this weekend and at first glance looks very similar to S 2836, Chairman Johnson’s senate bill. More on that later.

On the Floor


Starting late today the Senate will take up HR 6147, the FY 2019 Interior, Environment and Related Agencies (IER) spending bill. There is at least one news report that there is a chance that the Senate may add the THUD spending (S 3023) to the already expanded mix of HR 6147. That might cause problems for the House since they have not yet dealt with the House version of that spending measure (HR 6072) and the membership has not had their chance to muddy the legislative waters with floor amendments. It is going to be an interesting summer.

There is a chance that the House will have a chance late this week to vote on the conference version of HR 5515, the FY 2019 DOD authorization bill. Other than that, there is nothing on the calendar of specific interest for the last week before vacation in the House.

WARNING: With the long vacation coming up there will be a large number of bills offered in the House this week so that members have something to talk about while they are in their districts during the coming weeks. A larger percentage than normal will not see the light of legislative day, but they will get talked about.

Tuesday, June 19, 2018

Senate Passes HR 5515 – FY 2019 NDAA


Yesterday the Senate passed HR 5515, the FY 2019 National Defense Authorization Act (NDAA) by a bipartisan vote of 85 to 10. An earlier attempt (pg S3972) to adopt 47 additional amendments en bloc was blocked by Sen. Paul (R,KY) because the Senate would not consider his amendment on indefinite detention of American citizens (SA 2574, pg S3389). Presumably this list of amendments contained most of the block that was offered last week.

There is an outside chance that the House will accept the revised language that the Senate just passed. Much more likely is that the House will demand that its language stand and the bill will be sent to a conference committee to work out the differences.

Saturday, June 16, 2018

Senate Debates HR 5515 – FY 2019 NDAA

After a week of consideration of HR 5515 (with lots of talking and over 300 new amendments proposed), the Senate finally started taking concrete action on Thursday as they were preparing to leave for the weekend. Four recorded votes were taken, three amendments were agreed to, and final consideration of the bill is set for Monday. Thursday’s votes include:

• SA 2700 Cloture (35 to 62)
• SA 2282 Cloture (83 to 14)
• SA 2885 (97 to 0),
• SA 2276 (voice vote),
• SA 2282 (voice vote)
HR 5515 Cloture (81 to 15)

Amendments


Amendment 2282 (pgs S3042-S3223) is the substitute language for HR 5515 that basically comes from S 2987 and specifically includes the cybersecurity provisions that I discussed in that bill. Neither of the other two amendments adopted would be of specific concern to readers of this blog. Amendment 2285 (pg S3916) would establish the John S. McCain Strategic Defense Fellows Program and SA 2276 (pg S3041) would require a report on permanent stationing of United States forces in the Republic of Poland.

Earlier in the day Sen. Lee (R,UT) attempted (pg S3940) to have the Senate consider a bloc of 45 amendments. That block included three that might be of specific interest to readers of this blog:


SA 2509. Sen. Manchin (D,WV) – Report on cyber forces of the reserve components of the armed forces and cyberspace. [Pg S3360]
SA 2721. Sen. Shaheen (D,NH) – Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity. [S3704]
SA 2887. Sen. Sasse (R,NE) – Study on cyber exploitation of members of the armed forces and their families. [S3917-8]

Lee’s request to consider the amendments required unanimous consent and was blocked by Sen. Graham (R,SC) who objected to the language in one of the amendments offered by Sen. Cruz (R,TX). No attempt was made by Lee to retry the en bloc consideration of all but the Cruz amendment.

Moving Forward


The Senate is currently scheduled to finish consideration of HR 5515 on Monday. There is a good chance that additional amendments will be considered individually and in blocks. The Senate will pass the bill with some level of bipartisan support. The differences between the Senate and House versions of the bill will then have to be worked out in conference committee.

Sunday, June 10, 2018

Senate Begins Consideration of HR 5515 – FY 2019 NDAA


Last week the Senate began debating the consideration of HR 5515. By the end of the week the Senate had passed a cloture vote to close that debate and will vote on Monday to begin actual deliberations of the bill. As I noted in an earlier blog post today, the Senate will start off by adopting SA 2282, the Senate’s substitute language taken from S 2987.

