Showing posts with label CSF. Show all posts
Showing posts with label CSF. Show all posts

Saturday, February 19, 2022

Review - NIST RFI to Support CSF – Supply Chain Security Integration

This Monday DOC’s National Institute of Science and Technology (NIST) is publishing (available on line today) in the Federal Register (87 FR 9579-9581) a request for information on “Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework (CSF) and Cybersecurity Supply Chain Risk Management.” NIST is considering aligning the CSF and the National Initiative for Improving Cybersecurity in Supply Chains (NIICS). In this RFI, NIST is requesting information that will support the identification and prioritization of supply chain-related cybersecurity needs across sectors.

NIST is looking for comments in the following areas:

Use of the Cybersecurity Framework,

Relationship of the CSF to Other Risk Management Resources, and

Cybersecurity Supply Chain Risk Management

Comments Requested

NIST is soliciting comments on this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NIST-2022-0001). Comments should be submitted by April 25th, 2022.

Commentary

The CSF is a corporate level cyber risk management tool rather than a true cybersecurity tool. Its greatest strength has always been that NIST proactively works to keep it current and responsive to current needs. It has relied heavily on the input from the public and outside experts. This RFI continues that tradition.

 

For more details about this RFI, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-rfi-to-support-csf-supply-chain - subscription required.

Saturday, June 1, 2019

NIST Updates Manufacturing Profile for CSF - 05-20-19


Buried in a notice about the availability of a ‘low-security’ version of a Cybersecurity Framework (CSF) implementation guide for manufacturers is a link to a notice that NIST has updated their 2017 Cybersecurity Framework Manufacturing Profile (NISTIR 8183). Looking at the table of changes on page v, it looks like most of the changes are moving a number of controls from ‘low security’ to the ‘moderate security’ and ‘high security’ categories.

Saturday, December 2, 2017

NIST Mapping Framework Core to NIST SP 800-171

This week the National Institute of Standards and Technology published a new supporting document for the Cybersecurity Framework on the CSF web page. This is a Excel spread sheet mapping CSF Subcategories to NIST SP 800-171, Revision 1, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.

A disclaimer in spread sheet notes that:

“NIST SP 800-171 focuses on protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations, and recommends specific security requirements to achieve that objective. The requirements recommended for use in SP 800-171 are derived from FIPS Publication 200 and the moderate security control baseline in NIST Special Publication 800-53 and are based on the CUI regulation (32 CFR Part 2002, Controlled Unclassified Information). The tailoring criteria applied to the FIPS Publication 200 security requirements and the NIST Special Publication 800-53 security controls is not an endorsement for the elimination of those requirements and controls—rather, the tailoring criteria focuses on the protection of CUI from unauthorized disclosure in nonfederal systems and organizations.”

This is another effort by NIST to expand the usefulness of the CSF.


NOTE: The disclaimer cell in the spread sheet is overly large, making it difficult to see the mapping cells. To be able to see a reasonable number of mapping lines, reduce the height of line 2 of the spread sheet or even hide it.

Saturday, September 10, 2016

NIST Guts Cybersecurity Framework Web Site

When I did my weekly check of the NIST Cybersecurity Framework web site today I was very disappointed to see that in making a wholesale change in the site format a large number of valuable information links were removed from the site. While the site history claims that the latest revision dates back to August 31st, I have a copy of the web page from last Saturday that includes the missing links.

The links from last Saturday’s version of the web site still work, though many of those pages today also show up in a revised format. The earlier (and now missing) information links include:

News;
Workshops;
RFIs

To make matters even worse the information provided on the newly formatted landing page is poorly written with a confusing mixture of verb tenses and a frequent lack of noun-verb agreement. I generally try not to complain about government-speak (glass houses and such), but this a truly egregious example that should not remain on the web.


Hopefully this is just a glitch in the format change process and the landing page will be done with all (or at least most) of the links being returned to the rightful place.

