Showing posts with label HR 7174. Show all posts
Showing posts with label HR 7174. Show all posts

Wednesday, September 28, 2022

S 4673 Passed in Senate – NCFI Reauthorization

Yesterday, the Senate discharged the Senate Judiciary Committee from the responsibility of considering S 4673, the National Computer Forensics Institute Reauthorization Act of 2022, and passed the bill under the Senate’ unanimous consent process. There was no debate and no formal vote. The House passed an entirely different version of the reauthorization, HR 7174 back in June.

It will be interesting to see if the House takes up S 4673 and if they then amend the bill by substituting the language from HR 7174. With the Senate ignoring HR 7174 and taking up a bill that was introduced two months after HR 7174 was passed, I do not expect that the Senate would agree to a version of the bill amended in that manner. Insisting on the Senate version of the language would require a conference committee.

Since the major difference between the two bills in the expansion of the definition of information systems to include industrial control systems, I suspect that it is that expansion of coverage that the Senate leadership objects to. If that is the case, working out a compromise might be a problem.


Wednesday, September 7, 2022

Review – S 4673 Introduced – NCIF Reauthorization

Back in late July, Sen Grassley introduced S 4673, the National Computer Forensics Institute Reauthorization Act of 2022. While the bill shares a title with HR 7174 that was passed in the House back in July, there are significant differences between the two bills. For instance, this bill will only reauthorize the program through 2028 instead of the 2032 set in the House bill. Nor does it specifically expand the scope of the NCIF.

Moving Forward

Grassley is the Ranking Member, and four {Sen Feinstein (D,CA), Sen Klobuchar (D,MN), Sen Cornyn (R,TX), and Sen Whitehouse (D,RI)} of his seven cosponsors are members of the Senate Judiciary Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition. I suspect that the bill would pass with significant bipartisan support in Committee.

The timing problem that I have been talking about the last couple of months now is further aggravated in the Judiciary Committee. With there being a chance that the Republicans will ‘control’ (NOTE: anything less than 60 votes is not really controlling” the Senate, the Senate leadership is pushing to see as many judicial nominations as possible moved out of Committee to the floor of the Senate. Nomination hearings (and the requisite staff work) means that there is time for little else, at least between now and the first week in November.

 

There is a chance that the Senate could take up the House bill under the unanimous consent process. They could also adopt the language of this bill as substitute language under the same process. It all depends on if the Senate leadership {Schumer (D,NY) and Chairman Durbin (D,IL)} supports the House or Senate language. Alternatively, language from either bill could be included as part of the year-end spending bill.

Commentary

The changes made by this bill are mainly window dressing, important only to political infighters. They would have no real influence in the operation of the NCIF. The House bill, makes many similar meaningless changes, but it does expand the scope of coverage from strictly IT related issues to include (in passing) control system incidents and crimes in the scope of the systems covered by forensics training and research conducted by NCIF.

 

For more details about the changes to the NCIF authorization made in this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4673-introduced - subscription required.

Thursday, July 14, 2022

HR 7174 Passed in House – NCFI Reauthorization

Last night, the House finally completed their vote on HR 7174, the National Computer Forensics Institute Reauthorization Act. The bill passed by a strongly bipartisan vote of 410 to 16. The bill was initially debated in the House under the suspension of the rules process on June 21st, 2022. At the end of the debate a recorded vote was demanded.

The bill would reauthorize the Secret Service’s NCFI through 2032 and expand the scope of responsibilities for the Institute. It would make several changes to 6 USC 383, including adding a list of definitions of key terms. The bill does not include authorization for expenditures to support these changes.

For a more detailed look at the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7174-introduced - subscription required.

Tuesday, July 12, 2022

Committee Hearings – Week of 7-10-22

With both the House and Senate in session this week, and both trying to get a lot accomplished before the summer recess starts at the end of the month, there is a moderate load of hearings scheduled for this week. We have the NDAA Rules Committee hearing that I have been talking about in the House. There are two Senate hearings of interest: BIS oversight hearing and a counter UAS hearing. The House version of the NDAA will hit the floor this week and there might be along delayed vote on the cyber forensics bill from last month.

NDAA Hearing

Today, the House Rules Committee will take up HR 7900, the FY 2023 NDAA in a rule hearing. The rule will include two abortion bills and an active shooter bill, so there will be some contentious debates in the House this week. Depending on the order that the bills are taken up, we might not see a final vote on the NDAA this week.

