Earlier this month the House Passed HR 4521, the America COMPETES Act of 2022. While billed as a ‘bioeconomy’ bill, this legislation is another huge (3610 pages) legislative conglomeration that addresses a large number of issues. It includes 10 distinct sections addressing cybersecurity issues, funding for a cybersecurity training program and 12 separate mentions in passing of cybersecurity provisions in loosely related requirements.
Spending for Cybersecurity Training
Section 10303 authorizes spending for a variety of programs through the National Science Foundation. This includes money for the Cybercorps Scholarship for Service Program:
FY 2022 - $70,000,000,
FY 2023 - $72,000,000,
FY 2024 - $78,000,000,
FY 2025 - $84,000,000, and
FY 2026 - $90,000,000
Cybersecurity Sections
The bill contains ten sections that deal specifically with cybersecurity issues. Many of these sections are essentially the same as standalone legislative proposals that have already been offered in the House and/or Senate. Most of those earlier bills have little chance of making it through the legislative process on their own. The ten cybersecurity sections are:
§10223. NIST authority for cybersecurity and privacy activities
§10224. Software security and authentication.
§20102. Understanding cybersecurity of mobile networks. [HR 2685]
§20106. NTIA policy and cybersecurity coordination [HR 4046]
§20107. American cybersecurity literacy [HR 4055]
§30127. Digital connectivity and cybersecurity partnership.
§40101. Federal Rotational Cyber Workforce Program [HR 3599 or S 1097]
§50107. Improving cybersecurity of small entities [HR 6541]
§50108. Critical Technology Security Centers.
§90601. Dr. David Satcher cybersecurity education grant program. [S 2305]
Section 10223 would amend 15 USC 272(c), adding to the list of activities that NIST is allowed to do to support its mission requirements outlined in subsection (b). These ‘new’ activities address supporting various information security measures. There is nothing listed in the five new paragraphs that would be added by this section that NIST is not already working on. No new funding is authorized for these newly allowed activities.
Section 10224 contains five subsections that address NIST requirements to:
Assess vulnerabilities in open-source software and assign severity metrics to identified vulnerabilities with open-source software,
Carry out research and testing to improve the effectiveness of artificial intelligence enabled cybersecurity,
Ensure all software released by the Institute is digitally signed,
Provide technical assistance to improve the education and training of individual Federal agency Inspectors General and staff who are responsible for the annual independent evaluation they are required to perform of the information security program and practices of Federal Agencies, and
Develop a set of security outcomes and practices to enable software developers and operators to identify, assess, and manage cyber risks over the full lifecycle of software products.
Section 30127 would authorize the President to establish a Digital Connectivity and Cybersecurity Partnership to aid foreign countries to develop their cyber infrastructure. It includes eight paragraphs of goals for that program including:
“(7) build cybersecurity capacity, expand interoperability, and promote best practices for a national approach to cybersecurity;”
Section 50108 would amend the Homeland Security Act of 2002 by adding a new §323, Critical technology security centers. It would require DHS to establish four cybersecurity-focused Critical Technology Security Centers to evaluate and test the security of devices and technologies that underpin national critical functions. The four centers would include:
The Center for Network Technology Security,
The Center for Connected Industrial Control System Security,
The Center for Open Source Software Security, and
The Center for Federal Critical Software Security
Cybersecurity Mentions in Passing
The following cybersecurity related mentions were made in other sections of the bill:
§10251 would amend the National Institute of Standards and Technology Act, adding a new §25B, Expansion awards pilot program. §25B(e)(2) would allow as a purpose of the new grant program “provide services to improve the resiliency of domestic supply chains and to mitigate vulnerabilities to cyberattacks, including helping to offset the cost of cybersecurity projects for small manufacturers”.
§10304(c) would amend Scientific and Advanced-Technology Act of 1992. It would include the revision of the definition of the term ‘advanced technology’ in §3(j)(1) to include: “… micro and nano-technologies, cybersecurity technologies, geospatial technologies….”.
§10304(d) would amend section 10 of the National Science Foundation Act of 1950 to add §10(c)(C) to require that NSF would “ensure that students pursuing master’s degrees and doctoral degrees in fields relating to cybersecurity are considered as applicants for scholarships and graduate fellowships under the Graduate Research Fellowship Program”.
§10304(g) would amend §302(b)(1) of the Cybersecurity Enhancement Act of 2014, adding “cybersecurity-related aspects of other related fields as appropriate” as being eligible for the Federal Cyber Scholarship-for-Service Program.
§10308 would establish in NSF the Directorate for Science and Engineering Solutions. §10308(g)(3) lists ‘cybersecurity’ as one of the focus areas for the new Directorate.
§10663 would establish a new Microelectronics Research Program in DOE. One of the listed research areas in §10663(b) for that Program would be “cybersecurity by design to result in trusted and resilient microelectronics”.
§10664 would establish Microelectronics Science Research Centers within DOE. §10664(b)(6) specifies that one of the activities of those Centers would be “supporting development of cybersecurity capabilities for computing architectures that measurably improve safety and security, and that are adaptable for existing and future applications”.
§20209 would establish definitions used in Subtitle A—Supply Chain Resilience of Title II of Division C of the bill. Cybersecurity related definitions include:
(16) Key Technology Focus Areas – including “(I)Data storage, data management, distributed ledger technologies, and cybersecurity, including biometrics.”
(35) Supply Chain Shock – including “(F) A cyber attack.”
§30002 provides the Foreign Relations Committee findings for Division D of this bill. Paragraph (27) lists the accomplishments of the Asia Reassurance Initiative Act of 2018, including enhancing “cybersecurity cooperation between the United States and partners in the Indo-Pacific”.
§50102(h)(3) would require GAO to include in their report on the new DHS Software Supply Chain Risk Management program established under this section to include “an assessment of how the guidance issued pursuant to subsection (a) complies with Executive Order No. 14208 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity)”.
§90103 completely rewrites the National Apprenticeship Act of 1937. In the new §201(a)(1)(A) provides authority for grants for apprenticeship programs that include “advanced manufacturing (including semiconductor and auto-motive manufacturing), cybersecurity and information technology,”. Similarly, §201(A)(1)(C) allows for establishing sector-based partnerships for key sectors, including “information technology, cyber security, health care,”.
Moving Forward
The bill passed in the House by a nearly (1 Democrat and 1 Republican voted the other way) straight party-line vote of 222 to 210. This would indicate that the bill would never pass the cloture process for consideration in the Senate. Nor is it a given that if it did make it to a vote in the Senate, that there would be enough votes for it to be sent to the President.
There is one potential route forward for this bill. If the House were to vote to amend S 1260, the Endless Frontiers Act (a similar conglomeration bill) with the language from this bill, then the Senate would insist on their language and the two versions of the bill would go to conference to work out the differences. A conference version would pass in the House on a party-line vote and may make it through the Senate (with judicious paring and reduced spending).