Wednesday, April 19, 2023

Review – S 905 Introduced – Drone Zoning

Last month, Sen Lee (R,UT) introduced S 905, the Drone Integration and Zoning Act. The bill would provide for State and local government authority over ‘civil unmanned aircraft systems’ within 200-ft above the ground. Currently, sole jurisdiction over US airspace rest with the Federal Aviation Administration. This bill is very similar to S 600 introduced last session, and S 2607 which Lee introduced in the 116th Congress. No action was taken on either bill.

Moving Forward

Lee is not a member of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. This means that Lee no longer has the influence to see the bill considered in Committee. Of course, when he did have the potential influence in the last session, the bill was not considered. This is almost certainly due to the fairly radical change that this bill makes with respect to the regulation of the national airspace, designating areas over which the FAA does not have regulatory authority over aircraft operations.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-905-introduced - subscription required.

CISA Announces CSTAC Meeting – May 16th, 2023

Today, CISA published a meeting notice in the Federal Register (88 FR 24205-24206) for “Notice of President's National Security Telecommunications Advisory Committee Meeting” to be held in Washington, DC on May 16th, 2023. Portions of the meeting will be open to the public via teleconference.

The agenda for the public portion of the meeting includes:

• A keynote address; and

• A status update on the Addressing the Abuse of Domestic Infrastructure by Foreign Malicious Actors Subcommittee.

Personnel wishing to participate in in the public teleconference should contact NSTAC@cisa.dhs.gov by May 9th, 2023. Written comments on the agenda items (including the classified, non-public portions of the agenda) may be submitted via the Federal eRulemaking Portal (www.Regulations.gov, Docket # CISA-2023-0007) by May 9th, 2023

Bills Introduced – 4-18-23

Yesterday, with both the House and Senate in session, there were 66 bills introduced. One of those bills will receive additional attention in this blog:

HR 2670 National Defense Authorization Act (NDAA) for Fiscal Year 2024 Rogers, Mike D. [Rep.-R-AL-3]

While the ‘text’ of this bill is currently available, it is just the vaguest outline of the final bill with just the opening section of three Titles provided. The House Armed Services Committee and its various subcommittees will be fleshing out the details of the bill in hearings over the coming weeks. Only when that process is complete will we know what the final version of the bill will be that will come to the floor of the House for consideration. And then the amendment process will begin. The NDAA process is probably the most inclusive (from a member’s perspective) process for a major piece of legislation in the House. And this makes it one of the most bloated pieces of legislation outside of the spending bills that Congress routinely passes every year.

If the Republicans are going to fulfill their promise of limiting bills to a single purpose this bill will be a main target for their efforts. It will not change, there are just too many options for adding boondoggles, both funding and policy, in this process. Having said that, I expect there to be some major Republican infighting over this fattening up process between now and when this bill comes to the floor of the House. And they may have problems passing an NDAA this year.

Tuesday, April 18, 2023

Review - S 914 Introduced – DOE Threat Analysis Center

Last month, Sen Risch (R,ID) introduced S 914, the Energy Threat Analysis Center (ETAC) Establishment Act of 2023. The bill would formally authorize the ETAC which DOE started last year as a pilot project (see here, here, and here). No separate funding is provided in the bill.

Moving Forward

Both Risch and his sole cosponsor (Sen Manchin {D,WV)} are members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. Since no new funding is authorized by the bill, I see nothing that would engender any specific opposition. I suspect that there would be some measure of bipartisan support for the bill, probably enough to achieve 60 votes for cloture if the bill were to be considered under regular order.

Commentary

The crafters of this bill did not see the lack of specific funding for the NTAC to be a problem. They expected DOE to continue to tap into the funding ($50,000 per year through 2026) provided in §18724(d). that was the reason for the reference §18724 in §2(a) of the bill. It is almost as if the crafters of the §40125(c) of the Infrastructure Investment and Jobs Act (Public Law No: 117-58) that is responsible for §18724 planned it that way.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-914-introduced - subscription required.


Short Takes – 4-18-23

Pacific garbage patch providing a deep ocean home for coastal species. Arstechnica.com article. Pull quote: “Finally, the researchers caution against a natural tendency to think of these plastic-borne coastal species as "misplaced species in an unsuitable habitat." Instead, it appears that they are well suited to life in the open ocean as long as there's something there that they can latch on to.” It seems life adapts.

