Showing posts with label S 3309. Show all posts
Showing posts with label S 3309. Show all posts

Friday, September 28, 2018

Senate HSGAC Committee Amends and Adopts Bills – 09-26-18


Earlier this week the Senate Homeland Security and Governmental Affairs Committee held a business meeting at which a number of bills were considered, amended and ordered favorably reported. As is typical of the Senate committee operations, there are no public copies of the amendments provided before or after hearings. We will have to wait to see the reported version of the bill to see exactly what changes have been made.

S 3405 – CFATS Reauthorization


Sen. Johnson (R,WI) offered substitute language on the bill which was subsequently modified by two amendments by Sen. McCaskill (D,MO). All three amendments were adopted by voice votes as was the final bill.

There was some interesting back and forth between Johnson and McCaskill about this bill. McCaskill was concerned about the lack of bipartisan effort in the writing of this bill. She went so far as to complain about ‘industry being in driver’s seat’ in writing the bill [35:07 in the video]. She gave an example of this continuing during the substitute language development where whistleblower protections were added to last week’s draft of the language but were subsequently removed before this week’s hearing.

At the end of that discussion McCaskill made the comment that the bill “will not get my consent on the floor unless we get the whistleblower protections back in the bill” [39:26]. This referred back to an off-mike discussion between Johnson and the staff where he was apparently reminded that the bill will have to be considered on the Senate floor under the unanimous consent process rather than the ‘normal’ debate and amend process. This is due to the lack of time remaining in the session.

McCaskill had two amendments that were offered, considered, and adopted by voice vote. The first had to do with the recognition program. She noted that that changes were made to recognition program [40:04] and her first amendment would modify that language to authorize a DHS mechanism to recognize stewardship programs.

McCaskill’s second amendment to the bill had something to do with the revised explosive exemption language in the bill. Again, she thought [42:38] that either the original language or the revised language (it is not clear) went too far in bending to the desires of the explosives industry.

McCaskill did not have language ready to put whistleblower language back in the bill. As I noted above she vowed to object to the bill if it came to the floor for consideration without the language. We may see the material added to the bill between the time the report is published and the time that it comes to the floor for a vote.

Other Bills of Interest


There were a total of about 40 bills considered in the hearing this week. Most of them were considered en bloc near the end of the hearing, being passed with a single voice vote. These included:

S 278, the Support for Rapid Innovation Act of 2017 – Substitute language;
S 3085, the Federal Acquisition Supply Chain Security Act of 2018 – Substitute language and additional amendment; and
S 3309, the DHS Cyber Incident Response Teams Act of 2018 – Substitute language and additional amendment;

Commentary


Johnson made a point early in the hearing (in relation to a bill that did not end up being considered) about how the Committee works together in a ‘non-partisan’ manner. This is certainly the normal course of events in the Committee. This makes S 3405 very much an oddity in the process as it was written without the input of the Democrats on the Committee (or the Minority Staff). McCaskill’s displeasure with the process was evident in this week’s hearing, but she will go along with Johnson; as long as her party’s minimum requirements are met (whistleblower language). It is not clear that other Democrats in the Senate (not on the Committee; those McCaskill will almost certainly keep in line) will play along.

One Democrat that will have to be watched with respect to this bill is Sen. Markey (D,MA). With his recent attempts to frame himself as a cybersecurity expert, he might be expected to object to the removal of the cybersecurity risk-based performance standards from the CFATS program. Another senator with an interest in cybersecurity that also might object is Sen. Blumenthal (D,CT). That is, of course, if those provisions remain in the bill as amended.

Monday, September 24, 2018

Committee Hearings – Week of 9-23-18


Both the House and Senate are in Washington this week and it is likely to be the last week the House will be in session before the election. A lot of political hearings this week but there are three hearings that may be of interest; HR 6157 conference report, a homeland security markup hearing and cybersecurity in the energy sector.

HR 6157 Conference

On Tuesday the House Rules Committee will hold a hearing on the Conference Report on HR 6157, the FY 2019 DOD and HHS spending minibus. They will formulate the rule for the floor consideration of the bill. This bill will also include new language providing for the continuing resolution (CR) for DHS spending thru December 6th.

The Senate has already acted favorably on the Conference Report and the other two mini-busses have been sent to the White House. Congress has not come this close to finishing spending bills before the end of the fiscal year in quite some time. This may be the most important achievement of the 115th Congress.

Homeland Security Markup


On Wednesday the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting that will include the markup of a number of homeland security related bills, including:

S 3405, Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2018;
S 3309, OHS Cyber Incident Response Teams Act of 2018; and  
• S 594, National Cybersecurity Preparedness Consortium Act of 2017;

There will be a total of 43 bills considered during this meeting, but 21 of them are postal facility naming bills. Most of the remaining bills will be approved by unanimous consent. It will be interesting to see how many amendments are offered on S 3405. The bill did not have any cosponsors when offered and has not acquired any since then. This is unusual in a bill of this type where there is a general consensus on the need for extending the covered program (CFATS).

