Showing posts with label PREPARE Act. Show all posts
Showing posts with label PREPARE Act. Show all posts

Tuesday, June 27, 2017

HR 2922 Introduced – PREPARE Act

Earlier this month Rep. Donovan (R,NY) introduced HR 2922, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (Prepare) Act. The bill authorizes and modifies a number of DHS emergency planning, preparation and training programs.

Readers of this blog will probably be most interested in the following sections of the bill:

• §106. Allowable uses.
• §114. Port security grant program.
• §120. Cyber preparedness.
• §302. Medical Countermeasures Program.

Allowable Uses


Section 106 amends 6 USC 609 adding two new uses of funds to a number grant programs for States and high-risk urban areas. The two new uses are {new §609(a)(6) and (7)}:

Enhancing medical preparedness, medical surge capacity, and mass prophylaxis capabilities, including the development and maintenance of an initial pharmaceutical stockpile, including medical kits and diagnostics sufficient to protect first responders, their families, immediate victims, and vulnerable populations from a chemical or biological event;

Enhancing cybersecurity, including preparing for and responding to cybersecurity risks and incidents (as such terms are defined in section 227 [6 USC 148(1) and (3]) and developing statewide cyber threat information analysis and dissemination activities;

Port Security Program


Section 114 authorizes the port security grant program under 46 USC 70107. The section would authorize $200 Million dollars per year for the grants through 2022.

Cyber preparedness


Section 120 amends 6 USC 124h making cybersecurity additions to the support requirements set upon DHS for State, local and regional fusion centers. It requires DHS to provide fusion centers {new §124h(b)(10)}:

“…with expertise on Department resources and operations, including, in coordination with the national cybersecurity and communications integration center [(NCCIC)] under section 227 [6 USC 148], access to timely technical assistance, risk management support, and incident response capabilities with respect to cyber threat indicators, defensive measures, cybersecurity risks, and incidents (as such terms are defined in such section), which may include attribution, mitigation, and remediation, and the provision of information and recommendations on security and resilience, including implications of cybersecurity risks to equipment and technology related to the electoral process;”

It would also require the DHS NCCIC to review cybersecurity information developed by fusion centers, incorporate that information (where appropriate) into NCCIC information shared with fusion centers and other government agencies. It also adds the NCCIC as a potential personnel resource for fusion centers.

Medical Countermeasures Program


Section 302 adds a new §528 to the Homeland Security Act of 2002 that would add a requirement for DHS to {new §528(a)}:

“… establish a medical countermeasures program to facilitate personnel readiness, and protection for the Department’s employees and working animals and individuals in the Department’s care and custody, in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, or pandemic, and to support Department mission continuity.”

Moving Forward


Donovan is the Chair of the Emergency Preparedness, Response, and Communications Subcommittee of the House Homeland Security Committee; one of the three committees to which this bill was referred for consideration. Neither Donovan nor this three cosponsors are members of the other two committees (Transportation and Infrastructure Committee and Energy and Commerce Committee). This bill will certainly be considered in the Homeland Security Committee in the near future.

The bill does not currently have any Democratic cosponsors. This would seem to indicate that there is some opposition to at least some of current provisions (or missing provisions) of the bill. We will have to watch the markup of this bill to see how much bipartisan support there is for the bill. Bipartisan support is not really necessary in the House, but for the bill to make it to the floor of the Senate there cannot be serious Democratic opposition to the bill.

Commentary


The cybersecurity provisions of this bill all refer to 6 USC 148 with its IT-centric definitions of cybersecurity. Again, this would restrict the grant programs and fusion center support provisions limited to information system security, ignoring potential risks to critical infrastructure from attacks on industrial control systems (ICS) or the energy systems in this country.

Fortunately, the bill does include some modifications to definitions in §148, so it could be possible to clear up the multiple areas where we see similar problems with ignoring the ICS cybersecurity threat. The definition of ‘information system’ could be changed from its current reference to 44 USC 3502(8) to 6 USC 1501(9).


The medical countermeasures program is certainly important to providing support to DHS. I am glad to see that it specifically includes language about chemical incidents instead of just biological and radiological incidents; just see my post about the use of Cyanokits in response to an acrylonitrile spill. It would be nice to see some language in this authorization bill requiring the managers of the program to coordinate with local agencies when such countermeasures are not required by the Department, but could provide support to communities.

Tuesday, April 26, 2016

House Passes HR 3583 – The PREPARE Act

This evening the House passed HR 3583, the PREPARE Act. There were only sixteen minutes of debate and a voice vote. The bill reauthorizes and makes minor modifications to a number of emergency response and planning grant programs.

