Showing posts with label NG. Show all posts
Showing posts with label NG. Show all posts

Monday, June 21, 2021

HR 2982 Introduced - National Guard Cybersecurity Support Act

Last month Rep Kim (D,NJ) introduced HR 2982, the National Guard Cybersecurity Support Act. The bill would specifically allow members of the Army and Air Force National Guard to conduct ‘cybersecurity operations’ to protect critical infrastructure. This is a companion bill to S 70 that was introduced in January. As I had predicted the Senate bill has not seen any action in committee.

Moving Forward

Kelly and two of his four co-sponsors {Rep Wilson (R,SC) and Rep Kelly (R,MS)} are members of the House Armed Services Committee, the Committee to which this bill was assigned for consideration, so there could be sufficient influence to see the bill considered in Committee. I see nothing in this bill that would engender any significant opposition. The bill should receive broad, bipartisan support in Committee. If this bill moves to the House floor, it would be considered under the suspension of the rules process. This means limited debate, no floor amendments and a super majority would be required for passage.

Commentary

My comments on S 70 apply equally to this bill. I would like to add a new observation that also applies to both bills. They both rely on 42 USC 5195c(e) for their definition of ‘critical infrastructure’. That definition reads:

“In this section, the term ‘‘critical infrastructure’’ means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

This was deliberately written as broadly as possible, and for most applications that is helpful. It provides federal officials the maximum amount of leeway in addressing security concerns or responding to incidents. But as cybersecurity attacks are increasingly becoming more widespread and costly, there will be a need for federal government agencies to limit the deployment of their resources and rely more on the growing cybersecurity industry in the country to handle the all but the most critical facility attacks.

This bill may not be the place to start considering the limitations of federal cyber response capabilities, but it is a discussion that will have to be had.

Thursday, February 18, 2021

S 70 Introduced - National Guard Cybersecurity Support Act

Last month Sen Hassan (D,NH) introduced S 70, the National Guard Cybersecurity Support Act. The bill would specifically allow members of the Army and Air Force National Guard to conduct ‘cybersecurity operations’ to protect critical infrastructure.

The Authority

The bill would amend 32 USC 502(f)(1) to add the following language at the end of the paragraph:

“Such training or other duty may include cybersecurity operations or missions undertaken by the member's unit at the request of the Governor of the State concerned to protect critical infrastructure (as that term is defined in the Critical Infrastructures Protection Act of 2001 (42 U.S.C. 5195c)).” {§2}.

Sub-section 502(f) provides authorization for DOD to prescribe regulations for requiring National Guard members to perform duties in addition to monthly and annual drills required by §502(a).

Moving Forward

Neither Hassan, nor her cosponsor {Rep Cornyn (R,TX)} are members of the Senate Armed Services Committee to which this bill was assigned for consideration. This means that they are unlikely to have sufficient influence to have the Committee consider the bill.

I see nothing in this bill that would draw specific opposition if it were considered in Committee or brought to the floor of the Senate. I suspect that the bill would receive strong bipartisan support.

Commentary

The first odd thing about this bill is that it looks like it amends the wrong paragraph in §502(f). Paragraph (1) provides the general authorization and paragraph (2) provides a listing of the types of training or duty that could be included under (f).

The second odd thing about the language in this bill is that §502 applies to regulations for federal service {“operations or missions undertaken by the member’s unit at the request of the President or Secretary of Defense” §503(f)(2)(A)}, not service under State control. If the language were added (in either paragraph), it would require DOD to establish regulations allowing Governors to request to use their National Guard troops under these provisions.

The only reason that I could see for doing this would be to require DOD to fund the cybersecurity operations and assume responsibility for the logistical and administrative support for those units (and/or National Guard personnel) ordered to perform the duty requested by Governors who already have operational control of NG units withing thier State.

Monday, February 1, 2021

HR 119 Introduced – Cyber Defense National Guard Act

Last month Rep Jackson-Lee introduced HR 119, the Cyber Defense National Guard Act. The bill would require the Director of National Intelligence to conduct a study on “the feasibility of establishing a Cyber Defense National Guard” {§2(a)}.

