Showing posts with label S 2943 Amendments. Show all posts
Showing posts with label S 2943 Amendments. Show all posts

Friday, June 10, 2016

More Amendments to S 2943 – FY 2017 NDAA – 06-09-16

Yesterday there were 65 amendments proposed for S 2943, the FY 2017 National Defense Authorization Act. Of those there were only two that may be of specific interest to readers of this blog:
• SA 4642. Mr. BOOKER (D,NJ) - SEC. 1097. Completion of outstanding transportation security requirements. Pg S3742
• SA 4659. Mr. FRANKEN (D,MI) - SEC. ll. Reporting requirements regarding oil well and petrochemical manufacturing plant safety. Pgs S3768-9

The Amendments


The Booker amendment is essentially the same as SA 4531 that he submitted on Tuesday. The only difference is some additional ‘sense of Congress’ language that references a recent DHS IG report on TSA rail security failings. The actual requirements section of the amendment remain the same.

The Franken amendment would require operators of oil wells or oil and gas production facilities to report OSHA safety violations and/or citations in their annual reports to the Security Exchange Commission.

Moving Forward


The Senate continued consideration of S 2943 yesterday, failing to evoke cloture on two amendments which were subsequently withdrawn. An agreement was reached that the Senate would have a cloture vote on the bill this morning. The deadline for submitting amendments to S 2943 was also set for this morning. If the cloture vote succeeds and unless an agreement is reached for an earlier vote on the bill, it will be sometime next week before the bill comes to a vote.

Commentary


These non-DOD related amendments are just another part of the Senate bill (sausage) making process. I would bet that both Booker and Franken are hoping that they can get enough Democratic support for these amendments that they can force McConnell to include their amendment in the consideration process by threatening a ‘No’ vote on the cloture process and stalling consideration of the bill. The fact that Booker revised his amendment indicates that he is actively working that processes. I do not think that it will work for either of these two amendments, but you never can tell.


NOTE: It was announced yesterday that the next spending bill to be considered in the Senate will be the Commerce, Science and Justice (CSJ) bill. The ‘vehicle’ for this bill will be the House bill passed last year (HR 2578) for FY 2016 spending, but the language will be an amendment offered (probably today) based upon S 2837.

Wednesday, June 8, 2016

More Amendments to S 2943 – FY 2017 NDAA – 06-07-16

Yesterday there were 107 Amendments proposed for S 2943, the FY 2017 National Defense Authorization Act, currently under consideration in the Senate. Two of those amendments may be of specific interest to readers of this blog:

• SA 4465. Mr. JOHNSON (R,WI) – SEC. 1097. Critical Infrastructure Protection Act. Pgs S3553-4
• SA 4531. Mr. BOOKER (D,NJ) – SEC. 1097. Implementation of outstanding transportation security requirements. Pg S3589

The Amendments


Johnson’s amendment is essentially the EMP defense language seen in the reported version of S 1846.

The Booker amendment would require the TSA to complete (within six months) two railroad security rulemakings required by the the Implementing Recommendations of the 9/11 Commission Act of 2007 (6 U.S.C. 1162 and 1167). Those requirements address:

§1162 - Railroad carrier assessments and plans
§1167 - Railroad security training program

Moving Forward



The Senate began actual consideration of amendments to S 2943 yesterday. The adopted 18 amendments; all but two by voice votes. None of the amendments that I have been reporting on here were considered. Consideration of amendments continues today and there are two amendment cloture votes scheduled for Thursday. At this point it does not look like the Senate will vote on the bill this week.

Tuesday, June 7, 2016

More Amendments to S 2943 – FY 2017 NDAA – 06-06-16

Yesterday there were a total of 75 additional amendments proposed for S 2943, the FY 2017 National Defense Authorization Act (NDAA). Of those five may be of specific interest to readers of this blog:

• SA 4392. Ms. CANTWELL (D,WA) - SEC. 1641. Training for member of the armed forces on cyber skills for the protection of industrial control systems. Pgs S3440-1
• SA 4399. Mr. DAINES (R,MT) - SEC. 1655. Upgrades to the nuclear command, control, and communications system. Pg S3442
• SA 4413. Mr. CARPER (R,DE) - Subtitle J—Preventing Dirty Bomb Terrorism. Pgs S3449-50
• SA 4423. Mr. PORTMAN (R,OH) - SEC. 526. Plan to meet demand for cyberspace career fields in the reserve components of the armed forces. Pgs S3445-6
• SA 4430. Mr. CARPER - SEC. 1097. Renaming the national protection and programs directorate. Pgs S3458-9

The Cantwell and Portman amendments are pretty generic requirements to develop plans for training cybersecurity personnel. The Daines amendment includes specific (if brief) mention of including cybersecurity in the required upgrades for nuclear weapon command and control systems.

The Carper dirty bomb prevention amendment is mentioned here solely because it adds yet another security program to the list of those that require employee vetting against the Terrorist Screening Database (TSDB). This new requirement would be applied to organizations that were holders of Nuclear Regulatory Agency industrial and commercial licenses under 42 USC 2133. It does not specifically address similar medial licenses under §2134(a).


