Showing posts with label S 2556. Show all posts
Showing posts with label S 2556. Show all posts

Sunday, June 6, 2021

Review – S 1400 Introduced – PROTECT Act of 2021

Back in March, Sen Murkowski (R,AK) introduced S 1400, the Protecting Resources on The Electric grid with Cybersecurity Technology (PROTECT) Act of 2021. The bill would provide energy cybersecurity investment incentives and establish a grant and technical assistance program for cybersecurity investments. The language is virtually identical to S 2556 that was introduced in the 116th Congress and reported in the Senate.

Section 2 of the bill would amend the Federal Power Act by adding a new §219A, Incentives for Cybersecurity Investments. The bill would require the Federal Energy Regulatory Commission (FERC) to “conduct a study to identify incentive-based, including performance-based, rate treatments for the transmission of electric energy subject to the jurisdiction of the Commission that could be used to encourage” investment by public utilities in advanced cybersecurity technology.

One year after the study was completed the bill would require FERC to establish a rule providing for “incentive-based, including performance-based, rate treatments for the transmission of electric energy in interstate commerce by public utilities for the purpose of benefitting consumers by encouraging” the same investments and participation described above.

Finally, the bill would require DOE to establish the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program to “to provide grants and technical assistance to, and enter into cooperative agreements with, eligible entities to protect against, detect, respond to, and recover from cybersecurity threats.” The bill would authorize $50 million dollars per year thru 2026 for the grant program.

Murkowski and three of her cosponsors {Sen Manchin (D,WV), Risch (R,ID), and King (I,ME)} are all members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. Between them (especially considering that Manchin is the Committee Chair) they certainly have enough influence to see the bill considered in Committee. I expect that this bill (as did S 2556 last session) would receive strong bipartisan support in Committee and ultimately in the Senate.

For a more detailed review of the details of this bill, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1400-introduced - Subscription Required.

Wednesday, November 20, 2019

Senate ENR Amends and Approves Cybersecurity Bills – 11-19-19


Yesterday the Senate Energy and Natural Resources Committee held a business meeting to consider three nominations and markup 19 bills. Those bills included three cybersecurity bills that have been covered in this blog. All three of those bills were amended and then passed on voice votes.

S 876, DOE Vet Training


The Committee considered S 875, the Energy Jobs for Our Heroes Act of 2019. A staff amendment was adopted by the Committee rewrote the proposed §1107(f) by removing the grant funding provisions and removed (g) the spending authorization provisions of the bill. A second amendment was proposed by Sen Lee (R,UT) and it was also adopted by the Committee. The Lee amendment provided more detailed information about what was to be included in the Report to Congress required by (h) {changed to (g) by the previous amendment}.

S 2556, Cybersecurity Investment


The Committee considered S 2556, the PROTECT Act. The Committee adopted an amendment in the nature of a substitute. The substitute language:

Adds §219A(c)(2) that adds a prohibition of duplicate recovery to the rate recovery provision; and
Adds §3(a)(2)(E) that adds “an investor-owned electric utility that sells less than 4,000,000 megawatt hours of electricity per year” to the list of entities eligible for the e Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program.

S 2714, ARPA-E Reauthorization


The Committee considered S 2714, the ARPA–E Reauthorization Act of 2019. The Committee adopted an amendment. That amendment inserted a new §2(c) and renumbered the subsequent sub-sections. The new subsection amends 42 USC 16538(f). The new language would allow DOE to consider past grant performance during the award of new grants.

Moving Forward


These three bills had significant bipartisan support in Committee, but Lee insisted on being recorded as a Nay vote on each of the bills. This means that he would be likely to raise an objection if the bills were offered for consideration under the Senate’s unanimous consent process. If that were to happen the bills would not be adopted under those provisions and would have to be considered under regular order. None of these bills is important enough to take up the Senate’s time under regular order.

The only other way that these bills could be considered would be as part of a DOE authorization bill.

Monday, November 18, 2019

Committee Hearings – Week of 11-17-19


This week the impeachment hearings continue to attract the main attention of politicians and, to a lesser extent, the public. There are two markup hearings this week; one in the House that will deal with a pipeline safety bill, and one in the senate that will address cybersecurity bills.

Pipeline Safety Hearings


On Tuesday the House Energy and Commerce Committee will hold a markup hearing that will consider 18 bills. One of those bills is HR 5120 that was introduced last Friday. The official version of the bill has yet to be printed, but a Committee Print is available and a summary is included in the Committee Briefing Notes. I have not yet had a chance to review the bill.

