Showing posts with label S 2987. Show all posts
Showing posts with label S 2987. Show all posts

Saturday, June 16, 2018

Senate Debates HR 5515 – FY 2019 NDAA

After a week of consideration of HR 5515 (with lots of talking and over 300 new amendments proposed), the Senate finally started taking concrete action on Thursday as they were preparing to leave for the weekend. Four recorded votes were taken, three amendments were agreed to, and final consideration of the bill is set for Monday. Thursday’s votes include:

• SA 2700 Cloture (35 to 62)
• SA 2282 Cloture (83 to 14)
• SA 2885 (97 to 0),
• SA 2276 (voice vote),
• SA 2282 (voice vote)
HR 5515 Cloture (81 to 15)

Amendments


Amendment 2282 (pgs S3042-S3223) is the substitute language for HR 5515 that basically comes from S 2987 and specifically includes the cybersecurity provisions that I discussed in that bill. Neither of the other two amendments adopted would be of specific concern to readers of this blog. Amendment 2285 (pg S3916) would establish the John S. McCain Strategic Defense Fellows Program and SA 2276 (pg S3041) would require a report on permanent stationing of United States forces in the Republic of Poland.

Earlier in the day Sen. Lee (R,UT) attempted (pg S3940) to have the Senate consider a bloc of 45 amendments. That block included three that might be of specific interest to readers of this blog:


SA 2509. Sen. Manchin (D,WV) – Report on cyber forces of the reserve components of the armed forces and cyberspace. [Pg S3360]
SA 2721. Sen. Shaheen (D,NH) – Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity. [S3704]
SA 2887. Sen. Sasse (R,NE) – Study on cyber exploitation of members of the armed forces and their families. [S3917-8]

Lee’s request to consider the amendments required unanimous consent and was blocked by Sen. Graham (R,SC) who objected to the language in one of the amendments offered by Sen. Cruz (R,TX). No attempt was made by Lee to retry the en bloc consideration of all but the Cruz amendment.

Moving Forward


The Senate is currently scheduled to finish consideration of HR 5515 on Monday. There is a good chance that additional amendments will be considered individually and in blocks. The Senate will pass the bill with some level of bipartisan support. The differences between the Senate and House versions of the bill will then have to be worked out in conference committee.

Sunday, June 10, 2018

Senate Begins Consideration of HR 5515 – FY 2019 NDAA


Last week the Senate began debating the consideration of HR 5515. By the end of the week the Senate had passed a cloture vote to close that debate and will vote on Monday to begin actual deliberations of the bill. As I noted in an earlier blog post today, the Senate will start off by adopting SA 2282, the Senate’s substitute language taken from S 2987.

While the preliminaries to the actual debate have been taking up legislative time, Senator’s have been filing over 300 proposed amendments to the bill, over and above the substitute language mentioned above. Of those amendments there are 16 that may be of specific interest to readers of this blog:

