Showing posts with label CISA Subpoena. Show all posts
Showing posts with label CISA Subpoena. Show all posts

Sunday, April 4, 2021

CISA Publishes Subpoena Privacy System of Records Notice – 4-5-21

On Monday (available on line today) CISA is publishing a notice in the Federal Register (86 FR 17616-17619) announcing a new Privacy Act system of records to support CISA’s new subpoena authority. This new system of records will allow CISA to “to receive and collect customer or subscriber contact information from electronic  communications service providers to identify and notify entities at risk of security vulnerabilities  relating to critical infrastructure information systems and devices.” The new subpoena authority was provided to CISA by §1716(a)(3) of the FY 2021 National Defense Authorization Act.

The notice includes information on:

Purpose of the system,

Categories of records in the system,

Routine use of records,

Record retention and disposal,

Record access procedures, and

Contesting record procedures.

CISA is soliciting public comments on this new system of records. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov: Docket # CISA-2021-0004). Comments should be submitted by May 5th, 2021. The effective date for this system of records will be April 5th, 2021, the date of publication of the notice. Routine use of the system of records will not start until May 5th.

Commentary

These ‘system of records notices’ are about as pro forma as legal notices get. The agency attorneys and privacy people have poured over them to ensure that all of the I’s have been dotted and the T’s crossed. Having said that, I do have a couple of suggestions about how this notice (and others like it) could be improved.

First, the notice states that the information will be Controlled Unclassified Information (CUI). The basic rules for the protection of CUI are laid out in 32 CFR 2002. Additional requirements may be set forth by the individual program operating specific types of CUI. That means that a full understanding of the rules protecting the information labeled as CUI can only be had if the particular type of CUI is designated. I suspect that in this case it will be Protected Critical Infrastructure Information (PCII), but it would be helpful if CISA (in this particular case) would specify that in this Notice.

This CUI issue also relates to my second suggestion. Under ‘Policies and Practices for Storage of Records’ the Notice simply lists:

“Records in this system are stored electronically or on paper in secure facilities in a locked drawer behind a locked door.”

The rules of §2002 for the storage of CUI are a tad bit more complicated than that, and the term ‘stored electronically’ provides no information, however sketchy, about how the information is protected in electronic format. In this day and age, and particularly from a cybersecurity agency, this lack of attention to electronic security is unforgiveable. At the very least there should be an ‘in accordance’ reference to 6 CFR 2002 and I think that a cybersecurity agency could be expected to also reference FIPS Pub 199 and NIST SP 800-171 which are required standards from the CUI regulations {§2002.14(h)(2)}.

NOTE: A copy of this post will be submitted as a comment on this Notice.

Monday, August 17, 2020

S 3045 Reported in Senate – CISA Subpoenas


Last month the Senate Homeland Security and Governmental Affairs Committee published their report on S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. The Committee amended and ordered the bill reported at a meeting held in March 2020. . The bill would provide the Cybersecurity and Infrastructure Security Agency (CISA) with the authority to issue subpoenas “for the production of information necessary to identify and notify the [an] entity at risk”.

Subpoenas Limited to ISP’s?


I noted in my commentary on the introduction of S 3045 that:

“Much has been made in the more popular press (see here for example) about how this bill would allow CISA to issue these subpoenas to information services providers. This would certainly be helpful where CISA has been able to identify an IP address where a vulnerable system exists, but needs point of contact information from the ISP.”

There is nothing in the bill that specifically limits the application of the new CISA subpoena authority to just ISPs. In fact, there are just two mentions in the bill that would reference statutes applicable to ISPs. In the new §659(o) being added by the bill subparagraphs (2)(B)(i) and (2)(C) both refer to 18 USC 2703, Required disclosure of customer communications or records. The first two paragraphs of §2703 deal with obtaining copies of electronic communications while paragraph (c)(2) allows, upon application of an administrative subpoena “authorized by a Federal or State statute”, a Federal agency to require a “provider of electronic communication service or remote computing service” certain limited information about a “a subscriber to or customer of such service”.

If the intent of this bill were limited to collecting information from ISP’s, the crafters of the bill would have specifically provided reference to §2703(c)(2) in the new §659(o)(2)(A), rewording the final phrase of that sub-section to read:

“the Director may issue a subpoena under 18 USC 2703(c)(2) for the production of information necessary to identify and notify the entity at risk, in order to carry out a function authorized under subsection (c)(12).”

Failing to limit the subpoena authority to the referenced subparagraph means that someone in the crafting process intended to extend the subpoena authority to obtaining information identifying owner/operators of vulnerable equipment in critical infrastructure to other entities than just ISPs. And there is nothing in the language of the report that obviate that conclusion.

Moving Forward


The publication of the Committee Report technically clears this bill for consideration by the full Senate. It is unlikely that this bill would be considered under regular order with the full debate and amendment process. The bill is just not important enough (in the grand scheme of things, it is important to CISA) to take up any of the limited time left in the session to address this bill.

This leaves two options for consideration. The first would be to take this bill up under the unanimous consent process. This bill would allow a single Senator to object to the consideration of the bill to block consideration. I suspect that there would be a number of Democrats that would object to the bill under general principles just to object to anything from DHS without a chance to debate and amend the bill.

