Showing posts with label NIST. Show all posts
Showing posts with label NIST. Show all posts

Wednesday, August 12, 2026

Review - NIST Publishes RFI for Updating NVD for AI

Today, DOC’s National Institute of Standards and Technology (NIST) published a request for information (RFI) on “Modernizing the National Vulnerability Database in the Age of Artificial Intelligence”. NIST is looking for input from the cybersecurity community on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. 

According to the document summary: 

“The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.” 

Public Feedback  

NIST is requesting public feedback on, and answers to, the provided questions. NIST is requesting that those public responses be submitted via the Federal eRulemaking Portal (www.Regulations.gov; docket # NIST-2026-0100). Comments should be submitted by October 13th, 2026. 


For more details about the questions proposed, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-rfi-for-updating-nvd - subscription required. 

Wednesday, June 11, 2025

Additional NEPA Implementation Rules Sent to OMB – 6-10-25

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced (EO Review Search Criteria: Agencies=All;   Review Status=Pending Review;   Received from 06/09/2025) that it had received six additional National Environmental Policy Act (NEPA) implementation rules from agencies in the Department of Commerce and Department of Energy. This is in addition to the rules that I reported yesterday.

Yesterday’s rulemakings include:

• National Oceanic and Atmospheric Administration - NOAA NEPA Procedures,

• National Telecommunications and Information Administration - FirstNet Authority NEPA Procedures,

• National Telecommunications and Information Administration - NTIA NEPA Procedures,

• Economic Development Administration - EDA NEPA Procedures,

• National Institute of Standards and Technology - NIST NEPA Procedures, and

• DOE Office of the General Counsel - National Environmental Policy Act Implementing Procedures

One major difference from yesterday’s report, none of these rulemakings were listed in the Fall 2024 Unified Agenda, making these uniquely Trumpian NEPA rules. While you might be able to question Trumps commitment to environmental quality, there is no doubt that his Administration is ‘taking action’ to a whole new level. This is almost certainly attributable to the actions of Russel Voight, Director of the Office of Management and Budget and the primary author of Project 2025.

Again, I will probably not be covering any of these rulemakings in detail when published, but I do intend to mark that publication with notices in the appropriate Short Takes post.

Wednesday, October 9, 2024

Review - HR 9720 Introduced – NVD AI Update

Last month Rep Ross (D,NC) introduced HR 9720, the AI Incident Reporting and Security Enhancement Act. The bill would require the National Institute of Standards and Technology (NIST) to update the National Vulnerability Database (NVD) definitions and process to encourage voluntary disclosures of artificial intelligence safety and security incidents. NIST would also be required to track AI vulnerability reporting. No new funding is authorized by this legislation.

Moving Forward

Ross and one of her two cosponsors, Rep Obernolte (R,CA), are both members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. With the emphasis in the language on voluntary participation, I see nothing in the bill that would engender organized opposition to this legislation. I suspect that there will be some level of bipartisan support for HR 9720, whether it will be enough to allow the bill to be considered in the full House under the suspension of the rules process remains to be seen.

 

For more information about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9720-introduced - subscription required.

Tuesday, October 8, 2024

Review – HR 9466 Introduced – AI Standards

Last month, Rep Baird (R,IN) introduced HR 9466, the AI Development Practices Act of 2024. The bill would amend 15 USC 278h-1, Standards for artificial intelligence. It would require the National Institute of Standards and Technology (NIST) to develop “voluntary guidance for practices and guidelines relating to the development, release, and assessment of artificial intelligence systems”. No new funding would be authorized by this bill.

Moving Forward

Baird, and one of his six cosponsors {Rep Bonamici (D,OR)}, are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. Especially with no new funding authorization, I see nothing in the bill that engender any organized opposition. I suspect that the bill would receive some level of bipartisan report, sufficient bipartisan support, in fact, to see the bill (if reported favorably by the SST Committee) considered by the full House under the suspension of the rules process.

Commentary

My interest in AI, at least as far as this blog is concerned, is the need for cybersecurity protections for what is, at base, a sophisticated, complex, self-correcting, computer program. This is briefly and ineffectively accomplished here by requiring the development of security benchmarks {(h)(1)(B)(iii)} and disclosure of security practices {(h)(1)(B)(vi)} (thus the need for the definition of security of the term “artificial intelligence red teaming”).

As the use of AI systems is being expanded in the area of chemical and biological process development and control, the need for such cybersecurity protections becomes more important. While all software deserves at least some level of such protections, process controls that could be used to cause catastrophic disruptions of facilities and local communities should arguably be required to have some minimal level protection against unauthorized manipulations.