SA 2285. Mr. WARNER - SEC. 1107. Department of Defense Cyber Scholarship Program [Pg S3224]
SA 2286. Mrs. FISCHER SEC. XXX. Developing Innovation and Growing the Internet of Things. [Pg S3224]
SA 2314. Mr. JOHNSON – SEC. XXX. Preventing Emerging Threats (Unmanned Aircraft) [Pg S3237]
SA 2369. Mr. HOEVEN - SEC. 1066. Sense of Senate on Management of Unmanned Aircraft Systems Traffic Within the National Airspace System. [Pg S3262]
SA 2376. Mr. PERDUE - SEC. XXX. UNITED STATES CYBER STRATEGY. [Pg S3303]
SA 2380. Mr. PERDUE - SEC. XXX. BRIEFING ON CYBER EDUCATION AND TRAINING. [Pg S3306]
SA 2384. Mr. HEINRICH - SEC. 1636A. APPOINTMENT OF CYBERSECURITY COORDINATOR. [Pg S3308]
SA 2436. Ms. COLLINS - SEC. XXX. REPORT ON STRENGTHENING NATO CYBER DEFENSE. [Pg S3337]
SA 2458. Mr. WHITEHOUSE - SEC. 1066. UNSAFE OPERATION OF UNMANNED AIRCRAFT. [Pg S3345]
SA 2474. Mr. SCHATZ - SEC. 896. INTEGRATED PUBLIC ALERT AND WARNING SYSTEM. [Pg S3353]
SA 2483. Mr. WYDEN - SEC. XXX. FUNDING FOR NSF CYBER SCHOLARSHIP-FOR-SERVICE PROGRAM. [Pg S3355]
SA 2484. Mr. WYDEN - SEC. XXX. FUNDING FOR NSF CYBER SCHOLARSHIP-FOR-SERVICE PROGRAM. [Pg S3355]
SA 2509. Mr. MANCHIN - SEC. XXX. REPORT ON CYBER FORCES OF THE RESERVE COMPONENTS OF THE ARMED FORCES AND CYBERSPACE. [Pg S3360]
SA 2547. Mrs. SHAHEEN - SEC. 1626. ASSISTANCE FOR SMALL MANUFACTURERS IN THE DEFENSE INDUSTRIAL SUPPLY CHAIN ON MATTERS RELATING TO CYBERSECURITY. [Pg S3373]
SA 2564. Mr. RUBIO SEC. XXX. PILOT PROGRAM TO TEST MACHINE-VISION TECHNOLOGIES TO DETERMINE THE AUTHENTICITY AND SECURITY OF MICROELECTRONIC PARTS IN WEAPON SYSTEMS. [Pg S3380]
SA 2567. Mr. WARNER - Subtitle G—Internet of Things Cybersecurity Improvement Act [Pg S3382]

Needless to say, very few of these amendments will make it to the floor of the Senate for consideration. And, as the consideration of the bill continues, there will be more amendments offered right up to the final cloture vote leads to a final floor vote on the bill. Given the large disparity between the number of amendments offered and those that actually get approved; I will hold off on analysis of the amendments until they are adopted.

S 2987 Introduced – FY 2019 NDAA


Last week Sen. Inhofe (R,OK) introduced S 2987, the John S. McCain National Defense Authorization Act for Fiscal Year 2019. The bill contains one subtitle (Subtitle C of Title XVI) that specifically address cyber matters including cybersecurity for industrial control systems (ICS).

Subtitle C


Part 1 of Subtitle C deals with general cyber matters. The sections include:

§ 1621. Policy of the United States on cyberspace, cybersecurity, cyber warfare,
and cyber deterrence.
§1622. Affirming the authority of the Secretary of Defense to conduct military
activities and operations in cyberspace.
§1623. Active defense and surveillance against Russian Federation attacks
in cyberspace.
§1624. Reorganization and consolidation of certain cyber provisions.
§1625. Designation of official for matters relating to integrating cybersecurity and industrial control systems within the Department of Defense.
§1626. Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity.
§1627. Modification of acquisition authority of the Commander of the United States Cyber Command.
§1628. Email and Internet website security and authentication.
§1629. Matters pertaining to the Sharkseer cybersecurity program.
§1630. Pilot program on modeling and simulation in support of military homeland defense operations in connection with cyber attacks on critical infrastructure.
§1631. Security product integration framework.
§1632. Report on enhancement of software security for critical systems.
§1633. Comply to connect and cybersecurity scorecard.
§1634. Cyberspace Solarium Commission.
§1635. Program to establish cyber institutes at institutions of higher learning.
§1636. Establishment of Cybersecurity for Defense Industrial Base Manufacturing

Part II of Subtitle C deals with the mitigation of risks posed by providers of information technology with obligations to foreign governments. This part uses an unusual definition of ‘information technology’ from 40 USC 11101 that specifically includes “imaging peripherals, input, output, and storage devices necessary for security and surveillance” {§11101(6)(B)}. The part also specifically refers to ‘industrial control system’ without providing a definition of the term.

The sections in Part II include:

§1637. Definitions.
§1638. Identification of countries of concern regarding cybersecurity.
§1639. Mitigation of risks to national security posed by providers of information technology products and services who have obligations to foreign governments.
§1640. Establishment of registry of disclosures.

ICS Cybersecurity


Section 1625 (on pgs 731-2) requires DOD to designate one official “to be responsible for matters relating to integrating cybersecurity and industrial control systems within the Department of Defense” {§1625(a)}. That official would be responsible for all ICS cybersecurity matters for all levels of command down to the “facility using industrial control systems, including developing Department-wide certification standards for integration of industrial control systems” {§1625(b)}.

