Showing posts with label Cyber Emergency Response. Show all posts
Showing posts with label Cyber Emergency Response. Show all posts

Friday, February 24, 2017

HR 1049 Introduced – DOD Cybersecurity Database

Last week Rep. Langevin (D,RI) introduced HR 1049, the Department of Defense Emergency Response Capabilities Database Enhancement Act of 2017. This is a companion bill to S 307; that is an identical bill introduced to allow for simultaneous action by both houses of Congress instead of serial consideration.


Langevin is a member of the House Armed Services Committee, the committee to which this bill was referred for consideration. This means that it is possible that he could have enough influence to have this bill considered in committee. As I mentioned with S 307, there is nothing in this bill which should engender significant opposition.

Saturday, February 18, 2017

S 307 Introduced – DOD Cyber Capability Database

Earlier this month Sen. Ernst (R,IA) introduced S 307, the Department of Defense Emergency Response Capabilities Database Enhancement Act of 2017. The bill would require DOD to specifically include cybersecurity capabilities in an existing DOD emergency response capabilities database.

Database Expansion


The bill would amend §1406 of the ‘John Warner National Defense Authorization Act for Fiscal Year 2007 {PL 109-364 §1406 (120 STAT. 2436)} which required DOD to establish a database that recorded the “emergency response capabilities that each State’s National Guard, as reported by the States, may be able to provide in response to a domestic natural or manmade disaster, both to their home States and under State-to-State mutual assistance agreements” {§1406(1)}.

The bill would add two specific cybersecurity related requirements to that database {§2(b)(2)}:

• Cyber capabilities of the National Guard that are identified by the Department as important to national security and for response to domestic natural or manmade disasters.
• Cyber capabilities of the other reserve components of the Armed Forces that are identified by the Department as important to national security.

Moving Forward


Ernst is a member of the Senate Armed Services Committee (the committee to which the bill was assigned for consideration) and two of her co-sponsors {Sen. Gillibrand (D,NY) and Sen. Fischer (R,NE)} are members of the Cybersecurity Subcommittee of that Committee. This means that there is a good chance that there will be sufficient political influence to have that Committee take up this bill.

There is nothing in this bill that would cause any substantial opposition to its consideration. If this bill were taken up on its own, it would likely be considered under the Senate’s unanimous consent procedure. This bill is also a good candidate for inclusion in the 2018 DOD authorization bill, either in the initial draft or as a floor amendment.

Commentary


There is nothing in the bill that would specifically require the inclusion of industrial control system security experience/expertise in the database listing. It is likely that DOD would take that step on their own initiative.


What is not clear with respect to either the original database requirement, or this modification, is to what use DOD is expected to put this database; whether it is only for internal DOD use or whether other government organizations (FEMA for example) would have access to the database. This bill would be a good place to clarify which agencies are expected to have access to the database.

Monday, November 18, 2013

Cyber Attack Emergency Services

There is an interesting article over at SCMazazineUK.com about the establishment of an emergency response service for cybersecurity events. It isn’t really a unitary service, but rather a certification process for private sector organizations that provide the service. This “service” is for organizations in the UK, but there is no reason that such a service couldn’t be established here. This is a quick look at some of the thing that would have to be included in the certification process for such a service here in the US.

CFATS Customers

There are two different types of regulated organizations that might use this service that would require additional certification verifications before they could use the offered services; chemical facilities regulated under CFATS and defense industrial base organizations. Both types of organizations would almost certainly require personnel surety vetting of any investigators allowed access to covered computer systems.

Any computer system that has been identified as a critical system under a chemical facility’s site security plan {and this would almost certainly include any control system used in the manufacture or handling of DHS chemicals of interest (COI)} would be covered under the requirement for a background check. CFATS rules require that anyone with unaccompanied access to a critical system has to undergo a background check including vetting against the Terrorist Screening Database (TSDB).

I would argue that any access to a covered control system (or information system for that matter), especially the level of access required for an emergency response to an attack on such a system, would have to be considered ‘unaccompanied’ even if a control system engineer was sitting right beside the cyber-responder the whole time he had access to the system.

Access to an information system at a CFATS facility that contained information about the CFATS program implementation would also require that anyone given access to that system would have to be certified by DHS for access to Chemical-Terrorism Vulnerability Information (CVI). This could be avoided if all CVI information were held on a non-networked computer.

DIB Customers

Many defense industrial base organizations store or have access to classified information. Any computer systems that house such information would require a security clearance to access. It could also be argued that systems that contained sensitive unclassified information would require special vetting of personnel before they were given access to such systems.

ICS-CERT

For the control system side of things, this is the type thing that the ICS-CERT flyaway teams routinely do. Of course there are a number of private organizations that do similar work and I am not sure that we can continue to justify this work by ICS-CERT in view of that fact. I know that there have been some objections raised about the ‘unfair’ competition provided by ICS-CERT. Additionally, the ICS-CERT team is relatively small and I doubt that it could handle any significant increase in taskings for this type of response.

I would assume that ICS-CERT teams do have the requisite clearances to handle the DIB cases, though I would suspect that there is a DOD team that would handle this type of activity for DOD associated organizations.

I would be surprised if the ICS-CERT people were not already vetted in a manner that would be acceptable to the folks at ISCD for CFATS covered facilities. For CFATS related organizations I might suggest that ISCD and ICS-CERT establish an MOU that would specifically allow CFATS facilities to contact ICS-CERT for suspected control system attacks without the need for worrying about vetting the flyaway team for unrestricted access to those control systems.

Existing Private Vendors

It would be interesting to hear from any vendors currently working in the emergency cyber response business to see what they are currently doing in regards to documenting the vetting of their personnel for customers or potential customers in the CFATS program of the DIB program.

Saturday, March 23, 2013

Bills Introduced – 03-22-13


While the House had already left town for their Easter Recess, the Senate was still at work on their budget bill. They also had time to submit a number of new bills including just one that will probably be of interest to the cybersecurity community:

S 658 Latest Title: A bill to amend titles 10 and 32, United States Code, to enhance capabilities to prepare for and respond to cyber emergencies, and for other purposes. Sponsor: Sen Gillibrand, Kirsten E. (D,NY)

As with any other type of security, one must assume that cybersecurity protections for critical infrastructure are, at some point, going to fail. One would like to think that cyber emergency response procedures are in place before that happens. Maybe this bill will help to ensure that; we’ll have to see bill to see if that may be the intention here.
 
/* Use this with templates/template-twocol.html */