Showing posts with label S 3045. Show all posts
Showing posts with label S 3045. Show all posts

Friday, October 22, 2021

Bills Introduced – 10-21-21

Yesterday, with both the House and Senate in session, there were 57 bills introduced. Four of those bills may receive additional coverage in this blog:

HR 5658 To require the Secretary of Homeland Security to submit a report on the cybersecurity roles and responsibilities of the Federal Government, and for other purposes.  Rep. Bacon, Don [R-NE-2]

S 3035 A bill to establish the Artificial Intelligence Hygiene Working Group, and for other purposes. Sen. Peters, Gary [D-MI]

S 3042 A bill making appropriations for the Departments of Commerce and Justice, Science, and Related Agencies for the fiscal year ending September 30, 2022, and for other purposes.

S 3045 A bill making appropriations for the Departments of Transportation, and Housing and Urban Development, and related agencies for the fiscal year ending September 30, 2022, and for other purposes.

I am not sure what to expect with S 3035. If you google ‘artificial intelligence hygiene’ you get references to the use of AI to modify/control hand washing in medical settings, but I do not think that that is the purpose of this bill. I suspect that it is cybersecurity related. If that is the case, I will be watching the bill for language and definitions that would include industrial control systems within its purview.

I will be covering the three remaining bills.

Monday, August 17, 2020

S 3045 Reported in Senate – CISA Subpoenas


Last month the Senate Homeland Security and Governmental Affairs Committee published their report on S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. The Committee amended and ordered the bill reported at a meeting held in March 2020. . The bill would provide the Cybersecurity and Infrastructure Security Agency (CISA) with the authority to issue subpoenas “for the production of information necessary to identify and notify the [an] entity at risk”.

Subpoenas Limited to ISP’s?


I noted in my commentary on the introduction of S 3045 that:

“Much has been made in the more popular press (see here for example) about how this bill would allow CISA to issue these subpoenas to information services providers. This would certainly be helpful where CISA has been able to identify an IP address where a vulnerable system exists, but needs point of contact information from the ISP.”

There is nothing in the bill that specifically limits the application of the new CISA subpoena authority to just ISPs. In fact, there are just two mentions in the bill that would reference statutes applicable to ISPs. In the new §659(o) being added by the bill subparagraphs (2)(B)(i) and (2)(C) both refer to 18 USC 2703, Required disclosure of customer communications or records. The first two paragraphs of §2703 deal with obtaining copies of electronic communications while paragraph (c)(2) allows, upon application of an administrative subpoena “authorized by a Federal or State statute”, a Federal agency to require a “provider of electronic communication service or remote computing service” certain limited information about a “a subscriber to or customer of such service”.

If the intent of this bill were limited to collecting information from ISP’s, the crafters of the bill would have specifically provided reference to §2703(c)(2) in the new §659(o)(2)(A), rewording the final phrase of that sub-section to read:

“the Director may issue a subpoena under 18 USC 2703(c)(2) for the production of information necessary to identify and notify the entity at risk, in order to carry out a function authorized under subsection (c)(12).”

Failing to limit the subpoena authority to the referenced subparagraph means that someone in the crafting process intended to extend the subpoena authority to obtaining information identifying owner/operators of vulnerable equipment in critical infrastructure to other entities than just ISPs. And there is nothing in the language of the report that obviate that conclusion.

Moving Forward


The publication of the Committee Report technically clears this bill for consideration by the full Senate. It is unlikely that this bill would be considered under regular order with the full debate and amendment process. The bill is just not important enough (in the grand scheme of things, it is important to CISA) to take up any of the limited time left in the session to address this bill.

This leaves two options for consideration. The first would be to take this bill up under the unanimous consent process. This bill would allow a single Senator to object to the consideration of the bill to block consideration. I suspect that there would be a number of Democrats that would object to the bill under general principles just to object to anything from DHS without a chance to debate and amend the bill.

The other path would be to add the provisions of this bill to a must pass bill. There is nothing in this bill that would cause serious enough objections to stall or even delay a must pass bill. I almost expected this to be added to the new Division E added to S 4049, the FY 2021 NDAA. Sen Johnson (R,WI) did propose similar language as two separate amendments (SA 1807 – pgs S3329-30; and SA 2195 – pgs S3584-5) to that bill. Neither were taken up by the Senate. Neither amendment was taken up on the floor of the Senate.

