Showing posts with label CEII. Show all posts
Showing posts with label CEII. Show all posts

Tuesday, February 27, 2024

OMB Approves FERC’s CEII Data Request ICR Revision

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision request for the Federal Energy Regulatory Commission’s (FERC’s) information collection request (ICR) on “Critical Energy/Electric Infrastructure [CEII] Information Data Request”. The ICR burden was revised downward based upon the recent history of such requests.

The abstract for the announcement notes that:

“In accordance with section 215A(d) of the Federal Power Act and 18 CFR 388.113, this collection of information provides that persons may seek Critical Energy/Electric Infrastructure Information (CEII). To receive CEII, they must show they have a legitimate need for such information, and they must submit a non-disclosure agreement that decreases the likelihood that such information could be used to plan or execute terrorist attacks.”

FERC is one of those agencies that actually periodically updates their ICR requests to reflect recent historical data (which in my opinion all agencies should do for all ICRs). This ICR has been in place since 2002, and the table below is a quick look at the changes in their burden estimates over that time.

 

# of Responses

Burden (hrs)

2002

200

50

2005

182

46

2008

200

60

2020

100

30

2023

50

15

Wednesday, June 17, 2020

S 3688 – Energy Infrastructure Security – Miscellaneous Provisions


This is the fifth in a series of posts about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. The earlier posts in the series were:

S 3688 Introduced – Energy Infrastructure Security
            S 3688 – Energy Infrastructure Security – Security Assistance to Energy Infrastructure
S 3688 – Energy Infrastructure Security – CEII disclosure authorization
In this blog post I will look at the last three sections that bill would add to the Federal Power Act:

§235. Designating information held by other governmental authorities,
§236. Wartime clearance,
§237. Enforcement and sanctions

Government Requests for CEII Designation


Section 235 establishes the procedures that will be used by eligible government entities to request the designation of information as Critical Electrical Infrastructure Information (CEII). In this section the term ‘eligible entities’ is defined as {§235(a)(1)}:

• A Federal, State, political subdivision, or Tribal authority [excluding DOE and FERC], and
• A utility owned or operated by 1 or more of the authorities above, including a joint action agency or similar entity.

While those agencies fall within the ‘any individual or entity’ terminology used in §231(c)(3)(B) authority to request CEII designation, requests under §235 require DOE or FERC, if they approve CEII designation, to apply that designation for 10 years, not the general period “the information is related to energy infrastructure in service” standard established under §231(c)(9)(A).

Paragraph (d) makes the requesting government entity responsible for the defense “against any claim for disclosure of the designated information” {§235(d)(2)}, not DOE or FERC.

Wartime Clearance


Section 236 allows DOE and FERC to loosen CEII disclosure rules “during the state of war or period of national disaster due to enemy attack” {§236(a)}. That loosening of disclosure rules is limited to the authority “to confer with individuals and grant individuals access to critical electric infrastructure information pending further investigation of those individuals”.

Enforcement


Section 237(a) provides that any entity that does not return an item of CEII within 90 days of a request by DOE or FERC will be subject to enforcement under 16 USC 825m, §825o, and §825o-1.

Section 237(b) requires DOE and FERC to establish appropriate sanctions for knowingly and willfully disclosing critical electric infrastructure information in a manner that is not authorized under this new subpart of the Federal Power Act. It specifically provides that the minimum sanctions for FERC Commissioner or former Commissioner who knowingly and willfully discloses CEII in an unauthorized manner will be {§237(b)(1)(A)}:

• The potential loss of access to critical electric infrastructure information; and
• The potential public issuance of letters of reprimand.

Sunday, June 7, 2020

S 3688 – Energy Infrastructure Security – CEII Changes


This is the second post about the introduction of S 3688, the Energy Infrastructure Protection Act of 2020. In the initial post I talked about the organizational changes the bill proposes for the Federal Power Act and the definitional changes proposed. In this post I will look at the changes the bill would make in the Critical Electric Infrastructure Information (CEII) program.

CEII Designation


Section 3(c) of the bill would revise §215(d), “Protection and sharing of critical electric infrastructure information”, of the Federal Power Act {16 USC 824o-1(d)(2)} [after changing the designation of that subsection to §231(c)].

