Showing posts with label Energy Cybersecurity. Show all posts
Showing posts with label Energy Cybersecurity. Show all posts

Sunday, June 6, 2021

Review – S 1400 Introduced – PROTECT Act of 2021

Back in March, Sen Murkowski (R,AK) introduced S 1400, the Protecting Resources on The Electric grid with Cybersecurity Technology (PROTECT) Act of 2021. The bill would provide energy cybersecurity investment incentives and establish a grant and technical assistance program for cybersecurity investments. The language is virtually identical to S 2556 that was introduced in the 116th Congress and reported in the Senate.

Section 2 of the bill would amend the Federal Power Act by adding a new §219A, Incentives for Cybersecurity Investments. The bill would require the Federal Energy Regulatory Commission (FERC) to “conduct a study to identify incentive-based, including performance-based, rate treatments for the transmission of electric energy subject to the jurisdiction of the Commission that could be used to encourage” investment by public utilities in advanced cybersecurity technology.

One year after the study was completed the bill would require FERC to establish a rule providing for “incentive-based, including performance-based, rate treatments for the transmission of electric energy in interstate commerce by public utilities for the purpose of benefitting consumers by encouraging” the same investments and participation described above.

Finally, the bill would require DOE to establish the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program to “to provide grants and technical assistance to, and enter into cooperative agreements with, eligible entities to protect against, detect, respond to, and recover from cybersecurity threats.” The bill would authorize $50 million dollars per year thru 2026 for the grant program.

Murkowski and three of her cosponsors {Sen Manchin (D,WV), Risch (R,ID), and King (I,ME)} are all members of the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. Between them (especially considering that Manchin is the Committee Chair) they certainly have enough influence to see the bill considered in Committee. I expect that this bill (as did S 2556 last session) would receive strong bipartisan support in Committee and ultimately in the Senate.

For a more detailed review of the details of this bill, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1400-introduced - Subscription Required.

Tuesday, February 27, 2018

S 2444 Introduced – Grid Security


Earlier this month Sen Cantwell (D,WA) introduced S 2444, the Energy Cybersecurity Act of 2018. It would require the Department of Energy to address electric grid cybersecurity, resiliency and risk assessment issues.

Cybersecurity


Section 3(a) would require the Secretary to address energy sector cybersecurity issues. It would require DOE to develop cybersecurity applications and technologies to {§3(a)(1)(A)}:

• Identify and mitigate vulnerabilities; and
Advance the security of field devices and third-party control systems;

The vulnerabilities that are required to be addressed specifically include {§3(a)(1)(A)(i)}:

• Dependencies on other critical infrastructure; and
• Impacts from weather and fuel supply.

The security advances would specifically include devices and systems such as {§3(a)(1)(A)(ii)}:

• Systems for generation, transmission, distribution, end use, and market functions;
• Specific electric grid elements including advanced metering, demand response, distributed generation, and electricity storage;
• Forensic analysis of infected systems; and
• Secure communications

The bill would authorize the expenditure of $65 million per year through 2026 for these efforts.

Cyberresilience Testing


Section 3(b) of the bill would require the Secretary to develop a cyberresilience testing program “to identify vulnerabilities of energy sector supply chain products to known threats” {§3(b)(1)(A)}. The program would include oversight of third party cyber-testing and developing procurement guidelines for energy sector supply chain components. The bill would authorize the expenditure of $15 million per year for this program.

Cyberresilience Operational Support


Section 3(c) of the bill would allow the Secretary to carry out a program to {§3(c)(1)}:

• Enhance and periodically test the emergency response capabilities
 of the Department in coordination with other agencies, the National Laboratories, and private industry;
• Expand cooperation of the Department with the intelligence communities for energy sector-related threat collection and analysis;
• Enhance the tools of the Department and ES–ISAC for monitoring the status of the energy sector;
• Expand industry participation in ES–ISAC; and
• Provide technical assistance to small electric utilities for purposes of assessing cyber-maturity level.

The bill would authorize the expenditure of $10 million per year for these activities.

Energy Sector Infrastructure Risk


Section 3(d) of the bill would require the Secretary to “develop an advanced energy security program to secure energy networks, including electric, natural gas, and oil exploration, transmission, and delivery” {§3(d)(1)}. The goal of the program would be “to increase the functional preservation of the electric grid operations or natural gas and oil operations in the face of natural and human-made threats and hazards, including electric magnetic pulse and geomagnetic disturbances” {§3(d)(2)}.

To support this effort the Secretary would be allowed to {§3(d)(3)}:

• Develop capabilities to identify vulnerabilities and critical components that pose major risks to grid security if destroyed or impaired;
• Provide modeling at the national level to predict impacts from natural or human-made events;
• Develop a maturity model for physical security and cybersecurity;
• Conduct exercises and assessments to identify and mitigate vulnerabilities to the electric grid, including providing mitigation recommendations;
• Conduct research hardening solutions for critical components of the electric grid;
• Conduct research mitigation and recovery solutions for critical components of the electric grid; and
• Provide technical assistance to States and other entities for standards and risk analysis.

