Showing posts with label HR 636. Show all posts
Showing posts with label HR 636. Show all posts

Tuesday, October 9, 2018

S 3513 Introduced – UAS Restricted Areas

Last month Sen Cortez-Masto (D,NV) introduced S 3513, the UAS Critical Infrastructure Protection Act. The bill would amend provisions in the 2016 FAA Extension, Safety, and Security Act of 2016 (PL 114-190) that would allow facilities to petition the FAA to be declared restricted flight zones for unmanned aircraft.

UAS Restricted Areas


Section 2 of the bill would add ‘railroad facilities’ to the limited list of facilities that should be authorized to request that the FAA “prohibit or restrict the operation of an unmanned aircraft in close proximity” {PL 114-190 §2209(a), (130 STAT. 634)} to the facility.

The bill would also establish a deadline of March 31, 2019 for the FAA to publish a notice of proposed rulemaking to carry out §2209 and a requirement to publish the final rule within one year of that date.

Moving Forward


Both Cortez-Masto and her single cosponsor {Sen. Fischer (R,NE)} are members of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. Earlier in the session this might have allowed for their influence to ensure that this bill was considered in Committee. It is certainly less likely now, however, that this bill will receive any additional attention in the closing days of the session. The bill is likely to be re-introduced in the 116th Congress.

The original authorization bill that this bill amends received bipartisan support in both the House and Senate. There is nothing in this bill that would raise the prospects for significant opposition. If the bill were to be considered in this session it would likely pass in both Committee and on the floor with bipartisan support.

Commentary


The practical problem with this bill and the underlying requirement for establishing critical infrastructure ‘no fly zones’ is that there is currently no way to enforce the restrictions. Unmanned aerial systems (UAS) are typically too small to have readily identifiable identification numbers while they are in flight and it is currently illegal for anyone in the private sector or non-federal law enforcement to interfere with the operation of UAS or intercept the communications between the UAS and its controller. Even the recent authorization (sent to the President on October 4th) for DHS or DOJ physical action against UAS would not apply at these facilities.

The inclusion of a new deadline for the FAA to take regulatory action on the requirements of §2209 is interesting. The original legislation already required the FAA to establish the facility registration program within 180-days of the enactment of HR 636 (July 15th, 2016). The only way that Congress has of forcing compliance with such deadlines is by restricting funding for Department operations until the requirements are met, something for which there is very little political will to support.

Wednesday, July 13, 2016

House and Senate Pass HR 636 - FAA Authorization Bill

On Monday the House adopted a version of HR 636 that substituted new language for that adopted by the Senate in April by a voice vote. The cybersecurity provisions in the Senate language were removed and a new cybersecurity section was added. One of the two unmanned aircraft provisions associated with critical infrastructure facilities was completely re-written and the other remained mainly intact.

Cybersecurity


Section 2111 of the bill would require the FAA to develop “a comprehensive and strategic framework of principles and policies to reduce cybersecurity risks to the national airspace system, civil aviation, and agency information systems”. It would require the FAA’s Aircraft Systems Information Security Protection Working Group (ASISPWG) to identify and address cybersecurity risks associated with aircraft systems {§2111(a)(2)(1)(A)} including:

• To assess cybersecurity risks to aircraft systems;
• To review the extent to which existing rulemaking, policy, and guidance to promote safety also promote aircraft systems information security protection;
• Cybersecurity risks associated with in-flight entertainment systems;
• Whether in-flight entertainment systems can and should be isolated and separate, such as through an air gap, under existing rulemaking, policy, and guidance; and
• To provide appropriate recommendations to the Administrator if separate or additional rulemaking, policy, or guidance is needed to address cybersecurity risks to aircraft systems;

Critical Infrastructure Overflight


Section 2209 is a rewrite of §2154 that was adopted from S 2658. It requires the FAA to establish procedures for critical infrastructure facilities to apply to the FAA “to prohibit or restrict the operation of an unmanned aircraft in close proximity to a fixed site facility” {§2209(a)}. The bill would limit such restrictions to the following types of facilities:

• Critical infrastructure, such as energy production, transmission, and distribution facilities and equipment;
• Oil refineries and chemical facilities;
• Amusement parks; and
• Other locations that warrant such restrictions.

