Madam Chair, I yield myself such time as I may consume. I rise in support of this bill. I want to thank Ranking Member Hall and I want to thank my good friends across the other side of the aisle,…
Madam Chair, I yield myself such time as I may consume.
I rise in support of this bill. I want to thank Ranking Member Hall and I want to thank my good friends across the other side of the aisle, Chairman Gordon and Mr. Lipinski, for, as usual, working in a bipartisan way to get good things done for the country. I think the American people deserve that, and they want to see more of that, of us up here in Washington.
I was proud to be the lead Republican sponsor on this bill as well because this issue is so important. A lot of times when you talk about cybersecurity, people's eyes kind of glaze over, and yet when we talk about cybersecurity, we are really talking about national security. We held hearings both in the Science and Technology Committee and on the Homeland Security Committee where we examined the vulnerabilities and the threats presented by cyberattacks, and it is very frightening.
When you talk to the top military advisers to the President, they will tell
you one of the greatest threats we face as a Nation is a cyberattack and that we are vulnerable. And when we had hearings on the issue, we heard that just about every Federal agency, in fact every one, including the Pentagon, had been hacked into and this institution had been hacked into. And there have been major data dumps where information was stolen from countries that we cannot speak of in the well of the floor right now, but foreign countries stealing information from the United States Government.
There are really several areas. There are criminal enterprises who use cyberattacks to steal intellectual property, and then there is the realm of espionage, where we have countries that go in and steal information from the United States Government, intellectual property, secrets within the government, data dumps the size of the Library of Congress. We had a classified program that was subsequently declassified that showed that through the click of a mouse power grids could be blown up.
Every critical infrastructure is tied to cybernetworks. Whether it be our utilities, our power grids, our financial institutions, whether it be air traffic controllers, virtually every sector is tied to the networks, to the Internet, and, therefore, is vulnerable. This bill I think is a good step forward in helping to protect our networks, certainly in the Federal Government.
Last year, I joined with Congressman Jim Langevin from Rhode Island, working with CSIS, who had worked on the Iraq Study Group as well, to put together a team, a commission of experts across the Nation of cyberexperts to make recommendations to the next President of the United States. We made those recommendations to President Obama. I am pleased that this bill actually fulfills one of the main recommendations in that report, and that is to provide improving Federal cyberworkforces within the Federal Government. And this bill does a lot more than that.
Improving research and development, this bill establishes cybersecurity R&D grant programs that focus on technical and human behavioral aspects of cybersecurity. It improves our Federal cyberworkforce. It creates a scholarship program at NSF that can be repaid by Federal service. And, it improves coordination in the government. It gives NIST the authority to set security standards for Federal computer systems and develop checklists for agencies to follow. I think this is a very, very important point, because in our hearings, when we asked the Department of Homeland Security or representatives from the Department of Defense or NSA who is in charge of defending our networks, who is in charge, they couldn't answer that question, because there isn't one person in charge.
One of our recommendations was to have someone at the White House level be put in charge to coordinate the various agencies. And because there is no one in charge, there is the lack of coordination. So the very entities that have the offensive capability for cyberattack are not coordinating with the agencies that are tasked with defending the Nation from a cyberattack. I think that giving NIST the authority to set these standards for the first time is going to go a long way in protecting our networks inside the Federal Government.
It also reaches out to the private sector, which I particularly like about this bill. It emphasizes the implementation of checklists by Federal agencies that they should remain flexible and technology neutral in working with the private sector. It improves coordination outside the government by creating a task force of the Federal Government universities who know this issue very well and the private sector to coordinate the research and development.
I think the idea of a public-private partnership rather than having bureaucrats in Washington make all these decisions is vitally important, to bring in the expertise of the private sector and the technology sector who know this issue very well. And, as Chairman Gordon mentioned, this has broad-based support from business groups outside in the private sector and from the technology sector in particular.
So with that, I think this is a great first step towards protecting our Federal networks. I again want to commend the great leadership on both sides of the aisle for making this happen today.
I reserve the balance of my time.
I yield as much time as he may consume to the gentleman from Georgia (Mr. Kingston).
Just in closing, I co-chair the Cybersecurity Caucus with Congressman Langevin, and I want to commend him for his great work not only on the CSIS Commission but also on the caucus to try to raise awareness of this issue. It is a very, very important issue. I also want to thank Chairman Gordon, who I know is going to retire. We're going to miss him. But just the bipartisan spirit in which he has conducted himself on this committee to allow us to work together with the majority to get good legislation out of the Congress. As I said earlier, I think that's what the American people want. It's what they deserve. Certainly, there's no greater issue where Republicans and Democrats should come together than on issues impacting national security, which this bill does. We are Americans first. Again, this bill is a great step forward into furthering and protecting our Federal networks.
