Showing posts with label Cybersecurity Legislation. Show all posts
Showing posts with label Cybersecurity Legislation. Show all posts

Friday, May 14, 2021

Cybersecurity Legislation Watch – 5-14-21

I received two emails from Congress.gov this morning about the publication of text for two cybersecurity bills. Anyone can sign up for this service for tracking changes in the files for individual pieces of legislation on that site. It has been especially valuable to me this session because of the large number of bills being introduced and the problems the Government Printing Office is having publishing text of those bills in a timely manner.

Anyway, back to the two bills. The two cybersecurity bills are:

HR 2980, the Cybersecurity Vulnerability Remediation Act, and

HR 3138, the State and Local Cybersecurity Improvement Act

Generally speaking, the GPO tries to publish the text of bills in the order that they were introduced. This keeps them out of problems with congresscritters screaming favoritism when someone else’s bill is published first. These two bills, however, are being published well outside of that sequence. This typically means that the leadership has notified the GPO of their particular interest in seeing these bills published early in the que.

Now I have not had time yet to do a detailed comparison, but it looks like each of these bills is substantially the same as bills introduced in the 116th Congress:

• HR 2980 – HR 3710, which passed in the House on September 26th, 2019, and

• HR 3138 – HR 5823, which passed in the House on September 30th, 2020

I suspect that later this afternoon when the House Majority Leader’s ‘The Weekly Leader’ is published outlining what will be happening in the House next week, we will see both of these bill on the list of bills that will be considered under the suspension of the rules process. Bills are not typically seen on the floor before they are considered in committee, but with the current attention on cybersecurity and the fact that both bills went through the committee process last session, this would not be a very unusual process.

There are two other cybersecurity bills that could also be considered on the floor next week, as they have both been considered in committee:

HR 1833, the DHS ICS Capabilities Enhancement Act, and

HR 1850, the Supporting Research and Development for First Responders Act

Sunday, June 29, 2014

ICS-CERT and Information Sharing

An interesting series of twitversations were started yesterday about a single sentence in my post about the latest ICS-CERT update on the Havex Trojan. That dialog is important but a little more complicated than can be easily captured in 140 characters. I will try to address my outlook on the question here and welcome comments and opposing points of view to chime in on this discussion.

The Twitversation

What started this was the blog comment about mitigation measures:

“Presumably more up-to-date indicators are available through the US-CERT secure portal. This is another reason for potential targets to request access to the US Cert Secure Portal.”

Dale Peterson from DigitalBond started the twitversation from there noting that “we were told portal access is limited to asset owners”. I don’t know who the US-CERT allows to have access to their secure portal (I have not applied as I would almost certainly be turned down not being an owner or security professional, just a gadfly), but I replied “DHS ought to be fairly broadly defining 'asset owners'”.

I then made the more than a little sarcastic comment that folks in the ICS security business probably would not be included because “Ya'll are competitors after all (SAD)”. This touched a perennial sore spot with Dale who does not think that ICS-CERT/INL should be one of his business competitors (I agree).

Dale also asked: “what about integrators, resellers, vendors, industry groups ...”. To which Andy Robinson chimed in: “we are the ones who usually id and fix”. Again these are both important points.

US-CERT Portal

According to the US-CERT web site describes the US-CERT Portal this way:

“The US-CERT Portal provides a secure, web-based, collaborative system to share sensitive, cyber-related information and news with participants in the public and private sector, including GFIRST, the CISO Forum, NCRCG, ISAC members, and various other working groups. Authorized users can visit the US-CERT Portal.”

Access to the secure portal is provided to individuals or organizations that have been approved by various agencies of DHS. The ICS-CERT is apparently an approving agency for the ‘control systems compartment’ of the portal. Send requests for access to: ics-cert@hq.dhs.gov.

I do not personally know what criteria DHS uses to allow access to this portal. I would assume that representatives from critical infrastructure with cybersecurity exposure would be given access. I would hope that ICS-CERT would provide the widest possible access to control system owner.

I am extremely disappointed to hear that organizations like DigitalBond, an internationally recognized control system security company would have been denied access. I would think that it would be in the best interest of industry if security service providers, integrators and vendors were made an integral part of the information sharing community in the US-CERT secure portal. For a very large portion of the industrial control system owner community, these people are the ones that install, maintain and secure industrial control systems.

Why Restrict Access to Information

There are a number of legitimate reasons that the security and intelligence communities need to restrict access to information about control system vulnerabilities and threat information. For many control system applications, for example, there is no easy way for vendors of an application to reach out to the ultimate owners and users of those applications to ensure that they are informed of mitigation measures before a public release of vulnerability information. The ICS-CERT use of the secure portal to make such information available to the affected community before publicly announcing the vulnerability makes good sense.