The only other ‘must pass bill’ that this bill could be appended to would be the DHS spending division of the final omnibus spending bill that may be taken up much later this year.

Sunday, March 15, 2020

HSGA Amends and Adopts S 3045 – CISA Subpoena


Last week the Senate Homeland Security and Governmental Affairs Committee held a business meeting during which they considered S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. Substitute language was offered by Sen Hassan (D,NH), a co-sponsor of the bill. The substitute language was further modified by an amendment offered by Sen Paul (R,TN) and the modified language was subsequently adopted by a voice vote.

Limit on Authority


The original substitute language modified the language of the proposed §2209(o)(2)(B) by adding a new category of limits to the information that the Cybersecurity and Infrastructure Security Agency (CISA) can seek under the new subpoena authority. The added restriction is that a subpoena cannot be seek information on “more than 20 covered devices or systems” {§2209(o)(2)(B)(ii)}.

Information Sharing Within the Government


Both the substitute language and the Rand amendment made changes to the authorization for CISA to share information obtained through the newly authorized subpoena authority.

The substitute language modified New §2209(o)(7)(A)(ii) by adding two new clauses; additionally allowing the Agency to share information received with another Federal agency if a cybersecurity incident is involved and:

• The Director determines that sharing the nonpublic information with another Federal agency is necessary to take law enforcement or national security actions pertaining to such incident; and
• The entity to which the information pertains is notified of the Director’s determination, to the extent practicable consistent with national security or law enforcement interests

The Paul amendment would modify that authority requiring the affected entity to consent to the disclosure unless “another Federal agency identifies the entity to the Agency in connection with a suspected cybersecurity incident” {new §2202(o)(7)(A)(iv)}.

The Paul Amendment also added a new paragraph (12) that further restricted the sharing of information with other Federal agencies. It would prohibit the sharing of any information produced as a result of the subpoena with “any other Federal agency for any purpose other than a cybersecurity purpose” as defined in 6 USC 1501.

Information Sharing with Affected Entity


The substitute language would revise the proposed §2202(o)(7) by adding a new sub-paragraph (F) that would require CISA, when notifying an entity at risk, to include:

• A discussion or statement that responding to, or subsequent engagement with, the Agency, is voluntary; and
• To the extent practicable, information regarding the process through which the Director identifies security vulnerabilities.

The substitute language also modified the language of §2202(o)(7)(C) requiring, after information received as a result of a subpoena showed that the covered entity was not a critical infrastructure entity, that the affected entity be informed about the vulnerability information before the contact information for the entity was destroyed.

Moving Forward


Once the Committee submits their report on the bill along with the amended language, the bill would be cleared for consideration by the full Senate. It seems to me, however, that this bill is still too controversial to be considered under the Senate’s unanimous consent process; some one would object. That would require the bill to be considered under regular order. That is too time consuming this late in the session and the Senate leadership would never bring it to the floor. The only other hope for this bill is for it to be included in a CISA authorization bill, which may be high-enough priority to be considered under regular order.

I am going to add a new caveat to this ‘moving forward’ discussion; COVID-19. At the seriousness of this epidemic becomes more apparent and the economic consequences become more painful, the normal operations of the House and Senate are going to become affected as a lot of priorities shift. Add to the fact that we are inevitably going to see a number of legislators and their staffs personally affected by the disease and that is going to affect the legislative process in ways that are going to be difficult to predict.

Commentary


I think that the changes made this week by the Committee are all worthwhile changes. I will note that changes did address two items that I noted in my original post about S 3045. My proposed language changes at the end of that post were not specifically made, but the new language for that clause achieves the same end. I will pretend that I helped that change along.

The other change addressed the objections of a number of commenters about the broader than popularly described scope of the subpoena authority. The way this bill written, even after the changes here, does not limit the CISA subpoena power to just contact information from ISPs. As I noted in that post:

“A more effective use of this subpoena power, however, would be to contact control system equipment vendors or integrators about owners of equipment with known cybersecurity vulnerabilities, particularly where those vulnerabilities do not yet have effective mitigation measures available. There is nothing in this bill that would prevent such subpoenas.”

