Showing posts with label S 278. Show all posts
Showing posts with label S 278. Show all posts

Friday, September 28, 2018

Senate HSGAC Committee Amends and Adopts Bills – 09-26-18


Earlier this week the Senate Homeland Security and Governmental Affairs Committee held a business meeting at which a number of bills were considered, amended and ordered favorably reported. As is typical of the Senate committee operations, there are no public copies of the amendments provided before or after hearings. We will have to wait to see the reported version of the bill to see exactly what changes have been made.

S 3405 – CFATS Reauthorization


Sen. Johnson (R,WI) offered substitute language on the bill which was subsequently modified by two amendments by Sen. McCaskill (D,MO). All three amendments were adopted by voice votes as was the final bill.

There was some interesting back and forth between Johnson and McCaskill about this bill. McCaskill was concerned about the lack of bipartisan effort in the writing of this bill. She went so far as to complain about ‘industry being in driver’s seat’ in writing the bill [35:07 in the video]. She gave an example of this continuing during the substitute language development where whistleblower protections were added to last week’s draft of the language but were subsequently removed before this week’s hearing.

At the end of that discussion McCaskill made the comment that the bill “will not get my consent on the floor unless we get the whistleblower protections back in the bill” [39:26]. This referred back to an off-mike discussion between Johnson and the staff where he was apparently reminded that the bill will have to be considered on the Senate floor under the unanimous consent process rather than the ‘normal’ debate and amend process. This is due to the lack of time remaining in the session.

McCaskill had two amendments that were offered, considered, and adopted by voice vote. The first had to do with the recognition program. She noted that that changes were made to recognition program [40:04] and her first amendment would modify that language to authorize a DHS mechanism to recognize stewardship programs.

McCaskill’s second amendment to the bill had something to do with the revised explosive exemption language in the bill. Again, she thought [42:38] that either the original language or the revised language (it is not clear) went too far in bending to the desires of the explosives industry.

McCaskill did not have language ready to put whistleblower language back in the bill. As I noted above she vowed to object to the bill if it came to the floor for consideration without the language. We may see the material added to the bill between the time the report is published and the time that it comes to the floor for a vote.

Other Bills of Interest


There were a total of about 40 bills considered in the hearing this week. Most of them were considered en bloc near the end of the hearing, being passed with a single voice vote. These included:

S 278, the Support for Rapid Innovation Act of 2017 – Substitute language;
S 3085, the Federal Acquisition Supply Chain Security Act of 2018 – Substitute language and additional amendment; and
S 3309, the DHS Cyber Incident Response Teams Act of 2018 – Substitute language and additional amendment;

Commentary


Johnson made a point early in the hearing (in relation to a bill that did not end up being considered) about how the Committee works together in a ‘non-partisan’ manner. This is certainly the normal course of events in the Committee. This makes S 3405 very much an oddity in the process as it was written without the input of the Democrats on the Committee (or the Minority Staff). McCaskill’s displeasure with the process was evident in this week’s hearing, but she will go along with Johnson; as long as her party’s minimum requirements are met (whistleblower language). It is not clear that other Democrats in the Senate (not on the Committee; those McCaskill will almost certainly keep in line) will play along.

One Democrat that will have to be watched with respect to this bill is Sen. Markey (D,MA). With his recent attempts to frame himself as a cybersecurity expert, he might be expected to object to the removal of the cybersecurity risk-based performance standards from the CFATS program. Another senator with an interest in cybersecurity that also might object is Sen. Blumenthal (D,CT). That is, of course, if those provisions remain in the bill as amended.

Sunday, February 12, 2017

S 278 Introduced – Cybersecurity Research

Earlier this month Sen. Daines (R,MT) introduced S 278, the Support for Rapid Innovation Act of 2017. The bill would require the DHS Science and Technology Directorate to support the research, development, testing, evaluation, and transition of cybersecurity technologies.

Cybersecurity Research


The bill would add a new §312, Cybersecurity Research and Development, to Title III of the Homeland Security Act of 2002 (6 USC 181 et seq). The new section outlines a number of areas of cybersecurity research, including {§321(b)}:

• Advancing the development and accelerating the deployment of more secure information systems;
• Improving and creating technologies for detecting and preventing attacks or intrusions;
• Improving and creating mitigation and recovery methodologies;
• Assisting the development and supporting infrastructure and tools to support cybersecurity research and development efforts;
• Assisting the development and support of technologies to reduce vulnerabilities in industrial control systems [emphasis added];
• Assisting the development and support cyber forensics and attack attribution capabilities;
• Assisting the development and accelerating the deployment of full information lifecycle security technologies to enhance protection, control, and privacy of information to detect and prevent cybersecurity risks and incidents;
• Assisting the development and accelerating the deployment of information security measures, in addition to perimeter-based protections;
• Assisting the development and accelerating the deployment of technologies to detect improper information access by authorized users;
• Assisting the development and accelerating the deployment of cryptographic technologies to protect information at rest, in transit, and in use;
• Assisting the development and accelerating the deployment of methods to promote greater software assurance;
• Assisting the development and accelerating the deployment of tools to securely and automatically update software and firmware; and
• Assisting in identifying and addressing unidentified or future cybersecurity threats.

The bill also specifies that no additional funding is provided to support these research efforts. It closes by noting that {§2(c)}: “Such requirements shall be carried out using amounts otherwise authorized.”

Moving Forward


Daines is a member of the Senate Homeland Security and Governmental Affairs Committee, the committee to which this bill was assigned for consideration. This means that there is at least the potential that the Committee will consider this bill. If the bill were considered, it is likely that it would be approved since there are no new regulations or spending authorized by the bill. Similarly, if the bill were to make it to the floor of the Senate, it would likely pass. It is too early to tell if there is the necessary political will to advance this bill.

Back on January 10th the House passed HR 240 by a voice vote with limited debate. HR 240 is a companion bill to S 278 according to the introductory speech (pgs S 657-8) by Daines. There was no committee action on HR 240 in the House Homeland Security Committee.

Commentary


It is a good thing that industrial control systems are specifically mentioned in the bill since the bill relies on the IT limited definition of ‘information system’ both in the bill {new §312(e)(4)} and as a part of the support for the definition of the term ‘incident’ {new §312(e)(4)}. That information system definition is found in 44 USC 35002(8).


Given the funding limitation in this bill and the long list of cybersecurity research activities to be supported, it is extremely unlikely that the bill will result in any new significant cybersecurity research support. But passing the bill would make it look like Congress is doing something; appearances are everything.

Friday, February 3, 2017

Bills Introduced – 02-02-17

Yesterday, with both the House and Senate in session, there were 59 bills introduced. Of those only one may be of specific interest to readers of this blog:

S 278 A bill to amend the Homeland Security Act of 2002 to provide for innovative research and development, and for other purposes. Sen. Daines, Steve [R-MT]

This bill will only be followed here if it contains specific reference to chemical security or cybersecurity research.
 
/* Use this with templates/template-twocol.html */