Showing posts with label S 2491. Show all posts
Showing posts with label S 2491. Show all posts

Tuesday, November 2, 2021

Senate Amendments to HR 4350 – 11-1-21

While the Senate still has not officially started the consideration of HR 4350, the FY 2022 NDAA, there were 63 amendments proposed yesterday. One of those amendments may be of interest here:

SA 4112 – Sen King (I,ME): DIVISION E—Defense Of United States Infrastructure [pg S7557] Similar to S 2491.

Monday, November 1, 2021

Committee Hearings – Week of 10-31-21

This week, with both the House and Senate in Washington, there is a relatively light committee schedule. There is one mark-up hearing and two cybersecurity hearings of interest.

Senate Mark-up Hearing

On Wednesday, the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. In addition to three nominations and two postal-naming bills, the Committee will take up 25 bills. That includes bills of interest here:

S 2993, the CISA Cyber Exercise Act,

S 2491, the Defense of United States Infrastructure Act of 2021,

S 2274, the Federal Cybersecurity Workforce Expansion Act,  and

S 2483, the Improving Cybersecurity of Small Organizations Act of 2021

With this large of an agenda, there will be little or no debate during the hearing, but in this Committee that sort of give and take almost always takes place behind closed doors.

Cybersecurity Hearings

On Wednesday the House Homeland Security Committee will hold a hearing on “Evolving the U.S. Approach to Cybersecurity: Raising the Bar Today to Meet the Threats of Tomorrow”. The witness list includes:

• Jen Easterly, CISA, and

• Chris Inglis, National Cyber Director

While not directly in the purview of this Committee, it will be interesting to see if the testimony reiterates previous calls for EPA cybersecurity mandate authority.

On Thursday, the House Transportation and Infrastructure Committee will hold a hearing on “The Evolving Cybersecurity Landscape: Industry Perspectives on Securing the Nation's Infrastructure”. No witness list is currently available. While the Committee certainly (and legitimately) wants to hear from industry, it would seem to me that a panel from TSA and CISA would certainly be appropriate in the current regulatory climate.

On the Floor

We may see the Senate this week formally start the consideration process for HR 4350, the FY 2022 NDAA. We certainly saw enough amendments proposed to that bill last week. The amendment submission process will likely continue in any case. This must pass bill is a great place for Senators to place legislation that could not make it to the floor under regular order.

The House is scheduled to take up three small-business cybersecurity bills this week (only two of which I have covered here) under the suspension of the rules process. Those bills are:

HR 3462 – SBA Cyber Awareness Act,

HR 4513 – Small Business Advanced Cybersecurity Enhancements Act of 2021,

HR 4515 – Small Business Development Center Cyber Training Act of 2021

These bills will have strong bipartisan support, but Republican delaying tactics could result in actual votes being delayed until next week.

The House leadership is still trying to get their two infrastructure bills to the floor for votes. Maybe we will see them this week, maybe not.

Tuesday, August 31, 2021

Review - S 2491 Introduced – Defense of US Infrastructure

Review - Sen King (I,ME) introduced S2491, the Defense of United States Infrastructure Act of 2021. The bill would establish a cyber resilience assistance fund and take other measures to improve the resilience and cybersecurity of critical infrastructure. Funding is authorized in the bill.

Those other measures include:

• A government-wide, cloud-based, information sharing environment,

• The establishment of up to three cybersecurity-focused critical technology security centers,

• A requirement for the Homeland Security Advanced Research Projects Agency to conduct connected industrial control system security testing,

• The establishment of a National Cybersecurity Certification and Labeling Authority,

• The establishment of a Bureau of Cybersecurity Statistics within DHS, and

• The designation of Systemically Important Critical Infrastructure.

While King is not a member of the Senate Homeland Security and Governmental Affairs Committee, to which this bill was assigned for consideration, one of his three cosponsors {Sen Rosen (D,NV)} is a member. This means that there may be enough influence to see this bill considered in Committee. I suspect that there would be some significant Republican opposition to this bill because of the use of mandatory reporting and security requirements included in the bill. The lack of the terms ‘voluntary’ and ‘consensus standards’ will make it hard for many Republicans to support this measure.


For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2491-introduced - subscription require.

Wednesday, July 28, 2021

Bills Introduced – 7-27-21

 Yesterday, with both the House and Senate in Washington, there were 62 bills introduced. Two of those bills may receive additional coverage in this blog:

S 2483 A bill to require the Director of the Cybersecurity and Infrastructure Security Agency to establish cybersecurity guidance for small organizations, and for other purposes. Sen. Rosen, Jacklyn [D-NV]

S 2491 A bill to amend the Homeland Security Act of 2002 to establish the National Cyber Resilience Assistance Fund, to improve the ability of the Federal Government to assist in enhancing critical infrastructure cyber resilience, to improve security in the national cyber ecosystem, to address Systemically Important Critical Infrastructure, and for other purposes. Sen. King, Angus [I-ME]

I will be watching both bills for language and definitions that would include industrial control systems within the coverage of the bill.
 
/* Use this with templates/template-twocol.html */