Tuesday, July 19, 2016

NIST Looking at CSF and Manufacturing Operations

Thanks to Joel Langill for his TWEET® pointing at a new pre-publication draft of a National Institute of Standards and Technology (NIST) document entitled “Manufacturing Profile Cybersecurity Framework”. The Executive Summary of the document describes its purpose this way:

“This document provides the Cybersecurity Framework implementation details developed for the manufacturing environment. The “Manufacturing Profile” of the Cybersecurity Framework can be used as a roadmap for reducing cybersecurity risk for manufacturers that is aligned with manufacturing sector goals and industry best practices.”

It is not clear when/if NIST intends to publish this document, but it looks like it will be a valuable addition to the documents used to help organizations implement the Cybersecurity Framework (CSF).

Manufacturing Overview


There is a brief, if somewhat simplistic, overview of manufacturing systems. It breaks manufacturing down into two broad categories; process-based and discrete-based. It then breaks the process-based manufacturing into two separate processes; continuous and batch. I call this ‘somewhat simplistic’ because many manufacturing organizations use a combination of both systems and processes.

The important missing element in the manufacturing overview is any mention of the different types of cyber-systems used in the manufacturing environment. A wide variety of industrial control systems are used in the control of manufacturing processes, inventory control, safety systems, security systems and environmental controls.

Manufacturing and Business Objectives


The section on manufacturing and business objectives lays out five main areas where cybersecurity affects the manufacturing environment:

• Maintain personnel safety;
• Maintain environmental safety;
• Maintain quality of product;
• Maintain production goals; and
• Maintain trade secrets

The document then ties these categories of cybersecurity concern back into the categories and subcategories of the CSF Core. It highlights each of the subcategories in the Core that apply to each of the manufacturing objectives listed above.

The NIST document then goes on to undertake a lengthy discussion about how risks can be categorized for each of the subcategories in the CSF Core. Then, in Section 7 (Manufacturing Profile Subcategory Guidance) of the document NIST provides detailed proposed language for evaluating the cybersecurity risk profile for the manufacturing segment of an organization. Again this is based upon the categories and subcategories of the CSF Core.

Moving Forward


This document currently stands alone on the NIST web site without any indication of how NIST intends to move forward with this draft document. I would hope that NIST will continue their proactive efforts to bring industry into the development of the various documents that support the CSF. The 28 pages of the Manufacturing Profile Subcategory Guidance is too much for a single person (even me – GRIN) to effectively review and provide suggestions for improvement.


I do think that NIST has done another remarkable job of producing a draft document for public review and comments.

Saturday, June 11, 2016

NIST Framework Update – 06-09-16

This week the National Institute of Standards and Technology (NIST) published a document summarizing the results of the workshop that they held in April on the future of the Cybersecurity Framework (CSF). The document summarizes the views expressed by workshop participants and outlines the continuing steps that NIST intends to undertake in support of the CSF.

There were seven major topic areas covered in the document with two receiving detailed discussion. The seven topics were:

• Background;
• Cybersecurity Framework Use;
• Evolution and Maintenance;
• “Best Practice” Sharing;
• Roadmap for Improving Cybersecurity;
• Update; and
• Next Steps

The first area that included a more detailed discussion was the Roadmap. Topics discussed included:

• Authentication;
• Automated Indicator Sharing;
• Assessment and Confidence Mechanisms;
• Cybersecurity Workforce;
• Federal Alignment;
• International Aspects, Impacts, and Alignment;
• Supply Chain Risk Management; and
• Technical Privacy Standards

As expected the final area to receive detailed attention was the ‘Next Steps’ portion of the document. This was divided into two sections; NIST Actions and Recommended Stakeholder Actions. The later included discussions on:

• Customizing the Framework for your sector or community;
• Publishing a sector or community Profile or relevant “crosswalk.”;
• Advocating for the Framework throughout your sector or community, with related sectors and communities;
• Publishing “summaries of use” or case studies of your Framework implementation; and
• Sharing your Framework resources with NIST.

There is no time table mentioned in the document for updating the CSF, but it is being reported (here and here) that NIST is expecting to publish an update next year. If past history is any guidance, I would expect NIST to hold a series of future workshops during the development process.

