Showing posts with label HR 8. Show all posts
Showing posts with label HR 8. Show all posts

Thursday, May 26, 2016

House Amends and Passes S 2012 – Energy Policy

Last night the House passed an amended version of S 2012, the Energy Policy Modernization Act of 2016 by a nearly party-line vote of 241 – 178. Later the House voted to insist on its amendment and called for a conference committee.

Bill Provisions of Interest


The bill includes the following cybersecurity provisions from HR 8:

Sec. 1104. Critical electric infrastructure security.
Sec. 1106. Cyber Sense.
Sec. 2008. Report on smart meter security concerns.
Sec. 3126. Internet of Things report.

The bill includes the following chemical transportation safety provision from HR 8:

Sec. 5009. Study of volatility of crude oil.

Moving Forward


The Senate version of the bill passed by a vote of 85 – 12 with only Republicans voting No. The House version passed on a mainly partisan vote with 172 Democrats voting no. It will take the conference committee a while to work out a version of the bill that will be able to come to a vote in the Senate and still be acceptable to the leadership in the House. The bill that passed yesterday would not make it to the Senate floor.

A final version of the bill will probably include the provisions listed above; there is nothing there that is objectionable. The Senate bill had a slightly different version of §1104. It will be interesting to see how the differences are worked out.

The Senate bill has one additional cybersecurity provision that should also make it into the final bill:


Sec. 2002. Enhanced grid security.

Thursday, January 28, 2016

Senate Considering S 2012

Yesterday the Senate began consideration of S 2012, the Energy Policy Modernization Act of 2015. Somehow I missed this bill when it was introduced back in September, but it is very similar to HR 8 that was passed by the House last month. The bill does contain cybersecurity related provisions, but certainly not all of those included in the House bill.

Critical Electric Infrastructure Information

Like the House bill, §2001 amends the Federal Power Act to include specific authority to designate Critical Electric Infrastructure Information (CEII). As I explained in an earlier post, while a CEII program does currently exist it is not specifically authorized by statute. This will become important when the National Archives and Records Administration finally publishes its final rule on Controlled Unclassified Information (CUI). Being authorized by statute would allow the DOE Secretary more latitude on the way CUI is controlled.

There are several provisions of the HR 8 CUI section that are not included in S 2012. They include provisions associated with:

• Submission of information to congress;
• Disclosure of protected information;
• Duration of designation;
• Removal of designation; and
• Judicial review of designations

The lack of coverage of these items in the bill simply means that the NARA regulations would govern these areas, not the DOE regulations.

Enhanced Grid Security

Section 2002 of the bill establishes a number of cybersecurity programs, some of which already exist in fact, if not in law. Each of the programs include authorized funding. They include:

• Cybersecurity sector specific agency designation;
• Cybersecurity for the energy sector research, development, and demonstration program;
• Energy sector component testing for cyberresilience program;
• Energy sector operational support for cyberresilience program;
• Modeling and assessing energy infrastructure risk;
• Study on expanding industry membership and participation in ES–ISAC

The component testing program is somewhat similar to the Cyber Sense program include in §1106 of HR 8. The Senate version is not nearly as comprehensive or detailed. The Senate program does include $15 Million in annual funding where the Cyber Sense program included no funding, relying entirely on 3rd party testing and certification.

Moving Forward

Consideration of the bill continues today and there is not currently a schedule for a final vote. Sen. Murkowski (R,AK) is working hard to keep the amendment process limited to energy matters so that the bill does not get saddled with any of the controversial riders that have earned HR 8 a Presidential veto threat.


It is very likely that this bill will pass in the Senate. The House will then have to decide whether or not to accept the Senate bill or insist on the language of HR 8. If the latter occurs there would probably be a conference committee formed to work out the differences in the two bills.

Thursday, December 3, 2015

House Amends and Passes HR 8

This morning the House passed HR 8 by a mainly party-line vote of 249 to 174. The House concluded their consideration of the 35 amendments to the bill before the vote. All four of the amendments I discussed Tuesday passed by voice votes yesterday.


With a Presidential veto promised if this bill passes a Senate vote today’s vote did not indicate that there was anywhere near enough support for this bill to overcome a veto if the bill were passed in the Senate. It is unlikely, however, that this bill will be considered in the Senate with the solid Democratic opposition to the bill.

