Showing posts with label Port Cybersecurity. Show all posts
Showing posts with label Port Cybersecurity. Show all posts

Friday, November 17, 2017

S 2083 Introduced – Port Cybersecurity

Earlier this month Sen. Harris (D,CA) introduced S 2083, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. This bill is essentially identical to the version of HR 3101 that was passed in the House last month.

While Harris is not a member of the Senate Commerce, Science, and Transportation Committee (the committee to which this bill was assigned for consideration), her co-sponsor, Sen Sullivan (R,AK) is. This means that there is a chance that the Committee could take up the bill.

It is unusual for companion legislation to be introduced this late in the process. It probably means that Harris does not think that there is a reasonable chance that the Senate will take up HR 3101, even though there was bipartisan support for that bill in the House. That is not unusual, the House passes a lot of bills that are never taken up by the Senate; the Senate is slower to pass legislation.

If this bill is marked up by the Commerce Committee there will be a better chance that it will be taken up by the whole Senate. Unless there are significant amendments made to the bill, there is a good chance that the House would accept the Senate version of the bill and not require it to go to conference.


It is unlikely that this bill will receive any consideration this year.

Wednesday, November 8, 2017

Bills Introduced – 11-07-17

Yesterday with both the House and Senate in session, there were 49 bills introduced. Of those, on may be of specific interest to readers of this blog:

S 2083 A bill to enhance cybersecurity information sharing and coordination at ports in the United States, and for other purposes. Sen. Harris, Kamala D. [D-CA]


This bill may (possibly?) be a companion bill to HR 3101 that was recently passed in the House. I suspect that it is a re-write of the bill instead of trying to get the Senate Homeland Security and Governmental Affairs Committee trying to take up and amend HR 3101. I’ll know better when the bill is printed.

Wednesday, October 25, 2017

HR 3101 Passed in House – Port Cybersecurity

Yesterday the House passed HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017, by a voice vote.

As I noted in an earlier post the version of the bill approved yesterday is not the same version that was reported by the House Homeland Security Committee. The amended text is available in the Congressional Record. The change is inconsequential; a reformatting of the list of organizations to be included in the information sharing recommendations in §2(5).

This bill had wide bipartisan support in the House and will likely have the same in the Senate if it reaches the floor for consideration, not a necessarily guaranteed action. I do suspect that the bill will eventually be considered under the Senate’s unanimous consent provisions with no debate, no vote, and few Senators on the floor of the Senate. Nothing untoward in this, it is just the way that the Senate expeditiously handles non-controversial legislation. A single objection from the floor would prevent the action going forward, so the leadership is careful about how the process is used.


As I have noted in previous discussions, this bill continues to use the IT-limited cybersecurity definitions of 6 USC 148. This means that the provisions of this bill do not specifically include control system cybersecurity in the vulnerability assessment and security plan provisions the added cybersecurity requirements for 46 USC §70102 and §70103. This is a serious deficiency in the bill, and it will not be corrected as no further amendment processes are likely to be included in the future consideration of the bill.

Monday, October 23, 2017

HR 3101 Reported in House – Port Cybersecurity

Last week the House Homeland Security Committee published their report on HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. The same day, the House Transportation and Infrastructure Committee was discharged from further consideration of the bill.

HR 3101 was ordered reported without amendment when it was considered by the Committee on 9-7-17. This typically means that there is little to be gained by reviewing the report. But, with Transportation and Infrastructure Committee being discharged from consideration, it is important to look at the included letter (pgs 15) from the Chair of that Committee {Rep. Shuster (R,PA)} to see if there were any conditions imposed when he acquiesced in allowing the bill to move forward.

Sure enough, there were two conditions, both agreed to by Chairman McCaul (R,TX). The second, is the standard requirement that the Transportation and Infrastructure Committee be represented in any conference (if required) on the bill. The first is:

“Further, this is conditional on our understanding that mutually agreed upon changes to the legislation will be incorporated into the bill prior to floor consideration.”

