Homeland Security Network Defense and Accountability Act of 2008

Date: July 29, 2008
Location: Washington, DC


HOMELAND SECURITY NETWORK DEFENSE AND ACCOUNTABILITY ACT OF 2008 -- (House of Representatives - July 29, 2008)

BREAK IN TRANSCRIPT

Mr. THOMPSON of Mississippi. Mr. Speaker, I rise in support of this measure and yield myself as much time as I may consume.

Keeping our Federal and critical infrastructure network secure is an issue of national security. The United States and its allies face a significant and growing threat to our information technology systems. The acquisition of our government's information by outsiders undermines our strength as a Nation. Over time the theft of critical information from government computers could cost the United States our advantage over our adversaries.

This legislation is the result of extensive oversight work undertaken by the chairman of the Subcommittee on Emerging Threats, Science and Technology, Mr. Langevin.

An organization is only as strong as the integrity and reliability of the information that it keeps. H.R. 5983, a piece of the DHS authorization package, seeks to improve cybersecurity at DHS by ensuring that DHS's defenses of information systems are robust and by holding individuals at all levels accountable for mitigating vulnerabilities.

H.R. 5983, which was approved by voice vote in the committee, Mr. Speaker, is composed of five important provisions:

First, it establishes authorities and qualifications for the Chief Information Officer position at the Department. Through our oversight work, Mr. Speaker, we have observed how lack of an information security background can hamper the CIO's understanding and ultimately efforts to secure DHS' networks.

Second, the bill establishes specific operational security practices for the CIO, including a continuous real-time cyber incident response capability, network security architecture, and vulnerability assessments. These are fundamental elements for a comprehensive information security program.

Third, H.R. 5983 establishes testing protocols to reduce the number of vulnerability exploitations throughout the Department's networks. Time and again we have heard the current Federal information security requirements do not go far enough to actually ``operationalize'' security to reduce the number of successful attacks. Under H.R. 5983 security will be ``operationalized'' at DHS, a Federal agency that has a critical homeland security mission and is the receptacle of highly sensitive information.

Fourth, Mr. Speaker, the bill requires the Secretary of Homeland Security to determine if the internal security policy of a contractor who provides network services to DHS is consistent with the agency's requirements. This is a standard operating procedure for all private sector companies. It should be also for DHS as well.

Finally, Mr. Speaker, this bill seeks a formal report from the Secretary of Homeland Security on meeting the deadlines established by the Office of Management and Budget for Trusted Internet Connections, encryption and authentication mandates. These are critical for the Department's efforts to improve information security. It is unclear whether proper deadlines are being met.

I encourage my colleagues to support the Homeland Security Network Defense and Accountability Act of 2008.

House of Representatives, Committee on Oversight and Government Reform,

Washington, DC, July 24, 2008.
Hon. Bennie G. Thompson,
Chairman, Committee on Homeland Security, Ford House Office Building, Washington, DC.

Dear Chairman Thompson: I am writing about H.R. 5983, the Homeland Security Network Defense and Accountability Act of 2008, which the Homeland Security Committee ordered reported to the House on June 26, 2008.

I appreciate your effort to consult with the Committee on Oversight and Government Reform regarding H.R. 5983. In particular, I appreciate your willingness to strike the provision of the bill addressing the Freedom of Information Act and for agreeing to add rule of construction with regard to application of the Federal Information Management Security Act (FISMA) to the Department of Homeland Security.

In the interest of expediting consideration of H.R. 5983, and in recognition of your efforts to address my concerns, the Oversight Committee will not request a sequential referral of this bill. I would, however, request your support for the appointment of conferees on the Oversight Committee should H.R. 5983 or a similar Senate bill be considered in conference with the Senate.

Moreover, I believe it is important to identify additional provisions in H.R. 5983 that are of particular concern to me.

Specifically, H.R. 5983 creates new responsibilities that might cause confusion with existing requirements under FISMA. Although these requirements do not necessarily contradict FISMA, I am concerned that when the Department seeks to implement these new requirements there may be uncertainty as to which law takes precedence. The unique set of requirements created in H.R. 5983 does not appear to align with current governmentwide requirements.

In addition, I am concerned that H.R. 5983 puts too much responsibility with the Department's Inspector General. In my view, primary responsibility for performance reviews and testing should reside with the Department.