First, paragraph (2), “Designation and sharing of critical electric infrastructure information”, is re-written, removing reference to sanctions {existing (2)(C)} and the ‘standards of the Electric Reliability Organization’ {existing (2)(D)}.

Then, paragraph (3), “Authority to designate”, is greatly expanded. The existing language is essentially rewritten as subparagraph (A). Then two new subparagraphs were added:

(B) Submission of request for designation, and
(C) Conflicts between designations by the secretary and the commission

Subparagraph (B) would allow anyone to request that either the Secretary or FERC designate any information in the respective agency’s possession as CEII. Upon receipt of such a request the agency would be required to treat the requested information as CEII until it is actually designated as such or 21 days after the agency notifies the requestor that the information was not so designated.

Subparagraph (C) would require the Department and FERC to confer anytime that there was a conflicting decision made on whether a specific piece of information would be designated as CEII. Absent a mutual resolution of such conflicts, each agency would be allowed to rely on its own designation in the protection of the information.

Segregation of CEII


Changes would also be made to the existing §215(d)(8), “Disclosure of nonprotected information” [re-designated §231(c)(8)]. The poorly named paragraph currently requires DOE and FERC to “segregate critical electric infrastructure information or information that reasonably could be expected to lead to the disclosure” of CEII within documents or communications. The new language would ease that requirement somewhat by changing “shall segregate” to “shall reasonably attempt to segregate”.

A new subparagraph (B) was added to provide legal cover for that easing of the segregation requirement by specifically noting that any such failure to segregate CEII in a document “shall not result in an inference or finding that the information should not be entitled to protection as critical electric infrastructure information”.

Duration of Designation


Paragraph §215(d)(9), “Duration of designation” [re-designated §231(d)(9)], is completely rewritten. The reference to the ‘5 year’ limitation on CEII designation is removed. The replacing limitation in the new subparagraph (A) would be not “for a period longer than the information is related to energy infrastructure in service”. Even for that broader limit an exception is provided, allowing DOE or FERC to re-designate information as CEII “before, on, or after the date on which an earlier designation has expired”.

An even broader duration designation is provided in subparagraph (C) for information “about a vulnerability or threat to energy infrastructure, or the planning and construction of a system or asset that is intended to address a vulnerability or threat to energy infrastructure”. This subparagraph allows DOE or FERC to designate such information as CEII “for the period during which the vulnerability or threat exists” {new §231(d)(9)(C)(i)} and “for any additional period determined to be appropriate” {new §231(d)(9)(C)(ii)}.

Removal of Designation


The bill deletes the current language of §215(d)(10), “Removal of designation” and provides ‘substitute’ language for §231(c)(10), “Removal of designation”. That is somewhat misleading though as the only actual change to the existing language is the insertion of the term ‘energy infrastructure’ before the words “the bulk-power system, or distribution facilities” at the end of the paragraph. This was necessary because of the expansion of the definition of term ‘critical electric infrastructure’ used in the definition of CEII.

Two New Paragraphs Added


The bill also adds two new paragraphs to §231(c):

(12) No immediate obligation to designate, and
(13) Effect of prior determinations

The first specifically allows DOE or FERC to sit on a CEII designation request until a request for disclosure of the information is made under 5 USC 552 (Freedom of Information Act) or any other law “requiring public disclosure of information or records”. Since, as noted above, lacking a determination, information is required to be treated as CEII upon request, this has little legal effect on the duty of DOE or FERC to protect the information as CEII.

The second new paragraph specifically allows DOE or FERC to designate information as CEII even if a previous decision had been made not to make such a designation in the past.

This is another good stopping point even though there are CEII changes in subsequent portions of this bill.

Monday, March 16, 2020

DOE Publishes CEII Admin Final Rule


Today the Department of Energy (DOE) published a final rule in the Federal Register (85 FR 14756-14772) concerning “Critical Electric Infrastructure Information; New Administrative Procedures”. The rule establishes procedures for the designation of critical electric infrastructure  information (CEII) under section 215A(d) of the Federal Power Act (16 USC 824o-1). The notice of proposed rulemaking (NPRM) for this action was published in October 2018. OMB approved this final rule on January 28th, 2020.

