Showing posts with label Cyber Incident Reporting. Show all posts
Showing posts with label Cyber Incident Reporting. Show all posts

Friday, August 30, 2024

Review - New CISA Voluntary Cyber Incident Reporting Initiative

Yesterday, CISA announced a new effort targeting efforts to get organizations to voluntarily report cyber incidents. The new website “is designed to help entities that may be considering voluntarily reporting cyber incidents understand “who” CISA recommends report an incident, “why and when” CISA recommends they report, as well as “what and how to report.””

Commentary

While this is strictly a voluntary incident reporting system, I am reasonably sure that CISA will be using this as a part of their effort to develop the mandatory critical infrastructure reporting system required by Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Pushing this voluntary system will allow CISA to work out any bugs in the reporting system before it is rolled out live next year.

 

For more information about this new initiative, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/new-cisa-voluntary-cyber-incident - subscription required.

Thursday, February 1, 2024

Senate Fails to Act on SJ Res 50 – Objection to SEC Cyber Reporting Rule

Back in November, Sen Tillis (R,NC) introduced SJ Res 50, that would nullify the Security and Exchange Commission’s cyber incident reporting rule. On December 20th, the Senate reached a unanimous consent agreement that, as long as the Senate Banking, Housing, and Urban Affairs Committee discharged the resolution, it would be considered by the Senate by January 31st, 2024. Yesterday, with no action yet taken in Committee, that agreement was officially vitiated (terminated).

These joint resolutions of disapproval are governed by 5 USC 802 which generally limits the authority of Congress to disapprove of a regulation adopted by the executive branch to within 60-days (days that congress is in session) of when the regulation was published. The unanimous consent agreement adopted in December removed that 60-day consideration limit for SJ Res 50. Yesterday’s vitiation of that agreement canceled that removal, essentially killing SJ Res 50 since the 60-day limit has since passed.

Wednesday, January 3, 2024

CISA Sends Cyber Incident Reporting NPRM Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs announced that it had received a notice of proposed rulemaking (NPRM) from CISA on Cyber Incident Reporting for Critical Infrastructure Act Regulations. CISA published a request for information (removed from paywall) supporting this rulemaking on September 12th, 2022.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

 

The Cybersecurity and Infrastructure Security Agency (CISA) will propose regulations to implement certain aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).  Specifically, CIRCIA directs CISA to develop and implement regulations requiring covered entities to submit reports to CISA regarding covered cyber incidents and ransom payments.  CIRCIA requires CISA to publish a Notice of Proposed Rulemaking (NPRM) within 24 months of the date of enactment of CIRCIA as part of the process for developing these regulations.  CISA previously issued a Request for Information on September 12, 2022, and held a series of listening sessions seeking public input on potential aspects of the proposed regulation prior to publication of the NPRM.

 

The CIRCIA deadline for publishing this NPRM is March 15th, 2024.

Monday, May 22, 2023

Software Compliance Tools and CFATS

Last week, I briefly mentioned an article over on FCW.com that discussed plans in DOD to make available free software tools for small contractors to better enable them to meet DOD’s contractor cyber maturity requirements. This is a concept that should spread through out the government, but is especially applicable to the Chemical Security Anti-Terrorism Standards (CFATS) program.

To be fair, the CFATS program is practically run on software applications in its Chemical Security Assessment Tool (CSAT). This collection of compliance tools was innovative in its day (and still should be looked at by other security and safety agencies), but it is time to further modernize the program and start moving some tools to the facility devices. One obvious possibility is cyber incident reporting.

Back in September of 2021, CISA clarified (removed from paywall) the cyber incident reporting requirements for CFATS covered facilities. While CISA does have an online cyber incident reporting form, it would make far more sense for regulated facilities to have an app available for such reporting. It would make reporting easier and could automatically include information about the regulated status of the facility (including facility identification).

Such an application could also provide CISA with a secure mechanism to share cyber threat information with regulated facilities.

Monday, February 27, 2023

Review - HR 1160 Introduced – DOE Cybersecurity Reporting

Last week Rep Walberg (R,MI) introduced HR 1160, the Critical Electric Infrastructure Cybersecurity Incident Reporting Act. The bill would make DOE the designated agency to receive cybersecurity incident reports from critical electric infrastructure. It would also require DOE to publish regulations covering those reporting requirements. No spending is authorized in the bill.

The bill amends 16 USC 824o–1, Critical electric infrastructure security.

Moving Forward

As I reported earlier today, the Subcommittee on Energy, Climate, and Grid Security of the House Energy and Commerce Committee will hold a markup hearing that includes this bill. This indicates that the Committee leadership considers this an important bill. It is likely that there will be at least some level of bipartisan support for this bill. Moving this bill to the floor of the full House may be difficult because these reporting requirements conflict with the requirements of Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Division Y of PL 117-103) that designate CISA as the agency to receive cybersecurity incident reports and sets a 72 hour reporting standard.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-1160-introduced - subscription required.

