Showing posts with label S 3600. Show all posts
Showing posts with label S 3600. Show all posts

Monday, March 7, 2022

Review - S 3600 Cyber Incident Reporting Provisions

Last week, the Senate passed S 3600, the Strengthening American Cybersecurity Act of 2022. Title II of that bill is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The seven sections of that title outline the cyber incident reporting program to be established by CISA. It establishes CISA as the action agency for the receipt, processing and sharing of information provided in such reports and establishes a 72-hour reporting standard for covered cyber incidents and a 24-hour reporting standard for making ransomware payments. It also provides CISA 42-months to complete a rulemaking implenting these requirements.

Commentary

 

While a mandatory reporting requirement is long overdue, the reality is that even if this bill were to pass tomorrow, the reporting process will still be years in the making. The rulemaking process is lengthy, with the 24-month NPRM requirement and 18-month final rule publication requirements pushing the process out to three and a half years (plus what ever effective-date delay is included in the final rule) before process goes live. And that is ‘IF’ CISA is able to comply with those time constraints.

 

Congress gave DHS six months to stand up the Chemical Facility Anti-Terrorism Standards (CFATS) program under an interim final rule. That deadline was essentially met and DHS included an NPRM that was not required by the authorizing language. A more reasonable deadline for a cyber incident reporting interim final rule would be somewhere between six months and a year. This is especially true here because the legislation outlines the requirements in quite some detail.

 

For more details about the specific requirements in the legislation, particularly for the rulemaking, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3600-cyber-incident-reporting-provisions   - subscription required.

Wednesday, March 2, 2022

Review - Senate Passes S 3600 – Cybersecurity

Yesterday, the Senate took up S 3600, the Strengthening American Cybersecurity Act of 2022, which was introduced last week. The Senate considered the bill under the unanimous consent process. After adopting two amendments, the Senate passed S 3600 without debate or vote. The bill contains FISMA modifications similar to those found in S 2902, cybersecurity incident reporting requirements similar to those found in S 2875, as well as federal cloud security requirements.

Moving Forward

This strongly bipartisan action by the Senate would seem to grease the skids for this to pass quickly through the House and land on the President’s desk. Unfortunately, there are competing versions of portions of this bill in the House and this bill will have to overcome the ‘my bill first’ claims from at least two different House committees, Homeland Security and Science, Space, and technology. The current concerns about the Russian/Ukrainian related cybersecurity threats, may provide sufficient impetus to bring this bill to the floor of the House. If it gets by the two Chairs, this bill could easily be considered under the House suspension of the rules process and it could be on the President’s desk before the end of the month, or it could still be sitting on the Clerk’s desk at the end of the year.

Commentary:

This bill reflects a great deal of behind the scenes bargaining in the Senate. This will probably be the premier cybersecurity legislation for this Congress. My review today was done quickly to get it out and I am going to have to take a very detailed look at the cyber incident reporting requirements of §203. That post will come out later this week.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/senate-passes-s-3600 - subscription.

Wednesday, February 9, 2022

Bills Introduced – 2-8-22

Yesterday, with both the House and Senate in session, there were 32 bills introduced. One of those bills may receive additional coverage in this blog:

S 3600 A bill to improve the cybersecurity of the Federal Government, and for other purposes. Sen. Peters, Gary C. [D-MI] 

I will be watching this blog for language and definitions that would include control system security within the scope of its provisions.

 
/* Use this with templates/template-twocol.html */