Showing posts with label Critical Infrastructure Protection. Show all posts
Showing posts with label Critical Infrastructure Protection. Show all posts

Tuesday, August 12, 2014

Nationalizing Cybersecurity?

Last week the Langner Group published a blog post by Perry Pederson talking about the need for nationalizing cybersecurity for critical infrastructure. Perry very clearly outlined the reasons why individual companies did not have the resources to take on nation state backed entities in the cybersecurity realm. Citing the ‘provide for the common defense’ clause {§8} in the US Constitution he argues that at some level cyber defense is purely governmental function.

In a brief twitversation I asked where the line should be drawn between national cyber defense and daily operations security and that is the topic that I would like to look at today.

National Defense

In a classical sense a nation state provides for the common defense in a couple of ways. First it maintains a military of sufficient size, equipment and training that potential adversaries are forced to decide that attacking the state would cost more than the potential benefits. Where potential adversaries are right at the border in neighboring states fortifications are constructed and manned to ensure that there will be enough delay of the enemy forces to allow the full strength of the military to rally to the defense of the point of attack while remaining prepared for attack at other points along the border.

On the other hand nation states also under take diplomacy as a means of reducing tensions with potential adversaries to lessen the need for taking up arms.

In extremis nation states conduct pre-emptive attacks on their adversaries so that they can set the time and place for armed conflict to best suit their needs and capabilities. Establishing a well understood capability to conduct pre-emptive strikes provides potential adversaries with an additional incentive to use diplomacy to address tensions that could lead to armed conflict.

Cyber Defense

Until recently cyber defense was more of a police type action against individuals rather than a military type activity against nation states. Individual owners of cyber infrastructure took minimal security protections to ensure that the common criminal had to have a minimal level of skill and ingenuity to gain access to the owner’s cyber infrastructure. In the event of a break in police were notified, rudimentary investigations were conducted, and the occasional high-profile arrest and subsequent conviction of the cyber criminal served as a deterrent of sorts to further cyber crime.

As more wealth has been moved into the cyber realm criminals have become more sophisticated in their abilities to attack that wealth. In response the owner’s capability to defend against breaches has become more complex; the law enforcement effort has become more sophisticated; and the courts’ response has become more intense.

Enemies not Criminals

Since the public discovery of Stuxnet just a little over two years ago it has become apparent that the nation state has discovered the capability of surreptitiously attacking an adversary’s critical infrastructure. Nation states have the resources to pull together a comprehensive development team to fashion and operate cyber tools and techniques to execute attacks that are practically undetectable in the short term.

The cyber attack objectives of these nation state actors may include the gathering of intelligence (spying) that has been a common tool of statecraft and warfare for millennia, gaining a political or economic advantage by destabilizing critical infrastructure in an adversarial state, stealing technological innovation to allow for economic advancement at reduced cost, or just weakening an adversary as a prelude to a physical attack.

The point that Pederson makes so clearly in 7 points is that in an unequal contest between a nation state and most private sector owners, the private sector will almost certainly loose. Now this is bad for the economy if it is just the random facility that is attacked, but nation states will be conducting targeted attacks ultimately against critical infrastructure facilities. The only other target of worthy of their effort is the military and suppliers of the military.

What does the Government Defend?

It is quite clear that the Government does not have the unlimited funds to provide for an absolute defense of all cyber assets within the country. It will have to pick and choose those cyber assets which provide some level of existential threat to the country if damaged or destroyed. This is the essential definition of ‘critical infrastructure’. A political decision will have to be made about what requires protection, what needs protections and what cannot be protected.

Since cyber operations are an integral part of the operational and management of most all critical infrastructure (I would say all but someone would come up with some off-the wall counter example to prove me wrong) does this mean that the Government will have to take complete control of an enterprise to defend it against a nation state attack? There are many people that would make that argument, but any real assessment of the situation would show that the government does not have the manpower, expertise or will to manage all aspects of the varied infrastructure that goes into providing critical support for the day-to-day operation of the country.