There are no changes in the reported version of HR 3101, as I would expect given the fact that no amendments were adopted by the Committee. We will not be able to see the changes that are being made until today’s Congressional Record is published tomorrow (remember, the bill is being considered on the floor today). Interestingly, neither will any of the members of Congress that will be voting on the bill. Such is the power of committee chairs.


I do not expect that the changes will be major and I do not really look for them to make changes to affect the IT-centric nature of this bill.

Thursday, September 7, 2017

HR 3101 Passes in Committee – Port Cybersecurity

This morning the House Homeland Security Committee adopted HR 3101, a bill that would establish a number of modest cybersecurity requirements for (and in support of) port operations. No amendments were offered and the bill was adopted in a voice vote; signifying significant bipartisan support.

As I mentioned in my earlier post, this bill relies on the IT-centric definition of cyber risk that would exclude control systems from the modest requirements established by this bill.


The bill will probably be taken up in the House at some future (probably not near future) date under the suspension of the rules provisions. No floor amendments would be allowed under those circumstances and a supermajority would be required for passage. If the bill makes it to the floor of the Senate, it would almost certainly pass.

Tuesday, July 18, 2017

HR 3101 Introduced – Port Cybersecurity

Last month Rep. Torres (D,CA) introduced HR 3101, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017. The bill establishes a number of modest cybersecurity requirements for (and in support of) port operations.

Federal Requirements


Section 2 of the bill establishes federal requirements for cybersecurity risk assessments, information sharing and coordination. First it requires DHS to conduct (and subsequently evaluate) a risk assessment for maritime cybersecurity based upon the NIST Cybersecurity Framework. Next, it requires DHS to ensure that at least one maritime information sharing analysis committee (ISAC) participates in the National Cybersecurity and Communications Integration Center.

Paragraph (4) requires DHS to establish “guidelines for voluntary reporting of maritime-related cybersecurity risks and incidents (as such terms are defined in section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)) to the Center [NCCIC]”. The next paragraph then requires DHS to “to report [on] and make recommendations to the Secretary on enhancing the sharing of information related to cybersecurity risks and incidents between relevant Federal agencies and State, local, and tribal governments”.

Local Requirements


Section 3 of the bill establishes local cybersecurity requirements. First it requires each Maritime Security Advisory Committee “to facilitate the sharing of cybersecurity risks and incidents to address port-specific cybersecurity risks, which may include the establishment of a working group of members of Area Maritime Security Advisory Committees to address port-specific cybersecurity vulnerabilities” {§2(1)}. Next it requires all new maritime or facility security plan (under 46 USC 70103) to “include a mitigation plan to prevent, manage, and respond to cybersecurity risks” {§2(2)}.

Specifically §4 amends two separate provision of 46 USC {§70102(b)(1)(C) – facility and vessel assessments – and §70103(c)(3)(C) – vessel and facility security plans} by adding the word “cybersecurity” after “physical security”. It would also add a requirement for vessel and facility security plans to address the “prevention, management, and response to cybersecurity risks” {new §70103(c)(3)(C)(v)}.

Moving Forward


While Torres is not a member of either committee to which the bill has been assigned for consideration, two of her cosponsors are {Rep. Correa (D,CA) – Homeland Security; and Rep. Wilson (D,FL) – Transportation and Infrastructure}. This means that there is at least a chance that either or both of these committees could consider HR 3101.

I do not see anything in the bill that would engender any significant opposition. If the bill were to be considered on the floor of the House it is likely that it would pass, probably under the suspension of the rules provision.

Commentary


Once again, the provisions of this bill rely on the 6 USC 148(a)(1) definition of ‘cybersecurity risk’, a definition that is limited to information systems and does not include control systems. This would mean that the requirements of this bill would not apply to operation of any of the many critical control systems found on vessels or in maritime facilities.


I would again like to point to a solution to this definitional problem in port cybersecurity legislation that I proposed in an earlier blog post. It would still use the existing, IT-centric, definition of ‘information system’, but would add a new definition for ‘control system’ and then combine both terms in the definition of ‘cybersecurity risk’.

