Showing posts with label S 1500. Show all posts
Showing posts with label S 1500. Show all posts

Friday, May 26, 2023

Review - S 1500 Introduced – Election System Cybersecurity Testing

Earlier this month Sen Warner (D,VA) introduced S 1500, the Strengthening Election Cybersecurity to Uphold Respect for Elections through Independent Testing (SECURE IT) Act. The bill would require the Election Assistance Commission (EAC) “to provide for the conduct of penetration testing as part of the testing and certification of voting systems and to provide for the establishment of an independent security testing and coordinated vulnerability disclosure pilot program for election systems. No funding is authorized in this legislation.

Moving Forward

Warner is a member of the Senate Rules and Administration Committee to which this bill is assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I do not see anything in the bill that would engender any organized opposition. I suspect that the bill would receive some level of bipartisan support. But again, as with most bills introduced in the Senate, this bill is not ‘important’ enough to be considered in the Senate under regular order. I also believe that there would be enough opposition to this bill to prevent it from being considered under the Senate’s unanimous consent process.

Commentary

One major item missing from this bill is the definition of the term ‘penetration testing’. NIST has a full page of potential definitions of the term. I think the most appropriate for this context would be the definition taken from NIST SP 800-137 under Penetration Testing. I would modify that definition slightly and add it in a new paragraph §231(e)(3):

“(3) In this section the term ‘penetration testing’ means a test methodology in which the researcher, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an election system as that term is defined in §297.”

 

For more details about the provisions of this bill, including additional commentary about the penetration testing requirements – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1500-introduced - subscription required.

Saturday, May 13, 2023

Bills Introduced – Week of 5-6-23

VACATION DELAYED

This week with both the House and Senate in Washington, 314 bills were introduced. Eight of those bills may receive additional attention in this blog:

HR 3147 To establish a defense industrial base advanced capabilities pilot program. Houlahan, Chrissy [Rep.-D-PA-6]

S 1493 A bill to amend title V of the Public Health Service Act to secure the suicide prevention lifeline from cybersecurity incidents, and for other purposes. Sinema, Kyrsten [Sen.-I-AZ] 

S 1500 A bill to amend the Help America Vote Act of 2002 to require the Election Assistance Commission to provide for the conduct of penetration testing as part of the testing and certification of voting systems and to provide for the establishment of an Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program for Election Systems. Sen. Warner, Mark R. [D-VA]

HR 3169 To require the inspection of certain foreign cranes before use at a United States port, and for other purposes. Gimenez, Carlos A. [Rep.-R-FL-28]

S 1526 A bill to amend the National Telecommunications and Information Administration Organization Act to establish the Office of Policy Development and Cybersecurity, and for other purposes. Hickenlooper, John W. [Sen.-D-CO]

HR 3208 To amend the Homeland Security Act of 2002 to establish a DHS Cybersecurity On-the-Job Training Program, and for other purposes. Jackson Lee, Sheila [Rep.-D-TX-18]

HR 3224 To amend the Homeland Security Act of 2002 to extend the authorization of the Countering Weapons of Mass Destruction Office of the Department of Homeland Security, and for other purposes. D'Esposito, Anthony [Rep.-R-NY-4]

S 1560 Rural Hospital Cybersecurity Enhancement Act Hawley, Josh [Sen.-R-MO]

I will be covering HR 3208, HR 3224, and S 1526.

I will be watching the remaining bills for language and definitions that specifically include control system or medical device cybersecurity requirements within the scope of the legislation.


 
/* Use this with templates/template-twocol.html */