Showing posts with label S 1197. Show all posts
Showing posts with label S 1197. Show all posts

Thursday, November 21, 2013

S 1197 Cloture Vote Fails

The bipartisan spirit that allowed a unanimous vote to start considering the DOD spending bill, S 1197, fell apart this afternoon when an attempt was made to end debate on the endless amendments and start voting on amendments and the bill. The Cloture vote failed 51 – 41 (60 ayes required for passage) along party lines.

While there had been some disagreement on the number of amendments that would be considered, it was the move by Sen. Reid to change the voting rules on the consideration of appointments that sealed the fate on the chance to get this bill to a final Senate vote before the Thanksgiving recess.

In a common parliamentary move, Reid actually voted against the bill. This will allow him to ask for reconsideration of the cloture vote. A successful vote then would allow the Senate to move forward on the voting process. This move is unlikely to be used this week as it is unlikely that the Republicans will be cooled down enough to accept cloture.


Failure to pass this bill before the Thanksgiving break makes it very difficult to get it passed and into conference with the House and then back to the floor for votes before the end of the year. As December advances, more effort will be made to get the consolidated spending bill complete, putting this DOD bill on the back burner. It isn’t yet impossible; it’s just getting more unlikely.

Senate to Close S 1197 Debate Friday

A cloture motion to end debate on S 1197, the National Defense Authorization Act for Fiscal Year 2014, was filed yesterday and there will be a vote on the motion on Friday. This raises the possibility that a final vote on the bill could take place before the Thanksgiving recess.

Amendments

As part of the unanimous consent motion to continue debate today on the bill, a deadline for 1 pm today was established for the filing of first-degree amendments to the bill. Yesterday there were again a large number of amendments offered to S 1197. This time there were a number of cybersecurity related amendments. Four of those were minor wording changes to existing cybersecurity provisions (SA 2352 – SA 2355) offered by Sen. Landrieu (D,LA).


The only other cybersecurity related amendment was offered by Sen. Moran (R,KS) would modify the wording of §945 concerning the use of National Guard personnel in a cybersecurity role. I have not had a chance to review all of the substitute wording but the significant provisions that I described in the original bill are still there.

Tuesday, November 19, 2013

Senate Moves to Debate S 1197, FY 2014 DOD Spending

As I noted in yesterday’s blog post, the Senate voted on the cloture motion to allow the Senate to proceed to the consideration of S 1197, the National Defense Authorization Act for Fiscal Year 2014. The cloture motion passed by a vote of 91 – 0; clearly a bipartisan vote. A large number of amendments were also offered, but none had anything to do with cybersecurity or chemical safety.

As I noted earlier, this bill has a number of cybersecurity provisions that are missing from the House bill, HR 1960, passed in the House back in June.


Actual debate on the bill started today, and there will be additional amendments offered. Debate on this bill is never short. A final vote is not really expected until after Thanksgiving.

Monday, November 18, 2013

Congressional Hearings – Week of 11-17-13

Both the House and Senate will be back in session today. While there are a number of hearings scheduled for this week only three appear to be of specific potential interest to readers of this blog: they include medical software, FirstNet and DHS confirmation hearings. And it looks like the Senate may actually consider the 2014 National Defense Authorization Act, S 1197.

Medical Software

The Health Subcommittee of the House Energy and Commerce Committee will be holding a hearing tomorrow looking at “Federal Regulation of Mobile Medical Apps and Other Health Software” and HR 3303. As I mentioned in my blog post about that bill, there is nothing currently in the bill that would extend FDA regulatory authority to software security issues. There is an outside chance that this will come up during this hearing.

BTW: There is a nice background document on the hearing web site, but no mention of software security issues.

FirstNet

The Communications and Technology Subcommittee of the House Energy and Commerce Committee will hold an oversight hearing on FirstNet and the Advancement of Public Safety Wireless Communications. No witness list is currently available.

