Showing posts with label S 2993. Show all posts
Showing posts with label S 2993. Show all posts

Monday, November 1, 2021

Committee Hearings – Week of 10-31-21

This week, with both the House and Senate in Washington, there is a relatively light committee schedule. There is one mark-up hearing and two cybersecurity hearings of interest.

Senate Mark-up Hearing

On Wednesday, the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. In addition to three nominations and two postal-naming bills, the Committee will take up 25 bills. That includes bills of interest here:

S 2993, the CISA Cyber Exercise Act,

S 2491, the Defense of United States Infrastructure Act of 2021,

S 2274, the Federal Cybersecurity Workforce Expansion Act,  and

S 2483, the Improving Cybersecurity of Small Organizations Act of 2021

With this large of an agenda, there will be little or no debate during the hearing, but in this Committee that sort of give and take almost always takes place behind closed doors.

Cybersecurity Hearings

On Wednesday the House Homeland Security Committee will hold a hearing on “Evolving the U.S. Approach to Cybersecurity: Raising the Bar Today to Meet the Threats of Tomorrow”. The witness list includes:

• Jen Easterly, CISA, and

• Chris Inglis, National Cyber Director

While not directly in the purview of this Committee, it will be interesting to see if the testimony reiterates previous calls for EPA cybersecurity mandate authority.

On Thursday, the House Transportation and Infrastructure Committee will hold a hearing on “The Evolving Cybersecurity Landscape: Industry Perspectives on Securing the Nation's Infrastructure”. No witness list is currently available. While the Committee certainly (and legitimately) wants to hear from industry, it would seem to me that a panel from TSA and CISA would certainly be appropriate in the current regulatory climate.

On the Floor

We may see the Senate this week formally start the consideration process for HR 4350, the FY 2022 NDAA. We certainly saw enough amendments proposed to that bill last week. The amendment submission process will likely continue in any case. This must pass bill is a great place for Senators to place legislation that could not make it to the floor under regular order.

The House is scheduled to take up three small-business cybersecurity bills this week (only two of which I have covered here) under the suspension of the rules process. Those bills are:

HR 3462 – SBA Cyber Awareness Act,

HR 4513 – Small Business Advanced Cybersecurity Enhancements Act of 2021,

HR 4515 – Small Business Development Center Cyber Training Act of 2021

These bills will have strong bipartisan support, but Republican delaying tactics could result in actual votes being delayed until next week.

The House leadership is still trying to get their two infrastructure bills to the floor for votes. Maybe we will see them this week, maybe not.

Thursday, October 28, 2021

Review - S 2993 Introduced – Cyber Exercise Program

Earlier this month, Sen Rosen (D,NV) introduced S 2993, the CISA Cyber Exercise Act. The bill would amend the Homeland Security Act of 2002 by adding a new §2220A, National cyber exercise program. It would formally establish an existing exercise program to evaluate the National Cyber Incident Response Plan, and other related plans and strategies. No funding is authorized by this bill.

Rosen is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there should be adequate influence available to see this bill considered in Committee. I see nothing in the bill that would engender any organized opposition. I suspect that the bill would receive significant bipartisan support in Committee. The bill is not important enough to be considered under regular order in the Senate, but it might be able to survive the unanimous consent process since it is simply codifying and existing program in DHS.

Commentary

The alert reader will have noticed that §2220A has been used by a number of bills for different proposed amendments to the Homeland Security Act of 2002. This is because this is the next section available in that Act. When any of these bills is finally passed and ready to send to the President for signature, the clerk for whichever body is the last to take action will be authorized to make ‘make such changes as necessary’ to the section numbering. If this happens the way it should, we will not see the ongoing renumbering scrambling that we see in §2(b) in this bill (as we have seen in almost every bill that proposes to add a new §2220A).

For more details about the proposed program requirements, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2993-introduced - subscription required.

Wednesday, October 20, 2021

Bills Introduced – 10-19-21

Yesterday, with both the House and Senate in session, there were 54 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 5616 To require reporting regarding accreditation of basic training programs of the Department of Homeland Security, and for other purposes. Rep. Demings, Val Butler [D-FL-10]

S 2993 A bill to amend the Homeland Security Act of 2002 to establish in the Cybersecurity and Infrastructure Security Agency the National Cyber Exercise Program, and for other purposes. Sen. Rosen, Jacklyn [D-NV]

I will be watching HR 5616 for language and definitions that would indicate that Chemical Security Inspectors would be covered under the provisions of the bill.

S 2993 will be covered in this blog. 

 
/* Use this with templates/template-twocol.html */