Changes from NPRM


Changes that were made in the final rule include:

Added definition of ‘confidential business information’;
Added definition of ‘CEII Coordinator’;
Specified that the CEII Coordinator or Coordinator's designee can designate certain information sought by DOE as CEII;
Expanded the coordination of implementation of DOE's CEII authority to include all CEII Coordinators;
Updated the marking of CEII as “CEII-CRITICAL ELECTRIC INFRASTRUCTURE INFORMATION—DO NOT RELEASE”;
Added dual marking requirement for material that is both confidential business information and CEII;
Clarified that a conference call will be scheduled within five days of when the CEII submitter is notified of the request;
Added DHS and NRC to the list of federal agencies that the CEII Coordinator will meet with annually to discuss CEII issues;
Added requirement that the designation decision be communicated “promptly” to the requestor;
Removed all references to “pre-designation” in the Final Rule;
Clarified that there are two methods for initiation of the re-designation process;
Clarified that  reconsideration requests can be made through a secure electronic submission or by mail;
Clarified that inadvertent disclosure does not affect the disclosed material's CEII status

Effective Date


The effective date on this rule is May 15th, 2020.

Tuesday, January 28, 2020

OMB Approves DOE CEII Final Rule


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOE’s final rule on Critical Electric Infrastructure. This rule was submitted to OIRA in October 2019. The notice of proposed rulemaking (NPRM) was published in October of 2018. Interestingly, there was one meeting at OIRA concerning this bill where environmental activists expressed their concerns about the rule.

This rule addresses the DOE internal procedures for approving and restricting access to Critical Electric Infrastructure Information (CEII).

Wednesday, October 30, 2019

DOE CEII Final Rule to OMB – 10-29-19


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOE on “Critical Electric Infrastructure” According to the Spring 2019 Unified Agenda, the rule would outline the “administrative procedures [that] are intended to ensure that stakeholders and the public understand how the Department would designate, protect, and share CEII under the Federal Power Act”. The notice of proposed rulemaking for this action was published in October 2018.

Monday, October 29, 2018

CEII Admin Procedures NPRM Published


The Department of Energy published a notice of proposed rulemaking (NPRM) today in the Federal Register (83 FR 54268-54278) describing the DOE’s proposed procedures for the designation and control of Critical Electric Infrastructure Information (CEII) that would parallel the Federal Energy Regulatory Commission’s rules on CEII (18 CFR 388.113). This rule implements the CEII requirements set forth in §61003(d) of the 2015 FAST Act {PL 114-94, 129 STAT. 1773; codified at 16 USC 824o-1(d)}.

The NPRM would add 10 CFR 1004.13, Critical Electric Infrastructure Information. This would include sub-paragraphs for:

Protection of CEII (Note: This is apparently mismarked at ‘(6)’ not ‘(g)’ in the NPRM);

Readers are reminded that CEII is a listed type of controlled unclassified information (CUI) under the Information Security Oversight Office (ISOO) regulations (32 CFR 2002). Where the requirements of this new DOE rule do not exceed the requirements of the ISOO regulation, the ISOO regulation supersedes these requirements.

DOE is soliciting comments on this NPRM. Comments must be received by December 28th, 2018. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; RIN 1901-AB44).

Wednesday, October 17, 2018

OMB Approves New CEII NPRM


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking (NPRM) from the Department of Energy on their Critical Electric Infrastructure Information (CEII) program. The NPRM was submitted to OMB in July.

When this NPRM was submitted the rulemaking had not been listed in the latest (Spring 2018) Unified Agenda. Yesterday OIRA published the Fall 2018 Unified Agenda (more on this in another post) and this rulemaking was included; not much information in the listing, unfortunately. The abstract in the listing simply notes:

“The Department of Energy (DOE or Department) is publishing a proposed rule for public comment to implement DOE’s critical electric infrastructure information (CEII) designation authority under section 215A of the Federal Power Act.  The proposed administrative procedures are intended to ensure that stakeholders and the public understand how the Department would designate, protect, and share CEII under the Federal Power Act”

I expect that the NPRM will be published in the Federal Register in the next week or two; even when it initiates regulatory action, the Trump Administration is not quick about these things.


