Showing posts with label Markup. Show all posts
Showing posts with label Markup. Show all posts

Tuesday, May 18, 2021

Update on Cybersecurity Markup – 5-18-21

The House Homeland Security web site now has complete listings for the seven bills that it will be marking up this afternoon. Four of the bills are cybersecurity bills and a fifth deals with critical infrastructure. I have not yet had a chance to publish detailed reviews of each of these bills, so I am going to do a quick review of those that I have not reviewed.

The five bills of interest are:

HR 2980, the “Cybersecurity Vulnerability Remediation Act”

• HR 3138, the “State and Local Cybersecurity Improvement Act”

• HR 3223, the “CISA Cyber Exercise Act”

• HR 3243, the “Pipeline Security Act”

• HR 3264, the “Domains Critical to Homeland Security Act”

HR 3138

This bill is similar to HR 5823 from last session. It would establish a grant program, the State and Local Cybersecurity Grant Program, with $500 million being authorized each year for the program through 2026. Each grant applicant would have to submit a cybersecurity plan to DHS for approval. Each applicant would also have to establish a cybersecurity planning committee. Multi-state grants would be authorized.

CISA would be required to establish a State and Local Cybersecurity Resiliency Committee. CISA would also be required to prepare and maintain a resource guide to help officials identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents.

Definition of ‘information system’ in this bill uses the ICS inclusive definition from 6 USC 1501.

HR 3223

This bill would amend the Homeland Security Act or 2002 by adding a new section 2220A, National Cyber Exercise Program. It would require CISA to establish a National Cyber Exercise Program  to evaluate the National Cyber Incident Response Plan. No additional funding authorization is provided. CISA is already conducting similar cybersecurity exercises.

HR 3243

This bill (Committee Print) would amend 49 USC 114, Transportation Security Administration, mandating that TSA continue being responsible for securing pipeline transportation and pipeline facilities against cybersecurity threats {new §114(f)(16)}.

It would also add a new section 1631, Pipeline Security Section, to a new Subtitle D, Pipeline Security, to the Homeland Security Act of 2002. It would require TSA to establish a pipeline security section to implement the responsibilities of §114(F)(16) {§1631(a)}. The new section would include personnel with cybersecurity expertise {§1631(c)}.

HR 3264

This bill (Committee Print) would add a new section 890B, Homeland Security Critical Domain Re6 Search And Development, to the Homeland Security Act of 2002. It defines two new terms {§890B(c)}: ‘United States critical domains for economic security’ (NOT related to  the cyber term ‘domains’) and ‘economic security’. Section 890B(a) would authorize research and development to identify and evaluate United States critical domains for economic security and homeland security. The bill authorizes $1 million for this program.


Monday, May 10, 2021

Update for Senate HSGA Markup – 5-12-21

The Senate.gov website now lists the bills that will be marked up by the Senate Homeland Security and Governmental Affairs Committee on Wednesday. The thirteen bills scheduled include four cybersecurity related measures:

S 1097, to establish a Federal rotational cyber workforce program for the Federal cyber workforce {Sen. Peters, (D,MI)}

S 1316, to amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to make a declaration of a significant incident {Sen. Peters, (D,MI)},

S 1324, to establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs for the United States with respect to national security {Sen Rosen (D,NV)}, and

S 1350, to require the Secretary of Homeland Security to establish a national risk management cycle {Sen Hassan (D,NH)},

The GPO has not yet published official versions of any of these bills, nor can I find them posted to the HSGA web site. Hassan’s web site does have a submission draft copy posted for S 1350, the ‘National Risk Management Act of 2021. I will have a detailed review of that bill, based upon that draft available later this evening. We may see S 1097 published this evening, but I doubt the GPO will get to S 1316 or S 1324 before Wednesday morning.

Monday, January 27, 2020

Congressional Hearings – Week of 1-26-20


With the House back from their MLK break and the Senate still sitting in their impeachment proceeding there are a limited number of committee hearings this week. There is one markup hearing of interest by the House Homeland Security Committee.

Markup Hearing


On Wednesday the House Homeland Security Committee will hold a markup hearing. The bills to be reviewed include HR 5667, the Cybersecurity Vulnerability Identification and Notification Act of 2019. This bill was introduced last Friday, and the official version has yet to be printed. I have briefly reviewed the committee print and it looks to be similar to S 3045 but there are some interesting definitions related to operational technology that I look forward to reviewing in depth.