So the government, if it is to be even moderately successful at defending critical infrastructure against catastrophic cyber attack, is going to have to carefully pick and choose the cyber battles that it chooses to fight. To do that it is going to have to understand exactly what portions of the national infrastructure require national defense. This understanding has both strategic and tactical implications.

Under strategic considerations it must be remembered that all infrastructure is critical at some level; see the old story about the want of nail. The government (and that includes the governed) will have to prioritize the national cyber defense to what can be afforded (to spend) and what can’t be afforded (to loose). And it must be remembered that those priorities will change frequently as the economy grows and contracts and as adversaries change.

On the tactical level is not necessary to defend every inch of the cyber coastline. The national level cyber defense only requires that only those portions of critical infrastructure that pose the threat of catastrophic failure (call it Catastrophically Critical Infrastructure or CCI) if attacked on the cyber battlefield need the limited attention and resources of the Government defense. The Government will find it less expensive and more effective to respond to non-catastrophic damage to critical cyber infrastructure than to try to defend it all.

How do you defend CCI?

Once CCI are identified the planning for the cyber defense of CCI will begin by prioritizing the protection of CCI assets based upon their critical failure nodes (CFN); a CFN is any operation where a minimal change in control could cause a catastrophic incident.  The most critical failure nodes will get first attention. This will be determined by looking at the level of catastrophe that would result from the worst case failure of the node and the likelihood that a cyber attack could cause the failure of that node.

Once the CFN are identified then the cyber failure modes for those nodes would have to be identified. This would be done in a cooperative effort between the Government and the owner of the CFN; the fewer cyber protective resources available to the owner the more those resources would have to be supplied by the Government. The cost of reliance on Government resources would be the partial loss of control over the use and employment of those assets. This potential loss of control would be the incentive for business owners to develop their own cyber protective resource capability because the Government use of those resources would not necessarily align with the business interests of the owner.

For the highest risk CFN, the government would retain the ability to monitor the cyber protective resources to detect probing and attacks on those resources. The purpose of the monitoring capability would detect the early stages of a cyber attack with the intent to trace them back to their origins. Political, electronic or physical counter-attacks would then be used to dissuade adversaries from pursuing their attacks.

The Government would also share information about attacks against CFN with other CFN defenders so that they could use that information to improve the defenses of their cyber assets.

Protecting the Rest of Critical Infrastructure

While the Government has the highest level of interest in protecting CFN, the protection of all critical infrastructure is of legitimate concern to the Government. Instead of the Government taking an active role in the defense of non-CCI facilities, the Government would require the identification and minimum protection of CFN at non-CCI facilities. It would also require reporting of all attempts to compromise those protections, which the Government would then investigate and take appropriate actions against the perpetrators.

The protection of all non-catastrophic failure nodes would be the sole responsibility of the owner of the facility. Owners most Government regulated facilities would be required to report detected cyber attacks to a Government agency that would then investigate those suspected attacks with the view towards identifying the perpetrators and the techniques that they used.

Broad Outline

This is, of course, only the broad outline of how the Government could address the protection of critical infrastructure against cyber attacks. As it becomes more and more obvious that nation states are undertaking cyber operations against their adversaries, it becomes clearer that the Government needs to be actively involved in the defense of the most critical infrastructure from such operations.


Serious discussion needs to begin on how this type of defense of private sector facilities can be best implemented.

Monday, July 28, 2014

House Passes Four Homeland Security Bills

As I noted this morning the House addressed a number of bills today under suspension of the rules. Four of them were mentioned as being of probably interest to readers of this blog:

HR 2952 - The Critical Infrastructure Research and Development Act;
HR 3107 - The Homeland Security Cybersecurity Boots-on-the-Ground Act;
HR 3202 - The Essential Transportation Worker Identification Credential Assessment Act; and
HR 3696 - The National Cybersecurity and Critical Infrastructure Protection Act.