When a cyber attack is first identified in the wild the cyber intelligence community needs to be able to share information with other potential targets to be able to identify and limit the effects of the attack. Conducting that outreach in a public forum would just ensure that the adversary make changes to their methodology to avoid further detection.

When cyber attack information is developed by private entities (such as F-Secure, Symantec, or CrowdStrike) using proprietary technology or techniques the sharing of that proprietary information would damage the business of those researchers and limit their ability to continue to develop threat information. Protecting information about those techniques and technology is a legitimate way to encourage those companies to continue to share their intelligence information with the government.

Questions about Status of Specific Information

It is easy for someone on the outside (like myself) to criticize government agencies for what information they share or fail to share. By definition we don’t have all of the information about a particular data release (or non-release) to be completely aware of what actually went into the release decision. Still we have a moral obligation to try to hold the officials involved accountable for their actions.

In a perfect world these decisions are made by professionals who have the best access to the information involved and complete understanding of the consequences of the release or restriction of that information. In the real world professionals are called upon to make these decisions on the fly with incomplete information about sources and consequences. And too frequently these decisions are made by professional politicians not security professionals.

From the outside, a good example of questionable information restrictions is the data about the three compromised web sites in the F-Secure report. I understand why a commercial organization like F-Secure would not publish that information; they are protecting themselves against potential libel and slander charges from the owners of the affected sites.

A government agency might take the same action based upon those concerns, but they are much better isolated from such liability claims than would be an organization like F-Secure. However, when ICS-CERT publicly announces that the identity of these sites is available on the US-CERT secure portal it is obvious that they are not trying to avoid litigation from the sites involved. Even the claim that they are protecting F-Secure from such litigation would be hard to accept in light of the public announcement of the information being available.

This is one of those times that it appears that the politicians have made a decision to protect information for a non-security related reason. And as is usual when security decisions are made for political reasons, this decision has put people (control system owners) at risk unnecessarily. This information should be given the widest possible dissemination to allow potentially affected system owners to evaluate their particular risk.

Lack of Cybersecurity Information Sharing Rules

It is situations like this one that illustrate the problem with the lack of information sharing rules for cybersecurity issues. Without a full and complete political discussion about what information should be shared by whom, with whom and under what conditions, the politicians within the executive branch are making these decisions on an ad hoc basis behind closed doors.

Now I understand and agree that the sharing of personally identifiable information is an important concern within the personal liberties community (and that community should be very large and important). How to protect individual information from abuse by large corporations and the government is a very complex and politically sensitive issue.


Fortunately, that portion of the cybersecurity problem is not very prevalent in industrial control system security issues. Perhaps Congress ought to take a first pass at cybersecurity sharing legislation that focuses on the narrow issue of information sharing about industrial control system security issues. This would allow that very important part of the security problem to be addressed and would allow the government to work out information sharing protocols that could be adopted to the broader cybersecurity problems without putting personal information at risk during the development process.

Saturday, November 16, 2013

Short Takes – 11-16-13

It has been a very busy week at work, so much so that the day-job expanded well into the evening and early-morning hours as well. Here are some brief looks at some of the topics that I might have discussed if more time had been available.

CFATS Delays

While the CFATS program has been back up and running for a month now since the federal funding fiasco ended, they have still not published some things that probably should have been published well before the FFF. These include the presentations from the 2013 CSSS and the 30-day PSP ICR notice. There are also some short term late postings that are of concern; including the stats for the abbreviated October site security plan process and the list of chemicals that might be added to the DHS chemicals of interest list (required by the Chemical Safety and Security EO). It would also have been nice to see a public statement about the recent comparison of the Top Screen list and the EPA’s RMP list to find unreported chemical facilities.

Cybersecurity

There have been a couple interesting running debates in the cybersecurity press and blogosphere. Most are more technical than I am willing to wade into with my opinions, but they really need to be expanded to the non-technical press because they potentially have important consequences in the public realm. One concerns the actual consequences of exploits of the DNP3 vulnerabilities that I have discussed here. Another is the perennial debate about whether we should concentrate our cybersecurity improvement efforts at the device level or at the perimeter.

Cybersecurity Legislation

There has been mention in the mainstream press for about a month now about the imminent offering of several bits of cybersecurity legislation in both houses of Congress. Nothing has been offered yet. While Congress is unlikely to pass anything this year or next, the offering of the legislation would prompt further detailed discussions.