Unfortunately, we are unlikely to see the text of any of the offered amendments. We will see the revised version of the bill (if changes are made) when the committee report is published in the next month or so (if we are lucky).

Energy Cybersecurity


On Thursday, the Energy Subcommittee of the House Energy and Commerce Committee will hold a hearing looking at “DOE Modernization: The Office of Cybersecurity, Energy Security, and Emergency Response (CESER)”. The witness list has not yet been posted, but a press release notes that the Subcommittee will hear from Assistant Secretary Karen Evens who is in charge of the CESER. The discussions here will almost certainly focus on policy level issues, but cybersecurity will certainly be the overarching topic.

On the Floor

With the mid-term election pending the House will be trying to clean up a lot of miscellaneous business this week with grandstanding and political posturing making the most news, but lots of less controversial stuff being taken care of as well. The HR 6157 Conference Report will be the most important, but the House will also be taking up 54 bills under their suspension of the rules procedure; most of these will pass with significant bipartisan support. Bills of interest here include:

HR 6620 – Protecting Critical Infrastructure Against Drones and Emerging Threats Act; and
HR 6229 – National Institute of Standards and Technology Reauthorization Act of 2018, as amended;

As always there will be limited debate, no floor amendments and a supermajority will be required to pass. Both of these bills will pass; no political posturing here – okay, bipartisan posturing.

Tuesday, August 14, 2018

S 3309 Introduced – Cyber Incident Response Teams


Last month Sen. Hassan (D,NH) introduced S 3309, the DHS Cyber Incident Response Teams Act of 2018. This bill is nearly identical to HR 5074 which was passed in the House in March on a voice vote. The bill essentially authorizes the existing response teams of the US-CERT and ICS-CERT in the National Cybersecurity and Communications Integration Center's (NCCIC).

The differences between the two bills are editorial in nature and are only of interest to legislative grammarians. This new version does still include the same ‘control system security’ language found in the House bill. Similarly, it does not include a definition of ‘control system’.

Moving Forward


Both Hassan and her cosponsor, Sen. Portman (R,OH), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill (and HR 5074) was assigned for consideration. Normally, this would mean that there would be a possibility that the bill could be considered in Committee. This late in the session, however, I suspect that the only consideration that this bill will receive is as a potential amendment to the DHS authorization bill when that bill comes up for consideration after the election.

Nothing in this bill should draw any sort of opposition other than the fact that it would require the House to subsequently reconsider their vote on HR 5074, a cumbersome process going into election season. I suspect that if the Senate were to take up this bill as a stand-alone measure it would consider the House language under the unanimous consent process.

Commentary


Since the existing response teams from NCCIC are already included in the DHS funding, there is no real need in either of these bills for authorization of new funding. It would have been helpful for Congress to increase the funding so that the activities (and number) of these teams could be expanded, but that is unlikely in the current spending climate.

Of specific interest is the language specifically authorizing the use of “cybersecurity specialists from the private sector” {new §148(f)(2)}. This establishes the Congressional intent that these teams are not an inherently governmental service. This may have some interesting legal implications further down the road.

There are two other interesting things missing from this authorization language (in both bills). First, there is no mention of protections for the information gathered by the response teams. This means that there is no specific reason why a Freedom of Information Act request for results of the investigations of these teams should be denied. This could be a cause for organizations to not request support from these teams.

The second is the lack of any requirement for these teams to coordinate their activities with the FBI or some other law enforcement activity. Nor is there any requirement to preserve forensics evidence during the investigations conducted by these teams. At some point the government is going to have to go after the folks conducting these attacks and the preservation of chain of custody and other legal requirements of preserving evidence is going to raise its ugly head.

Wednesday, August 1, 2018

Bills Introduced – 07-31-18

Yesterday with the Senate in Washington and the House meeting in pro forma session there were 27 bills introduced. Of those, two may be of specific interest to readers of this blog:

S 3309 A bill to authorize cyber incident response teams at the Department of Homeland Security, and for other purposes. Sen. Hassan, Margaret Wood [D-NH]

S 3311 A bill to amend title 18, United States Code, to prohibit interference with voting systems under the Computer Fraud and Abuse Act. Sen. Blumenthal, Richard [D-CT]

With such teams already in existence it will be interesting to see the language of S 3309 to see if ICS-CERT is specifically mentioned (probably not) and to see if specific funding authority is provided for these teams.

Any time Congress messes with the Computer Fraud and Abuse Act, cybersecurity researchers need to pay attention. With the obvious interest in protecting voting systems from computer assault, it will be interesting to see how well Blumenthal protects the researchers who will be the ones finding the vulnerabilities.
 
/* Use this with templates/template-twocol.html */