Showing posts with label Legislation. Show all posts
Showing posts with label Legislation. Show all posts

Sunday, January 4, 2026

Congress in 2026

Tomorrow marks the first day of the Second Session of the 119th Congress. While there have been no new elections since the last real session of the 119th in 2025, there have been a number of political changes that may affect how well the Republicans will control the House and Senate. This could have major legislative implications particularly in the House.

Republican control of the House has already been weakened by the resignation (effective tomorrow) of Rep Green (R,GA). Until Georgia holds a special election to replace her, there will be one fewer vote for their narrow majority when the matter follows a party-line vote. One or two missing Republicans on votes could mean a Democratic majority, and this is an election year so there will be an increase in the number of missing congress critters due to electioneering. This will affect both sides of the aisle, but it is something that Speaker Johnson is going to have to pay close attention to in his vote scheduling.

Another problem that will face both Johnson and Majority Leader Thune (R,SD), is the increasing number of members that are not seeking reelection. According to BallotPedia.org there are 53 members of Congress (9 in the Senate and 44 in the House) who have announced that they will not be running for reelection in their current seat, and that number is expected to increase. While a slim majority are running for another office, 26 (8 in the Senate and 18 in the House) are retiring.

The seven Republicans retiring in the House are going to be the ones to watch. Since they are no longer subject to primary threats by the President, they are going to be harder to press to toe the line on key votes. Most of them will continue to vote with the caucus on most issues, but we are going to see an increasing number joining Democrats on the moderate sides of votes. The more radical Republicans in the retirement group {Rep Roy (R,TX) for instance} are also going to be more difficult to press into service.

Thune is going to face a similar problem in the Senate, particularly on cloture votes and some nominations. This is going to make the political dealing in amendment votes much more difficult. Both sides of the Republican spectrum are going to be placing conflicting demands on Thune, and this will make it more difficult to pass even slightly controversial bills.

Discharge petitions are another area where some of these retiring Republicans in the House will make life difficult for the Speaker. Minority Leader Jefferies (D,NY) is going to be hard at work finding more issues where a few retiring Republicans will be swayable for signing discharge petitions to bring legislation to the floor that Johnson and the Administration oppose. This has already started to be an issue, but it will increase in 2026.

The other election related problem that both Republican leaders in Congress are going to have to face is that moderates seeking reelection are going to be increasingly reluctant to toe the party line as the President’s popularity continues to decline. This will become a major problem after primaries are held this year when swing district politicians have to moderate their stances to keep attracting moderate voters from the other side. Johnson and Thune both understand this and will try to pass the more radical portions of their agenda before the primaries. I expect, however, that the President will continue to press for his agenda right up to election day (and of course beyond). This will particularly affect spending bills this summer and fall. There will be almost no chance that any regular spending bills will reach the President’s desk before the election, and there will be a very real chance of a shutdown again this year.

Sunday, February 9, 2025

Legislative Housekeeping, 118th Congress – 2-9-25

This week the GPO printed the text of one of the last two bills that I am tracking from the 118th Congress:

S 5468, the Coast Guard Authorization Act of 2024

The GPO is continuing to have problems keeping up with the number of bills being introduced in the 119th Congress. There have been 1,864 bills introduced so far this session. I am currently tracking 30 of those bills. Only six of those bills have had the text printed (3 are disapproval resolutions that are extremely short). The earliest date of the bills without text is January 17th. Interestingly, it seems that the backlog is worse in the House introduced bills than in those from the Senate, the oldest un-texted bill in the Senate that I am following is January 25th.

Sunday, January 5, 2025

118th Legislation Housekeeping – 1-5-24

No new reports were published this week.

Texts of two bills were published:

HR 10320 - New Space Age Act of 2024, and

HR 10333 - Defense Hackathon Act of 2024

Sunday, December 29, 2024

End of Session Housekeeping – 118th Congress – 12-29-24

With the end of the 118th Congress fast approaching, nothing but one pro forma session for each house until they adjourn sine die on January 3rd, it is time to catch up on legislation files that are dying with the session’s end. Committees are busy publishing reports that no one will read and the GPO is catching up on publishing bills that will have no effect. Instead of trying to complete writeups on each of these housekeeping items, I am simply going to provide a list of each of the bills that I would normally expect to cover in this blog with the appropriate links. If anyone wants me to cover one of these bills in detail in my blog, just drop me a comment on this post; I will see if I can work them into the schedule.