Sunday, July 22, 2018

FERC to Expand Cybersecurity Reporting Requirements


Earlier this week the DOE’s Federal Energy Regulatory Commission published an order (final rule) on their web site (it will become official when published, probably next week, in the Federal Register) directing the North American Electric Reliability Corporation (NERC) “to develop and submit modifications to the NERC Reliability Standards to augment the mandatory reporting of Cyber Security Incidents, including incidents that might facilitate subsequent efforts to harm the reliable operation of the bulk electric system (BES).” The notice of proposed rulemaking for this order was published in December of last year.

I am not going to go into a great deal of detail about this rule here; the complex relationships between FERC, NERC and the electric grid are just a little too byzantine for my simple mind to understand. The interesting take away here for the rest of the control system security community is that the new rules to be written by NERC will expand ‘Cyber Security Incidents’ (capitalized and not hyphenated in FERC SPEAK) to include some sort of measure of near misses and they will include a requirement to notify ICS-CERT of those incidents in addition to the current requirement to notify the Electricity Information Sharing and Analysis Center (E-ISAC).

Expanded Definition


Currently the NERC Reliability Standard CIP-008-05 requires the reporting of Cyber Security Incidents only if they have “compromised or disrupted one or more reliability tasks.” While such incidents are certainly worth reporting they leave a whole slew of potential preparatory ‘attacks’ and compromises outside of the mandatory reporting structure and completely ignore the salutatory effects of sharing information about ‘near misses’ or almost successful attacks.

With this order NERC will be required to recraft CIP-008 to include “Cyber Security Incidents that compromise, or attempt to compromise, a responsible entity’s [Electronic Security Perimeter] ESP or associated [Electronic Access Control or Monitoring Systems] EACMS” in the reporting requirements.

ICS-CERT


In the NPRM it was noted that the DOE noted only two Cybersecurity Incident Reports in 2015/2016 while in the same time frame the DHS ICS-CERT responded to 125 cybersecurity incidents in 2014/2015. Ignoring the whole apples and rocks comparisons here, it becomes apparent that some sort of reporting is already underway to ICS-CERT. The FERC order would formalize that and make it a reporting requirement.

Commentary


The expansion of the reporting requirements for Cyber Security Incidents (and I AM NOT going to do another ‘CSI’ acronym; can’t do it, sorry) cannot help but be a good thing; except….

Okay, we have no idea how many new reports this requirement will generate. IF the industry complies with the intent of the rule (an open question) the number of reports could be quite large. Does NERC (who owns E-ISAC) have the necessary number of analysts necessary to review, catalogue, cross-reference, and then deduce attack information from such submissions and then produce properly anonymized information to share with the remainder of the community in a timely manner. Because of the lack of a reasonable estimate of the potential number of reports, and the apparently expanding interest in probing/compromising the grid, I suspect not.

Then there is the whole issue of the quality of information that will be submitted to E-ISAC. Obviously, the more complete the information, particularly on attempted attacks, the easier it will be for E-ISAC to establish actionable information to share with the other E-ISAC members; poor quality or inaccurate information means the information ultimately shared is less useful and potentially even counter-productive.

That leads to the question of who will train facility control system engineers to recognize, isolate and document cyber-attacks. Oh, sorry, control system engineers will not be doing that, it will be the Security Operations Center with its staff of forensically trained experts. I forgot that those existed at each facility in the Bulk Electric System (SIGH).

Actually, I suspect that this is the reason that the Order includes a requirement to report to ICS-CERT. I do not expect (that is my guess, I certainly do not know) that E-ISAC has fly-way teams of control system experts to investigate these incidents. That is not a complaint, it is just not what one should probably expect from any ISAC.

The problem that arises from this is has anyone looked at the capability of ICS-CERT to expand the operations of its fly-away teams to respond to an increasing number of incidents. Who is going to pay for the additional costs of the investigations of the new reports? FERC has no control of ICS-CERT either directly nor through the DOE, so is there a memorandum of understanding between the two organizations about how ICS-CERT is supposed to respond to these newly required reports?