Tuesday, December 1, 2015

HR 8 Amendments

The House Rules Committee met this afternoon to craft the rule for the consideration of amendments to HR 8, the North American Energy Security and Infrastructure Act of 2015, on the floor of the House. A structured rule was approved with 38 amendments to be considered during the floor debate.

Amendments of Possible Concern

Of the six amendments that I discussed yesterday only four were included for possible consideration on the floor. Those four are:

4. Franks (R,AZ) #93 (LATE) (REVISED) Secures the most critical components of America's electrical infrastructure against the threat posed by a potentially catastrophic electromagnetic pulse.
9. Jackson-Lee (D,TX) #84 (LATE) Directs the Secretary of Energy to submit to the Committees on Energy and Commerce and Natural Resources of the House of Representatives and the Committee on Energy and Natural Resources of the Senate a report on methods to increase electric grid (10 minutes) resilience with respect to all threats, including cyber attacks, vandalism, terrorism, and severe weather, no later than 120 days after the date of enactment of the Act.
32. DeSaulnier (D,CA), Lowey (D,NY), Garamendi (D,CA) #34 Requires the Department of Energy to study the maximum level of volatility that is consistent with the safest practicable shipment of crude oil.
38. Norcross (D,NJ) #19 (REVISED) Directs the Secretary of Energy to study weaknesses in the security architecture of certain smart meters currently available.

The revision to the Franks amendment added an exemption from the requirements of the amendment for the Tennessee Valley Authority and the Bonneville Power Administration.  The revision to the Norcross amendment adds a requirement for the Secretary to ‘promulgate rules’ to correct the weaknesses discovered in the required study.

Moving Forward

The amendment process will probably start tomorrow. With only 10 minutes of ‘debate’ on each amendment it should go pretty quickly. I expect that there will be a final vote on the bill tomorrow. While the bill will almost certainly pass, the question will be how many Democrats vote for the bill. With the President promising a veto of the bill the Republicans need a total of 290 votes to override aveto.

Monday, November 30, 2015

HR 8 Rule Approved by Rules Committee

This evening the House Rules Committee met to craft the rule for the Consideration of HR 8, the North American Energy Security and Infrastructure Act of 2015. The version of the bill being considered includes the original bill, amendments adopted by the House Energy and Commerce Committee, modified versions of HR 2295 (as a new §1111) and HR 2358 (as a new §1112), along with some technical amendments proposed by Rep. Upton (R,MI). The rule for HR 8 adopted this evening only covers the initial 1 hour of general discussion of the bill, not any amendment process on the House Floor.

Possible Amendments

A total of 94 proposed amendments to HR 8 were submitted to the Rules Committee. If a restrictive rule for the amendment process is adopted, it is likely that only selected amendments from this list would be considered on the House floor. It is not clear from tonight’s Committee actions that a restricted rule will be adopted at a future hearing.

Of those amendments there are only six that may be of specific interest to readers of this blog. They are:

#19 Norcross (D,NJ) – Directs  the Secretary of Energy to study weaknesses in the security architecture of certain smart meters currently available, and promulgate regulations to mitigate those weaknesses.

#21 Norcross – Allows the Secretary of Energy to address prospective grid security emergencies proactively.

#34 DeSaulnier (D,CA), Lowey (D,NY) – Requires  the Department of Energy to study the maximum level of volatility that is consistent with the safest practicable shipment of crude oil.

#84 Jackson-Lee (D,TX) – Directs the Secretary of Energy to submit to the Committees on Energy and Commerce and Natural Resources of the House of Representatives and the Committee on Energy and Natural Resources of the Senate a report on methods to increase electric grid resilience with respect to all threats, including cyber attacks, vandalism, terrorism, and severe weather, no later than 120 days after the date of enactment of the Act.

#92 Garamendi (D,CA) – Sets the maximum volatility threshold for crude oil transported by rail at 8.5 psi until a national standard is established.

#93 Franks (R,AZ) – Secures the most critical components of America's electrical infrastructure against the threat posed by a potentially catastrophic electromagnetic pulse.

Moving Forward

The initial consideration of HR 8 under the rule approved this evening will probably start tomorrow. Based upon the way the House dealt with HR 22 earlier this month it is very possible that there will not be any more work by the Rules Committee on HR 8 and that all 94 amendments submitted to date will be allowed to be introduced on the House floor. There is a minor chance that there will be an open amendment process on this bill that would consider any offered amendments.

