Showing posts with label S 2943. Show all posts
Showing posts with label S 2943. Show all posts

Tuesday, October 19, 2021

Review - S 2943 Introduced - Ransom Disclosure

Earlier this month, Sen Warren (D,MA) introduced S 2943, the Ransom Disclosure Act. This is very similar to S 2926 which Warren introduced two days earlier. As with the very slightly earlier bill, S 2943 would require covered individuals to report ransomware payments to DHS and require DHS to publish an annual report to Congress about such ransomware reporting.

Warren is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was referred. This means that there is probably insufficient influence to see this bill considered in Committee. I suspect that there would be little support for this bill in that Committee. I would not be surprised to see this bill included as a potential amendment to a larger authorization bill on the floor of the Senate.

I would like to note that I pointed out each of the three major problems corrected in this version of the bill in my post about S 2926. I cannot, however, claim to have influenced Warren’s staff to make these changes; S 2943 was introduced 5-days before I wrote my ‘influential’ post. Besides, they did not correct the most important problem, the huge definitional loophole.

For more details about the differences between the two bills, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2943-introduced - subscription required.

Thursday, October 7, 2021

Bills Introduced – 10-6-21

Yesterday, with the Senate in Washington and House committees meeting virtually, there were thirteen bills introduced. One of those bills may receive additional coverage here.

S 2943 A bill to require certain entities to disclose to the Secretary of Homeland Security ransom payments, and for other purposes. Sen. Warren, Elizabeth [D-MA]

I will be watching this bill for language and definitions that would include control systems within the coverage of the bill.

We are seeing an increasing number of Senate bills addressing various parts of the cyber incident reporting process. This is a sure sign that the crafters are positioning themselves to be part of the amendment process when a more comprehensive bill reaches the Senate floor.

Friday, December 2, 2016

House Adopts S 2943 Conference Report – 2017 NDAA

Today the House accepted the Conference Report on S 2943, the FY 2017 National Defense Authorization Act (NDAA), by a strongly bipartisan vote of 375 – 34. The cybersecurity provisions of both HR 4909 and the Senate version of S 2943 were included in the final version with some modifications.

Cybersecurity Provisions


The cybersecurity provisions in the bill included (the page numbers refer to the explanation of the provision in the Conference Report):

Sec. 1641 [HR 4909, §1631] Special emergency procurement authority to facilitate the defense against or recovery from a cyber attack (pg 2717);
Sec. 1642 [S 2943, §1633] Limitation on termination of dual-hat arrangement for Command of the United States Cyber Command (pg 2717);
Sec. 1643 [S 2943, §1632] Cyber mission forces matters (pgs 2717-8);
Sec. 1644 [HR 4909, §1633] Requirement to enter into agreements relating to use of cyber opposition Forces (pg 2718);
Sec. 1645 [S 2943, §1631] Cyber protection support for Department of Defense personnel in positions highly vulnerable to cyber attack (pg 2718);
Sec. 1646 [HR 4909, §1634] Limitation on full deployment of joint regional security stacks (pg 2719);
Sec. 1647 [HR 4909, §1637] Advisory committee on industrial security and industrial base policy (pgs 2719-20);
Sec. 1648 [HR 4909, §1632] Change in name of National Defense University’s Information Resources Management College to College of Information and Cyberspace (pg 2720);
Sec. 1649 [S 2943, §1635] Evaluation of cyber vulnerabilities of F–35 aircraft and support systems (pg 2720);
Sec. 1650 [S 2943, §1637 and §1634] Evaluation of cyber vulnerabilities of Department of Defense critical infrastructure (pg 2721);
Sec. 1651 [HR 4909, §1639] Strategy to incorporate Army reserve component cyber protection teams into Department of Defense cyber mission force (pg 2721);
Sec. 1652 [S 2943, §1636] Strategic plan for the Defense Information Systems Agency (pgs 2721-2);
Sec. 1653 [S 2943, §1638] Plan for information security continuous monitoring capability and comply-to-connect policy; limitation on software licensing (pg 2722);
Sec. 1654 [S 2943, §1639 and §1640] Reports on deterrence of adversaries in cyberspace (pgs 2722-3); and
Sec. 1655 [HR 4909, §1638] Sense of Congress on cyber resiliency of the networks and communications systems of the National Guard (pg 2723).