All sorts of interesting questions being raised by this relatively simple final rule, but I will ask but one more (really); how are the Critical Electrical Infrastructure Information (CEII) regulations going to affect the information submitted by owners to ICS-CERT? Owners can request that sensitive security information submitted to FERC or NERC be protected by CEII disclosure rules, but not information directly submitted to ICS-CERT. Information submitted to ICS-CERT by NERC or FERC could be so protected, but there are no provisions for information submitted directly from the private sector to ICS-CERT. Another important quandary to be considered stumbling down the road to information sharing.

Wednesday, July 11, 2018

DOE Sends CEI Rulemaking to OMB for Approval


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that DOE had submitted a notice of proposed rulemaking (NPRM) on Critical Electric Infrastructure (CIE) for approval. This rulemaking was not published in the Spring 2018 Unified Agenda, so it is not clear what the rule would specifically address.

An article (registration required) in E&E News yesterday, however, states:

“The Department of Energy will soon publish proposed regulations outlining how it plans to ‘receive, hold and share’ critical electricity infrastructure information from utilities, a senior DOE official [Catherine Jereza, DOE's deputy assistant secretary for transmission planning and technical assistance] said yesterday.”

Most of what Jereza describes is covered under 18 CFR 388.113. Interestingly that Critical Electric Infrastructure Information (CEII) regulation only covers information disclosed to the Federal Energy Regulatory Commission (FERC). It does not specifically include similar (or even identical) information disclosed directly to DOE.

Wednesday, December 21, 2016

FERC Publishes CEII Revision Final Rule

Today the DOE’s Federal Energy Regulatory Commission (FERC) published a final rule implementing changes to the Critical Energy Infrastructure Information (CEII) program mandated by §61003 (16 USC 824o–1) of the Fixing America's Surface Transportation (FAST) Act (PL 114-94). The notice of proposed rulemaking NPRM (FERC uses a different acronym – NOPR) was published in June of this year. This rule is unlikely to be overturned by the 115th Congress.

Congressional Mandate


The FAST Act required FERC to:

• Establish criteria and procedures to designate information as critical electric infrastructure information;
• Prohibit the unauthorized disclosure of critical electric infrastructure information;
• Ensure there are appropriate sanctions in place for Commissioners, officers, employees, or agents of the Commission or the Department of Energy [DOE] who knowingly and willfully disclose critical electric infrastructure information in a manner that is not authorized by the statute; and
• Facilitate voluntary sharing of critical electric infrastructure information  between, and by Federal, State, political subdivision, and tribal authorities; the Electric Reliability Organization; regional entities; information sharing and analysis centers; owners, operators, and users of critical electric infrastructure in the United States; and other entities determined appropriate by the Commission.

CEII


A number of commenters on the NPRM requested that the Commission provide more details on what constitutes CEII. The preamble to this rule notes that §824o-1(a)(2) provides a definition of CEII. As a result FERC does not see any need to provide additional guidance on what constitutes CEII. FERC reminds commenters that CEII protections only apply to information submitted to FERC and DOE so no other agencies (including the NRC) may designate information CEII. That does not, however, prohibit other agencies from providing protections to electric grid related information submitted to non-DOE agencies.

Protection of CEII and CUI


FERC declined to provide clarification of what constitutes ‘a secure place’ for storing CEII. The preamble to this rule failed to note that by not specifying regulatory requirements for storing CEII that the controlled unclassified information (CUI) regulations of the National Archives and Records Administration provide the controlling authority to define those requirements (including NIST SP 800-171 for electronic storage and transmission) since CEII is a covered CUI listed in the CUI registry.

Effective Date


This rule will become effective on February 21st, 2017. As I noted earlier, this rule is unlikely to be considered for review by the 115th Congress. The rule implements requirements set by the Republican 114th Congress so there will be little impetus for essentially the same Congress to negate this rulemaking even though it fulfills many of the definitional requirements of a ‘midnight rule’.

Commentary


The CEII program only protects information submitted to FERC and the DOE from disclosure by those agencies or personnel with whom those agencies share the information. It does not establish any requirements for protection of that information by submitting organizations. The only drawback that I see is that FERC/DOE are not required to make a determination that the information actually qualifies for CEII protections until the CEII Coordinator at FERC makes that determination in response to a request for the information.