While the preliminaries to the actual debate have been taking up legislative time, Senator’s have been filing over 300 proposed amendments to the bill, over and above the substitute language mentioned above. Of those amendments there are 16 that may be of specific interest to readers of this blog:

SA 2285. Mr. WARNER - SEC. 1107. Department of Defense Cyber Scholarship Program [Pg S3224]
SA 2286. Mrs. FISCHER SEC. XXX. Developing Innovation and Growing the Internet of Things. [Pg S3224]
SA 2314. Mr. JOHNSON – SEC. XXX. Preventing Emerging Threats (Unmanned Aircraft) [Pg S3237]
SA 2369. Mr. HOEVEN - SEC. 1066. Sense of Senate on Management of Unmanned Aircraft Systems Traffic Within the National Airspace System. [Pg S3262]
SA 2376. Mr. PERDUE - SEC. XXX. UNITED STATES CYBER STRATEGY. [Pg S3303]
SA 2380. Mr. PERDUE - SEC. XXX. BRIEFING ON CYBER EDUCATION AND TRAINING. [Pg S3306]
SA 2384. Mr. HEINRICH - SEC. 1636A. APPOINTMENT OF CYBERSECURITY COORDINATOR. [Pg S3308]
SA 2436. Ms. COLLINS - SEC. XXX. REPORT ON STRENGTHENING NATO CYBER DEFENSE. [Pg S3337]
SA 2458. Mr. WHITEHOUSE - SEC. 1066. UNSAFE OPERATION OF UNMANNED AIRCRAFT. [Pg S3345]
SA 2474. Mr. SCHATZ - SEC. 896. INTEGRATED PUBLIC ALERT AND WARNING SYSTEM. [Pg S3353]
SA 2483. Mr. WYDEN - SEC. XXX. FUNDING FOR NSF CYBER SCHOLARSHIP-FOR-SERVICE PROGRAM. [Pg S3355]
SA 2484. Mr. WYDEN - SEC. XXX. FUNDING FOR NSF CYBER SCHOLARSHIP-FOR-SERVICE PROGRAM. [Pg S3355]
SA 2509. Mr. MANCHIN - SEC. XXX. REPORT ON CYBER FORCES OF THE RESERVE COMPONENTS OF THE ARMED FORCES AND CYBERSPACE. [Pg S3360]
SA 2547. Mrs. SHAHEEN - SEC. 1626. ASSISTANCE FOR SMALL MANUFACTURERS IN THE DEFENSE INDUSTRIAL SUPPLY CHAIN ON MATTERS RELATING TO CYBERSECURITY. [Pg S3373]
SA 2564. Mr. RUBIO SEC. XXX. PILOT PROGRAM TO TEST MACHINE-VISION TECHNOLOGIES TO DETERMINE THE AUTHENTICITY AND SECURITY OF MICROELECTRONIC PARTS IN WEAPON SYSTEMS. [Pg S3380]
SA 2567. Mr. WARNER - Subtitle G—Internet of Things Cybersecurity Improvement Act [Pg S3382]

Needless to say, very few of these amendments will make it to the floor of the Senate for consideration. And, as the consideration of the bill continues, there will be more amendments offered right up to the final cloture vote leads to a final floor vote on the bill. Given the large disparity between the number of amendments offered and those that actually get approved; I will hold off on analysis of the amendments until they are adopted.

S 2987 Introduced – FY 2019 NDAA


Last week Sen. Inhofe (R,OK) introduced S 2987, the John S. McCain National Defense Authorization Act for Fiscal Year 2019. The bill contains one subtitle (Subtitle C of Title XVI) that specifically address cyber matters including cybersecurity for industrial control systems (ICS).

