Showing posts with label HR 7138. Show all posts
Showing posts with label HR 7138. Show all posts

Friday, March 25, 2022

Review - HR 7138 Introduced – IoT Supply Chain Security

Last week, Rep Obernolte (R,CA) introduced HR 7138, the Protecting Against Compromised Internet of Things Technology Act. The bill would require the DOC’s Bureau of Industry and Security to submit (and periodically update) to the End-User Review Committee a list of foreign persons that “pose a threat to the security of supply chains of Internet of Things devices”.

Moving Forward

While Obernolte is not a member of either the House Foreign Affairs or Oversight and Reform Committee, the two committees to which this bill was assigned for consideration, his sole cosponsor {Rep Jacobs (D,CA)} is a member of the Foreign Affairs Committee. This means that there may be enough influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition. If the bill were introduced in Committee, I would expect that there would be significant revisions made to make the bill more effective (see ‘Commentary’), that could change the potential for support.

Commentary

This bill does not actually appear to accomplish anything. The definition of the term ‘covered foreign person’ limits the people that could be affected by suggested listing by BIS to overseas vendors of IoT devices. These are not typically the people that we are concerned with when it comes to endangering the security of IoT supply chains. If, for some reason, they do endanger that supply chain security, we prohibit people in this country from selling items to the affected vendors. Which means that the federal government is adversely impacting the supply chain of those IoT vendors, which further threatens the supply chain that started the whole thing into motion.

I do not see any simple fix for this problem without defining ‘security of supply chains’ and then describing what actions might endanger that security. I would like to suggest that the definition should specifically address software security requirements.

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - - subscription required.

Friday, March 18, 2022

Bills Introduced – 3-17-22

Yesterday, with the House and Senate both in session (and the Senate preparing to leave for the weekend), there were 73 bills introduced. Four of those bills may receive additional coverage in this blog:

HR 7138 To establish procedures to include certain foreign persons that pose a threat to the security of supply chains of Internet of Things devices on the Department of Commerce's Entity List, and for other purposes. Rep. Obernolte, Jay [R-CA-8]

S 3859 A bill to control the export of electronic waste in order to ensure that such waste does not become the source of counterfeit goods that may reenter military and civilian electronics supply chains in the United States, and for other purposes. Sen. Whitehouse, Sheldon [D-RI]

S 3863 A bill to require the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of information systems of the Department of Veterans Affairs, and for other purposes. Sen. Rosen, Jacky [D-NV]

S 3875 A bill to require the President to develop and maintain products that show the risk of natural hazards across the United States, and for other purposes. Sen. Peters, Gary C. [D-MI] 

HR 7138 will be covered in this blog.

I probably will not be covering S 3859, but there just may be something here worth looking at.

I am not really interested in VA cybersecurity (other than personally, since they maintain information on me), so S 3863 will probably not be covered here, but it raises an interesting mode of cybersecurity regulation that could be used to get around the resistance of many folks to regulations.

I will be watching S 3875 for language and definitions that would include chemical manufacturing facilities and transportation systems in the items that could be at risk of natural hazards.

 
/* Use this with templates/template-twocol.html */