Showing posts with label S 754. Show all posts
Showing posts with label S 754. Show all posts

Thursday, April 17, 2025

Review – S 754 Introduced – Food & Ag Cybersecurity

Back in February Sen Cotton (R,AR) introduced S 754, the Farm and Food Cybersecurity Act of 2025. The bill would require USDA to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector. Additionally, it would be required to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes. The bill would authorize $1 million per year through 2030 to fund such activities.

The bill is very similar to S 3661, that was introduced by Cotton in January of 2024. Changes were made to increase the influence of “the sector-specific ISAC” without actually naming the Food and Ag-ISAC. No actions were taken on that bill in the 118th Congress. A similar bill, HR 1604, was introduced in the House this session.

Moving Forward

While Cotton is not a member of the Senate Agriculture, Nutrition, and Forestry Committee to which this bill was assigned for consideration, one of his six cosponsors, Sen Slotkin (D,MI), is a member. This means that there may be sufficient influence to see the bill considered in Committee. The spending authorization included in the bill will be a major stumbling block for this bill in the 119th Congress. I do not expect that, lacking a significant and successful cyberattack on food and agriculture critical infrastructure, that this bill will move forward out of Committee.

 

For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-754-introduced - subscription required.

Thursday, February 27, 2025

Review - Bills Introduced – 2-26-25

Yesterday, with both the House and Senate in session, there were 88 bills introduced. Three of those bills may receive additional coverage in this blog:

HR 1604 To direct the Secretary of Agriculture to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector and to provide recommendations to enhance their security and resilience, to require the Secretary of Agriculture to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes. Finstad, Brad [Rep.-R-MN-1]

HR 1636 To direct the Nuclear Regulatory Commission to take certain actions relating to security measures for radioactive materials, and for other purposes. Torres, Ritchie [Rep.-D-NY-15]

S 754 A bill to direct the Secretary of Agriculture to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector and to provide recommendations to enhance their security and resilience, to require the Secretary of Agriculture to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes. Cotton, Tom [Sen.-R-AR]

 

For more information on these bills, including legislative history for similar bills in the 118th, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-2-26-25 - subscription required.

Wednesday, March 29, 2017

Bills Introduced – 03-28-17

With both the House and Senate in session yesterday there were 43 bills introduced. Of those one may be of specific interest to readers of this blog:

S 754 A bill to support meeting our Nation's growing cybersecurity workforce needs by expanding the cybersecurity education pipeline. Sen. Markey, Edward J. [D-MA]


It will be interesting to see what definitions are used in this bill to outline the scope of cybersecurity workforce. If the language is inclusive of industrial control systems then there will be further mention of this bill in this blog.

Wednesday, October 28, 2015

Senate Passes S 754 – CISA

As everyone is probably already aware the Senate yesterday passed an amended S 754 by a substantially bipartisan vote of 74 to 21. The bill will now go to a conference committee where the differences between this bill and HR 1560 that was passed in the House in April.

Control System Security Issues

The revised bill does contain two provisions that have specific implications for control system security. First the information sharing provisions of the bill do apply to control systems as the definition of ‘information system’ in §102(10) specifically “includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers”.

Second, as I reported earlier, §407 of the bill would require DHS to report to Congress on the extent that critical infrastructure is currently required to report cyber intrusions or incidents involving cybersecurity incidents that “could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. DHS would also be required to suggest to Congress additional statutory authority that would be required to allow the department to put into effect “a strategy that addresses each of the covered [critical infrastructure] entities, to ensure that, to the greatest extent feasible, a cyber security incident affecting such entity would no longer reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” {§407(c)(1)}.

The Whitehouse amendment (revised amendment #2626) that I described in my earlier post was not considered by the Senate. This amendment and Mikulski #257 were objected to by Sen. Burr (R,NC; Chair of the Senate Intelligence Committee and co-author of S 754) as not being “germane to amendment No. 2716.” { CREC-2015-10-27-pt1-PgS7503). Readers might remember that the Whitehouse amendment would have made it a federal criminal offense to damage to a critical infrastructure computer during the commission of computer fraud.