The Rules Committee also announced an amendment deadline for a mini-bus spending bill. It looks like the plan is to combine six of the less controversial spending bills into a single bill to bring to the floor next week. This might allow the Senate to actually take up the bill before the end of the fiscal year, something they have not been able to do in a number of years. The deadline for amendments is Wednesday. The rule hearing will likely be next week.  More on this later.

BIS Oversight

On Thursday, the Senate Banking, Housing, and Urban Affairs Committee will hold an oversight hearing on “Advancing National Security and Foreign Policy Through Export Controls: Oversight of the Bureau of Industry and Security”. The sole witness will be Alan Estevez, DOC’s Under Secretary for Industry and Security. There is a possibility that questions will be asked about cybersecurity export controls, but I expect that the focus will be on sanctions on Russia, China, Iran and North Korea; BIS also manages the details of those programs.

Counter UAS Hearing

On Thursday, the Senate Homeland Security and Governmental Affairs Committee will hold a hearing on “Protecting the Homeland from Unmanned Aircraft Systems”. The witness list includes: 

• Robert Silvers, DHS,

• Brad Wiegmann, DOJ,

• Tonya D. Coultas, FAA

This hearing may be a lead up to legislation reauthorizing the very limited authority that DHS and DOJ have for taking out UAS that endanger a limited number of federal activities. That authorization expires later this year. At the very least there should be an interesting discussion about what changes need to be made to the criminal code to allow wider spread counter UAS actions. 

I do expect that Coultas will be asked about the FAA’s continuing lack of action on the rulemaking on allowing critical infrastructure facilities to ask FAA to be declared ‘No Fly Zones’ for UAS. I expect that a reasonable answer might include the reality that a ‘no fly zone’ with no local enforcement capability is just a waste of time.

On the Floor

As noted above, HR 7900 is scheduled to come to the floor this week in the House, along with three other controversial bills. Fifteen new bills are on the schedule to be considered under the suspension of the rules process, including a cybersecurity bill (HR 7535, the Quantum Computing Cybersecurity Preparedness Act) that I have not covered. Additionally, there should be (well, ‘may be’ is probably a better term) votes on seven bills that were debated last month under the suspension of the rules process, including HR 7174, the National Computer Forensics Institute Reauthorization Act of 2022. There are going to be a lot of late nights in the House this week.

Tuesday, June 21, 2022

Committee Hearings – Week of 6-19-22

This week, with both the House and Senate in session and the Summer Recess deadline approaching, there is a moderately heavy hearing schedule. The House Armed Services Committee will markup their FY 2023 NDAA. The House is pushing ahead with spending bill markups while there are still budget hearings being held (including a bunch of closed intel agency hearings). There will also be a hearing looking at the cybersecurity of new technologies. Finally, there are a couple of cybersecurity bills scheduled for consideration in the House.

FY 2023 Spending Bill Markups

Tuesday – House – IER – Subcommittee,

Tuesday – House – EWD – Subcommittee,

Wednesday – House – State – Subcommittee,

Wednesday – House – CJS – Subcommittee,

Thursday – House – ARD – Subcommittee,

Thursday – House – THUD – Subcommittee,

Thursday – House – LHH – Subcommittee, and

Friday – House – DHS & Legislative – Full Committee

Cybersecurity Hearing

On Wednesday, the Cybersecurity, Infrastructure Protection, & Innovation Subcommittee of the House Homeland Security Committee will hold a hearing on “Securing the Future: Harnessing the Potential of Emerging Technologies While Mitigating Security Risks”. The witness list includes:

• Andrew Lohn, Georgetown University,

• Charles Robinson, IBM,

• Ron Green, Mastercard, and

• Rob Strayer, Information Technology Industry Council (ITI)

This looks like it will be concentrating on quantum technology, so I do not expect to hear much about control system security.

On the Floor

The House is scheduled to take up eleven bills today under the suspension of the rules process. They include two cybersecurity bills that I briefly discussed yesterday:

HR 7777 – Industrial Control Systems Cybersecurity Training Act, as amended, and

HR 7174 – National Computer Forensics Institute Reauthorization Act of 2022, as amended

Both bills are likely to pass with substantial bipartisan support, but Republican bomb-throwers are likely to demand recorded votes in their continuing campaign to slow the legislative process.

