Showing posts with label S 2875. Show all posts
Showing posts with label S 2875. Show all posts

Wednesday, March 2, 2022

Review - Senate Passes S 3600 – Cybersecurity

Yesterday, the Senate took up S 3600, the Strengthening American Cybersecurity Act of 2022, which was introduced last week. The Senate considered the bill under the unanimous consent process. After adopting two amendments, the Senate passed S 3600 without debate or vote. The bill contains FISMA modifications similar to those found in S 2902, cybersecurity incident reporting requirements similar to those found in S 2875, as well as federal cloud security requirements.

Moving Forward

This strongly bipartisan action by the Senate would seem to grease the skids for this to pass quickly through the House and land on the President’s desk. Unfortunately, there are competing versions of portions of this bill in the House and this bill will have to overcome the ‘my bill first’ claims from at least two different House committees, Homeland Security and Science, Space, and technology. The current concerns about the Russian/Ukrainian related cybersecurity threats, may provide sufficient impetus to bring this bill to the floor of the House. If it gets by the two Chairs, this bill could easily be considered under the House suspension of the rules process and it could be on the President’s desk before the end of the month, or it could still be sitting on the Clerk’s desk at the end of the year.

Commentary:

This bill reflects a great deal of behind the scenes bargaining in the Senate. This will probably be the premier cybersecurity legislation for this Congress. My review today was done quickly to get it out and I am going to have to take a very detailed look at the cyber incident reporting requirements of §203. That post will come out later this week.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/senate-passes-s-3600 - subscription.

Sunday, October 24, 2021

Review - HR 5440 Introduced – Cyber Incident Reporting

Last month, Rep Clarke (D,NY) introduced HR 5440, the Cyber Incident Reporting for Critical Infrastructure Act of 2021. Similar to S 2875, this bill establishes the Cyber Incident Review Office in CISA and establishes requirements for cyber incident reporting. It amends the Homeland Security Act of 2002 by adding a new §2220A, Cyber Incident Review Office. No new funding is provided in the bill.

Moving Forward

Clarke and all three of her cosponsors {Rep Thompson (D,MS), Rep Katko (R,NY), and Rep Garbarino (R,NY)} are influential members of the House Homeland Security Committee to which this bill was assigned for consideration. This bill will move forward in Committee, but there will almost certainly be revisions made to the language of the bill before it is approved with strong bipartisan support.

I am not convinced that the strong support in Committee will allow this bill to move to the floor of the House. There will be some inter-committee posturing trying to see more influence on these cybersecurity reporting requirements being retained by existing regulatory agencies. This would ensure that the leadership of other committees would retain their influence on both such reporting and the regulatory responses to those reports. If this bill were to make it to the floor of the House, I suspect that it would receive bipartisan support.

Commentary

I am suitably impressed with the effort that the Committee Staff took in their use of language and definitions to insure that cyberattacks on industrial control systems would be included in the regulations to be developed by CISA. There was one area, however, where that effort fell short. In the proposed §2220A(d)(5)(D) discussion of the content that would be required in the covered reports, bill requires in  clause (iv) that the report includes: “Where applicable, identification of the category or categories of information that was, or is reasonably believed to have been, accessed or acquired by an unauthorized person.” There is no corresponding requirement to report any specific information about operational technology or processes affected by the covered cyberattack. To correct this, I would suggest inserting a new clause (v):

“(v) Where applicable, identification of the operational control system, technology, or devices believed to have been accessed, modified or interrupted by an unauthorized person,”

While the language in this bill and S 2875 are not nearly identical, my comments about the weaknesses in the Senate bill also apply to this bill. To be effective these reporting regulations will have to include provisions for CISA to specifically identify covered facilities and directly notify them of that status and their reporting obligations prior to a cyber incident occurring. Otherwise, facilities will be able to argue that they were unaware that they were specifically considered to be a covered facility with reporting responsibilities under the rules.

I am not sure how CISA would go about accomplishing that task in anything approaching a comprehensive manner. This may be the best argument for letting this designation responsibility remain with other federal regulating agencies and allowing CISA to be the recipient of the required reports.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-5440-introduced - subscription required.

Tuesday, October 5, 2021

Review - S 2875 Introduced – Cyber Incident Reporting

Last month Sen Peters (D,MI) introduced S 2875, the Cyber Incident Reporting Act of 2021. The bill amends the Homeland Security Act of 2002 to establish a Cyber Incident Review Office within CISA and establishes cyber incident reporting requirements, including specific reporting requirements for ransomware incidents. No new spending is authorized by this bill.

