Showing posts with label DIB. Show all posts
Showing posts with label DIB. Show all posts

Monday, April 28, 2025

Review – Committee Hearings – Week of 4-27-25

This week with both the House and Senate back in Washington from their Spring Break, there is a fairly busy hearing schedule. The House will be working on their reconciliation bill. Additionally there will be a cUAS hearing and one markup session of interest in the House. The Senate continues to focus on nomination hearings but also includes a hearing on the defense industrial base cybersecurity.

cUAS Hearing

On Tuesday, the Subcommittee on Military and Foreign Affairs of the House Committee on Oversight and Government Reform will hold a hearing on “Securing the Skies: Addressing Unauthorized Drone Activity Over U.S. Military Installations”.

Markup Hearing

On Tuesday the House Space, Science, and Technology Committee will hold a business meeting that will look at six pieces of legislation. The bills that will be covered here include:

HR 2613 - Next Generation Pipelines Research and Development Act,

HR 1223 - ANCHOR Act, and

HR TBA - Nucleic Acid Standards for Biosecurity Act (will probably be introduced today).

Defense Industrial Base

On Wednesday the Subcommittee on Cybersecurity of the Senate Armed Services Committee will hold a hearing on “To receive testimony on industry views on partnership with the Department of Defense and defense of the Defense Industrial Base”.

 

For more information on these hearings, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/committee-hearings-week-of-4-27-25 - subscription required.


Monday, January 6, 2025

OMB Approves Revised DIB Incident Reporting ICR – 1-3-24

On Friday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a revision of an information collection request from DOD on “DoD's Defense Industrial Base (DIB) Cybersecurity (CS) Activities Cyber Incident Reporting”. This ICR supports the incident reporting requirements of 10 USC 393.

The table below shows the revised burden estimate approved by OIRA:

The revised burden estimate is based upon the actual reporting conducted in 2021, 2022, and 2023.

Wednesday, February 7, 2024

OMB Approves DOD Threat Information Sharing Final Rule

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for DOD on “Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities”. The rulemaking was submitted to OIRA on December 7th, 2023. The notice of proposed rulemaking was published on May 11th, 2023.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“The DIB CS Program currently provides cyber threat information to cleared defense contractors. Proposed revisions would allow all defense contractors who process, store, develop, or transit DoD controlled unclassified information to be eligible for the program and to receive cyber threat information. Expanding participation will allow a broader community of defense contractors to participate in the DIB CS Program and is in alignment with the National Defense Strategy.”

We may see this published later this week in the Federal Register, but it is more likely to appear next week.

Friday, December 8, 2023

DOD Sends DIB Cybersecurity Final Rule to OMB

Yesterday, OMB’s Office of Information and Regulatory Affairs announced that it had received a final rule from the Department of Defense on “DOD Sends DIB Cybersecurity Final Rule to OMB”. The notice of proposed rulemaking (NPRM) for this action was published on May 3rd, 2023.

According to the Fall 2023 Unified Agenda entry for this rulemaking:

“The DIB CS Program currently provides cyber threat information to cleared defense contractors. Proposed revisions would allow all defense contractors who process, store, develop, or transit DoD controlled unclassified information to be eligible for the program and to receive cyber threat information. Expanding participation will allow a broader community of defense contractors to participate in the DIB CS Program and is in alignment with the National Defense Strategy.”

That Unified Agenda entry includes the following risk statement:

“Threats to unclassified information systems represent a risk of compromise of DoD information and mission. This threat is particularly acute for  small and medium size companies with less mature cybersecurity capabilities. Through collaboration with DoD and the sharing with other contractors in the DIB CS Program, defense contractors will be better prepared to mitigate the cyber risk they face today and in the future.”

Saturday, October 14, 2023

CRS Reports – Week of 10-7-23 – Defense Industrial Base

The Congressional Research Service published a report on “US Defense Industrial Base: Background and Issues for Congress”. The document summary explains:

“The DIB encompasses a wide variety of entities, including commercial firms operated on a for profit basis, not-for-profit research centers and university laboratories, and government-owned industrial facilities. It provides everything from large, technologically sophisticated weapons platforms (e.g., nuclear submarines) and highly specialized operational support (e.g., intelligence analysis) to general commercial products (e.g., laptop computers) and routine services (e.g., information technology support). By supplying and equipping the armed services, the DIB enables the United States to execute national strategy and develop, maintain, and project military power.”

There is a minor cybersecurity mention in the discussion on Supply Chain Resilience, particularly in regards to the “proliferation of counterfeit items (particularly for microelectronics)”, but the report provides little focus on those issue, completely missing, for instance, any discussion about the impact of the DOD’s Cyber Security Maturity Model certification process. Instead the report focuses on overseas sourcing and domestic content issues.

Thursday, March 30, 2023

OMB Approves DOD DIB Cybersecurity NPRM

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a DOD notice of proposed rulemaking (NPRM) for “Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities”. The NPRM was submitted to OIRA on December 7th, 2022.

According to the Fall 2022 Unified Agenda entry for this rulemaking:

“The DIB CS Program currently provides cyber threat information to cleared defense contractors. Proposed revisions would allow all defense contractors who process, store, develop, or transit DoD controlled unclassified information to be eligible for the program and to  receive cyber threat information. Expanding participation will allow a broader community of defense contractors to participate in the DIB CS Program and is  in alignment with the National Defense Strategy.”

