Showing posts with label Senate. Show all posts
Showing posts with label Senate. Show all posts

Friday, August 1, 2014

Senate Homeland Security Committee Rewrites and Adopts HR 4007

On Wednesday the Senate Homeland Security and Governmental Affairs Committee marked up and adopted HR 4007, the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014 (NOTE: That is a name change). Substitute language was offered by Chairman Carper (D,DE) and Ranking Member Coburn (R,OK) and it was subsequently modified. The new language was adopted by a voice vote with Sen. Senator Baldwin (D,WI) voting no.

Changes

Most news reports have identified only two changes to the bill; a new expedited approval program for Tier 3 and Tier 4 facilities and an expansion of the whistleblower protections. These were the two really major changes (and will be discussed in more detail in a subsequent post), but the substitute language was a major re-write of the bill passed by the House. Most of the changes were language and formatting changes (this version does read cleaner), but there were other changes that will significantly change the Department’s actions resulting from this modified bill.

The changes include:

• Specifically allows the Secretary to suggest improvements to an alternative security plan to allow its approval {§2102(c)(2)(A)(ii)};
• Specifically authorizes the use of contractors (nongovernment personnel) to support the audit and inspection program {§2102(d)(1)(C)};
• Specifically authorizes the use of nondepartment personnel to conduct audits and inspection (EPA-RMP and/or OSHA-PSM presumably) {§2102(d)(1)(C)};
• Limits site security plan approval authority to DHS personnel {§2102(d)(1)(D)(iii)};
• Replaces requirement of nongovernment inspectors to have a Secret security clearance with the possession of a CVI certificate {§2102(d)(1)(e)};
• In two places where ‘consultation’ is required adds requirement for consulting with ‘public and private labor organizations’ {§2102(e)(1) and §2109};
• Adds a requirement for semi-annual reports to Congress about retiering and removal of facilities from CFATS program {§2102(e)(4)};
• Removes phrase ‘if such information may not be disclosed pursuant to any State or local law’ from paragraph about sharing with States and local governments {§2103(b)};
• Removes requirement to share information through ‘Homeland Security Information Network or the Homeland Secure Data Network’ {§2103(c)};
• Added specific exemption from disclosure under the Freedom of Information Act (5 USC 552) {§2103(e)};
• Expanded ‘Civil Penalties’ section to include ‘Civil Enforcement’ activities {§2104};
• Added ‘Non-reporting chemical facilities of interest’ under Civil Penalties {§2104(b)};
• Specifically limits rights of enforcement action under the program to the Secretary of DHS {§2104(d)};
• Specifically allows that “each existing CFATS regulation shall remain in effect unless the Secretary amends, consolidates, or repeals the regulation” {§2107(b)};
• Gives Secretary 30 days to “repeal any existing CFATS regulation that the Secretary determines is duplicative of, or conflicts with, this title” {§2107(b)(2};
• Lowers maximum number of employees to 100 at facility and adds ‘small business concern’ (15 USC 632 for definition) to definition of Small Covered Facility {§2108(a)};
• Expands assistance that may be provided to Small Covered Facilities to include “cybersecurity, recordkeeping, and reporting procedures” {§2108(b)};
• Specifically repeals Section 550 upon effective date of this bill {§4(b)}; and
• Sets 4 year termination of program {§5};

In addition to the above changes there were three things that were specifically removed from the bill:

• References to ‘Security Screening Coordination Office’ {Old §2101(d)(3)(C)};
• The rail transit exemption language {Old §2105(c)}; and
• The entire spending authorization section {Old §2110}.

Security Plan Suggestions

One of the problems that has plagued the enforcement of the current CFATS regulations is the interpretation that the prohibition against requiring specific security measures for approval of site security plans also applied to DHS providing suggestions to facilities about how to get their programs within compliance. Some inspectors have been more aggressive than others in limiting their suggestions to avoid the appearance of requiring a security measure and this makes it harder for facilities to know what changes need to be made to get their SSP authorized.

The language of {§2102(c)(2)(A)(ii)} will certainly make this clearer for facilities submitting alternative security plans (ASP) and I think that most inspectors (and inspectees) will assume that it is okay for an inspector to let a facility know what types of things have been used at other facilities to respond to a specific security situation.

Consultation with Labor Organizations

The language of §2102(e)(1) and §2109 could have only been added in the Democrat controlled Senate. Having said that, since the relationship with the labor organizations is only consultative, this language should not raise any significant ire in the Republican controlled House. There were lots of other labor inspired additions that could have been added to the bill that could have interfered with its adoption by the House.

Moving Forward


The earlier in September that this bill comes to the floor of the Senate for a vote (which will almost certainly have bipartisan support) the better the bill’s chances of getting through Conference before the November elections.

Wednesday, April 30, 2014

Another Information-Sharing Draft Bill

There was a short article over on the WashingtonPost.com Monday about a draft Senate bill addressing information sharing with respect to cybersecurity. The editors were kind enough to share a link to the possible proposed legislation that is being crafted by Sen. Feinstein (D,CA) and Sen. Chambliss (R,GA).

It is way too early in the process to delve too far into this bill as it is way early in the legislative process and may die without being introduced. Having said that, there are some interesting provisions being considered. Before going into those I must warn readers that this is at heart an IT bill with no mention of control systems and I want to remind readers that Senate cybersecurity bills normally die with even less action than in the House.

There is the definition of the term ‘malicious reconnaissance’ {§2(15)} that is an apparent attempt to deal with the separation of cyber-attacks from the mere act of unauthorized access of a system. This combined with the reference to First Amendment protections in the definition of ‘cybersecurity threat’ would seem to protect political hacking of a system for information gathering purposes.

The draft bill would provide limitations on the government use of information voluntarily shared with the Federal government. Those limitations would include the prohibition of:

• Public disclosure under Federal, State and local disclosure laws;
• Use in regulatory actions;
• Use in criminal prosecutions (without prior written consent of original discloser).

It would provide anti-trust exemptions for cybersecurity information sharing between private entities. This would address the issue raised by recent ephemeral DOJ opinions about the non-applicability of anti-trust laws.


Finally, I must repeat my cautionary statement about the potential for this bill to move forward in the Senate. There have been many cybersecurity bills discussed in the Senate that were never introduced. Few of those that have been introduced ever saw any Committee action and none have made it to the floor for a vote. This is still an interesting IT security bill.

Thursday, April 14, 2011

Senate to Consider HR 1473 Today

According to the Daily Digest for the Congressional Record (pg D 403) the Senate reached a unanimous consent agreement yesterday to consider HR 1473 today as soon as the House notifies them that they have completed action on the bill and its two associated resolutions.

The agreement requires that 60 votes will be necessary for passage. This may be a tough requirement for the bill, but it will be a certain death knell for the two amending resolutions.

The Senate will consider the three items in a different order than will be used in the House. The Senate will consider H. Con. Res 35, then H. Con. Res 36 and then, finally, HR 1473. The House rule called for a vote on HR 1473 with the other two votes to follow only if HR 1473 passes. Apparently there are those in the Senate leadership that were concerned that some members might not vote for HR 1473 if the possibility existed that either (or both) of the two resolutions could also be passed.

That the Senate was able to agree to this consideration format has ensured that a vote will take place if/when the House passes the bill. No one Senator from either extreme will be able to stop the consideration of the bill. It certainly isn’t a guarantee that the bill will pass (I’m betting that it will), but it does insure that a vote will take place.
 
/* Use this with templates/template-twocol.html */