Saturday, April 2, 2016

NIST Updates Workshop Agenda

This week the National Institute of Standards and Technology (NIST) published an updated version of the draft agenda for next week’s NIST Cybersecurity Framework (CSF) Workshop. The new version provides more details about the breakout sessions where most of the work will be accomplished. It also includes more information on some of the panel discussions.

Panel Discussions


There are two of the panel discussions that may be of specific interest to readers of this blog; one on Coast Guard use of the CSF and the other on insurance and the CSF. Here is how the agenda describes these two panels:

US Coast Guard Maritime Profile Strategy – This panel will focus on the work done by the US Coast Guard and partner organizations on building security profiles, based on the Framework, to secure the bulk liquid transport sector.

Insurance – This panel will discuss the benefits to an evolving and growing insurance market of a widely used and consistent approach to understanding and   communicating cyber risks. Panelists will provide their experience with using the Cybersecurity Framework for developing and analyzing data and using the data for underwriting cyber risks.

Other News


The Workshop web page also announced this week that registration has closed for attending the Workshop in person. People that did not complete the registration process will not be allowed on the NIST campus during the workshop. NIST also announced that they would be web casting at least portions of the Workshop on the Workshop homepage starting at 08:30 EDT on April 6th.

NIST also published the ‘official’ TWITTER® hashtag for the Workshop; #NISTCSF. Those of you who already follow NIST on TWITTER (@USNISTGOV) will already have seen that hashtag in their announcements about the Workshop. It is nice to see a government agency taking a proactive use of social media and not just flooding media with meaningless sound bites

Saturday, February 27, 2016

NIST Announces New CSF Workshop

Earlier this week the National Institute of Standards and Technology (NIST) announced that they would be holding a 2-day Cybersecurity Framework (CSF) workshop starting on April 6th, 2016 at their facility in Gaithersburg, Maryland. This will be a public workshop and advanced registration is required.

While a draft agenda is available (.docx download) it is currently only vaguely general in nature. The CSF web site provides a little more detail on what the workshop will cover:

• Ways in which the Framework is being used to improve cybersecurity risk management;
• How best practices for using the Framework are being shared;
• The relative value of different parts of the Framework;
• The possible need for an update of the Framework; and
• Options for long-term governance of the Framework.


In short, it looks like the workshop will address many of the same issues that have been addressed in the latest request for information, but that should not be unexpected to anyone who followed the CSF development process. I expect that more information will be made available in the coming weeks.

Friday, February 12, 2016

NIST Publishes RFI Comment Extension Notice

As I mentioned earlier this week, today the National Institute of Standards and Technology published a notice in the Federal Register (81 FR 7506) announcing the extension of the comment period on their request for information (RFI) on updating the Cybersecurity Framework. The comment period is extended until February 23rd, 2016.

It does not appear that there were any specific requests for extension of the comment period. The notice only mentions that the comment period coincides with “a timeframe in which a variety of cybersecurity events are scheduled to occur”. While a number of cybersecurity professionals do attend many of these events, I really doubt that that is the reason for the very poor comment rate that we have seen to date.


I would like to mention again that NIST has adopted the use of a spread sheet format for submission of comments. Since I also do my own personal reviews of these comments (as my readers are certainly aware) I can attest to the fact that it is much easier to compile comments from this spread sheet format. If you have to include a long expository comment showing your erudition and mastery of the subject matter, please at least take the time to put a brief answer to the questions into the NIST response form. I know that I will only give a cursory scan to your exposition and concentrate on the concise answers in the form.

Tuesday, February 9, 2016

CSF RFI Comment Deadline Extended

I just got a form type email from NIST announcing that they are extending the comment period on their latest Cybersecurity Framework (CSF) request for information (RFI) until February 23rd. The original deadline had been today.

As I have been mentioning in my weekly updates on the comments received, there has been a particularly inadequate response to the RFI. I’m assuming that that is at least part of the reason for the comment extension. I would also assume that NIST had specifically received requests for an extension, probably citing the Christmas holidays as a reason for the low response rate.


According to the email, NIST will be publishing a notice in Friday’s Federal Register officially announcing the extension of the comment deadline.

Saturday, January 30, 2016

Responses to Latest CSF RFI – 01-30-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



As of this morning there are only one new response posted to the RFI Response site. They come from:

Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Emblem Health suggested using the CSF as the basis of any regulation noting: “If a minimum standard could be adopted that would allow health care companies to have a target that if reached would provide some guidance to the C-suite that the IT department had achieved the proper security level.”

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

Emblem Health responded that: “The framework should be continuously reviewed and updated.”

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Emblem Health suggested participation in a ‘governing committee’ would be an appropriate for private sector organizations to be involved in the future governance of the Framework.

Commentary

This week’s response was submitted using the NIST template and Emblem Health responded to nearly every question asked by NIST. The responses were short and to the point. It would be helpful to NIST if all responses were similarly prepared and targeted.


With less than two weeks left in the comment period, it is very disappointing to see only seven comments submitted to date. Hopefully we will begin seeing responses from corporate America next week.

Saturday, January 23, 2016

Responses to Latest CSF RFI – 01-23-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



As of this morning there are only one new response posted to the RFI Response site. They come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Danilo noted that existing duplications and inconsistent policies across agencies resulted from “lack of collaboration and coordination across agencies”. This could be prevented by continuing NIST process.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

Not addressed in this response.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Not addressed by this commenter.

Commentary

The response today continues the unresponsive nature of the contributions to date. While the comments certainly have merit, they continue to ignore the basic questions posed by NIST in regards to future actions to improve the CSF.


With just a little over two weeks left in the comment period, it is very disappointing to see only six comments submitted to date. Hopefully we will begin seeing responses from corporate America next week.

Saturday, January 16, 2016

Responses to Latest CSF RFI – 01-16-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:


As of this morning there are only two new responses posted to the RFI Response site. They come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Not addressed by either commenter.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

One of the commenters noted that the use of the CSF should be expanded to all small and medium businesses, even those not specifically considered ‘critical infrastructure’.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Not addressed by either commenter.

Commentary


Both responses posted today were remarkably non-contributory to the intended discussion. With the comment period over half-way completed the number of responses has been underwhelming to say the least, but that is fairly typical of the response process. The response rate should increase significantly as the deadline approaches. It takes time for organizations to develop their official responses.

Saturday, January 9, 2016

Responses to Latest CSF RFI – 01-09-16

Almost a month has gone by and we are just now seeing the National Institute of Standards and Technology (NIST) posting comments to their latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016.

As of this morning there are only three responses posted to the RFI Response site. They come from:


Comment Format

Before looking at the actual responses, I would first like to take a look at the reason that NIST has suggested that the comments to the RFI should be submitted using the provided spread sheet submission form on the RFI web site. This is a technique that NIST established in their earlier RFI submissions.

If you look at the three submissions available today, only one of them uses the spread sheet. In the first submission it is very hard to actually find the comments from Mr. Marks as he has appended them directly to the questions with no visual separation. The submission from Cybernance uses a similar format, but provides visual separation which makes the responses easy to identify and read. Finally, the Esterline submission uses the NIST spread sheet which not only makes it easy to identify and read the response, but it makes it easier for NIST to abstract the comments to a review/response database.

The whole point of responding to a request for information like this is to have one’s voice heard in the most effective manner possible. NIST has come up with a technique that makes this easier for them to evaluate the responses, and at the same time is relatively easy for the responding community to use. Not only do I think that the public should use this particular response form for replies to this RFI, but other agencies should consider employing the same technique when soliciting public comments on RFI’s and rulemakings.

Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Only one commenter addressed this question with a fairly succinct: “Form a single body for the US gov't that has a singular standard system.”

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

All three commenters generally agreed that the CSF should be updated regularly. One commenter suggested improving ability to access the referenced controls. Another suggested upgrading the ‘Profile’ section to aid charting a path forward to improving cybersecurity. The third suggested that the CSF should better reflect differences in response based upon organization size.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

All three commenters strongly supported continued involvement of the private sector. One noted that in particular organizations like the FS-ISAC (presumably including all information sharing and analysis centers) should be involved.


Friday, December 11, 2015

Another NIST CSF Request for Information

Today the National Institute for Standards and Technology (NIST) published a request for information (RFI) in the Federal Register (80 FR 76934-76936) seeking information on the “Framework for Improving Critical Infrastructure Cybersecurity” (Cybersecurity Framework – CSF). This is part of an on-going effort by NIST to improve the efficacy and employment of the CSF.
               
According to the RFI the CSF consists of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks. It was published in February 2014 after a publicly inclusive process in a series of meetings and workshops over the period of a year. A subsequent RFI was published in August of 2014 to gauge how the CSF was being put into use by the private sector.

In today’s RFI NIST is seeking specific information about the variety of ways in which the Framework is being used and the relative value of different parts of the Framework, the possible need for an update of the Framework, how best practices for using the Framework are being shared and might be enhanced, and the long-term governance of Framework. Specifically, NIST is looking for information regarding:

• Use of the CSF (9 specific questions);
• Possible CSF updates (6 specific questions);
• Sharing information using the CSF (4 specific questions); and
• Private sector involvement in the future governance of the CSF (6 specific questions)


NIST continues to use their own internal comment submission process rather than using the Federal eRulemaking Portal. NIST requests that users use their EXCEL® based template for submitting comments. This has proven a very successful technique that allows NIST to turn around the processing and cataloging of large numbers of comments in a very short time. Comments may be submitted via email to cyberframework@nist.gov. NIST is requesting that comments be submitted by February 9th, 2016. 

Friday, January 9, 2015

DOE Publishes Cybersecurity Framework Implementation Guidance

Yesterday the Department of Energy published the Energy Sector Cybersecurity Framework Implementation Guidance. This is the DOE’s approach to helping “the energy sector establish or align existing cybersecurity risk management programs to meet the objectives of the Cybersecurity Framework released by the National Institutes of Standards and Technology (NIST) in February 2014”.

I’ve had a chance to just glance through the 24 page document and it looks like it provides a pretty good summary of the Framework and looks at how the Framework can be applied to cybersecurity management under a number of DOE related security programs and processes.

The discussion about the Framework implementation using the DOE’s Cybersecurity Capability Maturity Model (C2M2) approach is quite detailed. There is a lengthy table mapping the C2M2 practices to the Framework Core and another describing how the C2M2 practices can be utilized in establishing the Framework Tier ranking.

Since DOE components have probably been looking at cybersecurity concerns longer than most any non-military agency of the US Government, it is nice to see their take on the NIST Framework. It is somewhat disheartening though that this document took almost a year to field.


BTW: Thanks to ICS-CERT for pointing at this document.

Sunday, October 5, 2014

No Responses to NIST RFI

Back in August the National Institute for Standards and Technology published a request for information about organizational experience with the Cybersecurity Framework (CSF) that was published last February. With five days left in the comment period NOT ONE RESPONSE has been posted to the NIST web site. I suppose that it could be that NIST is so overwhelmed with responses that they just haven’t had a chance to get them up on their site, but I don’t really expect that that is the case.

I suspect that while the information security press has had qualified good things to say about the CSF that it is mainly a dead issue with industry in general. We have seen no movement by the regulatory agencies that might have been able to use the CSF as a tool to help gauge cybersecurity management to publicize much less use this tool.


It is a shame. The folks at NIST, and many folks in the private sector, spent a great deal of time and effort coming up with a consensus document that is either so perfect that no one sees a need to improve it, or is so lame that nobody thinks that it is fixable. 

NOTE: Thanks to a TWEET by Aristotle Tzafalias I learned that NIST has said that they will only post the comments to their web site after the close of the comment period. Certainly an odd way of doing things, but within their prerogative. 10-16-14 04:20 CDT.