Cybersecurity Hearing


On Tuesday the Senate Energy and Natural Resources Committee will hold a business meeting that will consider 17 bills and three nominations. The list includes 3 cybersecurity related bills:

S 876, to amend the Energy Policy Act of 2005 to require the Secretary of Energy to establish a program to prepare veterans for careers in the energy industry, including the solar, wind, cybersecurity, and other low-carbon emissions sectors or zero-emissions sectors of the energy industry;

S 2556, to amend the Federal Power Act to provide energy cybersecurity investment incentives, to establish a grant and technical assistance program for cybersecurity investments;

S 2714, to amend the America COMPETES Act to reauthorize the ARPA-E program,

On the Floor


On Tuesday the House will consider HR 4634; Terrorism Risk Insurance Program Reauthorization Act of 2019 (as amended) under the suspension of the rules process. This means that there will be limited debate, no floor amendments and a super majority will be required for passage. A significant bipartisan majority is expected on this bill.

It is likely that the House Rules Committee will take up a continuing resolution some time this week to continue funding the government, probably through sometime next month.

Tuesday, November 5, 2019

Committee Hearings – Week of 11-3-19


This week just the Senate will be in session; the House is working (campaigning? Or just explaining impeachment?) in their districts. There are two cybersecurity related hearings scheduled; one a markup and one a DOE look at legislation.

Markup Hearing


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will be holding a business meeting that includes marking up 16 bills (plus 11 postal naming bills and four nominations). Only one of those bills is of interest here:

HR 1589, the CBRN Intelligence and Information Sharing Act of 2019

The House passed this bill by a voice vote back in April. I would not normally expect the Committee to make any substantive changes to this bill in this type of crowded hearing.

Legislative Hearing


On Wednesday the Energy Subcommittee of the Senate Energy and Natural Resources Committee will hold a legislative hearing looking at 11 Department of Energy related bills. There is only one witness scheduled; Daniel Simmons from DOE. Two of those bills are of interest here:

S 2556 – Protecting Resources On The Electric grid with Cybersecurity Technology Act of 2019
S 2714 – ARPA-E Reauthorization Act

The language for S 2714 has just become available. I hope to be able to review it in detail before tomorrow’s hearing.

Sunday, October 13, 2019

S 2556 Introduced – Cybersecurity Investments

Last month Sen. Murkowski (R,AK) introduced the Protecting Resources on the Electric Grid with Cybersecurity Technology (PROTECT) Act of 2019. The bill would provide energy cybersecurity investment incentives.

Incentives


Section 2 of the bill would amend the Federal Power Act (16 USC Chapter 12) by adding a new §219A, Incentives for Cybersecurity Investments. The new section begins by defining two new terms {new §219A(a)}:

• Advanced Cybersecurity Technology – any technology, operational capability, or service, including computer hardware, software, or a related asset, that enhances the security posture of public utilities through improvements in the ability to protect against, detect, respond to, or recover from a cybersecurity threat (as defined in 6 USC 1501).

• ADVANCED CYBERSECURITY TECHNOLOGY INFORMATION – information relating to advanced cybersecurity technology or proposed advanced cybersecurity technology that is generated by or provided to the Commission or another Federal agency.

Subsection (b) would require the Federal Energy Regulatory Commission (FERC) to “conduct a study to identify incentive-based, including performance-based, rate treatments for the transmission of electric energy subject to the jurisdiction of the Commission that could be used to encourage”:

• Investment by public utilities in advanced cybersecurity technology; and
• Participation by public utilities in cybersecurity threat information sharing programs.

Subsection (c) would require FERC to establish a rule providing for “incentive-based, including performance-based, rate treatments for the transmission of electric energy in interstate commerce by public utilities for the purpose of benefitting consumers by encouraging” the same investments and participation describe above. FERC may also include in that rulemaking additional incentives for {§219A(d)}:

• Defense critical electric infrastructure (as defined in section 215A(a)) and other facilities subject to the jurisdiction of the Commission that are critical to public safety, national defense, or homeland security, as determined by the Commission; and
• Facilities of small- or medium-sized public utilities with limited cybersecurity resources, as determined by the Commission.

Subsection (g) would provide protection against disclosure of advanced “cybersecurity technology information that is provided to, generated by, or collected by the Federal Government under subsection (b), (c), or (f)” by considering the information to be critical electric infrastructure information (CEII) under 16 USC 824o-1.

Grant Program


Section 3 of the bill would require the Department of Energy to establish the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program to “to provide grants and technical assistance to, and enter into cooperative agreements with, eligible entities to protect against, detect, respond to, and recover from cybersecurity threats” {§3(b)}. The following types of entities would be eligible to apply for such grants or assistance {§3(a)}:

• A rural electric cooperative;
• A utility owned by a political subdivision of a State, such as a municipally owned electric utility;
• A utility owned by any agency, authority, corporation, or instrumentality of one or more political subdivisions of a State; and
• A not-for-profit entity that is in a partnership with not fewer than 6 entities described in subparagraph (A), (B), or (C).