Again, thank you for your efforts to address my concerns with H.R. 5983. Although I still have reservations about a few provisions, I look forward to working with you to resolve these matters and develop policies that benefit the federal government as a whole.

This letter should not be construed as a waiver of the Oversight Committee's legislative jurisdiction over subjects addressed in H.R. 5983 that fall within the jurisdiction of the Oversight Committee.

Please include our exchange of letters on this matter in the Homeland Security Committee Report on H.R. 5983 and in the Congressional Record during consideration of this legislation on the House floor.

Sincerely,

Henry A. Waxman,
Chairman.

--

HOUSE OF REPRESENTATIVES,

COMMITTEE ON HOMELAND SECURITY,

Washington, DC, July 24, 2008.
Hon. Henry A. Waxman,
Chairman, Committee on Oversight and Government Reform, House of Representatives, Rayburn House Office Building, Washington, DC.

Dear Mr. Chairman: Thank you for your letter regarding H.R. 5983, the ``Homeland Security Network Defense and Accountability Act of 2008'', introduced on May 7, 2008, by Congressman James R. Langevin.

I appreciate your willingness to work cooperatively on this legislation. I acknowledge that H.R. 5983 contains provisions that fall under the jurisdictional interests of the Committee on Oversight and Government Reform. I appreciate your agreement to not seek a sequential referral of this legislation and I acknowledge that your decision to forgo a sequential referral does not waive, alter, or otherwise affect the jurisdiction of the Committee on Oversight and Government Reform.

Further, I recognize that your Committee reserves the right to seek appointment of conferees on the bill for the portions of the bill that are within your jurisdiction, and I agree to support such a request.

I will ensure that this exchange of letters in included in the Committee's report on H.R. 5983 and in the Congressional Record during floor consideration of H.R. 5983. I look forward to working with you on this legislation and other matters of great importance to this nation.

Sincerely,

Bennie G. Thompson,
Chairman.

--

INFORMATION TECHNOLOGY

ASSOCIATION OF AMERICA,
Arlington, VA, June 25, 2008.
Hon. James R. Langevin,
Chairman, the Homeland Security Subcommittee on Emerging Threats, Cybersecurity, Science, and Technology, House of Representatives, Washington, DC.

On behalf of the more than 350 members of the Information Technology Association of America (ITAA), I am writing to express our support for the overall objective of H.R. 5983. As you know, IT AA has long been an outspoken supporter of many Congressional initiatives to improve federal information security practices and we commend the committee's efforts to specifically address information security at the Department of Homeland Security.

We would like to take this opportunity to note that Sec 836(c) has significant requirements to develop and implement plans for the awarding of subcontracts to small businesses and disadvantaged businesses. This is duplicative of existing law and we feel it is unnecessary to require it in the context of this Bill.

Should you have any questions on these comments or our perspective, please feel free to contact Audrey Plonk or Jennifer Kerber. Thank you for your attention to our concerns.

Sincerely,

Philip J. Bond,
President and CEO.

--

New York State Office of Cyber Security & Critical Infrastructure, Coordination,

Albany, NY, May 30, 2008.
Re House Bill: H.R. 5983.

Hon. Bennie Thompson,
Chairman, Emerging Threats, Cybersecurity, S&T Subcommittee Committee on Homeland Security, House of Representatives, Washington, DC.

Dear Chairman Thompson: The New York State Office of Cyber Security and Critical Infrastructure Coordination (CSCIC) supports H.R. 5983, which amends the Homeland Security Act of 2002 to enhance the information security of the Department of Homeland Security.

It is our view that amending the Act to institutionalize the responsibility for ensuring that the Department's information infrastructure is protected from cyber and other threats to the maximum extent practicable is a crucial step in improving the nation's security. All too often the responsibility for securing our cyber infrastructure gets lost in the myriad of operational activities at the expense of security. It is essential that these vital cyber responsibilities are institutionalized if we are to be as cyber prepared as possible.

Thank you for providing CSCIC with an opportunity to comment on this Bill. Please do not hesitate to contact me if you wish to discuss the Bill further as it advances through the legislative process.

Sincerely,
William F. Pelgrin.

Mr. Speaker, I reserve the balance of my time.

BREAK IN TRANSCRIPT


Source
arrow_upward