Showing posts with label S 914. Show all posts
Showing posts with label S 914. Show all posts

Tuesday, November 12, 2024

Review - Committee Hearings – Week of 11-10-24

This week is the first week of the Lame Duck session of the 118th Congress. Congress has been out of town since the end of September and has been in active campaign mode. This week starts the winding down of the 118th Congress and preparing for the 119th. The hearing schedule for this week is very light, but that may change as members return to Washington. There is currently one Senate markup hearing of interest here.

Markup Hearing

The Senate Energy and Natural Resources Committee will hold a business meeting to consider a large number of bills. One that I have been following here is S 914 [removed from paywall], the Energy Threat Analysis Center (ETAC) Establishment Act of 2023.

 

For more information on this hearing and the congressional leadership votes scheduled for this week, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-11-10 - subscription required.

Tuesday, April 18, 2023

Review - S 914 Introduced – DOE Threat Analysis Center

Last month, Sen Risch (R,ID) introduced S 914, the Energy Threat Analysis Center (ETAC) Establishment Act of 2023. The bill would formally authorize the ETAC which DOE started last year as a pilot project (see here, here, and here). No separate funding is provided in the bill.

Moving Forward

Both Risch and his sole cosponsor (Sen Manchin {D,WV)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. Since no new funding is authorized by the bill, I see nothing that would engender any specific opposition. I suspect that there would be some measure of bipartisan support for the bill, probably enough to achieve 60 votes for cloture if the bill were to be considered under regular order.

Commentary

The crafters of this bill did not see the lack of specific funding for the NTAC to be a problem. They expected DOE to continue to tap into the funding ($50,000 per year through 2026) provided in §18724(d). that was the reason for the reference §18724 in §2(a) of the bill. It is almost as if the crafters of the §40125(c) of the Infrastructure Investment and Jobs Act (Public Law No: 117-58) that is responsible for §18724 planned it that way.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-914-introduced - subscription required.


Tuesday, November 9, 2021

Review - HR 3684 Passed in House – FY 2022 Infrastructure Bill

Last Friday the House finally got around to passing HR 3684, the Infrastructure Investment and Jobs Act, by a slightly bipartisan vote of 228 to 206. With the complexity of the bill and the large amounts of money involved, this is a good time to re-look at the cybersecurity provisions in the bill.

The bill includes language from six separate pieces of cybersecurity legislation.

S 914, the Drinking Water and Wastewater Infrastructure Act of 2021, in §50113,

S 1316, the Cyber Response and Recovery Act of 2021, in §70601,

S 1400, the PROTECT Act of 2021, in §40123,

S 2199, the Cyber Sense Act of 2020, in §40122,

S 2585, the State and Local Cybersecurity Improvement Act, in §70611, and

HR 2931, the Enhancing Grid Security through Public-Private Partnerships Act, in §40121.

It also contains two new standalone cybersecurity provisions in the Energy Division of the bill. Additional (over the current annual spending) cybersecurity spending is authorized for four agencies of the federal government. Finally, there are 23 separate instances where cybersecurity mentions are made in other provisions of the bill

For more details about those provisions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3684-passed-in-house - subscription required.

 

Friday, April 30, 2021

S 914 Passed in Senate – Water Systems Authorization

Yesterday, after adopting the substitute language I described earlier this week by a voice vote, and adopting two other amendments, the Senate passed S 914, the Drinking Water and Wastewater Infrastructure Act of 2021, by a strongly bipartisan vote of 89 to 2. The cybersecurity provisions in the substitute language made it through to the final bill without modification.

Commentary

I think we are going to see additional authorization bills that are not strictly cybersecurity related containing cybersecurity provisions. While I had some concerns about definitions and such, I am glad to see this bill pass with the cybersecurity provisions that it contained. This reflects a growing recognition within the Congress that cybersecurity will have to be a component of much of what we do in this country and around the world.

Wednesday, April 28, 2021

Senate Starts Consideration of S 914 – Water Systems Authorization

Yesterday, by a vote of 92 to 3, the Senate agreed to begin consideration of S 914, the Drinking Water and Wastewater Infrastructure Act of 2021. Ten amendments were offered, including S 1460 (pgs S2229 to S2242) which is the substitute language that the Senate will consider instead of the language reported by the Senate Environment and Public Works Committee earlier this month. S 1460 includes additional changes to the cybersecurity provisions in the bill. None of the other amendments offered to this bill yesterday contain cybersecurity language.

Minor Language Changes

There were some minor formatting changes to the cybersecurity language that was found in the reported version of the bill. The only substantive revision was the removal of language that was originally found in §101 that specifically included ‘cybersecurity event’ as a potential cause for the emergency situations that could trigger the provision of technical assistance or grants under 42 USC 300j-1.