I hope, as with what happened with 9/11, we don't turn a blind eye and wait until there's a major denial of service attack before we start to pay attention to this issue. I think this bill, which I anticipate will pass the House overwhelmingly, is a great statement by the Congress that cybersecurity is important and that we can work together on this. I think, as Congressman Wu talked about the attacks on Google recently, last Fourth of July we had a denial of service attack emanating that hit Korea and the United States. The disturbing thing about that attack was it was not to phish or to steal information, or perhaps espionage. Rather, it was intended to do harm. That denial of service attack was intended to shut down our networks. It was relatively unsophisticated.
But as we examine the denial of service attacks that we saw in Estonia, the denial of service attack in Korea and the United States just last Fourth of July, to me, that is an eye opener. It's just like before 9/11 we saw signs that the Congress needed to pay attention to. I think we have seen signs of that in the cyber-realm, and I hope we can work together across the aisle to further enhance and strengthen our cybernetworks, and in the private sector as well, so that we can avoid a cyber-9/11 attack in the United States.
So this is, again, a very important issue that, when you talk to leaders in the military, they get it. They recognize it. They want to work with the Congress to better improve our cybersecurity. Again, let me just give my thanks to Chairman Gordon for allowing this to come out of the committee and come to the House floor. I urge my colleagues on both sides of the aisle to support this legislation.
I yield back the balance of my time.
Madam Chair, I rise to claim time in opposition, although I do not intend to oppose this amendment.
Mr. Hastings and my colleague from Texas (Mr. Rodriguez) are making improvements to this bill to ensure that the strategic plan takes into consideration the talents of women and minority populations in the cybersecurity workforce and that the University-Industry Task Force includes representatives from minority-serving institutions. I therefore urge support for this amendment.
I reserve the balance of my time.
As part of the Scholarship for Service program at NSF, scholarship awardees are to receive internships at Federal agencies. This amendment simply gives the director the discretion of allowing them to intern in the private sector. So, therefore, I support this amendment.
I yield back the balance of my time.
Madam Chair, I rise in support of this amendment, and I also support the gentleman's position on earmarks. This amendment would prohibit the earmarking of the NSF and NIST cybersecurity activities authorized in this bill. It is well understood that awarding grants through merit-based competitive processes is the best way to fund science and technology, and cybersecurity is certainly no exception. This insulation from political influences is, in fact, an important reason why NSF and NIST have such a strong reputation overall both within and outside of the Federal Government.
Mr. Flake's amendment will help ensure that this model is being protected by incorporating it specifically into the statute. I urge my colleagues to support this amendment.
Madam Chair, I rise to claim time in opposition, although I am not opposed to this amendment.
Madam Chair, NSF computer and network security research grants are intended to enhance computer security through basic hardware and software research in numerous areas, including the ability for law enforcement to detect, investigate, and prosecute cybercrimes.
This amendment merely highlights crimes against children and organized crime, such as cybercrimes, where these investments should be made. So I fully support this good amendment.
I yield back the balance of my time.
Madam Chairman, I'm pleased to strongly support this amendment. Our Nation's community colleges have played a crucial role in our technology and educational workforce. This amendment makes sure they are able to make recommendations and give advice to the Federal Government on the strategic plan. It emphasizes their eligibility as a potential institutional partner under the Scholarship for Service Program and really puts them at the table of the University-Industry Task Force.
So, with that, I strongly urge support.
Mr. Chairman, I rise to claim time in opposition to this amendment, although I am not opposed to it.
This amendment directs NIST to work with Federal, State, and private-sector partners to develop a framework that States may use to improve their cybersecurity posture. Developing such a framework for use in assisting States is certainly consistent with NIST's expertise and capabilities, and there is clearly a need for this expertise at the State level.
I should note, in working with the States, that we should, of course, expect that the NIST role remains limited to the development of guidance that the States may use, if they choose, avoiding any activities that are mandatory or binding in nature.
I'd like to yield to the gentlelady from Maryland (Ms. Edwards) to say if that's a correct statement. That is my understanding of this amendment.
Reclaiming my time then, I'm comfortable with the language in this amendment as written and very much support its passage.
I yield back the balance of my time.
Mr. Chairman, I rise in strong support of this amendment. The gentleman is absolutely correct. The Internet knows no boundaries. This is not just an issue for the United States; it's a global issue that we need to address. This amendment simply states that the interagency cybersecurity R&D plan required by the legislation outlines how the United States can work strategically with international partners on cybersecurity R&D.
