Showing posts with label S 3254. Show all posts
Showing posts with label S 3254. Show all posts

Wednesday, December 19, 2012

Rules Committee to Look at HR 4310 Conference Report


Today the House Rules Committee web site announced a hearing to be held this afternoon to formulate the Rule for the consideration of the Conference Committee Report on HR 4310, the National Defense Authorization Act of FY 2013. The Report includes language for the revised version of HR 4310 that was adopted by the Conference Committee.

Cybersecurity Provisions


Nothing in the final version of the bill directly addresses industrial control system security, but there are a number of cyber provisions in the bill. They include:

§244. Report on cyber and information technology research investments of the Air Force.

§931. Implementation strategy for Joint Information Environment.

§932. Next-generation host-based cyber security system for the Department of Defense.

§933. Improvements in assurance of computer software procured by the Department of Defense.

§934. Competition in connection with Department of Defense tactical data link systems.

§935. Collection and analysis of network flow data.

§936. Competition for large-scale software database and data analysis tools.

§937. Software licenses of the Department of Defense.

§938. Sense of Congress on potential security risks to Department of Defense networks.

§939. Quarterly cyber operations briefings.

§940. Sense of Congress on the United States Cyber Command.

§941. Reports to Department of Defense on penetrations of networks and information systems of certain contractors.

I have covered most of these in some detail in earlier blog posts on the Committee Report on HR 4310, House floor action on the bill, the introduction of S 3254, and the Senate floor action on that bill. Only two of the House provisions made it to the final bill, §244 and §939. There are two provisions that I cannot find in either the House or Senate versions of the bill (§931 and §936), but neither of them deal with cybersecurity so I did not look real hard for the earlier versions.

The three most significant provisions that will almost certainly have an impact on civilian cybersecurity are found in §932, §933, and §941. The host-based cybersecurity systems developed for DOD will almost certainly affect the development of similar systems for non-defense critical infrastructure systems. The software development security protocols should also migrate well to control system development. Finally, the network penetration reporting requirements will almost certainly find their way into any cybersecurity legislation for critical infrastructure protection.

Moving Forward


The rule reported by the Committee will certainly be a closed rule with no floor amendments allowed. There will be a limited debate; probably 40 minutes. And, when this comes to a floor vote on Thursday evening or Friday it will almost certainly pass with a substantially bipartisan vote.

Thursday, December 13, 2012

House Returns Both Versions of NDA to Senate


Yesterday the House passed H. Res 829, a very short measure that returned H 4310 and S 3254 to the Senate without action. Readers of this blog will recall that these two identical bills were passed last week in the Senate and are the National Defense Authorization Act FY 2013.

The two bills were returned because, “in the opinion of this House, contravenes the first clause of the seventh section of the first article of the Constitution of the United States and is an infringement of the privileges of this House” {§1(a)(1)}. This constitutional provision maintains that all “Bills for raising Revenue shall originate in the House of Representatives” {Article 1, Section 7}.

I did not notice a tax provision in the language, but I wasn’t looking for one either. Apparently the Chairman of the House Ways and Means Committee (or more likely the Committee Staff) did, because he was the one responsible for this Resolution. There was no debate on the issue in the House and its full consideration took only 53 seconds.

I thought that it was unusual that the Senate amended HR 4310, substituting the language from the Senate bill as this is typically done with spending bills not authorization bills. That is done to avoid just this type of issue. It appears that in using HR 4310 as the vessel in this case stepped on the toes of the House Ways and Means Chairman as his Committee had no say in that bill.

It will be interesting to see if the Senate takes the matter back up and removes the offending section of the bill or just lets this go until the next session. I kind of expect the latter. If they do that the cybersecurity provisions of the 113th Congress version of this bill will undoubtedly be different.

Wednesday, December 5, 2012

Senate Amends and Passes HR 4310 – NDA Goes to Conference


Last night when I reported on the passage of S 3254 I missed one of those interesting parliamentary moves that show up frequently in the Senate. After passage of their version of the National Defense Authorization bill Sen Reid (D,NV) called up HR 4310, the House version that passed back in May. The Senate then amended that bill by substituting the language from S 3254 for the House language. Now instead of S 3254 going to the House for a vote there will be a conference committee formed to resolve the differences in the two bills.

As best as I can tell in a quick scan of things none of the cybersecurity or cyber-warfare provisions in the two bills are the same. There is no telling what will make it into the final bill until we see the version coming out of conference.