Saturday, July 26, 2014

NIST Increases CSF Usability

This week the National Institute of Standards and Technology (NIST) expanded (somewhat) the usability of the Cybersecurity Framework (CSF) as a management tool. They published the CSF Reference Tool [Zip file containing a Windows® .EXE file; there is an alternative OS® application version]; “a FileMaker runtime database solution”.

According to the NSF web site:

“The CSF Reference Tool allows the user to browse the Framework Core by functions, categories, subcategories, informative references, search for specific words, and export the current viewed data to various file types, e.g., tab-separated text file, comma-separated text file, XML, etc.”

The tool is designed to make it easier for corporate management to use the CSF as a management tool for the implementation (and tracking the implementation) of the CSF. It makes it easier for the user to search for and extract information from the CSF Core [Excel® download] and to export that data into forms and formats that can be used for various management functions.

My biggest complaint about the CSF Core applies to this tool as well. The references data should include links to the specific areas of the applicable documents or at least to the documents themselves. I understand that there are copyright issues and many of the document owners require users to buy the documents. That and many of the documents are not formatted to be linkable down to the section level.

If NIST had been given a budget for the CSF (which would have meant that Congress get involved instead of it just being based upon an Executive Order) they might have been able to negotiate link access rights from this tool to the various standards involved. Without that capability, the utility of this tool will be limited for most organizations.


OOPS – I just found some other headaches; this file is set up to run from the NIST-CSF.exe from the extracted zip file each time it is opened. It does not automatically set up an icon or even a link on the START page. Even if you pin it to your task bar, you get ‘Run’ dialog box opening up on your screen before you get to the program. When you exit the program you get another dialog box that shows up informing you that the base program, FileMaker Pro®, ‘has stopped working’. These are software issues that ruin the run ability of the program. It is really sad that the programming skills and QA skills are so low at NIST that these types of errors remain in their distributed programs. We were not allowed to have errors like this remain in our college projects twenty years ago.

Monday, April 21, 2014

Volunteer for CDCI Status

Last week I wrote about the notice published by DHS National Protection and Programs Directorate (NPPD) concerning the notifications made to organizations and facilities that have been designated Cyber Dependent Critical Infrastructure (CDCI). In that post I mentioned in passing that the request for reconsideration process outlined in that notice could be used by facilities that wished to be so designated. Today I want to look at why a facility might want to make such a request.

Program Benefits

The CDCI program is part of the President’s executive order on Improving Critical Infrastructure Cybersecurity (EO 13636) and is identified in §9 of that document. Actually, §9 only outlines the procedures for designating facilities as CDCI. The Notice published last week provides a brief listing of the positive impacts associated with the CDCI designation:

● Ability to request expedited processing through the DHS Private Sector Clearance Program, which may provide access to classified government cybersecurity threat information as appropriate;
● May be prioritized for routine and incident-driven cyber technical assistance activities offered by DHS and other agencies; and
● May receive priority in gaining access to Federal resources and programs to enhance the security and resilience of critical infrastructure against cybersecurity threats.

It is interesting to note that the Notice never uses the word ‘shall’ in the paragraph describing the positive impacts of the CDCI designation. The closest that it comes is in the final sentence:

“As Federal government resources and programs develop and improve to enhance the security and resilience of critical infrastructure against cybersecurity threats, cyber-dependent critical infrastructure will be a continued priority.”

There is nothing in the recent Notice or in §9 of the Executive Order that indicates that there are any specific requirements levied on a facility as a result of being designated as CDCI. The closest the Notice comes is a brief statement that the CDCI designees will be “encouraged to participate in the National Institute of Standards and Technology (NIST) cybersecurity framework for critical infrastructure”.

CSF Mandate

While the Administration has been very careful to talk about the voluntary nature of the cybersecurity framework (CSF) that was developed by NIST, the President made clear in the Executive Order that that there was the distinct possibility that certain organizations might be required to adopt the CSF. Specifically mentioned (but certainly not limited to) in §10(a) of the EO are the critical infrastructure identified under §9 of the order (the CDCI).

Agencies are required to determine which CDCI they currently have adequate regulatory authority to “establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure”. Where that authority does not currently exist, the EO directs the agencies to identify “any additional authority required”. The clear implication is that the implementation of the CSF will be required for identified critical infrastructure facilities.

Agencies have until May 16th, 2014, to make a determination if they currently have authority to mandate CSF implementation or make recommendations as to what additional authorities are necessary to require implementation. At this point there is no telling how long it might take to implement CSF requirements if the authority currently exists; it will depend on if a new rulemaking is required or just the publication of a notice. New authority will typically require Congressional action, which could take anywhere from years to decades to acquire.

There is also nothing that says that only CDCI will be required to implement the CSF. It will probably be easier for most regulatory agencies to require all existing critical infrastructure installations to implement the CSF than just a subset of the currently identified CI that has been selected by another agency of DHS. Either that, or agencies are going to have to come up with a separate designation process with criteria that are unique to their sector. That will just add an additional layer of complexity to the process; slowing it down even more.

Cost Benefit Analysis

Critical infrastructure facilities that have not been designated as CDCI have a choice to accept that lack of designation or request reconsideration of that decision. Such facilities will have to weigh the potential benefits vs the potential costs of the CDCI status to determine if they want to go through the reconsideration process.

Right now it looks as if the only ‘costs’ associated with the designation will be the potential requirement at some future time of implementing the CSF. For facilities that are already implementing or planning on implementing the CSF would not really a cost associated with the decision to request a positive reconsideration. Other facilities will certainly view a CSF mandate as a cost if and when the administrative processes for requiring the implementation are completed.

The other question that has to be taken into account in this cost benefit analysis is when the cost may be incurred. Since there is only a future possibility (a fairly high probability in my estimate) of a CSF implementation requirement, organizations might significantly discount that potential cost. This is particularly true because the EO calls for an annual review of the designation of CDCI; a future designation may come at a time when the potential cost is fully realized with CSF implementation regulations already in place.

Staying off the Bureaucratic Radar

There is one other downside cost that some organizations may perceive arising from the submission of a request for reconsideration; that of placing themselves on the DHS radar.  Organizations, particularly smaller organizations, that may not otherwise attract the notice of potential future regulators at DHS may want to avoid attracting the attention of Federal agencies. This is particularly true in this era of the intended increase of information sharing within the Federal bureaucracy.

On the other hand, small organizations are unlikely to have extensive in-house cybersecurity resources. Leveraging some of the assistance that may be provided by the CDCI program may give installations a significant boost in the cybersecurity realm. This may provide a competitive advantage in the market place, or at least reduce the advantage enjoyed by larger competitors with more developed internal cybersecurity capabilities.

Quick Decision
With the May 15th deadline for requesting reconsideration fast approaching, organizations are going to have to make a quick decision. Having said that; this is an annual process with a fairly high certainty that the selection criteria will almost certainly change somewhat in the next go around. Failure to file a request for reconsideration by the deadline does not mean that an organization will be kept out of the program (or be forced to remain in the program) in perpetuity.

What is not clear from last week’s Notice, however, is when the next round of designations will be made. The current list of CDCI facilities was initially provided to the President in July of last year, but it is not clear when the facilities were actually designated as CDCI. I would assume that the program was officially stood up in the last couple of months and that we should expect to see the next annual notice of the reconsideration period about this time next year.


In any case, if an organization wishes to avail themselves of the potential benefits of the CDCI program, it probably makes sense to take advantage of the current reconsideration process by submitting their request before the May 15th deadline.

Thursday, April 17, 2014

NPPD Makes CSF Notifications

The DHS National Protection and Programs Directorate (NPPD) published a notice in today’s Federal Register (79 FR 21780-21782) announcing that it had, in accordance with §9 of the President’s executive order on Improving Critical Infrastructure Cybersecurity (EO 13636), completed notification of facilities that they have been identified as “critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. The notice also outlines the procedure by which a facility can appeal that designation.