The two crude oil volatility amendments (#34 and #92) of those listed above are the only ones that have any significant controversy associated with them. I would expect that all of the others could pass in floor votes. Since #34 would effectively only require a study and report to Congress, I think that it could pass. The Garamendi amendment will certainly be opposed vigorously by the oil industry and that limits it chance of passing.

Commentary

The Garamendi amendment is very similar in intent to HR 2379.


I did a somewhat detailed explanation of the shortcomings of the use of Reid Vapor Pressure measurement in my discussion of HR 1679. Garamendi continues to try to use this method even though it is ill suited to the differentiation of crude oil flammability or explosiveness. This is a fairly typical case of a politician not understanding the technical details of what he is attempting to legislate. The DeSaulnier amendment, on the other hand, requires the Secretary of Transportation to study and set a volatility standard for crude oil; leaving the technical details to the professionals.

Sunday, October 11, 2015

Energy and Commerce Committee Amends and Passes HR 8

A week and a half ago the House Energy and Commerce Committee marked up HR 8, the North American Energy Security and Infrastructure Act of 2015 with a party line final vote on passage of 32 to 20. The substitute language amended and adopted by the Committee turned the bill from one enjoying at least some measure ofr bipartisan support to a bill that was approved along mostly party lines. In addition to the substitute language there were another 40 amendments offered to the bill in two days of hearings.

Only five of those amendments will be of specific interest to readers of this blog. Two of those amendments dealt with internet of things (IOT) provisions, one modified the rules for Critical Electric Infrastructure Information, one included cybersecurity requirements for technology demonstration projects and the final one set cybersecurity requirements for smart building research.

IOT Requirements

There were two amendments to the bill submitted by Rep. Lujan (D,NM) that dealt with IOT issues. The first was a short amendment adding IOT reporting requirements to existing requirements for an updated report on Server and Data Center Energy Efficiency {§4112(d)} and on energy and water savings from thermal insulation in federal buildings (§4113).

The second amendment would add a new section to the bill {§4127} that would require the Secretary to submit a report to Congress on “the utilization of advanced technologies such as Internet of Things end-to-end platform solutions to provide real-time actionable analytics and enable predictive maintenance and asset management to improve energy efficiency wherever feasible”. It requires the Secretary to “to encourage and utilize Internet of Things energy management solutions that have security tightly integrated into the hardware and software [emphasis added] from the outset”.

Only the first amendment was actually considered by the Committee and it was adopted by a voice vote.

CEII Requirements

An amendment by Rep Eshoo (D,CA) modified the new §215a being added to the Electric Power Act by §1104 of the bill. It added three new subparagraphs to §215a(d) and modified a fourth. It modified (d)(7) to clarify that the implementation of the CEII requirements would be used only to “protect from disclosure only the minimum amount of information necessary to protect the security and reliability of the bulk-power system and distribution facilities”. The new provisions establish:

• That CEII designations do not prohibit sharing the protected information with Congress;
• A 5 year time limit for CEII designation on information;
• CEII designation removal requirements when the information can “no longer be used to impair the security or reliability of the bulk-power system or distribution facilities”; and
• Judicial review procedures for CEII information designations.

This amendment was adopted by a voice vote.

Technology Demonstration Projects

Rep. Sarbanes (D,MD) introduced an amendment that added a new §1111 to the bill that addressed requirements for the Secretary to establish a financial assistance program for technology demonstration projects “related to the modernization of the electric grid, including the application of technologies to improve observability, advanced controls, and prediction of system performance on the distribution system and related transmission system inter-dependencies” {§1111(a)}.

Key requirements for these programs include the demonstration of “secure integration and management [emphasis added]of energy resources, including distributed energy generation, combined heat and power, micro grids, energy storage, electric vehicles, energy efficiency, demand response, and intelligent loads” {§1111(b)(2)(A)} as well as “secure integration [emphasis added] and interoperability of communications and information technologies” {§1111(b)(2)(B)}.

While ‘secure integration’ is not specifically defined there is a specific requirement that each eligible project “shall include the development of a cybersecurity plan written in accordance with guidelines developed by the Secretary” {§1111(c)}.

This amendment was not officially considered by the Committee.