Cybersecurity issues are certainly global in nature. Many of our closest allies face the same threats and vulnerabilities that we do. Thus, it makes sense that we should work to cooperate more closely with our international partners, and that is what this amendment will do. Therefore, I strongly urge support.
Mr. Chairman, I rise to claim time in opposition to this amendment, although I'm not opposed to it.
This amendment simply provides an establishing or enhancing cybersecurity collaboration between community colleges, universities, and NIST Manufacturing Extension Partnership centers, and is among the most eligible activities that may be supported by NSF cybersecurity research grants.
This collaboration between researchers and those that provide technical support regarding cybersecurity best practices is benefiting and should be encouraged. And therefore, I support
the gentlelady from Pennsylvania's amendment.
I yield back the balance of my time.
I rise to claim time in opposition to this amendment although I am not opposed to it.
This amendment specifies that as part of its outreach and education efforts NIST may host regional workshops on cybersecurity risks and best practices for businesses, State, and local governments and educational institutions.
I think that's a good thing, and while I do not oppose this amendment, I'd like to note that NIST has a very modest budget for cybersecurity activities, of which outreach and education is just a small fraction.
Accordingly, in carrying out the section of this bill is my expectation that this should work to leverage this funding to benefit the largest number of entities and individuals as it can. I recognize workshops can also serve as a useful outreach tool and should be an option.
So with that point in mind, I do not object to this amendment.
I yield back the balance of my time.
I rise to claim time in opposition to this amendment, but do not intend to oppose it.
Mr. Chairman, this amendment simply States that the NIST Cybersecurity Awareness and Education Program established in the bill helps makes the technical standards and best practices more usable for everyone, especially those new to computers: The elderly, those with low incomes, and those that may not have broadband quite yet, such as rural areas. Therefore, I do not oppose this amendment.
I would like to join Chairman Gordon at this point in time to offer my sincere condolences as well to the family of Judy Ruckel.
Judy served as a printer for the Science and Technology Committee since 2001 under both Republican and Democratic leadership. Day in and day out, Judy carried out her job with style and grace and never did she allow her struggle with diabetes to diminish her presence nor her performance.
Judy worked from home, but during her visits to our offices each week, she took time to look in on staff, inquiring about our families and challenges, always leaving a smile on the faces of those she came in contact with.
The job of managing countless hearing transcripts and markups and transforming them into permanent records is absolutely critical to the life of our committee, and Judy did it to perfection. She is irreplaceable. Judy's suffering has ended, and we will miss her very deeply, and God be with her.
I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition, although I'm not opposed to this amendment.
This amendment would include some additional factors to be considered in the assessment of the cybersecurity workforce and barriers to entry into that workforce. Job security clearance and suitability requirements are important factors to consider in this assessment. I thank the gentlelady for a constructive amendment.
I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition to the amendment, although I am not opposed to it.
Let me tell you it is a point of personal privilege to commend the gentleman from Rhode Island for all of his great work in this particular area and how much I have enjoyed working with the gentleman, co-chairing the CSIS commission and also co-chairing the Congressional Cybersecurity Caucus. So thank you.
This amendment would modify the section of the bill requiring the President to transmit a cybersecurity workforce report to Congress, specifically by requiring that the President's review consider the potential for temporary assignment of private sector cybersecurity professionals as a means through which to meet Federal workforce needs.
These types of mechanisms, such intergovernmental personnel agreements, have long been used by Federal agencies in various capacities; and they provide a flexible means through which to address workforce needs expeditiously.
Accordingly, it makes sense for the President's workforce assessment to consider and report on these mechanisms. So therefore, I support the gentleman's amendment.
I yield back the balance of my time.
Let me say first I commend the gentlelady from California for the emphasis on the private sector.
I think too often when we deal with this issue, we focus mainly on the government and not enough on the private sector where the majority of the critical infrastructures are in this country. So let me commend the gentlelady for bringing this forward.
This amendment makes two changes to the bill which I believe are good changes. First, it requires that the cybersecurity R&D strategic plan describe how interagency efforts will facilitate access to realistic threat and vulnerability data by academic researchers. Secondly, it tasks the university-industry R&D task force created by the bill to consider how best the public and private sectors can share ``lessons learned on the effectiveness of new technologies.''
Both of these provisions make changes to the underlying bill that I believe improve the bill, and therefore I fully support its passage.
With that, I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition to this amendment. However, the good news is, Mr. Cuellar, I do not intend to oppose it.