The Study

The DNI would consult with DOD and DHS to produce the required study within 240 days of the bill being enacted. A report to Congress on the study would be published in unclassified form, but a classified annex could be included. The items to be included in the study would include {§2(b)}:

• The cost of creating a Cyber Defense National Guard,

• The number of persons who would be needed to defend the critical infrastructure of the United States from a cyber-attack or manmade intentional or unintentional catastrophic incident,

• The sources of potential members of a Cyber Defense National Guard, including industry, academic institutions, research facilities, and Federal contractors,

• Which elements of the Federal Government would be best equipped to recruit, train, and manage a Cyber Defense National Guard,

• The criteria required for persons to serve in a Cyber Defense National Guard,

• The impact of the effectiveness of a Cyber Defense National Guard of the possibility that the population of potential recruits may be dominated by men and women without military, intelligence, law enforcement, or government work experience,

• The recruitment and vetting costs for a Cyber Defense National Guard,

• How well military discipline is able to be adapted for use for creating command and control systems and protocols for a Cyber Defense National Guard,

• The logistics of allowing governors to use the Cyber Defense National Guard in States during times of cyber emergency,

• The advantages and disadvantages of creating a Cyber Defense National Guard on the cyber security of the United States, and

• Whether a force trained to defend the networks of the United States in the event of a major attack or natural or manmade disaster will benefit overall efforts to defend the interests of the United States.

Moving Forward

Jackson-Lee is not a member of the House Intelligence Committee to which this bill was assigned for consideration. This means that it is unlikely that she has the influence necessary to see the bill considered in Committee. I see nothing in the bill that would cause organized opposition to its passage. I suspect that it would receive at least some bipartisan support if it were considered in Committee or on the floor of the House.

This bill is a potential candidate to be offered as an amendment to either the National Defense Authorization Act or the Intelligence Authorization Act.

Commentary

Ms Jackson-Lee made an interesting choice when she designated the DNI as the entity responsible for the conduct of this study. If the CDNG were to be considered as part of the traditional National Guard, the study should have been the responsibility of the Department of Defense. It is apparent from some of the study requirements that the CDNG is not envisioned to be primarily a military type of organization. That would make crafting legislation establishing such an organization challenging.

A CDNG as a third leg of the National Guard Bureau (the Army National Guard and Air National Guard are the two existing legs) would be able to draw on the authority and logistical support designed for the NGB. Existing National Guard statutory language for personnel issues, logistics, deployment, medical support, education and training, and retirement might have to be amended to address unique CDNG issues, but they would not have to be stood up from scratch. Standing up a CDNG outside of the National Guard Bureau would mean that an entirely new and duplicative administrative support structure would have to be included in the legislative authorization along with the necessary funding for that structure.

The other thing that bothers me about this bill is the underlying assumption that it is possible to ‘defend’ critical infrastructure from cyberattack. The cyber realm is much different from the classic defense situation. We cannot establish a navy or air force capable of interdicting enemy cyber forces off our shores. The internet provides an open highway for nation-state and less-than-state adversaries to enter our physical boundaries and probe for weaknesses in our cyber structure.

Defending critical infrastructure from a cyberattack would require taking control of the complete cyber and communications structure of the entity that the CDNG (or anyone else in the government, for that matter) was trying to protect. Private entities are not going to allow that to happen. Even where the guvmint has that control, they are not able to stop cyberattacks, see SolarWinds for example.

Where a CDNG would be more appropriate and effective would be in providing cyber response support to entities that had already affected by a cyberattack, particularly where a cyberattack has interfered with communications or energy transmission. I would envision a Cyber Response National Guard that was able to come in and help isolate and replace and/or bypass affected equipment. The mission would be to help State and local governments and important private sector operations get back into operation providing critical services and products to the public.

