Showing posts with label HR 6395. Show all posts
Showing posts with label HR 6395. Show all posts

Friday, January 1, 2021

Senate Votes to Overturn Trump Veto of HR 6395 – FY 2021 NDAA

This afternoon the Senate voted to overturn the President’s veto of HR 6395, the FY 2021 NDAA by a vote of 81 to 13. The House voted to override the veto on Monday. With the Senate’s action today, this is the first successful veto override of the Trump presidency.

Interestingly, neither Republican Senator from Georgia (Perdue or Loeffler) voted on the measure today. I suppose that could be excused since they are both in the final days of their election-runoff campaign. I expect, however, that the failure to vote to sustain the veto (an important vote for so many military families and businesses around the many military bases in Georgia) is more about not getting the President angry at them. This runoff election (final day of voting is Tuesday) is going to be about which side gets out the most voters and an angry Trump could keep Republicans away from the polls on Tuesday (and like in November, most Republicans are not early voting).

Monday, December 28, 2020

House Votes to Override Veto of HR 6395 – FY 2021 NDAA

This evening the House took up the President’s veto of HR 6395, the FY 2021 National Defense Authorization Act. The House voted to override the veto by a vote of 322 to 87. The House voted to accept the Conference Report on the bill early in the month by a vote of 355 to 78. As expected, there were some Republican defections; 40 Republicans voted ‘Nay’ on the Conference report, but 67 voted not to override the veto. These were nearly offset by 17 Democrats that changed their votes from ‘Nay’ to ‘Yeah’.

The Senate will start the process of considering the President’s veto tomorrow, but a final vote could take place as late as the last day of the 116th Congress next week. 

Wednesday, December 9, 2020

House Agrees to HR 6395 Conference Report – FY 2021 NDAA

Yesterday the House voted to agree to the Conference Report on HR 6395, the FY 2021 National Defense Authorization Act. The Report was agreed to by a strongly bipartisan vote of 335 to 78. The 78 negative votes were nearly equally divided between Republicans (40) and Democrats (37). This would tend to indicate that the crafters of the Report constructed a fairly middle-of-the-road compromise on the legislation.

The Senate will take up the bill later this week. It appears that the Senate will also agree to the Report with a bipartisan majority.

There has been no word of Trump backing down from his threat to veto the bill. The vote in the House could mean that there were enough votes there to override a veto. That is not certain, since there is a good chance that there would be some level of Republican defections if it comes down to a veto override vote.

Monday, December 7, 2020

Conference Report for HR 6395 – FY 2021 NDAA

On Thursday the conferees for HR 6395, the FY 2021 National Defense Authorization Act (NDAA), published their 4500 page ‘Conference Report’ working out the differences between the two versions of the bill. The official GPO version is not yet available, but the House Armed Services Committee posted a copy on their web site. The House is slated to take up the revised language from the report on Tuesday, followed by the Senate later in the week. There is an open threat of a presidential veto, but we will have to wait and see how that turns out.

Provisions of Interest

There are a huge number of ‘cyber’ related provisions in this bill. The following list shows those that I think are most interesting from a control system security point of view.

§1715. Establishment in Department of Homeland Security of joint cyber planning office. (pg 1810) (revised pg 4170)
§1716. Subpoena authority. (pg 1815)
§1717. Cybersecurity State Coordinator. (pg 1827) (revised pg 4170)
§1718. Cybersecurity Advisory Committee. (pg 1836) (revised pg 4170)

§1725. Pilot program on remote provision by National Guard to National Guards of other States of cybersecurity technical assistance in training, preparation, and response to cyber incidents. (pg 1865) (revised pg 4174)

§1729. Cyber capabilities and interoperability of the National Guard. (pg 1880) (revised pg 4175)

§1736. Defense industrial base cybersecurity sensor architecture plan. (pg 1901) (revised pg 4178)

§1737. Assessment on defense industrial base participation in a threat information sharing program. (pg 1903) (revised pg 4179)

§1738. Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity. (pg 1909)

§1739. Assessment on defense industrial base cybersecurity threat hunting program. (pg 1912) (revised pg 4180)

§1742. Department of Defense cyber hygiene and Cybersecurity Maturity Model Certification framework. (pg 1922) (revised pg 4182)

§1745. Cybersecurity and Infrastructure Security Agency review. (pg 1933)

§1752. National Cyber Director. (pg 1950) (revised pg 4186)

§9005. GAO study of cybersecurity insurance. (pg 3407)

The ‘(pg XXXX)’ listing refers to the language of the actual provision in the bill. The ‘(revised pg 4XXX)’ listing refers to the brief discussion of changes made to the provision in the conference.