Subtitle C


Part 1 of Subtitle C deals with general cyber matters. The sections include:

§ 1621. Policy of the United States on cyberspace, cybersecurity, cyber warfare,
and cyber deterrence.
§1622. Affirming the authority of the Secretary of Defense to conduct military
activities and operations in cyberspace.
§1623. Active defense and surveillance against Russian Federation attacks
in cyberspace.
§1624. Reorganization and consolidation of certain cyber provisions.
§1625. Designation of official for matters relating to integrating cybersecurity and industrial control systems within the Department of Defense.
§1626. Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity.
§1627. Modification of acquisition authority of the Commander of the United States Cyber Command.
§1628. Email and Internet website security and authentication.
§1629. Matters pertaining to the Sharkseer cybersecurity program.
§1630. Pilot program on modeling and simulation in support of military homeland defense operations in connection with cyber attacks on critical infrastructure.
§1631. Security product integration framework.
§1632. Report on enhancement of software security for critical systems.
§1633. Comply to connect and cybersecurity scorecard.
§1634. Cyberspace Solarium Commission.
§1635. Program to establish cyber institutes at institutions of higher learning.
§1636. Establishment of Cybersecurity for Defense Industrial Base Manufacturing

Part II of Subtitle C deals with the mitigation of risks posed by providers of information technology with obligations to foreign governments. This part uses an unusual definition of ‘information technology’ from 40 USC 11101 that specifically includes “imaging peripherals, input, output, and storage devices necessary for security and surveillance” {§11101(6)(B)}. The part also specifically refers to ‘industrial control system’ without providing a definition of the term.

The sections in Part II include:

§1637. Definitions.
§1638. Identification of countries of concern regarding cybersecurity.
§1639. Mitigation of risks to national security posed by providers of information technology products and services who have obligations to foreign governments.
§1640. Establishment of registry of disclosures.

ICS Cybersecurity


Section 1625 (on pgs 731-2) requires DOD to designate one official “to be responsible for matters relating to integrating cybersecurity and industrial control systems within the Department of Defense” {§1625(a)}. That official would be responsible for all ICS cybersecurity matters for all levels of command down to the “facility using industrial control systems, including developing Department-wide certification standards for integration of industrial control systems” {§1625(b)}.

Section l636 (on pgs 769-70) requires DOD “establish an activity to assess and strengthen the cybersecurity resiliency of the defense industrial base of the United States” {§1636(a)(1)}. It would be known as the ‘Cybersecurity for Defense Industrial Base Manufacturing Activity’. The purpose of the Activity would be “to explore ways to increase the
 cybersecurity resilience of the defense industrial supply chain” {§1636(b)} to include:

• Developing cybersecurity test capabilities to support identifying and reducing security vulnerabilities in defense industrial base manufacturing processes.
• Developing in-person and online training to help small defense industrial base manufacturers improve their cybersecurity.
• Ensuring that cybersecurity for defense industrial base manufacturing is included in Department of Defense research and development roadmaps and threat assessments.
Aggregating, developing, and disseminating capabilities to address cybersecurity threats that can be provided to and adopted by defense industrial base manufacturers of all sizes.

The definition of ‘security vulnerability’ used by this section relies on the ICS-inclusive definition of ‘information system’ found in 6 USC 1501.

Foreign Government Influence


Section 1638 would require DOD to produce a “prioritized list of countries of concern regarding cybersecurity" {§1638(a)} based upon:

• A foreign government’s engagement in acts of violence against personnel of the United States or coalition forces.
• A foreign government’s willingness and record of providing financing, logistics, training or intelligence to other persons, countries or entities posing a force protection or cybersecurity risk to the personnel, financial systems, critical infrastructure, or information systems of the United States or coalition forces.
• A foreign government’s engagement in foreign intelligence activities against the United States.
• A foreign government’s direct or indirect participation in transnational organized crime or criminal activity.
A foreign government’s ability and intent to conduct operations to affect the supply chain of the United States Government.

Section 1639 would prohibit DOD from using any “product, service, or system relating to information or operational technology, cybersecurity, an industrial control system, a weapons system, or computer antivirus” {§1639(a)} unless the provider discloses whether the provider has allowed:

A foreign government to review or access the code of a product, system, or service custom-developed for the Department, or is under any obligation to allow a foreign person or government to review or access the code of a product, system, or service custom-developed for the Department as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government.

