Showing posts with label S 2274. Show all posts
Showing posts with label S 2274. Show all posts

Thursday, August 3, 2023

Review - S 2256 Introduced – CISA Cyber Training

Last month Sen Hassan (D,NH) introduced S 2256, the Federal Cybersecurity Workforce Expansion Act. It would require CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or other Federal entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. There is no funding authorized in the legislation.

This bill is nearly identical to the reported version of S 2274 from the 117th Congress. That bill was reported favorably by the Senate Homeland Security Committee, but no further action was taken.

Moving Forward

Hassan is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. She probably has enough influence to see this bill considered in Committee. I see nothing in the bill that would engender any specific opposition. I suspect that it would receive significant bipartisan support in committee. This bill would not be considered on the floor of the Senate under regular order, but it might make it into the DHS spending bill as an amendment.

Commentary

While this bill does not directly address control system security issues, increasing the cybersecurity qualified staffing of CISA is certainly of interest to the ICS security community. While the training programs established under this bill would be targeted at future CISA employment, they should result in a net increase to the nation’s cybersecurity workforce.

 

For more information about the two programs outlined in this legislation, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2256-introduced - subscription required.

 

Monday, November 1, 2021

Committee Hearings – Week of 10-31-21

This week, with both the House and Senate in Washington, there is a relatively light committee schedule. There is one mark-up hearing and two cybersecurity hearings of interest.

Senate Mark-up Hearing

On Wednesday, the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. In addition to three nominations and two postal-naming bills, the Committee will take up 25 bills. That includes bills of interest here:

S 2993, the CISA Cyber Exercise Act,

S 2491, the Defense of United States Infrastructure Act of 2021,

S 2274, the Federal Cybersecurity Workforce Expansion Act,  and

S 2483, the Improving Cybersecurity of Small Organizations Act of 2021

With this large of an agenda, there will be little or no debate during the hearing, but in this Committee that sort of give and take almost always takes place behind closed doors.

Cybersecurity Hearings

On Wednesday the House Homeland Security Committee will hold a hearing on “Evolving the U.S. Approach to Cybersecurity: Raising the Bar Today to Meet the Threats of Tomorrow”. The witness list includes:

• Jen Easterly, CISA, and

• Chris Inglis, National Cyber Director

While not directly in the purview of this Committee, it will be interesting to see if the testimony reiterates previous calls for EPA cybersecurity mandate authority.

On Thursday, the House Transportation and Infrastructure Committee will hold a hearing on “The Evolving Cybersecurity Landscape: Industry Perspectives on Securing the Nation's Infrastructure”. No witness list is currently available. While the Committee certainly (and legitimately) wants to hear from industry, it would seem to me that a panel from TSA and CISA would certainly be appropriate in the current regulatory climate.

On the Floor

We may see the Senate this week formally start the consideration process for HR 4350, the FY 2022 NDAA. We certainly saw enough amendments proposed to that bill last week. The amendment submission process will likely continue in any case. This must pass bill is a great place for Senators to place legislation that could not make it to the floor under regular order.

The House is scheduled to take up three small-business cybersecurity bills this week (only two of which I have covered here) under the suspension of the rules process. Those bills are:

HR 3462 – SBA Cyber Awareness Act,

HR 4513 – Small Business Advanced Cybersecurity Enhancements Act of 2021,

HR 4515 – Small Business Development Center Cyber Training Act of 2021

These bills will have strong bipartisan support, but Republican delaying tactics could result in actual votes being delayed until next week.

The House leadership is still trying to get their two infrastructure bills to the floor for votes. Maybe we will see them this week, maybe not.

Friday, July 23, 2021

Review - S 2274 Introduced - Federal Cybersecurity Workforce Expansion

Last month Sen Hassan (D,NH) introduced S 2274, the Federal Cybersecurity Workforce Expansion Act. It would allow CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or a CISA supporting entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. The CISA program is authorized ‘such funds as necessary’, but no funding is specified for the VA program.

Hassan is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. She probably has enough influence to see this bill considered in Committee. I see nothing in the bill that would engender any specific opposition. I suspect that it would receive significant bipartisan support in committee. This bill would not be considered on the floor of the Senate under regular order, but it might make it into the DHS spending bill as an amendment.

While this bill does not directly address control system security issues, increasing the cybersecurity qualified staffing of CISA is certainly of interest to the ICS security community. While the training programs established under this bill would be targeted at future CISA employment, they should result in a net increase to the nation’s cybersecurity workforce.

For a closer look at the details of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2274-introduced - subscription required.

Friday, June 25, 2021

Bills Introduced – 6-24-21

Yesterday, with both the House and Senate in Washington (and the Senate preparing to leave for their 2-week 4th of July recess), there were 176 bills introduced. Five of those bills will receive additional coverage in this blog:

S 2269 A bill to secure the bulk-power system in the United States. Sen. Scott, Rick [R-FL] 

S 2274 A bill to authorize the Director of the Cybersecurity and Infrastructure Security Agency to establish an apprenticeship program and to establish a pilot program on cybersecurity training for veterans and members of the Armed Forces transitioning to civilian life, and for other purposes. Sen. Hassan, Margaret Wood [D-NH]

S 2292 A bill to require the Secretary of Homeland Security to study the potential consequences and benefits of amending the Computer Fraud and Abuse Act to allow private companies to take proportional actions in response to an unlawful network breach. Sen. Daines, Steve [R-MT]

S 2302 A bill to amend the Department of Energy Organization Act to assign certain functions to the Assistant Secretaries of Energy relating to energy emergencies and energy security, and for other purposes.

S 2305 A bill to enhance cybersecurity education. Sen. Ossoff, Jon [D-GA]

 
/* Use this with templates/template-twocol.html */