Showing posts with label S 2199. Show all posts
Showing posts with label S 2199. Show all posts

Tuesday, November 9, 2021

Review - HR 3684 Passed in House – FY 2022 Infrastructure Bill

Last Friday the House finally got around to passing HR 3684, the Infrastructure Investment and Jobs Act, by a slightly bipartisan vote of 228 to 206. With the complexity of the bill and the large amounts of money involved, this is a good time to re-look at the cybersecurity provisions in the bill.

The bill includes language from six separate pieces of cybersecurity legislation.

S 914, the Drinking Water and Wastewater Infrastructure Act of 2021, in §50113,

S 1316, the Cyber Response and Recovery Act of 2021, in §70601,

S 1400, the PROTECT Act of 2021, in §40123,

S 2199, the Cyber Sense Act of 2020, in §40122,

S 2585, the State and Local Cybersecurity Improvement Act, in §70611, and

HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, in §40121.

It also contains two new standalone cybersecurity provisions in the Energy Division of the bill. Additional (over the current annual spending) cybersecurity spending is authorized for four agencies of the federal government. Finally, there are 23 separate instances where cybersecurity mentions are made in other provisions of the bill

For more details about those provisions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3684-passed-in-house - subscription required.

 

Saturday, July 10, 2021

S 2199 Introduced - Cyber Sense Act

Last month, Sen Rosen (D,NV) introduced S 2199, the Cyber Sense Act of 2020 (yep, it says 2020). The bill would require DOE to “establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system”. The bill is similar to HR 2928 which was adopted by the House Energy and Commerce Committee without amendment.

Definitions

Section 2(a) of the bill provides the definitions for four critical terms used in the bill (these definitions are not laid out in HR 2928, the terms are defined in passing), two by reference to existing definitions. There are no cybersecurity related definitions provided.

Program Established

Sections 2(b) and 2(c) in this bill are essentially identical to §2(a) and §2(b) respectively in the House bill. The only difference is that the House bill keeps referring to the ‘Cyber Sense Program’ where the Senate bill uses the term ‘Program’ after defining that in §2(a)(3) as meaning the ‘Cyber Sense Program’ established in §2(b).

Moving Forward

While Rosen is not a member of the Senate Energy and Natural Resources Committee, the committee to which this bill was assigned for consideration, three of her four cosponsors {Sen Hoeven (R,ND), Sen King (I,ME), and Risch (R,ID), are members and Hoeven is the Ranking Member of the Energy Subcommittee. This means that there is probably sufficient influence to see this bill considered in Committee.

The House version of this bill received bipartisan support and I would expect to see the same in Committee in the Senate. The problem remains moving the bill to the floor of the Senate. The bill is not important enough to be considered under regular order (debate, amendments, and, of course, two separate cloture votes) and I suspect that there would be sufficient opposition to stop consideration under the unanimous consent process.

The only way this bill is moving forward in the Senate is attached to some other, must pass piece of legislation.

Commentary

In my Substack post on HR 2928 I addressed my concerns about the information sharing restrictions in what is §2(d) in this bill. Many pieces of control system equipment are used outside of the bulk power system and restricting those outside that system from being notified of vulnerabilities is just not fair.

In my post on this blog I talked about adding a software bill of materials requirement to the House version of this bill. My interest in seeing that done remains.

Thursday, June 24, 2021

Bills Introduced – 6-23-21

Yesterday, with both the House and Senate in session, there were 63 bills introduced. Two of those bills may receive additional coverage in this blog:

S 2199 A bill to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Sen. Rosen, Jacky [D-NV] 

S 2201 A bill to manage supply chain risk through counterintelligence training, and for other purposes. Sen. Peters, Gary C. [D-MI]

I will be covering S 2199. I suspect that it is a companion measure to HR 2928.

As always, one has to be careful with the term ‘supply chain risk’. I will be watching this bill to see if that term is used in the cybersecurity sense and, if it does, whether the bill contains language and definitions that would include industrial control systems in its coverage.

 
/* Use this with templates/template-twocol.html */