Let me first commend the gentleman from Texas, my dear friend and colleague, Mr. Cuellar, on the outstanding work he has done in this area and on the Homeland Security Committee, and also his work with the Center for Excellence, in San Antonio, for cybersecurity. It is great for our great State of Texas.
This amendment requires a strategic plan to describe how the program will strengthen cybersecurity education and training efforts in order to ensure an adequate, well-trained workforce. The bill already has in place a robust workforce assessment requirement, but the robustness of our future cybersecurity workforce I believe is important enough to reemphasize it.
With that, I do not oppose this amendment. In fact, I strongly support it.
I yield back the balance of my time.
The gentlelady from New Hampshire's amendment is one that our side favored during the drafting of this legislation and one that we think makes the Scholarship for Service program at NSF even stronger. So I thank the gentlelady for bringing this amendment.
The intent of the program is to educate the Federal Government's future cybersecurity workforce. This amendment increases the amount of employment service a graduate will owe the Federal Government upon the completion of her or his education, ensuring a greater return on our initial investment.
Therefore, I support this amendment, and I encourage my colleagues to do so.
I yield back the balance of my time.
Let me first commend Ms. Clarke for this amendment, but also her great work on the Homeland Security Committee as the chairwoman of the Cybersecurity Subcommittee.
This amendment simply requires the present Cybersecurity Workforce Assessment Report include an analysis of the capacity of the overall agency workforce to manage contractors providing cybersecurity support to Federal agencies. Contractors are a significant component of our cybersecurity efforts, and assessing their role and agencies' capacity to manage them is very, very appropriate. Therefore, I support this amendment.
With the time I do have remaining, Mr. Chairman, I would like to yield to the gentlelady from Texas, Ms. Sheila Jackson Lee.
Mr. Chairman, I yield back the balance of my time.
Mr. Chairman, I claim time in opposition to this amendment, although I am not opposed to it.
This amendment would require a National Academy of Sciences study on the role of community colleges in cybersecurity education, with an aim toward identifying best practices related to improving cybersecurity education through better linkages between community colleges and 4-year colleges and universities. It is important not to overlook the contributions of community colleges, as the gentleman stated, to our overall technical workforce, including those involved in computer and network security. This amendment is intended to help address that issue, and I strongly urge my colleagues to support it.
With that, I yield back the balance of my time.
First let me say what a great amendment this is. As a Federal prosecutor, I encountered crimes against children and also as deputy attorney general for the State of Texas. While there, we formed an Internet crimes against children's task force. The threat to children, both from child pornography and online predators, as the gentleman knows, is very real. And while the Internet is a great tool for our youth, it also does present a vulnerability and a threat to them. That is why I am so glad to see this amendment.
It simply clarifies when we are promoting and educating people on the importance of cybersecurity, we must include children and young adults along with the other targeted audiences. So let me again thank the gentleman for bringing this. I strongly support it, and encourage my colleagues to do so.
I yield back the balance of my time.
Let me thank the gentlelady for bringing this amendment. My home State of Texas is the home to probably more active duty service and veterans than probably any other State in the country. I think this is a great idea, including Lackland Air Force Base, which provides a cybersecurity command.
It is very straightforward. It adds veteran status as an additional item for consideration by NSF when it selects individuals for scholarships under its Cybersecurity Scholarships for Service program. Therefore, I strongly support the gentlelady's amendment, and I urge its passage.
With that, I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition to this amendment, although I do not intend to oppose it.
I thank the gentlelady for this amendment. Certainly, our youth know the Internet and how to operate on it more effectively than anyone in this Chamber. This amendment adds an outreach to high schools and community colleges component to the characteristics of the Scholarship for Service program in an effort to attract more students to the program. I think it's a good idea. I support this amendment, and urge my colleagues to do so.
I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition to the amendment, but I do not intend to oppose it.
This amendment simply clarifies that NSF's support for cybersecurity-related curriculum development at universities includes ``curriculum on the principles and techniques of designing secure software.'' It's a good amendment that codifies and clarifies NSF's role in support of computer security curriculum development. I support this amendment. I urge my colleagues to do so.
I yield back the balance of my time.
Mr. Chairman, I rise to claim time in opposition to this amendment, although I am not opposed.
While the statute that we are amending today already authorizes the director of NSF to provide grants for computer and network security research centers, I believe that the establishment of a National Center of Excellence dedicated solely to cybersecurity can only increase our defensive capabilities, provided that any funding that does go to the National Center does not come at the expense of other Centers of Excellence, of course. With that, I urge my colleagues' support for this amendment.
I yield back the balance of my time.