Showing posts with label Markup Hearing. Show all posts
Showing posts with label Markup Hearing. Show all posts

Thursday, June 10, 2021

Energy & Commerce Committee Approves 3 Cybersecurity Bills

Today the House Energy and Commerce Committee held a markup hearing for six bills. Three of those bills were related to cybersecurity. All three cybersecurity bills were ordered reported favorably to the full House, each by voice votes. No amendments were offered on any these three amendments.

The three cybersecurity bills were:

HR 3078, the Pipeline and LNG Facility Cybersecurity Preparedness Act,

• HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, and

• HR 2928, the Cyber Sense Act of 2021

NOTE: To date, I have only reviewed HR 3078. None of these bills have yet been published by the GPO.

Wednesday, June 9, 2021

House Energy and Commerce Cybersecurity Markup Hearing Scheduled

The House Energy and Commerce Committee will be holding a markup hearing tomorrow. The agenda includes three cybersecurity bills:

HR 3078, the Pipeline and LNG Facility Cybersecurity Preparedness Act,

HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, and

HR 2928, the Cyber Sense Act of 2021

NOTE: Each of the links above are to committee prints of the bills. GPO has not yet gotten to these bills. I have not yet reviewed them.

Saturday, March 20, 2021

Homeland Security Markups – 3-18-21

On Thursday the House Homeland Security Committee held a markup hearing on seven bills. All of the bills were passed by unanimous consent after three of the bills were amended. The four bills that I have covered here in this blog included:

HR 1833 – Amended and passed,

HR 1850 – Passed,

HR 1871 – Passed

HR 1833 – DHS ICS Capabilities Enhancement Act

There were two amendments adopted for this bill. The first was proposed by Rep Langevin (D,RI). It inserted the words ‘Sector Risk Management Agencies’ in three places in the bill, indicating the need for NCCIC-ICS to coordinate their ICS security tasks in coordination with these agencies. This brings the bill more in-line with HR 5733 that was introduced in 2018.

The second amendment was proposed by Rep Torres (D,NY). It added a requirement for a GAO report within 2 years of the passage of this bill. GAO would be specifically tasked to address {new §2(c)}:

•Any interagency coordination challenges to the ability of the Director of the CISA to lead Federal efforts to identify and mitigate cybersecurity threats to industrial control systems,

• The degree to which the Agency has adequate capacity, expertise, and resources to carry out threat hunting and incident response capabilities to mitigate cybersecurity threats to industrial control systems, as well as additional resources that would be needed to close any operational gaps in such capabilities.

• The extent to which industrial control system stakeholders sought cybersecurity technical assistance from the Agency, and the utility and effectiveness of such technical assistance.

• The degree to which the Agency works with security researchers and other industrial control systems stakeholders to provide vulnerability information to the industrial control systems community.

Moving Forward

The unanimous consent passage of these measures indicates that there is wide spread, bipartisan support for all of these bills. I expect that all these bills will move to the floor of the House under the suspension of the rules process. Typically bills will not be considered by the Full House until reports are published, but that is not a requirement. I would not be surprised to see HR 1833 move to the floor when the House returns to session after the Easter break on April 13th.

Tuesday, June 25, 2019

Subcommittee Markup of HR 3432 – Pipeline Safety


The Energy Subcommittee of the House Energy and Commerce Committee will hold a markup hearing on HR 3432, the Safer Pipelines Act of 2019, tomorrow. The bill was introduced earlier this week and an official copy of the bill has not yet been published. A Committee print of the bill is available.

A quick review of that print indicates that this is an authorization bill for the pipeline safety activities of DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA). I have not yet had a chance to do an in depth review of the bill but it does include provisions making modification to current requirements for:

Integrity management programs;
Pipeline hazard communication requirements;
Emergency preparedness planning; and
The adjustment of civil and criminal penalties for violations of pipeline safety rules and regulations.

Additionally, §6 of the bill includes the same mandamus provisions found in HR 3290.

The markup notice indicates that at least one amendment will be considered to HR 3432. That amendment proposed by Rep. Kennedy (D,MA) would add six new sections to the bill. Again, I have not yet had a chance to do an in depth review of the amendment, but it looks very similar to HR 2139 that was cosponsored by Kennedy. HR 2139 has not yet been referred to the Energy Subcommittee and no action has been taken on that bill.

Wednesday, July 22, 2015

Homeland Security Committee Announce Markup Hearing for Thursday

This morning the House Homeland Security Committee announced that their Transportation Security Subcommittee would be holding a markup hearing on Thursday. Three bills would be included in the markup:

H.R. 3102, the “Airport Access Control Security Improvement Act of 2015”.
H.R. ____, the ‘‘Partners for Aviation Security Act”.
Committee Print of H.R. ___, the “Transportation Security Administration Reform and Improvement Act of 2015”.