Moving Forward

With the House and Senate bills headed to conference in the coming weeks, there is no telling exactly when the resulting bill will come back for votes in the House and Senate. It is also not yet clear which bill number will be the vessel for that vote. It is apparent, however, that we will have an information sharing bill sent to the President in the not too distant future (probably before the end of the year).

Commentary

I think that I have to agree with Jack Whitsitt’s view of the effectiveness of the information sharing provisions of this bill; it is not going to be a game changer by any stretch of the imagination. Nor do I subscribe to the dystopian view that this bill specifically furthers the government invasion of privacy evidenced in the NSA revelations of the last couple of years. It will, however, relieve Congress from any further requirement in the near term to craft ‘comprehensive cybersecurity legislation’.

I think what we will see from Congress is a continuation of the trend that I have mentioned here a couple of times of including relatively minor cybersecurity language in bills dealing with technology issues or general security issues. This will, in my opinion, be a much more effective (if piecemeal) way of dealing with cybersecurity issues in general and control system security issues specifically.

As Congress routinely addresses technical issues in automotive safety, intelligent transportation systems, medical devices, the smart grid and aircraft safety (to name a few specific areas) legitimate attention will also have to be directed at the security of the electronic systems that form the control basis for those systems. Integrating control system security into those larger issues is where important legislative work needs to be done.

The one area, however, that still needs major legislative attention is the protection of control systems where failure or an attack could have significant impact on a large segment of society. Section 407 of the bill that was passed yesterday was an important step in identifying those control systems that need to be protected.

I think that the time frame requirements in that section are way too short for effective analysis. This means that some truly critical systems are sure to be missed and some not so critical systems will be included. But, it is an important first step.

The control system security community, meanwhile, needs to start thinking seriously about how we want to see meaningful legislation crafted to deal with the control system vulnerabilities in these critical facilities. We need to figure out how to craft rules that won’t be technically obsolete by the time that they are published. We need to figure out how regulate control system security without stifling the creative expansion of control system capabilities.


We need to do it because Congress does not (and never will have) the technological skills and comprehension to do it on their own. If we leave this to them we will either have systems so complicated that future changes in automation technology will be fatally handicapped; or so weak that there will be no protection of critical infrastructure control systems at all. Congress is not equipped to find the technological middle ground; we are.

Monday, October 26, 2015

S 754 Amendments to Date - CISA -

Okay, I couldn’t help myself. I have gone back and looked at the amendments to S 754 to date and I have pieced together the following analysis.

Boxer Amendment

The Senate is currently dealing with what many are referring to as the ‘Boxer Amendment’. This is actually Senate Amendment # 2716 submitted by Sen. Burr (R.NC) and Sen. Boxer (D,CA) (Chair and Ranking Member of the Senate Intelligence Committee). It is substitute language for S 754 that takes the least controversial of the 21 amendments that the Senate agreed to consider last July and rolls them into S 754, along with some other changes that have bipartisan support in Committee.

There is only one section of this substitute language that specifically applies to control system security issues (kind of); §407. Strategy to protect critical infrastructure at greatest risk. This section requires the DHS Secretary to “identify critical infrastructure entities where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” {§407(b)}. It would then require a report to Congress “describing the extent to which each covered entity reports significant intrusions of information systems essential to the operation of critical infrastructure” {§407(c)} to either DHS or a regulating agency.

Additionally, DHS would be required to “conduct an assessment and develop a strategy that addresses each of the covered entities, to ensure that, to the greatest extent feasible, a cyber security incident affecting such entity would no longer reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” {§407(d)(1)}.

Unreasonably short timelines are required for all of the required reports to Congress.

Other Control System Security Amendments

In my July blog post I mentioned that the only one of the 21 amendments agreed to be considered specifically (okay almost specifically) addressed control system security issues was Whitehouse 2626. Since the Senate has taken up consideration of the bill this week only one more amendment has been proposed that address (again, almost specifically) control system security issues and that is Whitehouse 2713.

