Showing posts with label S 2658. Show all posts
Showing posts with label S 2658. Show all posts

Wednesday, July 13, 2016

House and Senate Pass HR 636 - FAA Authorization Bill

On Monday the House adopted a version of HR 636 that substituted new language for that adopted by the Senate in April by a voice vote. The cybersecurity provisions in the Senate language were removed and a new cybersecurity section was added. One of the two unmanned aircraft provisions associated with critical infrastructure facilities was completely re-written and the other remained mainly intact.

Cybersecurity


Section 2111 of the bill would require the FAA to develop “a comprehensive and strategic framework of principles and policies to reduce cybersecurity risks to the national airspace system, civil aviation, and agency information systems”. It would require the FAA’s Aircraft Systems Information Security Protection Working Group (ASISPWG) to identify and address cybersecurity risks associated with aircraft systems {§2111(a)(2)(1)(A)} including:

• To assess cybersecurity risks to aircraft systems;
• To review the extent to which existing rulemaking, policy, and guidance to promote safety also promote aircraft systems information security protection;
• Cybersecurity risks associated with in-flight entertainment systems;
• Whether in-flight entertainment systems can and should be isolated and separate, such as through an air gap, under existing rulemaking, policy, and guidance; and
• To provide appropriate recommendations to the Administrator if separate or additional rulemaking, policy, or guidance is needed to address cybersecurity risks to aircraft systems;

Critical Infrastructure Overflight


Section 2209 is a rewrite of §2154 that was adopted from S 2658. It requires the FAA to establish procedures for critical infrastructure facilities to apply to the FAA “to prohibit or restrict the operation of an unmanned aircraft in close proximity to a fixed site facility” {§2209(a)}. The bill would limit such restrictions to the following types of facilities:

• Critical infrastructure, such as energy production, transmission, and distribution facilities and equipment;
• Oil refineries and chemical facilities;
• Amusement parks; and
• Other locations that warrant such restrictions.

Section 2210 is essentially the same language that was found in Senate bill. It would allow critical infrastructure owners more latitude in their use of drones in inspection and monitoring activities.

Moving Forward



With the July 15th authorization deadline fast approaching, it appears that the Senate has accepted the House language on HR 636 by a vote of 89 to 4. The bill will go to the President who will certainly sign the bill.

Wednesday, April 6, 2016

Senate to Consider FAA Authorization as HR 636

The Senate will begin the pre-debate on consideration of HR 636 today. The bill passed by the House as the America's Small Business Tax Relief Act of 2015 will be used as the vehicle for a long-term reauthorization bill for the Federal Aviation Administration (FAA).

The details on the language that will be substituted for the House bill are still being developed. It will be based upon the version of S 2658 that was marked up last month in the Commerce, Science and Transportation Committee, but there will almost certainly be additional items added to that language before it is offered, probably today. The language on cybersecurity and critical infrastructure overflights that I reported on earlier will almost certainly remain in the substitute language, though modifications are possible.

Many observers believe that this may be the last major piece of legislation that will be passed by Congress before the elections. As such it is sure to attract an extensive amendment process on the floor of the Senate. Only two proposed amendments have been published to date, but that will certainly change today.


One issue that has been holding up the publication of the substitute amendment has been the extension of tax breaks for some forms of renewable energy that were overlooked last year in the spending bill. This is one of the reasons that HR 636 will be used as the ‘vehicle’ for this bill instead of considering S 2658; tax related bills must originate in the House.

Saturday, March 19, 2016

S 2658 – FAA and Cybersecurity

Earlier this week the Senate Energy, Commerce and Transportation Committee marked up S 2658, the Federal Aviation Administration Reauthorization Act of 2016. While the bill includes a number of sections on unmanned aviation systems (which I will cover in a later post), there was one section of the bill that concerns cybersecurity and there was an amendment offered in the markup that would have significantly increased the cybersecurity requirements of the bill.

NOTE: The GPO has finally printed a copy of the original bill, but that has already been superseded by substitute language that formed the basis for the Committee markup. All references to the bill in this post refer to that substitute language.

