Showing posts with label Legislation. Show all posts
Showing posts with label Legislation. Show all posts

Tuesday, December 11, 2018

Goldman's CISO Andy Ozment Balks at Tangle of Cyber Regulations

CNBC reports on CISO Andy Ozment's take on the current chaotic and cumbersome patchwork of cybersecurity laws.

Thursday, October 11, 2018

Gov's Cyber Performance: 10 Key Metrics

Performance.gov published the Federal government's Cybersecurity Key Performance Indicator report for Q3 FY 2018. 10 key metrics were measured for 23 agencies.

Key Performance Indicators for Federal Cybersecurity
Source: Performance.gov

Performance.gov was created to fulfill the statutory requirements of the Government Performance and Results Act of 1993 and the GPRA Modernization Act of 2010 legislating the creation of an online performance reporting portal. The portal provides information about the President's Management Agenda (PMA), the Federal performance management framework, and the federal goal-setting process.

Here is a good article on the report.

Wednesday, October 10, 2018

Foreign Political Influence, Manafort, and FARA Enforcement

FARA, or the Foreign Agents Registration Act, is a law that was originally passed in 1938. It essentially requires that people who represent foreign interests in a political capacity register with the Department of Justice and publicly disclose certain transactions. From the NY Times:
Lobbyists that register under FARA must report specific meetings, phone calls and other details of contacts with members of Congress or federal officials to the Justice Department, which then posts the material online.
FARA is administered and enforced by the FARA Registration Unit under the Department of Justice's National Security Division's (NSD) Counterintelligence and Export Control Section (CES).

Over the course of its enactment, the law has only been lightly enforced, with the emphasis being on voluntary compliance.

Paul Manafort, Trump’s former campaign chairman, has been the most prominent FARA case to be prosecuted in five decades. During the previous five decades, only 7 people have been criminally charged under the law.

Manafort has represented the interests of many foreign government and political group clients over his career. In more recent years, he reportedly received $60m from Ukraine oligarchs to help promote their political interests, one of those was helping to bring Ukraine's now former pro-Russian president to office. Though Manafort had been investigated many years before and told to correct his filings under FARA he never did.

In addition to light enforcement, FARA has some further shortcomings. Again from the NY Times:
Congress is also considering whether to strengthen the statute. A bill sponsored by Senator Charles E. Grassley, the Iowa Republican who leads the Senate Judiciary Committee, would close a major loophole by requiring lobbyists hired by foreign commercial interests to file FARA reports. 
Currently, lobbyists representing foreign commercial interests register only with Congress, which requests minimal information, while those who represent foreign “principals” working for the benefit of foreign governments or political parties register with the Justice Department. The dual disclosure regimes create a huge gray area because in many countries, including Russia and Ukraine, the line between commercial and government interests is heavily blurred.
Some privacy, non-profit, and pro-business groups are opposing the bill saying the original bill is still too vague and needs to be cleaned up before new legislation makes sweeping and possibly politicized investigations easier.

Due in part to the recent activity with Manafort and Mueller’s Special Counsel investigation, there have been 50% more new FARA registrations this year from last.

Tuesday, October 9, 2018

Testimony on Sanctions Programs, Particularly for Iran, Russia, and North Korea

The Treasury's Assistant Secretary for Terrorist Financing Marshall Billingslea
testifies for a hearing on sanctions programs on September 26, 2018.


Marshall Billingslea testified for a Congressional hearing titled “Administration Goals for Major Sanctions Programs” on September 26, 2018.

His introduction by Congressman Barr details his long history of public service (at 37:35):
Today we welcome the testimony of Marshall Billingslea who was confirmed in June of 2017 as Assistant Secretary of the Treasury for Terrorist Financing. In this role he helps oversee the Trump administration's efforts in administering economic sanctions programs globally.

Prior to joining Treasury Mr. Billingsley served as managing director for business intelligence services at Deloitte Advisory. He had previously held positions at the Department of Defense where he served as Deputy Under Secretary of the Navy and Principal Deputy Assistant Secretary of Defense for Special Operations and Low Intensity Conflict.

