Showing posts with label Electric Grid Security. Show all posts
Showing posts with label Electric Grid Security. Show all posts

Tuesday, July 24, 2018

S 3153 Introduced – FY 2018/19 Intel Authorization


Last month Sen. Burr (R,NC) introduced S 3153, the Matthew Young Pollard Intelligence Authorization Act for Fiscal Years 2018 and 2019. Both the bill and the accompanying Committee Report pay special attention to control system security issues.

Energy Sector Cybersecurity


Section 732 of the bill would require the Secretary of Energy to establish a 2-year pilot program to study control system security in the energy sector. The pilot program would be funded at $10 Million for the 2-year study. This section is essentially the same as S 79 which was reported in the Senate earlier this year by the Energy and Natural Resources Committee.

ICS Security and the Intelligence Community


On page 17 of the Committee Report, the matter of industrial control system security is directly addressed. The Report notes:

“The Committee is aware of significant threats to our critical infrastructure and industrial control systems posed by foreign adversaries. The sensitive nature of the information related to these threats make the role of the IC of vital importance to United States defensive efforts. The Committee has grave concerns that current IC resources dedicated to analyzing and countering these threats are neither sufficient nor closely coordinated. The Committee includes provisions within this legislation to address these concerns.”

Section 732 of the bill (described above) is the only place that I can find in the unclassified portions of the bill and annexes that directly mentions activities related to ICS security.

Moving Forward


The House passed HR 6237, the House version of this bill earlier this month. While the House bill did receive a large measure of bipartisan support, the Senate will still take up this version of the bill as an amendment to HR 6237 when it comes to the floor of the Senate. I expect that to happen sometime after the Senate returns from the abbreviated summer recess next month. There will be some contentious political amendments offered for the bill when it makes it to the floor, but eventually a version of the bill will be passed and then a conference committee will meld the two versions together into a workable whole.

Commentary


It is interesting to see the language from S 79 appear in this bill. Sen. King (I,ME) has been trying to get this bill to move forward through two sessions of Congress now, so it is not unexpected that he would use his position on the Intelligence Committee to try to advance the bill when it was apparently stalled after being approved in the Energy and Natural Resource Committee.

The association between this bill and the intelligence community is vague to say the least. The working group to be established would be under the Department of Energy which does have some tenuous ties to the IC, but that has been mainly in support of nuclear weapons program, not power generation. King has always included a representative of the IC in the working group {§732(c)(2)(F) in this bill}, but that always seemed to me to be a pro forma inclusion as a source of information rather than an actual participant.

It will be interesting to see where the funds come from to support this program. If they come out the intelligence spending bill, then I expect that the role of the IC will be much more important in the activities of the working group and the resulting study.

One political fact is certain however. Since the authorization for the program (if it makes it to the final bill that reaches the President’s desk) comes from the Intelligence Committee, it will be that Committee (and it’s House counterpart) that will provide the oversight for the program, that alone will color many of the decisions made as the program proceeds.

Monday, October 30, 2017

HR 4120 Introduced – ICS Research

On Wednesday Rep. Bera (D,CA) introduced HR 4120, the Grid Cybersecurity Research and Development Act. The bill would provide for a comprehensive interdisciplinary research and development initiative to strengthen the capacity of the electricity sector to neutralize cyberattacks.

Definitions


Section 3 of the bill provides the working definitions for the bill. Since this is a stand-alone bill (not amending existing legislation) these definitions are very important. The terms include:

• Critical electric infrastructure information – uses definition from 16 USC 824o-1 (incorrectly printed in the bill as ‘824a-1’);
• Cybersecurity – “means a set of preventative measures to protect information from a digital device or system, including a device or system used to manage the electric grid, from being stolen, compromised, or used to carry out an attack” {§3(2)};
• Human factors research – “means research on human performance in social and physical environments, and on the integration of humans with physical systems and computer hardware and software” {§3(5)};
• Human-machine interface – “means technologies that present information to an operator about the state of a process or system, or accept human instructions to implement an action, including visualization displays such as a graphical user interface” {§3(6)}; and
• Transient devices – “means removable media, including floppy disks, compact disks, USB flash drives, external hard drives, mobile devices, and other devices that utilize wireless connections for limited periods of time {§3(8)}.

Energy Cybersecurity R&D


Section 4 of the bill requires the Secretary of Energy, in coordination with a variety of federal, state and local agencies and private sector groups, to “carry out a research, develop23
ment, and demonstration initiative to harden and mitigate the electric grid from the consequences of cyber attacks by increasing the cybersecurity capabilities of the electricity sector and accelerating the development of cyberse curity technologies and tools” {§4(a)}. It specifically identifies responsibility to carry out activities to {§4(b)}:

• Identify cybersecurity risks to the communication and control systems within, and impacting, the electricity sector;
• Develop methods and tools to rapidly detect cyber intruders and cyber incidents, including the use of data analytics techniques to validate and verify system behavior using multiple data streams reflecting the state of the system;
• Assess emerging energy technology cybersecurity capabilities, and integrate cybersecurity features and protocols into the design, development, and deployment of emerging technologies, including renewable energy technologies;
• Develop secure industrial control system protocols and identify vulnerabilities in existing protocols;
• Improve the physical security of communication technologies and industrial control systems, including remote assets;
• Integrate human factors research into the design and development of advanced tools and processes for dynamic monitoring, detection, protection, mitigation, and response;
• Advance the capabilities and use of relevant interdisciplinary mathematical and computer simulation modeling and analysis methods;
• Evaluate and understand the potential consequences of practices used to maintain the cybersecurity of information technology systems on the cybersecurity of industrial control systems;
• Increase access to and the capabilities of existing cybersecurity test beds to simulate impacts of cyber-attacks on industrial control system devices, components, software, and hardware; and
• Reduce the cost of implementing effective cybersecurity technologies and tools in the electricity sector.

Additionally, the Energy Department is specifically tasked with working “with manufacturers to build or retrofit security features and protocols into” {§4(b)(5)}:

• Communication and network systems and management processes;
industrial control and energy management system devices, components, software, firmware, and hardware, including distributed control and management systems and building management systems;
• Data storage systems and data management and analysis processes;
• Generation, transmission, distribution, and energy storage technologies;
• Automated and manually controlled devices and equipment for monitoring or managing frequency, voltage, and current;
• Technologies used to synchronize time and develop guidance for operational contingency plans when time synchronization technologies are compromised;
• End user elements that connect to the grid, and
• The supply chain of electric grid management system components.

Technical Guidance and Standards


Section 5 of the bill addresses support activities required by DOE and other federal agencies in developing and sharing technical guidance documents and standards.

DOE is required to facilitate the updating of {§5(a)(1)}:


DOE is also required to develop voluntary guidance to improve forensic analysis capabilities to include {§5(a)(2)}:

• Developing standardized terminology and monitoring processes;
Identifying minimum data needed; and
• Utilizing human factors research to develop more effective procedures for logging incident events; and
• Developing a mechanism to anonymize, aggregate, and share the testing results from cybersecurity industrial control system test beds to facilitate technology improvements by public and private sector researchers.

DOE and the National Institute of Standards and Technology (NIST) are tasked with developing voluntary, consensus-based standards to improve cybersecurity for {§5(c)(1)}:

• Emerging energy technologies;
• Distributed generation and storage technologies, and other distributed energy re24
sources;
• Electric vehicles; and other technologies and devices that connect to the electric grid that can affect voltage stability.

Vulnerability Testing


Section 6 of the bill requires DOE to work with owner/operators and the national laboratories to {§6(a)}:

• Utilize a range of methods, including voluntary vulnerability testing and red team-blue team exercises, to identify vulnerabilities in physical and cyber systems;
• Develop cybersecurity risk assessment tools and provide confidential analyses and recommendations to participating stakeholders;
• Work with stakeholders to develop methods to share anonymized and aggregated results in a format that enables the electricity sector, researchers, and the private sector to advance cybersecurity efforts, technologies, and tools;
• Identify information, research, staff training, and analysis tools needed to evaluate industrial control system cybersecurity issues and challenges in the electricity sector; and
• Facilitate the sharing of information and the development of tools needed to evaluate industrial control system cybersecurity issues.

Appropriations


Section 11 of the bill provides the authorization for spending money to support the various programs called for in this bill. It sets the following annual authorization amounts:

$65,000,000 for fiscal year 2018;
$68,250,000 for fiscal year 2019;
$71,662,500 for fiscal year 2020;
$75,245,625 for fiscal year 2021; and
$79,007,906 for fiscal year 2022.

Moving Forward


Bera is a member of the House Science, Space, and Technology Committee to which the bill was assigned for primary consideration. His three cosponsors are also influential Democrats on that Committee. This means that there may be enough influence to have the bill be considered in Committee. The one problem here is that there are no Republican cosponsors of the bill, indicating a potential lack of bipartisan support.

Since no regulatory actions are included (or authorized) by the bill the only thing that will draw any real opposition is the authorized spending. Those monies will have to come from somewhere in the budget and probably from the DOE budget. With money already tight, this will be the major stumbling block that the sponsors will have to overcome to see this bill considered in Committee and move it to the floor of the House.

Commentary


The Committee Staff members that crafted this bill are to be commended on developing a comprehensive energy sector cybersecurity bill. Section 2 of the bill, the Congressional Findings that support the need for the bill, is one of the best non-technical descriptions of the cybersecurity problems facing the electrical grid that I have seen. It includes an appropriately nuanced attention to the differences between information and operational technology and a realistic appreciation of the role of human factors in the problem. Good job.

Having said that, there are a few short comings that need to be addressed. The first is the issue of Critical Electric Infrastructure Information (CEII), the controlled but unclassified information system protecting information shared by the electric grid industry and the Department of Energy. Throughout this bill there are numerous references rightfully reiterating that the information shared by industry with DOE is protected from public disclosure under this program.

There are multiple references in the bill to ‘aggregating and anonymizing information’ as this is the key to ‘sharing’ the information provided under the CEII program. Unfortunately, the federal government does a poor job generally (and I suspect DOE specifically) of sanitizing and sharing restricted information. This may not be a problem within the grid operation community (I don’t have the information necessary to make the assessment), but DOE does not play well with outsiders.

This is a problem here because large amounts of the ICS cybersecurity research and development efforts outlined in the bill could have enormous positive impacts on the remainder of the ICS community. DOE has no incentive, nor even a mechanism, to share this valuable information outside of their regulated community.

This problem is further compounded by the failure to specifically include ICS-CERT in the federal agencies to be included in this development effort. ICS-CERT is the only federal agency with the sole focus on the cybersecurity of industrial control systems. And they have the mechanisms in place to share information with the remainder of the ICS security community.

The other major issue is the lack of attention to the issue of vulnerability disclosures. The bill attempts to address the issue in §6 of the bill, but it only really looks at system testing at the facility level. While this is certainly a valuable part of vulnerability testing, it ignores the much larger issue of the cybersecurity testing of individual components of the control systems done on a daily basis by independent security researchers and relatively small research companies.


Congress needs to come up with a way to incentivize those researchers to share their information with DOE instead of with the other existing organizations that pay researchers for their identified vulnerabilities and then provide the information to paying customers. DOE needs to establish a coordinating mechanism so that vulnerability reports from researchers are coordinated with the vendors and the mitigation measures are reported to the user community. OR the bill could just recognize the already existing mechanisms established by ICS-CERT and provide for priority disclosure of vulnerabilities and their mitigations to grid operators (and establishing a mechanism for doing that).

Tuesday, September 12, 2017

Senate Amendments to HR 2810 (FY 2018 NDAA) – 9-11-17

Yesterday the Senate voted to close debate on the motion to close further debate on the motion to proceed to consideration of HR 2810, the FY 2018 National Defense Authorization Act (NDAA) by a vote of 89 to 3.This is the first step in the process to begin consideration of HR 2810. In addition to the previously proposed amendments (see here and here) a large number of possible amendments to HR 2180 were proposed in the Senate yesterday; including five that may be of specific interest to readers of this blog:

• SA 856. Mr. BROWN - Collaboration between federal aviation administration and department of defense on unmanned aircraft systems (pg S5118);
• SA 867. Ms. WARREN - Report on significant security risks of defense critical electric infrastructure (pgs S5121-2);
• SA 868. Mr. VAN HOLLEN - Strengthening allied cybersecurity (pgs S5122-3);
• SA 919. Mr. MCCAIN - Report on training infrastructure for cyber forces (pg S5146);
• SA 922. Mr. MCCAIN - Unmanned aircraft systems that pose a threat to the safety or security of certain department of defense facilities and assets (pg S5147)

Electric Infrastructure Security Risks


Yesterday’s amendment by Sen. Warren (D,MA) is nearly identical to the one she proposed last week (SA 794). The only change that I could see is that her staff added a definition of ‘security risk’:

“The term ‘‘security risk’’ shall have such meaning as the Secretary of Defense shall determine, in coordination with the Director of National Intelligence and the Secretary of Energy….”

Not much of a definition, but it does lay the onus for coming up with a useful definition with the people technically qualified to make the assessment.

DOD and UAS


SA 922 takes an interesting approach to the problem of shooting down unmanned aircraft systems (UAS) in United States airspace. Currently, damaging or shooting down an aircraft in US airspace is a criminal act under 18 USC 32 and there is no exemption in that section for actions by military personnel. This amendment would tangentially approach that problem for UAS by allowing the military to ‘seize’ UAS irrespective of the restrictions in 18 USC. Interestingly, there is no indication in the amendment on how DOD would be expected to seize those UAS or in what condition they would be when seized.

