Showing posts with label S 658. Show all posts
Showing posts with label S 658. Show all posts

Tuesday, May 17, 2022

S 658 Signed by President – Cybersecurity Consortia

Last week, President Biden signed S 658, the National Cybersecurity Preparedness Consortium Act of 2021. Yesterday, the bill was assigned the Public Law number PL 117-122 (it will be months before the PL is actually printed).

As I have noted earlier the provisions in this bill allowing NCCIC to work with a consortium of non-profit entities to “develop, update, and deliver cybersecurity training in support of homeland security” are simply acknowledgement of DHS activities that have been taking place for a number of years. Since there is no new funding authorized in this bill, Congress again takes credit for work already done by DHS without spending any money or political capital.

Saturday, April 9, 2022

Senate Agrees to House Amendments to S 658 – Cybersecurity Consortium

On Thursday, the Senate took up the House message on S 658, the National Cybersecurity Preparedness Consortium Act. That message notified the Senate of the amendment to the bill passed in the House. By unanimous consent, the Senate accepted the amendment. The amended bill now goes to the President for signature.

Again, this bill authorizes existing CISA programs.

Tuesday, March 8, 2022

House Passes S 658 – Cybersecurity Consortium

Yesterday, the House passed S 658, the National Cybersecurity Preparedness Consortium Act by a mostly bipartisan vote of 403 to 19. All 19 negative votes were from Republicans. The bill was considered under the House suspension of the rules process with limited debate. In this case, there was little discussion of the pros and cons of the bill in the debate.

Since the version of the bill passed yesterday was different than that approved in the Senate. The bill goes back to the Senate for approval of the House language. I suspect that the Senate will accept the changes and send the bill to the President.

As I have noted previously, this bill authorizes programs that DHS already has in place. With no new funding authority provided by the bill, this is simply another example of Congress taking action to look like they are taking action.

Monday, March 7, 2022

Committee Hearings – Week of 3-6-22

This week, with both the House and Senate in session, there are no hearings scheduled of particular interest here. There will be some legislative activity of interest, two DHS related bills and some sort of FY 2022 spending bill.

The House is currently scheduled to take up six bills under their suspension of the rules process this week. These include:

HR 5616 – DHS Basic Training Accreditation Improvement Act of 2021, as amended, and

S 658 – National Cybersecurity Preparedness Consortium Act of 2021, as amended

The deadline for passing the FY 2022 (which we are almost half-way through) spending bill is Friday. There are still a number of stumbling blocks holding up an agreement in the Senate on the provisions to be included in the bill. We may see yet another ‘short term’ continuing resolution.

Saturday, October 30, 2021

Review - S 658 Amended in House Committee – Cybersecurity Consortia

On Tuesday the House Homeland Security Committee conducted a markup hearing that included the consideration of S 658, the National Cybersecurity Preparedness Consortium Act of 2021. The Committee adopted substitute language offered by Rep Thompson (D,MS) and ordered the bill reported by a voice vote.  The new language places more emphasis on including minority serving institutions in the consortia. The bill was passed in the Senate in July by unanimous consent.

Once the Committee report on this bill is published this bill will probably move to the floor of the House for consideration under the suspension of the rules process. This will mean limited debate, no floor amendments and would require a supermajority for passage. The bill will receive substantial bipartisan support.

For more details about the changes made in Committee, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-658-amended-in-house-committee   - subscription required. 

Monday, October 25, 2021

Committee Hearings – Week of 10-24-21

This week, with both the House and Senate in Washington, there will be a full slate of hearings in both bodies. There are two hearings of note here; a markup hearing and a hearing on transportation cybersecurity.

Markup Hearing

On Tuesday, the House Homeland Security Committee will hold a markup hearing looking at 12 pieces of legislation.

HR 5616, “DHS Basic Training Accreditation Improvement Act of 2021”,

HR 5658, “DHS Roles and Responsibilities in Cyber Space Act”, and

S 658, "National Cybersecurity Preparedness Consortium Act of 2021",

I have not yet published reviews of HR 5616 and HR 5658. While HR 5616 does not appear to affect chemical security inspector training, it could have future impact on cybersecurity law enforcement teams that could be developed within CISA or TSA. HR 5658 is a ‘report to Congress’ bill that may inform future cybersecurity legislative efforts. S 658 passed in the Senate in July and I do not expect any significant amendments in this week’s hearing.

