Showing posts with label HR 5760. Show all posts
Showing posts with label HR 5760. Show all posts

Thursday, October 1, 2020

HR 5760 Passed in House – Grid Security Research

I missed this in yesterday’s post on DOE legislation passed in the House, but on Tuesday the House passed HR 5760, the Grid Security Research and Development Act. It passed by a voice vote under the suspension of the rules process. There was limited debate and no one spoke in opposition to the bill.

Again, reiterating what I said yesterday, this bill will only be considered in the Senate if it is taken up under their unanimous consent process. Because of COVID-19, the election, and the general inability of the current Senate to consider much of anything beyond judicial nominations, it is unlikely that this bill will be considered in the Senate.

Monday, September 28, 2020

House to Take Up 5 Cybersecurity Bills

This week the House is scheduled to take up 50 bills under the suspension of the rules process. Five of those bills are related to cybersecurity. The suspension of the rules process calls for limited debate and no amendment of the bill to be accepted from the floor. Bills are required to get a supermajority vote to pass.

The five cybersecurity bills are:

HR 359 – Enhancing Grid Security through Public-Private Partnerships Act, as amended (Rep. McNerney – Energy and Commerce)

HR 360 – Cyber Sense Act of 2020, as amended (Rep. Latta – Energy and Commerce)

HR 5760 – Grid Security Research and Development Act (Rep. Bera – Science, Space, and Technology)

HR 5780 – Safe Communities Act of 2020, as amended (Rep. Underwood – Homeland Security)

HR 5823 – State and Local Cybersecurity Improvement Act, as amended (Rep. Richmond – Homeland Security)

Only one of these bills as being considered this week have been changed since they were adopted in committee. HR 359 has had the phrase “and other Federal agencies” removed from language requiring the DOE to consult with various organizations as “the Secretary determines appropriate”. This means that Congress does not want to even suggest that DOE might want to consult with CISA. This is an odd change.

The other oddity in this list is the inclusion of HR 5760. The language from this bill was mostly included in the recently passed HR 4447. That bill has little to no chance of being considered by the Senate. That means that taking up this bill in a stand-alone version would increase its chances of making it to the President’s desk for signature. It makes one wonder why it was added to HR 4447 in the first place; it might have been an attempt to politically buy the vote of Rep Weber (R,TX) who was a cosponsor of HR 5760. If so, it did not work; Weber was not one of the 7 Republicans to vote for the bill.

The House leadership expects each of these bills to pass this week with substantial bipartisan support. This means that there is some chance that the bills could be taken up by the Senate under their unanimous consent process. We will have to wait and see what kind of votes these bills actually get before we can assess what those chances might actually be.

Friday, February 14, 2020

HR 5760 Introduced – Energy Security Research


Earlier this month Rep Bera (D,CA) introduced HR 5760, the Grid Security Research and Development Act. The bill would require DOE to fund a variety of electric sector cybersecurity research efforts. The bill would also authorize funding for such activities. The bill would amend Title XIII of the Energy Independence and Security Act of 2007 (42 USC 17381 et seq.) by adding nine new sections.

Definitions


The new §1317 would add definitions for the Smart Grid Title. Key definitions include:

• The term ‘cybersecurity’ means protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.
• The term ‘cybersecurity threat’ has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501).
• The term ‘information system’—has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501); and includes operational technology, information technology, and communications.
• The term ‘security vulnerability’ has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501).
• The term ‘transient devices’ means removable media, including floppy disks, compact disks, USB flash drives, external hard drives, mobile devices, and other devices that utilize wireless connections.

R&D Program


Section 1310 would require DOE “to carry out a research, development, and demonstration program to protect the electric grid and energy systems, including assets connected to the distribution grid, from cyber and physical attacks” {new §1310(a)}. The program would include the award of research, development, and demonstration grants to {new §1310(b)}:

• Identify cybersecurity risks to information systems within, and impacting, the electricity sector, energy systems, and energy infrastructure;
• Develop methods and tools to rapidly detect cyber intrusions and cyber incidents, such as intrusion detection, and security information and event management systems, to validate and verify system behavior;
• Assess emerging cybersecurity capabilities that could be applied to energy systems and develop technologies that integrate cybersecurity features and procedures into the design and development of existing and emerging grid technologies, including renewable energy, storage, and demand-side management technologies;
• Identify existing vulnerabilities in intelligent electronic devices, advanced analytics systems, and information systems;
• Develop technologies that improve the physical security of information systems, including remote assets;
Integrate human factors research into the design and development of advanced tools and processes for dynamic monitoring, detection, protection, mitigation, response, and cyber situational awareness;
• Evaluate and understand the potential consequences of practices used to maintain the cybersecurity of information systems and intelligent electronic devices;
• Develop or expand the capabilities of existing cybersecurity test beds to simulate impacts of cyber attacks and combined cyber-physical attacks on information systems and electronic devices; and
• Develop technologies that reduce the cost of implementing effective cybersecurity technologies and tools, including updates to these technologies and tools, in the energy sector.

Additionally, DOE would be required to work with relevant entities to develop technologies or concepts that build or retrofit cybersecurity features and procedures into work with relevant entities to develop technologies or concepts that build or retrofit cybersecurity features and procedures into {new §1310(b)(5)}:

• Information and energy management system devices, components, software, firmware, and hardware, including distributed control and management systems, and building management systems;
• Data storage systems, data management systems, and data analysis processes;
• Automated- and manually-controlled devices and equipment for monitoring and stabilizing the electric grid;
• Technologies used to synchronize time and develop guidance for operational contingency plans when time synchronization technologies, are compromised;
• Power system delivery and end user systems and devices that connect to the grid
• The supply chain of electric grid management system components;

Resilience and Response


Section 1311 would require DOE to establish a separate grant program “to enhance resilience and strengthen emergency response and management pertaining to the energy sector” {new §1311(a)}. Grants would be awarded for {new §1311(b)}:

• Developing methods to improve community and governmental preparation for and emergency response to large-area, long-duration electricity interruptions;
• Developing tools to help utilities and communities ensure the continuous delivery of electricity to critical facilities;
• Developing tools to improve coordination between utilities and relevant Federal agencies to enable communication, information-sharing, and situational awareness in the event of a physical or cyber-attack on the electric grid;
• Developing technologies and capabilities to withstand and address the current and projected impact of the changing climate on energy sector infrastructure, including extreme weather events and other natural disasters;
• Developing technologies capable of early detection of deteriorating electrical equipment on the transmission and distribution grid, including detection of spark ignition causing wildfires and risks of vegetation contact; and
• Assessing upgrades and additions needed to energy sector infrastructure due to projected changes in the energy generation mix and energy demand.

Best Practices and Guidance


Section 1312 would require DOE to “coordinate the development of guidance documents for research, development, and demonstration activities to improve the cybersecurity capabilities of the energy sector through participating agencies” {new §1312(a)}. This would include updating {new §1312(a)(1)}:

• The Roadmap to Achieve Energy Delivery Systems Cybersecurity;
• The Cybersecurity Procurement Language for Energy Delivery Systems; and
• The Electricity Subsector Cybersecurity Capability Maturity Model, including the development of metrics to measure changes in cybersecurity readiness.

The changes to the cybersecurity procurement language document would include suggestions for {new §1312(a)(1)(B)}:

• Contracting with third parties to conduct vulnerability testing for information systems used across the energy production, delivery, storage, and end use systems;
• Contracting with third parties that utilize transient devices to access information systems; and
• Managing supply chain risks.

DOE would also be required to work with the National Institute of Standards and Technology (NIST) to convene relevant stakeholders to develop consensus-based best practices to improve cybersecurity for {new §1312(b)(1)}:

• Emerging energy technologies;
• Distributed generation and storage technologies, and other distributed energy resources;
• Electric vehicles and electric vehicle charging stations; and
• Other technologies and devices that connect to the electric grid.

Section 1312(c) specifically states that none of the activities authorized by this section “shall be construed to authorize regulatory actions”.

Funding


Section 1318 authorizes funding for the programs outlined in this bill. Funding would start at $150 million in 2021 and increase each year to $182 million in 2025.

Amendments


On Wednesday the House Science, Space, and Technology Committee held a markup hearing that included consideration of HR 5760. Three amendments were offered by:

Bera;
Rep Lofgren (D,CA); and
Rep Waltz (R,FL)

All three amendments were adopted by voice vote as was the amended bill. Most of the changes made by the three amendments were relatively minor wording changes. The most significant change was made by the Waltz amendment. It would add a new §4, Critical Infrastructure Research and Construction, to the bill (not another change to the Energy Independence and Security Act of 2007).

The new §4 would require DOE to establish and operate a Critical Infrastructure Test Facility “that allows for scalable physical and cyber performance testing to be conducted on industry-scale critical infrastructure systems” {§4(d)}. The Test Facility would focus on cybersecurity test beds and electric grid test beds. The Test Facility would be authorized to operate for five years with the possibility of a single 5-year extension by DOE.

Moving Forward


This bill received bipartisan support in Committee, and I expect that it would receive similar support on the floor of the House. This bill could be brought to the floor under the suspension of the rules process or it could be added to a DOE authorization or spending bill. Because of the monies authorized for the grant programs, I suspect that this bill would receive less opposition if it were included in an authorization bill.

Commentary


You have to give the Committee Staff credit; this is a very comprehensive cybersecurity research program outlined in the bill. Unfortunately, the paltry amount of funding authorized in the bill will hardly make a start of a dent in the research program outlined. That amount of money, however, is probably about as much as Congress is going to allocate for cybersecurity research.

One thing that is interesting about this bill is the recognition by the Staff that grid security is going to be affected by not just by grid operators, but also by any number of entities that will be increasing connecting to the grid. The rise of the ‘smart grid’ is increasing the amount of cyber communication between grid operators and their customers. Those communications channels are going to be an increasingly important pathway for attackers to gain effective access to grid control mechanisms. The sooner cybersecurity research starts focusing on that process access route, the sooner defenses can begin to be appropriately arrayed to protect the grid.

Monday, February 10, 2020

Committee Hearings – Week of 2-9-20

The President’s budget comes to Capital Hill this week, but apparently chemical safety and security (and cybersecurity) will have to wait until next week. There will be four other hearing of interest; two markups, autonomous vehicles and cybersecurity.

Markup Hearings


The House Homeland Security Committee will hold a markup hearing on Wednesday. Among the ten bills that are scheduled for consideration are:

• HR 5780, the Safe Communities Act of 2020;
• HR ____, the State and Local Cybersecurity Improvement Act

The official version of HR 5780 has not yet been published and the second has not yet been introduced (okay it probably was today, but we will not see it until tomorrow).

The House Science, Space, and Technology Committee will hold a markup hearing on Wednesday. Among the five bills that are scheduled for consideration are:

HR 5428, Grid Modernization Research and Development Act of 2019; and
• HR 5760, Grid Security Research and Development Act

HR 5760 has not yet been officially published.

Autonomous Vehicles


On Tuesday the Consumer Protection and Commerce Subcommittee of the House Energy and Commerce Committee will hold a hearing on “Autonomous Vehicles: Promises and Challenges of Evolving Automotive Technologies”. The witness list includes:

• John Bozzella, Alliance for Automotive Innovation
• Cathy Chase, Advocates for Highway and Auto Safety
• Daniel Hinkle, American Association for Justice
• Mark Riccobono, National Federation of the Blind
• Gary Shapiro, Consumer Technology Association
• Jeffrey Tumlin, San Francisco Municipal Transportation Agency

Cybersecurity


On Tuesday the Senate Homeland Security and Governmental Affairs Committee will hold a hearing on “What States, Locals and the Business Community Should Know and Do: A Roadmap for Effective Cybersecurity”. The witness list includes:

• Christopher C. Krebs, CISA;
• Amanda Crawford, Department of Information Resources, Texas;
• Christopher DeRusha, Cybersecurity and Infrastructure Protection Office, Michigan

On the Floor


The House is scheduled to take up HR 4432, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act tonight or perhaps tomorrow under the suspension of the rules process. There will be limited debate, no floor amendments and the bill will require a supermajority to pass. This bill will almost certainly receive strong bipartisan support.

Thursday, February 6, 2020

Bills Introduced – 2-5-20


With both the House and Senate in session (and the Senate finishing with the impeachment process) there were 23 bills introduced. One of those bills may received additional coverage in this blog:

HR 5760 To provide for a comprehensive interdisciplinary research, development, and demonstration initiative to strengthen the capacity of the energy sector to prepare for and withstand cyber and physical attacks, and for other purposes. Rep. Bera, Ami [D-CA-7] 

This could get complicated.

 
/* Use this with templates/template-twocol.html */