Showing posts with label Critical Infrastructure. Show all posts
Showing posts with label Critical Infrastructure. Show all posts

Friday, February 12, 2016

The Actual Drone CI Provision

The information that I received yesterday for last night’s post about drones and critical infrastructure facilities was not as complete as it could have been and as a result I made a small leap to the wrong amendments. While the two amendments that I reported on were submitted for consideration, they were not taken up by the Committee. Instead, Chairman Schuster’s (R,PA) Manager’s Amendment does contain similar language and was adopted by the Committee.

The Schuster amendment still adds a new 49 USC 45509 that adds the requirement I described yesterday for new regulations from the FAA. There is no requirement for covered facilities to register in order to have the regulations apply like we saw in Babin #81.

The very real difference between the adopted Shuster language and the two Babin amendments that I described last night can be found in the definition of critical infrastructure. The Schuster amendment’s definition {§45509(c)} only includes CFATS facilities and MTSA facilities. It does not include water treatment plants, waste water treatment facilities, DOD/DOE owned facilities or NRC regulated facilities.

Moving Forward

HR 4441 was approved in Committee yesterday on a near party line vote. In fact, there were two Republicans that voted against the bill. This means that the bill probably would not pass if it was brought to the floor under suspension of the rules which requires a 2/3rds vote to pass. This means that it would require a rule which would leave open the possibility of further amendments on the floor.

The unanimous Democratic opposition to the bill means that this version of the bill would almost certainly not get considered in the Senate. We are likely, therefore, to see another version of the bill with more bipartisan support introduced and voted upon in the Senate. The House could then either accept the Senate language or demand that a conference committee work out the differences in the two bills. In the 114th Congress there has been a pretty even split between the two options.

There was no recorded vote on the Schuster amendment (not unusual) so it is hard to tell whether there is any substantial opposition to this provision which was a relatively minor part of that amendment. I suspect that there was significant opposition to the Babin amendments and that the Schuster language was offered as an acceptable substitute. This might mean that the Schuster language could end up in any conference reported bill.

Commentary

My comments from last night still stand except that the even further limiting of the drone regulations to just CFATS and MTSA covered facilities is even more inexplicable than was the lack of coverage in the Babin amendments for the electric grid and gas distribution lines. The only thing that I can figure is that including the water facilities would have required involving the EPA oversight committees and that was fraught with problems. There has been a general disinterest in Congress in requiring any real security of water treatment facilities. This is probably due to the fact that most of the facilities are owned by local governments that generally have little interest in spending money on real security measures.

DOT/DOE and NRC regulated facilities are already typically listed as flight restricted zones so that technically flying drones over them is already illegal. Raising the issue in this forum would just add ways for the bill to acquire more opposition.


It will be interesting to see if the industrial backers of this language can convince the Senate Commerce, Transportation and Infrastructure Committee to include it in their version of this bill.

Wednesday, October 28, 2015

Senate Passes S 754 – CISA

As everyone is probably already aware the Senate yesterday passed an amended S 754 by a substantially bipartisan vote of 74 to 21. The bill will now go to a conference committee where the differences between this bill and HR 1560 that was passed in the House in April.

Control System Security Issues

The revised bill does contain two provisions that have specific implications for control system security. First the information sharing provisions of the bill do apply to control systems as the definition of ‘information system’ in §102(10) specifically “includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers”.

Second, as I reported earlier, §407 of the bill would require DHS to report to Congress on the extent that critical infrastructure is currently required to report cyber intrusions or incidents involving cybersecurity incidents that “could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. DHS would also be required to suggest to Congress additional statutory authority that would be required to allow the department to put into effect “a strategy that addresses each of the covered [critical infrastructure] entities, to ensure that, to the greatest extent feasible, a cyber security incident affecting such entity would no longer reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” {§407(c)(1)}.