DHS Confirmation

The Senate Homeland Security and Governmental Affairs Committee will vote tomorrow on the nomination of Jeh C. Johnson to be the Secretary of DHS. While there has been some controversy about the background of Mr. Johnson, this vote coming so soon after his appearance before the Committee probably means that a favorable vote will be forth coming.

S 1197

According to the Congressional Record, the Senate is scheduled to vote on a cloture motion to allow the Senate to proceed to consideration of S 1197. As I noted earlier this bill has a number of cybersecurity provisions. It’s original consideration was held up by the general disagreement between the Republicans and Democrats on spending issues. I’m not sure what has changed, but it would seem that Sen. Reid (D,NV) thinks that he has enough votes to move this bill forward.

If it passes (and it probably will if the cloture vote succeeds) it will then be tacked onto the House Bill (HR 2397) which probably means another spending conference committee. Many of the same folks will be on that conference as are on the budget conference that is trying to iron out differences between the Senate (read Democrats) and House (Republicans) so that a final 2014 spending bill can be put together.


This move by Reid may signal that there is at least some agreement between the conferees on defense issues.

Sunday, June 30, 2013

S 1197 Introduced – FY 2014 DOD Authorization

As I noted earlier Sen. Levin (D,MI) introduced S 1197, the National Defense Authorization Act for Fiscal Year 2014, and the bill has been reported favorably by the Senate Armed Services Committee. As expected the bill has some significant cybersecurity provisions including support for the development of tools for checking software code vulnerability, looking at the use of National Guard troops for homeland cyber-response tasks and controls on the trade in ‘cyber-weapons’.

Cyberspace Subtitle

Subtitle D of Title IX (DOD Organization and Management) deals with ‘Cyberspace-Related Matters’. Most of the provisions relate to cyber-warfare but some deal with cybersecurity related matters. The eight sections within the Subtitle are:

• Section 941: Authorities, capabilities, and oversight of the United States Cyber Command.
• Section 942: Joint software assurance center for the Department of Defense.
• Section 943: Supervision of the acquisition of cloud computing capabilities for intelligence analysis.
• Section 944: Cyber vulnerabilities of Department of Defense weapon systems and tactical communications systems.
• Section 945: Strategy on use of the reserve components of the Armed Forces to support Department of Defense cyber missions.
• Section 946: Control of the proliferation of cyber weapons.
• Section 947: Integrated policy to deter adversaries in cyberspace.
• Section 948: Centers of Academic Excellence for Information

Probably the most significant of the DOD provisions in this Subtitle can be found in §941. It provides for the separation of the DOD cyber-warfare (offensive and defensive) organizations from the cyber intelligence program and the information security program in DOD. This specifically includes providing separate hardware and internet access capabilities for US Cyber Command (USCC) separate from the National Security Agency. It does not, however, address the current fact that the commander of both the NSA and the USCC are the same person.

Software Assurance Tools

Section 942 requires DOD to establish a Joint Software Assurance Center separate from the one established by the National Security Agency (more separation of USCC from NSA). The new JSAC would work with the NSA agency to establish a “program of research and development to improve automated software code vulnerability analysis and testing tools” {§942(c)(3)}.

The Committee report further emphasizes this the importance of this program in the Committee report (pg 46, Adobe 69) by providing an additional $10 million for the Air Force version of this proposed organization, Application Software Assurance Center of Excellence (ASACOE).

The Committee report also notes that this proposed JSAC would help the military comply with the §933 requirements of the FY 2103 National Defense Authorization Act.

There is nothing in §942 that would address the availability of such tools for work in the civilian sector, but it is reasonable to suppose that it might be made available to DHS in support of cybersecurity activities in the critical infrastructure sectors.

Homeland Cyber Response

It is apparent that the use of National Guard cyber-warriors is the ‘cybersecurity’ idea of the year. We have seen it proposed in two identical bills (HR 1640 and S 658) and a version was included in the House DOD spending bill, HR 2397, Committee Report. This bill provides yet a third version of the idea as part of §945 examination of the use of the Reserve Components in DOD cyber missions.

