Showing posts with label Wassenaar Arrangement. Show all posts
Showing posts with label Wassenaar Arrangement. Show all posts

Thursday, September 1, 2016

OMB Approves 2015 Wassenaar Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the Department of Commerce’s direct final rule implementing the Wassenaar Arrangement 2015 Plenary Agreements. This rulemaking was submitted to OIRA on July 29th.

The Unified Agenda entry for this rulemaking notes that: “Because this year's WA agreements include the total restructuring of Category 5 part 2 [Information Security], BIS is taking this opportunity to also streamline and update license requirements and policies associated with Category 5 part 2 in this rule.”

Note: The current Category 5 part 2 of the US Commerce Control List (CCL) can be found here (.PDF Download) and the new version proposed in the 2015 Plenary Agreement can be found on pages 85 – 90 here (.PDF).


There is no telling when this will be published in the Federal Register. There have been significant delays between the OIRA approval and subsequent publication for a number of rules in the last couple of months. This is probably due to additional political reviews to ensure that rulemakings do not get labeled as midnight rules in the last six months of the Obama administration.

Tuesday, August 2, 2016

New Wassenaar Rule Sent to OMB

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule for review from the DOC’s Bureau of Industry and Security (BIS) concerning the latest updates to the 2015 Wassenaar Arrangement implementation. This rulemaking does not appear to address the ‘intrusion software’ issues associated with the 2013 Wassenaar Arrangement.

According to the abstract in the 2016 Spring Unified Agenda listing for this rulemaking this rulemaking will address:

“This rule harmonizes the CCL [the Commerce Control List] with the changes made to the WA List at the Plenary by revising Export Control Classification Numbers (ECCNs) controlled for national security reasons in each category of the CCL, as well as making other associated changes to the EAR. The WA agreements include raising of the Adjusted Peak Performance for high performance computers, therefore other parts of the EAR that have APP limitations are also amended by this rule, e.g., de minimis, License Exception APP, reporting requirements. This rule removes the Foreign National Review requirement associated with deemed exports under License Exceptions APP and CIV, because after years of reviewing these requests with no denials ever coming from this information BIS has determined it is not an efficient use of U.S. Government resources. Because this year's WA agreements include the total restructuring of Category 5 part 2, BIS is taking this opportunity to also streamline and update license requirements and policies associated with Category 5 part 2 [Information Security .PDF download] in this rule.”

The information security license and policy update portion of this rule should probably be watched fairly closely when it is published. Again, this is a direct final rule without the normal publish and comment process being required. This is the same process that was used (and later withdrawn) on the intrusion software rulemaking last year.

Thursday, August 6, 2015

Amendments to S 754 – 08-05-15

Yesterday there were 23 additional amendments submitted in the Senate for S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015. Only three of those proposed amendments may be of specific interest to readers of this blog.

SA 2623. Ms. Collins, pgs S6411;
SA 2626. Mr. Whitehouse, pgs S6415-6; and
SA 2628. Mr. Wyden, pg S6419

The Amendments

The Collins amendment would require the owners of ‘critical cyber infrastructure’ to report to the DHS Secretary or appropriate agency head “if an information system of a covered entity that is essential to the operation of critical cyber infrastructure is successfully intruded upon” {new §lll(b)(1)}; note that there is no definition of ‘successfully intruded upon’ provided. The report would include {new §lll(b)(2)}:

A description of the technique or method used in such intrusion;
A sample of the malicious software, if discovered and isolated by the covered entity, involved in such intrusion;
Damage assessment; and
Such other matters as the Secretary or the appropriate agency head, as the case may be, consider appropriate.

The Whitehouse amendment would add a new section to the US criminal code; 18 USC 1030A. This new section would make it a federal crime “during and in relation to a felony violation of section 1030, to knowingly cause or attempt to cause damage to a critical infrastructure computer” {new §1030A(a)}. Unfortunately, because of the definition of ‘protected computer’ in §1030(e)(2) only attacks on financial institutions or communications companies would give rise to the underlying felony that is a required part of this new definition. I do not think that that was the intent.

The Wyden amendment would require the Secretary of Commerce to reconsider the rulemaking concerning the implementation of the Wassenaar Arrangement 2013 Plenary Agreements Implementation: Intrusion and Surveillance Items. The reconsideration would include drafting a supplemental of proposed rulemaking that is written in consultation with “civil society organizations, including privacy advocates, public and private sector technologists, security researchers, and public and private sector software developers” {new §ll(b)(1)}. The new proposed rule would be required to be:

Limited to the scope of the agreements reached at the plenary meeting of the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies in December 2013;
Consistent with the regulation of cybersecurity items by other countries participating in the Wassenaar Arrangement, as appropriate; and
Exclude cybersecurity items available for mass-market purchase from regulation under the proposed rule

Agreement to Consider the Bill

A unanimous consent agreement was reached yesterday to allow for the Senate to move forward with the consideration of the bill without having to go through a cloture procedure. That agreement calls for the consideration of 21 specific amendments; ten from the Republicans and eleven from the Democrats. There is a possibility that other amendments may be subsequently considered.


Of the seven amendments that I discussed here yesterday and today only one is on either list; Whitehouse 2626. Most of the remaining ones that I discussed were excluded from consideration because they did not directly deal with cybersecurity information sharing.
 
/* Use this with templates/template-twocol.html */