Committee Reports

The following bills were reported by Committees; the reported versions of the bills are available, but the committee reports are not (links are to the published bill):

S 559 Reported in Senate – Fire Grants and Safety Act,

S 4630 Reported in Senate – Streamlining Cybersecurity Regs,

S 4697 Reported in Senate – Healthcare Cybersecurity,

S 5028 Reported in Senate – Contractor Cybersecurity,

S 5321 Reported in Senate – DHS Cybersecurity Interns

Text of Introduced Bills

There were no bills published this week that I am currently following. There are nine House bills that I am still waiting to see published and five Senate bills.


Tuesday, January 17, 2023

To Legislate or Not, that is the Question

Maybe you saw a news report yesterday (here for example) about a legislative attempt to ban the sales of electric vehicles in Wyoming. The attempt to protect the crude oil production industry in the State sounded serious and fit in with various anti-environmental, anti-wokism politics that are receiving national attention right now. Only according to a Washington Post article published today, the legislators were not really serious, it was more about responding to a recent law passed in California outlawing the sale of gasoline powered vehicles in that State by 2035.

I have frequently pointed out in this blog that the introduction of a piece of legislation does not mean that the bill will become law, the vast majority do not. I have also noted on occasion that the introduction does not mean that the sponsor ever had any intention to see the bill passed. Sometimes it is simply an effort to get their colleagues (or the public) to start looking at a problem. More frequently, unfortunately, it is more of a fund-raising effort, making it look like the sponsor is working on a favorite issue of a high-spending contributor or significant voting block.

Similarly, a small majority in the House (currently the Republicans, but of course the Democrats did the same) will pass a controversial bill knowing full well that it has no chance to be considered in the Senate (where consideration of a bill can be blocked by 41 Senators), and if it were (through some legislative miracle) it would never be signed by the President. It makes it look like the small majority is doing something, it fires up the conservative (liberal) base, and keeps money coming in to the campaign coffers. So, maybe in two years, the small majority will become big enough to ‘actually accomplish something’.

This is one of the reasons that when I look at a piece of legislation here in this blog, I always try to look not only on what it attempts to accomplish, but its chance of making it through the legislative process.

Wednesday, July 21, 2021

6 Cybersecurity Bills Passed in House – 7-20-21

Yesterday the House passed six cybersecurity bills as part of an en bloc vote on 21 bills that were considered on Monday and Tuesday under the suspension of the rules process. The recorded vote was 319 to 105 with the Republican vote nearly evenly split. The six cybersecurity bills were:

HR 2928 – Cyber Sense Act of 2021

HR 1871 – Transportation Security Transparency Improvement Act,

HR 3138 – State and Local Cybersecurity Improvement Act, as amended,

HR 1833 – DHS Industrial Control Systems Capabilities Enhancement Act of 2021, as amended,

HR 2980 – Cybersecurity Vulnerability Remediation Act, as amended,

HR 3223 – CISA Cyber Exercise Act

Friday, March 12, 2021

Philosophy of Cybersecurity Legislation – Part 4: Vulnerability Reporting

This is part of a continuing series on the Philosophy of Cybersecurity Legislation. With all of the calls for improving cybersecurity and the increasing sense that legislation is necessary this series will try to define the necessary parameters for effective cybersecurity legislation. The earlier posts in the series were:

Part 1: What to Regulate

Part 2: How to Regulate

Part 3: Information Sharing

Civil Liability for Vulnerabilities

Again, I will start this discussion out from an unusual point, the civil liability for vulnerabilities. There are many reasons for the existence of exploitable vulnerabilities in modern software and firmware, but arguably one of the main reasons is the financial/time pressure to get new products to market make secure coding practice and vulnerability testing too expensive for most vendors. One certain way to shift that cost/benefit analysis would be to make vendors liable for damages related to exploits of cyber vulnerabilities in their products.

To do this, our cybersecurity legislation would establish the presumption under law that a cyber-attack that exploited an undisclosed vulnerability in a product was aided and abetted by the producer of that product by failure to prevent, identify and/or remediate the exploited vulnerability. In cases where a vulnerability was disclosed, and the only remediation made available was the suggestion of actions that the owner of the product could take to prevent exploit, the victim would still sue for civil liability if they could show that they had made a good-faith effort to follow the suggested actions.