The first two bills are airport security bills pure and simple, so I intend to ignore them. The third bill contains two titles; the second being “Surface Transportation Security”. That means that it is fair game in this blog.

Surface Transportation Security Changes

This Title contains three sections:

Sec. 201. Surface Transportation Inspectors.
Sec. 202. Repeal of biennial reporting requirement for the GAO relating to the Transportation Security Information Sharing Plan.
Sec. 203. Repeal of frontline employee training requirements.

Section 201 outlines a new reporting requirement for the Comptroller Generals Office concerning “the efficiency and effectiveness of the Administration’s 4 Surface Transportation Security Inspectors Program” {§201(b)}. From the tenor of the items to be addressed in the report, the author (almost certainly the Committee Staff) don’t think much of the current crop of Surface Transportation Inspectors. It looks like they want the responsibility for this program to revert to the DOT modal agencies.

Section 202 removes a reporting requirement for the Comptroller Generals Office established in 49 USC 114(u)(7). This is a biennial reporting requirement on a user satisfaction survey concerning “the quality, speed, regularity, and classification of the transportation security information products disseminated by the Department of Homeland Security to public and private stakeholders”.

Section 203 removes the requirement for TSA to establish employee security training programs that were originally required under the 9/11 Commission Act of 6 2007 (Public Law 110–53). Those programs are:

Public transportation security training program {6 USC 1137};
Over-the-road bus security training program {6 USC 1184}

There are two other programs included in the elimination program set out in this section that have nothing to do with employee training; they both deal with employee threat assessment programs:

Threat assessments (public transportation) {6 USC 1140};
Threat assessments (railroad) (§1520 of the 9/11 Commission Act of 6 2007}

Both of those threat assessment requirements use virtually the same wording:

“Not later than 1 year after the date of enactment of this Act, the Secretary shall complete a name-based security background check against the consolidated terrorist watchlist and an immigration status check for all railroad frontline employees, similar to the threat assessment screening program required for facility employees and longshoremen by the Commandant of the Coast Guard under Coast Guard Notice USCG-2006-24189 (71 Fed. Reg. 25066 (April 8, 2006)).”

Commentary

TSA has never actually gotten around to establishing any of the programs mentioned in §203, so as a practical matter eliminating them does not make much difference. And since everyone knows (pardon the sarcasm) that terrorists never attack public transportation, there really is no need for security training of front line employees in that sector.


Likewise, there is no chance (again sarcasm alert) that terrorists would want to become railroad employees to effect an attack. And we know that terrorists have made no attempt to radicalize Americans as a part of an effort to encourage lone wolf attacks in this country. With both of those facts established, there is obviously no need to vet first line surface transportation employees against the TSDB.

Thursday, May 14, 2015

House Subcommittee Markup of HR 1646

Yesterday the Oversight and Management Efficiency Subcommittee of the House Homeland Security Committee held a markup hearing where four bills were recommended to the full Committee for consideration. Among those was HR 1646, the Homeland Security 3 Drone Assessment and Analysis Act.

Amendments

Two amendments were offered for HR 1646, one by Rep. Coleman (D,NJ) the author of the bill, and one from Rep. Scott Perry (R,PA). Both amendments were adopted by voice vote. The Coleman amendment expanded the participation in the study development process and added State and local fusion centers to the list of agencies that would receive copies of the required study. The Perry amendment limited the maximum size of ‘medium sized’ drones to 1300 lbs and stressed the need for recommendations on how prevent and mitigate the risk from drone attacks.

Moving Forward

As I mentioned in my earlier post on this bill it looks like this bill will be actively moving forward in the House Homeland Security Committee. It could easily become one of those bill that is moved further forward as much for its show of bipartisan support as for the actual content of the bill.

Commentary


There is still nothing in the bill that would drive the report down to non-government owned critical infrastructure facilities that are responsible for the security of most CI facilities. While the addition of the fusion centers to the report recipients is a positive move there is still nothing that would guarantee that responsible security personnel would ever see the results.

Tuesday, June 10, 2014

Full Committee Draft of FY 2015 DHS Spending Bill Published

Today the House Appropriations Committee published the Full Committee Draft of the bill to fund DHS for FY 2015. The bill is substantially the same as the one that was published a couple of weeks by the Homeland Security Subcommittee. It certainly contains the two CFATS provisions that I discussed earlier.

The Committee also published a draft of their Committee Report that would accompany the bill when it is reported to the Whole House. This contains a great deal more information that may be of interest to readers of this blog.