Section 4109


Section 4109 was included in the original version of the bill and made it whole into the substitute language. It is found in Title IV, Subtitle A; Next Generation Air Transportation System (pg 267). It would require the FAA Administrator to {§4109(a)}:

• Identify and implement ways to better incorporate cybersecurity measures as a systems characteristic at all levels and phases of the architecture and design of air traffic control programs, including NextGen programs;
• Develop a threat model that will identify vulnerabilities to better focus resources to mitigate cybersecurity risks;
• Develop an appropriate plan to mitigate cybersecurity risk, to respond to an attack, intrusion, or otherwise unauthorized access and to adapt to evolving cybersecurity threats; and
• Foster a cybersecurity culture throughout the Administration, including air traffic control programs and relevant contractors.

In short, the section recognizes that cybersecurity issues exist and leaves it to the professionals at the FAA to deal with the specifics while providing them the general authority to do so. And, of course, it included a requirement for the obligatory report to Congress after one year.

Markey Amendment


Sen. Markey (D,MA) introduced an amendment that would have virtually re-writen §4109. It started off with a new paragraph (a) that provided definitions of key terms. Those terms included:

• Covered air carrier;
• Covered manufacturer;
• Cyberattack;
• Critical software systems; and
• Entry point.

The paragraph (a) requirements (see above) from the bill would have been made paragraph (b) and the following paragraphs with detailed regulatory requirements would have been added:

• Disclosure of cyberattacks by the aviation industry;
• Incorporation of cybersecurity into requirements for air carrier operating certificates and manufacturer production certificates;
• Annual report to Congress on cyberattacks on aircraft systems as well as maintenance and ground support systems; and
• Managing cybersecurity risks of consumer communications equipment;

In general, Markey’s amendment would have provided the FAA with specific authority to craft the most comprehensive cybersecurity oversight regulations in the Federal government (outside of military contractors, anyway).

The Markey amendment was voted down by a vote of 8-12. The Committee does not provide details of the votes on their web page, but with a 13-11 Republican majority on the Committee, this means that at least 3 Democrats voted against the Markey amendment. In contrast, the overall bill (and the vast majority of the 60 submitted amendments) passed on a voice vote.

Moving Forward


As I remarked in an earlier post this bill will move to the Senate floor fairly quickly. The Senate just started their two week Easter recess, but I suspect that the Committee staff will be hard at work writing the report on this bill. I would not be surprised to see that report filed in one of the three pro forma sessions that the Senate has scheduled over the next two weeks, but at the very latest it should be published in the first full week of April when the Senate returns to Washington.

Commentary

While there is fairly widespread opposition in the cybersecurity community to additional regulation of cybersecurity, I firmly believe that public safety and security require more than voluntary application of cybersecurity principles in certain aspects of our society; especially since there has been such an obvious dearth of that voluntary application. Aviation safety and security, are in my estimation, one of the obvious areas where public good requires legislative and regulatory attention to cybersecurity.

The broadly shaped goals of the adopted version of §4109 can hardly be opposed because of specificity of equipment or protocols. The requirements are written with an absolute paucity of specificity. It does, however, rely upon a significant amount of cybersecurity acumen (if not necessarily technical knowledge) on the part of the FAA administration to establish the minimum level of regulatory oversight that the FAA needs to maintain over carriers and manufacturers to protect the public from cybersecurity vulnerabilities and their deliberate or accidental exploitation.

The provisions of the Markey amendment were a lot more specific in their cybersecurity requirements, but still avoided the problems of specifying techniques or equipment. For example, in the proposed paragraph for air carrier certificate requirements, there was the following mandate {§4109(d)(2)(a)}:

“Require all entry points to the electronic systems of each aircraft operating in the United States airspace[,] and [the] maintenance or ground support systems for such aircraft[,] to be equipped with reasonable measures to protect against cyberattacks, including the use of isolation measures to separate critical software systems from noncritical software systems;”

Unfortunately, the opposition (both inside Congress and out) to any serious specificity in cybersecurity requirements is obvious and in the short term (at least) is clearly in the entrenched majority with substantially bipartisan support. But again, I want to remind people in the cybersecurity community, political support is fickle at best. All it requires is one cyber incident that obviously and publicly puts people in harm’s way or kills people and the politicians in Washington will craft the most demanding and potentially contradictory cybersecurity rules that one could imagine.