DOE would be required to prioritize grants and technical assistance by giving priority to an eligible entity that, as determined by the Secretary {§3(d)(2)}:

• Has limited cybersecurity resources;
• Owns assets critical to the reliability of the bulk power system; or
• Owns defense critical electric infrastructure (as defined in 16 USC 824o–1(a).”

The bill would authorize $50 million per year for the next four years for this grant/assistance program.

Information provided to FERC or collected by FERC under this program would be protected from public disclosure, but would not specifically be considered CEII.

Moving Forward


Murkowski is the Chair of the Senate Energy and Natural Resources Committee to which this bill is assigned for consideration. Her cosponsors include Sen. Manchin (D,WV) who is the Ranking member of the Committee, and three other influential members of the Committee. This bill will almost certainly be considered in Committee and the bipartisan sponsorship would seem to indicate that the bill will receive significant bipartisan support in the Committee.

The big problem facing this bill is getting it to the Senate floor for consideration. There is just too much going on during the remainder of the year for this to be considered under the normal process. I do not suspect that this will be able to be considered under the unanimous consent process; too many Senators would see this bill as an ideal vehicle to add their own pet energy projects.

There may be a relatively short window next year that this bill could be considered before the election silly season gets into full swing.

Commentary


I am glad to see that Murkowski’s staff used the §1501 definition of ‘cybersecurity threat’ in their definition of ‘advanced cybersecurity technology’ since that definition relies on the ICS inclusive definition of ‘information system’. Having said that, the definition of ‘cybersecurity threat’ is still grossly lacking when it comes to energy system security since it relies on the IT triad of “availability, confidentiality, or integrity of an information system”. It does not specifically address the potential physical consequences of a cyber-attack on electric grid cyber assets.

I have addressed this definitional issue is some detail. Unfortunately, I doubt that my entire proposed solution will be attempted in this bill. Instead I would suggest the addition of the below listed definitions and the deletion of the reference to §1501 in the existing definition.

(5) the term ‘control system’ means a discrete set of information resources, sensors, communications interfaces and physical devices organized to monitor, control and/or report on physical processes, including power production, electric transmission or distribution, access control, and facility environmental controls;

(6) the term ‘cybersecurity threat’ means:

(A) threats to and vulnerabilities of information, information systems, or control systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information, information systems, or control systems, including such related consequences caused by an act of terrorism; and

(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement; and

(7) the term "information system" has the meaning given that term in section 3502(8) of title 44.

The other problem with this bill is the inclusion of the protection of information under the provisions of CEII. While a great deal of the information addressed in this bill could well fit under the CEII designation, I question how much information provided in the rate filings under §219A(f) should receive that protection. The public deserves the right to see why rates are being changed. With that in mind I would re-write subsection (f):

(f) SINGLE-ISSUE RATE FILINGS.

(a) The Commission shall permit public utilities to apply for incentive based rate treatment under the rule issued under this section on a single-issue basis by submitting to the Commission a tariff schedule under section 205 that permits recovery of costs and incentives over the depreciable life of the applicable assets, without regard to changes in receipts or other costs of the public utility.

(b) Data submitted to the Commission to justify the rate change will include a sensitive annex listing computer hardware, software and services that will constitute the advanced cybersecurity technology justifying the incentive based rate treatment in (a). The sensitive data will be protected as critical electric infrastructure information (CEII) under 16 USC 824o-1.

(c) The information in the sensitive annex will include a detailed listing of costs and the depreciable life of the computer hardware, software and services described in (b). A summary of the costs and depreciable life of those assets will be included under the listing of ‘advanced cybersecurity technology’ in the public information provided to the Commission.

Friday, September 27, 2019

Bills Introduced – 09-26-19


Yesterday with both the House and Senate preparing to leave Washington for a two-week recess, there were 114 bills introduced. Four of these bills may see additional coverage in this blog:

S 2556 A bill to amend the Federal Power Act to provide energy cybersecurity investment incentives, to establish a grant and technical assistance program for cybersecurity investments, and for other purposes. Sen. Murkowski, Lisa [R-AK]

S 2580 An original bill making appropriations for the Department of the Interior, environment, and related agencies for the fiscal year ending September 30, 2020, and for other purposes. Sen. Murkowski, Lisa [R-AK]

S 2582 An original bill making appropriations for the Department of Homeland Security for the fiscal year ending September 30, 2020, and for other purposes. Sen. Capito, Shelley Moore [R-WV]

S 2584 An original bill making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2020, and for other purposes. Sen. Moran, Jerry [R-KS]

 
/* Use this with templates/template-twocol.html */