The bill requires a DHS report on the cybersecurity of FirstNet, the nationwide first responder network. It also requires DHS to establish a Social Media Working Group to enhance public communications during emergencies. And it requires the DHS Office of Health Affairs to establish a medical stockpile program for DHS employees.


It is likely that this bill will be taken up by the Senate under their unanimous consent procedures; again with limited debate and no actual vote.

Tuesday, September 29, 2015

HR 3583 Introduced – PREPARE Act

Last week Rep. McSally (R,AZ) introduced HR 3583, the Promoting Resilience and Efficiency in Preparing for Attacks and Responding to Emergencies (PREPARE) Act. The bill reauthorizes and makes minor modifications to a number of emergency response and planning grant programs. Program changes of specific interest to readers of this blog include

• Cybersecurity protections for Public Safety Broadband Network;
• DHS use of social networking; and
• The medical countermeasures program

FirstNet Cybersecurity

Section 206 of the bill requires the DHS National Protection and Programs Directorate Under Secretary to provide Congress with a report on the cybersecurity support that DHS is providing to the Department of Commerce FirstNet program. Specifically the Under Secretary is tasked with the requirement “to identify and address cyber risks that could impact the near term or long term availability and operations of such [public safety broadband] network and recommendations to mitigate such risks”.

Social Networking

Section 207 of the bill would add §318 to the Homeland Security Act of 2002. It provides for the establishment of a DHS Social Media Working Group. Alert readers of this blog will realize that I recently reported that the HR 623, with nearly identical language, has been reported in the Senate.

Medical Countermeasures Program

Section 303 of the bill would add §527 to the Homeland Security Act of 2002. It establishes a medical countermeasures program under the DHS Chief Medical Officer. The program is to be designed to “facilitate personnel readiness, and protection for working animals, employees, and individuals in the Department’s care and custody, in the event of a chemical, biological, radiological, nuclear, or explosives attack, naturally occurring disease outbreak, or pandemic” {new §527(a)}.

Moving Forward

McSally is the Chair of the Emergency Preparedness, Response, and Communications Subcommittee of the House Homeland Security Committee. The Committee Chair, Rep. McCaul, is cosponsor of this bill. So there is certainly the political will and power to move this bill forward.

The Subcommittee marked-up this bill before it was introduced. The full Committee markup is scheduled for Wednesday. I suspect that the bill will be approved by a voice vote without further amendment. If so it will move to the floor of the House before the end of the year; probably to be considered under suspension of the rules with little debate and no floor amendments.

Commentary

The Congress is taking more and more actions like that seen here in specifying that DHS will report on the cybersecurity of FirstNet. These little one section toss offs in a wide variety of legislation are doing more to further the centralization of cybersecurity responsibility in DHS than any single piece of legislation could. I expect that this means that I am going to have to be watching a wider variety of bills to find those mentions that might be of specific interest to the control system security community.

I am not sure why the Social Media Working Group language is once again in legislation that is obviously heading to the floor. It was already passed in the House as a standalone bill. The only thing that makes a modicum of sense is that McSally and McCaul do not expect the Senate to actually take up HR 623 and they really want this group to be formed.

Of concern to me is that this version of the §318 language is also missing any mention of monitoring social media to provide situational awareness to the Department. While the intel folks are trying desperately to monitor the social network communications of IS and AQ supporters, the emergency response folks are, due to excessive concern with avoiding the appearance of spying on the public, being forced to ignore the vital information that could be available in natural disasters and after attacks or manmade disasters. A vitally important requirement for this SMWG should be the development of tools to abstract information from publicly available social networks to support emergency response.

The medical countermeasures program also seems to be an overly limited, if certainly legitimate DHS program. DHS certainly has a responsibility to ensure that medically foreseeable countermeasures to CBRNE attacks are available to keep their troops in the field fully functioning in their emergency response and criminal investigation capacities in the event of such attacks.


With minimal expansion of responsibility, however, the DHS Office of Health Affairs could be developing plans and standards for the deployment of medical countermeasures to the general public. In particular, incidents like the acrylonitrile train wreck this summer point to the need for the centralized stockpiling and subsequent distribution of medical countermeasures for industrial chemical accidents. OHA could have been tasked in this bill with the requirement to identify those industrial chemicals requiring specific medical countermeasures that would not routinely be available to local emergency rooms. In conjunction with such a list they could have been required to submit a plan to Congress on how a regional stockpiling and distribution plan could be put together for such countermeasures.
 
/* Use this with templates/template-twocol.html */