The Carper NPPD amendment would authorize the planned reorganization of the DHS National Protections and Programs Directorate as the new ‘United States Agency for Cyber and Infrastructure Security’. This is very similar to the as of yet unintroduced bill that the House Homeland Security Committee will be marking up tomorrow.

Wednesday, May 25, 2016

Amendments to S 2943, FY 2017 NDAA – 05-24-16

This afternoon the Senate officially began consideration of S 2943, the FY 2017 National Defense Authorization Act with a cloture vote of 98 – 0. The amendment offering process began on Monday with 13 amendments offered. Yesterday there were an additional 59 amendments offered. To date only one of those amendments may be of specific interest to readers of this blog; relating to the supply chain security of critical telecommunications equipment, technologies, or services.

Supply Chain Security


Sen. Gardner (R,CO) proposed SA 4130 (pg S3118). It would add a new §1641, “Comptroller General of the United States report on department of defense critical telecommunications equipment or services obtained from suppliers closely linked to a leading cyber-threat actor.”

The amendment would require a report to Congress on any critical telecommunications equipment, technologies, or services obtained or used by the Department of Defense or its contractors or subcontractors that is {§1641(a)(1)}:

• Manufactured by a foreign supplier, or a contractor or subcontractor of such supplier, that is closely linked to a leading cyber-threat actor; or
• From an entity that incorporates or utilizes information technology manufactured by a foreign supplier, or a contractor or subcontractor of such supplier, that is closely linked to a leading cyber-threat actor.

Two key terms are defined in the amendment; ‘leading cyber-threat actor’ and ‘closely-linked’. The cyber-threat actor term is linked to the identification as a ‘leading threat actor in cyberspace’ in the “Worldwide Threat Assessment of the US Intelligence Community”, dated February 9, 2016. The term ‘closely-linked’ is used to describe a relationship between one of the identified cyber-threat actors and a foreign supplier, contractor or subcontractor. The term is used to describe that relationship when the supplier, contractor or subcontractor {§1641(c)(2)}:

• Has ties to the military forces of such actor;
• Has ties to the intelligence services of such actor;
• Is the beneficiary of significant low interest or no-interest loans, loan forgiveness, or other support of such actor; or
• Is incorporated or headquartered in the territory of such actor.

Moving Forward


Tomorrow we will start to get some idea of what amendments will be taken up during the consideration of S 2943 and we will continue to see amendments offered tomorrow and (probably) a week from Monday when the Senate comes back from their very extended Memorial day weekend.

The cloture vote today was a good sign that there is nothing fatal in the current language of S 2943. Whether or not that will remain the case as the amendment process moves forward remains to be seen.

Commentary


While the report requirement in Gardner’s amendment is technically targeted at all four countries (Russia, China, Iran and North Korea) listed in World Wide Threat Assessment (pg 3) it would seem to me that Gardner is really expecting the report to focus on China and its telecommunication industry. I think that anyone would have concerns about the potential problems of having communications equipment provided by companies with close ties to the Chinese government or (in particular) the Chinese Army.

This amendment may be exhibiting a tad bit more than a normal amount of paranoia when it includes any company that is incorporated or headquartered in the territory of one of the big four countries of cyber concern (again China is the obvious main target). While it may be hard to identify all of the companies that fall under the first three standards for ‘closely-linked’, the sweeping inclusion of all Chinese chip and equipment makers in the reporting requirements would seem to ensure that it would be extremely difficult to separate the wheat from the chaff in the resulting report.

And it may be my paranoia seeping through, but I am more than a little concerned that the report being required in the amendment is limited to just telecommunications equipment. The universe of electronic and cyber equipment that includes Chinese made chips and components is way larger than just telecommunications equipment. Since this is an amendment to the Defense authorization bill the report should be expanded to include all critical electronic or computer control systems used by DOD and its contractors.

The other thing that is missing from this amendment is any definition of the type of information to be included in the report. The proposed language specifies what types of equipment from what sources should be addressed in the report, but nothing more about the content of the report. For example, Gardner might have required the report to identify:

• What military end equipment or systems contained parts manufactured by a company that is closely-linked with a leading cyber-threat actor;
• Identify if there are other sources of supply of those parts;
• What methods were available to verify that parts from ‘closely-linked’ suppliers met all of the safety, security and quality requirements of the military; and
• What techniques are available to adequately isolate components manufactured by ‘closely-linked suppliers’ from post-installation communications with the military or intelligence agencies of the ‘leading cyber-threat actors’.

This amendment is unlikely to be modified by the current process for consideration of S 2943. To see the types of changes described above, I’m afraid that we would have to see a completely new amendment if my concerns are to be addressed; I’m not holding my breath.


BTW: A real odd amendment was offered yesterday, SA 4141 would add a new division to S 2943. It would add the FY 2017 spending for the State Department to the spending approved in the bill. The State Department and DOD have always had a more than little strained relationship because of their nearly opposite way of dealing with foreign adversaries. Pairing these two departments would be just a tiny bit ironic.
 
/* Use this with templates/template-twocol.html */