Mr. Billingsley has also worked as NATO Assistant Secretary-General for Defense Investment and as a staff member on the Senate Foreign Relations Committee. He is a recipient of the Defense Medal for Distinguished Public Service. Assistant Secretary without objection your written statement will be made part of the record. The Honorable Marshall Billingslea you are now recognized for five minutes.

Monday, October 8, 2018

CFIUS Updated with Foreign Investment Risk Review Modernization Act (FIRRMA)

The President signed the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA) into law on August 13, 2018 as part of the National Defense Authorization Act (NDAA) for Fiscal Year 2019 (H.R.5515). The law seeks to balance the gains of foreign investment against potential national security risks.

A Harvard Law School Forum reports, "FIRRMA represents the most sweeping changes to the law governing the Committee on Foreign Investment in the United States (CFIUS) since the passage of the Foreign Investment and National Security Act of 2007 (FINSA)." And from Stephanie Zable on Lawfare:
FIRRMA identifies several factors that Congress wants CFIUS to take into account when considering the national security risks posed by foreign investments.
  • Whether a transaction involves a country of special concern that has a strategic goal of acquiring technologies that would affect U.S. technological leadership in that area;
  • The national security effects of cumulative market share control by foreign persons;
  • Whether a foreign person involved in a transaction has a history of complying with U.S. law;
  • [Continues ...]

On August 23, 2018, President Trump held a roundtable with lawmakers on FIRRMA. They discussed the importance of protecting U.S. intellectual property and technology from other countries, specifically China. The fairly brief video on C-SPAN is here. CSIS also has a longer audio broadcast "Putting FIRRMA into Practice: What CFIUS Reform Means for Foreign Investment in the United States."

On a related note, Michael Brown, former CEO of Symantec and co-author of a Pentagon study on China’s Technology Transfer Strategy, had recommended CFIUS reforms in his testimony before Congress on July, 19, 2018.



Click to expand or roll up









Friday, October 5, 2018

New ICT Supply Chain Task Force

The Department of Homeland Security (DHS) held its first National Cybersecurity Summit on July 31, 2018. During the summit DHS's Christopher Krebs announced the creation of the Information Communications Technology Supply Chain Task Force and spoke with a panel of experts on what the task force should focus on for its first 90 days. The panelists included NSA's Rob Joyce, AT&T's John Donovan, and Palo Alto Network's Mark McLaughlin. The task force will be a part of the newly created DHS National Risk Management Center which launched with the task force in August. To add to that Congress is currently considering several pieces of legislation to protect the supply chain. One bill "Securing the Homeland Security Supply Chain Act of 2018" (HR 6430) was passed in the House on September 4, 2018 and has been sent to the Senate for debate.




Video: "Department of Homeland Security National Cybersecurity Summit" (Panel starts at 2:04) Source: YouTube

Wednesday, October 3, 2018

Reducing Gang Activity with a $50m a Year Law

On June 18, 2018, President Trump signed the "Project Safe Neighborhoods Grant Program Authorization Act of 2018" into law (Act: H.R.3249, Public Law No: 115-185). It allocates $50m a year from 2019 to 2021 to the prevention and reduction of gang violence and crime. The law sponsored by Rep. Barbara Comstock (R-VA) was approved with 394 votes to 13 in the House, and by a unanimous voice vote in the Senate. From a WJLA article:
"We have a large number of unaccompanied minors in the area and they are very vulnerable to these gangs recruiting them," he said. MS-13 habitually targets young immigrants, often forcing them into the gang through threats and intimidation. 
"If I had my way, I'd spend the bulk of the money on intervention, prevention efforts," Lanham added, "because it's much cheaper to go that route and prevent them from joining the gangs than arrest your way out, which we're not going to do." [...] 
"The amount of money should really assist in the coordination of local and federal law enforcement to target the worst of the worst using the best science we have," he said.
I penciled out brief outline summaries of both the Act and the article below.

Monday, October 1, 2018

CLOUD Act

The CLOUD Act (H.R. 4943) was passed into law on March 23, 2018 as section 105 of the Consolidated Appropriations Act, 2018 (H.R. 1625, passed as PL 115-141), an omnibus spending bill. The CLOUD Act is an acronym for Clarifying Lawful Overseas Use of Data Act.