Well, the new language does hinder that use of the subpoena authority by limiting the use “for not more than 20 covered devices or systems”. A clever subpoena crafter could still gain valuable information from a Siemens or Rockwell about owners of vulnerable devices, but there would be some very real limits on that information as a result of this change. Those limits could deny CISA timely information that would prevent a cyberattack on critical facilities.

Does this make this a bill that should not pass? Of course not. No legislation is going to be perfect in a representative democracy. Compromises must be made to get bills passed and signed into law. The CISA subpoena authority is important, and if some limits have to be placed on that authority for it to become available, so be it.

Monday, March 9, 2020

Committee Hearings – Week of 3-8-20


This week with both the House and Senate in Washington before a week back in their districts the big news in congressional hearings continues to be COVID-19 as well as more budget hearings. There is also a markup hearing in the Senate that will look at a CFATS reauthorization bill and the CISA subpoena bill.

Budget Hearings


Agency
House
DOD
3-10-20 Budget
Coast Guard
3-10-20 A-DHS
CG/TSA
3-11-20 HS-S
CISA/S&T
3-11-20 HS-S
ARPA-E
3-11-20 A-EWR

Budget – Budget Committee
A-DHS – Appropriations – DHS Subcommittee
HS-S – Homeland Security Subcommittee
A-EWR – Appropriations – EWR Subcommittee

The Senate will also be holding budget hearings, but the ones that are scheduled are not agencies that I closely follow in this blog.

Senate Markups


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting that will include marking up 15 bills. Those will include:

S 3045, Cybersecurity Vulnerability Identification and Notification Act of 2019;
• S 3416, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2020; and
S 3207, Cybersecurity State Coordinator Act of 2020;

The CFATS bill is still not available for review. Hopefully, I will see it before Wednesday.

On the Floor


As I noted yesterday the Senate will resume consideration of S 2657, the comprehensive energy bill. There is a vote on SA 1407, the substitute language, at 5:00 pm EDT. Further amendments will likely be considered tomorrow and Wednesday. We should see a final vote this week.

Tuesday, January 28, 2020

HR 5680 Introduced – CISA Subpoena Authority


Today Rep Langevin introduced HR 5680, the Cybersecurity Vulnerability Identification and Notification Act of 2020. The bill would provide the DHS Cybersecurity and Infrastructure Security Agency (CISA) with the authority to issue subpoenas to identify owners of critical infrastructure identified as having cybersecurity vulnerabilities. The bill is similar to S 3045 that was introduced in the Senate last month.

Definitions


There are some significant differences in the definitions used in this bill and S 3045. First it moves the definition of ‘enterprise device or system’ from the new paragraph (n) of 6 USC 659 to paragraph (a), ensuring that the definition is of more general use in that section.

Then HR 5680 changes two existing definitions in (a):

Adds a reference to ‘cybersecurity purpose’: the terms ‘cyber threat indicator’, ‘cybersecurity purpose’ and ‘defensive measure’ have the meanings given those terms in section 102 of the Cybersecurity Act of 2015 [6 U.S.C. 1501];


Changes the definition of ‘information system’: the term ‘‘information system’’ has the meaning given that term in section 3502(8) of title 44; and terms ‘information system’ and ‘security vulnerability’ have the meanings given those terms in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501);

Other Changes from S 3045


The language in HR 5680 is a significant re-write of S 3045, but it is mainly due to the removal of the definition portion of the paragraph. However, in developing a subpoena procedure under (n)(8) the House bill adds a new requirement to include {new §659(n)(8)(A)(v)}:

The process for tracking engagement with each party that is subject to such a subpoena and the entity at risk identified by information obtained pursuant to such a subpoena.

At the end of (n)(8) HR 5689 adds a new congressional notification requirement:

(B) CONGRESSIONAL NOTIFICATION.— The Director shall brief the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate upon establishment of internal procedures and associated training required under this subsection.

Finally, this bill adds a new requirement under new §659(n):

(10) RESOURCE ASSESSMENT.—Not later than 120 days after the date of the enactment of this subsection, the Director shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate an assessment regarding whether additional resources are required to—

‘‘(A)(i) ensure timely notifications to entities at risk pursuant to paragraph (6); and

‘‘(ii) provide such entities at risk with timely support to mitigate security vulnerabilities; and

‘‘(B) provide associated training applicable to employees and operations of the Agency to comply with internal procedures established pursuant to paragraph (8).

