Showing posts with label EO 13694. Show all posts
Showing posts with label EO 13694. Show all posts

Friday, December 30, 2016

President Amends EO 13694 and Sanctions Russians

Yesterday the President signed a new executive order (number to be published) that amends the existing EO 13694, Blocking the Property of Certain Persons Engaging in Significant
Malicious Cyber-Enabled Activities, that was originally published in April, 2015. This action was taken in response to actions taken by Russian intelligence agencies during the 2016 presidential election cycle.

Amended EO 13694


The amendment of the so called cyber response executive order does three things. It adds an annex {Annex A} to the Executive Order providing a list of specific people to whom the sanctions provided for in the order will apply. Second, it provides a new ‘offense’ for which sanction activities may be applied in the future {1(a)(ii)(E)}. Finally, it provides the Secretary of the Treasury with the authority to remove names from Annex A when “circumstances no longer warrant the blocking of the property and interests in property of a person listed in the Annex to this order” {new Section 10}.

The new annex includes four ranking members of the Russian Main Intelligence Department [GRU], the GRU and the Russian Federal Security Service, as well as two affiliated civilian organizations. Coincidentally, the Treasury Department also named two Russian individuals to the Specially Designated Nationals List (SDN) (the same list to which the persons and organizations in the Annex were added, see pages 356 thru 360 for all of the additions made yesterday) for cybersecurity fraud related issues not related to the election.

The new offense was added as paragraph 1(a)(ii)(E):

Tampering with, altering, or causing a misappropriation of information with the purpose or effect of interfering with or undermining election processes or institutions;

Other Russian Sanctions


The White House also announced two other sets of sanctions against the Russian Government yesterday. First it is expelling 35 Russian diplomats (intelligence officers), giving them and their families 72 hours to leave the country. It is also denying remaining Russian diplomatic personnel access to two Russian owned properties in Maryland and New York.

Officially this action is not related to the reported Russian ‘interference’ in the 2016 election, but it is rather being taken because over the last two years “harassment of our diplomatic personnel in Russia by security personnel and police has increased significantly and gone far beyond international diplomatic norms of behavior”.

Russian reaction to these ‘other sanctions’ is already being reported. CNN reports that the Russians have “ordered the closure of the Anglo-American School of Moscow” (school for the children of English speaking diplomats) and closed “access to the US embassy vacation house in Serebryany Bor, near Moscow”.

Joint Analysis Report


Also yesterday the FBI and US-CERT issued a joint analysis report (JAR-16-20296A) on the election security compromises, code named GRIZZLY STEPPE. This report is supposed to provide the technical support for the claim of Russian intelligence involvement in the hacks of the email systems of the Clinton Campaign and the Democratic National Committee.

While it does not provide any direct evidence of Russian involvement (that information almost certainly remains classified), the report does provide the indicators of compromise that are associated with those hacks. Those indicators include the YARA signature (in the report) and CSV and STIX format files of the indicators available on the GRIZZLY STEPPE web page.

The bulk of the JAR is a listing of mitigation measures that individuals and organizations can take to prevent similar attacks in the future. Unfortunately, there is nothing new here. All of the mitigation techniques should have been well known by the IT people responsible for the systems involved.

Commentary


The other sanctions being directed at diplomats here in the United States is a fairly common game played in the diplomatic community. The people being expelled are known intelligence personnel, almost certainly responsible for classic spying type operations here in the United States. Their expulsion will have some delaying effects on those spying efforts, but no effects of any long-term consequence. The US personnel that will be expelled from Moscow in retaliation will be responsible for similar efforts against the Russians.

It is very likely that the expulsions have nothing to do specifically with the election fiasco. Announcing them on the same day as the EO 13694 actions allows the press to conflate the two-separate sanctions, making the EO 13694 sanctions seem more effective. The freezing of assets under EO 13694 may have some effect on the individuals and organizations listed, but only if they have clearly identified assets in the United States. Even that effect will be minimized, if/when the individuals are ultimately removed from the Annex A list.