That authority would only be available at some very limited ‘covered facilities or assets’. Those would be defined as facilities relating to:

• The nuclear deterrence mission of the Department of Defense, including with respect to nuclear command and control, integrated tactical warning and attack assessment, and continuity of government;
• The missile defense mission of the Department; or
• The national security space mission of the Department.

Moving Forward


Yesterday’s vote is a pretty good indication that the Senate leadership has worked out an agreement on how to proceed with the consideration of HR 2810. There are still some procedural measures where that consideration could be derailed by a sizeable minority of the Senators, but at this point it looks like a much-amended HR 2810 will eventually get a floor vote in the Senate, maybe even this month.


When it eventually passes it will almost certainly be referred to a conference committee to work out the differences between the House and Senate versions of the bill. Still, we are likely to see a final version of the bill on the President’s desk well before the December deadline on other measures clogs up the legislative process.

Wednesday, August 5, 2015

Amendments to S 754 – 08-04-15

While the Senate is trying to get S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015, to a floor vote before leaving on their summer recess at the end of the week, a number of amendments are being submitted that may or may not be considered before the final floor vote. Yesterday, for instance there were 65 such amendments submitted. Of those amendments only four may be of specific interest to readers of this blog:

SA 2573. Mr. Flake (R,AZ), pgs S6306-07;
SA 2576. Mr. Markey (D,MA), pgs S6309-10;
SA 2608. Ms. Warren (D,MA), pg S6321; and
SA 2609. Ms. Warren, pg S6321

The Flake amendment deals with electric grid cybersecurity issues and is a virtual copy of HR 2271 which has yet to be acted upon in the House. Similarly the Markey amendment is a copy of S 1806; his bill on automotive cybersecurity issues.

The two amendments by Warren both deal with liability issues. The first ensures that the provisions of §6 (Protection from Liability) of the bill are not misconstrued to apply to organizations that do not take actions to “action to address a cybersecurity threat or a security vulnerability”. Similarly SA 2609 adds a new paragraph to §6 that specifically requires an entity that receives information “regarding a cybersecurity threat or a security vulnerability under this Act” to take actions to “to address the threat or vulnerability” or be liable.


As of this morning’s publication of yesterday’s Congressional Record there was no agreement in place as to what amendments would or would not be taken up prior to the final vote on S 754.

Monday, April 7, 2014

Congressional Hearings – Week of 4-6-14

Both the House and Senate are in town and the budget is still the big topic with the House scheduled to vote on the FY 2015 budget and the Senate set to ignore it. Still the House has two spending related hearings of note and Senate hearings look at a CSB nomination and the security of the electric grid.

Spending Hearings

Agency
House
Approp.
House
Oversight
Senate
Approp.
Senate
Oversight
DHS
3-11-14
3-13-14
3-11-14
3-13-14
DOT
3-12-14
3-12-14
3-13-14

Defense
3-13-14
3-6-14
NA
NA
CG
3-12-14
3-26-14


FEMA
3-26-14
3-25-14

3-13-14
TSA
3-25-14




As you can see from the table above there are no changes to the big ticket spending hearings. This week’s House hearings of spending note address cybersecurity and WMD spending.

The Homeland Security Subcommittee of the House of the House Appropriations Committee will hold a closed hearing on the DHS cybersecurity budget on Tuesday. The witness list includes three witnesses from the DHS National Protection and Programs Directorate:

• Dr. Phyllis Schneck;
• Suzanne Spaulding; and
• Larry Zelvin

The Intelligence, Emerging Threats and Capabilities Subcommittee of the House Armed Services Committee will hold a hearing on the FY 15 Budget request for the Defense Threat Reduction Agency and the Chemical Biological Defense Program. Witnesses will include:

• Rebecca K. C. Hersman, Deputy Assistant Secretary of Defense for Countering Weapons of Mass Destruction;
• Kenneth Myers, Director, Defense Threat Reduction Agency;
• Carmen Spencer, Joint Program Executive Officer for Chemical and Biological Defense; and
• Andy Weber, Assistant Secretary for Defense for Nuclear, Chemical, and Biological Defense Programs

CSB Nomination

The Senate Environment and Public Works Committee will be holding a hearing Tuesday that will include the nomination of Manuel H. Ehrlich, Jr., to be a Member of the Chemical Safety and Hazard Investigation Board.

Electric Grid Security


The Senate Energy and Natural Resources Committee will be holding a hearing on Thursday looking at “Keeping the lights on — Are we doing enough to ensure the reliability and security of the US electric grid?” No witness list has yet been posted.
 
/* Use this with templates/template-twocol.html */