Showing posts with label HR 756. Show all posts
Showing posts with label HR 756. Show all posts

Tuesday, April 16, 2013

House Passes Three Cybersecurity Bills


Today the House considered and passed three cybersecurity bills with broad bipartisan support. All three bills were considered under suspension of the rules which requires a 2/3 vote for passage (I incorrectly said 3/5 the other day). The three bills were:

HR 756, the Cybersecurity Enhancement Act of 2013, 402 – 16;
HR 967, the Advancing America’s Networking and Information Technology Research and Development Act of 2012, 406 – 11; and
• HR 1163, the Federal Information Security Amendments Act of 2013, 416 – 0.

As I expected the no votes were all Republicans; presumably over spending objectives.

If any of these bills make it to the floor of the Senate, they will almost certainly pass with similar bipartisan support. Last session versions of these bills passed in the House only to be ignored by Sen. Reid (D,NV) in the Senate because he was attempting to push through a comprehensive cybersecurity bill. With less pressure on Reid this year because of the President's cybersecurity executive order, there is an increased chance that these bills might be considered and passed in the Senate.


HR 624 Reported in House


Yesterday the House Intelligence Committee reported HR 624, the Cyber Intelligence Sharing and Protection Act, as amended. The report is not yet available from the Government Printing Office (GPO). This formality is a prerequisite to this week’s consideration of this bill by the House.

BTW: The reports for HR 756, Cybersecurity Enhancement Act of 2013 (H Rept 113-33), and HR 967, Advancing America's Networking and Information Technology Research and Development Act of 2013 (H Rept 113-34), are now available from the GPO. There is no new information in either report. Both bills will be considered today under suspension of the rules.

Sunday, April 14, 2013

Committee Hearings – Week of 4-14-13


This week the House and the Senate will be hard at work in Washington and the President’s budget request will take up a lot of time in committees. There will also be a cybersecurity hearing and a look at Sequestration. Oh yes, it’s going to be Cybersecurity Week on the floor of the House.

Budget Hearings

There are too many to discuss in detail so here is a listing:

United States Coast Guard Budget – House Appropriations
Department of Defense Budget – House Appropriations
Department of Transportation Budget – House Appropriations

I’ve added the NIST budget to the ones that I’ll be following this year because of the Cybersecurity Framework under development by that agency.

Cybersecurity

CISPA (HR 624) will be coming to the floor this week so there will be a House Rules Committee hearing on Tuesday afternoon to develop the rule for the consideration of the bill. The only question is if it will be an open rule with amendments from the floor (my guess – not) or a lengthy list of amendments included in the rule (probably). At least a couple of the amendments rejected in Committee last week may be considered by the Committee of the Whole House.

Sequestration

The Subcommittee on National Security of the House Oversight and Government Reform Committee will be holding a hearing on Thursday looking at Sequestration Oversight: Prioritizing Security over Administrative Costs at TSA. There is no witness list yet so we really have no idea if surface transportation security will be addressed, but based upon past history, I doubt it. Congress has a tendency to forget security of trains, trucks and busses.

Cybersecurity Week

As I mentioned earlier, CISPA will be coming to the floor of the House this week as will a number of other cybersecurity bills. At this point CISPA is the only one that will be covered by a Rule; the others will be debated under suspension of the rules.

On Tuesday three bills will be covered under suspension of the rules. This means no more than an hour of debate, no amendments and the leadership considers these bills a slam-dunk for passage since it takes a 3/5th majority to pass bills this way. The bills that will be considered are:

• H.R. 1163 - Federal Information Security Amendments Act of 2013 
H.R. 756 - Cybersecurity Enhancement Act of 2013 
H.R. 967 - Advancing America’s Networking and Information Technology Research and Development Act of 2012 

HR 756 does contain some control system language as does HR 967 though neither are going to have a significant impact on ICS security issues. HR 1163 is a federal IT security measure that I am quite frankly ignoring.

The current plans for CISPA, according to the Majority Leader’s web site, is for debate to start on Wednesday with a final vote before 3:00 pm EDT on Thursday.

Friday, April 12, 2013

Two Cybersecurity Bills Reported in House


Yesterday there were two cybersecurity bills reported in the House by the Committee on Science, Space, and Technology. Those bills were HR 756, Cybersecurity Enhancement Act of 2013, and HR 967, the Advancing America's Networking and Information Technology Research and Development Act of 2013. The submission of these two reports clears the bills for action on the floor of the House as early as next week.

The actual reports are not yet available from the Government Printing Office. I did report on the markups of each of these bills (HR 756. HR 967) so the amended language should offer no real surprises, but there is frequently supporting information in the report that provides additional insight into how the resulting regulations should be written.

Monday, March 18, 2013

HR 756 Ordered Reported Favorably – Cybersecurity R&D


Last Thursday the House Space, Science and Technology Committee amended HR 756, the Cybersecurity Enhancement Act of 2013 and ordered reported favorably. All of the actions were approved by voice votes, a usually reliable sign of bipartisan support. Eight amendments were offered, one was withdrawn and the remainder were adopted.