Congressional leaders on both sides of the fence are saying essentially; about time, but too little too late. I’m not sure what the politicians want (other than blood?). I guess the CIA and NSA could hack the political emails of Putin cronies and leak them to the Russian press. I don’t suspect, however, that they would get the same play in Russia as we saw in the US press during the election.

That is the big point that is being lost here. There is nothing really new here in the hacks of the political emails; that is espionage, pure and simple. Intelligence agencies sharing that information with the press is unusual, but not unprecedented. Of course, if it had been ‘Deep Throat’ sharing the emails it would not have caused nearly the stir.

What was unprecedented was the huge amount of play that the American press gave the leaked emails, even when it was patently clear that it was a foreign intelligence agency responsible for the leak. If the press had not spent so much time talking about the petty squabbles and indiscretions of the party and campaign officials (and there was nothing new there in the level of squabbles or seriousness of indiscretions) then this whole thing would have been a non-issue that these sanctions would have been more than appropriate to deal with.


Unfortunately, we have not heard the last of this.

Thursday, December 31, 2015

OFAC Publishes Final Rule on Cybersecurity Sanctions

The Treasury Department’s Office of Foreign Assets Control (OFAC) published a notice in today’s Federal Register (80 FR 81752-81759) implementing the President’s Executive Order on Blocking the Property of Certain Persons Engaging in Significant Malicious Cyber-Enabled Activities (EO 13694). According to the notice OFAC is publishing the regulations (new 31 CFR 578) ‘in abbreviated form’ for the purpose of providing immediate guidance to the public.

Since OFAC proceeded directly to a final rule in this matter this notice is missing much of the analysis that one normally finds in final rules. The Treasury maintains that since this rule involves a ‘foreign affairs function’ neither the notice and comment process nor does the Regulatory Flexibility Act. The Department reportedly has rolled the information collection request (ICR) requirements for this rule into an existing collection under 31 CFR 501 (RIN 1505-0164) though there is not currently a record on the OMB’s Office of Information and Regulatory Affairs web site of an update to that IRC for this rule.

The new §578 contains 7 Subparts that pretty much reflect the Subparts in other sanctions regulations. In fact, many of the definitions and other materials are direct copies from the other sanction regulations, and this is probably to be expected and perhaps necessary to maintain an effective sanctions program.

In fact, as you read through this rule, there is nothing in it that refers to anything cyber related beyond the basic reference to EO 13694. The designation of the affected ‘certain persons’ is done completely under EO 13694 and is thus beyond the scope of this rulemaking.


OFAC is not soliciting public comments on this final rule. The effective date for this rule is today; December 31st, 2015.

Thursday, April 2, 2015

EO 13694 Published


Today the Office of the President published EO 13694 in the Federal Register (80 FR 18077-18079). This is the Executive Order on cyber-attack response that I described yesterday. This was published a little faster than normal, but I am not sure that that is really indicative of anything.

There are no regulatory actions required under this EO though the Secretary of the Treasury is authorized to issue regulations. I suspect that there will be some sort of regulations promulgated at some point in time.

In the past 24 hours there has been some serious internet discussion about the implications of this EO on the international cybersecurity research community. While this may be just a bit of normal paranoia there is some legitimate concern that the broadly defined scope of action that justifies retaliation could be used to stifle publication of cybersecurity research. While I don’t think that that concern is immediately justified, in the long term there is always the possibility that the provisions of this EO could be used in that manner.

That is one of the problems with executive orders. There is none of the public political give and take, discussion and reworking of the specifics of the requirements that serves as a limitation on the scope of retaliatory actions. This is especially true when there is no specific requirement to keep Congress, the Courts or the public informed about actions taken under this authority.


The other side of that coin is that there is no legal requirement to implement the policies outlined in the EO. This could just as easily sit unused as anything more than a feel-good statement of intent to do something about an apparently intractable problem. I don’t think that it will be, but it is always possible.
 
/* Use this with templates/template-twocol.html */