Wednesday, March 13, 2019

HR 1589 Marked Up in House


Today the House Homeland Security Committee held a markup hearing to consider seven bills, including HR 1589, the CBRN Intelligence and Information Sharing Act of 2019. That bill was amended twice and adopted by the Committee by unanimous consent as part of a block of bills.

Both of the amendments to HR 1589 were relatively minor wording additions.

The first amendment from Rep. Clarke (D,NY) changed §210H(a)(1) to read:

“(1) support homeland security-focused intelligence analysis of terrorist actors, their claims, and their plans to conduct attacks involving chemical, biological, radiological, or nuclear materials against the United States, including critical infrastructure [added];”

The second amendment from Rep. Jackson-Lee (D,TX) changed §210H(a)(4) to read:

“(4) leverage existing and emerging homeland security intelligence capabilities and structures to enhance early detection, [added] prevention, protection, response, and recovery efforts with respect to a chemical, biological, radiological, or nuclear attack;”

As I mentioned in my earlier blog post today, this bill will make its way to the floor of the House where it will be considered under the suspension of the rules process. That process does not provide for any additional amendments to be made from the floor. The bill will almost certainly pass with a significant bipartisan vote.

Tuesday, October 6, 2015

Homeland Security Committee Marks-Up Multiple Bills

Last Wednesday the House Homeland Security Committee held a markup hearing that dealt with a large number of bills. As I mentioned in an earlier post some of those bills will be of specific interest to readers of this blog. Those include:

HR 3350, the Know the CBRN Terrorism Threats to Transportation Act;
HR 3490, the Strengthening State and Local Cyber Crime Fighting Act;
HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015;
HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015;
HR 3573, the DHS Science and Technology Reform and Improvement Act of 2015;
HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act;
HR 3586, the Border and Maritime Coordination Improvement Act; and
HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015.

HR 3350 was adopted without amendments on a voice vote.

HR 3490

HR 3490 was amended and adopted by a voice vote. Rep. Ratcliffe (R,TX) proposed substitute language reflecting the changes made to the bill in a Subcommittee markup which was adopted by a voice vote. Two amendments were offered by Rep. Jackson-Lee (D,TX). The first dealt with chain-of-custody training. The second dealt reaffirmed the supremacy of the fourth and fifth amendments with respect to the provisions of this bill. Both amendments were adopted by voice vote.

HR 3503

HR 3503 was amended and adopted by a voice vote. Two amendments were introduced by Rep. Loudermilk (R,GA). The first dealt with a requirement for DHS to conduct an assessment for accessibility and interoperability of the information systems used to share homeland security information between the Department and fusion centers. The second required DHS to enter into a memorandum of understanding about what types of information fusion centers would share with DHS. Both amendments were adopted by voice vote.

HR 3510

HR 3510 was amended and adopted by a voice vote. Rep. Clawson (R,FL) introduced one amendment which dealt with privacy concerns. That amendment was adopted by a voice vote.

HR 3578

HR 3578 was amended and adopted by a voice vote. Eight amendments, including alternative language offered by Rep. Ratcliffe, were offered and all were adopted on voice votes. The alternative language made no substantive changes of particular interest to readers of this blog. Of the remaining seven amendments only one of specific.

That amendment by Rep. Langevin (D,RI) that modifies the new §322 the bill adds to the Homeland Security Act of 2002. That section addressed cybersecurity R&D and this amendment adds a new activity to be addressed by DHS S&T; “support, in coordination with the private sector, the review of source code that underpins critical infrastructure information systems” {new §322(b)(4)}.

HR 3583

This bill was amended and adopted by a voice vote. Of the seven amendments offered and adopted only one would be of specific interest to readers of this blog. It was offered by Rep. Payne (D,NJ), the Ranking Member of the Committee.

The amendment modifies 6 USC 321e(c)(1); adding a new duty to job of Department Chief Medical Officer. That new requirement is specifically requiring the provision of advice on “how to prepare for, protect against, respond to, recover from, and mitigate against the medical effects of terrorist attacks or other high consequent events utilizing chemical, biological, radiological, or nuclear agents or explosives”. This wording still limits that advice to ‘chemical agents’ so it would not include advice on response to industrial chemical incidents unless they were used as part of a terrorist attack.

