Showing posts with label Satellite Cybersecurity. Show all posts
Showing posts with label Satellite Cybersecurity. Show all posts

Monday, October 16, 2023

Review - S 1425 Reported in Senate – Satellite Cybersecurity

Last month, the Senate Homeland Security and Governmental Affairs Committee published their Report on S 1425 [removed from paywall], the Satellite Cybersecurity Act. The Committee held a business meeting of May 17th, 2023, where the bill was considered. They approved substitute language for the bill and in a unanimous vote, recommended the amended bill favorably.

The bill would require the GAO to publish a report on government actions to support cybersecurity of commercial satellite systems. It also outlines new responsibilities for CISA on satellite cybersecurity. No new funding is authorized by this legislation. Nothing in the revised language would change those requirements.

Moving Forward

The strong bipartisan support for this bill in Committee would certainly be reflected in a vote in the Senate if this bill were considered in regular order. Unfortunately, the bill is not politically important enough for the Senate to take up its limited time in that consideration process. This bill could be a candidate for consideration under the Senate’s unanimous consent process, but that is an iffy process at best, with bills being offered under those provisions frequently being stymied by a lone Senator making a point often having nothing to do with the bill. There is a possibility of the language being included in a piece of ‘must pass’ legislation like a spending or authorization bill.

 

For more details about the revisions made to the bill and the information included in the Committee Report, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1425-reported-in-senate - subscription required.

Thursday, July 21, 2022

Review - S 3511 Reported in Senate – Satellite Cybersecurity

Last month, the Senate Homeland Security and Governmental Affairs Committee published their Report for S 3511, Satellite Cybersecurity Act. The Committee met on March 30th, 2022 and adopted substitute language and one additional amendment before ordering the bill reported favorably. The new version of the bill modifies some of the reporting requirements and makes changes to the satellite cybersecurity recommendations process. Subsequent technical changes were made to the bill “by mutual agreement of the Chairman and Ranking Member” (Committee Report, pg 4).

Moving Forward

While there was (not unexpectedly) strong bipartisan support for this bill in Committee for this bill, the bill is not likely to be considered by the Senate leadership to be important enough to be considered under regular order on the floor of the Senate. The time and effort to go through the debate and amendment process would interfere with the agenda of the Senate as we go into the last four months of the session. There is a remote chance that the bill could be considered under the unanimous consent process, but that has a high potential for being blocked for political reasons having nothing to do with the bill. This bill is much more likely to be added to a major bill (such as the upcoming NDAA) as part of the substitute language or as a floor amendment.

For more details about the changes made to the language of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3511-reported-in-senate - subscription required. 

Friday, May 6, 2022

Review - S 4123 Introduced – Satellite Cybersecurity

Earlier this week, Sen Ossoff (D,GA) introduced S 4123, the Enhancing Satellite Cybersecurity Act. Vaguely similar to HR 7629, this bill would also require a GAO report on satellite cybersecurity for commercial satellite systems used by Federal agencies and CISA to provide information on satellite cybersecurity practices for those systems. There is no spending authorized by this legislation.

Moving Forward

Ossoff is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I see nothing in the bill that would engender any specific opposition. This bill would receive extensive bipartisan support if considered in Committee. This bill could make it to the floor of the Senate under the unanimous consent process.

Commentary

This bill is much more tightly focused on commercial satellite systems used by the Federal government than the earlier two satellite cybersecurity bills, HR 7629 and S 3511. This may increase its chance of consideration and ultimate passage. That would also mean that for some period of time, likely years, there would be no mandated federal focus on cybersecurity for commercial satellite systems that did not supply services to the Federal government. It would be an interesting trade-off, one that the commercial satellite industry probably needs to weigh in on.

 

For more details about this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4123-introduced - subscription required.

Wednesday, May 4, 2022

Review - HR 7629 Introduced – Satellite Cybersecurity Reporting

Last week, Rep Malinowski (D,NJ) introduced HR 7629, the Satellite Cybersecurity Act. The bill would require the GAO to prepare a report to Congress on the cybersecurity of commercial satellite systems. It would also require CISA to establish a Commercial Satellite System Cybersecurity Clearinghouse. No funding authorization is included in the legislation. This bill is very similar to S 3511.

Malinowski and his sole cosponsor {Rep Garbarino (R,NY)} are members of the House Homeland Security Committee to which this bill is assigned for primary consideration of this legislation. This means that there should be sufficient influence to see this bill considered in Committee. I see nothing in the bill that would engender any organized opposition. I suspect that the bill would receive substantial bipartisan support within the Committee and would probably be considered in the Full House under the suspension of the rules process.

This bill utilizes semi-technical terms (cybersecurity risk and threat) that come from two different sections of the Homeland Security Act of 2002 and those terms rely on definitions of the term ‘information system’ that contain two different takes on control system security, only one specifically includes industrial control systems within the scope of the definition. HR 7629 does nothing to address those definitional issues, but it does specifically address the different cybersecurity requirements of purely informational security and operational security. For that, the staff members that crafted the bill are to be commended. And realistically, a bill like this is probably not the proper vehicle for addressing the conflicting cybersecurity definitional issues that I harp on so frequently.

 

For more information about the legislative details, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7629-introduced - subscription required.

Sunday, January 23, 2022

Review - S 3511 Introduced – Satellite Cybersecurity

Earlier this month, Sen Peters (D,MI) introduced S 3511, the Satellite Cybersecurity Act. The bill would require CISA to establish a commercial satellite system cybersecurity clearinghouse and to develop voluntary cybersecurity recommendations designed to assist in the development, maintenance, and operation of commercial satellite systems. No funding is authorized by this bill.

Peters is the Chair of the Senate Homeland Security and Governmental Affairs Committee the committee to which this bill was assigned for consideration. This should ensure that there is adequate influence to see this bill considered in Committee. Since the bill only requires the development of ‘voluntary’ security measures, I do not see any significant organized objections interfering with the consideration of this bill. I suspect that the bill will pass out of Committee with at least some level of bipartisan support.

Commentary

We continue to see problems with the definition used by congressional staff in the crafting of cybersecurity legislation that affects operational technology or control systems that directly affect physical systems. In this case, the two cybersecurity terms defined in §2 are IT restrictive definitions. The term ‘cybersecurity risk’ for 6 USC 659 is based upon the IT restricted definition of ‘information system’. Even the term ‘cybersecurity threat’, while based upon the control system inclusive definition of ‘information systems from 6 USC 1501, refers to actions that “adversely impact the security, availability, confidentiality, or integrity of an information system”.

These definitions would suffice if the legislation were only concerned with the information transiting commercial satellites, but the required cybersecurity recommendations from CISA are specifically required to address protecting ‘vital commercial satellite system functions’ and the ‘satellite system’s command, control, and telemetry receiver systems’. Again, the definitions just do not match the requirements.

For more information on what changes to cybersecurity definitions need to be made to adequately reflect control system and operational technology cybersecurity needs, please see my post from February 2019.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3511-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */