Showing posts with label S 3905. Show all posts
Showing posts with label S 3905. Show all posts

Monday, December 7, 2020

Conference Report for HR 6395 – FY 2021 NDAA

On Thursday the conferees for HR 6395, the FY 2021 National Defense Authorization Act (NDAA), published their 4500 page ‘Conference Report’ working out the differences between the two versions of the bill. The official GPO version is not yet available, but the House Armed Services Committee posted a copy on their web site. The House is slated to take up the revised language from the report on Tuesday, followed by the Senate later in the week. There is an open threat of a presidential veto, but we will have to wait and see how that turns out.

Provisions of Interest

There are a huge number of ‘cyber’ related provisions in this bill. The following list shows those that I think are most interesting from a control system security point of view.

§1715. Establishment in Department of Homeland Security of joint cyber planning office. (pg 1810) (revised pg 4170)
§1716. Subpoena authority. (pg 1815)
§1717. Cybersecurity State Coordinator. (pg 1827) (revised pg 4170)
§1718. Cybersecurity Advisory Committee. (pg 1836) (revised pg 4170)

§1725. Pilot program on remote provision by National Guard to National Guards of other States of cybersecurity technical assistance in training, preparation, and response to cyber incidents. (pg 1865) (revised pg 4174)

§1729. Cyber capabilities and interoperability of the National Guard. (pg 1880) (revised pg 4175)

§1736. Defense industrial base cybersecurity sensor architecture plan. (pg 1901) (revised pg 4178)

§1737. Assessment on defense industrial base participation in a threat information sharing program. (pg 1903) (revised pg 4179)

§1738. Assistance for small manufacturers in the defense industrial supply chain on matters relating to cybersecurity. (pg 1909)

§1739. Assessment on defense industrial base cybersecurity threat hunting program. (pg 1912) (revised pg 4180)

§1742. Department of Defense cyber hygiene and Cybersecurity Maturity Model Certification framework. (pg 1922) (revised pg 4182)

§1745. Cybersecurity and Infrastructure Security Agency review. (pg 1933)

§1752. National Cyber Director. (pg 1950) (revised pg 4186)

§9005. GAO study of cybersecurity insurance. (pg 3407)

The ‘(pg XXXX)’ listing refers to the language of the actual provision in the bill. The ‘(revised pg 4XXX)’ listing refers to the brief discussion of changes made to the provision in the conference.

Interesting Finds

There is no way that I ‘read’ all 4517 pages of the report. Most of what I did do was put the term ‘cyber’ in the search tool of my .PDF reader and click through the report. In doing so, I discovered a couple of interesting items.

I found the first item on page 680 in §589F. This section introduces a new term that I have never heard before; ‘cyberexploitation’. It is defined as using digital means and online platforms to [§589F(d)(1)]:

• “knowingly access, or conspire to access, without authorization, an individual’s personal information to be employed (or to be used) with malicious intent; or

• “to deceive an individual with misinformation with malicious intent.”

In this section of the NDAA it is used to describe actions taken against family member of armed forces personnel. The bullet in the definition above could apply to all sorts of cyber activities that we have been seeing in recent history. I think that this term (I would hyphenate it ‘cyber-exploitation’) should be more widely used.

I found the second item on page 2247 during the discussion of §2826, Improved electrical metering of Department of Defense infrastructure supporting critical missions. The final subsection shows the increasing cybersecurity sophistication of congressional staffers. It reads:

“(c) CYBERSECURITY.—The Secretary of Defense and the Secretaries of the military departments shall consult with the Chief Information Officer of the Department of Defense to ensure that the electrical energy metering options considered under subsection (b) do not compromise the cybersecurity of Department of Defense networks.”

Intelligence Authorization Act

As I noted in my blog post about the Senate passing HR 3695, the Senate include the FY 2021 Intelligence Authorization Act as a division in the bill. That language did not survive conference. The House has not yet acted on their version of this (HR 7856) ‘must pass’ legislation. The Senate has not acted on their standalone version (S 3905). There is still a chance that some version of this bill could find it into the omnibus spending bill.

Monday, November 16, 2020

HR 7856 Reported in House – FY 2021 Intel Authorization

The House Permanent Select Committee on Intelligence recently published their Report on HR 7856, the Intelligence Authorization Act for Fiscal Year 2021. The reported version of the bill contains no significant changes to the cybersecurity provisions that were included in the introduced version and no new cybersecurity provisions. The Report only includes two discussions of cybersecurity issues.

Cybersecurity and the ABMS

The first cybersecurity discussion is found on pages 17 thru 18 under the heading “Advanced Battle Management Family of Systems”. The Committee insists that given “the sensitive nature of the intelligence information that will act as the backbone of ABMS, it is vital that ABMS use only the most secure tools and technology. To this end the Committee directs the Air Force to work with the National Security Agency to establish “minimum security standards, and build these recommendations into the requirements for ABMS” and to then vet those “technologies to ensure that they meet such standards”.

