Showing posts with label ICTS. Show all posts
Showing posts with label ICTS. Show all posts

Monday, October 13, 2025

Review – S 2593 Introduced – Grid ICTS Security

Back in July Sen Scott (R,FL) introduced S 2593, the Preventing Remote Operations by Threatening Entities on Critical Technology for (PROTECT) the Grid Act. The bill would require DOC to submit a report assessing vulnerabilities to the electric grid in the United States from certain Internet-connected devices and applications, and for other purposes. It would also codify EO 13873. No new funding is provided. 

Moving Forward

Scott is not a member of the Senate Banking, Housing, and Urban Affairs Committee to which this bill was assigned for consideration. This means that there is not sufficient influence to see the bill considered in Committee. Since this is mainly a report to Congress bill, I do not see anything in the legislation that would engender organized opposition. That also means that there is no chance that this bill would be considered by the full Senate under regular  order. This bill would probably be adopted under the unanimous consent process, even with its codification of a Trump (45) EO

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2593-introduced-grid-icts-security - subscription required.

Monday, January 6, 2025

Review – BIS Publishes Security ICTS Supply Chain (UAS) ANPRM

Friday, the DOC’s Bureau of Industry and Security (BIS) published an advanced notice of proposed rulemaking (ANPRM) in the federal register (90 FR 271-279) on “Securing the Information and Communications Technology and Services Supply Chain: Unmanned Aircraft Systems”. This ANPRM is looking at implementing the securing the information and communications technology and services supply chain requirements of EO 13873 with regards to unmanned aircraft systems that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries.

Background

In EO 13873, President Trump declared a national emergency with respect to the “unrestricted acquisition or use in the United States of information and communications technology or services designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries augments the ability of foreign adversaries to create and exploit vulnerabilities in information and communications technology or services, with potentially catastrophic effects, and thereby constitutes an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States.”

In the EO the term ‘information and communications technology or services’ is defined as “any hardware, software, or other product or service primarily intended to fulfill or enable the function of information or data processing, storage, retrieval, or communication by electronic means, including transmission, storage, and display”.

Potential Rule

BIS is considering developing a new regulation that could include mitigation measures and prohibitions addressing:

• Onboard computers responsible for processing data and controlling UAV flight

• Communications systems including, but not limited to, flight controllers, transceiver/receiver equipment, proximity links such as Global Navigation Satellite Systems (GNSS) sensors, and flight termination equipment,

• Flight control systems responsible for takeoff, landing, and navigation, including, but not limited to, exteroceptive and proprioceptive sensors,

• Ground control stations (GCS) or systems including, but not limited to, handheld flight controllers

• Operating software including, but not limited to, network management software,

• Mission planning software,

• Intelligent battery power systems,

• Local and external data storage devices and services, and

• Artificial intelligence (AI) software or applications.

Solicitation for Comments

BIS is soliciting public comments on these questions to advance their rulemaking process. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # BIS-2024-0058). Comments should be submitted by March 4th, 2025.

Commentary

I am disappointed that BIS did not include any questions about cybersecurity protections for UAS, and how the applications (or absence) of such protections could mitigate the risks discussed in this ANPRM. I would like to propose two questions that could provide additional information necessary for the BIS rulemaking:

 

• What cybersecurity controls are in place that could prevent unauthorized access/control of UAS?

• What aftermarket applications are available for UAS that could mitigate unauthorized access/control of UAS?

• Could additional cybersecurity controls be developed that would prevent unauthorized access/control of UAS?

 

For more information on this ANPRM, including discussion about the information that BIS is looking for, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bis-publishes-security-icts-supply - subscription required.

Wednesday, December 18, 2024

BIS Sends ICTS Final Rule for Connected Vehicles to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. The advanced notice of proposed rulemaking (ANPRM) was published on March 1st, 2024.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign governments or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 regarding connected vehicles. involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign governments or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 regarding connected vehicles.”


