Thursday, March 3, 2022

Review - HR 6825 Introduced – Nonprofit Grant Program

Last month, Rep Thompson (D,MS) introduced HR 6825, the Nonprofit Security Grant Program Improvement Act of 2022. The bill would amend 6 USC 609a, the Nonprofit Security Grant Program. The amendments include adding new allowed uses of the funds and requires FEMA to establish a program office to administer the grant program. The bill would increase the funding for the program and extends that funding through 2028.

The bill was approved yesterday by a voice vote in the House Homeland Security Committee after substitute language was approved. Among the changes made by the substitute is a provision that specifically includes the risk of “extremist attacks other than terrorist attacks and threats’ in the coverage of the grant program.

Moving Forward

Passage by voice vote in Committee indicates that there is at least some measure of bipartisan support for this bill. There was an attempt by Rep Higgins (R,LA) to express some concerns with this bill, but there was no follow-up at the end of the hearing. I suspect that the legislation will be considered in the Full House under the suspension of the rules process. It will probably pass with bipartisan support.

Commentary

While §609a does currently allow for the use of grant funds for cybersecurity training {§609a(c)(2)} and ‘cybersecurity resilience activities’ {§609a(c)(2)}, that funding only extends to protection against terrorist attacks or threats of such attacks. The substitute language addition of ‘extremist attacks’ allows DHS to include threats from domestic groups without the political baggage of trying to identify domestic terrorist groups. This is almost certainly why there is no definition of the term ‘extremist attacks’.

Still, this does not address the expanding need for protection against non-terrorist (or even extremist) cyberattacks like ransomware attacks. This bill would have been an ideal place to include protection against ransomware attacks as an allowed use of grant funds. With this bill probably going to the Full House under the suspension of the rules process, the chances for amending the bill have essentially passed.

Perhaps it is time to change the definition of ‘terrorism’ to specifically include ransomware attacks.

 

For more details about the provisions of the bill and the substitute language, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6825-introduced - subscription required.

Wednesday, March 2, 2022

Reader Comment – Pipeline Security and Ukraine

A long time reader pointed me at an article over at the new International Pipeline Resilience Organization web site and asked me what I knew about the organization. First part of that is simple, I’ve never heard of them, but they appear to be a new organization. Further, I have had very little contact with the pipeline industry, so I do not recognize any of the names listed on their ‘Leadership’ page. I do find it interesting that a large portion of their leadership comes from a single large law firm.

The article, though, that I have some thoughts on.

First off, nothing really new here except for the brief mentions about the benefits of joining their organization. The ‘increased cyber threat’ from Russia is a common thread seen in most of the messaging from most of the thought leaders in cybersecurity. The refrain goes that Russia has been aggressive in their cyber activities in stealing information and getting footholds in systems from the federal government to critical infrastructure long before their military crossed into Ukraine. And there were certainly a wide variety of cyber attacks against the Ukraine before the physical attacks started. So, we must (the conventional wisdom goes) expect that the Russians will attack our critical infrastructure.

I am sorry, but I have to take a contrarian stand here, the last thing Putin wants to see now is a really pissed off USA and/or NATO. He bit off more than he can conveniently chew and was obviously surprised at how well, NATO, the European Union, and the United States responded in a coordinated manner in exercising their individual and combined economic muscle in response to the Russian invasion. That combined with the strong nationalistic response from the citizens of the Ukraine, the unexpected leadership shown by large portions of the civilian government of the Ukraine, have all made the mission of the Russian armed forces much more difficult than expected.

 

Putin realizes that the last thing he needs to see at this point is an introduction of NATO forces into the conflict. Even just a NATO air campaign to remove Russia’s air superiority would almost certainly give the Ukrainian military the final tool it needs to repel the Russian forces, or worse yet, capture large portions of the stalled Russian equipment sitting in the mud of the steppes. This realization on Putin’s part is almost certainly a major reason for his threats about nuclear escalation. A significant cyberattack on critical infrastructure in NATO would be the final spur that would drive movement of NATO forces eastward.