A foreign government listed in section 1638(a) to review or access the source code of a product, system, or service that the Department is using or intends to use, or is under any obligation to allow a foreign person or government to review or access the source code of a product, system, or service that the Department is using or intends to use as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government.

DOD would have to evaluate if any of the disclosure required above would reveal “a risk to the national security infrastructure or data of the United States, or any national security system under the control of the Department” {§1636(c)(1)}. If such a risk were present DOD would be required to determine what actions would be necessary to mitigate such risks.

Moving Forward


This bill will not be considered on the floor of the Senate. It was offered as amendment SA 2282 as substitute language to HR 5515 that is currently being considered in the Senate. The S 2987 language was adopted in Committee by a strongly bipartisan vote of 25 to 2. This means that the base language will be relatively easy to bring to the floor of the Senate. In fact, the first cloture vote on HR 5515 was agreed to on a vote of 92 to 4 on Thursday. The Senate will begin actual consideration of HR 5515 on Monday.

Saturday, May 26, 2018

House Passes HR 5515 – FY 2019 NDAA


On Thursday the House passed HR 5515, the FY 2019 National Defense Authorization Act (NDAA) by a bipartisan vote of 351-66 (7 Republicans voted Nay). On Wednesday the House passed the Coast Guard Authorization Act amendment (amendment #52) to the bill as part of en bloc amendment #1 by a voice vote.

The Senate Armed Services Committee completed work on their version of the NDAA this week and will have a bill to introduce the week after next when Congress returns from its extended Memorial Day Weekend. That bill will move to the Senate floor in the coming weeks for a contentious amendment process. Once it is passed (probably before the summer recess) it will go to a conference committee to work out the differences. Both of the amendments that I have covered here will likely make it into the final bill.

Wednesday, May 23, 2018

HR 5515 Debate in House


Yesterday the House began their debate on HR 5515, the National Defense Authorization Act for FY 2019. The initial rule for the consideration of HR 5515 made 103 of the 564 proposed amendments in order for consideration.

Of the nine amendments that I had identified as being of potential interest here, only one made the short list; #189 submitted by Rep. Jackson-Lee (D,TX) regarding cybersecurity apprenticeships. That amendment was adopted as part of en block amendment #6 at the close of debate last night.

Apprenticeship Amendment


The Jackson-Lee amendment would require DOD to submit a “report on the feasibility of establishing a Cybersecurity Apprentice Program to support on-the-job training for certain cybersecurity positions and facilitate the acquisition of cybersecurity certifications.” The amendment does not define the term ‘certain cybersecurity positions’ nor does it explicate the certifications to be considered.

Today’s Debate


The debate will resume today under the provisions of a second rule. Under that rule an additional 168 amendments from the list of 564 submitted will be allowed to be proposed on the floor. Only one more of the amendments that I previously identified made it to the second short list; amendment # 357, the Coast Guard Authorization Act of 2017. It will be debated as amendment # 52.

CG Authorization


While this amendment is entitled “the Coast Guard Authorization Act of 2017” it does not look anything like HR 2518 or S 1129 with the same title. Neither of those bills contained any language of particular interest here. This amendment does, however, contain language of potential interest to readers of this blog; these two sections in particular:

§319. Protecting against unmanned aircraft (pg 93);
§602. Maritime Security Advisory Committees (pg 200);

Section 319 would add a new §528 to 14 USC. That section would authorize DHS to take actions to mitigate the threat “that an unmanned air craft system or unmanned aircraft poses to the safety or security of a covered vessel or aircraft” {new §528(a)} with exceptions to current law (18 USC 32, 18 USC 1030, 18 USC 2510–2522, 18 USC 3121–3127, and 49 USC 46502) being provided to allow such actions. The allowed actions would specifically include {new §528(c)}:

• Detect, identify, monitor, and track the unmanned aircraft system or unmanned aircraft, without prior consent, including by means of intercept or other access of a wire, oral, or electronic communication used to control the unmanned aircraft system or unmanned aircraft;
• Warn the operator of the unmanned aircraft system or unmanned aircraft, including by passive or active, and direct or indirect physical, electronic, radio, and electromagnetic means;
• Disrupt control of the unmanned aircraft system or unmanned aircraft, without prior consent, including by disabling the unmanned aircraft system or unmanned aircraft by intercepting, interfering, or causing interference with wire, oral, electronic, or radio communications used to control the unmanned aircraft system or unmanned aircraft;
• Seize or exercise control of the unmanned aircraft system or unmanned aircraft;
• Seize or otherwise confiscate the unmanned aircraft system or unmanned aircraft; or
Use reasonable force to disable, damage, or destroy the unmanned aircraft system or unmanned aircraft.

The definition of ‘covered vessel or aircraft’ is somewhat limited and regulations implementing this section will be required.

Section 602 is a complete re-write of 49 USC 70112. It looks, however, as if the rewrite was done to make the section easier to read with less bouncing back and forth between information about the National Maritime Security Advisory Committee and Area Maritime Security Advisory Committees.

Moving Forward


The debate on HR 5515 resumes today and will probably finish today. I suspect that amendment #52 will be adopted.

Again, the Senate will take up its own version of the bill which is being marked up this week. A conference committee with then work out the differences between the two bills. There is a decent chance that this process could be completed before the summer recess.

Sunday, May 20, 2018

HR 5515 Reported in House – FY 2019 NDAA

Earlier this month Rep. Thornberry (R,TX) introduced HR 5515, the National Defense Authorization Act for FY 2019. The bill has been marked-up by the House Armed Services Committee and its subcommittees and the Committee Report on the bill has been published. As is to be expected, the bill contains a number of cyber provisions, some of which may be of specific interest to members of the cybersecurity community.

The major cyber provisions in the bill are found in Subtitle C of Title XVI. They include:

• §1631. Amendments to pilot program regarding cyber vulnerabilities of Department of Defense critical infrastructure.
• §1632. Budget display for cyber vulnerability evaluations and mitigation activities for major weapon systems of the Department of Defense.
• §1633. Transfer of responsibility for the Department of Defense Information Network to United States Cyber Command.
• §1634. Pilot program authority to enhance cybersecurity and resiliency of critical infrastructure. (pg 754)
• §1635. Pilot program on regional cyber security training center for the Army National Guard. (pg 756)
• §1636. Procedures and reporting requirement on cybersecurity breaches and loss of personally identifiable information.
• §1637. Cyber institutes at the senior military colleges.
• §1638. Study and report on reserve component cyber civil support teams. (pg 763)

Cybersecurity Provisions


Three of the sections mentioned above may be of interest to the cybersecurity community.

Section 1634 would authorize DOD to detail up to 50 cybersecurity technical personnel to assist DHS. While the DOD assistance is specifically targeted at supplementing the operations of the National Cybersecurity and Communications Integration Center (NCCIC), the support authority would extend to other DHS operations as well. This authority is for a ‘pilot program’ that would expire on September 30th, 2020.

Section 1635 would authorize the Department of the Army to establish a pilot training center for National Guard cyber protection teams and cyber network defense teams. The goal would be to establish common training standards to allow these teams to defend {§1635(c)(1)(A)}:

• The information network of the Department of Defense in a State environment;
• While acting under title 10, United States Code, the information networks of State governments; and
• Critical infrastructure.

The pilot program would include activities that would {§1635(d)}:

• Provide joint education and training and accelerating training certifications for working in a cyber range;
• Integrate education and training between the National Guard, law enforcement, and emergency medical and fire first responders;
• Provide a program to continuously train the cyber network defense teams to not only defend the information network of the DOD, but to also provide education and training on how to use defense capabilities of the team in a State environment; and
• Develop curriculum and educating the National Guard on the different missions carried out under titles 10 and 32, United States Code, in order to enhance interagency coordination and create a common operating picture.