The Whitehouse amendment (revised amendment #2626) that I described in my earlier post was not considered by the Senate. This amendment and Mikulski #257 were objected to by Sen. Burr (R,NC; Chair of the Senate Intelligence Committee and co-author of S 754) as not being “germane to amendment No. 2716.” { CREC-2015-10-27-pt1-PgS7503). Readers might remember that the Whitehouse amendment would have made it a federal criminal offense to damage to a critical infrastructure computer during the commission of computer fraud.

Moving Forward

With the House and Senate bills headed to conference in the coming weeks, there is no telling exactly when the resulting bill will come back for votes in the House and Senate. It is also not yet clear which bill number will be the vessel for that vote. It is apparent, however, that we will have an information sharing bill sent to the President in the not too distant future (probably before the end of the year).

Commentary

I think that I have to agree with Jack Whitsitt’s view of the effectiveness of the information sharing provisions of this bill; it is not going to be a game changer by any stretch of the imagination. Nor do I subscribe to the dystopian view that this bill specifically furthers the government invasion of privacy evidenced in the NSA revelations of the last couple of years. It will, however, relieve Congress from any further requirement in the near term to craft ‘comprehensive cybersecurity legislation’.

I think what we will see from Congress is a continuation of the trend that I have mentioned here a couple of times of including relatively minor cybersecurity language in bills dealing with technology issues or general security issues. This will, in my opinion, be a much more effective (if piecemeal) way of dealing with cybersecurity issues in general and control system security issues specifically.

As Congress routinely addresses technical issues in automotive safety, intelligent transportation systems, medical devices, the smart grid and aircraft safety (to name a few specific areas) legitimate attention will also have to be directed at the security of the electronic systems that form the control basis for those systems. Integrating control system security into those larger issues is where important legislative work needs to be done.

The one area, however, that still needs major legislative attention is the protection of control systems where failure or an attack could have significant impact on a large segment of society. Section 407 of the bill that was passed yesterday was an important step in identifying those control systems that need to be protected.

I think that the time frame requirements in that section are way too short for effective analysis. This means that some truly critical systems are sure to be missed and some not so critical systems will be included. But, it is an important first step.

The control system security community, meanwhile, needs to start thinking seriously about how we want to see meaningful legislation crafted to deal with the control system vulnerabilities in these critical facilities. We need to figure out how to craft rules that won’t be technically obsolete by the time that they are published. We need to figure out how regulate control system security without stifling the creative expansion of control system capabilities.


We need to do it because Congress does not (and never will have) the technological skills and comprehension to do it on their own. If we leave this to them we will either have systems so complicated that future changes in automation technology will be fatally handicapped; or so weak that there will be no protection of critical infrastructure control systems at all. Congress is not equipped to find the technological middle ground; we are.

Tuesday, September 15, 2015

OIRA Approves DOD Cyber Intrusion Reporting Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) approved an interim final rule for the DOD concerning contractorreporting requirements for certain cyber intrusions. This rule was required by Congress in 2012 as part of the Defense Authorization Act of 2013 (§941; PL 112-239). The rule is likely to be published in the Federal Register later this week.

Commentary

It will be interesting to see if the procedures that DOD develops for a relatively selected group of non-governmental networks could be adopted for critical systems at all critical infrastructure facilities. I think that the government (and the public) has a specific and legitimate interest in attacks on critical infrastructure cyber-physical systems that could have a significant impact on the public.


The requirements of §941 focused principally on information compromise rather than cyber-physical systems and it would probably be inappropriate to require reporting on purely information related incidents (other than those involving significant amounts PII, of course; but those would be covered by separate requirements). This would mean that adaptations of the DOD rule would certainly be required, but the actual reporting process (other than to whom the reports would be sent) should be fairly easy to adapt to a cyber-physical incident reporting system.

Friday, April 17, 2015

S 902 Introduced – CI Trespassing

Last month Sen. Schumer (D,NY) introduced S 902, a bill that would make it a federal offense to trespass on critical infrastructure. This bill is identical to S 2934 that was introduced near the end of the last session without any action. In press release last November Schumer made it clear that it was targeting people who trespassed on New York bridges as publicity stunts or climbed the World Trade Center.

