Showing posts with label HR 6497. Show all posts
Showing posts with label HR 6497. Show all posts

Saturday, February 5, 2022

HR 6497 Amended and Adopted in Committee – FISMA 2022

Earlier this week, the House Oversight and Reform Committee held a mark-up hearing that included the consideration of HR 6497, the Federal Information Security Modernization Act of 2022. Rep Maloney (D,NY) offered substitute language for the bill which was adopted by voice vote before the Committee recommended that the amended language be recommended favorably to the Full House.

The ‘major’ change made in the substitute language was the insertion of a new §209, Renaming of Office of the Federal Chief Information Officer. That section amended 44 USC Chapter 36, renaming the existing “Office of Electronic Government” as the “Office of the Federal Chief Information Officer.” It also changed the title of the person in charge of that Office from ‘Administrator’ to ‘Director’.

There were other minor programmatic changes as well as grammatical and format changes made in the substitute language, but nothing of major significance.

Once the Committee Report is published, the bill will be ready for consideration by the Full House. I suspect that it will be considered under the suspension of the rules process and would pass with significant bipartisan support.

Tuesday, February 1, 2022

Review - HR 6497 Introduced – FISMA Update

Last week, Rep Maloney (D,NY) introduced HR 6497, the Federal Information Security Modernization Act of 2022. The bill is one of the periodic updates of the Federal Information Security Management Act (FISMA, 44 USC 3551 et seq) which outlines the cybersecurity programs for the federal government. It also includes two additional Titles:

Title II – Improving Federal Cybersecurity, and

Title III - Pilot Programs To Enhance Federal Cybersecurity

Moving Forward

Maloney is the Chair of the House Oversight and Reform Committee to which this bill is assigned for consideration. As I mentioned yesterday, the bill is currently scheduled to be considered by the Committee tomorrow. With the bipartisan co-sponsorship (8 Democrats and 8 Republicans) that this bill has, I expect the bill to be favorably reported at the end of tomorrow’s hearing with strong (perhaps a voice vote) bipartisan support, though there may be some amendments offered. The full bill will be taken up by the full House later this year and there is a good chance that the bill will be considered under the suspension of the rules process. In any case, I would suspect the bill to pass with strong bipartisan support.

Commentary

This bill continues the congressional ignorance of the fact that there are operations technology systems in the federal government that need cybersecurity protections that might be different than the protections required for purely information systems. One needs to read no further than the definitions in 44 USC 3552 (and by reference §3502) to see the truth of that assertion. This bill could be a first step in correcting that oversight by including the following new and revised definitions in §3552:

Control System - the term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes, including manufacturing, transportation, access control, and facility environmental controls;

Incident - the term "incident" means an occurrence that actually or imminently jeopardizes, without lawful authority;

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, on a control system or

(C) an information system or a control system;

Information System – the term information system has the meaning given that term in §3502 and includes controls systems as defined in this section;

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6497-introduced - subscription required.

Wednesday, January 26, 2022

Bills Introduced – 1-25-22

Yesterday, with just the House meeting in pro forma session, there were 37 bills introduced. Two of those bills may receive additional attention in this blog:

HR 6497 To modernize Federal information security management and improve Federal cybersecurity to combat persisting and emerging threats, and for other purposes. Rep. Maloney, Carolyn B. [D-NY-12]

HR 6499 To enhance rail safety and provide for the safe and covered transport of materials in railroad cars, and for other purposes. Rep. Meng, Grace [D-NY-6] 

I do not generally cover cybersecurity legislation that covers just federal agencies, but I will be watching this bill for language and definitions that may include operational technology in the coverage of its provisions.

I will be watching HR 6499 for language and definitions that would cover shipping of chemicals in the coverage of its provisions.

 
/* Use this with templates/template-twocol.html */