Showing posts with label S 2756. Show all posts
Showing posts with label S 2756. Show all posts

Thursday, May 19, 2016

HR 5222 Introduced – Iran Cyber-Sanctions

Last week Rep. Ratcliffe (R,TX) introduced HR 5222, the Iran Cyber Sanctions Act of 2016. The bill would require reports from the President to Congress on conducted on the United States at the behest of the government of Iran. The bill is similar to S 2756 that was introduced in the Senate last month.

Differences between House and Senate Versions


While both bills would require presidential reports on Iranian cyber-attacks on the United States, there are some significant differences. The first, and probably least significant, is that the Senate bill requires the first report within 180 days of enactment of the bill where this bill requires the first report in 90 days.

The most significant difference is also found in Section 2(a)(1) of the respective bills. Both bills require the reports on “significant activities undermining cybersecurity”. The Senate bill requires reports on activities conducted by “Iranian persons” while the House bill targets “by persons on behalf of or at the direction of the Government of Iran”.

Another difference is found in §2(b). The paragraph requires the President to add persons identified in the periodic reports required in this bill to the “designated nationals and blocked persons list maintained by the Office of Foreign Assets Control [OFAC] of the Department of the Treasury” {§2(b)(1)}. The Senate version of the bill also requires listing of “any Iranian person” under indictment for “significant activities undermining cybersecurity against the Government of the United States or any United States person” {§2(b)(1)(B)}. The House version of the bill only addresses “any person”.

The House version of the bill adds a new §2(c). It requires the President to take property blocking actions under EO 13694 for anyone identified in §2(b).

The final area where there are significant differences between the two bills is in the definitions paragraph {§2(d) in the Senate bill; §2(e) in the House bill}. The House bill does not contain a definition of ‘Iranian person’ since that term is not used in the House bill. Additionally the House bill adds another sub-paragraph to the definition of ‘Unites States person’: “any government (Federal, State, or local) entity” {§2(e)(3)(C)}.

Moving Forward


Ratcliffe is not a member of either the House Foreign Affairs or Judiciary Committees; the two committees to which the bill was referred for consideration. This means that it would be extremely difficult for him to influence either committee to consider the bill. The more likely way that this bill could get considered would be to add it as an amendment to an appropriations or authorization bill.

I do not see anything in the bill that would raise any significant opposition to the bill if it were to be considered on the floor of either the House or Senate.

Commentary


The differences between the two versions of the bill would mean that the House bill would not require (but would allow) the President to include in his listings purely criminal attacks on US businesses that originate in Iran. It would seem to me that limiting these requirements to politically motivated attacks would be a more reasonable application of US sanctions.

I am still concerned that the bill continues to ignore control system security, particularly with the recent conversations about vulnerabilities in the National Grid and press reports of Iranian attacks on physical infrastructure. This concern could be rectified by adding a sub-paragraph §2(e)(2)(A)(ii); “interfere with the operation of an industrial control system at any critical infrastructure facility;”.


If Ratcliffe really wants to see this bill become law, rather than just establish his anti-Iranian credentials, he really needs to work at getting co-sponsors to this bill that serve on either the Foreign Affairs or Judiciary (or both) Committees; the higher ranking the better. That way he would have a champion that could apply the appropriate legislative pressures to have the bill considered in Committee.

Sunday, April 10, 2016

S 2756 Introduced – Iran Cyber Sanctions

Last week Sen. Rounds (R,SD) introduced S 2756, the Iran Cyber Sanctions Act of 2016. The bill would require the President to periodically report to Congress on significant activities undermining cybersecurity conducted by Iranian persons against the Government of the United States or any United States person.

Identification and Sanctions


The bill defines ‘significant activities undermining cybersecurity’ as activities that include {§2(d)}:

• Significant efforts to deny access to or degrade, disrupt, or destroy an information and communications technology system or network, or exfiltrate information from such a system or network without authorization;
• Significant destructive malware attacks;
• Significant denial of service activities; and
• Such other significant activities as may be described in regulations prescribed to implement this section.

The President would be required to report to Congress on such activities every 180 days. Persons identified in those reports and any Iranian indicted for such activities would be required to be include on the specially designated nationals and blocked persons list maintained by the Office of Foreign Assets Control of the Department of the Treasury.

Moving Forward


Rounds is a very junior member of the Banking, Housing, and Urban Affairs Committee, so he could possibly have the influence to move this bill forward in Committee. I suspect that this bill could pass in Committee with at least some bipartisan support. With the summer recess fast approaching and spending bills being the political priority (to pass or block depending on your view), this bill is probably unlikely to make it to the floor of the Senate before the election. Unless, of course, there is a high-profile attack attributed (at least politically) to the Iranians; then all bets are off.

Commentary


The bill does use a legal definition of person that includes individuals and organizations. So the reporting requirement would apply to individuals like those indicted for their alleged attacks on the dam control system in New York, as well as major government organizations like the Revolutionary Guards or less important, semi-governmental hacking organizations.

Actually, the example I used for individuals is probably not a good one. There is nothing in the language of this bill that would indicate that attacks on control systems would be included in ‘significant activities undermining cybersecurity’. The bill does not provide a definition of “an information and communications technology system or network”, either directly or by reference. Even if the bill used the more standard ‘information system’, we might infer that the drafter was using the newer usage that included control systems.

It is interesting that the Iranian’s are being targeted with this bill. Most people rank the threat from Russian or Chinese cyber-attacks (government, government inspired, or criminal enterprise) much higher than the Iranian threat (though Iran gets credit for advancing quickly). The fact that we don’t need anything from Iran while we need to get along with both Russia and China for any number of international policy reasons, certainly would not have anything to do with targeting just threat #3 (or maybe #4 depending on how one ranks North Korea).

The other side of the game is that there are any number of also ran governments or international criminal organizations that pose nearly as much of a threat as Iran. The failure to include such organizations in the bill does little or nothing to address the threats posed from those organizations.

In the end, this is a political bill, not a cybersecurity bill. It may have some minor security benefits, but it really looks like a bill to score political points.
 
/* Use this with templates/template-twocol.html */