Cybersecurity Framework

I have been unwilling to get into a detailed discussion about the details of the published Cybersecurity Framework because I think the document is largely a waste of paper. There has been an interesting Twittversation (Tweets take less time than blogs, follow me @PJCoyle) on the topic that I have been part of (see #NISTCSF).

Back to Normal

It looks like work is back to a 10 to 11 hour day, so there should be more time for the blog. I still might get a chance to discuss the above topics in more detail as other news allows.

Sunday, October 14, 2012

S 3414 May Still Be Alive - Cybersecurity


Two different news organizations (TheHill.com and RollCall.com) are reporting that Sen. Reid (D,NV) is planning on bringing cybersecurity legislation back to the floor of the Senate when the body returns for their lame-duck session after the election. As I noted in August, Reid can call for reconsideration of the cloture vote on the bill at any time that he feels that he has the votes.

Legislation vs Executive Order


Both articles tie the Reed statement to the recent speech by the Secretary of Defense warning of a cyber Pearl Harbor attack. That statement follows recent news reports that the Administration was consulting with Congress and the business community on possible provisions for an executive order on cybersecurity for critical infrastructure. It seems likely that all of these events are tied together in a plan to provide the government the authority to regulate cybersecurity.

The politics of cybersecurity legislation are complicated. First, the regulatory authority that the Administration claims is necessary to protect this country against cyber-attacks by nation-states, terrorists, or even criminal organizations can only be provided by legislation. An executive order would provide only limited authority to expand regulations in only a few industrial sectors; other sector regulations would have to be based upon voluntary compliance.

Election Calculus


Cybersecurity legislation is clearly not a presidential election issue; neither side has made any attempt to make significant political capital taking a stand on the issue. President Obama is hardly likely to publish an executive order before the election for fear of offending some of his ‘civil liberties’ supporters who object to information sharing provisions supported by the Administration.

The Administration has a slim majority of support in the Senate for S 3414, but not enough as currently crafted to be able to get past a cloture vote. An agreement on allowing votes on some key amendments may change enough votes may provide a 60 vote margin to bring the bill to a vote; a vote that would probably lead to passage of the bill in the Senate. Passage of the bill in the House, as currently written, is almost impossible; the House cybersecurity legislation religiously avoids regulating industry beyond enabling some limited information sharing provisions that require nothing of industry.

The election next month may change the calculus in both bodies of Congress. If Democrats get closer to a supermajority (a clear supermajority does not currently seem to be a possibility) in the Senate, current opposition to S 3414 may be reduced by some departing members wishing to have at least some influence on cybersecurity legislation. If the Republicans, on the other hand gain seats (especially if they break the 50 vote barrier) in the election, the Democrats will have to surrender a lot of their desires to get S 3414 passed. The agreement would have to be for more than just votes on amendments; some of the mandatory provisions would have to be changed to voluntary. Which provisions would have to be changed would depend on the number of new Republicans reporting in January and which Democrats won’t return.

The House is much more complicated. Just about the only thing that will cause a wholesale change in the approach of the Republican leadership is if they lose control of the House in the election. Any other election outcome ensures that the current leadership will at the very least have a veto power over any cybersecurity legislation that heads towards the President. Any lame-duck Senate bill will have to take this into account.

Executive Order


Any effective executive order by President Obama will have to be proceeded by an election win. A President Romney would simply sign an executive order vacating one issued by Obama long before any effective action could be taken under such an order.

An Obama win would still not ensure that an executive order would have much of an effect on cybersecurity. To be effective the administration has to write regulations that have to go through the publish and comment process. This Administration has a poor record of writing regulations, particularly in the homeland security realm. A two-year old executive order harmonizing controlled unclassified information (CUI;  Executive Order 13556) has yet to produce any regulations changing the handling of such information. That regulation would only really affect executive branch politics, not business operations; that should make it an easier sell politically.

The Administration would also have to take into consideration that any regulations that have a substantial effect on business operations would certainly face litigation on the grounds of overstepping federal authority. Even just increasing cybersecurity controls over already regulated industries would certainly face such law suits. Extending such regulations to currently unregulated industries would be a non-starter just because of the threat of law suits. It has been made clear that even information sharing rules are likely to be opposed on privacy and free speech grounds.

Way Forward


There is a possibility that the Obama Administration could craft, with the help of the Republican leadership in the House a minimalist cybersecurity bill modeled on the House passed HR 2096. The House might acquiesce to limited cybersecurity regulations on the electric industry; the one industry that almost everyone has been mentioning as being at risk (shows how ‘everyone’s’ imagination is so limited). If they can get the House Republicans onboard, then they can probably convince the Senate.

One thing that all of the politicians have just about missed in their discussions is that there is a significant difference between IT and ICS cybersecurity. Any bill that really tries to address critical infrastructure cybersecurity must clearly differentiate between the two and write specific requirements for both types of security programs.