CFATS

The report details the amount of money that would be provided to the Infrastructure Security Compliance Division to fund the CFATS program and the Ammonium Nitrate Security Program (ANSP), if/when those regulations actually get published. The Committee will be recommending $83.3 Million for ISCD. This is up from the $81.0 Million allotted for FY 2014, but down from the $87.0 Million requested by the Administration. There is no threat this year to withhold any of those funds.

There is a lengthy discussion about the CFATS program on pages 89 and 90 of the Committee Report. Included in that discussion is a backhanded compliment to recent program improvements overseen by Director Wulf:

“Since that time [the 2006 adoption of the §550 authorizing language], and in spite of ample appropriations provided by Congress, DHS has only recently begun to make considerable progress in carrying out its regulatory responsibilities under the Chemical Facility Anti-Terrorism Standards (CFATS) program.”

The discussion goes on to explain the purpose of the $2.3Million year-to-year increase in funding enhance critical efforts related to compliance with CFATS, including:

• Developing an automated process for identification of CFATS outliers [non-reporting facilities];
• Addressing concerns raised by GAO regarding the risk-tiering methodology; and
• Fulfilling other requirements [almost certainly including the ANSP and SSP implementation].

There is an interesting discussion at the end of the CFATS section that I haven’t seen addressed by Congress before. It is a discussion about the techniques used to ‘seal’ [a device used to indicate that a load has not been tampered with since it was loaded] chemical containers in transit. The CFTATS discussion concludes by saying:

“The Committee is aware of concerns that storage and transit cargo containers used by the chemical industry may rely on outdated mechanical sealing technologies. The Committee encourages DHS to work with the Chemical Sector Coordinating Council to disseminate information about proven next generation sealing technologies to the chemical sector, including through the Chemical Sector Supply Chain Good Practices Guide [NOTE: this is a SOCMA link not a DHS link, I can’t find this on a DHS web site].”

This is addressed again during the discussion about the DHS Science and Technology Directorate (S&T). There they discuss the use of Reusable Electronic Conveyance Security (RECONS) solutions and recommend that DHS “consider piloting the use of commercially available RECONS that integrate physical security mechanisms with wireless tracking and security systems” (pg 117).

ICS Security

There is actually a brief discussion of control system security, termed ‘operational cybersecurity’. Again, as part of the S&T discussion, the Committee recommends S&T, “in collaboration with NPPD, establish operational cybersecurity research initiatives” (pg 116). There does not appear to be any additional funding for the exercise, however.

That lack of funding is in-line with the Committee’s planned reduction of NPPD’s cybersecurity spending by $46.7 Million from last year and an almost $1 Million less than requested by the Administration.

Markup Hearing

As I mentioned earlier the full Committee will meet tomorrow to markup this bill and I expect that it will be introduced later this week. The way that the House is moving on spending bills, I expect that this will reach the floor this month; well before the Summer Recess.

Wednesday, April 2, 2014

Substitute Language for HR 4007

Yesterday the House Homeland Security Committee posted a link to the substitute language for HR 4007 that the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee will consider at their HR 4007 markup hearing tomorrow. A number of relatively minor changes are made but amendment in the form of a substitute does increase the length of the authorization period and includes authorization of spending for the CFATS program.
Authorization
The substitute language revises §7 extending the termination date from 2 years to 3 years after the bill becomes law. This provides a little more time for Congress to prepare a permanent comprehensive

CFATS bill. Section 9 has been added to the bill providing spending authorization for the CFATS program. The spending level is set at $87,436,000. This is up from the $81,000,000  included in the FY 2014 spending bill passed in January. The additional money may be intended to fund the Ammonium Nitrate Security Program.

Ammonium Nitrate Security Program
Section 10 would be added to the bill by this substitute language, addressing the long overdue ammonium nitrate security program. It amends 6 USC 488a adding language to subsection (a) that clarifies the activities covered by the ANSP.

Substitute language is also provided for §488a(f) that adds transportation activities to the exempted from coverage of the ANSP. It adds a specific exemption for transportation activities regulated under 49 USC Chapter 51, Transportation of Hazardous Materials, or 49 USC 114(d) which provides for TSA responsibility for all transportation related security issues.

Personnel Surety
The substitute re-writes §2(d)(3) to make it clear that DHS may not require facilities to submit any information to ISCD that have been vetted for terrorist ties under “any Federal screening program that periodically vets individuals against the terrorist screening database” {§2(d)(3)(A)},

Information Sharing

Section 3 adds a paragraph related to information sharing with first responders, at least that is the title of the paragraph. It actually requires the Secretary to provide, via the Homeland Security Information Network (HSIN), “such information as is necessary to help ensure that first responders are properly prepared and provided with the situational awareness needed to respond to incidents at covered chemical facilities” {§3(c)}. It does not actually require sharing this information with local first responders. It requires that the information be provided to State, local and regional fusion centers. There are no requirements to push that information actual first responders.