Section 2210 is essentially the same language that was found in Senate bill. It would allow critical infrastructure owners more latitude in their use of drones in inspection and monitoring activities.

Moving Forward



With the July 15th authorization deadline fast approaching, it appears that the Senate has accepted the House language on HR 636 by a vote of 89 to 4. The bill will go to the President who will certainly sign the bill.

Tuesday, April 19, 2016

HR 636 Proceeding in Senate

Yesterday the Senate adopted the substitute language for HR 636 that would turn it into the FAA authorization bill without debate or vote. The then voted to close debate on HR 636 by a recorded vote of 89-5. The final debate on the bill will start this morning at 11:00 EDT and the Senate will vote on the bill at noon.

The bill includes a number of cybersecurity provisions including:

§4109 – Cybersecurity (from S 2658);
§4110 – Securing aircraft avionics systems; and
§5029 – Aviation Cybersecurity

It also includes two unmanned aircraft system (UAS) provisions of specific interest to critical infrastructure owners:

§2154 – No fly-zone designations (from S 2658); and
§2126 {§44805(f)} – CI owner overflight rights.

Based upon the cloture vote results, this bill will easily pass with substantial bipartisan support.


NOTE: After the vote on HR 636, the Senate is scheduled to take up final consideration of S 2012, the energy authorization bill which also has a number of cybersecurity provisions.

Wednesday, April 13, 2016

HR 636 Amendments – 04-12-16

Yesterday there were 44 amendments proposed to HR 636. Only one of those will be of specific interest to readers of this blog; SA 3679. This amendment is now the substitute language that will turn HR 636 into the Federal Aviation Administration Reauthorization Act of 2016. The previous substitute language amendment was dropped (tabled) yesterday by Sen. McConnell.

New Language


The new substitute language is pretty much the same language as the previous version. The amendments that had been adopted in the Senate have been added into this newer version. In addition, there has been a new title added to the bill, Title VII, that deals with the Airport and Airway Trust Fund.

I have not gone back and checked to see if all of the language in all of the sections of the bill, but I have done so for the four sections that I have been specifically covering in the bill:

• Sec. 2154. Applications for designation. [same]
• Sec. 4109. Cybersecurity. [same]
• Sec. 4110. Securing aircraft avionics systems. [same as added]
• Sec. 5029. Aviation cybersecurity. [same as modified]

Moving Forward


Cloture on the new amendment was filed yesterday, so there will be a vote on that tomorrow. It looks like McConnell intends to have a final vote on this bill this week. The cloture vote tomorrow will tell the tale on the chances of him getting his way.


Meanwhile today a number of Senators will have to make a decision if they are going to re-submit amendments to the new language that had been proposed to the old substitute. That plus the normal string of new amendments will ensure that I have a goodly number of amendments to peruse tomorrow.

Tuesday, April 12, 2016

HR 636 Amendments in Senate – 04-11-16

There were a total of 74 new amendments to HR 636, the FAA authorization bill, offered in the Senate yesterday. Two of those were cybersecurity related, SA 3621 and SA 3627. They were actually the same amendment, but one was amending the base bill (SA 3627) and the other was amending the substitute language (SA 3621). SA 3621 was one of the 12 amendments that were adopted by the Senate yesterday.

Security Aircraft Avionics Systems


Both of these amendments yesterday were proposed by Sen. Nelson (D,FL) and had similar intent to his amendment SA 3474 that I described last week. They did, however, provide more specifics as to how that intent would be accomplished.

Paragraph (a) of the proposed new section was re-formatted to have two subparagraphs, but the wording remained the same. Paragraph (b) was added to ensure that actions taken by the Administrator would be in accordance with “the recommendations of the Aircraft Systems Information Security Protection Working Group [link added] under section 5029(d) [discussed in last week’s post] of this Act”.