 

For more information on the provisions of this bill, as well as my suggestions for some added cybersecurity related verbiage, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9466-introduced - subscription required.

Friday, October 4, 2024

Review - NIST Publishes RFI for Safety of Chemical/Biological AI Models

Today the DOC’s National Institute of Standards and Technology (NIST) published a request for information notice in the Federal Register (89 FR 80886-80887) for “Safety Considerations for Chemical and/or Biological AI Models”. According to the notice summary: “The U.S. Artificial Intelligence Safety Institute (AISI), housed within the National Institute of Standards and Technology (NIST) at the Department of Commerce, is seeking information and insights from stakeholders on current and future practices and methodologies for the responsible development and use of chemical and biological (chem-bio) AI models.”

Public Comments

NIST is soliciting public comments on these proposed questions. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # 240920-0247). Comments should be submitted by December 3rd, 2024. Responses may inform AISI's overall approach to biosecurity evaluations and mitigations.

For more information on this request for information, including a list of the topics being addressed, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-rfi-for-safety-of  - subscription required.


Thursday, February 15, 2024

Review – 16 Advisories and 1 Update Published – 2-15-24

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Rockwell Automation and Siemens (15). They also updated an advisory for products from Mitsubishi.

CISA addressed each of the 15 advisories that Siemens published on Tuesday. As per their policy from last year, they did not publish updates for the eight Siemens updates from Tuesday. Nor did they address the three Schneider advisories and 1 update published that day. I will cover all of those this weekend.

Advisories

Rockwell Advisory - This advisory describes an incorrect execution-assigned permissions vulnerability in the Rockwell FactoryTalk Service Platform.

SINEC Advisory - This advisory discusses 62 vulnerabilities in the Siemens SINEC NMS product.

Polarian Advisory - This advisory describes two vulnerabilities in the Siemens Polarion ALM product.

Parasolid Advisory - This advisory describes two vulnerabilities in the Siemens Parasolid products. The vulnerabilities were self-reported.

SIMATIC Advisory #1 - This advisory describes two NULL pointer dereference vulnerabilities in the Siemens SIMATIC and OpenPCS products.

SIMATIC Advisory #2 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens Location Intelligence products.

SIMATIC Advisory #3 - This advisory discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in the Siemens SIMATIC RTLS Gateway products.

SCALANCE Advisory #1 - This advisory discusses 160 vulnerabilities in the Siemens SCALANCE XCM-/XRM-300 products.

SCALANCE Advisor #2 - This advisory describes eight vulnerabilities in the Siemens SCALANCE SC-600 family of products.

SCALANCE Advisory #3 - This advisory discusses fourteen vulnerabilities in the Siemens SCALANCE W1750D products.

Simcenter Advisory - This advisory describes six vulnerabilities in the Siemens Simcenter Femap product.

RUGGEDCOM Advisory - This advisory discusses a missing authentication for critical function vulnerability in the Siemens RUGGEDCOM APE1808.

Tecnomatix Advisory - This advisory describes ten vulnerabilities in the Siemens Tecnomatix Plant Simulation product.

Unicam Advisory - This advisory describes an incorrect use of privileged API’s vulnerability in the Siemens Unicam FX product.

Location Analysis Advisor - This advisory describes a use of hard-coded credentials in the Siemens Location Intelligence products.

CP-343-1 Advisory - This advisory describes an improper verification of a source of a communication channel vulnerability in the Siemens SIMATIC/SIPLUS Net CP 343 product lines.

SIDIS Advisory - This advisory discusses five vulnerabilities in the Siemens SIDIS Prime product.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on November 2nd, 2023.

 

For more details about these advisories, including links to 3rd party advisories, researcher reports and exploits, as well as a brief look at a new notice on the NIST.NVD pages, see my article at CFSN Detailed analysis - https://patrickcoyle.substack.com/p/16-advisories-and-1-update-published-b6c - subscription required.

Thursday, August 24, 2023

Review - NIST Publishes Update from IoT Federal Working Group – 8-24-23

Today, DOC’s National Institute of Science and Technology (NIST) published a notice in the Federal Register (88 FR 57937-57938) on “A Preliminary Update From the Internet of Things Federal Working Group”. The Preliminary Update is available on the NIST website. A final report to Congress is expected to be submitted in June 2024.

