Showing posts with label Cyber Sense Program. Show all posts
Showing posts with label Cyber Sense Program. Show all posts

Saturday, July 10, 2021

S 2199 Introduced - Cyber Sense Act

Last month, Sen Rosen (D,NV) introduced S 2199, the Cyber Sense Act of 2020 (yep, it says 2020). The bill would require DOE to “establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system”. The bill is similar to HR 2928 which was adopted by the House Energy and Commerce Committee without amendment.

Definitions

Section 2(a) of the bill provides the definitions for four critical terms used in the bill (these definitions are not laid out in HR 2928, the terms are defined in passing), two by reference to existing definitions. There are no cybersecurity related definitions provided.

Program Established

Sections 2(b) and 2(c) in this bill are essentially identical to §2(a) and §2(b) respectively in the House bill. The only difference is that the House bill keeps referring to the ‘Cyber Sense Program’ where the Senate bill uses the term ‘Program’ after defining that in §2(a)(3) as meaning the ‘Cyber Sense Program’ established in §2(b).

Moving Forward

While Rosen is not a member of the Senate Energy and Natural Resources Committee, the committee to which this bill was assigned for consideration, three of her four cosponsors {Sen Hoeven (R,ND), Sen King (I,ME), and Risch (R,ID), are members and Hoeven is the Ranking Member of the Energy Subcommittee. This means that there is probably sufficient influence to see this bill considered in Committee.

The House version of this bill received bipartisan support and I would expect to see the same in Committee in the Senate. The problem remains moving the bill to the floor of the Senate. The bill is not important enough to be considered under regular order (debate, amendments, and, of course, two separate cloture votes) and I suspect that there would be sufficient opposition to stop consideration under the unanimous consent process.

The only way this bill is moving forward in the Senate is attached to some other, must pass piece of legislation.

Commentary

In my Substack post on HR 2928 I addressed my concerns about the information sharing restrictions in what is §2(d) in this bill. Many pieces of control system equipment are used outside of the bulk power system and restricting those outside that system from being notified of vulnerabilities is just not fair.

In my post on this blog I talked about adding a software bill of materials requirement to the House version of this bill. My interest in seeing that done remains.

Tuesday, November 24, 2020

S 4795 Introduced – Cyber Sense Program

Last month Sen Rosen (D,NV) introduced S 4795, the Cyber Sense Act of 2020. This bill is very similar to HR 360 that passed in the House days before this bill was introduced. The bill would require DOE to establish “a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system” {§2(b)}.

Differences Between S 4795 and HR 360

The essential components of the ‘Cyber Sense Program’ are the same in the two bills. The differences are structural (S 4795 includes a definitions sub-section {§2(a)} and editorial (HR 360 makes multiple references to the ‘Cyber Sense Program’ where S 4795 makes reference to ‘the program’). These are common stylistic differences frequently seen in House and Senate language.

Moving Forward

Rosen is not a member of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration, but her three cosponsors {Sen Hoven (R,ND), Sen King (I,NH), and Sen Risch (R,ID)} are members of that Committee. If this bill had been introduced earlier in the session there would be a good chance that the bill would be considered in Committee and adopted with bipartisan support. There probably is not enough time remaining in the session for this to happen.

Given the fact that HR 360 passed in the House by a voice vote, there remains a good chance that the Senate could directly take up this bill under the unanimous consent process, but I am not sure why they would want to take up this bill rather than HR 360. If S 4795 were passed, it would have to go back to the House for an additional vote (where it would almost certainly pass) but passing HR 360 would avoid having to take that extra step. It is probably a toss up for which would be considered.

Commentary

My two objections to the language of HR 360 also apply to this bill. The information protection language in both bills would allow vendors to continue to sell vulnerable devices without notification and it would probably stop researchers from reporting vulnerabilities to the program instead of CISA NCCIC-ICS. The bigger problem continues to be the lack of specific funding authorization in either bill. This would mean that the DOE would have to fund this program with existing monies, taking money from other programs.

Friday, October 2, 2020

Bills Introduced – 10-1-20

Yesterday, with both the House and Senate in session (an unusual October session in an election year), there were 67 bills introduced. One of those bills will receive additional coverage in this blog:

S 4795 A bill to require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Sen. Rosen, Jacky [D-NV] 

It is unusual for this bill to be introduced this late in the session when the House just passed their version of the bill this week. It will be interesting to see what the differences are between this bill and HR 360.

Tuesday, January 15, 2019

HR 360 Introduced – Cyber Sense Program


Last week Rep. Latta (R,OH) introduced HR 360, the Cyber Sense Act of 2019. The bill is nearly identical to HR 5239 introduced last session and adopted by the House Energy and Commerce Commission. The new bill is most closely related to the reported version of the earlier bill.