To be clear there are ‘bomb-throwers’ on both sides of the aisle. This is not a dig against Republicans in general. After all, I was a Goldwater Republican in ’64 and a member of the California Republican Assembly in 1972.

Monday, June 20, 2022

HR 7174 Reported in House – Cyber Forensics

Last week, the House Homeland Security Committee published their report on HR 7174, the National Computer Forensics Institute Reauthorization Act of 2022. The Committee considered the bill on May 19th, 2022. Some relatively minor amendments were adopted, and the Committee ordered the amended bill reported favorably. The bill will be considered by the Full House tomorrow under the suspension of the rules process.

The Report provides a look at how multiple committees can work together when there is overlapping jurisdictions. In this case, the House Judiciary Committee has limited jurisdiction over some parts of the operation of the NCFI and were thus assigned to consider this bill. The Judiciary Committee held no hearings about the bill and the Chairs of the two committees were able to work together to allow the bill to move forward to consideration by the Full House. The Report contains letters between Rep Nadler (D,NY) and Rep Thompson (D,MS), the respective Chairs of the Judiciary and Homeland Security Committees.

There is no telling how much back and forth between the two chairs (and their staffs, of course) occurred to allow this cooperative action. I suspect that Thompson’s amendment to the bill may have been part of the process for moving that agreement forward.

Friday, May 20, 2022

Review - HR 7174 Amended and Adopted in Committee – Cyber Forensics Institute

Yesterday, the House Homeland Security Committee held a business meeting where five DHS related bills were considered, including HR 7174, the National Computer Forensics Institute Reauthorization Act of 2022. Rep Slotkin (D,MI) proposed substitute language and Rep Thompson (D,MS) introduced a brief amendment to that language. The Committee adopted both by voice votes.

The amendments approved by the Committee yesterday do not make any substantive changes to the bill. The bill would still reauthorize the Secret Service’s NCFI through 2032 and expand the scope of responsibilities for the Institute. It would make several changes to 6 USC 383, including adding a list of definitions of key terms. The bill does not include authorization for expenditures to support these changes.

The broad bipartisan support for the bill in Committee essentially ensures that the bill will be considered under the suspension of the rules process. Once the Committee publishes their report on the bill, the bill will be cleared for consideration by the full House.

Thursday, March 31, 2022

Review - HR 7174 Introduced – NCFI Reauthorization

Earlier this month, Rep Slotkin (D,MI) introduced HR 7174, the National Computer Forensics Institute Reauthorization Act of 2022. The bill would reauthorize the Secret Service’s NCFI through 2032 and expand the scope of responsibilities for the Institute. It would make several changes to 6 USC 383, including adding a list of definitions of key terms. The bill does not include authorization for expenditures to support these changes.

Moving Forward

Slotkin and a number of her 14 cosponsors {including Chairman Thompson (D,MS) and Rep McCaul (R,TX)} are members of the House Homeland Security Committee to which this bill was assigned for consideration. This means that there is certainly sufficient influence to see this bill considered in Committee. This bill will certainly be approved in Committee by a substantial bipartisan majority. The bill will likely be considered in the full House under the suspension of the rules process.

Commentary

The addition the three definitions to the bill ensures that the control system security issues fall within the scope of the NCFI. But it does point out once again that there is a disconnect in cybersecurity definitions in the US Code. Here, for example, the bill uses the control system inclusive definition of the term information system while also defining the term ‘incident’ by reference to a section of 6 USC that uses the IT restrictive definition of that term. Technically, that means that in this section wherever the term ‘information system’ is used it includes control systems, but where the term ‘incident’ is used control systems are excluded. I have discussed this problem many times before, but most explicitly here.

For more details on the provisions of this bill, including a look at the expanded responsibilities for NCFI, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7174-introduced - subscription required.

Saturday, March 19, 2022

Bills Introduced – 3-18-22

Yesterday, with just the House in session, there were 36 bills introduced. One of those bills may receive additional attention in this blog:

HR 7174 To amend the Homeland Security Act of 2002 to reauthorize the National Computer Forensics Institute of the United States Secret Service, and for other purposes. Rep. Slotkin, Elissa [D-MI-8]

I will be watching this bill for language and definitions that would include industrial control systems within the scope of Institute.

 
/* Use this with templates/template-twocol.html */