Vulnerability Research

There are all sorts of reasons why there would be some not-so-minor objections to this change in product liability law, but I will let that stew for a little bit while we look at the problem from a different perspective and that is the current system of vulnerability research. With the exception of a relatively small percentage of the largest manufacturers of cyber devices and software, companies do not generally do in-house searches for vulnerabilities. Government (mainly defense/intelligence) agencies and cybersecurity firms fund or do a large amount of vulnerability research, but a significant amount is done by independent researchers.

All of these non-governmental out-side research efforts are hindered by a common problem, access to cyber devices and software necessary to carry out their research efforts. Many of the products that would constitute the critical cyber component (3C) of a critical operation (CO) at a private sector critical infrastructure (PSCI) facility are not generally available to researchers or are too expensive to obtain.

Centers of Excellence

There are a limited (if probably really large) number of exploitable vulnerabilities in current cyber enabled products. If those vulnerabilities were discovered, reported early and then remediated, there would be a smaller window of available vulnerabilities for cyber-attackers to exploit. For 3C components, the federal government has a legitimate and specific interest in reducing the points of vulnerability for those components. One way of doing that would be to specifically encourage vulnerability research on those components.

One way of doing that would be to direct the DHS Science and Technology Directorate (S&T) to work with established colleges and universities (and the applicable SSAs) to establish vulnerability research centers-of-excellence (VR-CoE). Ideally, there would be a VR-CoE for each of the 16 critical infrastructure sectors. At a minimum, however, there should be VR-CoEs established by our cybersecurity legislation for the following:

• Medical devices,

• Energy production and distribution systems,

• Industrial control systems, and

• Transportation control systems

These CoEs would consist of laboratories where 3C devices and software could be tested for vulnerabilities by educators and students. Established independent security researchers could apply for federally funded fellowships to allow them access to 3C devices for testing purposes. The military could even have members of various cyber operations units periodically rotate through CoEs to increase their hands-on hacking skills.

For each vulnerability discovered by CoE researchers on a 3C piece of equipment or software/firmware, the researchers would be encouraged to develop proof-of-concept (PoC) code and potential indicators of compromise (PIC).

Equipment Donations

Getting the equipment for these CoEs to investigate could get more than a little expensive. This is where we can supply a carrot to offset the ‘stick’ of vulnerability liability. A company that donated a piece of equipment to one or more of these CoEs for vulnerability testing could use that donation as a prima facia defense to a cybersecurity vulnerability lawsuit. For equipment/software that fell out of the established VR-CoE coverage, companies could hire independent researchers or cybersecurity research firms  to conduct the testing.

I suspect that it would not take long for the CoEs to be overwhelmed by equipment/software donations. CoEs should be allowed to rent out donated equipment to established cybersecurity research firms for their inhouse research efforts. That loaner process would include non-disclosure agreements that would limit the ability of the research firms from publicly reporting on their research until the CoE had completed the established vulnerability disclosure process (see below).

Vulnerability Disclosure

The CoE’s would be required to coordinate disclosure of the discovered vulnerabilities with the manufacturer or vendor that contributed the equipment and/or software/firmware. The manufacturer or vendor would be given 90-days to develop mitigation measures that corrected the vulnerability. The discoverer of the vulnerability would then be given 10-days to confirm the efficacy of the fix. The CoE would then disclose the vulnerability through NCCIC.

For equipment that had been identified as a 3C for critical operations at one or more a private sector critical infrastructure (PSCI) facility, the CoE would inform the affected sector specific agencies (SSAs) responsible for those PSCI of the discovery of the vulnerability as soon as it was reported to the manufacturer/vendor. The report, protected as Protected Critical Infrastructure Information (PCII), would include information on the devices affected, the facilities potentially affected and the PIC for the vulnerability. The SSAs would pass along the PIC to the affected PSCI to be included in their cybersecurity monitoring program I described in Part 2.

If an SSA determined that a vulnerability was potentially critical to the safe/secure operation of one or more SSA, they would notify the NCCIC. The NCCIC would then issue the subsequent vulnerability notice in a two-step process. The initial notification would be made to all SSAs and PSCI and it would be protected as PCII. Then, 60-days later a public notification would be made by NCCIC, thus removing the PSCI protection.


Part 5 of this series will look at some the current definitions in USC will need to be changed by legislation to ensure the efficacy of the cybersecurity bill I have been discussing here.