DOD and DHS would be required to take a coordinated look at the use of National Guard in a cyber homeland defense role. The bill specifically tasks the two departments to get input from the Governors on “State cyber capabilities, and State cyber needs that cannot be fulfilled through the private sector” {§945(b)(2)}. This is part of the requirement to determine if the National Guard, operating under State status “can operate under unique and useful authorities to support domestic cyber missions and requirements of the Department or the United States Cyber Command” {§945(b)(4)}.

The bill even goes so far as to suggest that DOD looks into if it would be appropriate to hire part-time National Guard Technicians with appropriate cybersecurity expertise to assist “the National Guard in protecting critical infrastructure [emphasis added] and carrying out cyber security missions in defense of the United States homeland” {§945(b)(5)}.

Operation of the National Guard units under State status is an important legal distinction. Because of restrictions on the domestic use of military forces under the Posse Comitatus Act (18 USC 1385) it would be necessary to use National Guard units under the command of Governors to participate in many cyber related homeland defense missions.

Control of Cyber Weapons

Section 946 addresses attempt to control the international trade in cyber weapons. It requires the President to establish yet another “interagency process to provide for the establishment of an integrated policy to control the proliferation of cyber weapons” {§946(a)}.

Since there is not currently a legal definition of ‘cyber weapons’ the same interagency process is also required to identify “the types of dangerous software that can and should be controlled through export controls” {§946(b)(1)}. The Committee Report notes:

“This process will require developing definitions and categories for controlled cyber technologies and determining how to address dual use, lawful intercept, and penetration testing technologies.” (pg 159, Adobe 181)

It is clear that someone on the Senate Armed Forces Committee staff realizes that many of these ‘cyber weapons’ might have legitimate uses in the cybersecurity field. The Committee Report states:

“However, the approaches developed must also take into account the needs of legitimate cybersecurity professionals to mitigate vulnerabilities, and not stifle innovation in tools and technology that are necessary for national security and the cybersecurity of the Nation.” (pg 160, Adobe 182)

The section requires the identification of methods that should be used to “suppress the trade in cyber tools and infrastructure that are or can be used for criminal, terrorist, or military activities while preserving the ability of governments and the private sector to use such tools for legitimate purposes of self-defense” {§946(b)(2)}.

Moving Forward


I expect that the Senate will move forward with its consideration of S 1197 in the few weeks remaining before the Summer Recess. The bill will pass after some significant amendments are offered and wrangled over. The Senate will then vote to substitute the wording from this bill for the House wording of HR 1960. The bill will then go to conference to work out the differences between the two bills. That won’t happen until sometime later this year, probably after the start of FY 2014.

Friday, June 21, 2013

Bills Introduced – 6-20-13

We had four bills of potential interest to the cybersecurity community yesterday, a DOD authorization bill and three that would change the criminal statutes related to cybersecurity. The bills are:

S 1196 Latest Title: A bill to amend title 18, United States Code, to provide for clarification as to the meaning of access without authorization, and for other purposes.
Sponsor: Sen Wyden, Ron (D,OR)

S 1197 Latest Title: An original bill to authorize appropriations for fiscal year 2014 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sponsor: Sen Levin, Carl (D,MI)

HR 2454 Latest Title: To amend title 18, United States Code, to provide for clarification as to the meaning of access without authorization, and for other purposes. Sponsor: Rep Lofgren, Zoe (D-CA)

HR 2466 Latest Title: To amend title 18, United States Code to provide for strengthened protections against theft of trade secrets, and for other purposes. Sponsor: Rep Lofgren, Zoe (D-CA)


S 1196 and HR 2454 are likely companion bills, bills introduced in both the House and Senate with identical language.
 
/* Use this with templates/template-twocol.html */