So, we can ignore the cybersecurity ‘threat’ from Russia, right? Sorry, nothing in Eastern Europe is ever that simple. What we really have to concern ourselves with is the reaction of the masses in Russia. As the sanctions begin to take hold and Russians start to hear more from their disillusioned soldiers about the conditions in Ukraine (lack of food and fuel really hurts military morale), Putin is going to have to start worrying about an uprising back home. Putin’s concern about this possibility may be what has driven his keeping most of his military forces at home.

If that threat becomes real, then Putin might decide that he needs a NATO incursion into Ukraine to justify his actions. Again, the easiest way to encourage that response would be to execute a limited cyberattack on Western interests. And non-catastrophic cyberattacks on gas and fuel pipelines would be an effective target for such attacks. So, do not stop working on improving your cybersecurity posture.

Review - Senate Passes S 3600 – Cybersecurity

Yesterday, the Senate took up S 3600, the Strengthening American Cybersecurity Act of 2022, which was introduced last week. The Senate considered the bill under the unanimous consent process. After adopting two amendments, the Senate passed S 3600 without debate or vote. The bill contains FISMA modifications similar to those found in S 2902, cybersecurity incident reporting requirements similar to those found in S 2875, as well as federal cloud security requirements.

Moving Forward

This strongly bipartisan action by the Senate would seem to grease the skids for this to pass quickly through the House and land on the President’s desk. Unfortunately, there are competing versions of portions of this bill in the House and this bill will have to overcome the ‘my bill first’ claims from at least two different House committees, Homeland Security and Science, Space, and technology. The current concerns about the Russian/Ukrainian related cybersecurity threats, may provide sufficient impetus to bring this bill to the floor of the House. If it gets by the two Chairs, this bill could easily be considered under the House suspension of the rules process and it could be on the President’s desk before the end of the month, or it could still be sitting on the Clerk’s desk at the end of the year.

Commentary:

This bill reflects a great deal of behind the scenes bargaining in the Senate. This will probably be the premier cybersecurity legislation for this Congress. My review today was done quickly to get it out and I am going to have to take a very detailed look at the cyber incident reporting requirements of §203. That post will come out later this week.

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/senate-passes-s-3600 - subscription.

Tuesday, March 1, 2022

HR 6868 Introduced – School Cybersecurity Grants

Earlier this week, Rep Garbarino (R,NY) introduced HR 6868, the Cybersecurity Grants for Schools Act of 2022. The bill would amend 6 USC 665f (which established the Cybersecurity Education and Training Assistance Program), expanding the scope of entities that could receive grants under the CETAP grant program.

The bill would add a new subsection (e) to §665f that would allow CETAP grants to go to States, local governments, institutions of higher education, nonprofit organizations, and other non-Federal entities for the purposes of funding cybersecurity education or training programs.

As I noted on Monday, this bill will be marked up tomorrow by the House Homeland Security Committee. No amendments to this bill are currently listed on the Hearing web site. I expect that this bill will be adopted by the Committee, probably by a voice vote. The bill will move to the full House later this year.

T&I Committee to Markup HR 6865 - CG Authorization

This afternoon, the House Transportation and Infrastructure Committee updated their website for tomorrow’s markup hearing. As I wrote yesterday, that hearing will consider HR 6856, the Coast Guard Authorization Act of 2022. The update today included a link to a Committee Print of the bill and a list of amendments that are currently scheduled for consideration.

There is currently nothing in the bill relating to cybersecurity, or the Maritime Transportation Security Act, or chemical safety issues. Pipeline safety is obliquely addressed in §403, Providing requirements for vessels anchored in established anchorage grounds. It adds a new §70006, Anchorage grounds, to 46 USC. It would require the CG to “define and establish anchorage grounds in the navigable waters of the United States for vessels operating in such waters” {new §70006(a)(1)} as well as regulating such anchorage grounds. Factors to be consider in the definition would include “proximity to undersea pipelines and cables” {new §70006(a)(2)}.

None of the listed amendments are of any particular interest here.

Review - OMB Approves Two Generic TSCA ICRs

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved two EPA information collection requests { TSCA Existing Chemical Risk Evaluation and Management - Generic ICR for Surveys (2070-0218) and TSCA Existing Chemical Risk Evaluation and Management; Generic ICR for Interviews and Focus Groups (2070-0219)}. The EPA would use these ICRs to request chemical safety information on new investigations without having to go through the ICR submission process for each new investigation.