The bill would amend 18 USC Chapter 65, Malicious Mischief, by adding §1370. It uses a fairly conventional definition of ‘critical infrastructure’ and specifically adds ‘landmarks, structures and other objects’ declared to be a national monument {§1370(a)(2)}.

The bill would then make it a federal offense to “knowingly go on any critical infrastructure used in or affecting interstate commerce, with intent to commit a criminal offense” {§1370(b)}. Violation of this new section would be punishable by fines (limit not specifically set) and/or imprisonment for not more than five years.

Senator Schumer is a mover and shaker in the Senate and may have the pull to try to get this considered. I would not expect much opposition form many Republicans, who tend to be law and order types. Most of the opposition would be from Democrats concerned about stifling free speech.

Commentary

The simple act of trespass has a long history in the United States as being a component of free speech and political expression. A group of like-minded activists would move from a public space into a fringe area of a private space, or interfere with movement in a public space to attract the attention of the news media. Speeches would be made and the police would move in to break up the demonstration by arresting the participants for trespass. Since this is normally a misdemeanor, the protestors would be back on the street shortly and would return to their day jobs.

Allowing this type of simple political expression to be turned into a federal offense would severely inhibit this form of protest.

Having said that, there are certainly other forms of trespass on critical infrastructure facilities that are not mere political statements, but precursors for taking more violent action against those facilities. Most terrorist attacks are preceded by some form of physical surveillance. When that surveillance takes the form of trespass on the facility it would certainly be nice to have some federal statute to prosecute that form of trespass under instead of a typical misdemeanor trespass charge.


But then again, I don’t know how you would word the statute so as to allow non-violent political statements to be excluded and still deal with those suspected of planning some sort of violent attack. Unfortunately, this bill does not even attempt to make the distinction since it is specifically targeting protestors that would hang a Palestinian flag from the Brooklyn Bridge not violent terrorists.

Tuesday, November 18, 2014

Bills Introduced – 11-17-14

Both the House and Senate are back in town for week two of the lame duck session. Seventeen bills were introduced yesterday including one that may be of specific interest to readers of this blog:

S 2934 - A bill to prohibit trespassing on critical infrastructure used in or affecting interstate commerce to commit a criminal offense. Sponsor Sen. Schumer, Charles E. [D-NY].

This bill was publicized by Schumer during the election hiatus as a bill targeted at preventing the recent spate of publicity stunts involving bridges and other landmarks in New York City. We will have to wait to see what the bill actually says to be sure, but this sounds like an attempt to stifle free speech. Having said that, this could be used as a tool to federally prosecute recon actions that would be a precursor to a terrorist attack; details will make the difference.


NOTE: This bill has little chance of being considered in the lame duck session. It will be interesting to see if/when it is re-introduced in the 114th Congress.

Monday, February 10, 2014

HR 3990 Introduced – Cybersecurity

As I noted last week Rep. Shea-Porter (D,NH) introduced HR 3990, the Personal Data Privacy and Security Act of 2014. This is a companion bill to S 1897 introduced by Sen. Leahy (D,NH). The bill deals mainly with the protection of personally identifiable information, but it does contain one section (§109) that makes it a criminal act to damage critical infrastructure computers, including control system computers. Different versions of this section have been found in other bills as well (HR 1468 for instance).


There is one oddity in the Leahy-Shea-Porter version of the bill; the definition of critical infrastructure includes “electrical power delivery systems;” while other versions expand on that to include “electrical power generation and delivery systems;”. This ‘oddity’ should be corrected in committee markup.

Wednesday, October 30, 2013

Homeland Security Mark-up Hearing Results

Yesterday the House Homeland Security Committee held their markup hearing looking at six different bills including (of potential interest here) HR 1204, HR 1791, HR 2952, and HR 3107. All six bills were ordered to be reported favorably; some with amendments (including HR 1204, HR 2952, and HR 3107).

