Showing posts with label S 768. Show all posts
Showing posts with label S 768. Show all posts

Friday, April 19, 2019

S 715 Introduced – Smart Manufacturing


Last month Sen. Shaheen (D,NH) introduced S 715, the Smart Manufacturing Leadership Act. The bill would require the Secretary of Energy to develop a smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs. The bill is almost identical to S 768 that Shaheen introduced in the 115th Congress; no action was taken on that bill.

Differences in the Bills


There are two differences between these two versions of the bill; one minor and one significant. The minor change is found in §7(g); the dates have been changed for the authorization of funding. It now reads: “$10,000,000 for each of fiscal years 2020 through 2023”; this is an expected change.

The significant change addresses my one major complaint about the previous version of this bill; it did not address cybersecurity issues. Two new subparagraphs were added to §4(b)(2) addressing the requirements for what items must be included in the Secretary’s plan. The new subparagraphs are:

(C) the use of smart manufacturing to improve energy efficiency and reduce emissions in supply chains across multiple companies;
(D) actions to increase cybersecurity in smart manufacturing infrastructure;

Moving Forward


While Shaheen is still not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration, one of her cosponsors {Sen. Alexander (R,TN)} is an influential member of that Committee. This greatly increases the possibility that the Committee will consider this bill during the session.

Since no regulatory authority is actually provided by the bill, the main sticking point for its adoption (either in Committee or on the floor of the Senate) is the inclusion of $10 million in appropriations for the grant program outlined in the bill. This is not a large amount of money in federal spending terms, but it is money that will have to come from somewhere; probably from other programs in the DOE budget.

Commentary


The cybersecurity provision added to this bill is even more generic than the one I proposed in my posting of S 768. There are certain advantages in Congress employing vague, generic language in legislation; it allows regulatory agencies more leeway in adopting (and even more importantly) and later modifying actual regulatory or guidance language. While the process required to actually make such modifications is lengthy and time consuming, it would be much longer, if the agency had to rely on changes in congressional language to start the change process.

This time issue has been one of the problems cited whenever there is discussion about cybersecurity language or regulation. The cybersecurity risk landscape changes so quickly special care needs to be taken to ensure that outdated security measures are not locked into the regulatory process. Shaheen’s staff appears to have realized that problem and looks to have done their part to ensure that Congress is not the source of that kind of problem in this bill.

Sunday, March 31, 2019

S 715 Introduced – Smart Manufacturing


Earlier this month Sen. Shaheen (D,NH) introduced S 715, the Smart Manufacturing Leadership Act. The bill would require the Secretary of Energy to develop a smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs. The bill is nearly identical to S 768 that was introduced in the 115th Congress. The earlier bill saw no action beyond its introduction.

Differences


The only differences between the two bills is that the staff added two sub-paragraphs to §4(b) of the bill. That paragraph outlined the actions that Federal agencies would take in support of the smart manufacturing plan required by this bill. The two new actions included in §4(b)(2) are:

• Actions to increase cybersecurity in smart manufacturing infrastructure;
Deployment of existing research results; and

Moving Forward


While Shaheen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration, Sen. Alexander (R,TN) is. Adding Alexander as a cosponsor may see this bill considered by the Committee this session. No regulatory requirements are being added by this bill so there are unlikely to be any philosophical objections to the bill.

The major impediment to passage of this bill is the inclusion of a $10 million authorization for the grant program included in §7. That is small change in the Federal budget, but the money will have to come from somewhere. Shaheen avoided this spending problem in the other portions of her bill by requiring the money for the planning process to come out of Department unobligated funds; this left the spending allocation problem in the hands of DOE not Congress. That would have been difficult to do with a new grant program.

Commentary


It is interesting to see that one of the new sub-paragraph additions to this bill was similar in intent to a recommendation I made on S 768; readers would be unsurprised to realize that the language was dealing with cybersecurity. Unfortunately, the major cybersecurity suggestion I had for the bill was not adopted in the new version of the bill. I still think that the existing provisions are inadequate, so I would like to re-suggest the following addition be made to the definitions in §3:

§3(10): “VOLUNTARY CYBERSECURITY STANDARDS AND PROTOCOLS -The term “voluntary cybersecurity standards and protocols” means a standard and/or protocol developed by the National Institute of Standards and Technology (NIST) or recognized independent standards setting organizations that an electronic equipment manufacturer, system integrator or system owner may voluntarily apply in the manufacture, integration or operation of an industrial control system, energy management system or information and communication technology system, that would protect such systems from a cyber threat as that term is defined in 6 USC 1501.”

This definition would then be used in new wording for the added §4(b)(2)(D):

“encourage to the development, promulgation and implementation of voluntary cybersecurity standards and protocols in smart manufacturing operations; and”

As I noted in my post on S 768 this simple, generic language could add a significant measure of cybersecurity support to this bill without drawing any significant opposition from manufacturers fearing new government regulations.

Thursday, April 13, 2017

S 768 Introduced – Smart Manufacturing

Last month Sen. Shaheen (D,NH) introduced S 768, the Smart Manufacturing Leadership Act. The bill would require the Secretary of Energy to develop a smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs.

Definition of Smart Manufacturing


The basic definition of smart manufacturing in this bill encompasses the technologies that digitally {§3(9)(A)}:

• Simulate manufacturing production lines;
• Operate computer-controlled manufacturing equipment;
• Monitor and communicate production line status; and
• Manage and optimize energy productivity and cost throughout production


The bill goes on to further expand the definition to include technologies that {§3(9)}:

• Model, simulate, and optimize the energy efficiency of a factory building;
• Monitor and optimize building energy performance;
• Model, simulate, and optimize the design of energy efficient and sustainable products, including the use of digital prototyping and additive manufacturing to enhance product design;
• Connect manufactured products in networks to monitor and optimize the performance of the networks, including automated network operations; and
• Digitally connect the supply chain network.