Public Comments

NIST is soliciting public comments on the Preliminary Update. Comments should be emailed to NIST (iotfwg@nist.gov). Comments should be submitted by September 25th, 2023.

Commentary

A decent, non-technical summary of the work to date, which is mainly just a definition of the problem space. I hope the working group fleshes this document out before preparing their report to Congress, soliciting additional public input.

 

For more details about the Working Group and it Preliminary Update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-update-from-iot-federal - subscription required.

Thursday, August 10, 2023

NIST Sends Improper CHIPS Use Final Rule to OMB

On Tuesday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final from the National Institute of Science and Technology (NIST) on “Preventing the Improper Use of CHIPS Act Funding”. The notice of proposed rulemaking (NPRM) for this rulemaking was published on March 23rd, 2023.

According to the Spring 2023 Unified Agenda entry for this rulemaking:

“The CHIPS Act established an incentives program to sustain and reestablish U.S. leadership across the semiconductor supply chain. To ensure that funding provided through this program does not directly or indirectly benefit foreign countries of concern, the Act includes certain limitations on funding recipients, such as restricting engagement in any significant transaction involving the material expansion of semiconductor manufacturing capacity in foreign countries of concern and prohibiting certain joint research or technology licensing efforts with foreign entities of concern. The Department of Commerce is issuing, and requesting public comments on, a proposed rule to set forth terms related to these limitations and procedures for funding recipients to notify the Secretary of any planned significant transactions that may be prohibited.”

Tuesday, March 14, 2023

OMB Approves CHIPS Funding Limitation NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approve a notice of proposed rulemaking (NPRM) from the  DOC’s National Institute for Science and Technology on “Preventing the Improper Use of CHIPS Act Funding”. This rulemaking was not listed in the Fall 2022 Unified Agenda, so an official description of the purpose and scope of the rulemaking is not publicly available. This NPRM could be published later this week.

Wednesday, February 1, 2023

NIST Sends CHIPS Act NPRM to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the DOC’s National Institute of Standards and Technology for “Preventing the Improper Use of CHIPS Act Funding”. This rulemaking was not listed in the Fall 2022 Unified Agenda, so it is hard to determine what will actually be included in this rulemaking.

NOTE: OIRA has been having problems with their Reginfo.gov web site for the last couple of weeks. The display of new rulemakings is frequently ‘hidden’ behind the footer of the web page. Probably some simple HTML coding issue, but it indicates that the web site manager is not reviewing the actual display of the page when updating the page.

Friday, February 25, 2022

Review - HR 4609 Reported in House – NIST Reauthorization

Last week, the House Science, Space, and Technology Committee published their report on HR 4609, the National Institute of Standards and Technology for the Future Act of 2021. The Committee met on July 27th, 2021 and adopted substitute language along with 14 other amendments to the bill. The reported language includes eight new sections and many language changes, including some changes to the cybersecurity requirements.

New Sections

The following new sections were added to the bill:

§214. Facilitating development and distribution of forensic science standards.

§215. Sustainable Chemistry Research and Education.

§307. Standard technical update.

§308. GAO study of NIST research security policies and protocols.

§309. Premise plumbing research.

§401. Establishment of expansion awards pilot program as a part of the Hollings Manufacturing Extension Partnership.

§402. Update to manufacturing extension partnership.

§403. National supply chain database

Moving Forward

With the publication of the Committee Report, the bill is now cleared for consideration by the full House. The bill, along with all of the amendments, was adopted by voice vote. This indicates strong bipartisan support for the bill. I suspect that the bill will come before the House next month. It will likely be considered under the House suspension of the rules process. This limits debates, prohibit floor amendments, and would require a supermajority for passage. The bill will pass in the House.

 

For more details about the cybersecurity related changes to the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4609-reported-in-house - subscription required.

Saturday, February 19, 2022

Review - NIST RFI to Support CSF – Supply Chain Security Integration

This Monday DOC’s National Institute of Science and Technology (NIST) is publishing (available on line today) in the Federal Register (87 FR 9579-9581) a request for information on “Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework (CSF) and Cybersecurity Supply Chain Risk Management.” NIST is considering aligning the CSF and the National Initiative for Improving Cybersecurity in Supply Chains (NIICS). In this RFI, NIST is requesting information that will support the identification and prioritization of supply chain-related cybersecurity needs across sectors.

NIST is looking for comments in the following areas:

Use of the Cybersecurity Framework,

Relationship of the CSF to Other Risk Management Resources, and

Cybersecurity Supply Chain Risk Management

Comments Requested

NIST is soliciting comments on this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NIST-2022-0001). Comments should be submitted by April 25th, 2022.

Commentary

The CSF is a corporate level cyber risk management tool rather than a true cybersecurity tool. Its greatest strength has always been that NIST proactively works to keep it current and responsive to current needs. It has relied heavily on the input from the public and outside experts. This RFI continues that tradition.

 

For more details about this RFI, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-rfi-to-support-csf-supply-chain - subscription required.

Thursday, January 13, 2022

Review - NIST Announces Formation of IoTAB

Today, the National Institute of Standards and Technology published a notice in the Federal Register (87 FR 2138-2139) announcing the “Establishment and call for nominations to serve on the Internet  of Things Advisory Board.” The Advisory Board is established under the requirements of §9204(b)(5) of the FY 2021 National Defense Authorization Act (PL 116-283).

Those members would include representatives from:

• Information and communications technology manufacturers, suppliers, service providers, and vendors,

• Subject matter experts representing industrial sectors other than the technology sector that can benefit from the Internet of Things, including the transportation, energy, agriculture, and health care sectors,

• Small, medium, and large businesses,

• Think tanks and academia,

• Nonprofit organizations and consumer groups,

• Security experts, and

• Rural stakeholders.

The IoTAB will consist of 16 members appointed by the Secretary with the Chair be selected from that number by the Secretary. According to the Notice, Board Members will serve a two-year term unless the Board terminates earlier. Board Members will not be paid, though travel and per diem may be provided.

The Board will meet at least twice a year in a virtual format. Those meetings will be open to the public.

NIST is soliciting nominations for the initial 16 positions on the Board and will be accepting 2nd party nominations and self-nominations. Nominations, including resume, may be sent to Alicia Chambers, the Committee Liaison Officer by email (alicia.chambers@nist.gov). Nominations should be submitted by February 25th, 2022.

For more details about the IoTAB and the background for the groups formation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-announces-formation-of-iotab - subscription required.

Tuesday, September 28, 2021

Review - HR 5376 Introduced – Build Back Better

Yesterday, Rep Yarmuth (D,KY) introduced HR 5376, the latest reconciliation bill (popularly known as the Build Back Better bill). This is the long-awaited Democrat program spending bill that will not be subject to cloture requirements if/when it makes it to the Senate. The 2,468 page bill contains four sections with substantial cybersecurity spending and program requirements and three sections with cybersecurity mentions in passing. There are no chemical security or safety mentions in the bill. And beyond some fee establishment or increase provisons there are no pipeline safety or security mentions either.

The four sections with substantial cybersecurity provisions are:

§31102. Establishment of next generation 9–1–1 cybersecurity center (pg. 732).

§50001. Cybersecurity and infrastructure security agency (pg. 896).

§90009. National aeronautics and space administration oversight and cybersecurity (pg. 1067).

§90010. National Institute of Standards and Technology research (pg. 1068).

The House Rules Committee, as of this writing, has not set a meeting for establishing the rule for the consideration of HR 5376 on the floor of the House. It would seem that the House leadership is still working with members, the Senate and the White House to come up with a final version of this bill that will be able to pass in both the House and Senate.

While this bill is a priority for both President Biden and the Congressional Democratic leadership, Speaker Pelosi (D,CA) is unlikely to bring this bill to the House floor for a vote unless she is sure that the votes are available to pass it in the House, and is reasonably certain that there is support of the full Democratic Caucus in the Senate to pass the bill there.

Additionally, it is likely that the Rules Committee will be adding the debt limit extension to this bill, now that the Republicans in the Senate effectively killed HR 5305 yesterday in a party-line vote on the first cloture vote.

For more details on the cybersecurity provisions, including the cybersecurity mentions in passing, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-5376-introduced - subscription required.

Sunday, September 26, 2021

Review - Cybersecurity for the Manufacturing Sector – SP 1800-10 (draft)

Earlier this week the National Institute of Standards and Technology (NIST) published a draft of SP 1800-10, Protecting Information and System Integrity in Industrial Control System Environments. The new document provides a practical example solution to help manufacturers protect their Industrial Control Systems (ICS) from data integrity attacks. NIST is soliciting comments on this new document.

NIST is soliciting comments on the Draft of SP 1800-10. Comments should be submitted via email (manufacturing_nccoe@nist.gov) or by filling out the web form. Comments should be submitted by November 7th, 2021.