New Cybersecurity Support Language

S 1460 would add a new §113, Cybersecurity support for public water systems, to the bill. That section would add §1429A to the Safe Drinking Water Act. That section would require the EPA, in coordination with CISA, to “develop a prioritization framework to identify public water systems (including sources of water for those public water systems) that, if degraded or rendered inoperable due to an incident, would lead to significant impacts on the health and safety of the public” {§1429A(b)(1)(A), pg S2235}.

That ‘prioritization framework’ would incorporate consideration of {§1429A(b)(1)(B), pg S2236}:

• Whether cybersecurity vulnerabilities for a public water system have been identified under section 1433 [42 USC 300i–2],

• The capacity of a public water system to remediate a cybersecurity vulnerability without additional Federal support,

• Whether a public water system serves a defense installation or critical national security asset, and

• Whether a public water system, if degraded or rendered inoperable due to an incident, would cause a cascading failure of other critical infrastructure.

The ‘section 1433’ reference is to the EPA’s Risk Assessments and Emergency Response Plans requirements that I briefly described in my post about the Florida Water System Hack. The term ‘incident’ in the last bullet is defined in this section by reference to the 44 USC 3552 definition which applies specifically to information systems.

The new §1429A then goes on to require the EPA, again in coordination with CISA to develop “a Technical Cybersecurity Support Plan for public water systems” {new §1429A(b)(2)(A)} for providing voluntary support to public water systems. That Plan would {{new §1429A(b)(2)(B)}:

• Establish a methodology for identifying specific public water systems for which cybersecurity support should be prioritized;

• Establish timelines for making voluntary technical support for cybersecurity available to specific public water systems;

• May include public water systems identified by the Administrator, in coordination with the Director, as needing technical support for cybersecurity;

• Include specific capabilities of the Administrator and the Director that may be utilized to provide support to public water systems under the Support Plan, and

• Only include plans for providing voluntary support to public water systems.

The frequent use of the word ‘voluntary’ almost certainly refers to the voluntary use of the offered support by water systems and not the voluntary provision of support by EPA and CISA that the wording seems to imply. This is somewhat clarified by §1429A(c)(2), which states that nothing in this section “compels a public water system to accept technical support offered by the Administrator.”

There is no funding specifically authorized for §1429A activities. This is evidenced by the reference in means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system;:

(A) the integrity, confidentiality, or availability of information on an information system,

(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

(C) an information system or a control system;

Commentary

Let me start with my now standard diatribe about definitions. The use of the IT centric definition of ‘incident’ in the new §1429A really bothers me. It defines the term by reference to 44 USC 3552 which reads:

(2) The term ‘‘incident’’ means an occurrence that—

(A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or

(B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

The attack on the Oldsmar, Florida water treatment facility would NOT be an incident under this definition. An ‘information system’ as defined under §3552 was not involved. The ‘integrity, confidentiality or availability’ of information was not involved. Only by greatly stretching ‘acceptable use policies’ could this definition of ‘incident’ be made to apply to that attack.

Unfortunately, the definition in 6 USC 659 is essentially the same except that it removes (B) provision found in §3552. That is why I proposed a revision to §659 last year that would have changed that definition. Unfortunately, this bill is not the place to try to effect a change in §659, so I would propose to change the definition in the new §1420A:

‘‘(3) INCIDENT.—The term ‘incident’ has the meaning given the term in section 3552 of title 44, United States Code means an occurrence that actually or imminently jeopardizes, without lawful authority:

“(A) the integrity, confidentiality, or availability of information on an information system,

“(B) the timely availability of accurate process information, the predictable control of the designed process or the confidentiality of process information, or

“(C) an information system or a water treatment control system;.”

With that out of the way, I would like to turn to the ‘Prioritization Framework’ outlined in the new §1429A. This requires that the EPA have some understanding of the cybersecurity risks faced by individual water treatment facilities. This is evidenced in the reference in §1429A(b)(1)(B)(i) to §1433. While the risk assessment currently required under §1433 does vaguely address cybersecurity concerns, facilities are not required to send a copy of that assessment to the EPA, instead, they are required to certify to the EPA that they have completed that assessment. For the EPA to rely on the §1433 data a revision to §1433 would be required. To accomplish this I would suggest that Section 113 of the bill would also require a (b):

(b) Section 1433(a)(4) of the Safe Water Drinking Act (44 USC § 300i–2) is amended to read:

(4) Contents of certifications

A certification required under paragraph (3) shall contain only—

(A) information that identifies the community water system submitting the certification;

(B) a listing of any cybersecurity vulnerabilities identified;

(C) the date of the certification; and

(D) a statement that the community water system has conducted, reviewed, or revised the assessment, as applicable.

