Showing posts with label HR 701. Show all posts
Showing posts with label HR 701. Show all posts

Saturday, February 4, 2017

HR 701 Introduced – NHTSA Cybersecurity

Last month Rep. Wilson (R,SC) introduced HR 701, the Security and Privacy in Your (SPY) Car Study Act of 2017. The bill would require DOT’s National Highway Transportation Safety Administration (NHTSA) to conduct a study to determine appropriate standards for the regulation of the cybersecurity of motor vehicles.

The Study


The study would be required to address {§2(a)}:

• The isolation measures that are necessary to separate critical software systems from other software systems;
• The measures that are necessary to detect and prevent or minimize in the software systems of motor vehicles anomalous codes associated with malicious behavior;
• The techniques that are necessary to detect and prevent, discourage, or mitigate intrusions into the software systems of motor vehicles and other cybersecurity risks in motor vehicles, such as continuous penetration testing and on-demand risk assessments;
• Best practices to secure driving data collected by the electronic systems of motor vehicles;
• A timeline for implementing systems and software that reflect the measures, techniques, and best practices identified.

The bill requires a report to Congress within one year of passage of this bill. Presumably, then Congress would take necessary actions to pass legislation requiring implementation of the suggested program.

Moving Forward


Neither Wilson nor his co-sponsor {Rep. Lieu (D,CA)} are members of the House Energy and Commerce Committee, the committee to which this bill was referred for consideration. This means that the bill is unlikely to be considered by that Committee.

There is nothing in the bill that would draw substantial ire of any group. Since only a study is being required (with no spending to support the study) that could only serve to pass the buck to a future Congress, this bill would be adopted in committee if it was considered and subsequently passed if it made it to the floor of the House.

Commentary


The first major problem with this bill is that it fails to include the DHS ICS-CERT in the list of organizations with which NHTSA is required to consult in the conduct of the study. In fact, there is no mention of DHS, the agency designated by Congress to be responsible for cybersecurity matters, in the bill. This was almost certainly done to avoid the inevitable inter-committee conflicts that affect most homeland security legislation.

The major technical issue with this bill (other than the complete misuse/misunderstanding of technical terminology – ‘continuous penetration testing’???) is that it completely fails to address the communications issues that are an integral part of most any cyber threat. The current existence of in-car Wi-Fi nodes and the imminent future impact of vehicle-to-vehicle and vehicle-to-infrastructure communications systems cannot be overlooked in any study of automotive cybersecurity issues.


Finally, the bill overlooks the role of the independent security researcher in identification of cybersecurity vulnerabilities. Any cybersecurity study that fails to look at the relationships between such researchers, vendors and regulators is missing an important component of identifying and fixing cybersecurity vulnerabilities.

Wednesday, January 25, 2017

Bills Introduced – 01-24-17

With both the House and Senate leaving for an extended weekend (a proforma session for both houses on Friday) there were 152 bills introduced. Of those 9 bills may be of specific interest to readers of this blog:

HR 625 To provide for joint reports by relevant Federal agencies to Congress regarding incidents of terrorism, and for other purposes. Rep. Aguilar, Pete [D-CA-31]

HR 642 To amend the Homeland Security Act of 2002 to enhance the partnership between the Department of Homeland Security and the National Network of Fusion Centers, and for other purposes. Rep. Barletta, Lou [R-PA-11]

HR 666 To amend the Homeland Security Act of 2002 to establish the Insider Threat Program, and for other purposes. Rep. King, Peter T. [R-NY-2]

HR 677 To amend the Homeland Security Act of 2002 to establish chemical, biological, radiological, and nuclear intelligence and information sharing functions of the Office of Intelligence and Analysis of the Department of Homeland Security and to require dissemination of information analyzed by the Department to entities with responsibilities relating to homeland security, and for other purposes. Rep. McSally, Martha [R-AZ-2]

HR 678 To require an assessment of fusion center personnel needs, and for other purposes. Rep. McSally, Martha [R-AZ-2]

HR 686 To ensure appropriate spectrum planning and interagency coordination to support the Internet of Things. Rep. Paulsen, Erik [R-MN-3]

HR 697 To amend the Homeland Security Act of 2002 to improve the management and administration of the security clearance processes throughout the Department of Homeland Security, and for other purposes. Rep. Thompson, Bennie G. [D-MS-2]

HR 701 To direct the Administrator of the National Highway Traffic Safety Administration to conduct a study to determine appropriate cybersecurity standards for motor vehicles, and for other purposes. Rep. Wilson, Joe [R-SC-2] 

S Res 23 A resolution establishing the Select Committee on Cybersecurity. Sen. Gardner, Cory [R-CO]

HR 625 will only be of interest here if it includes specific language addressing cybersecurity, chemical security, or chemical transportation security issues.

Hopefully HR 642 will also address the types of expertise needed at fusion centers.

HR 666 will probably be reintroduced to avoid the religious connotations of the bill number.

HR 677 is probably very similar to HR 2200 introduced in the last session and passed in the House by a nearly unanimous vote. Another bill that was not taken up by the Senate.

HR 678 is probably similar to HR 3503 introduced in the last session and passed by a voice vote. And yet another one.

I suspect that HR 686 is a companion bill to S 88 introduced earlier this month in the Senate.

HR 697 may be similar to HR 3505 introduced in the last session. I did not cover that bill because it did not really address the security clearance process for the private sector organizations to aid information sharing.

Hopefully HR 701 will specifically address the relationship between independent security researchers, NHTSA and auto companies.


Establishing a Select Committee on Cybersecurity sounds like a way to raise the profile of cybersecurity issues. Unfortunately, it will also make law making on the topic more difficult as it will add another committee silo through which cybersecurity related bills will have to pass. Inter-committee politics does almost as much to slow down the legislative process as does partisan politics.
 
/* Use this with templates/template-twocol.html */