Commentary

This document provides an important look at how cybersecurity can be successfully engineered into an industrial control system. How useful that example will be for actual manufacturing systems remains to be seen. Looking at this document, it would appear that a high-level of IT knowledge will be required to implement the solutions reported in the document. Whether that level of support is readily available in small manufacturing of chemical facilities remains to be seen.

What is not clear from this document is how much work is needed to implement these tools. A description of the time needed to set up the equipment for these relatively simple control systems would be helpful, but I am not sure how well that would scale to real world control systems with hundreds of control devices and sensors. It is also not clear how much response action would be required by facilities to address the error messages and log files generated by such a system. Is a security operation center necessary or will facilities have to rely on already overstressed operators to deal with these results?

For understandable reasons, these test beds to not address process safety issues that must be taken into account when assessing security risks at a facility; even the Tennessee Eastman simulation fails to address this represents a generic chemical process without considering chemical hazards. I do wish, however, that there had been some discussion about the role process safety has in any process control system risk evaluation.

One final comment. I was really pleased to see that all of the test evaluations showed that the tested systems prevented the design criteria attacks. It shows that cybersecurity controls in a control system environment are possible. I would be surprised, however, to hear that they all did so on the first attempt. It would be helpful if initial testing-failure descriptions and a discussion of remedial actions taken were presented. It would also be helpful if NCCOE were to report on a well-funded red-team attack on the platforms tested.

For more details on the document and the systems evaluated, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cybersecurity-for-the-manufacturing  - subscription required.

Wednesday, September 1, 2021

Review - NIST Publishes Cryptographic Module Validation Program Notice

Today the DOC’s National Institute of Standards and Technology (NIST) published a notice in the Federal Register (86 FR48984-48986) for their “National Cybersecurity Center of Excellence (NCCoE) Automation of  the Cryptographic Module Validation Program (CMVP)”. NIST is inviting organizations to provide letters of interest describing products and technical expertise to support and demonstrate security platforms for the CMVP project.

NIST is soliciting letters of interest from entities wishing to enter into a Cooperative Research and Development Agreement (CRADA) to provide products and technical expertise to support and demonstrate security platforms for the Automation of the Cryptographic Module Validation Program (CMVP) project. The process of submitting letters of interest is outlined here. NIST will close the acceptance of letters of interest when sufficient replies have been received. A notice of that closure will be posted on the project website.

Collaborative activities will commence as soon as enough completed and signed letters of interest have been returned to address all the necessary components and capabilities, but no earlier than October 1, 2021.

For more details about the CMVP and what NIST is looking for in this solicitation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-cryptographic-module   - subscription required 

Thursday, March 26, 2020

NIST Publishes NCCoE Notice on Validating the Integrity of Computing Devices


Today the National Institute of Standards and Technology published a notice in the Federal Register (85 FR 17043-17045) on “National Cybersecurity Center of Excellence (NCCoE) Validating the Integrity of Computing Devices Building Block”. NIST is inviting organizations to provide products and technical expertise to support and demonstrate security platforms for the Validating the Integrity of Computing Devices project.

According to the Notice: “The objective of this project is to produce example implementations to demonstrate how organizations can verify that the internal components of their purchased computing devices are genuine and have not been altered during the manufacturing and distribution process.” The components that NCCoE intends to look at in this block include:

• Computing devices, including laptops, servers, and mobile devices
• Configuration management software
○ vulnerability scanning
○ detection
○ patch management
○ version control
○ synchronization
○ firmware
• Asset inventory software
○ asset management
○ asset discovery
• Security information and event management (SIEM)
○ event detection
○ log management
○ exfiltration activity
○ unauthorized activity
○ anomalous activity
• Certificate authority

Organizations wishing to participate will have to submit a letter of intent describing how their products address one or more of the following desired solution characteristics:

• Use verifiable and authentic artifacts that manufacturers produce during the manufacturing and integration process.
• Detect malicious component swaps of the computing device.
• Manage the automation process when accepting the delivery of a computing device and throughout the operational lifecycle of the device.
• Inspect computing devices to verify that the components in a delivered (or in-use) system computing device match the attributes and measurements declared by the manufacturer.

A copy of a letter of intent template may contact Nakia Grayson via email to supplychain-nccoe@nist.gov.

Commentary


While this is primarily an IT related project at this point, it seems clear to me that control system components potentially have the same vulnerability to post design/manufacture modification that could compromise the security of the system in which the compromised component resides. This will be an interesting project to participate in and/or watch.