All four bills, as expected, passed with impressive bipartisan support. Two of the bills (HR 2952 and HR 3696) passed by voice votes. The other two bills passed in voice votes; HR 3107 (395 to 8) and HR 3202 (400 to 0). Interestingly, HR 3107 was incorporated into HR 3696 before the bill was reported by the Homeland Security Committee.


I suspect the four bills could also garner similar bipartisan support in the Senate. There is a possible problem for HR 3696. This bill is as close at things will get in the near future to being a comprehensive cybersecurity bill. ‘Comprehensive bills’ have been routinely held up by Sen. Reid (D,NV) as the various affected committees in the Senate tried to craft their own bills. I suspect that Reid will do the same for this bill as the leadership tries to craft a deal to pass S 2588, the Cybersecurity Information Sharing Act of 2014. It is not really a competing bill, but Reid seems to figure that he can only pass one significant cybersecurity bill each session.

Tuesday, December 24, 2013

White House Issues Twin Policy Documents

As the sixth year of the Obama Administration quickly approaches, the White House has issued two high-level homeland security policy document that are designed to shape future of programs of the Federal Government. These two documents (in order of release) are the National Strategy for Information Sharing and Safeguarding (NSISS) and the National Infrastructure Protection Plan (NIPP). Neither of these documents has any specific regulatory force, yet they are both intended to help shape the direction of a wide range of regulatory programs within the Federal government.

NISS

This strategy is designed to address the conflicts in the twin nature of information. First information must be shared to have any effect on the real world and second information shared is likely to be released to someone who should not get the information. Finding the proper balance between these two aspects of information policy is never easy.

The NISS starts out with a discussion of the current operating environment in which information collection and sharing takes place. It then establishes three Core Principals that define the Administration’s approach to information sharing (pgs 6-7):

• Information as a National Asset
• Information Sharing and Safeguarding Requires Shared Risk Management
• Information Informs Decisionmaking

With those motherhood and apple pie principals in place, the NISS outlines five goals in some depth. The listed goals are (pgs 8-13):

• Drive Collective Action through Collaboration and Accountability.
• Improve Information Discovery and Access through Common Standards.
• Optimize Mission Effectiveness through Shared Services and Interoperability.
• Strengthen Information Safeguarding through Structural Reform, Policy, and Technical Solutions.
• Protect Privacy, Civil Rights, and Civil Liberties through Consistency and Compliance.

Finally the document lists sixteen information sharing objectives with five being given the title of Priority Objectives. Those Priority Objectives are (pg 14):

• Align information sharing and safeguarding governance to foster better decisionmaking, performance, accountability, and implementation of the Strategy’s goals.
• Develop guidelines for information sharing and safeguarding agreements to address common
requirements, including privacy, civil rights, and civil liberties, while still allowing flexibility to
meet mission needs.
• Adopt metadata standards to facilitate federated discovery, access, correlation, and monitoring
across Federal networks and security domains.
• Extend and implement the FICAM [Federal Identity Credential and Access Management] Roadmap [Link] across all security domains,
• Implement removable media policies, processes and controls; provide timely audit capabilities of assets, vulnerabilities, and threats; establish programs, processes and techniques to deter, detect and disrupt insider threats; and share the management of risks, to enhance unclassified and classified information safeguarding efforts.


NIPP

The 2013 NIPP is an update of the 2009 document that I found negatively stimulating. The newer document reads better, but it still doesn’t really say much.

It starts out with the standard corporate vision-mission-goal statement (pg 5):

Vision Statement - A Nation in which physical and cyber critical infrastructure remain secure and resilient, with vulnerabilities reduced, consequences minimized, threats identified and disrupted, and response and recovery hastened.

Mission Statement – Strengthen the security and resilience of the Nation’s critical infrastructure by managing physical and cyber risks through the collaborative and integrated efforts of the critical infrastructure community.

