Showing posts with label EO 13636. Show all posts
Showing posts with label EO 13636. Show all posts

Friday, April 18, 2014

Reader Questions – CSF Notifications

Yesterday I had two interesting questions posed to me about my post on the DHS designations of cyber dependent critical infrastructure.

First on TWITTER® from Aristotle Tzafalias - “Know of any non ‘Cyber dependent’ (as defined in prev) CI?”

And then on my blog from an anonymous reader - “Any thoughts on what sectors (and representative companies) make up the greatest representation?”

Both are important questions for homeland security reasons and I won’t be able to answer either definitively because DHS will not be disclosing either their list of ‘Critical Infrastructure’ facilities nor of their ‘Cyber Dependent Critical Infrastructure’ (CDCI) facilities for security reasons. That won’t, of course, stop me from offering my thoughts on the matter.

Critical Infrastructure

There are a number of variations of the basic definition of ‘critical infrastructure’ that are in current use. To make things easy let’s stick with the one found in §2 of the President’s executive order on Improving Critical Infrastructure Cybersecurity (EO 13636):

“As used in this order, the term critical infrastructure means systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

With the large number of undefined terms in that sentence it is obvious that there is a wide leeway for determining what is or is not ‘critical infrastructure’. In the narrowest sense I can think of only a single entity, the New York Stock Exchange, whose incapacity or destruction would have a debilitating effect on national economic security.

If we look at ‘systems’ however, there are a much wider variety of systems that would fit the bill. These could include the electric grid, fuel distribution systems, communications systems. In fact, the President has identified 16 critical infrastructure sectors of the economy that would meet a broad definition of critical infrastructure. Again, it is hard to imagine that the failure of any single entity within those sectors would meet the definition of critical infrastructure by themselves, but a limited number of individual failures within a sector could certainly have debilitating effects on the national economy or security.

I think that a reasonable supposition about how DHS has gone about determining which facilities are to be considered critical infrastructure would be those facilities that, if more than a couple failed at about the same time, there would be debilitating consequences for the national security or national economy. I think that most reasonable people would agree that this type of methodology would be the most usable way of designating critical infrastructure.

Cyber Dependent Critical Infrastructure

Aristotle raised an interesting question in his TWEET®; in today’s age isn’t everyone ‘cyber dependent’? To a certain extent this is true, but some sectors rely on cyber-systems more heavily than others. The ‘Information Technology Sector’ certainly relies more on their computers than does the ‘Dams Sector’, but no sector could long survive with their various electronic systems not functioning.

Using the broadest interpretation of the definition provided in yesterday’s Federal Register notice I would be hard pressed to think of any organization that would not be considered ‘cyber dependent’. And if DHS used that broad sweep to include all critical infrastructure, then the whole point of the exercise was lost. Section 9(a) of the EO required DHS to “use a risk-based approach to identify critical infrastructure where a cybersecurity incident could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security” [emphasis added].

So, instead of a complete loss of computer systems, DHS should have been looking at more limited incidents at these facilities that could result in ‘catastrophic’ effects. To be sure this would be a much more difficult standard to parse as DHS does not have a lot of internal information about most of these organizations and their systems. And again, even considering potential regional effects, there are very few facilities where a single cyber incident would cause catastrophic effects, so we should clearly expect that DHS would consider facilities where just a few related facilities affected by similar and concurrent attacks would cause catastrophic effects.

Now in my opinion, you are looking at just three types of facilities, the national stock exchanges, the electrical distribution system and fuel distribution pipelines. The remaining sectors have too much redundancy to be catastrophically disrupted by any reasonable set of cyber incidents. There could be economic disruptions in all sectors, but few that would even approach catastrophic on a regional or national basis.

Chemical Catastrophes

It might seem strange that I do not include the chemical sector or at least chemical facilities storing large quantities of toxic inhalation hazard (TIH) chemicals in the list of cyber dependent critical infrastructure. After all, we continue to hear organizations like Green Peace insist that a catastrophic release at many of these facilities could result in deaths of hundreds of thousands of people. Wouldn’t that be a catastrophe on a regional or national scale?

