Showing posts with label HR 6620. Show all posts
Showing posts with label HR 6620. Show all posts

Wednesday, September 26, 2018

Bills Passed Under Suspension of Rules in House – 09-25-18


Yesterday as part of their consideration of bills under suspension of the rules, the House passed two bill that I have been covering here; HR 6620, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act and HR 6229, the National Institute of Standards and Technology Reauthorization Act of 2018. Both bills passed by voice vote.

As is typical for bills considered under this procedure there was limited debate on each bill (10 minutes on HR 6620 and 17 minutes on HR 6229). Nary a word was said in opposition.

Monday, September 24, 2018

Committee Hearings – Week of 9-23-18


Both the House and Senate are in Washington this week and it is likely to be the last week the House will be in session before the election. A lot of political hearings this week but there are three hearings that may be of interest; HR 6157 conference report, a homeland security markup hearing and cybersecurity in the energy sector.

HR 6157 Conference

On Tuesday the House Rules Committee will hold a hearing on the Conference Report on HR 6157, the FY 2019 DOD and HHS spending minibus. They will formulate the rule for the floor consideration of the bill. This bill will also include new language providing for the continuing resolution (CR) for DHS spending thru December 6th.

The Senate has already acted favorably on the Conference Report and the other two mini-busses have been sent to the White House. Congress has not come this close to finishing spending bills before the end of the fiscal year in quite some time. This may be the most important achievement of the 115th Congress.

Homeland Security Markup


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting that will include the markup of a number of homeland security related bills, including:

S 3405, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018;
S 3309, OHS Cyber Incident Response Teams Act of 2018; and  
• S 594, National Cybersecurity Preparedness Consortium Act of 2017;

There will be a total of 43 bills considered during this meeting, but 21 of them are postal facility naming bills. Most of the remaining bills will be approved by unanimous consent. It will be interesting to see how many amendments are offered on S 3405. The bill did not have any cosponsors when offered and has not acquired any since then. This is unusual in a bill of this type where there is a general consensus on the need for extending the covered program (CFATS).

Unfortunately, we are unlikely to see the text of any of the offered amendments. We will see the revised version of the bill (if changes are made) when the committee report is published in the next month or so (if we are lucky).

Energy Cybersecurity


On Thursday, the Energy Subcommittee of the House Energy and Commerce Committee will hold a hearing looking at “DOE Modernization: The Office of Cybersecurity, Energy Security, and Emergency Response (CESER)”. The witness list has not yet been posted, but a press release notes that the Subcommittee will hear from Assistant Secretary Karen Evens who is in charge of the CESER. The discussions here will almost certainly focus on policy level issues, but cybersecurity will certainly be the overarching topic.

On the Floor

With the mid-term election pending the House will be trying to clean up a lot of miscellaneous business this week with grandstanding and political posturing making the most news, but lots of less controversial stuff being taken care of as well. The HR 6157 Conference Report will be the most important, but the House will also be taking up 54 bills under their suspension of the rules procedure; most of these will pass with significant bipartisan support. Bills of interest here include:

HR 6620 – Protecting Critical Infrastructure Against Drones and Emerging Threats Act; and
HR 6229 – National Institute of Standards and Technology Reauthorization Act of 2018, as amended;

As always there will be limited debate, no floor amendments and a supermajority will be required to pass. Both of these bills will pass; no political posturing here – okay, bipartisan posturing.

Wednesday, September 12, 2018

HR 6620 Introduced – UAS Threat Assessment


Back in July Rep. Richmond (D,LA) introduced HR 6620, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act. The bill requires data collection and analysis activities about the threats posed by unmanned aircraft systems (UAS).

The bill would require the DHS Office of Intelligence and Analysis (OIA) within 120 days to {§2(a)}:

• Request additional information from other agencies of the Federal Government, State and local government agencies, and the private sector relating to threats of unmanned aircraft systems and other emerging threats associated with such new technologies;
• Develop and disseminate a security threat assessment regarding unmanned aircraft systems and other emerging threats associated with such new technologies;
Establish a secure reporting infrastructure for reporting information on emerging threats, such as the threat posed by unmanned aircraft systems

Within one year of the bill being adopted, OIA would be required to report to Congress on the threat posed by unmanned aircraft systems.