The actual list of designated facilities was submitted to the President on July 19th of last year. The facilities have been designated as “cyber-dependent critical infrastructure” and the list will be reviewed on an annual basis.

Definitions

Today’s notice provides several definitions that are important to understanding this program. They include:

Cyber incident; and

The above definitions seem to be IT system centric. For example the ‘cyber incident’ definition covers events that impair “the confidentiality, integrity, or availability of electronic information, information systems, services, or networks”. While this does not specifically exclude control systems, it certainly needs to be stretched to include them.

The definition of ‘critical infrastructure’ is taken verbatim from §2 of the EO. As I noted in an earlier blog the definition would be difficult to apply to any single production facility though national distribution networks (pipelines and the electric grid, for instance) would easily fall within the definition.

It is strange that NPPD did not use the §9(a) definition from the EO that expands coverage to facilities with potential catastrophic regional effects. This is especially true since §9(a) is the section directing DHS to prepare the list of critical infrastructure. Of course, since the list will not be publicly available, we will never really know how expansive the definition is in actual practice.

Listed Facilities

Being listed as a cyber-dependent critical infrastructure (CDCI) facility does not currently add to any regulatory burden, though adoption of the NIST Cybersecurity Framework (CSF) is encouraged. CDCI designation does provide facilities with the following perks:

● Ability to request expedited processing through the DHS Private Sector Clearance Program, which may provide access to classified government cybersecurity threat information as appropriate;
● May be prioritized for routine and incident-driven cyber technical assistance activities offered by DHS and other agencies; and
● May receive priority in gaining access to Federal resources and programs to enhance the security and resilience of critical infrastructure against cybersecurity threats.

Please note all of the permissive ‘mays’ in the descriptions. There are no guarantees provided. This is almost certainly due to the fact that this program is based upon an EO not legislative authority.

Status Appeal

The notice also provides instructions on how a facility can appeal their designation (or lack of designation) as a CDCI. The process for a request of reconsideration is actually quite simple in concept if not necessarily in actual execution. A letter or email is sent to the Under Secretary for NPPD requesting reconsideration. The request should include:

● The entity for which the reconsideration is being requested;
● The name, title, telephone number and email address of a designated point of contact, whether an employee or non-employee agent, for the owner or operator of that entity to whom all communications related to the reconsideration process will be directed; and
● If desired, a request for a meeting with DHS representatives.

After DHS confirms receipt of the initial request the process becomes less well defined as it involves the provision of information by the facility to DHS. That information will be the justification for why a facility should or should not be on the CDCI list. What the information might be and how much information will be necessary will vary considerably.

The notice does provide some very specific requirements for the formatting of information. It should be submitted by email (with certain exceptions) as a single attachment. It must be:

● Double-spaced;
● In 12 point Times New Roman text or visual material;
● Have 1” margins; and
● Have page numbers. 

The Notice specifically reminds submitters that the information provided may constitute Protected Critical Infrastructure Information (PCII) and provides a list of references about that program. Information designated as PCII (by the submitter) must be protected against disclosure by the Federal government and by anyone with whom it shares that information.

Anyone that submits information for this reconsideration process should become familiar with the PCII program as outlined in 6 CFR Part 29, and the PCII Program Procedures Manual (additional information can be found here). The single most important thing to remember is that information to be protected under the PCII program must be so designated {in a very prescribed manner, see §29.5(a)(3)} when it is submitted. If that is not done, the information is not required to be protected under the program.

The notice also reminds personnel submitting classified information that such information cannot be submitted by email.

Deadline

Facilities or organizations wishing to request a reconsideration must have their initial request submitted to NPPD by May 15th, 2014. Requests received after that date will not result in reconsideration, but may be added to the consideration process in the preparation of the next annual list of CDCI.


Once NPPD notifies a facility that there request was received, facilities will have 60-days to submit supporting information.
 
/* Use this with templates/template-twocol.html */