Sunday, March 7, 2021

Philosophy of Cybersecurity Legislation – Part 3: Information Sharing

This is part of a continuing series on the Philosophy of Cybersecurity Legislation. With all of the calls for improving cybersecurity and the increasing sense that legislation is necessary this series will try to define the necessary parameters for effective cybersecurity legislation. The earlier posts in the series were:

Part 1: What to Regulate

Part 2: How to Regulate

Crime to Breach 3C Systems

We will start the information sharing discussion from an unusual angle, making it illegal to breach a critical cyber component (3C) of a critical operation (CO) at a private sector critical infrastructure (PSCI) facility as those three terms were defined in the previous two posts. For a definition of the term ‘breach’ we will use some sort of variation of the revised 6 USC 659(a) definition of the term ‘incident’ that I proposed in 2019.

Thus, when a covered PSCI discovers an indicator of compromise as part of their monitoring for compromise process described in the previous post in this series, they will report that occurrence to the FBI for criminal investigation. They will be required to include in that initial report to the FBI that they are a designated PSCI (inevitably with some sort of facility identification number) and that the breach affected a 3C of a regulated CO at the facility.

Breach Reporting Requirement

The reason for that notification is that the FBI would then be required to report the incident to an established reporting agency at the Sector Specific Agency (SSA) responsible for the regulation of 3Cs at that facility, as well as providing that SSA with ongoing information about the progress of the investigation. In order to not compromise the integrity of the investigation or possible future criminal prosecutions for the breach the FBI would only be required to report the following information to the SSA:

• The date of the report of compromise,

• The facility reporting the compromise,

• The 3C components affected by the compromise, and

• The indicators of compromise on each of the affected components.

The SSA responsible for the cybersecurity regulation of the facility would be expected to provide appropriate subject matter expert assistance to the FBI throughout the investigation of the incident. Those experts would be prohibited from sharing any information with the SSA beyond that delineated above without the express consent of the FBI until the Director of the FBI declared the investigation closed.

SSA Breach Information Sharing

The SSA would be responsible for reporting attack information to the National Cybersecurity and Communications Integration Center (NCCIC). Any information reported that contained the company name, facility name, SSA identification, or the name of any of the persons involved in the incident {facility identification information (FII)} would be protected as Protected Critical Infrastructure Information (PCII).

As soon as an SSA received actionable indicators of compromise (AIOC) the SSA would be required to report that information to NCCIC. When reporting AIOC, the SAA would not include any FII in the reported information. The AIOC would not be protected as PCII or any other sensitive but unclassified data protection program. The NCCIC would be required to publicly share AIOC and specifically send notice to each registered PSCI facility.

The reasons for using the FBI as a reporting cut-out in the information reporting process is two-fold. First, since the SAA is acting as a regulatory agent, there is an unintentional yet very real hinderance to voluntary reporting of timely reporting of security breaches. This criminal reporting process disconnects the breach reporting process from that of regulatory oversight. It also ensures that the initial investigation is done with all of the requisite forensic and evidentiary safeguards necessary to ensure that prosecution of the attackers (if/when identified and arrested) can proceed with some semblance of surety that convictions can be made.

Similarly, the use of NCCIC as the means of reporting AIOC is two-fold. Again, it helps maintain the regulatory relationship between the SAA and the covered facilities. More importantly, it ensures that information is shared in a timely manner with PSCI that are not regulated by the immediately affected SAA.

Reporting to Congress

The FBI would be required to periodically report to Congress on all reported cybersecurity incidents at PSCI. Because the protection of PSCI is a national security imperative, those reports to Congress would be classified with unclassified summary data being included for the purposes of public discussion and potential legislative action.

Each SSA would be responsible for periodically reporting to Congress on the cybersecurity issues identified in reports from FBI investigations. For each reported incident, the SAA would be required to inform Congress what actions had been taken to ensure that other PSCI overseen by that SAA were not affected by similar attacks.

In Part 4, I will look at vulnerability reporting as part of this cybersecurity legislation.

