As I mentioned Tuesday, the House will be considering HR 3684, the INVEST in America Act, next week. The bill was amended in Committee earlier this month and according to the House Rules Committee site, it has been further modified for that consideration. The version reported on the Rules Committee site includes two HAZMAT provisions and one section that specifically addresses cybersecurity issues, as well as seven mentions of cybersecurity in passing in other provisions.
Yesterday the Rules Committee announced that it was adding two new divisions to the language of HR 3684. These new divisions come from HR 1915, HR 3291, and HR 3293. Those divisions add one additional cybersecurity mention in passing.
HAZMAT Provisions
Section 8202 would provide for a stay of authorization to transport liquified natural gas by rail until certain conditions are met. The four conditions that would have to be met before the authorization that was put in place last year could be reinstated are:
The Secretary of Transportation conducts the evaluation, testing, and analysis outlined in the section,
The Secretary issues the report required as a result of that evaluation,
The GAO completes an independent evaluation and report of the evaluation conducted by DOT and
The Secretary issues a final rule updating the regulation described in this paragraph that incorporates the additional data, research, and analysis required above.
The section requires that DOT expend between $4 and $6 million in the conduct of the Department’s evaluation described.
Section 8203 would amend 49 USC 5107 by adding a new subsection (j) creating a new grant program “to develop hazardous materials response training for emergency responders and make such training available electronically or in person”.
AMTRAK Cybersecurity
The only section in the bill that specifically addresses cybersecurity issues is §9217, Amtrak cybersecurity enhancement and resiliency grant program. That section adds a new 49 USC 24325 of the same name. It would require DOT to “make grants to Amtrak for improvements in information technology systems, including cyber resiliency improvements for Amtrak information technology assets” {new §24325(a)}.
The bill would require that any program funded by the grants to “be consistent with cybersecurity industry best practices and publications issued by the National Institute of Standards and Technology” {new §24325(b)}.
Cybersecurity in Passing
Section 1211 adds a new 23 USC 155, electric vehicle charging stations. As part of the standards and guidance required for such charging stations, the bill would require that “network connectivity of electric vehicle charging, including measures to protect personal privacy and ensure cybersecurity” {new §155(e)(4)} be addressed.
Section 1303 amends 23 USC 151, adding a new subsection (f), Clean corridors program. In paragraph (6), project requirements the bill would add a requirement that “network connectivity of electric vehicle charging that includes measures to protect personal privacy and ensure cybersecurity” {new §151(f)(6)(E)}.
A new 49 USC 5316, Mobility innovation, is added by §2203. In subsection (f) of that new section there is a requirement to “to develop an open data standard and an application programming interface necessary to carry out this section” {new §5316(f)(1)}. Regulations for that standard would be specifically required to “enhance cybersecurity protections” {new §5316(f)(2)(H)}.
Section 5104 amends 49 USC 5505(b) by adding a new paragraph (7) adding focused research considerations for the University Transportation Centers Program which includes a requirement that DOT would “consider how the program under this section advances research on the cybersecurity implications of technologies relating to connected vehicles, connected infrastructure, and automated vehicles” {new §5505(b)(7).
An amendment to 23 USC 503(c)(4)(E) would be made by §5301. A new authorized use of grant funds under the Advanced Transportation Technologies Deployment would be made by adding “measures to safeguard surface transportation system technologies under this subparagraph from cybersecurity threats” {new §503(c)(4)(E)(x)}.
Section 5304, Study on safe interactions between automated vehicles and road users, lists as one of the considerations to be addressed in that study “a cybersecurity threat to the operation of the vehicle” {§5304(b)(3)(F)(iii)}.
A new third-party data integration pilot program would be established by §5307. It includes a requirement for DOT to “ensure the protection of privacy for all sources of data utilized in the program, promoting cybersecurity to prevent hacking, spoofing, and disruption of connected and automated transportation systems” {§5307(d)}.
Section 12015 amends 33 USC 1383(c)(10) to read: “(10) for measures to increase the security of
publicly owned treatment works, including measures to identify and address cybersecurity vulnerabilities of such treatment works [added language highlighted];
Moving Forward
The Rules Committee is currently accepting proposed amendments to HR 3684 and its additions. As of this writing there have been 223 amendments proposed. The Committee will meet early next week to formulate the rule for the consideration of HR 3684, including which amendments will be considered on the floor. That consideration will probably take place in the latter half of next week