It would add a new section to 18 USC, the US criminal statutes (§1030A. Aggravated damage to a critical infrastructure computer). This is virtually the same section that was proposed in # 2713 and my comments in the earlier blog post certainly apply here. The implementation of its intent seems to me (again I am not a lawyer) to be fatally flawed by its reliance on the definition of ‘protected computer’ in the existing §1030(e)(2).

Interestingly, the Friday Daily Digest of the Congressional record lists a ‘Modified Amendment No. 2626’as one of the pending amendments being considered by the Senate. I suspect that the modification is making it amendment to Amendment 2716 instead of S 754. Unfortunately, neither amendment was included in the unanimous consent agreement list of those that will be considered today before a vote on S 2716.

Moving Forward

There is one more cloture vote possible today on the full bill. If that passes (and all cloture votes to date have) then there will be a final vote on the bill today.


The question then arises if the Senate will just send S 754 to the House or if it will substitute the language from S 754 for HR 1560, the House passed information sharing bill. The later would then almost certainly see a Conference Committee ironing out the differences between the two bills. Just sending S 754 to the House would probably result in the House amending that bill and prolonging the ultimate passage. Either way it is beginning to look like we are going to see an information sharing bill on the President’s desk during this session of Congress (which remember does not end until December of next year.

Committee Hearings – Week of 10-25-15

Both the House and Senate will be in Washington this week. There is only one hearing currently scheduled this week that may be (okay a little bit of a stretch) of interest to readers of this blog; an oversight hearing of DHS S&T.

S&T Oversight

The House Science, Space and Technology Committee will be holding a hearing on Tuesday on a “A Review of Progress by the Department of Homeland Security (DHS), Science and Technology Directorate”. The sole witness will be Under Secretary Brothers.

On the Floor

There will be two bills of potential interest this week that will be considered under suspension of the rules (limited debate, no amendments and 3/5th majority):

• Concur in the Senate Amendment to HR 623 – DHS Social Media Improvement Act of 2015; and
HR 3819 – Surface Transportation Extension Act of 2015


The Senate will continue working on S 754 the CISA. I am not going to try to keep up on the details of the amendment process in the Senate with its amendments to amendments processes. I’ll report on the final wording of the bill when it is passed (probably) on Tuesday.

Thursday, August 6, 2015

Amendments to S 754 – 08-05-15

Yesterday there were 23 additional amendments submitted in the Senate for S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015. Only three of those proposed amendments may be of specific interest to readers of this blog.

SA 2623. Ms. Collins, pgs S6411;
SA 2626. Mr. Whitehouse, pgs S6415-6; and
SA 2628. Mr. Wyden, pg S6419

The Amendments

The Collins amendment would require the owners of ‘critical cyber infrastructure’ to report to the DHS Secretary or appropriate agency head “if an information system of a covered entity that is essential to the operation of critical cyber infrastructure is successfully intruded upon” {new §lll(b)(1)}; note that there is no definition of ‘successfully intruded upon’ provided. The report would include {new §lll(b)(2)}:

A description of the technique or method used in such intrusion;
A sample of the malicious software, if discovered and isolated by the covered entity, involved in such intrusion;
Damage assessment; and
Such other matters as the Secretary or the appropriate agency head, as the case may be, consider appropriate.

The Whitehouse amendment would add a new section to the US criminal code; 18 USC 1030A. This new section would make it a federal crime “during and in relation to a felony violation of section 1030, to knowingly cause or attempt to cause damage to a critical infrastructure computer” {new §1030A(a)}. Unfortunately, because of the definition of ‘protected computer’ in §1030(e)(2) only attacks on financial institutions or communications companies would give rise to the underlying felony that is a required part of this new definition. I do not think that that was the intent.