Thursday, February 25, 2021

Philosophy of Cybersecurity Legislation – Part 2: How to Regulate

This is part of a continuing series on the Philosophy of Cybersecurity Legislation. With all of the calls for improving cybersecurity and the increasing sense that legislation is necessary this series will try to define the necessary parameters for effective cybersecurity legislation. The earlier post in the series was:

Part 1: What to Regulate

Flexibility Needed

The most common complaint about calls for cybersecurity legislation over the last ten years or so has been that the cybersecurity field changes so quickly that any legislative effort is doomed to being out-of-date by the time that it is enacted. New types of threats, the expanding scope of cyber operations in daily life and the ever-changing variety of tools used by both defenders and attackers all make it hard for the crafters of legislation to provide laundry lists of do’s and don’ts in their legislative efforts.

Having said that, there are four key areas that any successful cybersecurity program is going to have to address:

• Identify critical cyber components,

• Limit access to those components,

• Monitor those components for signs of compromise, and

• Have a plan in place to recover operations.

I am not trying to say that an organization can afford to ignore the security of non-critical cyber components, but national-level cybersecurity legislation is going to have to focus on critical operations (CO) of private-sector critical-infrastructure (PSCI). There is just not enough time, money or personnel available to the federal government to worry about the cybersecurity infrastructure of each and every component of the economy.

Identify Critical Cyber Components

The task of identifying the 3Cs, ‘critical cyber components’ is going to be the key to a successful national critical infrastructure cybersecurity program, and it is going to be the most difficult process to define for this legislative effort. Each critical infrastructure sector is going to have different types of economic output that are going to have to be protected and each facility is going to have a different set of cyber controls in place that guides the completion of that output.

The goal of a successful critical infrastructure cybersecurity bill is not going to be to define what the 3Cs are for each and every facility in the United States. The task would be monumental, it would never be complete, and there would be too much resistance from every sector of the economy to ever allow the bill to pass. No, that task is going to have to be passed to the regulators at the Sector Specific Agencies (SSA) that oversee federal efforts to help protect each of the 16 CI sectors.

Even these regulators are going to have a tough time defining how each facility identifies its own 3Cs. One thing is certain however, the regulatory definitions are going to have to be operational in nature, basing the criteria on what systems are absolutely necessary for the continued output of whatever product or service that makes the facility critical infrastructure in the first place.

For example, in the Chemical Facility Anti-Terrorism Standards (CFATS) program DHS defines critical cyber systems as those that directly impact the safe/secure storage, handling or shipping of one or more of the DHS chemicals of interest at the facility which are the basis for the facility being covered by the CFATS regulations. Only those critical cyber systems have to be addressed in the facility’s site security plan. Facilities would probably want to protect their other cyber systems, but that is not the worry of the CFATS program.

Limit Access to 3Cs

Limiting access to 3Cs is one of those areas that legislative efforts are going to have to be carefully directed away from requiring specific types of technology for solving the access problem. The systems across the 16 critical infrastructure sectors are just too diverse for a single solution to be effective. While encrypted communications and two-factor authentication (2FA) will certainly be widely used in securing critical cyber components, requiring their use will be self-defeating when the next adversarial tool defeats 2FA or a new cybersecurity upstart comes up with an easier more effective way to address remote operations.

No, what a national legislative solution to protecting CO-PSCI from cyber-attacks is going to have to do is to authorize the regulators to establish processes by which regulated facilities can propose methodology to limit access to their 3Cs. If those methods achieve the four goals listed below then regulators would be required to accept the methodology:

• Systems in place to administratively identify those who are authorized access to 3Cs,

• Systems in place to confirm that a person attempting access is authorized for that level of access,

• Systems in place to alert appropriate authorities when an unauthorized access is attempted, and

• Systems in place to prevent unauthorized person from manipulating the controls of, or information transiting, a 3C component.

Notice that protecting access to information in a 3C component is not one of the four goals of limiting access. Where a primary purpose of a 3C component is the protection of information from unauthorized access the SSA should be authorized by this legislation to include ‘residing in or’ between the words ‘information’ and ‘transiting’ in the fourth goal above.

Monitoring for Signs of Compromise

This has always been one of those areas of cybersecurity that has caused multiple problems in the past. If the definition of attack is too broad (pinging a connection for instance) there are too many compromises to effectively deal with and if they are too narrow (publication of compromised data for example) then the attacker has had way too much access to the system for effective mitigation.

But again, if we limit the systems of concern to just the 3Cs and limit access in the way’s describe above we can have a better handle on defining signs of compromise. A simple definition could be the transit of data or command into or out of the defined system either via an unauthorized mode of communication, or to/from an unauthorized source or destination.