The one area of the Markey proposal that I would like to see again considered in any floor action on S 2658 would be a requirement for the reporting of cyberattacks by the aviation industry. I think that the Markey definition of cyberattack needs some work, but the basics are there. The definition in his amendment was: “the unauthorized access to aircraft electronic control or communications systems or maintenance or ground support systems for aircraft, either wirelessly or through a wired connection.” {§4109(a)(3)}.


Markey then went on in paragraph (c) to demand the DOT establish regulations for air carriers and manufacturers to report successful or attempted “cyberattack on any system on board an aircraft, whether or not the system is critical to the safe and secure operation of the aircraft”. Since this would include hacking the onboard entertainment system to get a free move or intercepting someone’s unencrypted wi-fi email, this language is overbroad. If it were limited to ‘electronic control or aircraft communications systems’ and specifically excluded passenger side communications or the entertainment system, it would be a more acceptable requirement.

Thursday, March 17, 2016

Protecting the Sky over CI

Yesterday the American Chemistry Council issued a press release commending the Senate Commerce, Science and Transportation Committee on their adoption of a much modified version of S 2658, the Federal Aviation Administration Reauthorization Act of 2016. An official copy of the bill has yet to be printed by the GPO, but a committee draft was used for mark-up process. The press release said (in part):

“ACC and its members commend Chairman Thune for his leadership on aviation safety and for working closely with Senator Blunt to include a provision to the Senate’s Federal Aviation Administration (FAA) reauthorization bill that will address the troubling gap in current policies regarding the safe operation of drones around chemical facilities. With today’s vote, Congress has taken another important step toward addressing the serious security concerns that have come with this new and rapidly growing technology.”

Background


There were over 50 amendments acted upon during that markup and most were adopted (I’ll have more on that hearing and the bill provisions in a later post). I searched through all of the amendments and could not find anything about protecting chemical plants. I then went back through the substitute language upon which the Committee actually acted. Sure enough I found the provision in §2144.

Now let me first start out by saying that this provision is not the same language that the ACC applauded last month in the House version of the FAA authorization, HR 4441. That bill was passed in committee but will apparently not work its way to the floor because of some intra-party problems.

First a procedural matter; there are a large number of provisions in S 2658 that are applicable to unmanned aircraft systems. Many of those would include additions to 49 USC in a new Chapter 448, Unmanned Aircraft Systems. The provisions of §2144 do not include instructions for adding language to Chapter 448. This may cause some minor administrative problems for the regulations that the FAA Administrator is supposed to craft, but those would be future problems of little interest to Congress. As a side note, the provision in HR 4441 would have been included in 49 USC.

Bill Provisions


Section 2144 would require the Administrator to establish new regulations within 180 days of the enactment of this bill; a very short time frame for any agency, but especially for the FAA, to complete the regulatory process. The purpose of the regulations would be to allow facilities to petition the FAA to “prohibit or otherwise limit the operation of aircraft, including an unmanned aircraft [emphasis added], over a fixed site facility” {§2144(a)}.

While the similar language in the House bill applied only to security regulated chemical facilities (CFATS and MTSA facilities) the coverage in this bill is much more expansive. It includes {§2144(b)(1)(C)}:

• Critical infrastructure;
• Oil refineries and chemical facilities;
• Amusement parks; and
• Other locations that may benefit from such restrictions

The bill provides only the broadest standards for the approval or disapproval of those applications. It allows the Administrator to consider {§2144(b)(2)(C)}:

• Aviation safety;
• Personal safety of the uninvolved public;
• National security; or
• Homeland security

The FAA is required to review those petitions within 90-days. The bill does not require the FAA to provide a notice of why the petition was denied. The Administrator, however, may allow a resubmission of the petition that addresses the reasons for its disapproval. If the petition is approved the FAA will outline {§2144(b)(2)(B)}:

• The boundaries for unmanned aircraft operation [emphasis added] near the fixed site facility; and
• Such other limitations that the Administrator determines may be appropriate.

