Showing posts with label CSAC. Show all posts
Showing posts with label CSAC. Show all posts

Friday, November 18, 2022

CISA Announces Cybersecurity Advisory Committee Meeting – 12-6-22

Today, CISA published a meeting notice in the Federal Register (87 FR 69283-69284) for an in-person meeting of their Cybersecurity Advisory Committee on December 16th, 2022 in Cupertino, California. The public will have access to portions of the meeting by teleconference.

The agenda includes:

  • A discussion on the status of previous CISA Cybersecurity Advisory Committee recommendations,
  • A member roundtable on the CISA Cybersecurity Advisory Committee strategic focus for 2023, and
  • A discussion on the CISA Cybersecurity Advisory Committee annual report.

Members of the public that wish to participate via the teleconference need to register (via email to CISA_CybersecurityAdvisoryCommittee@cisa.dhs.gov) by December 4th. Written comments may be submitted to the Committee by the same date via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2022-0008).

Friday, May 27, 2022

Review - CISA Announces Cybersecurity Advisory Committee Meeting – 6-22-22

Today CISA published a meeting notice in the Federal Register (87 FR 32178-32179) for an in person meeting of the Cybersecurity Advisory Committee (CSAC) on June 22nd, 2022 in Austin, TX. Portions of the meeting will be closed to the public.  The public portions of the meeting will include:

• Period for public comment,

• Updates from six subcommittees, and

• Discussion and voting on recommendations from CSAC to CISA

NOTE: Items to be voted upon should be available on the Committee’s website prior to the meeting.

CISA is soliciting public participation in next month's meeting. Personnel wishing to attend, either in person or telephonically, need to register by June 20th, 2022. Personnel wishing to make personal presentations at the meeting need to register that fact as well. Written comments to be considered by the CSAC can be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # CISA-2022-0002).

 

For more details about the upcoming meeting, as well as a brief look at the previous meeting, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-announces-cybersecurity-advisory - subscription required.

Sunday, March 13, 2022

Reader Comment – Misinformation in OT

In response to my post yesterday about the upcoming meeting of the CISA Cybersecurity Advisory Committee (CSAC), Vytautas Butrimas left the following comment on LinkedIn:

“Reading one of the bullets – ‘Protecting Critical Infrastructure from Misinformation and Disinformation Subcommittee’ - one may wonder what their definition of critical infrastructure is. Any room for safety and process control issues or will the focus be on email, websites and social media?”

The short and quick answer to the question looks like the target of this Subcommittee will be information system misinformation. I say this based upon the report from the first meeting of the CSAC. The page 3 discussion about this Subcommittee reads thus:

“On the topic of Protecting Critical Infrastructure from Misinformation & Disinformation, Dr. Kate Starbird, University of Washington, noted that the level of disinformation being spread across information systems has been increasing dramatically in recent years. She noted that it was used in 2020 to undermine the U.S. election system and that it has also made it difficult for Governments to address crisis events like the COVID-19 pandemic. She said that the solution to addressing this is to teach people to care about whether what they're sharing is true or false. Mr. Chesney noted that it might be very difficult to get people to unlearn bad behavior like that as, after a while, it becomes an entrenched cognitive bias. He suggested that working with the various social media platforms to address the problem might be the best approach. Mr. Stamos and Ms. Allison noted that Government agencies are very bad at using their authority and platforms to push back against disinformation. Ms. Allison suggested that CISA create a playbook for agencies to use in responding to the spread of disinformation.”

Truthfully, none of the subcommittees would seem to be specifically directed at operational technology cybersecurity issues. The closest we get is the Building Resilience and Reducing Systemic Risk to Critical Infrastructure Subcommittee. The summary of the discussion about that Subcommittee area give us this statement:

“Mr. Fanning stated that one of the biggest impediments to industry and Government working together to address systemic risk is identifying the truly critical elements in critical infrastructure. He said CISA can help develop solutions, but that industry will need to take the lead in working with the Government to address the problem. Mr. Fanning noted that there are a number of models that CISA and industry could build on, such as the Analysis and Resilience Center for Systemic Risk developed by the Finance and Energy sectors. He closed by stating that, because industry controls the vast majority of critical infrastructure in the United States, the end goal should be for the Government to provide industry the tools to defend themselves.”

While the overall statement is ambiguous as to the scope of coverage of control system security issues, the final sentence is a good reminder that we are unlikely to see much in the way specific help on OT security issues.

Having said that, it is early in the life of the CSAC and perhaps we can still influence the direction they will take as they move forward. The best way to do that would be to actively participate in the considerations of the Committee. The easiest way to do this would be to begin sending proposals for the Subcommittees to consider, targeting the reducing systemic risk subcommittee. I will start that process by proposing two activities to be considered.

Proposing the formal establishment of the NCCIC-ICS as the office within CISA that is responsible for receiving, coordinating and publishing reports of control system vulnerabilities.

Proposing that the subcommittee start work on developing the regulatory structure for setting up the recently passed cyber incident reporting requirement.

I’ll have more discussion about these two potential ideas in future posts.

Thursday, November 25, 2021

CISA Announces Initial Cybersecurity Advisory Committee Meeting – 12-10-15

CISA published a meeting notice in tomorrow’s (on-line today) Federal Register (86 FR 67484-67485) for the initial meeting of the Cybersecurity Advisory Committee on December 10th, 2021. This in-person (subject to changes in COVID status) meeting will be held in McLean, VA. Portions of the meeting will be closed to the public for security reasons.

The Cybersecurity Advisory Committee was established earlier this month. This initial meeting will include:

• An overview of CISA,

• A discussion on CISA's big challenges, priorities, and

• Potential study topics for the Committee

Personnel wishing to attend the meeting or make public comments at the meeting need to register via email (CISA_CybersecurityAdvisoryCommittee@cisa.dhs.gov) by December 8th. Written comments may be submitted by the same date via the Federal eRulemaking Portal (www.regulations.gov; docket #CISA-2021-0017).

 
/* Use this with templates/template-twocol.html */