FERC maintains in this rulemaking that the protect submitted information as if it were CEII until such determinations are made. I think that a good lawyer for a whistleblower could maintain that any disclosures of information by FERC/DOE employee prior to a determination being made by the CEII Coordinator. To my mind it would make more sense to declare all submitted material CEII upon receipt and then to remove that declaration when appropriate when the CEII Coordinator is asked to review the information for possible release.

Thursday, April 14, 2016

S 2012 Deal Reached

Yesterday a deal was reached in the Senate to allow for continued consideration of S 2012, the Energy Policy Modernization Act of 2015. It provides for an en bloc vote on 28 selected amendments with a 60 vote threshold to adopt the amendments. Four additional specific amendments will be considered individually, again with a 60 vote minimum for adoption.

None of the amendments that I described in a series of blog posts in January and February (here, here, here, and here) were among those covered in the agreement. The provisions in the base bill for the Critical Electric Infrastructure Information (CEII) program and the enhanced grid security provisions remain unchanged.


A date for these votes has not yet been set. Senators McConnell and Reed will work that out between them. I expect that it will be sometime next week. I would expect the en bloc amendments to pass with substantial bipartisan support. The remaining four amendments will be a much less sure thing for passage.

Thursday, January 28, 2016

Senate Considering S 2012

Yesterday the Senate began consideration of S 2012, the Energy Policy Modernization Act of 2015. Somehow I missed this bill when it was introduced back in September, but it is very similar to HR 8 that was passed by the House last month. The bill does contain cybersecurity related provisions, but certainly not all of those included in the House bill.

Critical Electric Infrastructure Information

Like the House bill, §2001 amends the Federal Power Act to include specific authority to designate Critical Electric Infrastructure Information (CEII). As I explained in an earlier post, while a CEII program does currently exist it is not specifically authorized by statute. This will become important when the National Archives and Records Administration finally publishes its final rule on Controlled Unclassified Information (CUI). Being authorized by statute would allow the DOE Secretary more latitude on the way CUI is controlled.

There are several provisions of the HR 8 CUI section that are not included in S 2012. They include provisions associated with:

• Submission of information to congress;
• Disclosure of protected information;
• Duration of designation;
• Removal of designation; and
• Judicial review of designations

The lack of coverage of these items in the bill simply means that the NARA regulations would govern these areas, not the DOE regulations.

Enhanced Grid Security

Section 2002 of the bill establishes a number of cybersecurity programs, some of which already exist in fact, if not in law. Each of the programs include authorized funding. They include:

• Cybersecurity sector specific agency designation;
• Cybersecurity for the energy sector research, development, and demonstration program;
• Energy sector component testing for cyberresilience program;
• Energy sector operational support for cyberresilience program;
• Modeling and assessing energy infrastructure risk;
• Study on expanding industry membership and participation in ES–ISAC

The component testing program is somewhat similar to the Cyber Sense program include in §1106 of HR 8. The Senate version is not nearly as comprehensive or detailed. The Senate program does include $15 Million in annual funding where the Cyber Sense program included no funding, relying entirely on 3rd party testing and certification.

Moving Forward

Consideration of the bill continues today and there is not currently a schedule for a final vote. Sen. Murkowski (R,AK) is working hard to keep the amendment process limited to energy matters so that the bill does not get saddled with any of the controversial riders that have earned HR 8 a Presidential veto threat.


It is very likely that this bill will pass in the Senate. The House will then have to decide whether or not to accept the Senate bill or insist on the language of HR 8. If the latter occurs there would probably be a conference committee formed to work out the differences in the two bills.

Friday, September 18, 2015

HR 8 Introduced – Energy Security

On Wednesday Rep Upton (R,MI) introduced HR 8, the North American Energy Security and Infrastructure Act of 2015. The bill mainly addresses energy supply chain issues, but it does have two provisions dealing with actual security issues. The first is protection of information about bulk electrical system security issues and the second is a new cybersecurity program.