The bill would authorize the expenditure of $10 million per year to support these activities.

Moving Forward


Cantwell is the Ranking Member on the Senate Energy and Natural Resources Committee to which this bill was assigned for consideration. This would seem to indicate that she could have the necessary influence to see this bill considered by that Committee. The lack of a Republican co-sponsor, however, may indicate the lack of bipartisan support necessary to see the bill moved out of Committee.

The big stumbling block to moving this bill forward is the inclusion of funding authorization for the programs described in the bill. While the amounts authorized are small on the federal money scale, under Senate rules they would still have to come out of existing funding. If Cantwell can identify funding sources for this bill, it would make moving the bill forward much easier.

Commentary


Section 2 of the bill does provide definitions of some of the organization terms used in the bill, but it does not address any of the technical definitions of terms like ‘cybersecurity’ or ‘cyberresilience’. I suspect that this was done to provide the Secretary with the widest possible latitude in exercising authority under this legislation. Unfortunately, I think that this actually have the opposite effect; actually limiting what actions are taken.

As I am with most pieces of cybersecurity legislation that I review, I am disappointed that Cantwell (and her Committee Staff who actually crafted this bill) fails to address the role of independent security researchers in discovering vulnerabilities in software and devices. Section 3(b) of this bill would have been an excellent place to address this issue.

Instead of establishing a “cybertesting (sic) and mitigation program to identify vulnerabilities of energy sector supply chain products” the bill should have established an office in the DOE responsible for the identification and coordination of cyber-vulnerability mitigation in devices and applications used in the energy sector. While this is very similar to what ICS-CERT is currently doing on a voluntary basis for a much wider range of devices, a DOE-CERT would be given the specific responsibility to push vulnerability communications down to covered user-entities. Positive vendor responses to vulnerability identification could be ensured by DOE-CERT requiring covered user-entities to take specific compensatory measures when vendors cannot or will not mitigate vulnerabilities. A DOE-CERT could also provide support to the independent researcher community buy managing a DOE bug bounty program.

Finally, I would have liked to have seen this bill specifically address supporting {in §3(c)} National Guard cyber units in preparing for emergency response for cyber related grid emergencies. This would be particularly appropriate for grid emergencies that cross State boundaries. A DOE resiliency office could serve a coordinating office for multi-state planning and execution of responses to grid emergencies. This non-military coordination would provide political and legal cover for posse comitatus concerns.

Monday, June 8, 2015

Committee Hearings – Week of 06-07-15

Both the House and Senate are in town this week. The House will be dealing with spending bills (THUD and DOD) and the Senate will be dealing with their DOD authorization bill, HR 1735. There will be some committee hearings that may be of specific interest to readers of this blog including DOD-civil support, transportation technology, energy cybersecurity, and the Senate DOD spending bill.

DOD Spending Bills

The House Rules Committee will be holding a hearing to develop the rule for the consideration of HR 2685. This will be the typical free-for-all amendment process that have come to make spending bills so interesting. There were no cybersecurity provisions of note in the original bill, but we may end up seeing some added in the amendment process. The Majority Leader’s web site expects that the bill will make it to the House floor this week.

The Senate Appropriations Committee is finishing up work on their version of the DOD spending bill this week. The Armed Services Subcommittee will mark it up on Tuesday and the whole Committee on Thursday.

DOD Civil Support

The Emergency Preparedness, Response and Communications Subcommittee of the House Homeland Security Committee will hold a hearing on Wednesday on Defense Support of Civil Authorities: A Vital Resource in the Nation’s Homeland Security Missions. I’ve long maintained that the military has response capabilities that would provide valuable augmentation for any number of different civil emergencies.

With the recent introduction of S 1478, with its requirement for DOD planning for cybersecurity support for the Homeland, this hearing should provide a more realistic look at DOD capabilities. I don’t really expect to hear much about cyber support capabilities in this hearing.

Transportation Technology

The Research and Technology Subcommittee of the House Science, Space, and Technology Committee will hold a hearing on Friday on US Surface Transportation: Technology Driving the Future. I expect that we will hear about vehicle-to-vehicle and vehicle-to-infrastructure communications, but not the potential cybersecurity or communications security problems with that developing technology.

Energy Cybersecurity

The Senate Energy and Natural Resources Committee will be holding a hearing on Tuesday on Energy Accountability and Reform Legislation. A high-powered selection of witnesses will testify about a VERY large list of bills under consideration by the Committee. Only two may be of specific interest to readers of this blog:

S 1068, to amend the Federal Power Act to protect the bulk-power system from cyber security threats;
S 1241, to provide for the modernization, security, and resiliency of the electric grid, to require the Secretary of Energy to carry out programs for research, development, demonstration, and information-sharing for cybersecurity for the energy sector, and for other purposes.


With the huge number of bills listed for consideration at this hearing, it is unlikely that there will be much detail provided about anything. This will be even worse than the typical congressional hearing because of the wide variety of topics under consideration.
 
/* Use this with templates/template-twocol.html */