Goals:

• Assess and analyze threats to, vulnerabilities of, and consequences to critical infrastructure to inform risk management activities;
• Secure critical infrastructure against human, physical, and cyber threats through sustainable efforts to reduce risk, while accounting for the costs and benefits of security investments;
• Enhance critical infrastructure resilience by minimizing the adverse consequences of incidents through advance planning and
mitigation efforts, as well as effective responses to save lives and ensure the rapid recovery of essential services;
• Share actionable and relevant information across the critical infrastructure community to build awareness and enable risk informed decision making; and
• Promote learning and adaptation during and after exercises and incidents.

There is an interesting, if broadly painted, discussion of the risk environment (pg 8) with the a summary of the information provided in figure 2, a graphic representation of the ‘evolving threats to critical infrastructure’. They are categorized as:

• Extreme weather
• Accidents or technical failures
• Cyber threats
• Acts of terrorism
• Pandemics

Interestingly there is a wide degree of overlap between the middle three categories that is not mentioned in the NIPP discussion. There is, however, one interesting risk that is tossed off at the end of this discussion that is then promptly ignored in the rest of the document; “vulnerabilities may exist as a result of a retiring workforce or lack of skilled labor”. Add in ‘reductions in force’ and you have an interesting topic for a whole series of discussions.

Then it provides a set of motherhood and apple pie statements (this time called ‘Core Tenets’; pgs 13-14) that will guide the remaining discussion of critical infrastructure protection:

• Risk should be identified and managed in a coordinated and comprehensive way across the critical infrastructure community to enable the effective allocation of security and resilience resources.
• Understanding and addressing risks from cross-sector dependencies and interdependencies is essential to enhancing critical infrastructure security and resilience.
• Gaining knowledge of infrastructure risk and interdependencies requires information sharing across the critical infrastructure community.
• The partnership approach to critical infrastructure security and resilience recognizes the unique perspectives and comparative advantages of the diverse critical infrastructure community.
• Regional and SLTT partnerships are crucial to developing shared perspectives on gaps and actions to improve critical infrastructure security and resilience.
• Infrastructure critical to the United States transcends national boundaries, requiring cross-border collaboration, mutual assistance, and other cooperative agreements.
• Security and resilience should be considered during the design of assets, systems, and networks.

The NIPP then goes into a lengthy discussion (pgs 15-20) of the iterative risk management framework that weaves together three elements of critical infrastructure; physical, cyber and human. It outlines five steps in the repetitive process:

• Set Infrastructure Goals and Objectives
• Identify Infrastructure
• Assess and Analyze Risks
• Implement Risk Management Activities
• Measure Effectiveness

It then goes on to describe 12 separate ‘Calls to Action’ that “will inform and guide efforts identified via the priority-setting and joint planning processes. They fall into three easily remembered categories:

• Build upon Partnership Efforts
• Innovate in Managing Risk
• Focus on Outcomes

Probably the most useful part of this document can be found in descriptions of the various organizations that have been established to aid in the critical infrastructure coordination process. This is found in Appendix A and includes:

• Sector Coordinating Councils
• Government Coordinating Councils
• Sector-Specific Agencies
• Critical Infrastructure Cross-Sector Council
• Federal Senior Leadership Council (FSLC)
• State, Local, Tribal, and Territorial Government Coordinating Council (SLTTGCC)
• Regional Consortium Coordinating Council (RC3)
• ISACs
• Critical Infrastructure Partnership Advisory Council
• NICC and NCCIC
• NOC
• NCIJTF

The Real Effect


There is nothing really new or earthshaking here, as one would expect from policy documents issued at the end of the fifth year of an Administration. How much effect this will have on future actions by the Federal government will depend more on who wins control of the Senate next November than how well the Administration writes regulations reflecting these goals in the next two years.

Thursday, September 19, 2013

DHS Announces CIPAC Meeting – 11-5-13

The DHS National Protection and Programs Directorate (NPPD) published a meeting notice in today’s Federal Register (78 FR 57644) for a meeting of the Critical Infrastructure Partnership Advisory Council (CIPAC) in Washington, DC on November 5th, 2013. The meeting will be open to the public.