It certainly would, but I would have a hard time positing a reasonable cyber incident that would result in a catastrophic release of one of these chemicals. A release yes, even a release that resulted in off-site casualties; certainly. But not a catastrophic release of the scale discussed by these organizations (and to be fair by me here in this blog), that would take a failure of the physical structure of the tank. A cyber incident could, at most, result in a valve being opened to the atmosphere that would take dozens of hours to release the total contents to the atmosphere. Long before that happened, manual efforts to close the line would be successful.

What about water system contaminations like we saw in Charleston, WV? While the Freedom Spill was certainly disruptive, even severely disruptive, to the lives of the folks that live in that area, it was hardly a catastrophe. But let’s assume that the definition of ‘catastrophe’ was wide enough to encompass that scale of disruption. I would be hard pressed to define a ‘reasonable’ cyber incident that would cause that type of problem. You would have to find an upstream facility that held a chemical that would not be removed by the municipal water treatment facility and find a way to electronically release that chemical in a way that bypassed existing secondary containment. You could not have done it at Freedom Industries; their tank valves were all manually operated.

There may certainly be facilities where this could be done. Identifying them would be very difficult for DHS and nearly impossible for anyone else but an insider. I’m certainly not saying that DHS or EPA shouldn’t be looking at this, but it wouldn’t be part of the cybersecurity program; at least not initially.

What Has Actually Been Done?

So that is my take on the limitations of the cyber dependent critical infrastructure designations covered by this notice. How closely does that track with reality? I haven’t the foggiest idea, DHS is keeping this information fairly closely held; they certainly are not discussing it with me.


I would guess that they are using a wider set of criteria than those that I have describe above. There is a certain bureaucratic incentive to broadly define the problem. The more facilities that are designated CDCI the more responsibility that DHS has for their oversight and assistance. So I would guess they include many more, and different types of, facilities than I have described. Which ones and how many? I just have no way of knowing.

Wednesday, March 12, 2014

GSA Publishes Cybersecurity RFI

Today the GSA’s Office of Mission Assurance (OMA) published a request for information (RFI) notice in the Federal Register (79 FR 14042) about recommendations that GSA and DOD have made to the President in response to §8(e) of the President’s Executive Order for Improving Critical Infrastructure Cybersecurity (EO 13636). Long time readers may remember a series of blog posts I did about the GSA’s original RFI that supported the preparations for the report about which this RFI is seeking comments.

The actual DOD/GSA report is on the GSA’ EO 13636 web site.

NOTE: There is a problem with the SSL certificate for this site so it is not a secure web site, even though it has ‘https’ in the URL. The Feds certainly seem to have problems maintaining their certificates. Could this be the sign of a cybersecurity problem???

GSA is seeking comments on the six recommendations made in that report so that they can formulate a plan to go forward. The six recommendations are:

• Institute baseline cybersecurity requirements as a condition of contract award for appropriate acquisitions;
• Address cybersecurity relevant training;
• Develop common cybersecurity definitions for Federal acquisitions;
• Institute a Federal acquisition cyber risk management strategy;
• Include a requirement to purchase from original equipment manufacturers, their authorized resellers, or other ‘trusted’ sources, whenever available, in appropriate acquisitions;
• Increase government accountability for cyber risk management.

Most of these seem to be the cybersecurity equivalent of motherhood and apple pie requirements, but the devil is, of course in the detail. There is a lot of verbiage supporting each of these recommendations that deserve a closer look. I’ll add it to my list of things to look at since this may be a harbinger of cybersecurity requirements in other acquisition processes, in and out of the Federal government.


GSA is soliciting public comments. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # OMA-2014-01). Comments need to be submitted by April 28th, 2014. Please note that that is a short, 45 day comment period.

Monday, July 22, 2013

Congressional Hearings – Week of 7-21-13

There are only three House hearings and one Senate hearing that might be of specific interest to the chemical safety/security and cybersecurity communities. They involve a TSA markup, a rule for two spending bills, a transportation bill and a cybersecurity bill. A WMD bill will also be considered on the floor of the House.

Spending Bills

The House Rules Committee will meet this evening to try again to formulate a rule for the consideration of HR 2610 (FY 2014 DOT spending bill) and HR 2397 (FY 2014 DOD spending bill). The big holdup here is the question of whether or not to have an open rule (which the Republican leadership has made the norm for spending bills) for the DOD bill. There is a great deal of concern about an amendment defunding the NSA over the recent cyber-snooping disclosure about that agency.