That entry further notes:

“Participation in the voluntary DIB CS Program enables DoD contractors to access Government Furnished Information and collaborate with the DoD Cyber Crime Center (DC3) to better respond to and mitigate cyber threats. In order to join the DIB CS Program, there is an initial labor burden to apply to the program and provide point of contact information which is estimated to take 20 minutes per company. In addition, there is a cost for defense contractors to voluntarily share cyber indicator information. DoD estimates that each response will take a respondent two hours to complete. The costs are under review as part of 0704-0489 and 0704-0490. For DIB participants, this program provides cyber threat information and technical assistance through analyst-to-analyst exchanges, mitigation and remediation strategies, and cybersecurity best practices in a collaborative environment for participating companies.”

This NPRM will probably be printed in the Federal Register next week.

Friday, December 9, 2022

DOD Sends Industrial Base Cybersecurity Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from DOD for “Department of Defense (DoD)-Defense Industrial Base (DIB) Cybersecurity (CS) Activities”. This rulemaking would expand the DIB threat information sharing activities.

According to the Spring 2022 Unified Agenda entry for this rulemaking:

“The DIB CS Program is currently only permitted to provide cyber threat information to cleared defense contractors, per the Program eligibility requirements within 32 CFR part 236. However, this proposed revision to the Federal rule would allow all defense contractors who process, store, develop, or transit DoD CUI to be eligible to participate and begin receiving critical cyber threat information. Expanding participation in the DIB CS Program is part of DoD’s comprehensive approach to collaborate with the DIB to counter cyber threats through information sharing between the Government and DIB participants. The expanded eligibility criteria will allow a broader community of defense contractors to participate in the DIB CS Program, in alignment with the National Defense Strategy.”


Tuesday, September 6, 2016

OMB Receives DOD Cybersecurity Info Sharing Rule

On Saturday the OMB’s Office of Information and Regulatory Affairs (OIRA) had received from the DOD a final rule mandating cybersecurity incident reporting by covered organizations in the Defense Industrial Base (DIB). This rule will modify the interim final rule published on this topic in October of last year.

According to the Spring 2015 Unified Agenda listing for this rulemaking:

“DoD is revising its DoD-Defense Industrial Base (DIB) Cybersecurity (CS) Activities regulation to mandate reporting of cyber incidents that result in an actual or potentially adverse effect on a covered contractor information system or covered defense information, or on a contractor’s ability to provide operationally critical support, and modify eligibility criteria to permit greater participation in the voluntary DoD-(DIB) (CS) information sharing program. The rule also revises the program's definitions to better harmonize with definitions that are already established and used by DoD and other Government agencies in similar contexts and modifies eligibility criteria to permit greater participation in the voluntary DoD-DIB CS information sharing program.”


This rulemaking is only directly applicable to DIB organizations who already have tighter cybersecurity reporting requirements than general industry because of their requirements to protect DOD classified and sensitive but unclassified information. If Congress ever mandates cybersecurity incident reporting requirements for other segments of the economy, this rule would probably serve as a model for any subsequent rulemaking.

Monday, November 18, 2013

Cyber Attack Emergency Services

There is an interesting article over at SCMazazineUK.com about the establishment of an emergency response service for cybersecurity events. It isn’t really a unitary service, but rather a certification process for private sector organizations that provide the service. This “service” is for organizations in the UK, but there is no reason that such a service couldn’t be established here. This is a quick look at some of the thing that would have to be included in the certification process for such a service here in the US.

CFATS Customers

There are two different types of regulated organizations that might use this service that would require additional certification verifications before they could use the offered services; chemical facilities regulated under CFATS and defense industrial base organizations. Both types of organizations would almost certainly require personnel surety vetting of any investigators allowed access to covered computer systems.

Any computer system that has been identified as a critical system under a chemical facility’s site security plan {and this would almost certainly include any control system used in the manufacture or handling of DHS chemicals of interest (COI)} would be covered under the requirement for a background check. CFATS rules require that anyone with unaccompanied access to a critical system has to undergo a background check including vetting against the Terrorist Screening Database (TSDB).

I would argue that any access to a covered control system (or information system for that matter), especially the level of access required for an emergency response to an attack on such a system, would have to be considered ‘unaccompanied’ even if a control system engineer was sitting right beside the cyber-responder the whole time he had access to the system.

Access to an information system at a CFATS facility that contained information about the CFATS program implementation would also require that anyone given access to that system would have to be certified by DHS for access to Chemical-Terrorism Vulnerability Information (CVI). This could be avoided if all CVI information were held on a non-networked computer.

DIB Customers

Many defense industrial base organizations store or have access to classified information. Any computer systems that house such information would require a security clearance to access. It could also be argued that systems that contained sensitive unclassified information would require special vetting of personnel before they were given access to such systems.

ICS-CERT

For the control system side of things, this is the type thing that the ICS-CERT flyaway teams routinely do. Of course there are a number of private organizations that do similar work and I am not sure that we can continue to justify this work by ICS-CERT in view of that fact. I know that there have been some objections raised about the ‘unfair’ competition provided by ICS-CERT. Additionally, the ICS-CERT team is relatively small and I doubt that it could handle any significant increase in taskings for this type of response.

I would assume that ICS-CERT teams do have the requisite clearances to handle the DIB cases, though I would suspect that there is a DOD team that would handle this type of activity for DOD associated organizations.

I would be surprised if the ICS-CERT people were not already vetted in a manner that would be acceptable to the folks at ISCD for CFATS covered facilities. For CFATS related organizations I might suggest that ISCD and ICS-CERT establish an MOU that would specifically allow CFATS facilities to contact ICS-CERT for suspected control system attacks without the need for worrying about vetting the flyaway team for unrestricted access to those control systems.

Existing Private Vendors

It would be interesting to hear from any vendors currently working in the emergency cyber response business to see what they are currently doing in regards to documenting the vetting of their personnel for customers or potential customers in the CFATS program of the DIB program.
 
/* Use this with templates/template-twocol.html */