Smart Building Acceleration

Rep. Welch (D,VT) proposed an amendment that called for the establishment of a Federal Smart Building Program. There were a number of cybersecurity requirements included the new §4117 that would be added to HR 8.

The most interesting are included in the definition portion of the new section. First the term ‘internet of things technology solution’ was defined as “a solution that improves energy efficiency and predictive maintenance through cutting-edge technologies that utilize internet connected technologies including sensors, intelligent gateways, and security embedded hardware [emphasis added]” {§4117(a)(1)}. Then the term ‘smart building’ includes the requirement that it is “cybersecure” {§4117(a)(3)}.

The descriptions of the technologies that to be included in the studies outlined in this new section include a requirement that selection includes ‘showing promise for’ “establishing cybersecurity” {eg: §4117(c)(3)(A)(ii)(IV)}.

Additionally, as part of the existing ‘Better Building Challenge’ paragraph (d) includes a requirement that new research and development programs should include (among other things) “protecting against cybersecurity threats and addressing security vulnerabilities of building systems or equipment” {§4117(d)(2)(B)(vi)}.

This amendment was not officially considered by the Committee.

Moving Forward

When this bill was originally introduced it looked like it would enjoy significant bipartisan support. The version of the bill being reported out of Committee has been modified with enough controversial items (none of specific interest to readers of this blog) that the bill will have to be brought to the floor of the House under a rule, probably with extended debate and at least a number of floor amendments. If not substantially amended it looks like this bill will not make it to the floor of the Senate after it passes in the House.

Commentary

The Committee web page dedicated to this markup hearing has a lot of information on it but it is missing even more. There are 41 listed amendments proposed for the bill but actions are listed only for 28. Since six of those listed actions are “withdrawn” it is not clear what happened to the other 13 amendments. It is possible that some of them were adopted ‘without objection’ and that that disposition was not reported on the page. I won’t be able to tell for sure until the Committee Report is printed.

This is kind of important for those of us concerned about cybersecurity issues. All of the amendments that contained cybersecurity provisions fall among those 13 missing amendments (that I reported above as not being ‘officially considered’.

Even if none of those amendments make their way into the bill, the cybersecurity provisions that I reported above mark a sea change in the way that Congress is trying to deal with cybersecurity issues. I have noted this on a couple of occasions now, but it bears repeating that smaller, targeted provisions like these will probably have more effect (when adopted) on private sector cybersecurity activities than will big cybersecurity bills like the still uncompleted information sharing bills wending their inconclusive ways through the halls of Congress, even if they are eventually passed (and that is far from a foregone conclusion).

What is really important about this change is that it shows that congress critters and their staffs are finally starting to realize that cybersecurity is not a standalone topic, but rather a part of everything in our lives that includes cyber devices. All of the public beating of the cybersecurity drums is finally starting to pay off. If this is finally starting to be recognized by Congress it can only mean that the upper echelons of corporate America are also starting to realize the seriousness of the cybersecurity problems that we are facing in the 21st Century.


Friday, September 18, 2015

HR 8 Introduced – Energy Security

On Wednesday Rep Upton (R,MI) introduced HR 8, the North American Energy Security and Infrastructure Act of 2015. The bill mainly addresses energy supply chain issues, but it does have two provisions dealing with actual security issues. The first is protection of information about bulk electrical system security issues and the second is a new cybersecurity program.

Information Protection

Section 1104 of the bill would add a new section (§215A; Critical Electric Infrastructure Security) to the Federal Power Act (16 USC 824 et seq.). The new section would provide authority for the Secretary of Energy to address a grid security emergency {new §215A(b)} and establish a program for the protection of critical electric infrastructure information. The provisions of this section are essentially those found in HR 2271 which I have previously discussed in detail.

While a CEII program does currently exist, pending regulations on controlled but unclassified information (CUI) from the National Archives and Records administration, treat such programs differently if they are authorized by law.

Cyber Sense Program

Section 1106 requires the Energy Secretary to establish a Cyber Sense Program to identify and promote cyber-secure products intended for use in the bulk-power system. The program would allow voluntary industry participation and would include {§1106(b)}:

• A testing process to identify products and technologies intended for use in the bulk-power system, including products relating to industrial control systems, such as supervisory control and data acquisition systems;
• The establish and maintain cybersecurity vulnerability reporting processes and a related database for products in the Cyber Sense program;
• Regulations regarding vulnerability reporting processes for products tested and identified under the Cyber Sense program; and
• Technical assistance to utilities, product manufacturers, and other electric sector stakeholders to develop solutions to mitigate identified vulnerabilities in products tested and identified under the Cyber Sense program.