Wednesday, October 5, 2022

CISA Announces Additional Cyber Incident Reporting Listening Session – 10-19-22

Today, CISA published a notice of public listening session in the Federal Register (87 FR 60409) for “Cyber Incident Reporting for Critical Infrastructure Act of 2022”. This listening session is in support of CISA’s development of cybersecurity reporting regulations in accordance with the provisions of CIRCIA. This session will be in addition to those reported last month

The additional session will be held in Washington, DC on October 19th. CISA is encouraging people to register to attend the session. You can register at CISA’s CIRCIA website.


Saturday, September 17, 2022

Review - CISA Incident Reporting RFI – Public Comments – 9-17-22

This is the first in a series of brief looks at public comments submitted in response to CISA’s request for information in support of the congressionally mandated Cyber Incident Reporting Rule. Since this is just the first week in the process, the limited responses are just from the following individual:

Mitchell Berger,

Anonymous,

Jasper Wyman, and

Alicia Fernandes

Comments addressed the following areas:

• Report formatting,

• Reporting limitations, and

• Who reports

 

For more information on these comments, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cisa-incident-reporting-rfi-public - subscription required.


Monday, March 7, 2022

Review - S 3600 Cyber Incident Reporting Provisions

Last week, the Senate passed S 3600, the Strengthening American Cybersecurity Act of 2022. Title II of that bill is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The seven sections of that title outline the cyber incident reporting program to be established by CISA. It establishes CISA as the action agency for the receipt, processing and sharing of information provided in such reports and establishes a 72-hour reporting standard for covered cyber incidents and a 24-hour reporting standard for making ransomware payments. It also provides CISA 42-months to complete a rulemaking implenting these requirements.

Commentary

 

While a mandatory reporting requirement is long overdue, the reality is that even if this bill were to pass tomorrow, the reporting process will still be years in the making. The rulemaking process is lengthy, with the 24-month NPRM requirement and 18-month final rule publication requirements pushing the process out to three and a half years (plus what ever effective-date delay is included in the final rule) before process goes live. And that is ‘IF’ CISA is able to comply with those time constraints.

 

Congress gave DHS six months to stand up the Chemical Facility Anti-Terrorism Standards (CFATS) program under an interim final rule. That deadline was essentially met and DHS included an NPRM that was not required by the authorizing language. A more reasonable deadline for a cyber incident reporting interim final rule would be somewhere between six months and a year. This is especially true here because the legislation outlines the requirements in quite some detail.

 

For more details about the specific requirements in the legislation, particularly for the rulemaking, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3600-cyber-incident-reporting-provisions   - subscription required.

Saturday, October 31, 2015

NRC Publishes Cybersecurity Event Reporting Final Rule

The Nuclear Regulatory Commission published in Final Rule in Monday’s Federal Register (80 FR 67264-67277; available on-line today) concerning Cyber Security Event Notifications. The rule codifies certain reporting activities associated with cybersecurity events contained in security advisories issued by the NRC.

The rule makes modifications to three sections of 10 USC Part 73 (§73.8, §73.22, and §73.54) and adds a new section (§73.77; Cyber Security Event Notifications). For readers of this blog, the items of specific interest will be found in the changes to §73.54 (Protection of digital computer and communication systems and networks) and the new §73.77.

Protecting Cyber Assets

Section 73.54 provides a great deal of detail about the requirements that a regulated facility needs to undertake to protect cyber systems associated with {§73.54(a)(1)}:

• Safety-related and important-to safety functions;
• Security functions;
• Emergency preparedness functions, including offsite communications; and
• Support systems and equipment which, if compromised, would adversely impact safety, security, or emergency preparedness functions

Paragraph (d) of the current §73.54 outlines the licensee actions that are required for the security program set forth in the section. They include:

• Ensure that appropriate facility personnel, including contractors, are aware of cyber security requirements and receive the training necessary to perform their assigned duties and responsibilities.
• Evaluate and manage cyber risks.
• Ensure that modifications to assets, identified by paragraph (b)(1) of this section, are evaluated before implementation to ensure that the cyber security performance objectives identified in paragraph (a)(1) of this section are maintained.

The new final rule adds a fourth required action: “Conduct cyber security event notifications in accordance with the provisions of §73.77.”

Event Notification

The NRC safety regulations contain a whole host of requirements for notification activities that must be under taken by licensees (see §73.71 for example). The new §73.77 adds a new set of notification requirements and classifies them generally by how soon notification is required after the event is detected. There are four operational time limit are:

• One hour;
• Four hour;
• Eight hour; and
• 24 hour

The one hour time limit is reserved for cyber attacks that: “that adversely impacted safety-related or important-to-safety functions, security functions, or emergency preparedness functions (including offsite communications); or that compromised support systems and equipment resulting in adverse impacts to safety, security, or emergency preparedness functions within the scope of § 73.54” {new §73.77(a)(1)}. In other words there was an actual impact on safety, security or emergency preparedness.