Thursday, April 5, 2012

Cybersecurity Legislation Campaign

Congress is home for two weeks dealing with fundraising and constituent services so nothing is ‘getting done’ on the cybersecurity legislation front, at least officially. Looking at happenings in the press it is fairly obvious though that there is a lot of political prep work being done to help grease the way for some sort of legislation in the not so distant future.

Cyber Legislation Outlook


First off there’s a very interesting article over at Politico.com looking at the prospects for the passage of cybersecurity legislation in the coming months. There are two points that I think need to be added to that commentary; first Sen. Reid (D,NV) has been promising imminent cybersecurity legislation consideration in the Senate for over two years now without success and more importantly (for readers of this blog in particular) none of the bills under consideration will have any real impact on control system security issues.

The interesting thing about this article is that it is mostly written from the perspective of the Administration’s interest in cybersecurity legislation with only a few unattributed quotes from GOP congressional staffers and the inevitable quote from Chairman King (R,NY). I don’t know anything about the two authors of this piece but it sounds like the article idea came from someone inside the Administration. Not that this is a shill piece by any stretch, but someone in the executive branch is making sure that the issue stays in the press.

ICS-CERT and the Threat


A second article, this one over at TechWorld.com, continues the current vague-threat reporting from the folks at DHS. This one looks at the infrastructure control systems (water and electric receive the biggest play here) that are ‘under daily cyber attack’. Once again DHS is sounding the alarm without providing much in the way of details.

Even when providing numbers, the information is unactionably thin. For instance the article quotes Sanaz Browarny, chief, intelligence and analysis, control systems security program at DHS, as claiming that of the 17 ‘fly-away’ ICS-CERT responses last year “11 of the 17 incidents were very ‘sophisticated’, signaling a well-organized ‘threat actor’”. In a tech publication one would have liked to see a little more detail about what kinds of systems and attacks were actually involved in the ‘sophisticated’ incidents.

Congressional Legal Analysis


The third article that is of interest to those of us concerned with cybersecurity legislation is a brief piece over at FederalNewsRadio.com. There is not really much in the article besides a link to a Congressional Research Service (CRS) report on some of the legal issues associated with some of the cybersecurity bills currently being considered by Congress. These CRS reports are typically requested by Committee Chairs or Ranking Members as an aid to the deliberation process.

This report was written by five legislative attorneys that work for the CRS. It examines a number of the legal issues that have been raised about the current batch of cybersecurity bills that Congress may actually get around to acting upon during this session. The specific issues include:

• Liability concerns;

• Protecting proprietary and confidential business information;

• Sharing cybersecurity threat information; and

• Preemption issues.

These issue discussions are very interesting and will probably be ignored during Congressional debates. As with most things dealing with legal issues, a good lawyer can argue just about any side of a legal issue. In the final analysis, the only legal argument that really counts is a Supreme Court majority opinion and those can frequently be used to argue both sides of a case.

Moving Forward


Probably the most noteworthy thing about these articles is that there appears to be an effort being made to keep these issues in the public. I kind of suspect that we will be seeing some sort of action on one or more of these bills in the near future. Unfortunately, I don’t think that any of these bills will reach the President’s desk before the first week in November; it’s just too late in a presidential election year for a subject as controversial as this.

Thursday, January 27, 2011

Cybersecurity Legislation in the Senate

Tuesday was the first day for legislation to be introduced in the Senate for the 112th Congress and 187 bills were introduced. This produces the typical backlog for the printing process, but based on the basic information available on Thomas.LOC.gov there were only two bills that might be of interest to the chemical security community; S 21 and S 158. The later is a reauthorization of the Surface Transportation Board (STB) and may contain provisions on rail shipments of TIH chemicals. The former may be the cybersecurity jackpot legislation for this session.

Interestingly this bill was introduced by Sen. Reid (D, NV); that would make the bill important enough. More important though is the fact that both Sen. Rockefeller (D, WV) and Lieberman (I, CT) are co-sponsors of the bill. They had competing versions of cybersecurity legislation last session and the participation of these three important Senators (and five other senior Democrats) probably indicate that this is a compromise version of the various bills from the last session.

The title of the bill is currently an unwieldy description of its general intent: “A bill to secure the United States against cyber attack, to enhance American competitiveness and create jobs in the information technology industry, and to protect the identities and sensitive information of American citizens and businesses”. No way to tell if it addresses control system security, but I would suspect that there will be provisions that will have some affect on the chemical security community.

I’ll be watching for this to be printed.
 
/* Use this with templates/template-twocol.html */