The CLOUD Act amends the Stored Communications Act (SCA) of 1986 and allows federal law enforcement to compel US companies to provide data requested by a warrant or subpoena whether the data is stored in the US or on foreign soil.

The law was introduced after Microsoft refused to comply with a FBI SCA warrant for email data stored on one of its servers in Ireland for a drug trafficking investigation. The refusal led to the Supreme Court case Microsoft Corp. v. United States. The challenge identified that if a mutual legal assistance treaty (MLAT) is not in place, cross-border data discovery can be slowed and impede law enforcement efforts. The Supreme Court case was vacated when the DoJ was able to secure a new warrant under the CLOUD Act, rendering the original case moot.

The CLOUD Act asserts that U.S. companies must provide data on U.S. citizens on any of their servers when requested by a warrant. It also provides an expedited route to MLATs through "executive agreements."



Sunday, September 30, 2018

Notable Federal Laws Passed in 2018

(Updated 12-14-2018)

Search for federal legislation and more at Congress.gov/search.


H.R.4254 - Women in Aerospace Education Act
12/11/2018 Became Public Law No: 115-303.

H.R.390 - Iraq and Syria Genocide Relief and Accountability Act of 2018
12/11/2018 Became Public Law No: 115-300.

S.2152 - Amy, Vicky, and Andy Child Pornography Victim Assistance Act of 2018
12/07/2018 Became Public Law No: 115-299.

S.140 - A bill to authorize appropriations for the Coast Guard, and for other purposes.
12/04/2018 Became Public Law No: 115-282.

H.R.3359 - Cybersecurity and Infrastructure Security Agency Act of 2018
11/16/2018 Became Public Law No: 115-278.

S.1595 - Hizballah International Financing Prevention Amendments Act of 2018
10/25/2018 Became Public Law No: 115-272.

H.R.4921 - STB Information Security Improvement Act
10/16/2018 Became Public Law No: 115-269.

S.2946 - Anti-Terrorism Clarification Act of 2018
10/03/2018 Became Public Law No: 115-253.

S.994 - Protecting Religiously Affiliated Institutions Act of 2018
09/28/2018 Became Public Law No: 115-249.

S.97 - Nuclear Energy Innovation Capabilities Act of 2017
09/28/2018 Became Public Law No: 115-248.

H.R.1109 - To amend section 203 of the Federal Power Act.
09/28/2018 Became Public Law No: 115-247.

H.R.589 - Department of Energy Research and Innovation Act
09/28/2018 Became Public Law No: 115-246.

H.R.2147 - Veterans Treatment Court Improvement Act of 2018
09/17/2018 Became Public Law No: 115-240.

S.717 - POWER Act
09/04/2018 Became Public Law No: 115-237.

S.770 - NIST Small Business Cybersecurity Act
08/14/2018 Became Public Law No: 115-236.
NIST Small Business Cybersecurity Act
(Sec. 2) This bill amends the National Institute of Standards and Technology Act to require the National Institute of Standards and Technology (NIST) to consider small businesses when it facilitates and supports the development of voluntary, consensus-based, industry-led guidelines and procedures to cost-effectively reduce cyber risks to critical infrastructure.
NIST must disseminate, and publish on its website, standard and method resources that small business may use voluntarily to help identify, assess, manage, and reduce their cybersecurity risks. The resources must be: (1) technology-neutral, (2) based on international standards to the extent possible, (3) able to vary with the nature and size of the implementing small business and the sensitivity of the data collected or stored on the information systems, and (4) consistent with the national cybersecurity awareness and education program under the Cybersecurity Enhancement Act of 2014. Additionally, the resources must include case studies of practical application.
Other federal agencies may also elect to publish the resources on their own websites. 

H.R.2345 - National Suicide Hotline Improvement Act of 2018
08/14/2018 Became Public Law No: 115-233.

H.R.5515 - John S. McCain National Defense Authorization Act for Fiscal Year 2019
08/13/2018 Became Public Law No: 115-232.


S.2245 - KIWI Act
08/01/2018 Became Public Law No: 115-226.

H.R.2353 - Strengthening Career and Technical Education for the 21st Century Act
07/31/2018 Became Public Law No: 115-224.