The Committee provides a nice summary of the amendments, but none of them were significant. The closest to being a meaningful change was the amendment from Rep. Horsford (D,NV) that changed one of the subcommittee names of the new Aviation Security Advisory Committee from the “Perimeter Security Subcommittee” to the “Perimeter Security, Exit Lane Security , and Access Control Subcommittee”.

Actually ‘access control’ was already one of the topics that this subcommittee was to cover, so it only added ‘Exit Lane Security’. This topic is already a big deal in the airport security community so this just gave ‘Exit Lane Security’ a specific home.


Of course, any time a House Committee can do the markup of six bills in a single hearing, we know that there are not going to be any controversial or substantive changes made to any of the bills.

Friday, August 2, 2013

Bills Introduced – 8-1-13

On the next to last day of the session before the summer recess it was a busy day for the introduction of legislation; 70 bills in the Senate and 86 bills in the House. The following may be of specific interest to the chemical security/safety and cybersecurity communities:

S 1429 Latest Title: An original bill making appropriations for the Department of Defense for the fiscal year ending September 30, 2014, and for other purposes. Sponsor: Sen Durbin, Richard (D,IL)

S 1435 Latest Title: A bill to amend title 49, United States Code, to provide certain port authorities, and for other purposes. Sponsor: Sen Gillibrand, Kirsten E. (D,NY)

S 1462 Latest Title: A bill to extend the positive train control system implementation deadline, and for other purposes. Sponsor: Sen Thune, John [SD]

S 1464 Latest Title: A bill to facilitate and enhance the declassification of information that merits declassification, and for other purposes. Sponsor: Sen Shaheen, Jeanne [NH]

HR 2952 Latest Title: To amend the Homeland Security Act of 2002 to make certain improvements in the laws relating to the advancement of security technologies for critical infrastructure protection, and for other purposes.Sponsor: Rep Meehan, Patrick (R,PA)


HR 2958 Latest Title: To amend title 49, United States Code, to provide certain port authorities, and for other purposes.Sponsor: Rep Nadler, Jerrold (D,NY)

Wednesday, February 13, 2013

Cybersecurity Executive Order


Well, President Obama finally signed the long promised Cybersecurity Executive Order. We don’t have an EO number yet, that will come in the next day or two when the EO is published in the Federal Register. In any case, what is posted on the White House web site is certainly good enough for us to start seeing what practical effect this EO will have on cybersecurity.

The Policy

We couldn’t even get started on this without looking at the basic policy statement included in §1:

“It is the policy of the United States to enhance the security and resilience of the Nation's critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties.”

While this policy is supposed to be focused on ‘critical infrastructure’ it is clear that the focus of the cybersecurity effort is on information security. Control systems are addressed in passing (a single mention, safety, is specifically targeted at physical systems), but it is clear that this is mainly an IT policy.

Critical Infrastructure

Since this EO is targeted on protecting the cybersecurity of critical infrastructure it is important to understand what that term means. First in §2 we see a basic definition of the term:

“As used in this order, the term critical infrastructure means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

The way this definition is constructed it is difficult to see any single facility or company that would qualify as ‘critical infrastructure’. This definition would only seem to apply to networks or organizations. For example, only the incapacity or destruction of the electric transmission network, the gasoline pipeline network or the financial network would have a truly debilitating impact on the ‘national economic security’ or ‘national public health’. It is hard to see how the destruction or incapacity of any single entity would meet the definition.

This definition is expanded somewhat in §9(a) where the Secretary of DHS is required to identify “critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional [emphasis added] or national effects on public health or safety, economic security, or national security”. The addition of a lower ‘regional’ impact standard will increase slightly the number of affected facilities. It would probably stretch to include major oil refineries for instance or regional power companies.

Now all of this certainly depends on how you define ‘debilitating impact’; a term carefully left undefined in this EO. The more broadly you define ‘debilitating’ the more inclusive the term ‘critical infrastructure’ becomes. Water it down enough and everything is critical infrastructure.