No monies are authorized by this bill.

Moving Forward


This bill will be considered by the House Homeland Security Committee tomorrow. I suspect that the bill will receive bipartisan support. If this bill does come to the floor of the House before the end of the session (probable) it will almost certainly be considered under the suspension of the rules process with minimal debate, no amendments and would require a supermajority to pass.

I really doubt that if this bill were considered in the House that it would make it to the floor of the Senate before the 115th Senate adjourns for good in December.

Commentary


This is another one of those motherhood and apple pie bills that allows congress critters to feel good about ‘doing something’ without raising any controversies or spending any money. Unfortunately, it will accomplish virtually nothing.

Oh yes, the bill includes an attempt to cover the important tech buzz words in §2(b)(3):

“establish and utilize, in conjunction with the Chief Information Officer of the Department and other relevant entities, a secure communications and information technology infrastructure, including data-mining and other advanced analytical tools, in order to access, receive, and analyze data and information in furtherance of the responsibilities under this section, including by establishing a voluntary mechanism whereby critical infrastructure owners and operators may report information on emerging threats, such as the threat posed by unmanned aircraft systems.”

They missed ‘artificial intelligence’ and ‘blockchain’; maybe they can add those tomorrow.

Tuesday, September 11, 2018

Homeland Security Mark-up Hearing – 09-13-18


This morning the House Homeland Security Committee announced that it would be conducting a mark-up hearing for five pieces of legislation including:

• H.R 6620, Protecting Critical Infrastructure Against Drones and Emerging Threats Act;
• HR 6735, To direct the Secretary of Homeland Security to establish a vulnerability disclosure policy for Department of Homeland Security internet websites, and for other purposes; and
S 1281, Hack the Department of Homeland Security Act of 2017

The official copy of HR 6620 just recently became available and I have just glanced through it at this point; hopefully I’ll get a chance to review it here before Thursday. The quick glance that I have done indicates that this is a ‘collect information and report to Congress’ type of bill, rather than something that will authorized any sort of action similar to S 2836.

The official copy of HR 6735 is not yet available, but a Committee Print is. There is not much in this bill of specific interest to readers of this blog beyond the fact that it uses the definition of ‘security vulnerability’ from 6 USC 1501 which is, in turn, based upon the ICS-inclusive definition of information system while the bill uses the IT-restrictive definition of ‘information system’ from 44 USC 3502.

Friday, July 27, 2018

Bills Introduced – 07-26-18


Yesterday with both the House and Senate in session (and the House preparing to leave on its extended summer break) there were 131 bills introduced (109 in the House). Of these, five may be of specific interest to readers of this blog:

HR 6555 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training and Employment Apprentice Program, and for other purposes. Rep. Jackson Lee, Sheila [D-TX-18]

HR 6609 To amend title 46, United States Code, to reauthorize the port security grant program, and for other purposes. Rep. Meng, Grace [D-NY-6]

HR 6617 To provide for a legal framework for the operation of public unmanned aircraft systems, and for other purposes. Rep. Poe, Ted [R-TX-2]

HR 6620 To require the Department of Homeland Security to prepare a threat assessment relating to unmanned aircraft systems, and for other purposes. Rep. Richmond, Cedric L. [D-LA-2]

S 3288 A bill to amend title 18, United States Code, to provide the Department of Justice needed legal authorities to combat cybercrime, including state sponsored cybercrime, and for other purposes. Sen. Graham, Lindsey [R-SC]

I suspect HR 6555 will be a program for federal employees, but it would still be worthwhile to watch how such a program was established. It could actually be an interesting model for similar programs in the private sector.

It will be interesting to see what sorts of restrictions are placed on public unmanned aircraft systems in HR 6617.

S 3288 will bear close scrutiny of definitions as they will likely have unintended bearing on activities of cybersecurity researchers.

 
/* Use this with templates/template-twocol.html */