Paragraph (c) would add an additional tasking for the ASISPWG in §5029(d). The Working Group would also be required to look at “the cybersecurity risks of in-flight entertainment systems to consider whether such systems can and should be isolated and separate from systems required for safe flight and operations, including reviewing standards for air gaps or other means determined appropriate”.

Amendments Adopted


A number of amendments to the substitute language were adopted by unanimous consent. Two of those may be of specific interest to readers of this blog. The first was SA 3621 that is described above. The second was the unmanned aircraft system (UAS) amendment, SA 3492 (described here last week) that would allow critical infrastructure owners to fly UAS without restrictions on time of day or the requirement for the pilot to maintain visual contact with the UAS under certain circumstances.

Moving Forward


Debate on HR 636 continues today. I have seen no reports that Sen. McConnell has filed cloture to close off debate, so the discussions will continue at least through tomorrow. TheHill.com is reporting that the agreement on adding tax breaks for environmental issues overlooked in last year’s spending bill will not be included in HR 636 as I reported last week. It is not clear what effect this will have on the continued consideration of this bill.

Commentary


The avionics security amendment should be much more effective than the one that Nelson originally introduced. Ensuring that the Working Group recommendations are taken into account when the FAA writes the cybersecurity regulations will help ensure that the technical issues are adequately addressed.

Unless we see additional cybersecurity amendments proposed today or tomorrow (looking less likely) this will be the only additional security language included in the bill. The requirements in the substitute language and yesterday’s amendment will provide the FAA with lots of regulatory work for the next couple of years.

Will it be adequate to protect against all potential attacks on aircraft systems? Absolutely not. Anyone that thinks that a single set of regulations, no matter how well written, will stop all attacks completely misunderstands how security works. It is not possible to stop a determined, well financed and trained attacker.

Will the regulations help? Almost certainly. It will ensure that there is at least a minimum level of security at each of the airlines. More importantly, it puts airplane manufacturers on notice of their responsibility for ensuring minimum levels of cybersecurity on aircraft that they sell to the airlines. Finally, this bill will ensure that there is an official, documented discussion about the advisability of linking aircraft entertainment, communications, and control systems on a single network. When people’s reputations are put on the line, I would be willing to bet that they will agree (reluctantly to be sure in some cases) that establishing three separate networks will be less costly in the long run.

Could more be done? Certainly. The biggest thing lacking in this bill is formal language making some agency (I would nominate ICS-CERT, due to possible overlaps with non-aviation systems) to act as a coordinator between vendors, airlines and the cybersecurity research community for software and firmware vulnerability reports. Finally, on that topic, someone at the FAA needs to be formally designated as the final arbiter of whether or not an unfixed avionics system vulnerability is of high enough risk to ground aircraft until the vulnerability is appropriately mitigated.


It is not surprising that Congress has not attempted to address the software vulnerability disclosure and consequence issue here. It has studiously ignored the problem in all sectors of the economy. The potential consequences of an unaddressed vulnerability in this venue, however, have an extraordinary potential to result in a spectacularly public failure; the type of failure that ends in vocal finger pointing and blame laying. The political backlash will be of epic making proportions. And the resulting legislation will handicap the industry for decades to come as unintended consequences overwhelm the best intentioned manufacturers.

Thursday, April 7, 2016

HR 636 Amendments in Senate – 04-06-16

HR 636 is the legislative vehicle that the Senate is using to consider the Federal Aviation Administration Reauthorization Act of 2016. An amendment (SA 3464) was offered yesterday by Sen. Thune (R,SD; Chair of the Senate Commerce, Science and Transportation Committee) that will be the substitute language that will form the basis of the bill to be considered. Fourty-nine other amendments were also proposed yesterday, including three cybersecurity amendments and a unmanned aircraft systems (UAS) amendment that may be of specific interest to readers of this blog.

Substitute Language


SA 3464 (pgs S1717 thru S1756) is based upon the version of S 2658 that was approved after extensive amendments in Thune’s Committee. As I have noted earlier that bill included a cybersecurity section, a large number of UAS provisions, and a specific provision allowing facility owners to request designation of their facilities as no-fly zones for UAS and other aircraft. The overflight (§2154) and cybersecurity provisions (§4109) made it intact into SA 3464.