Not Covered


This revised language does not address the two issues that have been responsible for the failure of Congress to be able to pass and CFATS related legislation since the §550 language was included in the FY 2007 DHS spending bill. Those two topics are the use of inherently safer technology and worker participation. Those topics do not need to be addressed to pass in the Republican controlled House, but will have to be included to be considered by the Democratic controlled Senate.

Thursday, March 27, 2014

Markup Results on DHS Communications Bills

This morning the Emergency Preparedness, Response, and Communications Subcommittee of the House Homeland Security Committee met to conduct a markup hearing on three communications related bills. Those bills were:

HR 3283, the Integrated Public Alert and Warning System Modernization Act of 2013;
HR 4263, the Social Media Working Group Act of 2014; and
HR 4289, the DHS Interoperable Communications Act.

The Subcommittee agreed to all three bills by voice vote. The first two were amended before being agreed to, but the last was agreed to without change.

HR 3283 Changes

As I noted earlier, Rep Brooks (R,IN) offered an amendment in the form of a substitute. This revised language was further amended by four amendments from Rep. Payne (D,NJ) that were considered en bloc; four amendments from Rep. Clarke (D,NY) that were considered en bloc; and a single amendment from Rep. Higgins (D,NY). All amendments were agreed to by voice vote.

Most of the Payne amendments were minor word changes, but the last one would require DHS to determine which commercial wireless devices were capable of receiving the warnings broadcast under the Integrated Public Alert and Warning System and to annually publish a list of those devices.

All four of the Clarke amendments were related to cybersecurity concerns. They included:

• A requirement to ensure that the Integrated Public Alert and Warning System is hardened ‘to the greatest extent practicable’ against cyber-attack (listed in two separate places);
• A requirement to add Under Secretary for Cybersecurity and Communications of the Department of Homeland Security to the members of the Advisory Committee; and
• A requirement for the Advisory Committee to conduct an assessment of the cybersecurity of the Integrated Public Alert and Warning System.

The Higgins amendment would require the Advisory Committee to consider lessons learned each time the Integrated Public Alert and Warning System is used.

HR 4263 Changes

Again, I reported earlier that Ranking Member Payne had offered an amendment in the form of a substitute for this markup. That language was further amended by a separate amendment from Mr. Payne that added the Office of Disability Integration and Coordination of FEMA to the Working Group.

An amendment from Higgins would add an additional requirement in the Working Group’s report to Congress about recommendations about how public awareness of the Department’s social media communications could be increased.

Moving Forward


The next step in the legislative process will be the full committee markup hearing and I expect that all three bills will again be marked up in a single hearing. How soon that hearing takes place will be a rough measure of the likelihood that this bill will make it to the floor of the House. If these bills don’t get to the floor before the summer recess, the only way they will likely make it to the President’s desk will to be included in the DHS spending bill.

Wednesday, March 26, 2014

Proposed Revisions to HR 3283 and HR 4263

As I noted in an earlier blog post the Subcommittee on Emergency Preparedness, Response and Communications will be holding a markup hearing on Thursday that will look at two bills that I have already covered (HR 3283and HR 4263). They will be considering substitute language in the hearing, so it seems logical to look at the changes that are already being considered.

HR 3283

 The substitute language for the Integrated Public Alert and Warning System Modernization Act of 2013 contains the most modifications of the two bills. It starts out by changing the title slightly to reflect the change in the year and it eliminates the short hand name for the new alert system, preferring to use the full descriptive name; the ‘national integrated public alert and warning system’. Note the use of lower case in the name throughout the bill, a more formal name is yet to come.

Some relatively minor changes in wording are made in the findings section of the bill (§2). For example the words “integration, flexibility, comprehensiveness” are added to the description of the expected benefits in §2(2)(A). More significantly there is more emphasis on ‘individuals with disabilities’ in this section; adding §2(2)(D), “an improved ability to notify individuals with disabilities” to the description of benefits. Additionally, the coverage of ‘individuals with disabilities’ is expanded in many places in the bill to specifically address individuals with “sensory disabilities” {see, for example §2(6)}.