Transportation Cybersecurity

On Tuesday the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation of the House Homeland Security Committee will hold a hearing on “Transportation Cybersecurity: Protecting Planes, Trains, and Pipelines from Cyber Threats.” The witness list includes:

• Suzanne Spaulding, Center for Strategic & International Studies,

• Patricia F.S. Coswell, Guidehouse,

• Jeffrey L. Troy, Aviation Information Sharing and Analysis Center, and

• Scott Dickerson, Maritime Transportation System Information Sharing and Analysis Center

Commentary - It is disappointing to see this industry only panel without having the TSA Administrator providing some insight into what that agency is trying to do with the limited resources it currently has available.

On the Floor

According to the House Majority Leader’s web site, we may actually see a vote on HR 3684, the Infrastructure Investment and Jobs Act. There is a lot of new cybersecurity program language and funding tied up in that bill. This is still tied up in the negotiations over the Build Back Better bill, so do not hold your breath waiting on the vote.

As I noted yesterday, we may see the Senate take up HR 4350, the FY 2022 NDAA, this week. The amendment process for that bill may see additional cybersecurity language added.

Tuesday, August 3, 2021

HR 3684 Debate in Senate – 8-2-21

The Senate continued their debate of HR 3684, the INVEST in America Act. There were 163 new amendments proposed. There were votes on three amendments; two were adopted and one rejected. None of those amendments were of specific interest here. The Debate continues today.

New Amendments

Two of the 163 amendments introduced yesterday may be of interest here. They were:

SA 2209 (pg S 5614) introduced by Sen Cornyn (R,TX). It would add a new subtitle to Division G, Title IV, the National Cybersecurity Preparedness Consortium Act. This is very similar to S 658 that was introduced in April and reported favorably by the Senate Homeland Security and Governmental Affairs in June.

SA 2269 (pg S5671) introduced by Sen Lee (R,UT). It would add a new division, Drone Integration and Zoning. This is very similar to S 600 that was introduced in April. No action has been taken on that bill.

Saturday, July 17, 2021

S 658 Passed in Senate - National Cybersecurity Preparedness Consortium Act

On Thursday the Senate passed S 658, the National Cybersecurity Preparedness Consortium Act of 2021, under the unanimous consent process. There was no debate and no vote (pg S4932). As was noted in the Committee Report on this bill, the language authorizes DHS to deal with the Consortium that it has been dealing with since 2004.

While the House has passed similar legislation in past sessions, there has not been a cyber consortium bill introduced in the House this session. There is a very good chance that the House will take up this bill under their suspension of the rules process as the Senate process demonstrated broad bipartisan support for the bill. I would not be surprised to see this reach the President’s desk before the summer recess.

This bill is a political win-win for Congress. They can look like they are doing something on cybersecurity without authorizing the expenditure of any new funds. DHS has already done the heavy lifting on this program, and it is already included in the budget.

Wednesday, June 16, 2021

S 658 Reported in Senate - National Cybersecurity Preparedness Consortium Act of 2021

Yesterday, the Senate Homeland Security and Governmental Affairs Committee published their report on S 658, the National Cybersecurity Preparedness Consortium Act of 2021. The Committee met on March 17th, 2021, and ordered the bill reported as introduced by a voice vote.

An important point is made in this report (pg 2):

“As a means to address these challenges, DHS has partnered since 2004 with the National Cybersecurity Preparedness Consortium (NCPC), an organization of five university partners that ‘‘provide research-based, cybersecurity-related training, exercises and technical assistance to local jurisdictions, counties, states and the private sector.’’ As of October 2020, NCPC members have trained more than 107,861 participants on topics such as cyberterrorism, critical infrastructure protection, and malware prevention. By leveraging the expertise of a consortium, DHS can better ensure that its partners in the private sector and state and local governments are prepared to assist the Federal Government in its efforts to combat cyber threats. S. 658 codifies an existing DHS practice and helps strengthen DHS’s efforts to partner with the private sector and academia to secure our nation’s cyber infrastructure.

In other words, passing this bill will have no new material effect on the cybersecurity situation in the country. But Congress will claim credit for doing something.

Friday, April 9, 2021

S 658 Introduced – National Cybersecurity Preparedness Consortium Act of 2021

Last month Sen. Cornyn (R,TX) introduced S 658, the National Cybersecurity Preparedness Consortium Act of 2019. The bill would authorize the DHS NCCIC to work with a consortium of non-profit entities to “develop, update, and deliver cybersecurity training in support of homeland security” {§2(1)}. This bill is nearly identical to S 333 that was passed in the Senate last session, but was not taken up in the House.