Control System Security


Control system security is now addressed in two of those sections; §1644 and §1650.

Section 1644 addresses the use and training of cyber opposition forces in military exercises. The Conference Committee added a new subsection (c) that calls for the development of a joint training program and certification “for the protection of control systems”. The development is to be completed by June 30th, 2017.

Section 1650 addresses the evaluation of cyber vulnerabilities within DOD critical infrastructure. It incorporates the ‘cyber informed methodologies’ that I discussed earlier. That terminology is not actually used, but the pilot program required in subsection (b) and the tools for that pilot described in subsection (e) clearly apply to those types of methodologies.

Moving Forward



The Senate is likely to take up the Conference Report next week. They are very likely to accept the report under their unanimous consent procedures.

Thursday, July 7, 2016

Rule for Consideration of S 2943 – FY 2017 NDAA

Last night the House Rules Committee adopted a rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act. As part of the adoption of H Res 809 the language of HR 4909 will be substituted for the language of S 2943. The House would then vote on a motion to insist on its amendment and request a conference.

Since HR 4909 passed along generally party lines, it would be highly unlikely that the Senate would accept the ‘new’ House language for S 2943. The Senate would be expected to also insist on their own language and vote for a conference. It is very probable that the conference could complete its work and both houses accept the conference report before the end of the fiscal year.


The House is currently debating H Res 809. The vote should come later today or tomorrow.

Tuesday, July 5, 2016

Committee Hearings – Week of 7-3-16

This week the House is in town, back from their extended 4th of July holiday. The Senate is taking their ‘week’ off this week and will only be meeting in pro forma sessions. Currently there is only one hearing of interest scheduled for this week; a Rules Committee hearing on the 2017 NDAA.

Hearing


The Rules Committee will be meeting on Wednesday to prepare their rule for the consideration of S 2943, the FY 2017 National Defense Authorization Act (NDAA). The House already passed their version of the bill (HR 4909) which has some important differences from the Senate bill.

It is too early to tell if the House is just going to substitute the HR 4909 language or actually amend the Senate bill. That should be more obvious as we get closer to the hearing.

On the Floor



The House will take up S 2943 sometime later this week. They will also be considering HR 4361, a federal information security bill; not one that I have been following.

Wednesday, June 15, 2016

S 2943 Passed in Senate – FY 2017 NDAA

Yesterday the Senate completed consideration of S 2943, the FY 2017 National Defense Authorization Act. One additional amendment was adopted and then the bill passed by a strongly bipartisan vote of 85-13.

None of the amendments adopted during the consideration of this bill included cybersecurity language. The original bill did include significant cybersecurity provisions, including a requirement for DOD to conduct a cyber-informed engineering pilot program.

The House passed its own version of the NDAA (HR 4909) last month by a more partisan vote. There will almost certainly be a conference committee to iron out the differences between the two bills.


According to TheHill.com: “The White House is threatening to veto the Senate version [of the NDAA] over several of its policy provisions, including restrictions on Guantanamo Bay detainee transfers and a cap on the size of the White House National Security Council staff.” There were more than enough Yea votes on S 2943 to overcome a veto, so it is not clear that such a veto would actually be forthcoming if those provisions made it into the compromise bill.

Friday, May 27, 2016

Amendments to S 2943, FY 2017 NDAA – 5-26-16

Yesterday the Senate continued consideration of S 2943, the FY 2017 National Defense Authorization Act. An agreement was reached to continue consideration on June 6th when the Senate returns from their Memorial Day weekend. During the day yesterday a total of 134 amendments were offered for consideration. Two of those amendments may be of specific interest to readers of this blog:

The Amendments


The two amendments of potential interest were

SA 4244 (pg S3302) – Sen. Reed (D,RI) - SEC. 1097. Cybersecurity transparency.
SA 4303 (pg S3322) – Sen. Portman (R,OH) - SEC. 526. Plan to meet the demand for cyberspace career fields in the reserve components of the air force.