Apparently there has been a resolution as to handle the DOD bill because the Majority Leader’s web site reports that HR 2397 will be considered this week.

TSA Markup

The Subcommittee on Transportation Security of the House Homeland Security Committee will be holding a markup hearing on Wednesday. One of the bills to be considered will be HR 1204, the Aviation Security Stakeholder Participation Act of 2013.

Transportation

Friday there will be a field hearing in New York City by the House Transportation and Infrastructure Committee’s Panel on 21st Century Freight Transportation looking at “How Freight Transportation Challenges in Urban Areas Impact the Nation”. There is no witness list yet available so it is hard to tell what might be discussed. Always a possibility is the issue of the risk of hazmat trains transiting urban areas.

Cybersecurity

The Senate Commerce Committee will be holding a hearing on Thursday looking at “The Partnership Between NIST and the Private Sector: Improving Cybersecurity”. This should be another feel good hearing about the Cybersecurity Framework being developed by NIST under the President’s Cybersecurity EO (EO 13636). No witness list is yet available, but we can expect to see the NIST Director.

WMD Intelligence


There will also be a House floor vote on HR 1542, the WMD Intelligence and Information Sharing Act of 2013. This bill will be considered under suspension of rules so there will be no floor amendments allowed. There was no committee markup of this bill so there was no chance to add the industrial chemical amendment that I suggested. This bill will pass in a bipartisan vote later today.

Thursday, June 27, 2013

DHS Announces NIAC Meetings for July, August and September

Today DHS published a meeting notice in the Federal Register (78 FR 38723-38724) establishing public meeting dates for the National Infrastructure Advisory Council for the next three months. Those meeting dates are:

• July 17th, 2013;
• August 14th, 2013; and
• September 17th, 2013.


The general agenda for all three meetings will be nearly identical. The Department will update the Council on the status of the implementation of the Cybersecurity Executive Order (EO 13636) and Presidential Policy Directive 21. The Council will then discuss that implementation and provide their recommendations on how to proceed. A more detailed agenda for each meeting will be published on the NIAC web site no later than one week before the scheduled meeting.

Saturday, June 15, 2013

NIST Publishes 3rd Workshop Agenda

Earlier this week the National Institute of Standards and Technology (NIST) published the preliminary agenda for their 3rd workshop on the development of the Cybersecurity Framework required by the President’s cybersecurity executive order (EO 13636). There is also a link on the Workshop web page to the registration site for the meeting.


The agenda is very preliminary; it just lists the opening ‘plenary session’, ‘working session’ and the closing ‘plenary – discussion of next steps’. The site promises to have all the preliminary details (probably including a draft document) on the site by June 28th.

Saturday, May 4, 2013

DHS ITF Establishes Collaboration Community


DHS has once again partnered with IdeaScale to establish a ‘collaboration community’ to help the DHS Integrated Task Force in the implementation and the coordination of interagency, and public and private sector efforts to support the President’s Executive Order on Improving Critical Infrastructure Cybersecurity (EO 13636). Patterned on previous IdeaScale campaigns on the National Dialogue on Preparedness and the Quadrennial Homeland Security Review, the Integrated Task Force Collaboration Community (ITFCC) allows for public input and discussion of proposals associated with EO 13636 implementation.

DHS is not being real proactive in publicizing this ITFCC. I have seen a single TWEET® on the topic and nothing else. That might explain why there are only four ideas currently on the page after being up for at least a week (that’s the date on the initial suggestion).

Topics

There are three different topic about which the site is soliciting public ideas. They are:


Only the third topic has an extensive explanation of what is being sought. It is also the only topic page that specifically mentions one of the working groups from the ITFCC; Evaluation and Planning Workgroup. They explain that they have already conducted focus group analysis and have come up with a four part purpose of the development of a public-private partnership for the implementation of the EO. Those parts are:

• Evaluate and address critical infrastructure risk through public-private collaboration and collective action across the national preparedness spectrum to prevent, protect against, mitigate, respond to, and recover from all hazards.
• Define and address national priorities for all-hazards critical infrastructure security and resilience through the bidirectional sharing of relevant and actionable information and the identification and exchange of best practices, tools, capabilities, and resources.
• Build and sustain trust, leverage existing, and develop new relationships to ensure the continued maintenance and growth of the partnership.
• Work collaboratively to identify and mitigate organizational and structural barriers to entry to facilitate increased participation by State, local, and private sector stakeholders in regions across the Nation.