Definitions

Section 2 of the bill provides definitions of the following four key terms used in the legislation:

Consortium,

Cybersecurity risk,

Department, and

Secretary

The term ‘cybersecurity risk’ is defined by reference to the definition of that term found in 6 USC 659(a).

Assistance to NCCIC

The bill would authorize DHS to work with a consortium primarily composed of nonprofit entities, including academic institutions to assist the National Cybersecurity and Communications Integration Center (NCCIC) in {§3(b)}:

• Providing training to State and local first responders and officials specifically for preparing for and responding to cybersecurity risks and incidents, in accordance with applicable law,

• Developing and updating a curriculum utilizing existing programs and models in accordance with such 6 USC 659, for State and local first responders and officials, related to cybersecurity risks and incidents,

• Providing technical assistance services to build and sustain capabilities in support of preparedness for and response to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism, in accordance with such §659,

• Conducting cross-sector cybersecurity training and simulation exercises for entities, including State and local governments, critical infrastructure owners and operators, and private industry, to encourage community-wide coordination in defending against and responding to cybersecurity risks and incidents, in accordance with 6 USC 660(c),

• Helping States and communities develop cybersecurity information sharing programs, in accordance with §659, for the dissemination of homeland security information related to cybersecurity risks and incidents; and

• Helping incorporate cybersecurity risk and incident prevention and response into existing State and local emergency plans, including continuity of operations plans.

Moving Forward

Neither Cornyn, nor his two cosponsors {Sen Leahy (D,VT) and Sen Boozman (R,AZ)} are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. Typically, this means that there is not adequate influence to have the bill considered in Committee. If the bill were considered, I would expect to see a repeat of the last session’s passage of S 333 by a voice vote.

NOTE: Last session Cornyn was a member of HSGAC.

Commentary

Congress certainly is not going to fund enough positions within CISA to be able to conduct the training, coordinating and planning envisioned in §3(b), so authorizing CISA to use outside agencies to perform these functions makes eminent sense. Unfortunately, nothing in the bill provides any indication of source of funding for these activities. If the end users are going to have to self-fund their participation, they might as well turn to any number of private companies for the support.

(Deep Breath, Hold, Let it Out Slowly) The definition of ‘cybersecurity risk’ used in this bill is based upon the IT restrictive definition of information system that §659 takes from 44 USC 3502. That means that the activities authorized in this bill do not specifically include activities related to cybersecurity issues of industrial control systems, transportation control systems, security systems, building control systems, medical systems or a whole slew of lesser operational technology. This restricted definition does not prevent any of the activities described in this bill being applied to operational technology cybersecurity issues, but it does not provide clear authority to do it either.

Long time readers of this blog have heard my rant about this issue many times before (most completely here). For most things that CISA does (I will admit) that this definition ‘problem’ does not make any significant difference, CISA does a lot of things that it is not specifically authorized to do. If CISA were regulating based upon these definitions, there would be lots of push back from the regulated community and there would probably be substantial support for that push-back from the Courts. Another way this could make problems for the Agency is when Congress starts to restrict or cutback funding, then those operations that are not specifically authorized will be the first to see the trimming.

But, this bill is not the place to make a stand on this particular definitional hill. I just did not want anyone to think that I had dropped the issue.

Thursday, March 11, 2021

Bills Introduced – 3-10-21

Yesterday, with both the House and Senate in session, there were 108 bills introduced. Two of those bills may receive additional coverage in this blog:

HR 1736 To direct the Secretary of Transportation to establish the Strengthening Mobility and Revolutionizing Transportation (SMART) Challenge Grant Program to promote technological innovation in our Nation's communities. Rep. DeSaulnier, Mark [D-CA-11]

S 658 A bill to authorize the Secretary of Homeland Security to work with cybersecurity consortia for training, and for other purposes. Sen. Cornyn, John [R-TX] 

I think that HR 1736 may be a companion bill to S 652 that was introduced yesterday. Again, I will be watching it for language and definitions that indicate that transportation cybersecurity concerns are being addressed.

I will be watching S 658 for language and definitions that specifically address control system security training issues.

Wednesday, May 1, 2013

Cyber Warrior Act Introduced in Senate and House


Identical versions of the Cyber Warrior Act (S 658 and HR 1640) have now been introduced in both the Senate and the House. Originally introduced by Sen. Gillibrand (D,NY) the bills would require DOD to establish National Guard Cyber and Computer Network Incident Response Teams (CCNIRT) in each State. These teams would be roughly patterned on the current weapons of mass destruction response units.

