Showing posts with label NCFI. Show all posts
Showing posts with label NCFI. Show all posts

Wednesday, September 28, 2022

S 4673 Passed in Senate – NCFI Reauthorization

Yesterday, the Senate discharged the Senate Judiciary Committee from the responsibility of considering S 4673, the National Computer Forensics Institute Reauthorization Act of 2022, and passed the bill under the Senate’ unanimous consent process. There was no debate and no formal vote. The House passed an entirely different version of the reauthorization, HR 7174 back in June.

It will be interesting to see if the House takes up S 4673 and if they then amend the bill by substituting the language from HR 7174. With the Senate ignoring HR 7174 and taking up a bill that was introduced two months after HR 7174 was passed, I do not expect that the Senate would agree to a version of the bill amended in that manner. Insisting on the Senate version of the language would require a conference committee.

Since the major difference between the two bills in the expansion of the definition of information systems to include industrial control systems, I suspect that it is that expansion of coverage that the Senate leadership objects to. If that is the case, working out a compromise might be a problem.


Monday, June 20, 2022

HR 7174 Reported in House – Cyber Forensics

Last week, the House Homeland Security Committee published their report on HR 7174, the National Computer Forensics Institute Reauthorization Act of 2022. The Committee considered the bill on May 19th, 2022. Some relatively minor amendments were adopted, and the Committee ordered the amended bill reported favorably. The bill will be considered by the Full House tomorrow under the suspension of the rules process.

The Report provides a look at how multiple committees can work together when there is overlapping jurisdictions. In this case, the House Judiciary Committee has limited jurisdiction over some parts of the operation of the NCFI and were thus assigned to consider this bill. The Judiciary Committee held no hearings about the bill and the Chairs of the two committees were able to work together to allow the bill to move forward to consideration by the Full House. The Report contains letters between Rep Nadler (D,NY) and Rep Thompson (D,MS), the respective Chairs of the Judiciary and Homeland Security Committees.

There is no telling how much back and forth between the two chairs (and their staffs, of course) occurred to allow this cooperative action. I suspect that Thompson’s amendment to the bill may have been part of the process for moving that agreement forward.

Monday, September 21, 2015

Subcommittee Amends and Adopts HR 3490

Last week the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee amended and favorably recommended to the full Committee HR 3490, the Strengthening State and Local Cyber Crime Fighting Act. The action was taken on a voice vote, suggesting substantial bipartisan support for the bill as I suggested in my earlier post.

The sole amendment added the Federal Law Enforcement Training Center (FLETC) to the list of agencies that the National Computer Forensics Institute is supposed to work with in furthering the goals of effective cyber forensics.

Moving Forward

Again, I expect that this bill will move forward to a full Committee markup fairly quickly. It will not be this week due to the short work week in the House (effectively only two days), but I expect it before the Columbus Day recess.

Commentary


I would still like to see this bill amended to specifically mention a requirement to establish control system forensics capabilities established at the NCFI. While the ICS-CERT certainly significant expertise in this area, they are woefully understaffed and funded to investigate an ever widening number of ‘control’ systems in the internet of things that will be coming under increasing attack as awareness of the vulnerabilities in these systems becomes increasingly understood by the cyber-criminal community. Even critical infrastructure ICS cases are going to start to come under criminal investigation and I don’t believe that criminal forensics is really the purview of ICS-CERT.
 
/* Use this with templates/template-twocol.html */