As I mentioned yesterday, the Homeland Security and Governmental Affairs Committee will hold a markup hearing tomorrow that will include this bill. While amendments to the language are probably to be expected, this bill will almost certainly pass out of Committee with a favorable report. While the business community would probably rather not see this bill become law, there is a large enough loop-hole (see below) that there will probably not be any strong public opposition to the bill. It will be some-time, however, before this bill makes it to the floor of the Senate for consideration and there will be significant amendments that will further weaken the bill.

Commentary

A major problem with this bill is that there are no provisions to allow CISA to establish an actual list of covered entities, or a requirement to notify covered entities of their specific coverage under the provisions of this bill. The regulations outlined in §2232(b) only allow CISA to provide a “clear description of the types of entities that constitute covered entities”. This allows a private entity to determine, absent specific notification, that they are not covered entities for any number of reasons, real or crafted. This would allow those companies to ignore the reporting requirements of the bill and argue (maybe successfully, maybe not) against an application of a CISA subpoena.

The provisions of §2232 needs to include authorization for CISA to specifically identify entities that it determines meet the criteria in §2232(b) and to notify those entities that they are covered entities and the reason for that identification. Obviously, provisions would have to be made for an appeal process to petition a reversal of that identification, but positive identification would remove the nearly legitimate “I did not think we were a covered entity” defense.

That still leaves the less obvious loophole related to the lack of a clear definition of a ‘covered cyber incident’. This is the same problem that I addressed in relation to the CFATS program new cyber incident reporting guidance. Unfortunately, I do not see a ‘simple’ solution to this. We can hope that CISA could provide a broad enough “clear description of the types of substantial cyber incidents” that existing and yet to be developed cyberattacks would not be able to be ignored by corporate lawyers under the “we just did not think that this was a covered incident” defense.

For more details on the provisions of the bill, see my article at CFSN Detailed Analysis - https://tinyurl.com/nv47z7jy - subscription required.

Monday, October 4, 2021

Committee Hearings – Week of 10-3-21

This week the Senate will be in Washington and the House will be holding hearings mostly remotely. A fairly lite slate of hearing, with just two of interest here. First a hearing on ‘data security’ and second a markup hearing with two cybersecurity bills.

Data Security

The Senate Commerce, Science, and Transportation Committee will hold a hearing on “Enhancing Data Security” on Wednesday. The witness list includes:

• James E. Lee, Identity Theft Resource Center,

• Jessica Rich, Of Counsel, Kelley Drye,

• Edward W. Felten, Princeton University,         

• Kate Tummarello, Engine

I do not normally cover ‘information security’ here, but the description of the Committee web site makes this sound fairly comprehensive:

“This hearing is the second in a series examining the growing urgency to protect consumer privacy and safeguard our data, as well as the need to ensure the Federal Trade Commission is equipped with the authorities and resources to fight digital harms and hold bad actors accountable for increasing privacy violations, data breaches, internet scams, ransomware assaults and other harmful data abuses. The hearing will address major recent cybersecurity incidents, the impact of data breaches on consumers and businesses, and the current state of commercial data security practices.”

I do not really expect that there will be any discussion of control system security issues, but the ransomware discussions may touch on them.

Markup Hearing

On Wednesday the Senate Homeland Security and Governmental Affairs Committee will be holding a business meeting. The agenda reports that, in addition to seven nominations considerations, five markups will be held that include two cyber security bills:

• S 2875, Cyber Incident Reporting Act of 2021, and

• A yet to be introduced, Federal Information Security Modernization Act of 2021.

I have not yet seen the official language for S 2875. It is, however, one of the cyber incident reporting bills that are under consideration in Congress. According to news reports (here, for example) this has a 24-hour reporting deadline. As always though, the devil is in the details. I suspect that the GPO will publish this bill today or tomorrow, so I may be able to review it before the hearing. The second bill is almost certainly an update to the current FISMA program.

Wednesday, September 29, 2021

Bills Introduced – 9-28-21

 Yesterday, with both the House and Senate in session, there were 44 bills introduced. One of those bills will receive additional coverage in this blog:

S 2875 A bill to amend the Homeland Security Act of 2002 to establish the Cyber Incident Review Office in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. Sen. Peters, Gary [D-MI]

 
/* Use this with templates/template-twocol.html */