Showing posts with label S 174. Show all posts
Showing posts with label S 174. Show all posts

Monday, July 15, 2019

Committee Hearings – Week of 7-14-19


With both the House and Senate in Washington and looking towards their extended summer recess, there are a number of interesting hearings on the schedule for this week. In addition to the House Rules Committee hearing on HR 3494 there will be two markup hearings addressing cybersecurity bills and two other hearings that may address cybersecurity issues.

Cybersecurity Markups


On Tuesday the Senate Energy and Natural Resources Committee will conduct a markup hearing on 23 bills. Bills of interest here include:

S 174, a bill to provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. (King/Risch); and
S 715, a bill to improve the productivity and energy efficiency of the manufacturing sector by directing the Secretary of Energy, in coordination with the National Academies and other appropriate Federal agencies, to develop a national smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs, and for other purposes. (Shaheen)

On Tuesday the House Homeland Security Committee will conduct a markup hearing on 18 bills. Bills of interest here include:

HR 3318, (Mr. Joyce) The “Emerging Transportation Security Threats Act of 2019”;
HR 3699, (Mr. Cleaver) The “Pipeline Security Act” (not yet reviewed here);
HR 3710, (Ms. Jackson Lee) The “Cybersecurity Vulnerability Remediation Act” (not yet reviewed here).

Both of these hearings are going to be dealing with a large number of bills. I do not expect much in the way of amendments and very little discussion.

Cybersecurity (?) Hearings


On Wednesday the Energy Subcommittee of the House Energy and Commerce Committee will be holding a hearing on “The Future of Electricity Delivery: Modernizing and Securing Our Nation’s Electricity Grid”. The witness list includes:

Karen Evans, DOE;
Juan Torres, National Renewable Energy Laboratory;
Kelly Speakes-Backman, Energy Storage Association; and
Katherine Hamilton, Advanced Energy Management Alliance

This is almost certainly going to focus on energy supply security, not cybersecurity, but Evans is the head of Office of Cybersecurity, Energy Security, and Emergency Response (CESER), so there will likely be some questions about grid cybersecurity.

On Thursday the House Oversight and Reform Committee will hold a hearing with Kevin K. McAleenan. There is no official indication of the topics to be discussed, but I suspect that it will focus on ‘border security issues.’ There is a slight chance that cybersecurity questions will be addressed to the Acting Secretary.

Tuesday, February 5, 2019

HR 680 Introduced – Energy Sector Security


Last month Rep. Ruppersberger (D,MD) introduced HR 680, the Securing Energy Infrastructure Act. This is a companion bill to S 174 that I discussed yesterday. Ruppersberger introduced a similar bill last session (HR 3958), but no action was taken on that earlier bill.

Moving Forward


Neither Ruppersberger nor his single cosponsor {Rep. Carter (R,TX)} are members of the House Science, Space, and Technology Committee to which this bill was assigned for consideration. This means that the bill is unlikely to receive consideration in that Committee unless additional sponsors are signed. As I mentioned yesterday, this study and report bill is unlikely to attract serious opposition other than the fact that it would require the appropriation of $11.5 million.

Interestingly, both Ruppersberger and Carter are on the House Appropriations Committee. That Committee has not been assigned consideration of the bill, but their bipartisan support could help alleviate concerns about the spending aspects of this bill if it were to make it to the floor of the House. Unfortunately, neither are on the Energy and Water Development, and Related Agencies Subcommittee which controls appropriations for DOE.

Commentary


Yesterday, in a LinkedIn comment on my S 174 post, Kenneth Crowther made the comment that “I hope when they. ... "discover new classes of vulnerabilities" they have a plan for responsible disclosure to the vendor...”  Unfortunately, there is nothing in the legislation that would require the pilot program to effect coordinated disclosures. It would certainly hamper the effort to increase grid security if they did not.

Crowther’s point is well taken, and I would suggest that language be added to §3 of both bills to require that vulnerabilities detected during the program be coordinated with the appropriate vendors via the DHS NCCIC-ICS. More importantly, that language should include provisions for delayed public disclosure of the vulnerabilities while secure disclosure is made to utilities after vendors have developed adequate mitigation measures. Here is how that language could read:

(b) Coordinated Disclosure

(1) Any vulnerabilities identified during the pilot program will be reported to vendors in coordination with the industrial control system team at the National Cybersecurity & Communications Integration Center (NCCIC-ICS) in the Department of Homeland Security;

(2) Once a vendor provides NCCIC-ICS with notification that appropriate mitigation measures have been developed, NCCIC-ICS would provide limited disclosure of the vulnerability through the Electricity Sector - Information Sharing and Analysis Center (ES-ISAC);

(3) Ninety days after the ES-ISAC is notified the NCCIC-ICS will provide public notification of the vulnerability; and

(4) If a vendor has not provided a reasonable schedule for mitigation of the reported vulnerabilities within 45 days of initial notification of the vulnerability by NCCIC-ICS, NCCIC-ICS will prepare an alert about the vulnerability and publish that report in accordance with (2) and (3) above.

Monday, February 4, 2019

S 174 Introduced – Energy Sector Security


Last month Sen. King (I-ME) introduced S 174, the Securing Energy Infrastructure Act. This bill is the same as the reported version of S 79 that was introduced in the 115th Congress (and actually dates back to S 3018 from the 114th). It calls for and finances a study on control system security in the electric sector.

King and Rep. Ruppersberger (D,MC), who has introduced what is probably a companion bill (HR 680 to be published) have been pushing hard for this idea for over two years now. Last session King got his version out of Committee, but could not get it to the floor of the Senate. This was almost certainly due to the cost of the bill ($11.5 million). With more news being released about the cybersecurity risks associated with the grid, we may see this bill get to the floor.

Friday, January 18, 2019

Bills Introduced – 01-17-19


Yesterday with both the House and Senate in session there were 86 bills introduced. Of those, three may receive additional coverage on this blog:

HR 648 Consolidated Appropriations Act, 2019 Rep. Lowey, Nita M. [D-NY-17] 

HR 680 To provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. Rep. Ruppersberger, C. A. Dutch [D-MD-2]

S 174 A bill to provide for the establishment of a pilot program to identify security vulnerabilities of certain entities in the energy sector. Sen. King, Angus S., Jr. [I-ME]

HR 648 is another version of an FY 2019 spending bill that addresses the spending for the shut down agencies in the Federal government (except for DHS). I will only be looking at this bill if there are specific provisions of the bill of interest. The schedule for next week has not yet been published, but I expect that it will be considered on the floor next week. This will be another attempt to get Republican support to re-open the government over Trump’s opposition.

It looks like the other two bills are companion bills, but I cannot be sure until I see the actual bills.

 
/* Use this with templates/template-twocol.html */