Tuesday, December 4, 2012

Senate Passes S 3254


This evening the Senate passed S 3254 the National Defense Authorization Act FY 2013, by a vote of 98-0. As I noted in earlier blog posts, this bill has a number of cybersecurity and cyber warfare provisions. It will now move to the House for consideration, possibly as early as this week.

Monday, December 3, 2012

Congressional Hearings – Week of 12-03-12


Congress is steadily puddling along taking care of make work while backroom negotiations are dealing with the real problems that will eventually be voted upon. The Hurricane Sandy response will catch some attention this week, but not much else is on the official agenda for committees this week.

CG Authorization


According to the House Majority Leader’s web site the House will consider adopting the Senate amendments to HR 2838, the Coast Guard Authorization bill for 2013. As I noted in an earlier blog post this is a wholesale revision of the bill passed by the House and if there is any discussion on the floor before the vote considered under the suspension of rules (60% required for passage) it may be the first time that some of the new provisions have been debated in any congressional forum.

In any case there are no MTSA or chemical safety/security provisions in this bill. It seems that Congress is no longer interested in the security missions of the Coast Guard.

DOD Authorization


The Senate will continue to consider the DOD Authorization bill (S 3254). They cleared a large number of amendments last week and there is a cloture vote scheduled for this afternoon. There were some cybersecurity/warfare amendments adopted last week; I’ll look at them in some detail later today.

This bill will certainly pass in the Senate this week and should clear the House next week.

Friday, November 16, 2012

The Lazy Duck Session


So much for Sen. Reid’s (D,NV) threat of holding Senators for a vote on S 3254, the National Defense Authorization Act, before Thanksgiving. Yesterday the Senate voted to start their Thanksgiving Recess today. Okay, it wasn’t even a vote; S. Con Res 60 {co-sponsored by Reid and Minority Leader McConnell (R,KY)} was adopted by unanimous consent; I’ll bet that there weren’t but a handful of Senators present.

To be fair, the important stuff that will be dealt with by this post-election session is mainly being done behind the scenes and will not really be debated in public. There will be a couple of short speeches on both sides and the votes will take place. They may be able to get this done before Christmas.

The House is meeting today and will, among other things, vote on S. Con Res 60; probably the last vote of the day. Even if the House doesn’t agree the Senate will just meet in pro forma sessions like they are today.

Oh, yes, S 3254? The Senate started debate today, officially any way, no actual talking about the bill took place. As predicted a number of amendments were offered, fewer than I expected, but none of them dealt with cybersecurity or cyber-warfare issues.

Wednesday, November 14, 2012

Senate begins consideration process for S 3254

Yesterday the Senate began the consideration process (consideration of the motion to proceed to consideration of the bill) for S 3254, the National Defense Authorization Act of 2012. Passage of this bill is one of the priorities for the Lame Duck session. It does contain a number of cybersecurity provisions but none of them specifically address control systems issues.
This is an early part of the consideration process for an important bill. A number of news agencies have reported that it won’t actually be considered until after the Thanksgiving Recess, but Sen. Reid (D,NV) said on the floor of the Senate yesterday that it will be voted on before Thanksgiving.
Yesterday’s action did start the amendment offering process.

Monday, June 11, 2012

S 3254 Introduced – DOD Authorization


This last week Sen. Levin (D,MI) introduced S 3254, the  National Defense Authorization Act for Fiscal Year 2013. While, as expected, there is nothing in this bill that directly addresses ICS security issues, there are some issues raised in Title IX of Division A in the bill that might be of interest to the cybersecurity community. Additional issues are raised in the Committee Report.

Interconnected Networks


Section 923 of the bill requires the Secretary of Defense take actions to “to substantially reduce the number of sub-networks and network enclaves across the Department of Defense, and the associated security and access management controls” {§923(a)}. There are a number of good reasons given for requiring this action; they include:

• Visibility for the United States Cyber Command in the operational and security status of all networks, network equipment, and computers.

• Elimination of redundant network security infrastructure and personnel.

• Rationalization and consolidation of cyber attack detection, diagnosis, and response resources, and elimination of gaps in security coverage.

• Reduction of barriers to information sharing and enhancement of the capacity to rapidly create collaborative communities of interest.

• Enhancement of access to information through authentication-based and identity-based access controls.

• Enhancement of the capacity to deploy, and achieve access to, enterprise-level services.

• Separation of server and end-user device computing to facilitate server and data center consolidation and a more secure tiered and zoned network architecture.