Interesting Finds

There is no way that I ‘read’ all 4517 pages of the report. Most of what I did do was put the term ‘cyber’ in the search tool of my .PDF reader and click through the report. In doing so, I discovered a couple of interesting items.

I found the first item on page 680 in §589F. This section introduces a new term that I have never heard before; ‘cyberexploitation’. It is defined as using digital means and online platforms to [§589F(d)(1)]:

• “knowingly access, or conspire to access, without authorization, an individual’s personal information to be employed (or to be used) with malicious intent; or

• “to deceive an individual with misinformation with malicious intent.”

In this section of the NDAA it is used to describe actions taken against family member of armed forces personnel. The bullet in the definition above could apply to all sorts of cyber activities that we have been seeing in recent history. I think that this term (I would hyphenate it ‘cyber-exploitation’) should be more widely used.

I found the second item on page 2247 during the discussion of §2826, Improved electrical metering of Department of Defense infrastructure supporting critical missions. The final subsection shows the increasing cybersecurity sophistication of congressional staffers. It reads:

“(c) CYBERSECURITY.—The Secretary of Defense and the Secretaries of the military departments shall consult with the Chief Information Officer of the Department of Defense to ensure that the electrical energy metering options considered under subsection (b) do not compromise the cybersecurity of Department of Defense networks.”

Intelligence Authorization Act

As I noted in my blog post about the Senate passing HR 3695, the Senate include the FY 2021 Intelligence Authorization Act as a division in the bill. That language did not survive conference. The House has not yet acted on their version of this (HR 7856) ‘must pass’ legislation. The Senate has not acted on their standalone version (S 3905). There is still a chance that some version of this bill could find it into the omnibus spending bill.

Wednesday, November 18, 2020

HR 6395 Amended and Passed in Senate – FY 2021 NDAA

On Monday, the Senate adopted substitute language for, and passed, HR 6395, the National Defense Authorization Act for Fiscal Year 2021, by a voice vote. The substitute language closely tracks the language the Senate earlier adopted for S 4049, the Senate version of this bill. The Senate’s action set up today’s scheduled vote in the House to go to conference on the bill. This would allow the House and Senate to work out the differences between the two versions of the bill.

The Senate language does include a version of the FY 2021 Intelligence Authorization Act.

I would suspect that most of the cybersecurity provisions that were added during floor action in the House will remain in the approved conference version of the bill.

Monday, July 20, 2020

House to Consider HR 6395 – FY 2021 NDAA


The House is set to begin consideration of HR 6395, the FY 2021 National Defense Authorization Act, today. The bill was originally introduced with skeletal language in April. The House Armed Services Committee completed their markup of the bill earlier this month, reporting the bill on July 9th, 2020. The GPO has not yet published the reported language of the bill, but the House Rules Committee has published a copy of the language that will be considered in the House.

As expected, the cybersecurity provisions in this bill are found in Division A, Title XVI, Subtitle B, Cyberspace-Related Matters. Four provisions in that subtitle address cybersecurity matters; two addressing government cybersecurity oversight and two defense industrial-base cybersecurity matters.

Cybersecurity Oversight


Section 1630 would require DHS to submit a report to Congress “a report on Federal cybersecurity centers and the potential for better coordination of Federal cyber efforts at an integrated cyber center within the national cybersecurity and communications integration center” (NCCIC) in DHS {§1630(a)}. Potentially included in that integrated cyber center would be {§1630(b)(4)}:

• The National Security Agency’s Cyber Threat Operations Center,
• United States Cyber Command’s Joint Operations Center,
• The Office of the Director of National Intelligence’s Cyber Threat Intelligence Integration Center,
• The Federal Bureau of Investigation’s National Cyber Investigative Joint Task Force,
• The Department of Defense’s Defense Cyber Crime Center, and
• The Office of the Director of National Intelligence’s Intelligence Community Security Coordination Center.