Wednesday, September 26, 2018

Bills Passed Under Suspension of Rules in House – 09-25-18


Yesterday as part of their consideration of bills under suspension of the rules, the House passed two bill that I have been covering here; HR 6620, the Protecting Critical Infrastructure Against Drones and Emerging Threats Act and HR 6229, the National Institute of Standards and Technology Reauthorization Act of 2018. Both bills passed by voice vote.

As is typical for bills considered under this procedure there was limited debate on each bill (10 minutes on HR 6620 and 17 minutes on HR 6229). Nary a word was said in opposition.

Monday, June 25, 2018

Committee Hearings – Week of 06-24-18


With both the House and Senate in session this week it looks to be a busy week for Committee work. We are still seeing spending bills being marked-up and we have three cybersecurity related authorization bills. There will also be a Senate mark-up of the TWIC Reader Delay bill in that body.

Spending Bills

Monday – House Rules Committee – HR 6157 DOD;
Tuesday – House Rules Committee – HR 6157 DOD;
Tuesday – House Committee – LHHS;
Tuesday – Senate Sub-Committee – DOD;
Tuesday – Senate Sub-Committee – LHHS;
Thursday – Senate Committee – DOD;
Thursday – Senate Committee – LHHS

The Senate will finish work on HR 5895, the FY 2019 EWR spending bill Monday evening. The House will take up HR 6157, the FY 2019 DOD spending bill, either late Tuesday or on Wednesday.

Cybersecurity Authorization Bills


The three authorization bills with a cybersecurity nexus are for the National Telecommunications and Information Administration (NTIA), the National Institute of Science and Technology (NIST) and the intelligence community.

On Tuesday the Communications and Technology Subcommittee of the House Energy and Commerce Committee will hold a hearing on their draft of an authorization bill for NTIA. The witness list includes:

• Michael D. Gallagher, Entertainment Software Association;
• John Kneuer, JKC Consulting; and
Joanne S. Hovis, CTC Technology and Energy

The draft bill includes two ‘Sense of Congress’ sections on cybersecurity threats and supply chain vulnerabilities, and on preservation of domain name system and WHOIS service.
On Wednesday the House Science, Space, and Technology Committee will hold a mark-up hearing for three as of yet unintroduced bills. One of those is the draft of the NIST authorization bill. The draft includes a section on general cybersecurity and a separate section on IoT with cybersecurity language included.

On Thursday the House Intelligence Committee will hold the inevitably closed-hearing on their mark-up of the as of yet unpublished FY 2019 Intelligence Authorization Act. The draft is not publicly available and, of course, the good stuff will be in the classified annex to the bill.

TWIC Reader Rule


On Wednesday the Senate Commerce, Science, and Transportation Committee will hold a mark-up hearing on eight bills, including S 3094. The text of that bill has not yet been published by the GAO, but it sounds like it should be a companion bill to HR 5729, the Transportation Worker Identification Credential Accountability Act of 2018. After having reviewed the Coast Guard NPRM on their proposed selective delay of the implementation of the TWIC Reader Rule, it seems unlikely that the two legislative delay attempts and the CG delay are very closely related to the same issues.

On the Floor


In addition to the two spending bills on the floor this week, we will also see the House take up two bills of potential interest to readers of this blog. Later today the House will consider HR 5081, the Surface Transportation Security and Technology Accountability Act of 2018, and HR 5733, the DHS Industrial Control Systems Capabilities Enhancement Act of 2018. Both bills will be taken up under the suspension of the rules provisions. This means limited debate and no floor amendments. It also means that the leadership expects serious bipartisan support for both bills since a super-majority is required for passage.

The House is also scheduled to take up a motion to go to conference on HR 5515, the FY 2019 DOD authorization bill, that passed in the Senate last week.

Sunday, April 15, 2018

NIST Announces CSF 1.1 Webinar


Earlier this week the National Institute for Science and Technology (NIST) announced a webinar providing an overview of the Cybersecurity Framework (CSF) version 1.1. The webinar will be held April 27th, 2018 at 1:00 pm EDT.

The webcast page describes the webinar as:

“This webcast will provide the audience with a brief history of how the Framework was developed, supply an understanding of basic components of the Framework (Core, Implementation Tiers, and Profiles), demonstrate how the Framework can be used by organizations, highlight the latest features added in version 1.1, and introduce the Framework Roadmap and Industry Resources.  The audience will have an opportunity to ask questions during a Q&A session at the end of the presentation.”

NIST will be using #CyberFramework for its live TWITTER® chat during the webinar.

Register early.

 
/* Use this with templates/template-twocol.html */