Bill Does Include Control System Language

In an earlier blog post I stated that this bill did not contain any language specifically addressing control system issues. That was wrong. Somehow I missed a single sentence in §110 that would add paragraph (e)(4) to 15 USC 278g-3. This would add research “associated with improving security of industrial control systems” to research to be conducted by NIST “to determine the nature and extent of information security vulnerabilities and techniques for providing cost-effective information security” {15 USC 278g-3(d)(3)}.

This requirement is shoe-horned into a position that it is not really suited to; ICS research in a section devoted to IT research, but that came about because there is no place in the existing law that addresses control system security. It’s not much for control systems, but it is something. Too bad there was not money authorized for the research.

Increased Funding

One of the eight amendments came from Chairman Smith (R,TX) and it would increase the funding authorized for the various research programs identified in §105 of the bill. Having increased the authorization, however, §206 of the amendment states:

“No additional funds are authorized to carry out this Act, and the amendments made by this Act. This Act, and the amendments made by this Act, shall be carried out using amounts otherwise authorized or appropriated.”

So the NIST Director gets to make the hard political decision as to what programs get cut to pay for these programs. That is a job that more properly belongs to Congress.

Science of Cybersecurity

Rep. Wilson (D,FL) proposed an amendment (that was accepted by a voice vote) that would add §111, Research on the Science of Cybersecurity. This would be research that leads to the development “of a scientific foundation for the field of cybersecurity, including research that increases understanding of the underlying principles of securing complex networked systems, enables repeatable experimentation and creates quantifiable security metrics”.

This is important sounding research, but once again, no new money has been made available to fund the research and, in this case, no specific funding was authorized for the directed research. No money means no research.

Moving Forward

This is a bipartisan bill, it spends no money and looks like it accomplishes something. It is a sure bet to pass floor votes in both the House and Senate, IF (that’s a big ‘if; sorry I couldn’t help myself) it gets to the floor. This bill (HR 2906) passed in the House last session but was never considered in the Senate. That was because the Senate leadership wanted a comprehensive bill and thought piecemeal bills would prevent the consideration of the big bill. With the cybersecurity EO in place that pressure is greatly relieved, so this bill may make it eventually to the President’s desk.

Saturday, March 2, 2013

HR 756 – Cybersecurity R&D


As I noted two weeks ago Rep. McCaul (R,TX) introduced HR 756, the Cybersecurity Enhancement Act of 2013. The GPO finally made a copy available so that we can see the actual language for the bill and it is, as I suspected, virtually identical to the version of HR 2096 adopted by the House in the last session in a bipartisan vote.  

Reauthorization

This is essentially a bill to reauthorize a number of cybersecurity R&D programs. It provides a three year authorization for spending on the following National Science Foundation (NSF) cybersecurity research and development programs:

• Computer and network security research grants, at $90,000/year {§105(b)};
• Computer and network security research centers, at $4,500,000/year {§105(c)};
• Computer and network security capacity building grants, at $19,000,000/ year {§105(d)};
• Scientific and advanced technology act grants, at $2,500,000/year {§105(e)}; and
• Graduate traineeships in computer and network security, $24,000,000/year {§105(f)};

International Standards

Title II of the bill takes on a new level of importance now that the President’s cybersecurity Executive Order has been published as it addresses coordination of federal agencies working on the development of international standards “related to information system security” {§202(a)(1)}. Since the EO emphasizes the adoption of consensus international standards where practical, the US government’s participation in the development of those standards becomes more important.

No Control System Research

While “critical infrastructures for electric power, natural gas and petroleum production and distribution, telecommunications, transportation, water supply, banking and finance, and emergency and government services” {§2 adds to 15 USC 7401(1)} is clearly mentioned in the congressional ‘findings’ that justify the bill, there is no mention of control systems anywhere within the bill. This bill is clearly focused on the larger portion of cybersecurity, information technology.

Moving Forward

HR 2096 passed easily in the House in the last session (most of the opposition came from anti-spending Republicans) and would have passed as easily in the Senate if Sen. Reid hadn’t been so focused on passing a comprehensive cybersecurity bill. With the EO in place to take the heat off in the Senate, this bill should pass as quickly as the leadership decides to bring it to the floor.

Saturday, February 16, 2013

Bills Introduced – 02-15-13


The last day before a 9 day weekend for Congress saw a flurry of bills introduced in the House including one cybersecurity bill. Rep. McCaul (now chairman of the House Homeland Security Committee) introduced HR 756. This bill dealing with cybersecurity R&B is almost certainly a reintroduction of his bill from last session that was one of a small number of cybersecurity bills actually passed in the House, HR 2096. We will have to await its publication by the GPO before we can tell if this has been improved in any way.
 
/* Use this with templates/template-twocol.html */