Thursday, June 29, 2017

Bills Introduced – 6-28-17

Yesterday with both the House and Senate in session there were 48 bills introduced. Of those only one may be of specific interest to readers of this blog:

HR 3101 To enhance cybersecurity information sharing and coordination at ports in the United States, and for other purposes. Rep. Torres, Norma J. [D-CA-35]

It will be interesting to see if the bill includes control system cybersecurity provisions.

Thursday, May 4, 2017

House Passes HR 244 – FY 2017 Spending

After a nearly party-line vote on the resolution adopting the rule for consideration of  HR 244, the House passed the Consolidated Appropriations Act, 2017 by a bipartisan vote of 309 to 118 (with 103 Republicans voting Nay). The Democratic opposition to the rule vote was an attempt to open consideration of HR 244 to the amendment process on the floor of the House.

Cybersecurity


The rule for consideration of HR 244 also added a new division to HR 244. The new Division N is the Intelligence Authorization Act for Fiscal Year 2017. As I have mentioned on a couple of occasions the House has passed various versions of this bill in both the 114th and 115th Congress, but the Senate has not taken up any version of this bill.

The version now included in HR 244 does not include any specific cybersecurity provisions beyond a reporting requirement; Sec. 614. Report on cybersecurity threats to seaports of the United States and maritime shipping. I have previously discussed this provision on a couple of occasions, the most recently here.

Moving Forward



The Senate is scheduled to debate HR 244 today and vote on cloture on Friday morning. The current plan for consideration in the Senate does not include a floor amendment process.

Wednesday, November 30, 2016

HR 6393 Introduced – FY 2017 Intel Authorization

Last week Rep. Nunes (R,CA) introduced HR 6393, the Intelligence Authorization Act for Fiscal Year 2017. This bill is apparently a replacement for both HR 5077 (which passed in the House in a strongly bipartisan vote) and S 3017. Both of those bills have stalled in the Senate. I suspect that Nunes and his Committee staff have coordinated with their Senate counterparts to remove/revise any provisions from the earlier bill that have held up consideration.

The cybersecurity intelligence report on US port operations requirement from HR 5077 remains in the new bill. Interestingly Dr. Andy Ozment, the Assistant Secretary for Cybersecurity and Communications at the Department of Homeland Security (DHS), published an opinion piece on CSOOnline.com Monday that describes the ICS-CERT response to a cyberattack on a US port control system earlier this year. Other than failing to note that there are only 13 of the vulnerable systems in use worldwide, the article does describe the ICS-CERT process fairly concisely.


HR 6393 is scheduled to be considered on the floor of the House today under the suspension of rules provisions. This provides for limited debate and no amendments from the floor. This bill should pass with strong bipartisan support. I suspect that the Senate will take up the bill under their unanimous consent procedures before the end of the lame duck session.

Wednesday, May 4, 2016

HR 5077 Introduced – FY 2017 Intel Authorization Bill

Last week Rep. Nunes (R,CA) introduced HR 5077, the Intelligence Authorization Act for Fiscal Year 2017. Analysis of this bill is complicated because significant portions (How much? Don’t know.) are classified for fairly obvious reasons. The unclassified portion available to the public does include one cybersecurity provision; a requirement for a port cybersecurity report.

Port Cybersecurity Report


Section 604 requires the Under Secretary of Homeland Security for Intelligence and Analysis to submit a report on port cybersecurity to the congressional intelligence committees. The report will cover the “cybersecurity threats to, and the cyber vulnerabilities within, the software, communications networks, computer networks, or other systems employed by” {§604(a)}:

• Organizations conducting significant operations at seaports in the United States;
• Maritime shipping concerns of the United States; and
• Organizations conducting significant operations at transshipment points in the United States.

The report will include:

• A description of any recent and significant cyberattacks or cybersecurity threats directed against software, communications networks, computer networks, or other systems employed by the port entities described above; and
• An update on the status of the efforts of the Coast Guard to include cybersecurity concerns in the National Response Framework, Emergency Support Functions, or both, relating to the shipping or ports of the United States.

