Showing posts with label S 1897. Show all posts
Showing posts with label S 1897. Show all posts

Monday, February 10, 2014

HR 3990 Introduced – Cybersecurity

As I noted last week Rep. Shea-Porter (D,NH) introduced HR 3990, the Personal Data Privacy and Security Act of 2014. This is a companion bill to S 1897 introduced by Sen. Leahy (D,NH). The bill deals mainly with the protection of personally identifiable information, but it does contain one section (§109) that makes it a criminal act to damage critical infrastructure computers, including control system computers. Different versions of this section have been found in other bills as well (HR 1468 for instance).


There is one oddity in the Leahy-Shea-Porter version of the bill; the definition of critical infrastructure includes “electrical power delivery systems;” while other versions expand on that to include “electrical power generation and delivery systems;”. This ‘oddity’ should be corrected in committee markup.

Saturday, January 11, 2014

S 1897 Introduced – Cybersecurity

As I noted earlier this week, Sen. Leahy (D,VT) introduced S 1897, the Personal Data Privacy and Security Act of 2014. This is essentially the same bill that was reported in the Senate in the 112th Congress under the same name, S 1151. That bill passed in the Judiciary Committee which Sen. Leahy still chairs, but never made it to the floor while Sen. Reid (D,NV) waited for comprehensive cybersecurity legislation to coalesce.

Most of this bill deals with data breaches and protecting personally identifiable information. I will leave the discussion of those portions of the bill to folks with more expertise in the area.

Control System Security

There is one section of the bill that addresses industrial control system security issues. It is found in §109, Damage to Critical Infrastructure Computers. It would add §1030A to Chapter 47 of 18 USC. This new section would make it a criminal act to “intentionally cause or attempt to cause damage to a critical infrastructure computer” {§1030A(b)}
  
It defines a ‘critical infrastructure computer’ as one that “that manages or controls systems or assets vital to national defense, national security, national economic security, public health or safety, or any combination of those matters, whether publicly or privately owned or operated” {§1030A(a)(2)} and then proceeds to give operational examples of industries where such computers could be found. Looking at the definition and the examples it clearly intends to protect against denial of service type attacks, but seems to ignore the possibility of such damage could result in catastrophic physical damage to the facility and the surrounding community.

I noted in an earlier blog post that identical language to §109 can be found in §305 of HR 1468.

Unauthorized Access

Sen. Leahy takes a light approach to ‘correcting’ the problem of people being inappropriately charged (or sued) for unauthorized access to a computer by virtue of violating terms or service agreements or acceptable use policies. Rather than proposing whole sale revisions to 18 USC 1030 as did Rep. Lofgren (D,CA) in HR 2454 {or Sen. Wyden (D,OR) in S 1196, a companion bill}, S 1897 would add a single subparagraph to §1030(g):

“(2) No action may be brought under this subsection if a violation of a contractual obligation or agreement, such as an acceptable use policy or terms of service agreement, constitutes the sole basis for determining that access to the protected computer is unauthorized, or in excess of authorization.”.

Moving Forward

Many news reports about the introduction of this bill indicate that the Thanksgiving Target POS attack was the impetus for Leahy’s re-introduction of this bill. It will certainly pass in his Committee with minimal changes (hopefully including re-wording §109 to specifically include cyber attacks with catastrophic physical consequences). Whether it will ever make it to the floor of the Senate depends in large part upon the political whims of Sen. Reid.


In general, however, I think this bill was submitted too late in the election cycle to make it through the legislative process before the end of the year.

Thursday, January 9, 2014

Bills Introduced – 01-08-14

Well we finally have the first bill of potential interest of the 2nd Session of the 113th Congress.

S 1897 Latest Title: A bill to prevent and mitigate identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information. Sponsor: Sen Leahy, Patrick J. (D,VT)


This is probably a purely IT security bill and it possibly may only be related health care related issues, but the term ‘fraudulent access’ caught my attention. We’ll have to see what the bill actually says when it gets printed.
 
/* Use this with templates/template-twocol.html */