Section 526 that is added to the Homeland Security Act of 2002 has seen extensive revisions. In the paragraph describing the program implementation requirements {§526(b)} the first subparagraph was rewritten to explain that the system would be used for alerts related to “an act of terrorism, a natural disaster, war, other man-made disasters, or other hazards to public safety” {§526(b)(1)}. Three other sub-paragraphs were added:

(2) establish or adapt, as appropriate, common alerting and warning protocols, standards, terminology, and operating procedures for the integrated public alert and warning system;

(3) include in the integrated public alert and warning system the capability to adapt the dissemination of homeland security information and other information, and the content of communications, on the basis of geographic location, risks, and multiple communications systems and technologies, as appropriate; and

(7) conduct periodic nationwide tests of the integrated public alert and warning system.

More interestingly, §526(b)(6) from the original bill was removed. That was the only place in the bill that referenced the current National Terrorism Advisory System. It would seem that the never used NTAS would be phased out if this bill becomes law.
Section 526(d), dealing with the establishment of the Integrated Public Alert and Warning System Advisory Committee (IPAWSAC), has some changes made to it as well. The subparagraph dealing with the Federal government representatives on the IPAWSAC adds the Director of the United States Geological Survey (or the Director’s designee) {§526(d)(2)(D)}. Changes are also made to the non-Federal representative in the next subparagraph:

• Adding a ‘consumer or privacy advocates’ category;
• Separating out as a separate category ‘national organizations representing the elderly’; and
• Changing ‘the cellular industry’ to the ‘commercial mobile radio service industry’.

HR 4263

The changes to the Social Media Working Group Act of 2014 are much less extensive, which is appropriate considering how recently it was introduced. Section 318 being added to the Homeland Security Act of 2002 is being changed in three places {§318(g)(1), (2) and (6)}  to add the phrase ‘other emergencies’ in describing when the use of social media is being considered in the bill.

It also amend the reporting requirement for the Social Media Group to require the recommended improvements to social media use be specifically targeted at the use of social media for emergency management purposes [emphasis added].

The Third Bill

The other piece of legislation has now been given the bill number HR 4289, the Department of Homeland Security Interoperable Communications Act. I have not yet had a chance to completely review the committee draft of that bill. It will be done before the Thursday hearing.


Monday, March 24, 2014

Homeland Security Committee Announces Markup Hearing

Today the House Homeland Security Committee announced that its Subcommittee on Emergency Preparedness, Response and Communications would hold a markup hearing on Thursday that would look at three separate bills. Those bills are:

HR 3283, the Integrated Public Alert and Warning System Modernization Act of 2013;
HR 4263, the Social Media Working Group Act of 2014; and
• A new bill, the Department of Homeland Security Interoperable Communications Act

Links to substitute language for both HR 3283 and HR 4263 have been provided. The hearing page also includes a link to the Committee Draft of the new bill. I’ll have appropriate comments on all three posted before the hearing.


I suspect that these three closely related bills will continue to work their way through the legislative process linked in close proximity to each other.

Wednesday, March 12, 2014

HR 4186 Documents Added to Hearing Docket

This morning the House Science, Space, and Technology Committee added a number of documents to the page for the markup hearing on HR 4186 that will be held tomorrow morning. That hearing will be convened by the Subcommittee on Research and Technology.

The documents linked to the hearing web page include:

• A committee draft of HR 4186 (GPO still does not have official version);
• The Staff Markup Memo providing background on the proposed bill; and
• A Section-by-Section review of the proposed bill.

I have not had a chance to do more than skim these documents at this point, but it is clear that there will be at least one section of the bill that will probably be of interest to readers of this blog. Section 504 deals with research on Cyber-Physical Systems.


More information to come in future posts.

Monday, March 10, 2014

Committee Announces Markup Hearing for HR 4186

The Research and Technology Subcommittee of the House Science, Space and Technology Committee announced this evening that it would be holding a markup hearing for HR 4186, the Frontiers in Innovation, Research, Science, and Technology Act of 2014. No I haven’t mentioned this bill because it was apparently introduced today. No copy of the bill is available yet and the hearing is not even listed on the Committee web site.

I hope that the Subcommittee members have had more notice than this, or there won’t be any amendments to mark-up the bill with. I'm assuming that the bill was introduced by the Committee Chair, Lamar Smith (R,TX) or the Subcommittee Chair (R,IN), or maybe both.

Monday, February 10, 2014

HR 4005 Markup Hearing Scheduled

The problem with doing a hearing post as early as I did it this last weekend is that I might miss late posted hearing. The House Transportation and Infrastructure Committee will hold a markup hearing tomorrow that will address HR 4005, the Coast Guard and Maritime Transportation Act of 2014. At least two other bills will also be considered (HR 3676 and HR 1378) as well as some GSA related resolutions. Apparently the Committee leadership does not expect there to be much discussion about HR 4005, a sure sign that the bill was appropriately vetted by the Staff.