The report will also include an intelligence assessment of:

• Any planned cyberattacks directed against such software, networks, and systems;
• Any significant vulnerabilities to such software, networks, and systems; and
• How such entities and concerns are mitigating such vulnerabilities.

Moving Forward


Nunes is the Chair of the House Intelligence Committee and this is one of those ‘must pass’ authorization bills. The battles have been fought behind closed doors on this bill and will not see the light of day. This bill will be considered on the floor of the House, probably with limited debate and amendments. That is limited in the terms of time; we know that it will be limited to unclassified information.

The Senate will probably have their own version of the bill that will be passed in that body and then a conference committee will work out the differences between the two bills.

Commentary


The port cybersecurity report required in this report would be significantly different than the one in HR 3878 that was passed in the House last December. This is much more of an intelligence report than a security systems report that was described in the earlier bill. The bill does not state this (an understandable oversight from the Intel Committee staff) but the report will certainly be classified and probably will not be shared further than with the Coast Guard’s Captains of the Port.


It would have been nice to see a requirement for an unclassified version of the report so that more sharing could be done with the information, but you never get much unclassified information from the intel community. It just goes too much against the grain.

Wednesday, December 16, 2015

House Passes HR 3878 – Port Cybersecurity

This afternoon the House passed HR 3878, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2015. There was only 17 minutes of debate under suspension of the rules and it was passed by voice vote.

As I mentioned in an earlier blog post amendments were made to this bill in Committee to make changes to 46 USC 70101 and 70103 to add ‘cybersecurity’ provisions to MTSA requirements for vulnerability assessments and security plans for facilities and vessels. This will be the first official mention of cybersecurity in the MTSA programs.


The bill is still missing any specific requirement for covered facilities or vessels to report cybersecurity incidents to the Coast Guard. There is very little chance that such reporting requirements will be made in the Senate since this bill will probably move directly to the Senate floor under the unanimous consent process.

Thursday, November 5, 2015

Homeland Security Bills Marked Up

Yesterday the House Homeland Security Committee held a markup hearing at which seven bills were approved (some after amendment) by voice votes. Only two of those bills (HR 3875 and HR 3878) may be of specific interest to readers of this blog.

HR 3875 – CBRNE Office

Rep. McCaul (R,TX) offered an amendment in the form of a substitute for this bill. It removed some of the language that I mentioned in my earlier post that made it seem that this bill was primarily a biosecurity bill. It also added new language to the proposed Title XXII of the Homeland Security Act of 2002 that created four Divisions within the proposed CBRNE Office; the Chemical Division, the Biological Division, the Nuclear Division and the Explosive Division.

The revised language still does not include the chemical security folks from the DHS Infrastructure Security Compliance Division (ISCD), but it did add specific language providing for a continuation of the Chemical Defense Program (that I first mentioned here) under the Chemical Division.

An amendment to the revised language was offered by Rep. Thompson (D,MS). It made a number of word changes to clarify certain issues, but there were no modifications to the intent of the bill.

Both amendments were agreed to by voice votes.

HR 3878 – Port Cybersecurity

Rep. Torres (D,CA) offered substitute language for the bill which was essentially a complete re-write of the original language, if not the general intention, of the bill. A new §2 of the bill would require the development and implementation of “a maritime cybersecurity risk assessment model” {§2(1)}. Additionally the section would also require the establishment of guidelines “for voluntary reporting of maritime-related cybersecurity risks and incidents” {§2(4)}.

The new language also removes all specific mention of the Maritime Information Sharing and Analysis Center; substituting more generic language (“at least one information sharing and analysis organization” representing the maritime community). The other information sharing provisions have had minor wording changes.

