Last month Sen Peters (D,MI) introduced S 1917, the K–12 Cybersecurity Act of 2021. The bill would require CISA to conduct a study on the specific cybersecurity risks facing K–12 educational institutions and develop an online cybersecurity training toolkit designed for officials at K–12 educational institutions. No funding is authorized by this bill.
Definitions
Section 3(a) of the bill provides definitions for four key terms used in the bill. All four are defined by reference to existing legislative definitions. Two cybersecurity terms are included:
Cybersecurity risk – 6 USC 659, and
Information Systems – 44 USC 3502.
Study
Within 120 days of the passage of this bill, CISA would be required to “conduct a study on the specific cybersecurity risks facing K–12 educational institutions”. The study would include:
Analyzing how identified cybersecurity risks specifically impact K–12 educational institutions,
Evaluating the challenges K–12 educational institutions face in securing information systems and personally identifiable information,
Evaluating the challenges K–12 educational institutions face in implementing cybersecurity protocols
Identifying cybersecurity challenges relating to remote learning, and
Evaluating the most accessible ways to communicate cybersecurity recommendations and tools.
A report to Congress would be required on the results of the study. Additionally, CISA would be required to develop recommendations that include voluntary cybersecurity guidelines designed to assist K–12 educational institutions in facing the cybersecurity risks identified.
Cybersecurity Training
Section 3(d) of the bill would require CISA, within 120 days of completing the recommendations described above, to “develop an online training toolkit designed for officials at K–12 educational institutions”. The toolkit would:
Educate the officials about the cybersecurity recommendations described above and
Provide strategies for the officials to implement those recommendations.
Moving Forward
Peters, and two of his three cosponsors {Sen Scott (R,FL) and Sen Rosen (D,NV)}, are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. Since Peters is the Chair of that Committee, he certainly has the influence to see this bill considered in Committee. I see nothing in this bill that would engender any specific opposition. I suspect that this bill would receive substantial bipartisan support in Committee.
As with most bills, this is not an important enough piece of legislation to make it to the floor of the Senate under regular order. On its own merits, I suspect that it could be considered under the Senate’s unanimous consent process as long as some Senator does not offer an objection for reasons unassociated with the bill, a fairly common occurrence.
The most likely way that this language would make its way to the President’s desk would be for the language to be included in some larger bill, an education authorization or spending bill, for instance.
Commentary
This bill is crafted on cybersecurity definitions and concepts that look at only the narrowest cyber risk to educational institutions, the information systems used to conduct and support the education processes. It ignores the cyber risks to the physical plant used for those processes; the environmental controls and security systems that allow for those information-based educational processes to proceed.
Attacks on those control systems, ignored by the definitions employed in this bill, could make the environment in which the educators work incapable of supporting the education processes, especially in an era when we are seeing an increasing number of record-breaking weather extremes. And, as these building control systems and the education information infrastructure are increasingly interconnected, vulnerabilities in the control systems could allow attacker to bypass security measures put into place to protect the information systems that form the increasingly important central place in K-12 educational systems.
This oversight could easily be rectified by changing the source of the definition for the term ‘information system’ from 44 USC 3502 to 6 USC 1501 as that definition explicitly includes the “industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers” that form the heart of building control systems.