Section 1638 would require DOD to conduct a study “on the feasibility, advisability, and necessity of the establishment of reserve component cyber civil support teams for each State” {§1638(a)}. The section provides a comprehensive list of requirements for the study that specifically includes {§1638(b)}:

• An examination of the potential ability of the teams referred to in such subsection to respond to an attack, natural disaster, or other large-scale incident affecting computer networks, electronics, or cyber capabilities;
• An analysis of State and local civilian and private sector cyber response capabilities and services, including an identification of any gaps in such capabilities and services; and
• Any effects on the privacy and civil liberties of United States persons that may result from the establishment of such teams.

The study would also be required to look at how the establishment of such teams would affect the operations DOD cyber mission forces and DHS cyber incident response activities.

Moving Forward


As I reported last week, the House Rules Committee announced that they were taking potential amendments to HR 5515. Those amendments were supposed to have been submitted by last Thursday. The Committee web site lists 564 amendments that have been submitted. Some of the amendments that may be of interest include:

55
Requires the Secretary of Defense to provide Congress a report on malicious cyber activities against the DOD systems within the past 24 months by the Russian Federation
78
Establishes the DOD Cyber Institute to serve as the principal Department entity for facilitating cyber cooperation between the Department and outside entities, including industry, academia, and other government organizations.
179
Directs the Secretary of Defense to develop plans for early detection, mitigation, and defense against state sponsored cyberattacks targeting federal public election assets, election administrators, election workers, or voter engagement efforts.
189
Seeks a report on the feasibility of the DOD developing a cybersecurity apprentice program that provides on the job training for certain cybersecurity positions and in support of acquisition of cybersecurity certifications.
337
Contains the Coast Guard Authorization Act of 2017
405
Directs the Secretary of Defense, in consultation with the Hollings Manufacturing Extension Partnership (MEP) and the Office of Small Business Programs, to establish a pilot program to extend the sharing of cyber threat information to contractors, including small and medium-sized manufacturers, who otherwise do not have appropriate security clearance
436
Prohibits the use of funds for cyber collaborations with China and Russia.
558
Late Supports state-led efforts to enhance cybersecurity by establishing a 5-year pilot program of National Guard cyber civil support teams in 10 states.
563
Late Amendment directs Secretary of Defense to develop effective countermeasures for cyber weapons developed for offensive purposes.

The Rules Committee will meet on Monday to set the general debate rule for this bill and then again on Tuesday to determine what amendments will be authorized to be considered on the floor of the House. The House will take up the bill this week and will almost certainly pass it with some level of bipartisan support.

The Senate Armed Services Committee will finish marking up their version of this bill this week. The two versions will not be the same and will almost certainly require a conference committee to work out the differences between the two bills.

Monday, May 7, 2018

Committee Hearings – Week of 5-6-18


With both the House and Senate back in Washington after a week back in their districts/States the focus starts to get serious on FY 2019 spending bills. We also have two other hearings of potential interest to readers of this blog; the FY 2019 NDAA markup and a hearing on unmanned aircraft systems (UAS).

Spending Bills


The Senate Appropriations Committee is still looking at Trump’s budget requests. This week’s hearings of potential interest include:

DHS – 5-8-18;
DOD – 5-9-18;

The House Appropriations Committee is starting to markup actual spending bills. Mark-up hearings of potential interest include:

• Commerce, Science, and Justice – Subcommittee – 5-9-18;

FY 2019 NDAA


The House Armed Forces Committee will conduct a full committee markup of HR 5515, the FY 2019 National Defense Authorization Act on Wednesday. The week before last saw subcommittee markup completed. The Subcommittee on Emerging Threats and Capabilities added six sections to the bill concerning cybersecurity. They were:

§1631—Amendments to Pilot Program Regarding Cyber Vulnerabilities of Department of Defense Critical Infrastructure
• §1632—Budget Display for Cyber Vulnerability Evaluations and Mitigation Activities for Major Weapon Systems of the Department of Defense
• §1633—Transfer of Responsibility for the Department of Defense Information Network to United States Cyber Command
• §1634—Pilot Program Authority to Enhance Cybersecurity and Resiliency of Critical Infrastructure
• §1635—Procedures and Reporting Requirement on Cybersecurity Breaches and Loss of Personally Identifiable Information
• §1636—Study and Report on Reserve Component Cyber Civil Support Teams

Section 1634 would allow DOD to detail up to 50 people per year to DHS to support cybersecurity operations of DHS (including NCCIC). Section 1636 would require a joint study to be conducted by DOD and DHS about establishing Reserve Component Cyber Civil Support Teams in each State.