Moving Forward


This bill is being considered in the House Homeland Security Committee tomorrow. I suspect that it will be adopted by a significant bipartisan majority. The bill will probably move forward to the House floor later this year under the suspension of the rules process. It will likely pass with similar bipartisan support. The Senate has yet to take action on S 3045. It is not clear whether or not the Senate will accept this version or insist on their own.

Commentary


I applaud Langevin’s addressing my pet peeve, the IT restrictive definition of ‘information system’ used in §659. The addition of the definition of ‘enterprise device’ would currently only apply to this subpoena authorization portion of §659, but it will be available for future changes to CISA authority.

The other changes in this bill do little to address my concerns about S 3045.

Monday, January 27, 2020

Congressional Hearings – Week of 1-26-20


With the House back from their MLK break and the Senate still sitting in their impeachment proceeding there are a limited number of committee hearings this week. There is one markup hearing of interest by the House Homeland Security Committee.

Markup Hearing


On Wednesday the House Homeland Security Committee will hold a markup hearing. The bills to be reviewed include HR 5667, the Cybersecurity Vulnerability Identification and Notification Act of 2019. This bill was introduced last Friday, and the official version has yet to be printed. I have briefly reviewed the committee print and it looks to be similar to S 3045 but there are some interesting definitions related to operational technology that I look forward to reviewing in depth.

Tuesday, December 24, 2019

S 3045 Introduced – CISA Subpoena Authority


Earlier this month Sen Johnson (R,WI) introduced S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. The bill would provide the Cybersecurity and Infrastructure Security Agency (CISA) with the authority to issue subpoenas “for the production of information necessary to identify and notify the [an] entity at risk”.

Definitions


Section 2(a)(1) of the bill would add a definition of ‘security vulnerability’ to 6 USC 659(a); taking that definition from 6 USC 1501(17).

Added CISA Function


Section 2(a)(2) of the bill would also add a new function to the list found in §659(c). That new function would entail “detecting, identifying, and receiving information about security vulnerabilities relating to critical infrastructure in the information systems and devices of Federal and non-Federal entities for a cybersecurity purpose” {new §659(c)(12)}.

Subpoena Authority


Section 2(a)(3) of the bill would add a new subsection (n) to §659, Subpoena Authority. This new subsection starts with a definition of ‘enterprise device or system’. That term would mean {new §659(n)(1)(a)}:

A device or system commonly used to perform industrial, commercial, scientific, or governmental functions or processes that relate to critical infrastructure, including operational and industrial control systems, distributed control systems, and programmable logic controllers.

The definition would specifically exclude {new §659(n)(1)(b)}:

Personal devices and systems, such as consumer mobile devices, home computers, residential wireless routers, or residential internet-enabled consumer devices.

Paragraph (n)(2) would authorize CISA to “issue a subpoena for the production of information necessary to identify and notify the entity at risk, in order to carry out a function authorized under subsection (c)(12).” This authority would apply when CISA “identifies a system connected to the internet with a specific security vulnerability and has reason to believe that the security vulnerability relates to critical infrastructure and affects an enterprise device or system owned or operated by a Federal or non-Federal entity.

The information sought under the subpoena would be limited to the information described in 18 USC 2703(c)(2)(A), (B), (D) and (E). That would include:

• Name;
• Address;
• Length of service (including start date) and types of service utilized;
• Telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and

Once the subpoenaed entity provides CISA with the requested information, CISA would be required, within 7 days, to “notify the entity at risk identified by information obtained under the subpoena regarding the subpoena and the identified vulnerability” {new§659(n)(5)}.

Moving Forward


Johnson is the Chair, and his sole cosponsor {Sen Hassan(D,NH)} is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This bill will almost certainly be considered by the Committee early in the new year. The provision of subpoena powers by Executive Agencies is not taken lightly by Congress, but every effort has apparently been made to develop a bipartisan and bicameral consensus on this measure. I suspect that it will be approved by the Committee. It would most likely be taken up by the full Senate under the unanimous consent process.

Commentary


Okay, let’s get the definitions rant out of the way. The CISA cybersecurity authority rests heavily upon an IT-restrictive definition of ‘information systems’. While the bill provides language that specifically includes “industrial control systems, distributed control systems, and programmable logic controllers”, it still uses terms such as ‘incident’ that rely on that IT-restrictive definition. To avoid that confusion Johnson (really the Committee Staff) should have used this bill as an opportunity to clarify the definition problems that I outlined earlier this year. Okay, that rant is over, let’s move on….