Information Sharing

The one thing that should be relatively easy to implement in this EO would be the information sharing provisions of §4. It shouldn’t take an EO, however, for the President to direct the intelligence agencies to produce unclassified reports on cybersecurity threats as is outlined in §4(a). The expansion of the sharing of classified intelligence as outline in §4(c) will be slow as the private sector will be slow to adopt the necessary security mechanisms required to handle classified documents.

The Cybersecurity Framework

Since there is no Congressional mandate or authority for the regulation of cybersecurity, the President has studiously avoided the use of the word ‘regulation’. Instead he has required the Director of the National Institute of Standards (NIST) to lead the development of “a framework to reduce cyber risks to critical infrastructure”. To ensure that everyone understands that these non-regulation are intended to behave like regulations, §7(a) goes on to explain that the framework “shall include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks”.

The semi-regulatory nature of the framework is further reinforced by the requirement in §7(d) that the Director shall “engage in an open public review and comment process”; the same type review process that is used for writing or revising regulations.

The one area where this EO has certainly taken an extreme leap of faith has been in the time frame set forth for the development of the Cybersecurity Framework. Section 7(e) of the order provides the Director 240 day to publish a preliminary version of the framework. Depending on how much of the work of developing the framework has already been done by NIST (and I would bet that they have been hard at work on this while the EO was being developed) this might actually be doable.

It will be nearly impossible, however, to have the final version of the framework published 125 days later (within one year of the official publication of this EO). This is because of the need to complete the comment and review process promised in §7(d). Anything less than a 90 day comment period will certainly end up in court and it will take a minimum of at least another 90 days for NIST to process and formulate responses to the huge number of comments that will inevitably result.

Since these are supposed to be consensus standards formulated in consultation with rest of the federal government, I will be very surprised if the draft version of the framework can be published within the one year time frame and it could be 2016 before the OMB approves the final version. And the OMB will be intimately involved in the publication of this document; see §12(b).

Voluntary Adoption of Framework

Section 8 of the EO clearly makes adoption of the framework by the private sector voluntary and there will be incentives developed {§8(d)} even before the draft framework is completed to encourage that voluntary participation in the program. The most important incentive is outlined in §8(e) where an attempt will be made (almost certainly successfully) to require adoption of the standards as part of the federal acquisition process. That is a fairly big carrot/stick that could be wielded far beyond the broadest possible definition of ‘critical infrastructure’.

The portion of the EO that will cause the most problems for the private sector is to be found in §10 where it spells out how agencies “with responsibility for regulating the security of critical infrastructure” will try to find existing authorities to require the implementation of the framework within the regulated community. Those agencies have 90 days from the publication of the preliminary framework to identify:

• If agency has clear authority to establish requirements based upon the Cybersecurity Framework to sufficiently address current and projected cyber risks to critical infrastructure;
• The existing authorities identified, and
• Any additional authority required.

It is likely that some agencies will be able to begin implementation of the framework requirements before the final framework is approved in the comment and response process. Even where clear authority exists, though, it will take regulatory changes (with the required comment and review process) to fully implement the final framework provisions.

The Legislative Process

 The one thing that this EO will certainly do is to aggravate the legislative process for the adoption of cybersecurity measures by Congress. The Republican controlled House is certain to start work on bills to limit the authority of the President to implement the framework even before the initial version is published. Those challenges will focus on the provisions of §8(e) and §10. That legislative work will certainly take away from efforts to produce a Republican consensus cybersecurity bill.

In the Senate, the amendment process on any cybersecurity legislation will be tied up in the processing of amendments to limit the implementation of this EO. The impossibility of getting the votes necessary to move past those amendments will kill any floor action on even the most agreeable cybersecurity legislation.

Implementation

Finally, I am going to have to announce that this EO is stillborn. The Obama Administration has demonstrated a complete inability to implement any of the executive orders published to date. I find it hardly likely for them to be able to implement something as complex and controversial as this.