Participation

This is a public participation discussion site, open to all comers. To publish new suggestions, make comments, or vote upon on existing suggestions you have to be registered with IdeaScale. People who registered on the two earlier DHS discussions can still use that registration ID and password.

I don’t see a ‘registration’ tool or button, but if you try to vote, make a suggestion, or comment on an existing suggestion you will be prompted to either sign in or register. It has been  a couple of years since I registered on IdeaScale, but I seem to recall that you have a wide latitude in the information that you provide or fail to provide to the site. I can’t vouch for the whole site security thing, but it does provide some fair level of anonymity on the public side if you so desire.

Current Comments

As I mentioned earlier there are only four comments currently posted on the board. They are (in order of current vote totals; highest to lowest):


The first three are glittering generalities that fall into the general ‘motherhood and apple pie’ category. The last is a little more specific but not really directed at cybersecurity concerns. This is one of the problems with these public comment/suggestion exercises; there are very few concrete proposals and more than a few that trend off-topic. Oh well, searching for gems is like that.

Currently there are no comments that directly apply to industrial control system security efforts. I will, however, continue to monitor and report upon this site.

Wednesday, March 6, 2013

NIST-NPPD Cybersecurity MOU


Thanks to a note from Bob Radvanovksy over on SCADASEC-L mailing list, I found a copy of the memorandum of understanding (MOU) between NIST and DHS NPPD about the cooperation between the two organizations in the development and implementation of the Cybersecurity Framework. It was signed the responsible Under Secretaries from DHS and Commerce the day the President publicly released his executive order.

The details of who provides assistance to whom are pretty straightforward, even couched in bureaucratese. Both will provide a person to work in the other’s office to act as a coordinator. There will be all sorts of consulting and coordinating going on. If you’re interested in how these two agencies are going to be working together to get the EO in actual operation, this is worth the read.

Handoff of Develop to Implement

One of the things that is hopeful here is that there seems to be a clear understanding that there is a difference between developing the Framework and implementing it. I was more than a little concerned that two different organizations from different bureaucratic cultures would be handling the two side of this program; particularly since the first common point in their respective chains-of-command is the President.

NIST promises to provide “technical expertise ot NPPD regarding the application of NIST-developed standards, guidelines, and frameworks; detection and handling of information security incidents, development of cybersecurity vulnerability assessments; and security automation” (pg 2).

NPPD’s side of the hand off is covered in two separate will consults;

• [O]n the production of bulletins or memoranda pertaining to implementation of standards, guidelines, frameworks or other applicable cybersecurity policies”; and

• [O]n the development of metrics that will be used by Departments and Agencies to measure the effectiveness of cybersecurity programs or identify optimal security solutions”.

One Small Red Flag

There is potential for problems in one of the areas where NPPD outlines its support responsibilities for the development of the Framework. At the bottom of page 2 NPPD promises to:

“Provide relevant information, including analyses, priorities, sector specific plans, vulnerability assessments, and reports on operational aspects of Federal agency cybersecurity, consistent with NPPD information sharing policies [emphasis added], to assist NIST in the development of information security standards, guidelines, and frameworks.”

I know that politicians are constitutionally incapable of committing to anything without caveats and exemptions and this MOU is no exception. But, having said that, the development of the Framework is such an important part of this program that the holding back of information because of intra-governmental information sharing policies could kill the effectiveness of the EO.

Timing Coincidence

One last thing; I do find it very interesting that the MOU between the main players in the President’s new cybersecurity executive order signed this document on the day the President publicly released the EO. Since the drafts that have been circulating since November were almost identical to the finished product, one wonders why the delay in publishing this signature document.

I suspect that it was to allow time for these two agencies to work out their differences and find a way to work together to get the project going in the right direction. If that is the case, this took quite a while for a relatively uncomplicated document. How much time is it going to take to iron out their differences on something like the Framework?

Moving Forward

I’m starting to feel a little better about the ability of NIST to get their preliminary Framework, published, though I am far from confident. The little red flag here still show that they have a number of bureaucratic hurdles to overcome while they are working on a technologically complex task. Few organizations are well suited to handle both.

BTW: The new Cybersecurity Executive Order is never mentioned in this MOU.
 
/* Use this with templates/template-twocol.html */