I noted this weekend that HR 4005 was on the fast track for consideration and this quick markup certainly supports that conclusion.

Tuesday, December 17, 2013

Senate Cybersecurity Markup Postponed

I noted yesterday that I had heard that the Cybersecurity Recruitment and Retention Act that was supposed to be marked up tomorrow was not yet ready for prime time.  Word was that the hearing would address the other bill (something non-consequential – slight sarcasm alert – about postal reform) but the cybersecurity bill would not be dealt with until next year (just a couple of weeks away).  Well today the Senate Homeland Security and Governmental Affairs web site announced that the whole hearing was postponed. No rematch date set; just postponed.

Monday, December 16, 2013

Update on Senate Cybersecurity Hearing

I’m hearing rumors that it doesn’t look like work will be done on the Cybersecurity Recruitment and Retention Act bill that was supposed to be marked up on Wednesday by the Senate Homeland Security and Governmental Affairs Committee. The Committee hearing web site still reports that the bill will be considered so I’ll keep a close eye on the site to see if the rumors are true.

Tuesday, October 8, 2013

HR 3202 Markup Hearing Update

The House Homeland Security announced on their web site this afternoon that HR 3202, the Essential Transportation Worker Identification Credential Assessment Act, markup hearing that had been scheduled for Wednesday had been postponed until a date and time to be determined. This is the second time in about a week that the markup of this bill was postponed. While the first delay was generally explained as a response to the government shut-down, that does not so easily explain the current delay. The shutdown was already in effect when the second hearing was scheduled.

Monday, September 30, 2013

House Homeland Security Committee Markup Hearing – 10-2-13

The House Homeland Security Committee announced this morning that they would be holding a markup hearing on Wednesday to look at six bills, four of which might be of specific interest to readers of this blog.

Those four bills would be:

HR 1204, The Aviation Security Stakeholder Participation Act of 2013;
HR 1791, The Medical Preparedness Allowable Use Act;
HR 2952, The Critical Infrastructure Research and Development Advancement Act of 2013; and
HR 3107, The Homeland Security Cybersecurity Boots-on-the-Ground Act.

The Committee web site indicates that there will be an amendment in the form of a substitute offered for three of the four bills listed above:

H.R. 1204, Amendment in the Nature of a Substitute [PDF];
H.R. 2952, Amendment in the Nature of a Substitute [PDF]; and
H.R. 3107, Amendment in the Nature of a Substitute [PDF]


I haven’t had a chance to do a detailed review of the substitute language, I’ll probably report on that tomorrow.

Tuesday, April 17, 2012

New Language for HR 3674

As I noted in yesterday’s blog post Rep. Lungren (R,CA), the chair of the Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee is planning on introducing substitute language for HR 3674, Promoting and Enhancing Cybersecurity and Information Sharing Effectiveness Act of 2011 (The PrECISE Act), during the full Committee markup of that bill. My earlier post provided just a general idea of the scale of changes included in the bill. I’ve now had a chance to do a more detailed review and this post looks at those areas that might be of interest to the control system security community.

Control System Security Ignored


HR 3674 has always been an information security bill, but earlier versions did include some brief mentions of control system security issues. This version of the bill removes all of those mentions. For example the wording in §226(a)(7), added in the substitute language submitted in the Subcommittee markup hearing that required the development of “guidelines for making critical infrastructure information systems and industrial control systems [emphasis added]  more secure at a fundamental level” has been removed in this latest version.

Even the wording in the original bill that addressed cybersecurity R&D efforts, requiring the “development and support of technologies to reduce vulnerabilities in process control systems” {§229(b)(5)} has been removed.

No Standards to be Set


It is apparent that the reason for the removal of any reference to control systems in this revised language is because of the full scale revision of the authority to be given to DHS to regulate cybersecurity in the private sector. Actually, ‘revision’ is hardly adequate; the regulatory scheme for this new bill is summed up nicely in §226 that is being added to the Homeland Security Act of 2002 in §2 of this bill. It requires the DHS Secretary to “perform necessary activities to help facilitate the protection of Federal systems and, solely upon the request of critical infrastructure owners and operators [emphasis added], assist such critical infrastructure owners and operators in protecting their critical infrastructure information systems” {§226(a)}.

The phrase ‘solely upon the request’ occurs in a number of places in the discussion in §226 of how the Secretary will go about ‘assisting in protecting’. It is specifically used to describe the conduct of risk assessments for critical infrastructure information systems and the providing of technical assistance to critical infrastructure owners and operators.