UAS Hearing


On Tuesday the Senate Commerce, Science, and Transportation Committee will hold a hearing on “Keeping Pace with Innovation – Update on the Safe Integration of Unmanned Aircraft Systems into the Airspace”. The witness list includes:

• Earl Lawrence, Federal Aviation Administration;
• Brian Wynne, Association for Unmanned Vehicle Systems International;
• Matthew S. Zuccaro, Helicopter Association International;
• Todd Graetz, BNSF Railway Co.

I doubt that we will hear much of anything about protecting critical infrastructure from UAS based attacks on critical infrastructure, but I could be pleasantly surprised.

Monday, April 23, 2018

Committee Hearings – Week of 04-22-18


With both the House and Senate in Washington this week things start to get busy before the primary season starts to make Congress really political. In addition to marking up the FY 2019 National Defense Authorization bill and budget hearings we have three hearings that may be of potential interest to readers of this blog; HR 4 and cybersecurity.

NDAA Markup

The introduced version of HR 5515, the National Defense Authorization Act for Fiscal Year 2019 was published last week. It has a number of large holes in it that will be filled this week by subcommittee markups. The full Armed Services Committee will not finish the markup process until the House comes back from their spring break the week after next. These two subcommittee hearings may be of specific interest:

April 26thReadiness Subcommittee;

Budget

There are still a number of hearings being held looking at the President’s proposed budget. This week there is only one that may be of specific interest here:

April 26th, DHS, House Homeland Security;

HR 4 Rule


As I mentioned over the weekend, the House Rules Committee will be holding a hearing on Tuesday to formulate the rule for the consideration of HR 4, the FAA Reauthorization Act of 2018, later this week. Two hundred and thirty-one proposed amendments have been submitted to the Committee for possible consideration on the floor of the House; the vast majority will not make it. Fourteen of those amendments deal with unmanned aircraft systems and two deal with cybersecurity issues. A large number of the rest deal with airport noise issues, a perennial concern of congresscritters. The bill will probably make it to the floor on Thursday.

Cybersecurity


On Tuesday the Senate Homeland Security and Governmental Affairs Committee will hold a hearing on “Mitigating America’s Cybersecurity Risk”. The witness list includes:

• Jeanette Manfra, DHS;
• Gregory C. Wilshusen, GAO; and
Eric Rosenbach; Harvard University

This hearing could go one of two ways; most likely a look at cybersecurity issues in the Federal government (always a problem), or it could look at the cybersecurity concerns in critical infrastructure that we have been hearing about in the mainstream news. In either case it will likely be a high-level policy type discussion rather than focusing in-depth on any actual security issues.

Sunday, April 15, 2018

Bills Introduced – 04-13-18


On Friday, with just the House in session, there were 23 bills introduced. Of those, three may be of specific interest to readers of this blog:

HR 4 To reauthorize programs of the Federal Aviation Administration, and for other purposes. Rep. Ryan, Paul D. [R-WI-1]

HR 5515 To authorize appropriations for fiscal year 2019 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Rep. Thornberry, Mac [R-TX-13]

HR 5517 To improve assistance provided by the Hollings Manufacturing Extension Partnership to small manufacturers in the defense industrial supply chain on matters relating to cybersecurity, and for other purposes. Rep. Panetta, Jimmy [D-CA-20]

The first two are important authorization bills. The FAA bill has already been printed and includes a title on unmanned aircraft systems that will be looked at here. The NDAA will be watched for cybersecurity provisions. Note that it is odd for Speaker Ryan to introduce the FAA authorization bill and even more so for him to use one of his reserved bill numbers.

I will be looking at HR 5517 for control system security issues. The defense industrial base regulation is always a potential forward indicator of possible congressional action on cybersecurity issues.

 
/* Use this with templates/template-twocol.html */