Information Protection

Section 1104 of the bill would add a new section (§215A; Critical Electric Infrastructure Security) to the Federal Power Act (16 USC 824 et seq.). The new section would provide authority for the Secretary of Energy to address a grid security emergency {new §215A(b)} and establish a program for the protection of critical electric infrastructure information. The provisions of this section are essentially those found in HR 2271 which I have previously discussed in detail.

While a CEII program does currently exist, pending regulations on controlled but unclassified information (CUI) from the National Archives and Records administration, treat such programs differently if they are authorized by law.

Cyber Sense Program

Section 1106 requires the Energy Secretary to establish a Cyber Sense Program to identify and promote cyber-secure products intended for use in the bulk-power system. The program would allow voluntary industry participation and would include {§1106(b)}:

• A testing process to identify products and technologies intended for use in the bulk-power system, including products relating to industrial control systems, such as supervisory control and data acquisition systems;
• The establish and maintain cybersecurity vulnerability reporting processes and a related database for products in the Cyber Sense program;
• Regulations regarding vulnerability reporting processes for products tested and identified under the Cyber Sense program; and
• Technical assistance to utilities, product manufacturers, and other electric sector stakeholders to develop solutions to mitigate identified vulnerabilities in products tested and identified under the Cyber Sense program.

This section would also require the Secretary to provide for public notice and comments before establishing or changing the required testing program. Products included in the program would be required to be tested every two years.

The bill does not specifically mandate that the results of the product testing should be considered as Critical Electric Infrastructure Information (CEII). It does, however, require that “any vulnerability reported pursuant to regulations promulgated under subsection (b)(3), the disclosure of which could cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be exempt from disclosure” under the Freedom of Information Act or any similar State and local laws.

Moving Forward
As I noted in my earlier post the assignment of ‘HR 8’ to this bill instead of a sequential bill number indicates that the Republican leadership in the House considers this bill a high political priority. It was considered in a markup hearing yesterday before the House Energy and Commerce Committee, but Committee web page does not yet provide any results of that consideration. I expect, however, that the bill was adopted by voice vote.

Commentary

The new Cyber Sense Program proposed by this bill is the first serious attempt by Congress to deal with the problems associated with industrial control system security. The idea of the Federal government establishing a testing and certification program for ICS components and systems is certainly an innovative approach to control system security.

Since this bill does not provide any funding for the program, it is fairly clear that the authors intend this testing to be done by third-party organizations and that is reinforced by the requirement for the Secretary to “oversee Cyber Sense testing carried out by third parties” {§1106(b)(8)}. The problem becomes that, since the Energy Department is not paying for the testing, that it will most likely be the vendor that pays. This always raises the potential issues of testers being beholden to the people that make the products being tested.

The establishment of regulations for vulnerability reporting for Cyber Sense products is something that was fairly glibly added to this bill. But, taken along with the information sharing restrictions outlined, this is going to be problematic. Except for equipment that is uniquely used by the bulk-power system, trying to regulate how security vulnerability reporting is conducted without intimately involving at least ICS-CERT is going to create more problems than it solves.

A brief example will help explain the problem. A private security researcher discovers a vulnerability in a PLC that is part of the Cyber Sense program, but is also used in a wide variety of other industrial control systems. Normally he would have a choice of coordinating that vulnerability disclosure with the vendor, ICS-CERT (or any one of a number of other coordination agencies) or publicly disclosing the vulnerability. Under the new program, if he instead disclosed it to the Cyber Sense program, then there would be no public disclosure through ICS-CERT or the vendor. In fact, if the new regulations were to declare this disclosure to the Cyber Sense to be CEII information (a logical move), then ICS-CERT would not be able to post it to the US-CERT Secure Portal because people without a CEII need-to-know have access to that system.

Crafters of this bill missed one of the biggest potential incentives for using Cyber Sense components. DHS has the Safety Act program under their Science and Technology Directorate that provides important legal liability protections for providers of Qualified Anti-Terrorism Technologies. This bill should have set up a similar program for Cyber Sense vetted products.