Smart Manufacturing Plan


Section 4 of the bill would require DOE to develop and implement a smart manufacturing plan within 3 years to improve the productivity and energy efficiency of the manufacturing sector of the United States. The plan would identify actions that the Federal government would take to {§4(b)(1)}:

• Facilitate quicker development, deployment, and adoption of smart manufacturing technologies and processes;
• Result in greater energy efficiency and lower environmental impacts for all American manufacturers; and
• Enhance competitiveness and strengthen the manufacturing sectors of the United States.

Moving Forward


Shaheen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This means that there is little chance that she has the influence necessary to have that Committee take up the bill.

The only thing in this bill that would cause any significant opposition to its consideration (in committee or on the floor) is the inclusion of a relatively modest new grant program. The $10 million dollars authorized for the grant program would have to come out of an already limited budget environment. That would probably be sufficient to ensure that the bill will not receive consideration.

Commentary


Sharp eyed readers will see little above that indicate that I would spend any time evaluating this bill on this blog; there are no chemical safety or cybersecurity provisions mentioned in the bill. The lack of cybersecurity provisions in the bill is what concerns me here.

Shaheen does mention cybersecurity a couple of place in Section 2 of the bill; the congressional findings section. These finding spell out the reason that the programs outlined in the bill are necessary. And she lays out a pretty good set of reasons to include cybersecurity.

First, she establishes that “the interconnection of the many components of manufacturing within a manufacturing plant with other business functions within a company and across companies within a supply chain will enable new production efficiencies” {§2(4)}. Those of us who follow control system security recognize (and object to) these ‘interconnections’ as a great source of the vulnerability of control systems that until recently were considered to have isolation as their greatest security measure.

Second, in laying out the barriers to adoption of smart manufacturing technologies, she specifically identifies the lack of “common cybersecurity protocols and standards” {§2(7)(D)}.

Finally, she establishes that the Department of the Energy is (and should be) specifically working “with the private sector to reduce the market barriers through the development of voluntary protocols and standards” {§2(9)} to overcome these barriers to smart manufacturing technology adoption in the US.

So why is there no mention of cybersecurity in the discussion of the smart manufacturing plan the DOE is supposed to develop and implement? It is almost certainly not because Shaheen and her staff (who really write these bills) do not see the need; they specifically mentioned the need. It is probably not because they are technologically ill equipped to set cybersecurity standards; there is no specificity in the other requirements for the smart manufacturing plan. I do not even believe it is because of the current resistance in the business community to establishing cybersecurity regulations; the bill could have easily called for the establishment of ‘voluntary standards or protocols’ for cybersecurity.

No, I think that the problem here is committee politics. If Shaheen had added the word ‘cybersecurity’ to section 4 of the bill, it would have forced the bill to have been referred to at least one more Committee (the Commerce, Science, and Technology Committee) for consideration. This would have destroyed any minor hope that Shaheen would have had for being able to horse trade with a Committee Chair to get the bill considered by a committee to which she was not a member.

Further, I suspect that she was hoping that the bill would have been assigned to the Senate Committee on Small Business and Entrepreneurship (of which she is the Ranking Member) not the Energy and Natural Resources Committee. That was the reason that she makes a major point of addressing small business concerns in the bill. Unfortunately, the inclusion of the DOE really put a kibosh on that hope.

I really think that we might see this bill again later this year when the DOE authorization bill makes it to the floor of the Senate as an amendment to that bill. If it does, I would hope to see some added cybersecurity language. To that end, I would suggest the following specific language:

Add a new §3(10): “VOLUNTARY CYBERSECURITY STANDARDS AND PROTOCOLS -The term “voluntary cybersecurity standards and protocols” means a standard and/or protocol developed by the National Institute of Standards and Technology (NIST) or recognized independent standards setting organizations that an electronic equipment manufacturer, system integrator or system owner may voluntarily apply in the manufacture, integration or operation of an industrial control system, energy management system or information and communication technology system, that would protect such systems from a cyber threat as that term is defined in 6 USC 1501.”

Add a new §4(b)(1)(C): “encourage to the development, promulgation and implementation of voluntary cybersecurity standards and protocols in smart manufacturing operations; and”


This simple, generic language could add a significant measure of cybersecurity support to this bill without drawing any significant opposition from manufacturers fearing new government regulations.

Thursday, March 30, 2017

Bills Introduced – 03-29-17

Yesterday with both the House and Senate in session there were 54 bills introduced. Of those three may be of specific interest to readers of this blog:

S 763 A bill to improve surface and maritime transportation security. Sen. Thune, John [R-SD]

S 768 A bill to improve the productivity and energy efficiency of the manufacturing sector by directing the Secretary of Energy, in coordination with the National Academies and other appropriate Federal agencies, to develop a national smart manufacturing plan and to provide assistance to small- and medium-sized manufacturers in implementing smart manufacturing programs, and for other purposes. Sen. Shaheen, Jeanne [D-NH] 

S 770 A bill to require the Director of the National Institute of Standards and Technology to disseminate resources to help reduce small business cybersecurity risks, and for other purposes. Sen. Schatz, Brian [D-HI]

I suspect that S 763 will be very similar to S 3379 that was introduced in the closing days of the 114th Congress. As expected it saw no action.

I will only be looking at S 768 if it provides for cybersecurity measures in support of ‘smart manufacturing’; I’m not holding my breath.


With S 770 I will be looking for specific provisions on, or at least coverage of, control system security issues.
 
/* Use this with templates/template-twocol.html */