Cybersecurity and UAS

The other discussion of cybersecurity issues in this report is found on pages 26 thru 27 under the heading “Countering the Malicious Use of Unmanned Aircraft Systems (UAS) in the United States”. The Committee notes that both DHS and the FBI report that UAS can be used maliciously in a number of ways, “including kinetic attacks with payloads of firearms, explosives, or weapons of mass destruction and cyber-attacks against wireless devices or networks [emphasis added]. The Committee directs the Director of National Intelligence to prepare an assessment of the potential UAS threat and a report on potential congressional actions necessary to counteract that threat. The Committee is specifically asking the DNI to:

“Propose what the Federal Government would need—with respect to authorities, regulations, policies, protections for civil liberties and privacy, and resources—to carry out feasibility studies and pilot programs enabling U.S. airports, state and local law enforcement, and critical infrastructure owners [emphasis added] to counter the malicious use of UAS.”

Moving Forward

This is typically considered to be one of those ‘must pass bill’ that is generally produced in a bipartisan manner in Committee and then taken up by the Whole House in a fairly collegial manner. That has not been the case this year.  The ‘Minority Views’ section of the Report (starting on page 151) lays out the Republican objections to this bill in quite some vociferous detail. This bill is likely to move to the floor of the House where it will pass on nearly party lines.

The Senate has not taken up their version of the bill (S 3905). If HR 7856 is passed in the House early enough, the Senate could take it up and substitute the language from S 3905. That language has some minor Democratic opposition {see Sen Widen’s (D,OR) short comment section on pages 18 and 19 of that Committee Report}, but probably not enough to stop the bill from being considered. There would be significant differences to be worked out in a Conference Committee, so many differences that they would probably not be able to be worked out before the 116th Congress closes next month.

I suspect that there are, however, on-going backroom negotiations that could allow for a Division in an FY 2021 spending bill to address necessary intelligence authorization issues. It is an open question on what cybersecurity provisions could make its way into such a division.

Sunday, June 14, 2020

S 3905 Introduced – FY 2021 Intel Authorization


Last week Sen Rubio (R,FL) introduced S 3905, the Intelligence Authorization Act for Fiscal Year 2021. This ‘must pass’ bill would set priorities, funding and authorization for the intelligence community. There are no specific cybersecurity measures in the bill, but there is a requirement for reports about the Cyberspace Solarium Commission Report.

Reporting on Commission’s Recommendations


Section 504 of the bill would establish reporting requirements for various federal agencies about the recommendations made by the Cyberspace Solarium Commission. The Commission was charged by the §1652 of the 2019 NDAA (PL 115-232) to make recommendations for opportunities for the private and public sectors to implement critical changes that could harden United States defenses against cyber-attacks. The five federal agencies included in the reporting requirement are {§504(c)}:

• Office of the Director of National Intelligence,
• Department of Homeland Security (Under Secretary of Homeland Security for Intelligence and Analysis),
• Department of Energy (Director of Intelligence and Counterintelligence),
• Department of Commerce, and
• Department of Defense

The reports, required within 180 days of the adoption of the bill, would be required to include {§504(d)}:

• An evaluation of the recommendations in the report described in subsection (b) that pertain to the agency, and
• A description of the actions taken, or the actions that the head of the agency expects to take, to implement any of the recommendations included in such report.

Moving Forward


Rubio is currently the Acting Chair of the Senate Select Committee on Intelligence. The bill was ordered reported by the Committee (without report) on June 8th, 2020. This bill will be taken up by the full Senate at some point in time and it (or some other version of it) will be amended and ultimately passed by the Senate and the House. That ‘some other version’ caveat has become increasingly necessary for this ‘must pass’ legislation in the last couple of years. Some version of the FY 2021 Intel Authorization Act will ultimately reach the President’s desk.

Commentary


I have not discussed the Cyberspace Solarium Commission Report, mainly because the recommendations are too vague to mean anything besides a call to action. That is why the staff of the Senate Select Committee on Intelligence included §504 in the bill. Unfortunately, they missed an important requirement, making recommendations to Congress on what congressional action would be required to fully implement the Commission’s proposals. A third sub-paragraph needs to be added to §504(d):

“(3) A list of congressional actions that would need to be taken to allow the full implementation of the Commission’s recommendations for the agency.”

Tuesday, June 9, 2020

Bills Introduced – 6-8-20


Yesterday with the Senate in Washington and the House meeting in pro forma session there were 44 bills introduced. One of those bills will receive future coverage in this blog:

S 3905 An original bill to authorize appropriations for fiscal year 2021 for intelligence and intelligence-related activities of the United States Government, the Intelligence Community Management Account, and the Central Intelligence Agency Retirement and Disability System, and for other purposes.  Sen. Rubio, Marco [R-FL] 

 
/* Use this with templates/template-twocol.html */