The notice provides only a very sketchy agenda, noting that CIPAC topics will include:

• Executive Order for Improving Critical Infrastructure Cybersecurity;
• Presidential Policy Directive 21—Critical Infrastructure Security and Resilience; and
• Critical Infrastructure Program Updates

Public participation is being solicited by DHS. There will be a limited period for oral comments from the public at the end of the meeting. Such comments will be limited to matters involving critical infrastructure security and resiliency. The limited comment time will require first come first serve registration at the meeting site. Written comments will be accepted and should be received by CIPAC by September 24th. Written comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2103-0050).


BTW: Once again DHS fails to provide web coverage of a public advisory committee meeting.

Monday, February 21, 2011

S 413 Introduced – Cyber Security

Last Thursday Senators Lieberman (D, CT), Collins (R, ME) and Carper (D, DE) introduced S 413, the Cybersecurity and Internet Freedom Act of 2011. This bill would establish the Office of Cyberspace Policy (OCP) in the White House and the National Center for Cybersecurity and Communications (NCCC) in DHS. The OCP Director would have cyber security budget approval authority and the NCCC Director would have regulatory authority over cybersecurity activities within the Federal Government.

While this bill is mainly directed at “information infrastructure” there is one section in Title II that addresses cyber risks to covered critical infrastructure (§248) that very carefully never specifically limits its application to ‘information’ systems. That section requires the Director of the NCCC to “issue interim final regulations establishing risk-based security performance requirements to secure covered critical infrastructure against cyber risks through the adoption of security measures that satisfy the security performance requirements identified by the Director” {§248(b)(1)} within 270 days of passage of this bill.

Generally speaking the wording of this section looks like the crafters intend for establishment of a regulatory scheme similar in construction and operation to the CFATS regulations for high-risk chemical facilities. This nine page section of the bill certainly deserves a more detailed look in future blogs.

According to a press release on the Homeland Security and Governmental Affairs Committee web site, there “is no so-called ‘kill switch’ in our legislation because the very notion is antithetical to our goal of providing precise and targeted authorities to the President”. In fact, §2(c) specifically says that under this legislation “neither the President, the Director of the National Center for Cybersecurity and Communications, or any officer or employee of the United States Government shall have the authority to shut down the Internet”. This kill-switch issue stalled the earlier version of this bill in the last session. Hopefully this bill will now have a chance to move forward in the legislative process.

BTW: The official GPO version of this bill is not yet available. Sen. Lieberman has made a copy of the bill available via a link on the Senate Homeland Security Committee web site.

Tuesday, December 28, 2010

DHS Updates Critical Infrastructure Protection Website

Today the DHS Office of Infrastructure Protection (OIP) updated the landing page for Critical Infrastructure Protection. This is part of their information sharing effort as part of the President’s proclamation of December as Critical Infrastructure Protection Month. There are links to four pages that have been revised/updated with new information on critical infrastructure protection. They are:


Bombing Prevention Training
Information Sharing for Critical Infrastructure Protection and Resilience
Information Sharing: A Vital Resource for a Shared National Mission to Protect Critical Infrastructure
More About the Office of Infrastructure Protection
Regional Directors and Protective Security Advisors

This page used to just refer to Protective Security Advisors and I briefly addressed their duties last spring. The first change to this page deals with the title and that it now explains that Regional Directors are “Supervisory PSAs”. I’m not sure if these are new positions or if they were just overlooked in the earlier version of this page. The total number of field operatives, 93, has not changed since the earlier version of the page was posted.

This page does note that the PSA’s are responsible for three program areas and provides a brief description of the these responsibilities. They are:

● Enhancing Infrastructure Protection
● Assisting with Incident Management
● Facilitating Information Sharing
The information sharing portion of this page does provide a new section on ‘Strengthening Regional Resilience’. This is keeping in-line with the Departments increased focus on ‘Resilience’. The most important part of this new section is the link to the two new pages on ‘Information Sharing’ that I discuss below.