HR 3586

The bill was amended and adopted by a voice vote. Rep. Miller (R,MI) offered an amendment in the form of a substitute. That substitute language softened much of the language in the bill but did not make any substantive changes of particular interest to readers of this blog. None of the other ten amendments that were adopted on this bill were of specific interest to readers of this blog.

HR 3584

This bill was amended and adopted by a voice vote. None of the eight amendments adopted on this bill substantially affected areas of specific interest to readers of this blog.

Moving Forward

All of these bills are apparently on Chairman McCaul’s (R,TX) agenda for moving to the floor of the House. I expect that there is a good chance that they will all make it to the floor prior to the end of the year and there is a chance that they will all arrive on the same day. With the broad bipartisan support seen in Committee I expect that they will all be considered under suspension of the rules with limited debate and not floor amendments. All of these bills should pass with substantial bipartisan support.

I do not see any of these bills as being a high priority for getting consideration in the Senate. Any of these bills could easily pass and none would have significant opposition; it is just a matter of legislative priorities about which of these might make it to the floor of the Senate.

Commentary

Not surprisingly, none of the suggestions that I have made here in this blog for improving any of these bills were included in the amendments that were adopted. Oh well, that is always the problem with being a voice crying in the wilderness; the few people that do hear you are not necessarily ones that can do anything about it.

There was that one odd amendment by Langevin on HR 3578 that kind of interests me. It does not cover control systems since this new section uses the definition of ‘information systems’ from 44 USC 3502 which interestingly only applies to Federal IT systems.

I’m not sure what Langevin was trying to accomplish with this ‘review of source code’. Okay I suppose that I could guess that he wants someone to check these IT programs for bugs, but reviewing the source code is not probably the most effective method of doing that. And the terminology ‘that underpins critical infrastructure information systems’ was obviously not written by a programmer. Now the vendor should already be conducting a source code review prior to publishing the software, so I am not sure what Langevin is expecting this to accomplish.

The real interesting thing about this amendment is not actually what it does or tries to do, but the fact that it is part of a new trend in legislation over the last month or so where there are bits of cybersecurity language being added to bills that are not overtly cybersecurity bills. In many ways this is probably a more practical way to cybersecurity provisions passed. Large, all-encompassing bills are going to always draw somebodies ire and we will see few of them actually become law. Small targeted provisions (even if poorly written like this one) in a bill that is not going to draw substantial opposition are much more likely to get passed.

The problem is, of course, how to you keep the ineffective or even offensive small cybersecurity provisions out of otherwise good legislation? Amendments like Langevin’s are not posted in advance for public review and I doubt anyone on the Committee (members or staff) are tech savvy enough to understand how ineffective this provision actually is. And once an amendment is adopted in full committee it is unlikely to get removed in the remaining portions of the legislative process.

Small cybersecurity provisions that are written into original legislation are likely to be seen by reviewers like me, but will generally be overlooked by most people. This means that only the most objectionable are likely to draw the kind of opposition that will have them removed from the bill or modified to make them more workable.


This new approach of adding small, limited cybersecurity provisions to other types of legislation is going to start to make things interesting in the legislative process.

Monday, September 28, 2015

Congressional Hearings – Week of 09-27-15

Both the House and Senate will be in session this week. It looks like the short term funding fight was resolved on Friday so the Congress turns to other items. Hearings this week will include three markup hearings in the House, a number of military related cyber hearings on both sides of the Capitol, as well as a pipeline safety and TSA management hearing.

Markup Hearings

The House Energy and Commerce Committee will hold a markup hearing on Tuesday that will look at HR 8, the North American Energy Security and Infrastructure Act of 2015. It will be interesting to see if any changes will be made to the Cyber Sense program to deal with the problems that I identified earlier.

The House Judiciary Committee will hold a markup hearing on Wednesday that will look at HR 3490, the Strengthening State and Local Cyber Crime Fighting Act. It is unlikely that this Committee will address the control system forensics concerns that I mentioned earlier. If that is to be addressed it will have to be in the Homeland Security Committee hearing described below. Both Committees will consider the same substitute language on the bill that is the result of the earlier subcommittee markup.