Tuesday, December 4, 2012

The Latest Cybersecurity Draft EO


There is another reported draft of a cybersecurity executive order floating around the internet; this one dated 11-21-12. The version that I have comes from Paul Rosenzweig’s  Lawfare Blog site. Since there is no way of telling for sure if this is really from the White House, or what changes might be made to it if it is, I’m not going to do a real detailed look at its provisions. There are, however, some things of interest that bear discussion.

Definitions


The key to the extent that a cybersecurity executive order will affect any particular facility is the definition that is used for ‘critical infrastructure’. There are a number of official definitions from various pieces of legislation adopted over the years and this draft {§2} uses one of the more expansive definitions taken from 42 USC 5195c(e). That definition reads:

“In this section, the term ‘‘critical infrastructure’’ means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.” (pg 5507)

Since the terms ‘incapacity’ and ‘debilitating impact’ are undefined this definition allows a great deal of leeway for the DHS Secretary to use in determining which facilities or systems are to be considered critical infrastructure.

The other interesting definition is the one that is quite obviously absent. There is no definition of cyber anything. Again, if the covered cyber-systems are not restrictively defined, and no definition is the least restrictive definition, then it is completely up to the Secretary what should be covered. Furthermore, there is no inherent reason for internal consistency in that decision.

Selection of ‘at Greatest Risk’ Facilities or Systems


Section 9 of the draft EO requires the Secretary to “identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security”. This identification is supposed to take place within 150 days of the publication of the EO. Fortunately a classified list of presumptive candidates for this list is already being maintained by DHS under provisions of 6 USC 124l.

That section requires that the Secretary maintain “maintain a single classified prioritized list of systems and assets… that the Secretary determines would, if destroyed or disrupted, cause national or regional catastrophic effects [emphasis added]” {6 USC 124l(a)(2)}. All the Secretary has to determine is which ones would remain on that list because of a cybersecurity incident. Again, since ‘cybersecurity incident’ is not defined in the EO this determination can be somewhat arbitrary.

It appears that the sole reason for establishing this list of ‘at greatest risk’ facilities is to allow the Secretary to prioritize the issuance of security clearances to “appropriate personnel employed by critical infrastructure owners and operators” {§4(d)}. This would, of course, allow for the sharing of classified intelligence information with those personnel. What this ignores is that there is a lot more to sharing classified information than just having a security clearance.

Information Sharing


This version of the draft EO has the most comprehensive requirements for the federal government to share information with the private sector that I have seen to date. Section 4 of the EO separately requires the Director of National Intelligence, the Attorney General and the Secretary of DHS to prepare within 120 days instructions to their subordinate agencies to “ensure the timely production of unclassified versions of all reports of cyber threats to the U.S. homeland that identify a specific targeted entity [emphasis added]” {§4(a)}. It then directs the Secretary to establish a coordinated process that “rapidly disseminates” such reports to the “U.S. targeted entity” {§4(b)}. Of course, this does not address cyber-intelligence that does not identify a specific targeted entity.

There is nothing in this draft EO that requires, suggests or even hints that the private sector should share cybersecurity information with the Federal government. There are a couple of mentions of 6 USC 133 which deals with the government sharing of voluntarily shared critical infrastructure information, but they are just reminders of what information provided by the private sector can be shared outside of the government without specific permission.

Security Guidelines


Section 7 deals with the development of a ‘baseline framework to reduce cyber risk to critical infrastructure’ (NOTE to EO drafters: you’ve got to come up with a better name that has a memorable acronym; it’s a requirement of the OMB style manual.) The Director of NIST is required to develop a ‘Cybersecurity Framework’ that includes “a set of standards, methodologies, procedures and processes that align policy, business, and technological approaches to address cyber risks” {§7(a)}.

A preliminary version of the Cybersecurity Framework will be ready within 240 days. There are, of course no penalties assigned for missing this time frame. That is a good thing as any number of standards organizations have been working for years to come up with their particular piece of just this type of framework. Then, one year after the EO is signed the Director, after engaging in an “open public review and comment process” {§7(e)} will publish a final version of the Framework.