Bombing Prevention Training

The only change to this page is that it now references ‘Regional Directors and Protective Security Advisors’ instead of just ‘Protective Security Advisors’.

Information Sharing

The first of these two pages that focus on information sharing provides an overview type description of the various players in the field of ‘Infrastructure Protection’ with some links to more information. Of interest to the chemical security community is the brief description of the ‘Chemical Facility Inspectors’ (CFI). The ‘additional information’ link provided for there does not pertain much to the CFI, but to the CFATS program in general. It would be nice to see a more detailed page of information about the CFI program (organization, training, etc).

The second page on information sharing has a great deal more information and many more links to other programs. The most valuable part of this page can be found in the last section, “Tools to Support Information Sharing”. This section provides links to a number of important information sharing sites, including:

● Homeland Security Information Network-Critical Sectors (HSIN-CS)
● Homeland Infrastructure Threat & Risk Analysis Center (HITRAC)
● National Infrastructure Coordinating Center (NICC).
● DHS Daily Open Source Infrastructure Report
● Office of the Director of National Intelligence
More About the Office of Infrastructure Protection

This page provides information on the operation of the OIP. It has been completely reworked, providing more links to web pages describing the groups that work within the OIP. A great deal of additional information has been provided through this page.

Monday, December 6, 2010

NIPP Page Updates 12-02-10

As part of the President’s declared Critical Infrastructure Protection Month, DHS has promised to provide new information about CIP through links on their Critical Infrastructure landing page. Last week they ‘updated/reviewed’ the information on two pages that are linked from that page, the National Infrastructure Protection Plan page and the Critical Infrastructure and Key Resources Support Annex page.

I don’t track the CIKRSA page, but I don’t see anything that looks really new on the page (though it is dated as being 'reviewed/updated on 12-02-10). The NIPP page is another page that I don’t track as closely as the chemical security pages on the DHS site, but I do note some changes since I last looked at the page in August. They have added a brief video about the NIPP, a link to subscribe to the NIPP Newsletter (this link has been on the landing page since August), and a new link to an established (and unchanged) page on NIPP Resources for State and Local Partners.

The changes on the NIPP page don’t really provide any new information, but they do make it easier to find some of the information and the video does provide an easier method to learn about the NIPP. So, I suppose this update is a net positive.

Friday, July 2, 2010

Misc DHS Web Page Updates 07-02-01

Over the last 24 hours or so there have been a number of DHS web pages updated that might be of interest to the chemical security community. One major change was made to the DHS CSAT FAQ page, but I will cover that in a separate blog post because of the extent and importance of that change. The changes that I will address here are less extensive. Those changes were made to the following web sites:
Private Sector Office web page, updated 07-01-10 Critical Infrastructure Protection landing page, updated 07-02-10 Control Systems Security Program web page, updated 07-02-10
Private Sector Office DHS added a new link on this web page for the Voluntary Private Sector Preparedness Accreditation and Certification Program (PS-Prep). This is a new program recently announced by Secretary Napolitano to provide a voluntary certification program for private sector efforts to ensure resiliency and enhance their ability to respond to natural or man-made disasters. There isn’t much information on this page yet beyond links to the three certification programs:
● ASIS International SPC.1-2009, Organizational Resilience; ● British Standards Institution 25999 (2007 Edition), Business Continuity Management; and ● National Fire Protection Association 1600; Standard on Disaster / Emergency Management and Business Continuity Programs
Critical Infrastructure Protection DHS added a new link on this page to subscribe to the ‘NIPP Newsletter’. No information was provided on the newsletter. Signing up will allow DHS to send you a copy of the newsletter. When I get my first issue I’ll let you know what it is all about. Control Systems Security Program DHS added a new link on this page to a new publication by the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT). This two-page publication, Incident Handling: Preparing for Incident Analysis, provides guidance on “recommended practices for developing incident response capabilities necessary to collect data and perform follow-on actions to restore your systems to normal operations” (pg 1).
 
/* Use this with templates/template-twocol.html */