An amendment to the revised language was offered by Rep. Donovan (R,NY). It would add an additional section to the bill that would amend portions of 46 USC regarding maritime security plans under the Maritime Transportation Security Act. First it would modify §70101(b)(1)(C) to add ‘cybersecurity’ as one of the areas of weakness to be evaluated in facility and vessel vulnerability assessments. Second it would modify §70103(c)(3)(C) to add ‘cybersecurity’ as one of the required provisions of a vessel or facility security plan. Area security plans were not addressed by this amendment.

The Torres language on cybersecurity provisions on area and facility site security plans was revised slightly by the Donovan amendment, but it still only applies those requirements to plans approved after the development of the new cybersecurity risk assessment model required by the bill has been completed. Thus existing security plans would not be required to be changed to reflect the cybersecurity requirements until their next five year renewal.

Both amendments were approved.

Moving Forward

Both of these bills appear to be on Chairman McCaul’s fast track for consideration. It is very likely that these will be considered on the floor of the House before the end of the year. Neither bill has any provisions that will spark any serious opposition so they will both probably be considered under suspension of the Rules.

Commentary

The changes to the CBRNE Office bill that were made yesterday make a lot of sense to me. The establishment of the five offices reflecting the different attack vectors seems like it has the potential to centralize the Departments disparate efforts at reducing the probability of a high-consequence CBRNE attack. It would also place CBRNE on a bureaucratic par with Cybersecurity within the Department.

I still would have preferred to see ISCD added to the Chemical Defense Office, but I suspect that if the Senate does not make that move (a low probability event, I doubt that any amendments will be made to the bill as it will probably be considered under unanimous consent provisions at the end of a daily session) I suspect that this would be one of the changes that would be recommended by the Secretary in his initial report to Congress required by the bill.

The revised language on the port cybersecurity bill are also a substantial step forward. Even before the Donovan amendment the changes that were made bring the language within the current information sharing meme that is wending its way through conference committee. This internal consistency of language is important from a bureaucratic point of view.

For critical infrastructure like ports I would have preferred to see some mandatory level of cybersecurity reporting. Using the general concepts used in the recent NRC cybersecurity reporting rule, this bill should have mandated reporting of cybersecurity events that had a cyber-physical impact (or at least those that affected the handling of hazardous chemicals) and specifically encouraged reporting cybersecurity events that affected safety security, or emergency response.


I was very happy to see the Donovan amendment make the statutory changes necessary to make the changes to vulnerability assessments and security plans. I am not sure, however, if the failure to include maritime area security plans in those changes was deliberate or an oversight. I suspect that it was deliberate and I would tend to agree that requiring cybersecurity security plan coverage at the vessel and facility level is probably more important than trying to deal with it at the area level.

Tuesday, November 3, 2015

HR 3878 Introduced – Port Cybersecurity

Yesterday Rep. Torres (D,CA) introduced HR 3878, the Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2015. The bill would require DHS to undertake a number of activities to increase the cybersecurity of port operations in the United States.

Information Sharing

The bill contains three separate cybersecurity information sharing provisions targeted at different levels of operations. The first is a directive to the Secretary to “enhance participation by the Maritime Information Sharing and Analysis Center (an independent, nonprofit entity sponsored and managed by the Maritime Security Council [link added]) in the National Cybersecurity and Communications Integration Center” {§2(1)}. The second would require the National Maritime Security Advisory Committee to “report and make recommendations to the Secretary on matters relating to methods to enhance cybersecurity situational awareness and information sharing between and with maritime security stakeholders” {§2(2)}. Finally each Captain of the Port to establish a working group within the local Area Maritime Security Advisory Committee to “facilitate the sharing of information about and development of plans to address port-specific cybersecurity vulnerabilities” {§3}.

Security Plans

Section 4 of the bill would require that all area and facility security plans approved after the enactment of this bill would “address cyber threats and vulnerabilities and include mitigation measures to prevent, manage, and respond to such threats and vulnerabilities”.

Moving Forward

Torres is a junior Democrat on the Border and Maritime Security Subcommittee of the House Homeland Security Committee. Normally this would not be expected to be a position of much influence in the Committee. In any case, the bill is already scheduled for a markup before the full Committee tomorrow, so it is obvious that this bill has the attention of the Committee leadership.