CCNIRT Requirements

The CCNIRT would “perform duties relating to analysis and protection in support of programs to prepare for and respond to emergencies involving an attack or natural disaster impacting a computer, electronic, or cyber network” {§3(a)(1)}. This would be accomplished by amending 10 USC §12310 by adding a new paragraph (d) that is roughly patterned on paragraph (c) dealing with Operations Relating to Defense Against Weapons of Mass Destruction and Terrorist Attacks. There are some significant differences:

• Authorizations for pay and allowances for team members would come from active duty force authorizations not from National Guard budget authorizations {10 USC §12310(d)(4)};
• CCNIRT would specifically be authorized to “to assist the combatant commands in developing and expanding their capacity relating to analysis and protection in support of programs to prepare for and respond to emergencies involving an attack or natural disaster impacting a computer, electronic, or cyber network” {10 USC §12310(d)(2)}; and
• The Secretary of Defense must certify to Congress that the individual CCNIRT “members possess the requisite skills, training, and equipment to be proficient in all mission requirements” {10 USC §12310(d)(2)}.

The bill would also amend 32 USC Chapter 9 by adding §902a addressing the State homeland defense activities of these units. The unit responsibilities would include:

• Training for State and local law enforcement and governmental personnel on analysis and protection to prepare for and respond to emergencies involving an attack or natural disaster impacting a computer, electronic, or cyber network {§902a(a)(1)}; and
• Assist State and local government agencies in preparing for and responding to emergencies involving an attack or natural disaster impacting a computer, electronic, or cyber network {§902a(a)(2)}

The §902a(d) would exempt the CCNIRT from certain existing limitations on National Guard units found in 32 USC 904. Those exemptions include:

• The 180 day deployment limitation in §904(b);
• The weekend and two week annual drill requirements of §502(a); and
• The requirement to maintain the military skills of the unit or member in §904(d).

Section 3(e) of the bills would require the Secretary of Defense to ensure that the training that the CCNIRT receive would “be equivalent to the training provided members of the regular component of the Army and the Air Force on such matters” {§3(e)(1)}. To that end the bills would require a report to Congress on the current status of such training and what changes would need to be made to meet that requirement.

The same section requires a separate report to Congress on the recruiting and retentions requirements to support these National Guard units and similar units in active Army and Air Force. There are two interesting and vague requirements of that report:

• Address potential deployment options (specifically including ‘virtual deployment’) “under which members of the reserve components with computer network defense duties can be managed without the geographic relocation of such members” {§3(e)(2)}; and
• Describing the “training requirements and physical demands” {§3(e)(3)} of the military occupational specialties involved in these units.

Analysis

There are a couple of closely related items that are not addressed in these two bills that would have a significant impact on the establishment and operations of the CCNIRT units. While these units are roughly patterned on the current WMD response teams, there is a significant difference. The WMD units were formed from a large number of existing chemical warfare units in the National Guard and Reserves. The military already had the personnel, equipment and basic skill training in place for these units. That is not the case with the CCNIRT.

Second, the active duty components of the military are already having problems attracting and retaining personnel to form cyberwarfare units. The CCNIRT units will be an additional impediment to the staffing of those units.

Finally, I think that there needs to be a discussion of the posse comitatus status of these units. An argument could be made that a legitimate response by these units to a cyberattack could include a counter-attack on the computer systems of the entity conducting the attack. If that attacking system were located in the United States this could be considered the use of military force against American citizens if the attacker were some domestic terrorist.

Moving Forward

This is such a novel concept that I really don’t have any basis for estimating the potential political response to these bills. I don’t really see any big push to bring these bills to floor consideration, but the bills do have bipartisan sponsorship so they might be able to move forward if the leadership can be convinced to bring them to the floor. We’ll have to see how they fair in the respective Armed Services committees. I would not be surprised, however, to see them rolled into the DOD authorization bills if they receive the support of committee leadership.

Saturday, March 23, 2013

Bills Introduced – 03-22-13


While the House had already left town for their Easter Recess, the Senate was still at work on their budget bill. They also had time to submit a number of new bills including just one that will probably be of interest to the cybersecurity community:

S 658 Latest Title: A bill to amend titles 10 and 32, United States Code, to enhance capabilities to prepare for and respond to cyber emergencies, and for other purposes. Sponsor: Sen Gillibrand, Kirsten E. (D,NY)

As with any other type of security, one must assume that cybersecurity protections for critical infrastructure are, at some point, going to fail. One would like to think that cyber emergency response procedures are in place before that happens. Maybe this bill will help to ensure that; we’ll have to see bill to see if that may be the intention here.
 
/* Use this with templates/template-twocol.html */