A number of additional sections appear in SA 3464 that were not in the version of S 2658. One of specific interest to readers of this blog is a second section of cybersecurity requirements; §5029, Aviation Cybersecurity. That new section would require the Administrator to:

• Establish a comprehensive cybersecurity aviation framework;
• Assess the potential cost and timetable of developing and maintaining an agency-wide threat model to strengthen cybersecurity across the Federal Aviation Administration;
• Implement DOT IG recommendations for security of FAA facilities and systems;
• Establish requirements for the Aircraft Systems Information Security Protection Working Group; and
• Submit 90-day and 1-year progress reports to Congress.

The comprehensive cybersecurity aviation framework would require the Administrator to establish principles and policies that would {§5029(a)(1)}:

• Clarify cybersecurity roles and responsibilities of offices and employees, including governance structures of any advisory committees addressing cybersecurity at the Federal Aviation Administration;
• Recognize the interactions of different components of the national airspace system and the interdependent and interconnected nature of aircraft and air traffic control systems;
• Identify and implement objectives and actions to reduce cybersecurity risks to the air traffic control information systems, including actions to improve implementation of information security standards and best practices of the NIST, and policies and guidance issued by the OMB for agency systems;
• Support voluntary efforts by industry, RTCA, Inc., or standards-setting organizations to develop and identify consensus standards, best practices, and guidance on aviation systems information security protection; and
• Establish guidelines for the voluntary sharing of information between and among aviation stakeholders pertaining to aviation related cybersecurity incidents, threats, and vulnerabilities.

Cybersecurity Amendments


Of the fifty amendments that were submitted yesterday there were four that specifically dealt with cybersecurity matters. Three of those were submitted by Sen. Markey (D,MA) and the other by Sen. Nelson (D,FL). Those amendments are:

• SA 3468, Markey – Amends §5029 by adding “(f) Disclosure of Cyberattacks by the
Aviation Industry”;
• SA 3469, Markey – Amends §5029 by adding “(d) Incorporation of Cybersecurity into Requirements for Air Carrier Operating Certificates and Production Certificates”
• SA 3470, Markey – Amends §5029 by adding “(f) Managing Cybersecurity Risks of Consumer Communications Equipment”
• SA 3474, Nelson – Adds a new section “Securing Aircraft Avionics Systems”

SA 3468 would require the Administrator to prescribe regulations requiring air carriers and manufacturers to disclose cyberattacks to the FAA. The attacks would have to be reported whether or not they were successful. The attacks would have to be reported “whether or not the system is critical to the safe and secure operation of the aircraft, or any maintenance or ground support system for aircraft, operated by the air carrier or produced by the manufacturer, as the case may be” {§5029(f)(1)}.

SA 3469 would require the Secretary of Transportation to prescribe regulations to incorporate
requirements relating to cybersecurity into the requirements for obtaining an air carrier operating certificate or a production certificate under chapter 447 of 49 USC. Those regulations would include requirements to {§5029(d)(2)}:

• Require all entry points to the electronic systems of each aircraft operating in United States airspace and maintenance or ground support systems for such aircraft to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;
• Require the periodic evaluation of the measures described in subparagraph (A) for security vulnerabilities using best security practices, including the appropriate application of techniques such as penetration testing; and
• Require the entry point measures to be periodically updated based on the results of the evaluations conducted above.

SA 3470 would make the DOT-FCC’s Commercial Aviation Communications Safety and Security Leadership Group responsible for evaluating the cybersecurity vulnerabilities of broadband wireless communications equipment designed for consumer use on board aircraft operated by covered air carriers that is installed before, on, or after, or is proposed to be installed on or after, the date of the enactment of this Act. Specifically, the Leadership Group would be required to {§5029(f)(2)}:

• Ensure the development of effective methods for preventing foreseeable cyberattacks that exploit broadband wireless communications equipment designed for consumer use on board such aircraft; and
• Require the implementation by covered air carriers, covered manufacturers, and communications service providers of all technical and operational security measures that are deemed necessary and sufficient by the Leadership Group to prevent cyberattacks described above.