The bill was also assigned to the Transportation and Infrastructure Committee so we will have to wait and see if the two Committee Chairs can work out a way for it to move to the floor of the House.

If the bill does make it to the floor it is unlikely to attract any serious opposition from industry. The bill would probably be considered under suspension of the rules with minimal debate and no amendments.

Commentary

The information sharing provisions of this bill are largely symbolic as there are no specific requirements for private sector facilities to report cybersecurity incidents. Additionally, any intelligence reports produced from such incidents would almost certainly be classified (that is the nature of intelligence agencies) and there are no provisions in the bill to provide classified information access to facility security managers.

I am very pleased that the bill tries to address the need for cybersecurity to be addressed in area security plans and facility security plans under the MTSA. Unfortunately the wording in the bill is weak since it does not actually amend the underlying statute or require a change to the regulations. Amendments should have been made to 46 USC 70103(b) and §70103(c) requiring security plans to address cybersecurity issues. That way appropriate changes could be made to 33 CFR 103.505 and §105.405.


I was disappointed to see that the cybersecurity provisions for security plans only applied to new security plans. I suspect that the intent was also to include the periodic (every 5 years) revisions of the security plans. Even so this could leave an area or facility without cybersecurity coverage for almost five years. Again, if changes had been made to §70103, then a reasonable effective date could have been provided in the regulatory change.

Monday, October 5, 2015

Congressional Hearings – Week of 10-04-15 –

Both the House and Senate will be in session this week. Budget issues have been pushed to the backrooms so we are going to see a variety of issues coming up in hearing rooms this week. Hearing of probable interest to readers of this blog include: drones, NPPD organization, and maritime cybersecurity.

Drones

The Aviation Subcommittee of the House Transportation and Infrastructure Committee will hold a hearing on Wednesday on “Ensuring Aviation Safety in the Era of Unmanned Aircraft Systems”. The witness list includes:

• Michael G. Whitaker, Deputy Administrator, FAA
• James Hubbard, Deputy Chief, United States Forest Service
• Captain Tim Canoll, President, Air Line Pilots Association
• Rich Hanson, Director of Government and Regulatory Affairs, Academy of Model Aeronautics
• Dr. Mykel Kochenderfer, Professor of Aeronautics and Astronautics

NPPD Organization

On Wednesday the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee will hold a hearing on “Examining the Mission, Structure, and Reorganization Effort of the National Protection and Programs Directorate”. The witness list includes:

• Ronald J. Clark, Deputy Under Secretary, NPPD
• Chris P. Currie , US GAO
• Phyllis Schneck, Deputy Under Secretary, Cybersecurity and Communications, NPPD
• Suzannee Spaulding, Under Secretary, Cybersecurity and Communications, NPPD

Looking at the witness list this certainly looks like it will concentrating on the cybersecurity side of NPPD. I doubt, however, that much mention will be made of ICS-CERT.

Maritime Cybersecurity

The Border and Maritime Security Subcommittee of the House Homeland Security Committee will be holding a hearing on “Are Our Nation’s Ports at Risk for A Cyber-Attack?” The witness list includes:

Jeh C. Johnson, Secretary, DHS;
James B. Comey, Jr., Director, FBI;
Nicholas J. Rasmussen, Director, National Counterterrorism Center,

Don’t expect to hear too many actionable details from this hearing. It is going to concentrate of policy and broad threat overviews.

On the Floor

Among the many bills that will be considered in the House on Tuesday under suspension of the rules, there is one bill that might be of specific interest to readers of this blog:

HR 3510 – Department of Homeland Security Cybersecurity Strategy Act of 2015, as amended


This bill was marked up in Committee last week. There was one amendment adopted dealing with privacy issues. HR 3510 is expected to pass with bipartisan support, minimal debate and no floor amendments will be authorized.
 
/* Use this with templates/template-twocol.html */