Another sign of compromise has been suggested by the Coast Guard in a recent Marine Safety Information Bulletin (MSIB 03-21) [corrected # and provided link, 3-16-21 10:17 EDT] where it required any MTSA covered vessel or facility to report a breach of security if:

• They have downloaded the trojanized SolarWinds Orion plug-in (see FBI Private Industry
Notification 20201222-001 https://www.ic3.gov/Media/News/2020/201229.pdf); or
• They note any system with a critical security function displaying any signs of compromise,
including those that may have not originated from the SolarWinds Orion compromise but utilize
similar TTPs (see CISA Alert AA20-352A).

Thus, we could include a requirement to include checking for indicators of compromise published by CISA, the FBI, NSA, the SSA for the PSCI, or the applicable industry or sector information sharing and analysis center (ISAC).

Again, how systems were monitored would be a regulatory matter for the SSA crafting the implementing regulations.

Recover Operations

One thing that is obvious from the SolarWinds breach is that any organization can be breached given an adversary with the appropriate resources and desire. Thus, any cybersecurity plan must contain a response plan for how the system will be recovered when a successful attack does occur. Again, since the scope of a response plan is going to vary from sector to sector, the legislation would not be expected to describe the acceptable parameters of a cyber response plan beyond the goal of returning to operation those parts of the business that are deemed to be the critical operations that were responsible for the facility being regulated as a CO-PSCI.

One thing that the recovery plan will have to include is the identification of outside resources that the facility will need to recover from a successful cyber-attack. SSA’s should be required to compile those lists from CO-PSCI across the sector and periodically report to Congress on those recovery assets that facilities would have to have assistance from the government to obtain in the event of a worst-case attack. FEMA could then be given the task of stockpiling the appropriate assets to aid recovery operations.

Part 3 to this series will address information sharing.


Sunday, February 21, 2021

Philosophy of Cybersecurity Legislation – Part 1: What to Regulate

There has recently been a lot of talk in the national media and political theater about the need for cybersecurity legislation to protect against cybersecurity threats such as the SolarWinds hack and the water facility ‘attack’ in Florida. Before one starts talking about the potential nuts and bolts of such legislation, I think that it is important to consider what I like to call the philosophy of cybersecurity legislation; the what and why of legislative need.

What to Legislate

The first thing that you need to establish is what one wants the federal government to regulate, or more importantly what one wants to accomplish with that regulation. For cybersecurity the most obvious desire would be to stop any foreign adversary from disrupting government and private-sector cyber-operations within the United States. That would certainly fit with the ‘provide for the common Defence’ provision of Article 1, Section 8, Clause 1 of the Constitution.

Unfortunately, short of throwing up a national firewall around the United States where the federal government controls all information and communications flowing into and out of the country, there is no method that the government is going to be able to intercept and prevent all attacks via either the internet or telecommunications infrastructure. Such governmental control of information flow would be an intolerable anathema to most Americans and legislators. So, the scope of the legislative intent will almost certainly have to be reduced.

We already have legislation in place that give the DHS Cybersecurity and Infrastructure Security Agency (CISA) extensive authority for protecting the federal government (except DOD and intelligence agencies) from cyber-attacks. Thus, broad new authority is not needed; just fine tuning and perhaps funding adjustments are all that should be required for preventing future SolarWinds type attacks. (Okay, that is being a tad simplistic as the nuts and bolts of such prevention have yet to be adequately discussed, but for a philosophy discussion that is just left as an exercise for the student – GRIN.)

With a national firewall off the board as a means of defense, we have to decide if preventing all foreign adversary attacks on private-sector cyber-operations is a reasonable goal for our legislative intent. First off, do we really suspect that a foreign government is going to want to target the disruption of the private email between ordinary citizens or the operation of my wife’s jewelry sales site on Etsy (I’ve been trying for weeks to figure out how to get that advertisement into my blog)? And if they did, for some obscure reason, would that really fit within the description of ‘provide for the common defense’?

Limit the Scope to CI

A more reasonable use of the federal government’s cyber resources, both money and personnel are significant constraints on any legislative endeavor, would be to limit non-federal government cyber defense to critical infrastructure. That is still an expansive (and potentially expanding) set of cyber resources to protect, but it would certainly be a more justifiable use of federal resources.