Careful reading of this section of the revised language for the bill allows one to understand why this bill does not intend to establish a regulatory regime for protecting cybersecurity in the private sector; there will not be enough resources made available to DHS to allow them to prepare rules and establish an enforcement capability to support such regulations. This is clearly seen in §226(e):

“The provision of assistance or information to critical infrastructure owners and operators, upon request of such critical infrastructure owners and operators, under this section shall be at the discretion of the Secretary and subject to the availability of resources. The provision of certain assistance or information to one critical infrastructure owner or and operator pursuant to this section shall not create a right or benefit, substantive or procedural, to similar assistance or information for any other critical infrastructure owner or and operator.”

Information Sharing


Lungren (and presumably the Committee Staff) is obviously trying to avoid the ire of various internet activists the way that the Roger’s information sharing bill (HR 3523) has increasingly done. Subtitle E of the bill would add a series of sections to the Homeland Security Act to address cybersecurity information sharing by DHS.

The first section of this subtitle clearly requires DHS to supply cyber-threat information to the private sector; something that has not been explicitly spelled out in any cybersecurity legislation to date. Section 241 requires the Secretary to make “information appropriately in the possession of the Department available to appropriate owners and operators of critical infrastructure on a timely basis”. Caveats are provided for details of protected information and classified information.

The bill establishes the National Cybersecurity and Communications Integration Center (NCCIC) as the agency within the Department responsible for carrying out the information sharing requirements of the Department. The sharing requirements for the NCCIC include cyber threat information and “exchanging technical assistance, advice, and support with appropriate entities” {§242(b)}. Unfortunately, the section that outlines the methodology and requirements for information sharing and protection is poorly written.

Section 243(a)(1) starts out explaining that that Federal agencies are required to provide cybersecurity threat information in their possession to the NCCIC; allowing them to place restrictions on what and how that information could be shared to protect the sources of that information. There is nothing really controversial here.

Section 243(a)(2) places additional and more specific restrictions on how information provided to the NCCIC can be shared. The wording implies, but never specifically states, that much of the information covered under this subparagraph would be information provided to DHS by the private sector. This can be seen in the use of the phrases “protected entity” and “self-protected entity” that have been proposed in other cybersecurity bills. Unfortunately they are not defined anywhere in this bill.

Information sharing protections listed in §243(a)(2)(C) and §243(a)(2)(D) include:

• Shall be exempt from disclosure under section 552 of title 5, United States Code;

• Shall be considered proprietary information and shall not be disclosed to an entity outside of the Federal Government except as authorized by the entity sharing such information;

• Shall not be used by the Federal Government for regulatory purposes;

• Shall be handled by the Federal Government consistent with the need to protect sources and methods and the national security of the United States; and

• Shall be exempt from disclosure under a State, local, or tribal law or regulation that requires public disclosure of information by a public or quasi-public entity.

Information Sharing Restrictions


Responding to specific privacy and domestic spying charges levied against HR 3523, Lungren has provided three separate restrictions on the use information shared with the Federal government (presumably, but not specified, by private sector entities). Actually this is another poorly written area as there is a repeated reference to ‘subsection (b)’ but there is no such subsection in §243.

The revised language provides the ‘limitation on use’ provisions that only allow Federal agencies to share the information only if “at least one significant purpose of the use” {§243(a)(3)(A)(ii)} is for cybersecurity purposes or protection of national security. Similar language is found in HR 3523.

Lungren has added language {§243(a)(3)(B)} that specifically prohibits searching such information provided to the Federal Government (again presumably by the private sector) except for national security or cybersecurity purposes. It also specifically prohibits {§243(a)(3)(C)} the Federal Government from requiring “a private sector entity to share information with the Federal Government”.

It is not clear that these efforts will mollify privacy and internet freedom advocates concerns about the effects of these security provisions on their privacy and freedom of expression rights. But an effort has been made.

The Markup Hearing


The full Homeland Security Committee will meet in a markup hearing on Wednesday, April 17th, 2012. It is likely that there will be a number of additional amendments made to this language. I’ll cover those results later this week.