There are three categories of events under the four hour reporting standard. First is an attack that could have resulted in a situation that would have required a one-hour report if it had been successful. The second is the discovery of a “suspected or actual cyber attack initiated by personnel with physical or electronic access to digital computer and communication systems and networks within the scope of §73.54” {§73.77(a)(2)(ii)}; essentially a breach of the cyber perimeter. The third is a generic catch all that requires a report of any cyber related situation that resulted in a notification of law enforcement.

The eight hour category is the last one that requires actual telephonic communications with the NRC. It is reserved for information “regarding observed behavior, activities, or statements that may indicate intelligence gathering or pre-operational planning related to a cyber attack against digital computer and communication systems and networks within the scope of §73.54” {§73.77(a)(3)}.

The ’24 hour’ category that I’ve listed here is not actually a requirement to ‘communicate’ with the NRC in any direct way. It is a requirement to record the event in the “corrective action program (CAP)”. This is an NRC inspect able document maintained under §73.55(b)(10) that the facility uses to “track, trend, correct and prevent recurrence of failures and deficiencies in the physical protection program”. Under the new §73.77(b) the facility will now also record “vulnerabilities, weaknesses, failures, and deficiencies in their § 73.54 cyber security program” as well as documenting any of the notifications made under the provisions outlined above.

The remainder of the new §73.77 outlines how the facility is to report the incidents described above to the NRC and how a follow-up written report will be prepared and submitted.

Effective Date

This rule becomes effective on December 2nd, 2015. The NRC will begin enforcement of the rule on May 2nd, 2016.

Commentary

Few readers (I know there are some, bear with me) of this blog are intimately involved in the operation of nuclear power plants or maintenance of the security apparat that protects them. I am certainly not planning on becoming a subject matter expert on the topic. This rulemaking is important, however, because it outlines a cybersecurity event notification process that can serve as a model in developing a regulatory scheme for control systems in other critical infrastructure sectors.

Before we go any further, let me remind folks that the NRC already has a regulatory process that is set up to take security reports from the regulated community, digest those reports and communicate the essential information to other facilities in that regulated community so that they can modify their on-going processes at a higher level of safety and security. Lacking that sort of information digestion and communication, there is absolutely no reason to require timely reporting of cybersecurity incidents, or any sort of security incidents for that matter.

The important thing for other regulators to take from this rulemaking is the way that the NRC prioritized reporting requirements; events that had cyber physical impacts, events that could have had cyber physical impacts, and events that demonstrate penetration of the cyber perimeter. This categorization should be able to withstand numerous changes in technology and be adaptable to any industry that has the potential for cyber physical impacts outside of the facility boundary.

The other important take away from this rulemaking is that the NRC had already established a workable definition of the critical control systems at their regulated facilities; safety functions, security functions, emergency response functions and systems that directly support those functions. Again, those functions could be easily translated into any regulated industry that has the potential for cyber physical impacts outside of the company fence line. With minor adaptations they could even be modified to apply to mobile control systems (auto, planes and ships) and even medical devices.


There is much that is still missing from this rulemaking, which is arguably part of the most proactive security program functioning in this country outside of the military. The NRC rules are still missing a cyber forensics component, for example. But the NRC is actually trying to codify a proactive cyber incident reporting program and that is a very important part of any cybersecurity program, a part that should be looked at very carefully by other critical infrastructure regulatory agencies.

Wednesday, November 18, 2009

ICS-CERT

I just don’t get back to check the DHS CERT Control Systems Security Program (CSSP) web page often enough. I checked it today and found that last week they announced the official launch of the Industrial Control System Cyber Emergency Response Team (ICS-CERT) coordination center in Idaho Falls, ID. Now the ICS-CERT have been operational since early this year, but their coordination center is now up and running. The brief article on the ICS-CERT contains a link to a two-page brochure about the ICS-CERT. It describes their mission and genearl capabilities. Probably the most valuable item in the brochure, however, is the ICS-CERT contact information. I’ll reproduce that whole section here.
“CSSP and ICS-CERT encourage you to report suspicious cyber activity, incidents and vulnerabilities affecting critical infrastructure control systems. Online reporting forms are available at https://forms.us-cert.gov/report/. You can also submit reports via one of the following methods: “ICS-CERT Watch Floor: 1-877-776-7585 “ICS related cyber activity: ics-cert@dhs.gov “General cyber activity: soc@us-cert.gov “Phone: 1-888-282-0870”
I certainly recommend that anyone that has an ICS cyber incident to immediately contact ICS-CERT. Even if the result of that particular incident seems relatively innocuous, it should still be reported. The intelligence and counter-intelligence portion of the ICS-CERT mission is very important and requires these inputs to be effective. Near-miss or ‘cyber-scouting’ incident reporting can be important in preventing serious incidents.
 
/* Use this with templates/template-twocol.html */