Section l636 (on pgs 769-70) requires DOD “establish an activity to assess and strengthen the cybersecurity resiliency of the defense industrial base of the United States” {§1636(a)(1)}. It would be known as the ‘Cybersecurity for Defense Industrial Base Manufacturing Activity’. The purpose of the Activity would be “to explore ways to increase the
 cybersecurity resilience of the defense industrial supply chain” {§1636(b)} to include:

• Developing cybersecurity test capabilities to support identifying and reducing security vulnerabilities in defense industrial base manufacturing processes.
• Developing in-person and online training to help small defense industrial base manufacturers improve their cybersecurity.
• Ensuring that cybersecurity for defense industrial base manufacturing is included in Department of Defense research and development roadmaps and threat assessments.
Aggregating, developing, and disseminating capabilities to address cybersecurity threats that can be provided to and adopted by defense industrial base manufacturers of all sizes.

The definition of ‘security vulnerability’ used by this section relies on the ICS-inclusive definition of ‘information system’ found in 6 USC 1501.

Foreign Government Influence


Section 1638 would require DOD to produce a “prioritized list of countries of concern regarding cybersecurity" {§1638(a)} based upon:

• A foreign government’s engagement in acts of violence against personnel of the United States or coalition forces.
• A foreign government’s willingness and record of providing financing, logistics, training or intelligence to other persons, countries or entities posing a force protection or cybersecurity risk to the personnel, financial systems, critical infrastructure, or information systems of the United States or coalition forces.
• A foreign government’s engagement in foreign intelligence activities against the United States.
• A foreign government’s direct or indirect participation in transnational organized crime or criminal activity.
A foreign government’s ability and intent to conduct operations to affect the supply chain of the United States Government.

Section 1639 would prohibit DOD from using any “product, service, or system relating to information or operational technology, cybersecurity, an industrial control system, a weapons system, or computer antivirus” {§1639(a)} unless the provider discloses whether the provider has allowed:

A foreign government to review or access the code of a product, system, or service custom-developed for the Department, or is under any obligation to allow a foreign person or government to review or access the code of a product, system, or service custom-developed for the Department as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government.

A foreign government listed in section 1638(a) to review or access the source code of a product, system, or service that the Department is using or intends to use, or is under any obligation to allow a foreign person or government to review or access the source code of a product, system, or service that the Department is using or intends to use as a condition of entering into an agreement for sale or other transaction with a foreign government or with a foreign person on behalf of such a government.

DOD would have to evaluate if any of the disclosure required above would reveal “a risk to the national security infrastructure or data of the United States, or any national security system under the control of the Department” {§1636(c)(1)}. If such a risk were present DOD would be required to determine what actions would be necessary to mitigate such risks.

Moving Forward


This bill will not be considered on the floor of the Senate. It was offered as amendment SA 2282 as substitute language to HR 5515 that is currently being considered in the Senate. The S 2987 language was adopted in Committee by a strongly bipartisan vote of 25 to 2. This means that the base language will be relatively easy to bring to the floor of the Senate. In fact, the first cloture vote on HR 5515 was agreed to on a vote of 92 to 4 on Thursday. The Senate will begin actual consideration of HR 5515 on Monday.

Wednesday, June 6, 2018

Bills Introduced – 06-05-18


Yesterday with both the House and Senate in session there were 36 bills introduced. Of these, three may be of specific interest to readers of this blog:

HR 6001 To safeguard certain technology and intellectual property in the United States from export to or influence by the People's Republic of China and to protect United States industry from unfair competition by the People's Republic of China, and for other purposes. Rep. Conaway, K. Michael [R-TX-11]

S 2987 An original bill to authorize appropriations for fiscal year 2019 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes. Sen. Inhofe, James M. [R-OK]

S 2991 A bill to amend the Rural Electrification Act of 1936 to provide that cybersecurity and grid security improvements are eligible for electric loans and loan guarantees under that Act. Sen. Bennet, Michael F. [D-CO]

The wording of the title for HR 6001 is vague enough to possibly cover industrial control systems, but it probably will not. This bill will probably not be mentioned again in this blog.

 
/* Use this with templates/template-twocol.html */