The EPA justified both ICRs on the basis that in support of the requirements of §6 of TSCA (pg 26) “EPA needs sufficient information about chemicals undergoing risk evaluation and risk management, including information related to the chemicals’ conditions of use, hazards, exposures, potentially exposed or susceptible subpopulations, health and environmental effects, benefits, reasonably ascertainable economic consequences, alternatives, and other information.” Given the time frame requirements of §6(c), the EPA would not be able to submit an ICR for each required investigation.

The EPA notes that the information collected in both ICRs would be shared with the Occupational Health and Safety Administration (OSHA) and the Consumer Product Safety Commission (CPSC).

Commentary

The use of generic ICRs initially seems to run counter to the whole purpose of the Information Collection Request process. The purpose of ICRs is to ensure that government agencies do not misuse their power to collect information to either overwhelm businesses with reporting requirements nor demand information for which they have little, or perhaps even no legal basis, to collect. Having said that, the ICR process is a time consuming, bureaucratic process. In instances like these, where the legal justification for the collection of the information concerned would be the same for each separate investigation pursued by the EPA pursuant to §6 of TSCA, it seems clear to me that in this case, at least, the EPA is justified in simplifying the bureaucratic process.

I am concerned, however, with the reported intent of the EPA to share the information collected, presumably with appropriate CBI protections, with the OSHA and CPSC. To be sure, another responsibility of the ICR approval process is the avoidance of duplicate information activities, but it is not clear that either OSHA or CPSC would have specific authority to collect the data outlined in these ICRs.

Sharing of chemical safety information between various regulatory and oversight agencies is an important part of ensuring that all agencies have the applicable information necessary to discharge their legal responsibilities. But agencies collecting voluntary information from the private sector have a clear responsibility to outline what information they intend to share with other agencies and request public comment on what limits would be appropriate for the sharing of that information.

For more details about these information collection requests, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/omb-approves-two-generic-tsca-icrs - subscription required.

Bills Introduced – 2-28-22

Yesterday, with both the House and Senate back in Washington, there were 38 bills introduced. Four of those bills may receive additional coverage in this blog:

HR 6865 To authorize appropriations for the Coast Guard, and for other purposes. Rep. DeFazio, Peter A. [D-OR-4] 

HR 6868 Cybersecurity Grants for Schools Act of 2022 Rep. Garbarino, Andrew R. [R-NY-2] 

HR 6869 To authorize the President of the United States to issue letters of marque and reprisal for the purpose of seizing the assets of certain Russian citizens, and for other purposes. Rep. Gooden, Lance [R-TX-5]

HR 6873 Bombing Prevention Act of 2022 Rep. Malinowski, Tom [D-NJ-7]

I will be watching HR 6865 for language addressing cybersecurity and the Maritime Transportation Security Act (MTSA) program. The House Transportation and Infrastructure Committee to which this bill was assigned for consideration will hold a markup hearing on the bill tomorrow. A committee print of the bill is not yet available on the Committee website.

HR 6868 is a cybersecurity job training package not a bill funding cybersecurity for schools. I will be covering this bill.

HR 6873 is a perennial attempt to codify the existing Office for Bombing Prevention in DHS. I will be covering this bill.

HR 6869 is one of a number of bills that was introduced yesterday that appears to be a response to last week’s invasion of Ukraine. I suspect that this bill is dead on arrival as an overreach, but I will be covering the bill because of the cybersecurity implications it carries.

For those that are interested (there will be no further coverage here), here is a listing of the other bills introduced yesterday that appear to be responses to the Russian invasion:

H.R.6867 To designate the area between the intersections of 16th Street, Northwest and Fuller Street, Northwest and 16th Street, Northwest and Euclid Street, Northwest in Washington, District of Columbia, as "Oswaldo PayĆ” Way". NOTE: This is the location of the Russian Ambassador’s residence.

H.R.6874 To establish a program to reduce the reliance of allied European countries on natural gas, petroleum, and nuclear fuel produced in Russia, and for other purposes.

H.R.6876 To provide authority for the President to authorize the United States Government to lend or lease defense articles to the Government of Ukraine to help bolster Ukraine's defense capabilities and protect its civilian population from potential invasion by the armed forces of the Government of the Russian Federation, and for other purposes.

 
/* Use this with templates/template-twocol.html */