Moving Forward


This bill was scheduled to be considered (along with HR 359)  in the House today under the suspension of the rules process, but that has since changed. This was apparently done to provide time for the consideration of HJ Res 27 as I mentioned earlier.

This bill received bipartisan support in Committee during the last session and I suspect that it will again, if/when it reaches the floor of the House.

The House has still not made committee assignments for its members (beyond most Chairs and Ranking Members), so it is not yet possible to definitively comment on the possibility of this bill being considered in the House Energy and Commerce Committee, it that is not pre-empted by floor action. I suspect that Latta and his co-sponsor {Rep. McNerney (D,CA)} will be influential members of that Committee.

Commentary


I still have concerns about the information sharing restrictions in the bill. Most of the devices that would be covered under the Cyber Sense program would be used by manufacturing facilities outside of the electric sector. They could be substantially harmed by restricting the sharing of vulnerability information about those devices by making that information Critical Electrical Infrastructure Information (CEII).

As I outlined in my post on the introduction to HR 5239, I would much rather see a requirement to provide restricted early notification of vulnerabilities to organizations in the electric sector before universal notifications are made by NCCIC-ICS.

Interestingly, device vendors would probably not be restricted from publishing vulnerability reports on their own products, even if ‘protected’ by the CEII labeling. CEII restrictions only apply to government agencies within the United States.

Thursday, January 10, 2019

Bills Introduced – 01-09-19


Yesterday with both the House and Senate in session there were 89 bills introduced. Of these, three bills will likely receive future mention in this blog:

HR 359 To provide for certain programs and developments in the Department of Energy concerning the cybersecurity and vulnerabilities of, and physical threats to, the electric grid, and for other purposes. Rep. McNerney, Jerry [D-CA-9]

HR 360 To require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes. Rep. Latta, Robert E. [R-OH-5] 

HR 370 To require the Secretary of Energy to carry out a program relating to physical security and cybersecurity for pipelines and liquefied natural gas facilities. Rep. Upton, Fred [R-MI-6] 

Bills Also Worth Mentioning


I am also going to call attention here to six other bills here that would attempt to mitigate the effects of the current Federal Funding Fiasco. I will briefly discuss these bills in this post and will probably not mention them again in this blog.

HR 367 Making appropriations for Coast Guard pay in the event an appropriations Act expires before the enactment of a new appropriations Act. Rep. DeFazio, Peter A. [D-OR-4]

HR 371 Making appropriations for certain Federal employees working during the Government shutdown beginning on or about December 22, 2018, and for other purposes. Rep. Biggs, Andy [R-AZ-5]

HR 374 To make continuing appropriations for Coast Guard pay in the event that appropriations for Coast Guard pay in fiscal year 2019 expire and a new appropriations Act has not been enacted. Rep. Byrne, Bradley [R-AL-1]

HR 419 To make continuing appropriations for the Federal Aviation Administration for fiscal year 2019. Rep. Van Drew, Jefferson [D-NJ-2]

HR 421 Making continuing appropriations for the Coast Guard. Rep. Wild, Susan [D-PA-7] 

S 72 A bill to suspend the enforcement of certain civil liabilities of Federal employees and contractors during a lapse in appropriations, and for other purposes.  Sen. Schatz, Brian [D-HI]

FFF Effect Mitigation


As we quickly approach the 21-day FFF record it is interesting to note the efforts by a wide variety of congresscritters to protect various agencies and employees of the Federal government from the effects of the FFF. At first glance it would seem that these efforts are commendable as they would reduce the suffering of employees who are, after all, bearing the direct brunt of this political foofaraw.

On the other hand, and there is ALWAYS an ‘other hand’ when it comes to politics, I think that these efforts are misguided. While reducing the pain and suffering of these employees would be great for them and their families, it would also serve to reduce the political price for shutting down the government (or portions thereof) and make future shutdowns more likely.

On the first Tuesday in November, 2020, the voters of this country will remember this little game of political hostage taking. The hardcore supporters of both the President and the Democratic leadership of Congress will probably reward them for their intransience, but the vast majority of folks in the center will take revenge for those hurt during this FFF. They will go into the voting booth having decided who was mainly at fault (both sides share at least some portion of the blame) and will vote for their political retirement.

That is as it should be, there should be a high price to pay for using the disruption of the government as a political tool. Unfortunately, any measures taken to reduce the impact of that disruption will lesson the anger of the electorate and thus reduce the price to be paid for this game of political one-up-man-ship.  That could have the unintended consequence of extending the length of the current FFF and increase the chance of a repeat performance in FY 2020.

Friday, September 18, 2015

HR 8 Introduced – Energy Security

On Wednesday Rep Upton (R,MI) introduced HR 8, the North American Energy Security and Infrastructure Act of 2015. The bill mainly addresses energy supply chain issues, but it does have two provisions dealing with actual security issues. The first is protection of information about bulk electrical system security issues and the second is a new cybersecurity program.