The House Homeland Security Committee will also hold a markup hearing on Wednesday with a large number of bills being considered. The bills of specific interest to readers of this blog include:

HR 3350, the Know the CBRN Terrorism Threats to Transportation Act;
HR 3490, the Strengthening State and Local Cyber Crime Fighting Act;
HR 3503, the Department of Homeland Security Support to Fusion Centers Act of 2015;
HR 3510, the Department of Homeland Security Cybersecurity Strategy Act of 2015;
HR 3578, the DHS Science and Technology Reform and Improvement Act of 2015;
HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies Act*;
HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015;
HR 3586, the Border and Maritime Coordination Improvement Act*; and
HR 3598, the Fusion Center Enhancement Act of 2015*

Note: I have not had a chance to review the bills marked with an ‘*’ yet. I should publish reviews on them by Wednesday.

Military Cyber Issues

Military cyber issues are certainly going to touch on some IT and ICS security issues, but that will not be their primary focus. I am just going to list the hearings here without discussion.

Senate Armed Services - Cybersecurity policy and threats

TSA

The Homeland Security Subcommittee of the Senate Appropriations Committee will be holding a hearing on Tuesday to examine the Transportation Security Administration's efforts to address inspector general findings. There will only be two witnesses:

• Peter V. Neffenger, TSA Administrator; and
• John Roth, DHS Inspector General

Pipeline Safety

The Surface Transportation and Merchant Marine Infrastructure, Safety and Security Subcommittee of the Senate Commerce Science and Transportation Committee will hold a hearing on Tuesday to examine pipeline safety, focusing on oversight of our nation's pipeline network. Witnesses will include:

• Susan Fleming, US GAO;
• Christopher Hart, NTSB;
• Michael Bellamy, PII Pipeline Solutions;
• Donald Santa, Interstate Natural Gas Association of America; and
• Terry McCallister, American Gas Association

On the Floor

In addition to the clean version of HR 719 [Bill # corrected 17:00, 9-28-15] (the Continuing Resolution that will continue funding through December 13th) that the Senate will consider tonight and the House will consider on Wednesday, there are a couple of bills of specific interest that are scheduled to make it to the floor of the House this week. They are:

HR 2786, Cross-Border Rail Security Act of 2015, under suspension of the rules; and
HR 1735, 2016 NDA conference version, under a rule.

Monday, September 14, 2015

Energy Security Mark-up Hearing Announced

This evening the House Energy and Commerce Committee announced that they would be holding a markup hearing on Wednesday and Thursday for two energy related bills. Readers of this blog would probably be most interested in the North American Energy Security and Infrastructure Act of 2015, a bill that has not yet been introduced.

I do not intend to do a full analysis of this bill until it is introduced, but table of contents of the bill contains a listing of the bill’s sections that includes topics like:

Sec. 1104. Critical electric infrastructure security;
Sec. 1106. Cyber Sense; and
Sec. 3104. Collective energy security

A committee summary of the bill can be found here.


According to the draft version of the bill on the Committee web site Chairman Upton (R,MI) will be introducing this bill. This almost certainly ensures that it will be promptly reported out of Committee after this week’s two part hearing. I suspect that it would not, however, come to the floor until after October 1st. It will be interesting to see if Ranking Member Pallone (D,NJ) will be a co-sponsor of the bill.

Friday, May 15, 2015

Subcommittee Amends and Adopts CBRN Intel Bill

Yesterday the Subcommittee on Emergency Preparedness, Response, and Communications of the House Homeland Security Committee passed two amendments to HR 2200, the CBRN Intelligence and Information Sharing Act of 2015 by voice vote and then recommended the bill to the full Committee.

The first amendment was the substitute language from Chair McSally (R,AZ) that I described in an earlier post. The second amendment was offered by Rep. Payne (D,NJ), the Ranking Member of the Subcommittee. That amendment added local public health departments to the agencies to be notified of CBRN information developed by the Office of Intelligence and Analysis of the Department of Homeland Security.


As I mentioned earlier while this legislation is billed as chemical, biological, radiological and nuclear intelligence bill, it is clear that the main focus is actually biological attacks. I understand the concern with the consequences of a successful bio-attack it still takes a great deal of sophistication to execute an attack of this sort, much more sophistication than it takes to conduct an attack with industrial chemicals.