To make things a tad bit more confusing, while the Framework was being developed in a consultive (okay the word was made up, but it sounds appropriately bureaucratic) environment, the Sector-Specific [Federal] Agencies in further consultation with their [Private] Sector Coordinating Councils are encouraged to “develop implementing guidance or supplemental materials to address sector-specific risks and operating environments” {§8(b)}.

Voluntary Program


Section 8 requires the DHS Secretary to “establish a voluntary program to support the adoption of the Cybersecurity Framework by owners and operators of critical infrastructure and any other interested parties” {§8(a)}. The Secretaries of Commerce and Treasury will identify incentives that can be given to encourage participation under current law and to suggest new legislation to further enhance those incentives.

In addition to those carrots there are at least two sticks included in this draft EO that will be used to encourage participation. The gentlest is the provision requiring Sector Specific Agencies to report annually “on the extent to which owners and operators notified under section 9 [the ‘at greatest risk’ list, see above] of this order are participating in the Program” {§8(c)}. Presumably there could be some Presidential arm twisting as a result.

The potentially more serious stick is regulatory action. Section 10 requires Federal agencies (but not independent regulatory agencies, they are not under the direction of the President) responsible for regulating the security of critical infrastructure to review the Cybersecurity Framework and determine if they have “clear regulatory authority to establish requirements based upon the Cybersecurity Framework” {§10(a)} and identify any additional authority needed. Agencies would then have 60-days to “propose prioritized, risk-based, efficient, and coordinated actions” {§10(b)} to mitigate cyber-risk consistent with the Cybersecurity Framework.

The CFATS program, for instance, should have no legal problem adding the Cybersecurity Framework to its regulatory scheme as long as the requirements were risk-based performance standards and not specific security requirements.

Moving Forward


Now all of the above is predicated on the ‘fact’ that this ‘draft EO’ is legitimately a working draft. Even if it is, we have no idea of what changes might be made to it before it is published in its final form. Realistically, we’ll just have to wait and see what comes out of the Oval Office.

Tuesday, May 24, 2011

HR 1540 and Cybersecurity

In an earlier blog on the introduction of HR 1540, the National Defense Authorization Act for Fiscal Year 2012 I mentioned that I saw no cyber security provisions but thought that that would change as this moved through the committee process. I was not completely wrong; I have found one fairly obscure reference to cyber security in the Committee Report on HR 1540.

In one of the reporting requirements that show up in committee reports but not the actual legislation, the House Armed Services Committee “directs the Secretary of Defense to conduct a study on the threat to the readiness of military installations from possible cyber attacks on civilian critical infrastructure” (pg 199). The requirement includes the inevitable ‘Report to Congress’ on the results and potential mitigation efforts.

The prior discussion makes it fairly clear that the Committee was concerned about potential attacks on local utilities supporting military bases. Interestingly the discussion makes no specific reference to Stateside facilities, so presumably it would also require DOD to look at potential affects on bases in foreign countries.

I am more than a little disappointed that the Committee has taken such a narrow view of the definition of ‘critical infrastructure’ in mandating this study. It fails to note that many military bases are served by fuel pipelines that could be subject to cyber attacks. Additionally, I would bet that there are military facilities that are located in areas that could be affected by attacks on high-risk chemical facilities and chemical facilities located in port areas covered by MTSA.

Interestingly, the chemical facilities that have the lightest federal security mandate, water treatment facilities, could be covered under this mandated report as long as they provide water service to a DOD facility. It would be interesting to see if there would be any mention of potential cyber attacks that could result in the release of chlorine gas from these facilities as a possible source of danger to military facilities.

Unfortunately we will never see this report. These reports to Congress usually get buried in any case, but this one will certainly be classified, so public release will be even less likely. It would have been nice to see a requirement for an unclassified summary to be included with this report, but Congress has never been keen on sharing their information with the public.
 
/* Use this with templates/template-twocol.html */