The one thing that seems to be missing from this reasoning is that if Cyber Command has easy ‘visibility’ of all of these networks, it means that an adversary who successfully penetrates one of these networks can achieve that same visibility. Just think about a single low-ranking intelligence analyst’s unfettered access that lead to Wiki Leaks.

Host Based Cybersecurity


Section 924 requires the DOD CIO to “develop a strategy to acquire next-generation host-based cybersecurity tools and capabilities” {§924(a)}. This next-gen capability should eliminate the current problems with signature based threat detection techniques. An important part of this new system is that it be expandable to include more than just intrusion detection. That potential tool set, yet to be developed, should include {§924(b)(2)}:

• Insider threat detection;

• Continuous monitoring and configuration management;

• Remediation following infections; and

• Protection techniques that do not rely on detection of the attack, such as virtualization, and diversification of attack surfaces.

An additional requirement is that it should be “designed for ease of deployment to potentially millions of host devices of tailored security solutions depending on need and risk, and to be compatible with cloud-based, thin-client, and virtualized environments as well as battlefield devices and weapons systems” {§924(b)(2)}.

While this is the holy grail of security systems, if anyone has the resources to get one developed that meets these requirements, it will be DOD and DARPA. Even if they only half-succeed, it will be a major accomplishment. The only question is since such a system will undoubtedly classified, will the Government allow its use by critical infrastructure that needs the same level of protection against similar attackers.

Improving Software Security


While an improved cybersecurity system will go a long way to protecting DOD computer systems, they will only be as secure as the software that runs on those systems. Section 925 would require an improved software acquisition process. This new process would require:

• Update of development and acquisition models {§(925(b)};

• Requirements for secure code development practices {§(925(c)}; and

• Verification of effective implementation {§(925(d)}.

There is an interesting sub-paragraph to this section that has the misleading title of “Study on additional means of improving software security” {§(925(e)}. What it is really being required is a study to look at ways of ensuring that procured software meets the security needs of the Department. The methods suggested include:

• Liability for defects or vulnerabilities in software code.

• So-called ‘‘clawback’’ provisions on earned fees that enable the Department to recoup funds for security vulnerabilities discovered after software is delivered.

• Exemption from liability for rigorous conformance with secure development processes.

• Warranties against software defects and vulnerabilities.

Because of the size of the DOD purchasing pocket book this could be a change in the way that software security is addressed in the market place. If these types of actions become the standards for software security assurance, there will be a wholesale change in the way software is developed and sold; probably an over due change.

Cyber-Operations Facilities


Anyone that has spent time in the military knows that all services have extensive physical facilities where the weapons of war are tested, evaluated, and most importantly where their use is practiced. The Senate Armed Services Committee takes the Department to task in its report for “its lack of attention to its cyber ranges” (pg 67; Adobe 87). An extensive discussion covering three pages of the Committee Report identifies a number of instances where funding and resourcing of existing and developing cyber ranges have declined in recent years.

The Committee requires DOD to prepare a report to Congress that identifies a central management structure for the oversight of cyber range “infrastructure, funding and personnel” (pg 69; Adobe 91). The report will also identify the sources of funding and resources for the modernization and operation of the cyber ranges.

Cybersecurity Personnel


Everyone knows that there is a severe shortage of personnel with a cybersecurity background. The Department of Defense has a large number of personnel slots that need to be filled in this area. The Committee Report notes that “that every effort must be made to successfully recruit, train, and motivate for military service young people with computer skills to operate and defend the Department of Defense’s computer networks and infrastructure” (pg 117; Adobe 139).

The Report requires DOD to provide a ‘letter report’ to Congress within 180 days of this legislation becoming law that:

• Describes current programs for identifying, recruiting, training, and retaining young people with outstanding computer skills for military service;

• Reports any human capital or specialty shortfalls in cyber defense career fields; and

• Describes bonuses or any non-traditional or non-standard recruiting practices that are employed by the military services to locate and recruit young people for cyber-related career fields.

Development of Cybersecurity Expertise


The Committee Report (pg 180, Adobe 202) “encourages the Department of Defense to continue to support multi-disciplinary programs of study and research that focus on developing U.S. cyber security expertise and tackling vital cyber security issues”. Included in those issues, the Committee specifically included the protection of critical infrastructure “which the Department would be called upon to defend in the event of a cyber attack on the United States”.

What is not clear from this discussion is how the Senator’s would expect DOD to impose themselves between such critical infrastructure and cyber-attackers.
 
/* Use this with templates/template-twocol.html */