Tuesday, May 12, 2015

New Homeland Security Subcommittee Markup Hearing

Yesterday the Emergency Preparedness, Response and Communications Subcommittee of the House Homeland Security Committee announced that they would be holding a markup hearing on Thursday. Three bills will be reviewed, including HR 2200 that I reviewed this weekend.

The Chair, Rep. McSally (R,AZ) is offering an amendment in the form of a substitute that will form the version to be marked up. The change is administrative in nature; taking the congressional reporting requirements out of the new section 210g being added to  the Homeland Security Act of 2002. They will remain in the bill, but will not become part of the statute if this bill is adopted.

As I noted in my earlier post this bill appears to be slated for early movement to the House floor. We are likely to see it considered in a full committee hearing in the next week or so.


Wednesday, March 4, 2015

Senate Homeland Security Committee Adopts S 546

As I predicted earlier today, the Senate Homeland Security and Government Affairs Committee took up S 546, the RESPONSE Act of 2015. The Committee ordered the bill to be reported favorably on a voice vote. There were no amendments.

Since my earlier posting the GPO has provided a link to the language for S 546 and I have been able to confirm that it is almost perfectly identical to HR 1043. The only difference that I could find was the addition of the words “as appropriate” in §318(d)(6); hardly an earth shaking change.


It really does look like this bill, barring something really strange, or its House counterpart will likely make to the floor in each house and then to the President. It is almost certainly only a matter of timing.

Tuesday, July 9, 2013

New Mark-up Hearing Scheduled

Yesterday evening the House Transportation and Infrastructure Committee added a markup hearing for tomorrow. Among the bills to be considered will be HR 2576, a bill that affects the pipeline safety law by amending 49 USC 60102(p), the Limitation on Incorporation of Documents by Reference.

The bill revises that paragraph (added in January, 2012 by PL 112-90, the Pipeline Safety, Regulatory Certainty, and Job Creation Act of 2011) to read:

“Beginning 3 years after the date of enactment of this subsection, the Secretary may not issue a regulation pursuant to this chapter that incorporates by reference any documents or portions thereof unless the documents or portions thereof are made available to the public, free of charge.”

The bill changed the time limit from one year to 3 years {§1(1)}, removed the words ‘guidance or’ from the phrase “not issue guidance or a regulation” {§1(2)}, and removed the words “on an Internet Web Site” from the end of the paragraph.

In short, this bill would expand, slightly, the use of incorporation by reference that was restricted somewhat by the 2012 law.


Given the number of other bills being considered by the Committee during this hearing, I don’t expect that any significant changes will be made to this bill in mark-up. The bill will certainly pass in committee and I suspect that it will pass on the floor without significant opposition if it gets to the floor. It might also get added to the DOT authorization bill.

Monday, April 8, 2013

CISPA Hearing Scheduled – 04-10-13


The House Intelligence Committee web site now says that there will be a markup hearing on HR 624, the Cyber Intelligence Sharing and Protection Act (CISPA), on Wednesday on April 10th. A second page notes that the hearing will be open but it will be held in a House meeting room (HVC-304) that is normally used for closed meetings. I haven’t been there, but I would assume that this means that public seating will be limited. There is no word on either page about whether or not the hearing will be televised or web cast.

Tuesday, September 13, 2011

Transportation Security Subcommittee to Markup TSA Authorization Bill

The House Homeland Security Committee announced yesterday that its Transportation Security Subcommittee will be holding a markup hearing this tomorrow on an as yet unpublished ‘TSA Authorization Act’. Since this is an ‘open markup’ it is expected that this will be a multiple day hearing.

Ranking Member Jackson-Lee has introduced a bill (HR 1900) that would specifically authorize ground transportation security measures for TSA. Provisions from that bill might be included in the bill being marked up in this hearing or may be added as amendments to Chairman Rogers’ (R,AL) bill.

Tuesday, May 12, 2009

HR 2200 Full Committee Markup Scheduled

As I mentioned in last week’s blog on the subcommittee markup of HR 2200, the Transportation Security Administration Authorization Act, this bill certainly seems to be on the fast track. Introduced less than two weeks ago, it will undergo a full House Homeland Security Committee markup this week on May 14th at 10:00 a.m. EDT. Once that is completed it may take a couple of weeks to get the committee report submitted, but I expect that this bill will go to the floor right after the Memorial Day recess.
 
/* Use this with templates/template-twocol.html */