I would like to suggest that instead of making the vulnerability information CEII and limiting the disclosure to just the energy sector, that the bill should have designated ICS-CERT as the agency responsible for coordinating disclosures of vulnerabilities for all Cyber Sense Products. It would then go on to require that ICS-CERT initially release the vulnerability information on the US-CERT Secure Portal and only make full public disclosure in coordination with the Department of Energy organization overseeing the Cyber Sense program. That way non-energy sector organizations using the same equipment would have an opportunity to fix their devices before the public disclosure of the vulnerability.


Now, I really like the idea of an independent agency that does in depth security vulnerability testing of control system components and certifying some level of minimum security for such devices. That would certainly make the purchasing of secure ICS components much easier. But we do need to be careful how that is done to prevent the most egregious unintended consequences.

Friday, May 29, 2015

HR 2402 Introduced – Protected Electric Security Information

Earlier this month Rep. Lofgren (D,CA) introduced HR 2402, the Protecting Critical Infrastructure Act. The bill would create a new class of controlled unclassified information (CUI) to protect information sharing within the bulk power distribution system and with Federal, State and local government agencies.

In many ways the bill shares elements in common with HR 2271 and S 1068, but there are two major differences. First there is no authorization for the Secretary of Energy to take any actions to protect cybersecurity. Second instead of recognizing the current Critical Energy Infrastructure Information (CEII) category of CUI it constructs a new category out of whole cloth.

Protected Electric Security Information

As I have mentioned in other blogs the current CEII would be classified as CUI Basic under the rulemaking on CUI currently being undertaken by the National Archives and Records Administration (NARA) of the OMB. This means that the NARA regulations would govern markings, protective measures, classification authority and declassification authority for CEII.

This bill, on the other hand would establish a new category of CUI, Protected Electric Security Information (PESI) as a matter of law. That would place PESI in the CUI Specified category. This means that the NARA CUI regulations (when finalized, maybe next year) would only govern those aspects of security not specifically covered in this bill or subsequent regulations issued in accordance with this bill.

The information protection items specifically addressed in the bill include:

∙ Protection from disclosure under Federal, State and local freedom of information rules {new §215A(a)(1)};
∙ Duration of protection, maximum 5 years §215A(a)(6)};
∙ Early declassification authority, resides in FERC §215A(a)(7)};
∙ Judicial review process §215A(a)(8)};

Additionally, FERC is given authority to draft regulations governing the sharing of CEII information between and amongst government agencies (at all levels in the US) and private entities, as well as with Mexican and Canadian authorities as necessary.

Moving Forward


Neither Lofgren nor her cosponsor {Rep. Gowdy (R,SC)} are members of the House Energy and Commerce Committee so it is unlikely that this bill will make it to committee consideration, especially considering that sponsors of HR 2271 are on that Committee.

Tuesday, May 19, 2015

Bills Introduced – 05-18-15

There were 26 bills introduced in the House and Senate yesterday. Of those two may be of specific interest to readers of this blog:

HR 2396 To amend the Federal Food, Drug, and Cosmetic Act with respect to the regulation of health software, and for other purposes Rep. Blackburn, Marsha [R-TN-7]

HR 2402 To amend the Federal Power Act to prohibit the public disclosure of protected information, and for other purposes Rep. Lofgren, Zoe [D-CA-19]

Blackburn has tried to limit the FDA’s authority to regulate non-patient-contact software in the past, but it is too early to tell what regulation or lack thereof is being covered here.


HR 2402 is probably another effort to codify critical electrical infrastructure information in light of the current NARA rulemaking that is underway.

Thursday, June 19, 2014

Critical Energy Infrastructure Information Release ICR Approved

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the renewal of the Federal Energy Regulatory Commission’s (FERC) information collection request (ICR) for their Critical Energy Infrastructure Information (CEII) Release program. The approval was conditional upon FERC’s continued review of internal procedures of how to best protect CEII while allowing the widest possible dissemination.

The actual condition language reads:

“The Commission will incorporate any changes, upon the resubmission of this information collection request, in response to FERC's ongoing assessment of how best to keep Critical Energy Infrastructure Information secure while allowing those in the industry who need the information to access it.”


CEII is defined at 18 CFR 388.113(c)(1) and the procedures for requesting access are outlined in the same section. There is an interesting review of the changes in the FERC handling of CEII access process on the FERC web site.
 
/* Use this with templates/template-twocol.html */