The Reed amendment is essentially identical to S 2410 introduced by Reed in December, 2015 establishing cybersecurity expertise requirements for corporate boards. The language does specifically include “industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers” {new §1097(a)(3)(B)} in the definition of ‘information system’.

The Portman amendment would require the Air Force to report to Congress on their plan “for meeting the increased demand for cyberspace career fields in the reserve components of the Air Force, in accordance with the recommendations of the National Commission on the Structure of the Air Force” {new §526(a)}.

Moving Forward


The Senate has only reached agreement on the consideration of one amendment so far (and it is not one of the amendments of concern here), but I expect that we will see a lot more movement when the Senate returns. Either of these two amendments could easily be adopted if they were to be considered in the floor debate.


The Reed amendment is not really a DOD related topic, but the Senate rules are quite generous about the topics that can be added in the amendment process. It all depends on how much political will Reed and any other amendment supporters can bring to bear on the Senate leadership.

Amendments to S 2943, FY 2017 NDAA – 04-25-16

On Wednesday the Senate voted 98 – 0 on a cloture vote to proceed with consideration of S 2943, National Defense Authorization Act for Fiscal Year 2017. Additionally, 93 new amendments were proposed to be considered for that bill. Two of those amendments may be of specific interest to readers of this blog:

SA 4205 (pg S3212) – Sen. Rounds (R,SC) - SEC. 1227. Imposition of sanctions with respect to significant activities undermining cybersecurity conducted on behalf of or at the direction of the government of Iran; and

SA 4226 (pg S3221) – Sen. Cantwell (D,WA) - SEC. 1641. Pilot program on training for national guard personnel on cyber skills for the protection of industrial control systems associated with critical infrastructure.

The Amendments


SA 4205 is almost identical to S 2756 that had been introduced by Rounds last month.

SA 4226 would require the Chief of the National Guard Bureau to establish a pilot program “to provide National Guard personnel with training on cyber skills for the protection of industrial control systems associated with critical infrastructure” {new §1641(a)}. The three year pilot program would be designed to “permit personnel who receive such training to assist National Guard Cyber Protection Teams in carrying out activities to protect systems and infrastructure” {new §1641(c)}. A report to Congress would be required after the pilot program was completed.

Moving Forward



It is still too early to see which amendments will actually reach the floor for consideration. The publication of the Congressional Record for Thursdays session later today may include a partial listing of the amendments that will be considered, but we will probably not know until the Senate returns from their Memorial Day weekend on June 6th exactly what all of those favored amendments will be.

Monday, May 23, 2016

S 2943 Introduced – FY 2016 NDAA

Last week Sen. McCain (R,AZ) introduced S 2943, the National Defense Authorization Act (NDAA) for Fiscal Year 2017. The House version of this bill (HR 4909) passed last week. It provides authorization for military activities for the next fiscal year.

Like the House bill, there is an entire subtitle of this bill (Subtitle C of Title XVI) related to cyber issues. The following sections are listed in that subtitle:

Sec. 1631. Cyber protection support for Department of Defense personnel in positions highly vulnerable to cyber attack.
Sec. 1632. Cyber Mission Forces matters.
Sec. 1633. Limitation on ending of arrangement in which the Commander of the United States Cyber Command is also Director of the National Security Agency.
Sec. 1634. Pilot program on application of consequence-driven, cyber-informed engineering to mitigate against cybersecurity threats to operating technologies of military installations.
Sec. 1635. Evaluation of cyber vulnerabilities of F–35 aircraft and support systems.
Sec. 1636. Review and assessment of technology strategy and development at Defense Information Systems Agency.
Sec. 1637. Evaluation of cyber vulnerabilities of Department of Defense critical infrastructure.
Sec. 1638. Plan for information security continuous monitoring capability and comply-to-connect policy.
Sec. 1639. Report on authority delegated to Secretary of Defense to conduct cyber operations.
Sec. 1640. Deterrence of adversaries in cyberspace.