I would actually think that a copy of the complete risk assessment in (B) would be very valuable, but I am only going suggest this as that is all that this section of the bill would need.

Tuesday, April 27, 2021

Committee Hearings – Week of 4-25-21

This week with the Senate in session and the House only conducting hearings there are a large number of hearings with COVID-19 and budget hearings being most prevalent. Only two budget hearings of note here and nothing on cybersecurity this week.

FY 2022 Budget Hearings

4-28-21 FY 2022 EPA Budget – Senate Environment and Public Works Committee

4-29-21 FY 2022 EPA Budget – House Subcommittee on Environment and Climate Change

On the Floor

The only floor activity in the House will be Wednesday’s joint address by President Biden and because of COVID restrictions only a relatively small number of House members will be present.

As I noted last week, the Senate is taking up S 914, the Drinking Water and Wastewater Infrastructure Act. With a short opening day yesterday, they are still working through confirmations, but they may get to a vote on cloture for the bill late today or tomorrow. There were no amendments offered yesterday, but again, it was a short day.

Friday, April 23, 2021

S 914 Being Considered in Senate

Yesterday the Senate began consideration of the motion to proceed to consideration of S 914, to amend the Safe Drinking Water Act and the Federal Water Pollution Control Act to reauthorize programs under those Acts. They will be considering the version reported by the Senate Environment and Public Works Committee last week.

A cloture motion has been filed. That motion to close debate on the motion to proceed to consideration of the bill will take place sometime early next week. According to yesterday’s Congressional Record that cloture vote will come after Kahl nomination vote, which comes after McCabe nomination vote, which comes after the Jason Scott Miller nomination vote, which should happen after 5:30 p.m., on Monday, April 26, 2021.

A reminder, there are cybersecurity provisions in the bill.

There have been no amendments proposed for S 914 yet. That process should start to flow on Monday. 

Friday, April 16, 2021

S 914 Reported in Senate – Water Systems Reauthorization

Earlier this week the Senate Environment and Public Works Committee adopted substitute language for S 914, the Drinking Water and Wastewater Infrastructure Act of 2021, and ordered the bill reported favorably without a written report. The reported version of this bill is now available.

The only major change made to the bill was the insertion of a new §109, Rural and low-income drinking water assistance pilot program. A number of word and editorial changes were made in the language of the bill. Of interest here is the replacement of the term ‘cybersecurity threat’ with ‘cybersecurity vulnerabilities’. That change was made everywhere the original term was used. Neither term was defined in the bill.

This bill received strong bipartisan support in Committee and I expect that it will move quickly to the floor of the Senate. It will be interesting to see if it is considered under the Senate’s unanimous consent process or if it will be brought up under the ‘normal’ debate and amend process.

Tuesday, March 30, 2021

S 914 Introduced - Drinking Water and Wastewater Infrastructure Act of 2021

Last week Sen Duckworth (D,IL) introduced S 914, the Drinking Water and Wastewater Infrastructure Act of 2021. The bill reauthorizes drinking water and wastewater treatment programs. While, it does not include any specific cybersecurity programs, it does add addressing cybersecurity concerns to a number of existing programs.

Cybersecurity Mentions

Section 101 amends 42 USC 300j-1(b) adding “(including an emergency situation resulting from a cybersecurity event)” after “emergency situation”; would allow providing technical assistance and grants.

Section 107 adds §1459F, the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program, to the Safe Drinking Water Act, which includes:

In (b) - “shall award grants to eligible entities for the purpose of increasing resilience to natural hazards, cybersecurity threats [emphasis added], and extreme weather events”,

In (c) - “may only use grant funds received under the resilience and sustainability program to assist in the planning, design, construction, implementation, operation, or maintenance of a program or project that increases resilience to natural hazards, cybersecurity threats [emphasis added], or extreme weather events”

In (c)(6) - “the development and implementation of measures to increase the resilience of the eligible entity to natural hazards, cybersecurity threats [emphasis added], or extreme weather events”,

In (d)(2) - “an identification of the natural hazard risk or potential cybersecurity threat [emphasis added], as applicable, to be addressed by the proposed program or project”,

In (d)(3) - “documentation prepared by a Federal, State, regional, or local government agency of the natural hazard risk, potential cybersecurity threat [emphasis added], or risk for extreme weather events”,

In (d)(4) - “a description of any recent natural hazards, cybersecurity events, or extreme weather events that have affected the community water system of the eligible entity”,

In (d)(5) - “a description of how the proposed program or project would improve the performance of the community water system of the eligible entity under the anticipated natural hazards, cybersecurity threats [emphasis added], or extreme weather events”,

In (d)(6) - “an explanation of how the proposed program or project is expected to enhance the resilience of the community water system of the eligible entity to the anticipated natural hazards, cybersecurity threats, or extreme weather events”.