In an unusual move for a ‘report to Congress’ mandate, the section includes a requirement for DHS to “begin establishing an integrated cyber center in the national cybersecurity and communications integration center” {§1630(e)} within one year of submitting the report to Congress. That paragraph does not specify which components will be included in the ‘integrated cyber center’.

Section 1631 would require DHS to develop an information collaboration environment and associated analytic tools that enable entities to identify, mitigate, and prevent malicious cyber activity” {§1631(a)}. The ‘collaborative environment’ would be designed to:

• Provide limited access to appropriate operationally relevant data about cybersecurity risks and cybersecurity threats, including malware forensics and data from network sensor programs, on a platform that enables query and analysis,
• Allow such tools to be used in classified and unclassified environments drawing on classified and unclassified data sets,
• Enable cross-correlation of data on cybersecurity risks and cybersecurity threats at the speed and scale necessary for rapid detection and identification;
• Facilitate a comprehensive understanding of cybersecurity risks and cybersecurity threats; and
• Facilitate collaborative analysis between the Federal Government and private sector critical infrastructure entities [emphasis added] and information and analysis organizations.

Section 1631(e) would also establish the Cyber Threat Data Standards and Interoperability Council, chaired by DHS. The Council would include representatives from Federal agencies and “public and private sector entities who oversee programs that generate, collect, or disseminate data or information related to the detection, identification, analysis, and monitoring of cybersecurity risks and cybersecurity threats” {1631(e)(2)}. The Council would “identify, designate, and periodically update programs that shall participate in or be interoperable with the information collaboration environment” {§1631(e)(3)} including:

• Network-monitoring and intrusion detection programs,
• Cyber threat indicator sharing programs,
• Certain government-sponsored network sensors or network-monitoring programs,
• Incident response and cybersecurity technical assistance programs,
• Malware forensics and reverse-engineering programs, and
• The defense industrial base threat intelligence program of the Department of Defense.

Defense Industrial Base Cybersecurity


Section 1632 would require DOD to establish “a threat intelligence program to share with and obtain from the defense industrial base information and intelligence on threats to national security” {§1632(b)(1)}. The program would include {§1632(b)(2)}:

• Cybersecurity incident reporting requirements,
• A mechanism for developing a shared and real-time picture of the threat environment,
• Joint, collaborative, and co-located analytics,
• Investments in technology and capabilities to support automated detection and analysis across the defense industrial base,
• Coordinated intelligence sharing with relevant domestic law enforcement and counter-intelligence agencies, in coordination, respectively, with the Director of the Federal Bureau of Investigation and the Director of National Intelligence, and
• A process for direct sharing of threat intelligence related to a specific defense industrial base entity with such entity.

Participation in the program would be required for all DOD contractors, subcontractors, and suppliers.

Section 1634 would require DOD to report to Congress on “the feasibility and resourcing required to establish the Defense Industrial Base Cybersecurity Threat Hunting Program” {§1634(b)(1)}. If determined to be feasible, DOD would be required to establish the Program “to actively identify cybersecurity threats and vulnerabilities within the information systems, including covered defense networks containing controlled unclassified information, of entities in the defense industrial base” {§1634(c)(1)}.

Section 1634(e) would allow DOD to:

• Utilize Department of Defense personnel to hunt for threats and vulnerabilities within the information systems of entities in the defense industrial base that have an active contract with Department of Defense,
• Certify third-party providers to hunt for threats and vulnerabilities on behalf of the Department of Defense, or
• Require the deployment of network sensing technologies capable of identifying and filtering malicious network traffic.

Floor Consideration of HR 6395


Last week the House Rules Committee developed the Rule for the consideration of HR 6395. It is a structured rule providing limited debate and a limited number of specific amendments that can be offered on the floor of the House.