There are no overlaps between the items found in this subtitle of the bill and the corresponding subtitle of the House version. Two of the sections in this version of the bill may be of specific interest to readers of this blog: §1634 and §1640

Cyber-Informed Engineering


Section 1634 requires the DOD to establish “a pilot program to assess the feasibility and advisability of applying consequence-driven, cyber-informed engineering methodologies to the operating technologies of military installations, including industrial control systems, in order to increase the resilience of military installations against cybersecurity threats and prevent or mitigate the potential for high-consequence cyberattacks.”

While I am waiting for the Armed Forces Committee report on S 2943 to see if there are any additional insights into what the Committee expects to see included in the ‘cyber-informed engineering’ pilot, I did find an interestingpaper [updated link, 23:21 1-28-17]on the topic from a couple of engineers at the Idaho National Laboratory. They note that modern industrial processes are constructed with the assumption that the control system is trusted, an assumption that is increasingly proving to be incorrect. They call for a new engineering design process that takes the potential insecurity of the control system into account as part of the design basis for the entire industrial process.

Deterrence of Adversaries in Cyberspace


In many ways §1640 is similar to HR 5220 and S 2905 in that it requires the President to report to Congress on “determining when an action carried out in cyberspace constitutes an act of war against the United States” {§1640(b)(1)}. The important difference here is that that report only comes after the Joint Chiefs of Staff provide a detailed report to Congress “on the military and nonmilitary options available to the United States to deter Russia, China, Iran, North Korea, and terrorist organizations in cyberspace” {§1640(a)(1)}. This makes the report more of a policy development requirement rather than just a political gotcha game.

Moving Forward


The Senate Armed Services Committee has already completed their action on this bill (and I am expecting their report to be published today or tomorrow) so this bill is cleared to move to the Floor of the Senate. It is being reported on TheHill.com that this bill will come to the floor of the Senate this week, though it is not the first bill slated for floor action today.

There are a number of controversies that could arise in connection with this bill (unrelated to cybersecurity issues) that could slow consideration especially considering that the Senate is heading home for a week of campaigning at the close of the week. It would not be surprising to see some vocal posturing before the Memorial Day Recess and then more reasonable actions following the return to Washington.

When this bill is eventually passed, it will have to go to a conference committee to work out the significant differences with that House over a number of matters. It is not entirely clear at this point that a House-Senate compromise bill would be acceptable to the President as both sides try to make points going into the election. I suspect that a final version of this bill will only be achieved in the lame duck session.

Commentary


It is interesting to see a piece of legislation addressing a new and innovative engineering concept like cyber-informed engineering. It is less surprising that it was found in a defense authorization bill, particularly in the Senate. McCain did after all receive a pretty good technical education at the US Naval Academy. And as a military pilot he did come to have a pretty good personal understanding of the importance of good engineering. I am not saying that he came up with the concept, but he was better able to comprehend its importance when briefed on it by DOD than a less technologically trained congress critter would have.


In many ways the chemical engineering profession has embraced the basic idea behind this new engineering concept in the way they that have developed their stand-alone safety systems. Those systems were not developed with cybersecurity in mind, but rather to deal with problems with another less-than-trusted part of the chemical manufacturing process, the human operator. The lessons that chemical engineers have learned over the last couple of decades in dealing with human-engineering issues should be directly applicable to cyber-informed engineering.

Thursday, May 19, 2016

Bills Introduced – 05-18-16

With both the House and Senate in session yesterday twelve bills were introduced. Actually at this point there were twelve bills introduced in the Senate. Since the House did not adjourn until almost 1:00 am EDT this morning any bills introduced in the House yesterday were not included in yesterday’s listing on Congress.gov. In any case only one of the twelve bills listed may be of specific interest to readers of this blog:

S 2943 An original bill to authorize appropriations for fiscal year 2017 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sen. McCain, John [R-AZ]

NOTE: Title Corrected for date on 5-20-16 07:48 EDT.
 
/* Use this with templates/template-twocol.html */