Section 111 adds §1459H, Advanced Drinking Water Technologies, to the Safe Drinking Water Act,  which includes:

In (a)(1) - “the Administrator shall carry out a study that examines the state of existing and potential future technology, including technology that could address cybersecurity threats [emphasis added], that enhances or could enhance the treatment, monitoring, affordability, efficiency, and safety of drinking water provided by a public water system”, and

In (b)(1)(A)(iii) - “has expressed an interest in the opportunities in the operation of the public water system to employ new or emerging, yet proven, technologies, including technology that could address cybersecurity threats [emphasis added]”,

Section 205 adds §222, Clean Water Infrastructure Resiliency and Sustainability Program, to the Federal Water Pollution Control Act, which includes:

In (b) - “the Administrator shall establish a clean water infrastructure resilience and sustainability program under which the Administrator shall award grants to eligible entities for the purpose of increasing the resilience of publicly owned treatment works to a natural hazard or a cybersecurity threat [emphasis added]”,

In (c) - “shall use the grant funds for planning, designing, or constructing projects (on a system-wide or area-wide basis) that increase the resilience of a publicly owned treatment works to a natural hazard or a cybersecurity threat [emphasis added]”,

In (d)(2) - “an identification of the natural hazard risk or potential cybersecurity threat [emphasis added], as applicable, to be addressed by the proposed project”,

In (d)(3) - “documentation prepared by a Federal, State, regional, or local government agency of the natural hazard risk or potential cybersecurity threat [emphasis added], as applicable, of the area where the proposed project is to be located”,

In (d)(4) - “a description of any recent natural hazard events or cybersecurity threats [emphasis added] that have affected the publicly owned treatment works”,

In (d)(5) - “a description of how the proposed project would improve the performance of the publicly owned treatment works under an anticipated natural hazard or cybersecurity threat [emphasis added]”,

In (d)(6) - “an explanation of how the proposed project is expected to enhance the resilience of the publicly owned treatment works to an anticipated natural hazard or cybersecurity threat [emphasis added]”,

Section 213, Water Data Sharing Pilot Program, which includes:

In (a)(1) - “the Administrator may award grants to eligible entities under subsection (b) to establish systems that improve the sharing of information concerning water quality, water infrastructure needs, and water technology, including cybersecurity technology [emphasis added]”.

Moving Forward

The bill was considered by the Senate Environment and Public Works Committee last Wednesday. Substitute language (not currently publicly available) and adopted (pg 27) by the Committee by a unanimous vote. This clears the bill (once the Committee Report is published) for consideration by the full Senate, where it is likely to be considered under the unanimous consent process, meaning no debate, no amendments and no actual vote. Of course, a single Senator could stop that consideration process, and the reasons for that ‘objection’ could have nothing to do with anything in this bill.

Commentary

This is the type of ‘cybersecurity’ language that I expect to see more frequently in this session of Congress. Instead of standing up any new cybersecurity program, I suspect that there will be more language adding cybersecurity concerns to authorization bills by tacking ‘cybersecurity’ to existing safety and security measures already in place. This will give existing regulatory agencies more authority to address cybersecurity issues. Unfortunately, this will seldom come with increased funding to address those issues.

The one problem with this approach is that there are typically no cybersecurity related definitions included in the authorization statutes for these programs. On one hand, this does give regulators the maximum amount of leeway in how they address the cybersecurity issues, but on the other hand, it does not insure that the full gamut of issues will be addressed.

The major shortcoming in this bill is that, while it addresses information sharing about cybersecurity technology, it does not specifically establish a program for sharing information about cybersecurity threats or system vulnerabilities. There is a Water Information Sharing and Analysis Committee (WaterISAC), but that is a voluntary organization without any specific government support or authority.

Wednesday, March 24, 2021

Bills Introduced – 3-23-21

Yesterday with the Senate in Washington and the House meeting in pro forma session (this is a ‘Committee Week’ in the House) there were 124 bills introduced. One of those bills may receive additional coverage in this blog:

S 914 A bill to amend the Safe Drinking Water Act and the Federal Water Pollution Control Act to reauthorize programs under those Acts, and for other purposes. Sen. Duckworth, Tammy [D-IL]

According to at least one news report notes that the bill would “create a grant program for projects aimed at making water systems more resilient to natural hazards, cybersecurity threats [emphasis added] and extreme weather.” There is nothing in Duckworth’s press release on the bill that confirms this, but that means little. The Senate Environment and Public Works Committee will take up the bill at their business meeting scheduled for today. No link to a committee print of the bill is available on the meeting website.

 
/* Use this with templates/template-twocol.html */