Amazon Web Services gets set to ignite space accelerator program’s third stage. Geekwire.com article. Pull quote: ““Cloud computing is incredibly important to our business strategy, as handling all of the ITAR restrictions with an on-premises solution would be very difficult – in addition, it allows us to scale to hundreds of thousands of users and anticipate our costs easily,” he said.” Interesting outlook on cloud services.

NERC opposes expanding physical security rules for critical substations following Duke, PSE, other attacks. UtilityDive.com article. Pull quote: “But NERC’s report concluded establishing a “uniform, bright line set of minimum physical security protections” for all BPS substations and associated primary controls centers “is unlikely to be an effective approach to mitigating physical security risks and their potential impacts” because it “fails to provide for a methodical approach necessary to address site-specific threats or objectives.””

Discord flushes leaked docs, reposters after leading FBI to prime suspect. ArsTechnica.com article. Pull quote: “Identifying classified materials unlawfully shared on its platform is not a straightforward process for Discord, though. In a blog, Discord noted that "only authorized government personnel can determine whether a document is classified, unclassified, or even authentic. And currently, there is no structured process for the government to communicate their determinations to platforms like Discord."”

VA’s New Cyber Apprenticeship Program Will Focus on Training for Underserved Veterans. GovExec.com article. Pull quote: “VA is currently developing a strategic communications campaign to outline its recruitment and application processes for the program. Tierney said that effort will also include a more targeted recruitment drive focused on veterans that “have adjacent skill sets and interest,” such as those “that have separated from service within the last five years, as well as veterans in the VET TEC program.” Only five slots in initial program.

Transportation Worker Identification Credential-Facility Reader Requirement; Conforming Amendment. Federal Register CG direct final rule. Summary: “The Coast Guard is amending its Risk Group A facility regulations so that their provisions to implement Transportation Worker Identification Credential (TWIC) electronic inspection requirements by May 8, 2023, is changed to May 8, 2026. This will revise our regulations to conform with recently passed legislation. The James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (Authorization Act) was enacted December 23, 2022. A provision within the Authorization Act directs the Secretary of Homeland Security to not implement TWIC reader regulations for certain facilities before May 8, 2026. This conforming amendment will have no substantive effect. Controlling statutory authority already nullifies the May 8, 2023, implementing dates in our regulations. We note there is a separate ongoing rulemaking to address whether the implementation date should remain May 8, 2026, or be moved to a later date. The Authorization Act was enacted after the Coast Guard published the proposed rule for that separate rulemaking.” Effective March 17th, 2023.

National Cybersecurity Center of Excellence Mitigating Cybersecurity Risk in Telehealth Smart Home Integration. Federal Register NIST notice. Summary: “The National Institute of Standards and Technology (NIST) invites organizations to provide letters of interest describing products and technical expertise to support and demonstrate security platforms for the Mitigating Cybersecurity Risk in Telehealth Smart Home Integration project. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the Mitigating Cybersecurity Risk in Telehealth Smart Home Integration project. Participation in the project is open to all interested organizations.”

Review – 2 Advisories and 2 Updates Published – 4-18-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Schneider and Omron. They also updated two advisories for products from Mitsubishi and Omron.

Advisories

Schneider Advisory - This advisory describes three vulnerabilities in the Schneider Easy UPS Online Monitoring Software.

Omron Advisory - This advisory describes a missing authentication for critical function vulnerability in the Omron SYSMAC CS/CJ Series programmable logic controllers.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on January 17th, 2023 and most recently updated on January 26th, 2023.

Omron Update - This update provides additional information on an advisory that was originally published on November 30th, 2021 and most recently updated on November 29th, 2022.

 

For more details on these advisories, including links to researcher reports and a brief description of the changes made in the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-2-updates-published-c83 - subscription required.

TSA Publishes 30-Day ICR Extension for Surface Trans Security Training

Today, TSA published a 30-day information collection request (ICR) extension notice in the Federal Register (87 FR 23681-23682). The 60-day ICR notice for this ICR was published on January 10th, 2013. Today’s notice repeats the revised burden estimate (218 respondents, 4,623 hours) from the earlier ICR notice, but again provides no explanation for the revised numbers. We will have to wait and see what TSA reports to OMB’s Office of Information and Regulatory Affairs (OIRA), probably later this week, to determine the cause of the downwardly revised numbers.

 
/* Use this with templates/template-twocol.html */