SA 3474 would require the Administrator to revise aircraft air-worthiness regulations to include provisions requiring “assurance that cybersecurity for avionics systems, including software components, is addressed and require that aircraft avionics systems used for flight guidance or aircraft control be isolated and separate from other networking platforms such as by using an air gap or such other means as the Administrator determines appropriate, except firewall, to protect the avionics systems from unauthorized external and internal access”.

Critical Infrastructure UAS Use


Sen. Inhofe (R,OK) proposed SA 3492 would add a new paragraph to one of the UAS. That new paragraph would require the Secretary of Transportation to establish a process to allow owners and operators of critical infrastructure to conduct UAS operations to conduct:

• Activities to ensure compliance with Federal or State regulatory, permit, or other requirements, including to conduct surveys associated with applications for permits;
• Activities to inspect, repair, construct, maintain, or protect covered facilities, including to respond to a pipeline, pipeline system, or electric energy infrastructure incident, or in response to or in preparation for a natural disaster, man-made disaster, severe weather event; or
• Activities not described above if the covered person notifies the local Flight Standards District Office before the operation of the unmanned aircraft system for such activities.

The process would allow the activities described above to be conducted beyond the visual line of sight of the individual operating the unmanned aircraft system; and without any restriction on the time of the operation.

Moving Forward


The Senate officially starts considering HR 636 today. This will be a multi-day operation with a large number of amendments. The tax provisions that I described yesterday were not included in the substitute language nor were they proposed separately yesterday. That means that additional behind the scenes work is still being done on that issue.

There have been few non-FAA amendments submitted through yesterday, but I expect that we will start to see those being offered today along with a large number of additional FAA specific amendments. This amendment offering process will continue for days.

Commentary


Markey is rapidly establishing the reputation as the cybersecurity regulation senator. His three amendments offered here were offered in slightly different forms during the consideration of S 2658 where it was voted down in an 8-16 vote (which indicates at least some bipartisan disapproval). As I noted in my earlier post this reflects a general mistrust of specificity in cybersecurity legislation. I would be surprised if any of the three Markey amendments made it to the floor of the Senate for consideration.

Markey’s reporting requirement amendment is quite specifically dead on arrival. I certainly applaud his attempt to get a cyber-attack reporting requirement established as I believe that some sort of reporting requirement in regulated industries is going to be necessary if we are going to be able to obtain some level of control over cybersecurity. Unfortunately, Markey’s all systems, successful or not requirement is too broadly written to be acceptable to the industry or be within the capabilities of the FAA to oversee.


The Nelson amendment has a better chance of being considered since it lacks much of the Markey specificity and puts the onus of developing actual requirements on the interagency working group. This provides Congress with the appearance of action without really being required to understand the details of the requirements imposed on the industry. Unfortunately, leaving an interagency committee to come up with regulations is a recipe for slow play and inadequate requirements.

Wednesday, April 6, 2016

Senate to Consider FAA Authorization as HR 636

The Senate will begin the pre-debate on consideration of HR 636 today. The bill passed by the House as the America's Small Business Tax Relief Act of 2015 will be used as the vehicle for a long-term reauthorization bill for the Federal Aviation Administration (FAA).

The details on the language that will be substituted for the House bill are still being developed. It will be based upon the version of S 2658 that was marked up last month in the Commerce, Science and Transportation Committee, but there will almost certainly be additional items added to that language before it is offered, probably today. The language on cybersecurity and critical infrastructure overflights that I reported on earlier will almost certainly remain in the substitute language, though modifications are possible.

Many observers believe that this may be the last major piece of legislation that will be passed by Congress before the elections. As such it is sure to attract an extensive amendment process on the floor of the Senate. Only two proposed amendments have been published to date, but that will certainly change today.


One issue that has been holding up the publication of the substitute amendment has been the extension of tax breaks for some forms of renewable energy that were overlooked last year in the spending bill. This is one of the reasons that HR 636 will be used as the ‘vehicle’ for this bill instead of considering S 2658; tax related bills must originate in the House.
 
/* Use this with templates/template-twocol.html */