This section would also require the Secretary to provide for public notice and comments before establishing or changing the required testing program. Products included in the program would be required to be tested every two years.

The bill does not specifically mandate that the results of the product testing should be considered as Critical Electric Infrastructure Information (CEII). It does, however, require that “any vulnerability reported pursuant to regulations promulgated under subsection (b)(3), the disclosure of which could cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be exempt from disclosure” under the Freedom of Information Act or any similar State and local laws.

Moving Forward
As I noted in my earlier post the assignment of ‘HR 8’ to this bill instead of a sequential bill number indicates that the Republican leadership in the House considers this bill a high political priority. It was considered in a markup hearing yesterday before the House Energy and Commerce Committee, but Committee web page does not yet provide any results of that consideration. I expect, however, that the bill was adopted by voice vote.

Commentary

The new Cyber Sense Program proposed by this bill is the first serious attempt by Congress to deal with the problems associated with industrial control system security. The idea of the Federal government establishing a testing and certification program for ICS components and systems is certainly an innovative approach to control system security.

Since this bill does not provide any funding for the program, it is fairly clear that the authors intend this testing to be done by third-party organizations and that is reinforced by the requirement for the Secretary to “oversee Cyber Sense testing carried out by third parties” {§1106(b)(8)}. The problem becomes that, since the Energy Department is not paying for the testing, that it will most likely be the vendor that pays. This always raises the potential issues of testers being beholden to the people that make the products being tested.

The establishment of regulations for vulnerability reporting for Cyber Sense products is something that was fairly glibly added to this bill. But, taken along with the information sharing restrictions outlined, this is going to be problematic. Except for equipment that is uniquely used by the bulk-power system, trying to regulate how security vulnerability reporting is conducted without intimately involving at least ICS-CERT is going to create more problems than it solves.

A brief example will help explain the problem. A private security researcher discovers a vulnerability in a PLC that is part of the Cyber Sense program, but is also used in a wide variety of other industrial control systems. Normally he would have a choice of coordinating that vulnerability disclosure with the vendor, ICS-CERT (or any one of a number of other coordination agencies) or publicly disclosing the vulnerability. Under the new program, if he instead disclosed it to the Cyber Sense program, then there would be no public disclosure through ICS-CERT or the vendor. In fact, if the new regulations were to declare this disclosure to the Cyber Sense to be CEII information (a logical move), then ICS-CERT would not be able to post it to the US-CERT Secure Portal because people without a CEII need-to-know have access to that system.

Crafters of this bill missed one of the biggest potential incentives for using Cyber Sense components. DHS has the Safety Act program under their Science and Technology Directorate that provides important legal liability protections for providers of Qualified Anti-Terrorism Technologies. This bill should have set up a similar program for Cyber Sense vetted products.

I would like to suggest that instead of making the vulnerability information CEII and limiting the disclosure to just the energy sector, that the bill should have designated ICS-CERT as the agency responsible for coordinating disclosures of vulnerabilities for all Cyber Sense Products. It would then go on to require that ICS-CERT initially release the vulnerability information on the US-CERT Secure Portal and only make full public disclosure in coordination with the Department of Energy organization overseeing the Cyber Sense program. That way non-energy sector organizations using the same equipment would have an opportunity to fix their devices before the public disclosure of the vulnerability.


Now, I really like the idea of an independent agency that does in depth security vulnerability testing of control system components and certifying some level of minimum security for such devices. That would certainly make the purchasing of secure ICS components much easier. But we do need to be careful how that is done to prevent the most egregious unintended consequences.

Thursday, September 17, 2015

Bills Introduced – 09-16-15

There were 33 bills introduced in the House and Senate yesterday. Of those only one may be of specific interest to readers of this blog:

HR 8 North American Energy Security and Infrastructure Act of 2015 Rep. Upton, Fred [R-MI-6]

This bill will only receive additional coverage here if it contains requirements for cybersecurity or physical security of power production or transmission facilities.


Note: The first 20 House bill numbers are reserved at the beginning of the session for the Speaker to use. They are typically doled out for legislation that has a high political priority for the majority party.
 
/* Use this with templates/template-twocol.html */