That leaves an important gap in the area needing cyber protection, that is the protection of the cyber resources of State, local, Tribal and Territorial (SLTT) government. Because of the curious constitutional separation of rights and responsibilities of governmental authority in the United States, the current CISA authority over governmental cybersecurity does not directly extend to SLTT government operations. They are currently restricted to providing advice and limited assistance to those governments.

For the purposes of this discussion, I will assume that general SLTT government cybersecurity is going to take separate legislation from that being discussed here due to the wide disparity in the needs and desires for federal cybersecurity support from SLTT governments. I will, however, include in the remaining discussion those SLTT operated pieces of critical infrastructure like drinking water treatment plants and wastewater treatment facilities.

So, for this discussion we are looking to discuss writing legislation that attempt to prevent a foreign adversary from disrupting the cyber-operations of private-sector critical infrastructure (PSCI) including SLTT owned and operated water and wastewater operations.

What Cyber-Operations Will Be Protected?

Are we going to try to protect all of the cyber-operations of these PSCI entities? That is a very wide field of dreams, covering email, payroll, personnel administration, security, and operations. On one hand, the one thing that differentiates PSCI from other private sector entities is typically the output of their operations. The federal government’s interest is in ensuring the continued output of the critical operations (CO) of PSCI so the intent of the legislation is to protect those CO of PSCI from disruption by foreign adversaries. To be sure CO of PSCI protection may necessitate providing protections against disruption of other cyber-operations of PSCI or at least mitigating the effect of those other disruptions on the CO.

Congressional Oversight Impact

So, a critical portion of the any legislative action will be how to identify what facilities in the United States will be affected by the legislation. The problem here is that different sorts of critical infrastructure are regulated by different portions of the federal government. Even when considering security, the different executive departments did not surrender their oversight to the Department of Homeland Security.

Even if new legislation did give CISA authority to regulate cybersecurity at PSCI, there would still be the problem of congressional oversight to deal with. We have specifically seen this with the CFATS program legislation. While there is frequently disagreement between the House and Senate on legislative matters, the larger stumbling block for CFATS legislation has been the conflict between the House Homeland Security Committee and the Energy and Commerce Committee. This has more to do with the different foci of the two Committees than inter-party conflict we typically seen in House-Senate relations. The internecine conflict between House committees would be intense in any PSCI cyber-legislative effort.

The National Infrastructure Protection Plan (NIPP) provides a methodology to overcome the problems identified above. The federal government has already designated which executive departments are responsible for the oversight of security at the 16 different critical infrastructure sectors; these are designated as Sector Specific Agencies (SSA). Thus, our cybersecurity legislation does not need to identify who will be responsible for regulating which sectors, it can simply rely on the oversight designations that already exist.

Identifying Operations to be Protected

With these political considerations and the inevitable push-back by industry against any new regulations, defining what cyber-operations would be covered in different industries would be difficult. The general definition though, should be easier. We would only have a federal interest in regulating those cyber-operations that have a direct impact on the entities capability of providing the critical output for which receive the critical infrastructure definition. While protecting other cyberoperations might be beneficial, the federal interest in ensuring critical output should limit the application of federal influence to just those operations.

Legislation would each SSA to establish by regulations criteria for identifying PSCI entities that require cybersecurity oversight to protect national security and national preparedness. The intent would not be a broad definition to encompass as many facilities as possible, but rather to limit the identification of facilities to those that are the most critical to the economy or national security of the United States. The reason for this limitation is that the government agencies responsible for the oversight have only limited resources for ensuring that the resulting cybersecurity regulations are followed by the identified agencies.

And make no mistake about it, enforcement of cybersecurity regulations will be necessary. We need look no further than the various OSHA and EPA safety regulations to see that without effective enforcement many facilities are going to only have paperwork, check-the-box, cybersecurity programs. Even with the facilities that are going to make an  honest effort to comply with the regulations, the lack of facility cybersecurity expertise will limit the effectiveness of those efforts.

In Part 2, I will look at the philosophy of how to regulate that should drive cybersecurity legislation.

Sunday, January 31, 2021

First Month of 117th Congress

At heart, I am a process person. I like to look at production rates and the numbers affecting them. It is almost a compulsion. So, with that in mind, lets look at the production rates of legislators in the 117th Congress. NOTE: all numerical data in this post comes from using the ‘Advanced Search’ tool on Congress.gov.

