HR 4611 Introduced - Software Supply Chain Risk Management Act
Last week, Rep Torres (D,NY) introduced HR 4611, the DHS Software Supply Chain Risk Management Act of 2021. The bill would require DHS to develop contract guidance to require that proposed contract bids would include a planned bill of materials for covered information and communications technology or service and a certification that such materials are free of known security vulnerabilities. The guidance would go into effect 180 days after the enactment of this bill.
NOTE: This review is based upon a Committee Print of the bill provided by the House Homeland Security Committee. The official GPO version has not yet been printed.
Definitions
Section 2(h) of the bill provides definitions for six key terms used in the bill. Terms of specific interest here include:
Bill of Materials,
Covered information and communications technology or services, and
Software
The term ‘bill of materials’ means “a list of the parts and components of an end product or service, including, with respect to each part and component, information relating to the origin, composition, integrity, and any other in20 formation as determined appropriate by the [DHS] Under Secretary [for Management]” {§2(h)(1)}.
The term ‘covered information and communications technology or services’ refers to the four following terms defined by reference {§2(h)(3)}:
Information technology {40 USC 11101(6)},
Information system {44 USC 3502(8)},
Telecommunications equipment {47 USC 153(52)},
Telecommunications service {47 USC 153 (53)}.
Guidance – New Contracts
Section 2(b) would require DHS to develop guidance for new contracts for covered information and communications technology or services for the inclusion of a planned bill of materials and a certification that each item listed in the BOM is free from all known security vulnerabilities or defects. The use of the term ‘known’ reflects the listing of vulnerabilities or defects in {§2(e)(1)}:
The NIST Vulnerability Database (VDB), and
Any other database designated by CISA that tracks security vulnerabilities and defects in open source or third-party developed software.
Section 2(b) also requires notification when security vulnerabilities or defects are identified. That notification would include a “notification relating to the plan to mitigate, repair, or resolve each security vulnerability or defect” {§2(e)(3)} so identified.
Guidance – Existing Contracts
Section 2(c) establishes a requirement that for existing contracts for covered information and communications technology or services, each contractor would be required to submit bill of materials and the certification described above.
Additionally, per §2(d), when changes are made to the information in a BOM, the contractor will report such changes in a timely manner.
Moving Forward
As I mentioned yesterday, this bill will be marked-up by the House Homeland Security Committee tomorrow. I expect that the bill will pass with significant bipartisan support. That would allow the bill to be considered by the full House under the suspension of the rules process.
Commentary
This is not technically software bill of materials (SBOM) legislation since the definition of ‘bill of materials’ does not refer to software. In fact, that definition is quite expansive and vague. This would cover a contractor providing an automobile, for instance, but there is no definition of what level of detail that bill-of-materials would entail. It could simply be a listing of the year, make and model; or it could a multipage document listing major components; or it could be a complete book, listing every nut and bolt used in the construction of the vehicle. As this is written, it would allow the DHS Under Secretary for Management to decide what level of detail is needed.
On the other hand, I suspect that this was supposed to be a SBOM bill. I base that upon the listing of the NIST NVD as the primary database for determining ‘known vulnerabilities’. I like the more expansive definition, but would have preferred it to specifically include SBOM with a reference to the NIST SBOM minimum elements document. I would change the definition to:
(1) BILL OF MATERIALS.— (a) The term ‘‘bill of materials’’ means a list of the parts and components of an end product or service, including, with respect to each part and component, information relating to the origin, composition, integrity, and any other information as determined appropriate by the Under Secretary.
(b) The term specifically includes software bill of materials as described in the National Institute of Standards and Technology document “The Minimum Elements For a Software Bill of Materials (SBOM), issued July 12th, 2021 or successor document.
As is usual, I would have preferred that the bill would have used the ICS expansive definition of ‘information system’ in 6 USC 1501 instead of the IT restrictive definition of 44 USC 3502 used in this bill. See my post here for a more detailed discussion of the problems with legislative cybersecurity definitions.