Information Protection

Section 1104 of the bill would add a new section (§215A; Critical Electric Infrastructure Security) to the Federal Power Act (16 USC 824 et seq.). The new section would provide authority for the Secretary of Energy to address a grid security emergency {new §215A(b)} and establish a program for the protection of critical electric infrastructure information. The provisions of this section are essentially those found in HR 2271 which I have previously discussed in detail.

While a CEII program does currently exist, pending regulations on controlled but unclassified information (CUI) from the National Archives and Records administration, treat such programs differently if they are authorized by law.

Cyber Sense Program

Section 1106 requires the Energy Secretary to establish a Cyber Sense Program to identify and promote cyber-secure products intended for use in the bulk-power system. The program would allow voluntary industry participation and would include {§1106(b)}:

• A testing process to identify products and technologies intended for use in the bulk-power system, including products relating to industrial control systems, such as supervisory control and data acquisition systems;
• The establish and maintain cybersecurity vulnerability reporting processes and a related database for products in the Cyber Sense program;
• Regulations regarding vulnerability reporting processes for products tested and identified under the Cyber Sense program; and
• Technical assistance to utilities, product manufacturers, and other electric sector stakeholders to develop solutions to mitigate identified vulnerabilities in products tested and identified under the Cyber Sense program.

This section would also require the Secretary to provide for public notice and comments before establishing or changing the required testing program. Products included in the program would be required to be tested every two years.

The bill does not specifically mandate that the results of the product testing should be considered as Critical Electric Infrastructure Information (CEII). It does, however, require that “any vulnerability reported pursuant to regulations promulgated under subsection (b)(3), the disclosure of which could cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be exempt from disclosure” under the Freedom of Information Act or any similar State and local laws.

Moving Forward
As I noted in my earlier post the assignment of ‘HR 8’ to this bill instead of a sequential bill number indicates that the Republican leadership in the House considers this bill a high political priority. It was considered in a markup hearing yesterday before the House Energy and Commerce Committee, but Committee web page does not yet provide any results of that consideration. I expect, however, that the bill was adopted by voice vote.

Commentary

The new Cyber Sense Program proposed by this bill is the first serious attempt by Congress to deal with the problems associated with industrial control system security. The idea of the Federal government establishing a testing and certification program for ICS components and systems is certainly an innovative approach to control system security.

Since this bill does not provide any funding for the program, it is fairly clear that the authors intend this testing to be done by third-party organizations and that is reinforced by the requirement for the Secretary to “oversee Cyber Sense testing carried out by third parties” {§1106(b)(8)}. The problem becomes that, since the Energy Department is not paying for the testing, that it will most likely be the vendor that pays. This always raises the potential issues of testers being beholden to the people that make the products being tested.

The establishment of regulations for vulnerability reporting for Cyber Sense products is something that was fairly glibly added to this bill. But, taken along with the information sharing restrictions outlined, this is going to be problematic. Except for equipment that is uniquely used by the bulk-power system, trying to regulate how security vulnerability reporting is conducted without intimately involving at least ICS-CERT is going to create more problems than it solves.

A brief example will help explain the problem. A private security researcher discovers a vulnerability in a PLC that is part of the Cyber Sense program, but is also used in a wide variety of other industrial control systems. Normally he would have a choice of coordinating that vulnerability disclosure with the vendor, ICS-CERT (or any one of a number of other coordination agencies) or publicly disclosing the vulnerability. Under the new program, if he instead disclosed it to the Cyber Sense program, then there would be no public disclosure through ICS-CERT or the vendor. In fact, if the new regulations were to declare this disclosure to the Cyber Sense to be CEII information (a logical move), then ICS-CERT would not be able to post it to the US-CERT Secure Portal because people without a CEII need-to-know have access to that system.

Crafters of this bill missed one of the biggest potential incentives for using Cyber Sense components. DHS has the Safety Act program under their Science and Technology Directorate that provides important legal liability protections for providers of Qualified Anti-Terrorism Technologies. This bill should have set up a similar program for Cyber Sense vetted products.

I would like to suggest that instead of making the vulnerability information CEII and limiting the disclosure to just the energy sector, that the bill should have designated ICS-CERT as the agency responsible for coordinating disclosures of vulnerabilities for all Cyber Sense Products. It would then go on to require that ICS-CERT initially release the vulnerability information on the US-CERT Secure Portal and only make full public disclosure in coordination with the Department of Energy organization overseeing the Cyber Sense program. That way non-energy sector organizations using the same equipment would have an opportunity to fix their devices before the public disclosure of the vulnerability.


Now, I really like the idea of an independent agency that does in depth security vulnerability testing of control system components and certifying some level of minimum security for such devices. That would certainly make the purchasing of secure ICS components much easier. But we do need to be careful how that is done to prevent the most egregious unintended consequences.
 
/* Use this with templates/template-twocol.html */