Records show that a notice of proposed rulemaking on this topic was submitted to OIRA on August 20th, 2024 and approved by that agency on September 19th, 2024, but no such NPRM has been published in the Federal Register. I suspect that the documents submitted to OIRA were supposed to be for a revised NPRM not a final rule.

Saturday, December 14, 2024

OMB Approves BIS ICTS Security for UAS ANPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an advanced notice of proposed rulemaking (ANPRM) from DOC’s Bureau of Industry and Security (BIS) on Securing the Information and Communications Technology and Services Supply Chain: Unmanned Aircraft Systems”. The ANPRM was sent to OIRA on November 12th, 2024.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) will publish an advance notice of proposed rulemaking (ANPRM) to seek public comment on questions related to transactions involving information and communications technology and services integral to Unmanned Aerial Systems that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign governments or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (EO) 13873. This ANPRM will assist BIS in determining the technologies and market participants most appropriate for regulation pursuant to EO 13873.”

Wednesday, November 27, 2024

OMB Approved DOC ICTS Supply Chain Security Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the Department of Commerce on “Securing the Information and Communications Technology and Services Supply Chain”. The notice of proposed rulemaking was published on November 27th, 2019. An interim final rule (IFR) was published on January 19th, 2021.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“Pursuant to Executive Order 13873 [link added] of May 15,2019,"Securing the Information and Communications Technology and Services Supply Chain” and Executive Order 14034 [link added] of June 9, 2021, Protecting Americans' Sensitive Data From Foreign Adversaries,” the Department of Commerce is finalizing the rule that sets forth the process and procedures that the Secretary of Commerce will use to identify, assess, and address transactions that pose an undue risk to the security, integrity, and reliability of information and communications technology and services provided and used in the United States.”

With a probable effective date well after Trumps inauguration in January, the new administration will be able to effectively kill this final rule with an executive order (the underlying IFR would take a new rulemaking to undo). While the rulemaking was initiated under Trumnp 45, the Biden Administration put their stamp on the rulemaking, so it is unclear whether the new administration would let this rule stand.

I will probably not be covering the publication of this final rule in any detail. I will, however, note its publication in the appropriate Short Takes post.

Wednesday, November 13, 2024

BIS Sends UAS ICTS Security ANPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Unmanned Aircraft Systems”.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) will publish an advance notice of proposed rulemaking (ANPRM) to seek public comment on questions related to transactions involving information and communications technology and services integral to Unmanned Aerial Systems that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign countries or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (EO) 13873 [link added]. This ANPRM will assist BIS in determining the technologies and market participants most appropriate for regulation pursuant to EO 13873.”

While the incoming Trump Administration is expected to be regulatorily reluctant this is an anti-China measure that would generally be expected to receive active support from the President. This is early enough in the regulatory development cycle that it will not be difficult to put the new administration’s stamp on the language of the rulemaking.

Wednesday, August 21, 2024

BIS Sends ICTS Connected Vehicle NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOC’s Bureau of Industry and Security (BIS) on “Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles”. BIS published [removed from paywall] an advanced notice of proposed rulemaking (ANPRM) on this topic on March 1st, 2024.

According to the Spring 2024 Unified Agenda entry for this rulemaking:

“The Department of Commerce’s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign countries or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873. BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 [link added] regarding connected vehicles.”

Monday, June 24, 2024

DOC Sends ICTS Supply Chain Final Rule to OMB

On Friday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the Department of Commerce on “Securing the Information and Communications Technology and Services Supply Chain”. The notice of proposed rulemaking for this rule was published on November 27th, 2019. An interim final rule was published on January 19th, 2021.

According to the abstract for this rulemaking in the Fall 2023 Unified Agenda:

“Pursuant to Executive Order 13873 of May 15, 2019, "Securing the Information and Communications Technology and Services Supply Chain,” (Executive Order) the Department of Commerce (the Department) is implementing the process and procedures that the Secretary of Commerce (Secretary) will use to identify, assess, and address transactions that pose an undue risk to the security, integrity, and reliability of information and communications technology and services provided and used in the United States.”

 

 
/* Use this with templates/template-twocol.html */