Moving Forward


This bill is going to the floor of the Senate; the only question is when. I expect that it will get to the floor pretty quickly for the Senate. The current FAA authorization ends at the end of March, but HR 4721 was just approved by the Senate and is on its way to the President to extend that until July 15th (which just happens to be the last day the House and Senate plan to be in session before their election year lengthened summer recess). It would appear that the House and Senate committee staffs have been hard at work crafting a version of this bill that should be able to pass in both bodies.

It will probably take most of a week of floor debate and amending in the Senate. As long as there are no poisoned amendments tacked on to the bill it will pass in the House the following week. The big question is can the Senate get this to the floor before things start to get clogged up with spending bills. Hopefully, it will get to the floor in early April.

Commentary


I never can understand why staff members fail to make legislative mandates such as this a part of the US Code. It really does not make much difference, but it makes it look like this is a temporary measure that does not deserve a place in formal federal law. It does provide another problem which this section very carefully ignores, without being included in a portion of the US Code that includes key definitions, a bill should provide those definitions internally; this bill did not do that for this section.

There is an important internal disconnect in this Section of the bill. It starts off by allowing facilities to petition to limit the operation of aircraft, including an unmanned aircraft. It concludes, however, by only allowing the FAA to set the boundaries for unmanned aircraft operation. I’m pretty sure that many facility owners would prefer to include all aircraft, but the petition and approval processes should apply to the thing.

This bill also has the same severe problem that I identified with the similar provisions in HR 4441; making flight illegal does not stop the aircraft overflights. The bill does include in other sections proposals to require real-time identification of UAS and their pilots sometime in the future, there does not yet exist technology to accomplish that requirement, especially for aircraft currently in the field.

Without being able to identify aircraft violating facility airspace, the only way this prohibition can be effective is to allow the facility owner to take action to take down offending aircraft. That is currently illegal under FAA interpretation of the law that makes it illegal to interfere with an aircraft in flight in the National Air Space (NAS; with exceptions, of course, for actions by duly ordered military aircraft). To be effective, this section should provide some sort of active legal recourse to facility owners.

The provisions of §2144 do not explain how the limitations authorized in {§2144(b)(2)(B)} compare or interact with other restricted airspace designations that the FAA is required to maintain. Nor does it explain how the FAA should go about communicating this information to the UAS flying public. While commercial UAS pilots should be expected to have flight charts available that should allow them to avoid designated restricted air space, it is extremely unlikely that most ‘model aircraft’ UAS pilots would have them available or know how to read them. Ultimately, most experts would prefer to see these designations included in mandatory geofencing firmware within the drone, but we are a long way from being able to require that level of control system sophistication in all covered UAS, much less have a reasonable way to update that firmware with changes to restricted airspace in the NAS.


What probably needs to be added to §2144 is a few study and report provisions that would address these and other not quite so obvious problems with adding additional airspace restrictions to the operations in the NAS. If such provisions were included in this bill with a related sunshine date to force Congress to deal with the results of those studies and reports, then this would probably be a very good first step in limiting the flight of aircraft, including UAS, near critical infrastructure.

Thursday, March 10, 2016

Bills Introduced – 03-09-16

With just the Senate in session yesterday there were only 7 bills introduced. Of those just one may be of specific interest to readers of this blog:

S 2658 A bill to amend title 49, United States Code, to authorize appropriations for the Federal Aviation Administration for fiscal years 2016 through 2017, and for other purposes. Sen. Thune, John [R-SD]


Since the FAA is one of the agencies that could conceivably start regulating control system security, I’ve added it to the list of agencies that I will watch for congressional cybersecurity action in authorization and funding measures. There probably will not be any cybersecurity measures this year, but we did see one minor cybersecurity measure in HR 4441, the House bill on this topic, so I will watch this bill.
 
/* Use this with templates/template-twocol.html */