Much has been made in the more popular press (see here for example) about how this bill would allow CISA to issue these subpoenas to information services providers. This would certainly be helpful where CISA has been able to identify an IP address where a vulnerable system exists, but needs point of contact information from the ISP.

A more effective use of this subpoena power, however, would be to contact control system equipment vendors or integrators about owners of equipment with known cybersecurity vulnerabilities, particularly where those vulnerabilities do not yet have effective mitigation measures available. There is nothing in this bill that would prevent such subpoenas. The reference to the wire fraud statute in this bill only reference the types of information that can be requested, not from whom the information can be requested.

There is one peculiar oddity in the bill that probably needs to be addressed. In the (n)(7) paragraph discussion of procedures that CISA is required to develop to support this subpoena authority it calls for {(n)(7)(C)(i)} “immediate destruction of information obtained through the subpoena that the Director determines is unrelated to critical infrastructure” {(n)(7)(C)(i)}. This apparently conflicts with the requirement in (n)(5) to notify the “entity at risk identified by information obtained under the subpoena" regarding the subpoena and the identified vulnerability. It would seem only fair that an identified entity that was subsequently identified as not being ‘related to critical infrastructure’ should be notified of the vulnerability before the information was destroyed by CISA. That conflict could be rectified by changing the wording of (n)(7)(C)(i) to read:

(i) immediate, subsequent to notification under (n)(5), destruction of information obtained through the subpoena that the Director determines is unrelated to critical infrastructure; and

Friday, December 13, 2019

Bills Introduced – 12-12-19


Yesterday with both the House and Senate in session there were 55 bills introduced. Of those three may receive additional coverage in this blog:

S 3033 A bill to establish a K-12 education cybersecurity initiative, and for other purposes. Sen. Peters, Gary C. [D-MI]

S 3040 A bill to amend the Higher Education Act of 1965 to include teacher preparation for computer science in elementary and secondary education. Sen. Rosen, Jacky [D-NV] 

S 3045 A bill to amend the Homeland Security Act of 2002 to protect United States critical infrastructure by ensuring that the Cybersecurity and Infrastructure Security Agency has the legal tools it needs to notify private and public sector entities put at risk by cybersecurity vulnerabilities in the networks and systems that control critical assets of the United States. Sen. Johnson, Ron [R-WI]

Cybersecurity Education


Actually, I doubt that S 3033 and S 3040 will contain language specifically including control system security processes in the required curriculum. That would normally mean that I would not cover these bills here. So I will take this opportunity to get a screed about K-12 education out of my system.

Students are in the K-12 education environment for 13 years for something like 9 months out of the year. A typical school day (minus extracurricular activities) last six to eight hours. In that brief time students are exposed to the basic knowledge necessary for participation in our society. Back in the dark ages when I went to school that consisted of reading, writing, arithmetic, foreign language, history and the arts with a smattering of physical education. Each year the components of those basics became more complex, building on the previous knowledge gained. And the school day was rather full.

Whenever we add new curriculum to that base, decisions have to be made about where the time for teaching the new material will be added. We could increase the number of hours at school, but that would cut into extracurricular activities and besides students can only be expected to take so much time sitting around learning. The alternative it to reduce the time it takes to teach the other subjects or to remove some of those subjects.

It would seem to me that anytime we legislatively attempt to expand the required knowledge base we must also determine where the time will come from to add that instruction. Unfortunately, congresscritters are notorious for adding program requirements without adding resources to effect those requirements. Just let the affected managers make the hard decisions. That way the complaints will be focused on them not congresscritters.

CISA Subpoenas


S 3045 has been in the works for a while now. I have not yet seen the bill, but press accounts (see here for instance) make this seem like a good idea. It would apparently give CISA that power to issue subpoenas to Telecoms to require them to provide contact information for internet addresses where CISA has identified a critical infrastructure vulnerability. That would allow CISA to contact the vulnerable party and work with them to mitigate the vulnerability. Motherhood and Apple Pie, who can object to that? Of course, the devil is in the details.

 
/* Use this with templates/template-twocol.html */