The Data

The best production measure for congresscritters and their staffs, particularly in the first month of the session is the number of bills written. This month we had a total of 884 bills introduced: 719 in the House and 165 in the Senate. To better understand what that means we have to look at the historical record for the last seven sessions of congress, spanning now three administrations.

Congress

Session Bills

January Bills

House Bills

Senate Bills

117th Biden’s 1st

TBW

884

719

165

116th

17,886

1,463

1,093

370

115th Trump’s 1st

9,423

1,272

954

318

114th

14,604

1,171

730

441

113th

12,328

759

521

238

112th

14,762

904

618

286

111th Obama’s 1st

15,724

1,385

954

431

The ‘Session Bills’ provides the total number of bills written during that session of congress, that’s a null data set for the 117th for obvious reasons. The ‘January Bills’ column provides the total number of bills introduced in Congress in the first January of the session. The ‘House Bills’ and ‘Senate Bills’ provides those number for each of the respective houses of congress.

The Analysis

The 116th Congress was hands down the most prolific bill writing congress that we have seen. Having said that, statistically it is not an outlier; it is well within three standard deviations (actually, only 1.41σ) of the other six congresses we are looking at in the table. To be sure, the percent standard deviation for the total number of bills written is very high (18.9%), so we have a bill-writing ‘process’ that is not very well ‘in control’.

We see something interesting in the first-January bills number in comparison to the total bills written by that Congress. If bill production were equally spread out across the 24 months that a congress was in session, we would expect to see about 4.2% of the total bills written introduced in that first-January. What we actually see is somewhere between 6.l1% and 13.5%. That ‘13.5%’ is 2.04σ above the average of 8.5%, so it is not technically an outlier, but the average value would be significantly different without it being included: 7.5%. In any case, there are two reasons that the first-January numbers would be expected to be higher; new congresscritters getting their first priority bills written and the reintroduction of bills from the previous congress.

Another thing that stands out is the relatively low number of bills that were introduced in the Senate. The number for the House bills is within 0.42σ of the average while the Senate bills is 1.67σ from the average. If we look at the ratio of House bills to Senate bills (remember that there are 435 Representatives to 100 Senators) the lack of production in the Senate is even more apparent. This year’s ratio is 4.4 versus an average of 2.6 (yes, Senators are more prolific bill writers Representatives, if this were not so we would expect a ratio of 4.35); that is 2.07σ above average and the %Standard Deviation for this set of data is 31.16%, the highest of all the data points being looked at.

The problem with bill introduction in the Senate has apparently been related to organizational issues. With the 50:50 split between the two parties, there has been significant wrangling going on in the Senate leadership about how that body will be working during this session. Once the organizational agreement was reached on Monday, the 25th, the legislative pipeline in the Senate opened with 118 bills (71.5% of the total) being introduced in the last week, comparative numbers in the House were 207 bills (28.8%). It will be interesting to see if the Senate’s bill writing pace catches up to that of previous congresses.

Tuesday, December 31, 2013

Cybersecurity Legislation in 113th Congress

Here on the last day of 2013 it is appropriate to look back at the cybersecurity accomplishments of the 113th Congress. The table below shows all of the cybersecurity bills that were introduced this year. The links to the bills and dates refer to my blog posts. While the House has passed a number of bills the Senate has only passed two; both were spending related bills that contained some cybersecurity measures.


Passed in House
Passed in Senate
Notes


Ed Grants

CISPA - Info Sharing

R&D Spending
FY 2013 CR

R&D Cyber-Physical Systems
HR 1163

FISMA Amendments


SECURE-IT


Cyber Warrior Act – S 658

FY 2014 NDA


Cyber Espionage – S 1111

FY 2014 DOD Spending


Aaron’s Law – S 1196


Trade Secrets Protection


Centers of Excellence


FY 2014 DOT Spending


FY 2014 DOC Spending


Includes CI Control Systems


Boots on the Ground Act


FDA Software
FY 2014 NDA


NCCIPA


Place Holder


Cyber Warrior Act – HR 1640
S 1034


FY 2014 DOD Spending


Cyber Espionage – HR 2281


Aaron’s Law – HR 2454


FY 2014 NDA


FY 2014 DOC Spending


Cybersecurity Act


FY 2014 DOD Spending


Public Awareness


 
/* Use this with templates/template-twocol.html */