Of the 407 amendments to be considered, the following contain cybersecurity provisions of note:

#2 – Bergman - Creates a cyber attack exception under the Foreign Sovereign Immunities Act (FSIA) to protect U.S. nationals against foreign state-sponsored cyberattacks,
#15 – Langevin - Establishes a National Cyber Director within the Executive Office of the President (similar to HR 7331),
#27 – Richmond - Implements a recommendation from the Cyberspace Solarium Commission to require the Department of Homeland Security to establish a cyber incident reporting program,
#72 – Chabot - Increases Air Force research funding by $3 million for the National Center for Hardware and Embedded Systems Security and Trust (CHEST),
#117 – DeFazio - Adds the Elijah E. Cummings Coast Guard Authorization Act of 2020,
#162 – Green - Enhances CISA’s ability to both protect federal civilian networks and provide useful threat intelligence to critical infrastructure by authorizing continuous threat hunting on the .gov domain. This will enable CISA to quickly detect, identify, and mitigate threats to federal networks from malware, indicators of compromise, and other unauthorized access,
#179 – Jackson-Lee - Implements a recommendation made by the Cyberspace Solarium Commission to require the Secretary of Homeland Security to develop a strategy to implement Domain-based Message Authentication, Reporting, and Conformance (DMARC) standard across U.S.-based email providers,
#219 – Langevin - Allows CISA to issue administrative subpoenas to ISPs to identify and warn entities of cyber security vulnerabilities (similar to HR 5680),
#220 – Langevin - Codifies the responsibilities of the sector risk management agencies with regard to assessing and defending against cyber risks,
#319 – Richmond - Implements a recommendation from the Cyberspace Solarium Commission that there be established at the Department of Homeland Security a Joint Planning Office to coordinate cybersecurity planning and readiness across the Federal government, State and local government, and critical infrastructure owners and operators,
#320 – Richmond – Implements a recommendation from the Cyberspace Solarium Commission that establishes a fixed 5-year term for the Director of the Cybersecurity and Infrastructure Security Agency and establishes minimum qualifications for the CISA Director (similar to HR 5679),
#329 – Ruppersberger - Requires the Secretary of Homeland Security to conduct a review of the ability of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security to fulfill its current mission requirements, and for other purposes,

S 4049 Consideration


A quick reminder that the Senate will also resume consideration of their version of the NDAA (S 4049) today. The two versions will have to be reconciled at a later date by a conference committee. Many provisions adopted in either the House or Senate will not make it into the final bill or will be revised enroute.

Tuesday, June 30, 2020

Committee Hearings – Week of 6-28-20


This week with both the House and Senate in Washington there is a more normal slate of congressional hearings being held. One of interest here; the final markup of HR 6395, the House version of the FY 2021 National Defense Authorization Act (NDAA).

NDAA Markup


On Wednesday the House Armed Services Committee will be marking up HR 6395. Last week subcommittees conducted their markups. The Intelligence and Emerging Threats and Capabilities Subcommittee added some cyber provisions to the bill. We are likely to see additional provisions added in the full committee markup tomorrow.
The Subcommittee language included two cybersecurity provisions that could affect the private sector:

§1627—Assessing Private-Public Collaboration in Cybersecurity
§1628—Cyber Capabilities and Interoperability of the National Guard

Neither of those provisions were as proactive in mandating private sector actions as we saw in some of the provisions reported out on S 4049, the Senate version of the NDAA.

Monday, April 6, 2020

HR 6395 Introduced – FY 2021 NDAA


Last month before the House left for their extended COVID-19 recess, Rep Smith introduced HR 6395, the National Defense Authorization Act for Fiscal Year 2021. This bill is one of the ‘must pass’ bills that Congress will have to deal with this year.

The version of the bill introduced is not complete. For the purpose of this blog an important missing piece is Title XVI of Division A, Strategic Programs, Cyber, and Intelligence Matters. It is expected that subsequent markups of the bill by both subcommittees of, and the full, House Armed Services Committee will fill in the missing pieces.

As introduced, there are no cyber provisions within HR 6395.

Friday, March 27, 2020

Bills Introduced – 3-26-20


Yesterday with just the House in session (but not really in Washington, but not a proforma session) and the Senate in their COVID-19 recess, there were 14 bills introduced. One of those bills will receive future coverage in this blog:

HR 6395 To authorize appropriations for fiscal year 2021 for military activities of the Department of Defense and for military construction, to prescribe military personnel strengths for such fiscal year, and for other purposes. Rep. Smith, Adam [D-WA-9]

 
/* Use this with templates/template-twocol.html */