Showing posts with label Structured Rule. Show all posts
Showing posts with label Structured Rule. Show all posts

Monday, June 15, 2015

Rules Committee Approves Rule for HR 2596

This evening the House Rules Committee met to develop the rule for the floor consideration of HR 2596, the FY 2016 intelligence authorization bill. As expected the bill will be considered under a structured rule with only 16 amendments allowed to be offered on the House floor tomorrow.

Five of the amendments may be of specific interest to readers of this blog:

#2 Rep. Israel (D,NY) - Requires the Director of National Intelligence to provide report to the congressional intelligence and defense committees on the cyber threat trends identified by the Cyber Threat Intelligence Integration Center, an assessment of collaborative efforts between federal agencies, and recommendations to improve those collaborative efforts.

#5 Rep. Keating (D,MA) - Restores reporting requirement on the progress of the Federal Bureau of Investigation in implementing information-sharing principles.

#7 Rep. Rooney (R,FL) - Requires a report detailing the Intelligence Community's utilization of the National Science Foundation's CyberCorps Scholarship for Service program.

#8 Rep. Moulton (D,MA) - Requires a report and briefing regarding the impacts on the intelligence community (IC) of the recently disclosed cyber breach at OPM.

#13 Rep. Wilson (R,SC) - Directs the Director of National Intelligence to study how we measure cyber attacks and report to the relevant committees in both a classified and unclassified format.


Sharp eyed readers will note the similarity of amendment #13 to HR 2708 that I reported on earlier today. Apparently the Rules Committee did not share my opinion on the inappropriateness of this measure.

Thursday, June 13, 2013

Rules Committee Adopts Rule for Amending HR 1960

Early this morning the House Rules Committee adopted H Res 260, a structured rule for the consideration of amendments to HR 1960, the FY 2014 DOD authorization bill. The rule provides for the consideration of 172 amendments to the bill on the floor of the House with up to 10 minutes of debate authorized for each of the amendments (this could take some time).

There is an interesting provision of the rule which could significantly shorten the time it takes to consider these amendments. At any time in the debate the Chair of the House Armed Services Committee can offer the remain amendments en-bloc (all at one vote) with just 20 minutes of debate for all of the amendments to be considered. This makes it more likely that the later amendments in this extensive list will be adopted.

Cybersecurity Amendments

Six of the amendments to be considered deal with cybersecurity issues.

• 98 #220 Version 2 Cárdenas (D,CA) Revised Ensures that an assessment of the retention, recruitment, and management of the cyber operation forces is included in a comprehensive mission analysis of cyber operations by the Department of Defense.

• 99 #218 Version 2 Cárdenas (D,CA) Revised Ensures that the investigations launched by the Department of Defense related to the compromise of critical program information include an estimate of economic losses resulting from the intrusion and any actions needed to protect intellectual property.

• 100 #126 Version 1 Ruiz, Raul (D,CA) Requires the Secretary of Defense to submit a report to the Congress on the feasibility of establishing a small business cyber technology office to assist small business concerns in providing cybersecurity solutions to the Federal Government.

• 101 #219 Version 1 Cárdenas (D,CA) Authorizes the Department of Defense to create a education program to assist small business understand cyber security threats.

• 102 #267 Version 1 DeSantis (R,FL) Prohibits funds from being authorized for collaborative cyber-security activities with the People's Republic of China.

• 166 #117 Version 1 Issa (R,CA) , Connolly (D,VA) Reforms the process by which Federal agencies procure products and services related to information technology.

NOTE: The first number in the above listing shows the order in which the amendment will be considered. It will be interesting to see at what point in the debate that the decision is made to consider the remaining amendments en bloc.

I have not yet had a chance to review them in detail but it does not appear that any of them specifically deal with control system security issues.

Moving Forward


The debate on HR 1960 could resume any time after H Res 260 is adopted by the House. I expect that that vote will happen today and we will see late night sessions today and tomorrow with a vote on the final bill on Friday morning. The bill will certainly pass, probably with substantial bipartisan support. Gaining that Democratic support is the main reason for the consideration of so many amendments.

Thursday, April 26, 2012

HR 3523 Rule


NOTE: Links added in first paragraph 4-26-12 05:51 EDT.
Last night (Wednesday) the House Rules Committee adopted therule for the consideration of HR 3523, the Cyber Intelligence Sharing and Protection Act (CISPA) on Thursday and Friday of this week. This will be a structured rule providing for limited debate (one hour on the bill and 10 minutes for each amendment) and allows for consideration of 16 specificamendments.

The vast majority of the amendments that will be considered on the floor of the House will deal with privacy issues; nothing surprising there.

Still No Mention of Control System Security


None of the amendments addresses control system security. There is one amendment that could be construed (with some imagination) to kind of possibly extend some of the definitions of covered ‘systems or networks’ so that an aggressive regulation writer might be able to use to justify trying to expand this bill to include control systems (did I get enough waffle words in there?). Rep. Turner’s (R,NY) amendment (#14) would add ‘deny access to’ in various definition phrases {§1104(h)}; “efforts to degrade, disrupt, or destroy such system or network”.  A denial of service attack on a control system might then be covered. The other components of that definition would not really apply to a control system attack since that attack only uses a control system network to attack the controlled physical system.

No Requirement for Feds to Share


As I noted in an earlier blog posting about this bill, there are not any provisions in the current version of the bill that would direct or require DHS or the intelligence community to share threat information with the private sector. Rep. Richardson (D,CA) has offered an amendment that almost comes close to allowing federal agencies to share information with the private sector. Her amendment (#10) would make clear that nothing in the bill would “prohibit a department or agency of the Federal Government from providing cyber threat information to owners and operators of critical infrastructure” {§1104(g)(3)}. That’s a long way from requiring such sharing.

No Requirement for Private Sector to Participate


There was never a requirement for any private entity to participate in any sharing activity under this bill. Just in case this wasn’t clearly understood, Rep. Woodal (R,GA) has proposed an amendment (#12) that specifically states that there is no liability “for choosing not to engage in the voluntary activities authorized under this section” {§1104(g)(3)}. Some people just need to ensure that voluntary means uh voluntary.
 
/* Use this with templates/template-twocol.html */