The Wyden amendment would require the Secretary of Commerce to reconsider the rulemaking concerning the implementation of the Wassenaar Arrangement 2013 Plenary Agreements Implementation: Intrusion and Surveillance Items. The reconsideration would include drafting a supplemental of proposed rulemaking that is written in consultation with “civil society organizations, including privacy advocates, public and private sector technologists, security researchers, and public and private sector software developers” {new §ll(b)(1)}. The new proposed rule would be required to be:

Limited to the scope of the agreements reached at the plenary meeting of the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies in December 2013;
Consistent with the regulation of cybersecurity items by other countries participating in the Wassenaar Arrangement, as appropriate; and
Exclude cybersecurity items available for mass-market purchase from regulation under the proposed rule

Agreement to Consider the Bill

A unanimous consent agreement was reached yesterday to allow for the Senate to move forward with the consideration of the bill without having to go through a cloture procedure. That agreement calls for the consideration of 21 specific amendments; ten from the Republicans and eleven from the Democrats. There is a possibility that other amendments may be subsequently considered.


Of the seven amendments that I discussed here yesterday and today only one is on either list; Whitehouse 2626. Most of the remaining ones that I discussed were excluded from consideration because they did not directly deal with cybersecurity information sharing.

Wednesday, August 5, 2015

Amendments to S 754 – 08-04-15

While the Senate is trying to get S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015, to a floor vote before leaving on their summer recess at the end of the week, a number of amendments are being submitted that may or may not be considered before the final floor vote. Yesterday, for instance there were 65 such amendments submitted. Of those amendments only four may be of specific interest to readers of this blog:

SA 2573. Mr. Flake (R,AZ), pgs S6306-07;
SA 2576. Mr. Markey (D,MA), pgs S6309-10;
SA 2608. Ms. Warren (D,MA), pg S6321; and
SA 2609. Ms. Warren, pg S6321

The Flake amendment deals with electric grid cybersecurity issues and is a virtual copy of HR 2271 which has yet to be acted upon in the House. Similarly the Markey amendment is a copy of S 1806; his bill on automotive cybersecurity issues.

The two amendments by Warren both deal with liability issues. The first ensures that the provisions of §6 (Protection from Liability) of the bill are not misconstrued to apply to organizations that do not take actions to “action to address a cybersecurity threat or a security vulnerability”. Similarly SA 2609 adds a new paragraph to §6 that specifically requires an entity that receives information “regarding a cybersecurity threat or a security vulnerability under this Act” to take actions to “to address the threat or vulnerability” or be liable.


As of this morning’s publication of yesterday’s Congressional Record there was no agreement in place as to what amendments would or would not be taken up prior to the final vote on S 754.

Wednesday, March 18, 2015

Bills Introduced – 03-17-15


Yesterday there were 54 bills introduced in the House and Senate. Four of these bills may be of specific interest to readers of this blog:


· HR 1385 - To provide for a legal framework for the operation of public unmanned aircraft systems, and for other purposes. Rep. Poe, Ted [R-TX-2]

· HR 1405 - To amend title 49, United States Code, to ensure railroad safety. Rep. Lipinski, Daniel [D-IL-3]

· S 754 - An original bill to improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes. Sen. Burr, Richard [R-NC]

· S 766 - A bill to limit the retrieval of data from vehicle event data recorders, and for other purposes. Sen. Hoeven, John [R-ND]


HR 1385 will probably address more than small unmanned aerial vehicles, but we will have to wait to see the details.


Lipinski's HR 1405 will almost certainly address crude oil train issues among other items.


S 754 is the much publicized bill from the Senate Intelligence Committee. The formal copy of the bill has not been published by the GPO yet, but earlier draft versions did specifically include industrial control systems in the definition of information systems covered by the bill. The bill was reported without a written report when it was introduced yesterday meaning that it can be brought to the floor at anytime the leadership desires. It will be interesting to see if and when this bill gets to the floor.
S 766 may have implications for cybersecurity of automobiles, but I won't be certain of that until we see the actual language.
 
/* Use this with templates/template-twocol.html */