Showing posts with label CIP. Show all posts
Showing posts with label CIP. Show all posts

Friday, January 21, 2022

Review - NERC-CIP and Internal Network Monitoring

Yesterday the Federal Energy Regulatory Commission (FERC) published a notice of proposed rulemaking (NOPR in the FERC jargon) on their website for “Internal Network Security Monitoring for High and Medium Impact Bulk Electric System Cyber Systems”. In this NOPR, FERC proposes to direct the North American Energy Reliability Corporation (NERC) to “to develop and submit for Commission approval new or modified Reliability Standards that require internal network security monitoring within a trusted Critical Infrastructure Protection networked environment for high and medium impact Bulk Electric System Cyber Systems.”

NOTE: Thanks to Patrick C Miller, Ampere Industrial Security [company name and link added, 8-11-22 13:24 EDT] for pointing out this NOPR on TWITTER®.

Seeking Public Comments

FERC is soliciting public comments on this NOPR. Comments may be submitted via the eFile option on www.FERC.gov for registered individuals (Docket # RM22-3-000). Others may send comments via snail mail to:

Federal Energy Regulatory Commission

Office of the Secretary

888 First Street NE

Washington, DC  20426

The deadline for submission of comments will be 60-days after the NOPR is published in the Federal Register, probably sometime next week.

Commentary

This proposed expansion of cybersecurity regulations should surprise no one. It does not appear to me to be the least bit unreasonable. I would hope that most organizations under the NERC CIP would have at least some level of view within their networks that would form part of the proposed INSM, so that this proposed requirement should not be too much of a new regulatory burden.

This rulemaking is targeted at the physical operations networks supporting the BES, but other organizations utilizing similar networks to conduct operations in the physical realm should take a hard look at the proposals in the NOPR as similar technology is necessary to protect operations technology in other industries as well.

For more details about the NOPR, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nerc-cip-and-internal-network-monitoring - subscription required.

Sunday, November 14, 2021

Water Cybersecurity – NERC CIP or Something Else

An interesting blog post by Patrick Miller over on Ampersec.com on the topic of using the NERC CIP as a model for cybersecurity regulation of the water treatment/wastewater treatment sector. With his long experience with NERC CIP from a number of different perspectives, Patrick makes a number of important points that should be taken into account in any discussion of how to regulate the water sector. Unfortunately, I think he missed an important question, does cybersecurity really need to be regulated in that sector?

Last February I weighed in on this topic with my post “Call for Cybersecurity Regulations”. I want to take another look at the topic here, from a slightly different perspective, a perspective well familiar to those with experience in the Chemical Facility Anti-Terrorism Standards (CFATS) program, risk-based cybersecurity.

From a regulatory perspective, the federal government has no legitimate interest in insuring that the information services at water treatment facilities are adequately protected from cyberattacks. That is a utility management issue, the purview of State and local utility oversight organizations. Similarly, the EPA is only interested in ensuring that the water leaving the facility (into drinking water distribution systems or back into the wild, depending on the type of treatment plant) meets certain quality standards. As long as output testing controls are adequately protected, the cybersecurity of upstream treatment is not a legitimate federal concern.

So, we do not need a comprehensive set of cybersecurity regulatory controls to protect water treatment facilities from cyberattacks. We need each facility to have a risk-based vulnerability assessment of what controls (manual, analog and digital) at their unique facility are critical to output quality controls and then a properly scoped security plan (physical and digital) to protect those critical controls.

The EPA has taken a poorly crafted crack at the assessment side of the equation, but they are relying on local facility management that is trained and experienced in water treatment engineering to conduct security assessments. And they are just requiring that facilities certify that those assessments have been properly done. Security planning is just an after-thought.

What is needed is an online tool like that used in the CFATS program to submit vulnerability assessment data and relatively formulaic security plans. Water facilities are going to be more similar than chemical facilities, so a water security assessment tool (WSAT) will not need to be as complicated as the CFATS chemical security assessment tool (CSAT).

As I have said before, CFATS is probably a better model to look at rather than something like NERC CIP or the nuclear facility security model.

Wednesday, March 1, 2017

House Rejects Cybersecurity Amendment to HR 998

Yesterday, during the consideration of HR 998, the Searching for and Cutting Regulations that are Unnecessarily Burdensome (SCRUB) Act, the House rejected an amend by Rep. McNerney (D,CA) that would have exempted rules related to the physical security or cybersecurity of the bulk-power system from the provisions of the bill.

HR 998


HR 998 would establish the Retrospective Regulatory Review Commission to conduct a review of the Code of Federal Regulations to identify rules and sets of rules that collectively implement a regulatory program that should be repealed to lower the cost of regulation. The bill would then require rulemaking agencies, when making a new rule, to repeal rules or sets of rules classified by the commission as recommended for repeal to offset the costs of the new rule (cut-go procedure).

The Amendment


McNerney’s amendment would have changed the definition of the term ‘rule’ in §501(4) by adding “, except that the term does not include any rule relating to the physical and cyber security of the bulk-power system (as defined in section 215(a) of the Federal Power Act (16 U.S.C. 824o(a)), including any emergency action to protect and restore reliability of the bulk-power system”.

The Debate


During the limited debate about this amendment, McNerney spoke in favor of the amendment. He argued that: “The Critical Infrastructure Protection standards have worked. My amendment ensures that Federal agencies will have the flexibility needed to respond to challenges without sacrificing any other necessary protections.”

Rep. Ross (R,FL) argued against the amendment; noting “Ensuring the physical and cybersecurity of the bulk power system is absolutely important and critical. We should know whether or not the existing regulations are effective and are useful.”

Moving Forward


Today, the House passed the amended HR 998 by a largely partisan vote of 240 to 185. The partisan nature of the vote would seem to indicate that it would be difficult to get the bill to the floor of the Senate for a vote.

Commentary


HR 988 is not a bill that I would normally cover in this blog. The McNerney amendment does show, however, that congress is starting to look at more areas where cybersecurity issues may arise. This means that more bills are likely to see cybersecurity amendments being offered.


It is interesting to see that both sides of the debate on this amendment cited their concerns about the cybersecurity of the bulk-power system as the reason that members should vote one way or the other on the bill. This is another indication of the increasing politicization of cybersecurity in Congress. Given the relatively low state of cybersecurity knowledge in congress critters and their staffs, this could make for some very interesting comments being made in future debates.
 
/* Use this with templates/template-twocol.html */