Thursday, January 28, 2021

Bills Introduced – 1-27-21

Yesterday with just the Senate in session, there were 20 bills introduced. One of those bills will see additional coverage in this blog:

S 70 A bill to amend title 32, United States Code, to authorize cybersecurity operations and missions to protect critical infrastructure by members of the National Guard in connection with training or other duty.  Sen. Hassan, Margaret Wood [D-NH]

This sounds like it will be similar to S 4833 that was introduced by Hassan in the last session.

Tuesday, January 5, 2021

Bills Introduced – 1-4-21

Yesterday with both the House and Senate in session (117th Congress), there were 192 bills introduced. Of those bills four may receive further coverage in this blog:

HR 117 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training and Employment Apprentice Program, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 118 To require the Secretary of Homeland Security to submit a report on cyber vulnerability disclosures, and for other purposes.  Rep. Jackson Lee, Sheila [D-TX-18]

HR 119 To require the Director of National Intelligence to conduct a study on the feasibility of establishing a Cyber Defense National Guard.  Rep. Jackson Lee, Sheila [D-TX-18] 

HR 171 To require the Secretary of Commerce to establish a task force to identify vulnerabilities in supply chains for United States entities, and for other purposes.  Rep. Stevens, Haley M. [D-MI-11]

It is not unusual to see such a large number of bills introduced during the first month of a new Congress. A very large number of the bills being introduced are political statements with a number of them being re-introduced in each new session. Again, the vast majority of bills introduced in Congress are never considered in committee, fewer are brought to the floor of the respective house for consideration, and even fewer make it to the President’s desk for signature. Seeing a particularly objectionable bill introduced is not cause for undue alarm; the 537 politicians in congress need to make political statements to their supporters from time to time.

I suspect that HR 117 will apply only to the federal government workforce. If that is the case it will probably not be covered here.

Both HR 118 and HR 119 will receive future coverage in this blog.

I will be watching HR 171 for language and definitions that address cybersecurity vulnerabilities, but I suspect that this will be dealing with commercial vulnerabilities in supply chains.

Monday, November 23, 2020

S 4833 Introduced – NG Cybersecurity Operations

Last month Sen Hassan (D,NH) introduced S 4833, bill that would authorize cybersecurity operations and missions to protect critical infrastructure by members of the National Guard.

The bill would amend 32 USC 502(f)(1) to specifically include “cybersecurity operations or missions undertaken by the member’s unit at the request of the Governor of the State concerned to protect critical infrastructure” in what actions could be included in duties to which a member of the National Guard could be assigned.

Moving Forward

Neither Hassan nor her single cosponsor Sen Cornyn (R,TX) are members of the Senate Armed Services Committee to which this bill was assigned for consideration. This means that the bill, even if it had been introduced earlier in the session, would not have been likely to have been considered by the Committee.

I see nothing in this bill that would have drawn any significant opposition. If it were considered in Committee, it would almost certainly draw significant bipartisan support.

Commentary

This is a perfect example of a piece of legislation that would authorize a government agency to do something which it was already doing. National Guard cyber units have been in active support of State agencies across the country and there have been numerous news reports of their support of cyber operations concerning critical infrastructure.

The interesting thing here is where this ‘authorization’ was placed in the United States Code. As currently constituted §502(f)(1) reads:

“(f)(1) Under regulations to be prescribed by the Secretary of the Army or Secretary of the Air Force, as the case may be, a member of the National Guard may—

(A) without his consent, but with the pay and allowances provided by law; or

(B) with his consent, either with or without pay and allowances;

be ordered to perform training or other duty in addition to that prescribed under subsection (a).”

The placement of the cyber operations language in this subsection, specifically ensures that a member of the National Guard can only be individually ordered to take part in “cybersecurity operations or missions” when those missions are “undertaken by the member’s unit”. Thus, an individual with cyber expertise in say an artillery unit could not be ordered to provide cybersecurity services for a private sector company owned by his National Guard unit commander. Not saying that that would happen….

 
/* Use this with templates/template-twocol.html */