Thursday, October 15, 2009

HR 2868 IST Changed

The Energy and Environment Subcommittee of the House Environment and Commerce Committee held the first markup hearing for HR 2868 in that committee. This is a major move forward, a step that was never reached in last year’s consideration of HR 5577. Various news reports indicate that the full committee markup will probably occur next week. All of the significant changes to the bill were made in the Manager’s Amendment proposed by Chairman Markey (D, MA). While that amendment made a large number of small changes, large changes were made to the IST, civil suits and background checks provisions of bill. It appears these changes were designed to broaden the potential support for (or at least reduce the opposition to) the bill. Inherently Safer Technology The IST provisions of the markup provide wins and losses for both sides in the debate. First the changes require the Department to consult with the local Captain of the Port before ordering an MTSA covered facility to implement an IST. Next the time to file an appeal of a mandate to implement IST, as well as the time for DHS to review such an appeal were both extended to 120 days. Finally, DHS is required to consult with “experts in the subjects of environmental health and safety, security, chemistry, design and engineering, process controls and implementation, maintenance, production and operations, chemical process safety, and occupational health” {§2111(b)(2)(B)}during the review of the appeal. All of these items were done to assuage the concerns of the chemical industry. To keep the environmentalists and labor groups from screaming about the weakening of the IST provisions, Chairman Markey changed the basis for the DHS decision process on mandating IST implementation. In the original bill the Secretary could only mandate the implementation of an IST technique identified by the facility as effective and feasible. The revised legislation moves the decision to the Director of the Office of Chemical Facility Security and allows more leeway in what IST techniques can be mandated. The new standard retains the standards of technical and financial feasibility and job retention. It specifically allows for the decision to be made at the discretion of the Director “based in part on an assessment conducted” {§2111(b)(1)(A)} by the facility. This provides for the prospect of the Director seeing and requiring an IST implementation that the facility ignored or overlooked. As a practical matter, it would be an unusual situation where the Director had sufficient information to require a facility to implement an IST technique not identified by the facility. This change also makes sure that the decision to require the implementation of IST is made by a career DHS employee rather than by a political appointee. Presumably this would insure that a professional is making the decision and not someone that is being swayed by the politics of the situation. Additionally, the phrase “in his or her discretion” {§2110(b)(1)(A)} exempts this decision from the citizen suit provisions of the legislation. Citizen Suits The Markey Amendment makes two significant changes to the Citizen Suits provisions of HR 2868. First it will restrict those citizen suits to suits filed against government entities. Even this would be limited in that it would be restricted to non-discretionary actions taken by the government. Where this would have its largest effect would be at Federally owned high-risk chemical facilities. It is not clear what facilities this would cover because §2112 still exempts DOD owned facilities and facilities regulated by the NRC. Instead of allowing citizens to sue privately owned facilities for non-compliance with this regulation, it would require the Secretary to establish a Citizen Petition process. This would provide a formal mechanism for private citizens to identify persons (including government agencies) that are “alleged to be in violation of any standard, regulation, condition, requirement, prohibition, plan, or order that has become effective under this title” {§2117(b)(1)} and to specify the alleged violation. The Secretary is required to investigate all of the alleged violations reported under this new procedure. Reports will be made back to the submitter of the initial support providing information, within the limitations of the information security requirements of the legislation, on the results of the investigation including any enforcement actions taken by the Secretary. To ensure transparency in the allegation review process the Secretary is required to allow the DHS Inspector General full access to the records of investigation. The one loophole that remains in this process is that there is no ‘at the discretion of the Secretary’ language in this section that would protect the Secretary against citizen suits under §2116 for failure to take actions under this section. Still, the non-government owned chemical facilities are being separated from the citizen suit process and should have no expectation that DHS would not investigate allegations of violations of the regulations prepared in support of this proposed legislation. Background Checks The background check section of the legislation {§2115} has undergone a major rewrite to increase the protections of employees in the background check process. Labor unions have long been concerned that the necessary personnel surety programs would be used by management to get rid of uncomfortable employees that are protected under a variety of labor laws. Most of these changes clarify what findings in a background check justify ‘adverse employment actions’ and better delineate the required redress procedures. The other issue that is addressed is the use of the TWIC card as a substitute for the required background checks under this regulation. To make sure that it is clear that no additional checks are necessary for TWIC holders the legislation specifically states {§2115(h)} that: “Such regulations shall provide that no security background check under this section is required for an individual holding a transportation security card issued under section 70105 of title 46, United States Code.” Not in the Revision I was surprised less at what was in the revised legislation than what was not in the bill. I expected to see an amendment removing waste water facilities from coverage under CFATS (to go the HR 3258 and EPA responsibility). Nor was there a provision authorizing the Secretary to use some form of staggered implementation of IST as was requested by DHS and the Administration. These may yet show up in the full committee markup, perhaps as early as next week. The provisions changed in the legislation yesterday should make the bill a little more palatable to industry, but I don’t think they will be enough to garner any significant number of Republican votes. It may, however make the bill easier to pass because it should be easier to convince moderate Democrats to follow the party line and vote for the bill. This will be especially important in the Senate. One final comment; I really appreciate the thorough web site that the House Energy and Commerce Committee maintains for recording these hearings. The markup web page provides copies of all of the amendments discussed in the hearing. This allows for a much better understanding of the proceedings. Chairman Waxman is to be commended on this innovative use of the Committee web site.
 
/* Use this with templates/template-twocol.html */