The other path would be to add the provisions of this bill to a must pass bill. There is nothing in this bill that would cause serious enough objections to stall or even delay a must pass bill. I almost expected this to be added to the new Division E added to S 4049, the FY 2021 NDAA. Sen Johnson (R,WI) did propose similar language as two separate amendments (SA 1807 – pgs S3329-30; and SA 2195 – pgs S3584-5) to that bill. Neither were taken up by the Senate. Neither amendment was taken up on the floor of the Senate.

The only other ‘must pass bill’ that this bill could be appended to would be the DHS spending division of the final omnibus spending bill that may be taken up much later this year.

Sunday, March 15, 2020

HSGA Amends and Adopts S 3045 – CISA Subpoena


Last week the Senate Homeland Security and Governmental Affairs Committee held a business meeting during which they considered S 3045, the Cybersecurity Vulnerability Identification and Notification Act of 2019. Substitute language was offered by Sen Hassan (D,NH), a co-sponsor of the bill. The substitute language was further modified by an amendment offered by Sen Paul (R,TN) and the modified language was subsequently adopted by a voice vote.

Limit on Authority


The original substitute language modified the language of the proposed §2209(o)(2)(B) by adding a new category of limits to the information that the Cybersecurity and Infrastructure Security Agency (CISA) can seek under the new subpoena authority. The added restriction is that a subpoena cannot be seek information on “more than 20 covered devices or systems” {§2209(o)(2)(B)(ii)}.

Information Sharing Within the Government


Both the substitute language and the Rand amendment made changes to the authorization for CISA to share information obtained through the newly authorized subpoena authority.

The substitute language modified New §2209(o)(7)(A)(ii) by adding two new clauses; additionally allowing the Agency to share information received with another Federal agency if a cybersecurity incident is involved and:

• The Director determines that sharing the nonpublic information with another Federal agency is necessary to take law enforcement or national security actions pertaining to such incident; and
• The entity to which the information pertains is notified of the Director’s determination, to the extent practicable consistent with national security or law enforcement interests

The Paul amendment would modify that authority requiring the affected entity to consent to the disclosure unless “another Federal agency identifies the entity to the Agency in connection with a suspected cybersecurity incident” {new §2202(o)(7)(A)(iv)}.

The Paul Amendment also added a new paragraph (12) that further restricted the sharing of information with other Federal agencies. It would prohibit the sharing of any information produced as a result of the subpoena with “any other Federal agency for any purpose other than a cybersecurity purpose” as defined in 6 USC 1501.

Information Sharing with Affected Entity


The substitute language would revise the proposed §2202(o)(7) by adding a new sub-paragraph (F) that would require CISA, when notifying an entity at risk, to include:

• A discussion or statement that responding to, or subsequent engagement with, the Agency, is voluntary; and
• To the extent practicable, information regarding the process through which the Director identifies security vulnerabilities.

The substitute language also modified the language of §2202(o)(7)(C) requiring, after information received as a result of a subpoena showed that the covered entity was not a critical infrastructure entity, that the affected entity be informed about the vulnerability information before the contact information for the entity was destroyed.

Moving Forward


Once the Committee submits their report on the bill along with the amended language, the bill would be cleared for consideration by the full Senate. It seems to me, however, that this bill is still too controversial to be considered under the Senate’s unanimous consent process; some one would object. That would require the bill to be considered under regular order. That is too time consuming this late in the session and the Senate leadership would never bring it to the floor. The only other hope for this bill is for it to be included in a CISA authorization bill, which may be high-enough priority to be considered under regular order.

I am going to add a new caveat to this ‘moving forward’ discussion; COVID-19. At the seriousness of this epidemic becomes more apparent and the economic consequences become more painful, the normal operations of the House and Senate are going to become affected as a lot of priorities shift. Add to the fact that we are inevitably going to see a number of legislators and their staffs personally affected by the disease and that is going to affect the legislative process in ways that are going to be difficult to predict.

Commentary


I think that the changes made this week by the Committee are all worthwhile changes. I will note that changes did address two items that I noted in my original post about S 3045. My proposed language changes at the end of that post were not specifically made, but the new language for that clause achieves the same end. I will pretend that I helped that change along.

The other change addressed the objections of a number of commenters about the broader than popularly described scope of the subpoena authority. The way this bill written, even after the changes here, does not limit the CISA subpoena power to just contact information from ISPs. As I noted in that post:

“A more effective use of this subpoena power, however, would be to contact control system equipment vendors or integrators about owners of equipment with known cybersecurity vulnerabilities, particularly where those vulnerabilities do not yet have effective mitigation measures available. There is nothing in this bill that would prevent such subpoenas.”

Well, the new language does hinder that use of the subpoena authority by limiting the use “for not more than 20 covered devices or systems”. A clever subpoena crafter could still gain valuable information from a Siemens or Rockwell about owners of vulnerable devices, but there would be some very real limits on that information as a result of this change. Those limits could deny CISA timely information that would prevent a cyberattack on critical facilities.

Does this make this a bill that should not pass? Of course not. No legislation is going to be perfect in a representative democracy. Compromises must be made to get bills passed and signed into law. The CISA subpoena authority is important, and if some limits have to be placed on that authority for it to become available, so be it.

 
/* Use this with templates/template-twocol.html */